Microsoft-Windows-Hyper-V-Hierarchical-NIC-Switch

EventTitleChannelSampleRule
10Begin starting the driverOperationalNN
11Finished starting the driverOperationalNN
12Starting the driver failed with status codeOperationalNN
12Starting the driver failed with status code StatusCode.SystemNN
13Begin unloading the driverOperationalNN
14Finished unloading the driverOperationalNN
20Begin attaching to adapter AdapterLuid id AdapterGuid ifAlias ifAlias MAC …OperationalNN
21Finished attaching to adapter AdapterLuid.OperationalNN
22Declining to attach to adapter AdapterLuid as it is not necessary.OperationalNN
23Attaching to adapter AdapterLuid failed with status codeOperationalNN
23Attaching to adapter AdapterLuid failed with status code StatusCode.SystemNN
24Begin detaching from adapter AdapterLuid.OperationalNN
25Finished detaching from adapter AdapterLuid.OperationalNN
26Begin pre-detaching from adapter AdapterLuid.OperationalNN
27Finished pre-detaching from adapter AdapterLuid.OperationalNN
28VF initialize AdapterLuid failed with status code StatusCode.OperationalNN
30The state machine on adapter AdapterLuid enqueued event 'Event' of type …OperationalNN
31The state machine on adapter AdapterLuid transitioned from state 'SourceState' …OperationalNN
32Time elapsed: VF ID = DeviceID and Elapsed Time in ns = SerialNumber.OperationalNN
33Event ID 33OperationalNN
40Cannot create another ObjectType on adapter AdapterLuid: the maximum number of …OperationalNN
41Cannot find an object of type ObjectType with ID ObjectID on adapter …OperationalNN
42Rejecting attempt to allocate new objects on adapter AdapterLuid while the …OperationalNN
43Received 'NotificationType' PNP notification for device with device interface …OperationalNN
50The VF availability on adapter AdapterLuid has changed.OperationalNN
51Setting linked device: AdapterLuid: AdapterLuid, DeviceAddress: deviceAddress, …OperationalNN
52Setting MAC address: AdapterLuid: AdapterLuid, PreviousMacAddress: MacAddress1, …OperationalNN
53Policy notification: AdapterLuid: AdapterLuid, UniqueEventValue: …OperationalNN
54Applying device policy: AdapterLuid: AdapterLuid, LinkedDeviceAddress: …OperationalNN
55Reevaluating the advertised VF state: AdapterLuid: AdapterLuid, ProxyState: …OperationalNN
56Received device notification for adapter AdapterLuid: notification kind: …OperationalNN
60A status indication on adapter AdapterLuid was suppressed because the filter …OperationalNN
70Begin handling NDIS OID request NdisOidCode on adapter AdapterLuid.OperationalNN
71Finished handling NDIS OID request NdisOidCode on adapter AdapterLuid.OperationalNN
72Handled NDIS OID request NdisOidCode on adapter AdapterLuid by failing with NDIS …OperationalNN
73Begin issuing NDIS OID request NdisOidCode on adapter AdapterLuid.OperationalNN
74Finished issuing NDIS OID request NdisOidCode on adapter AdapterLuid.OperationalNN
75Issued NDIS OID request NdisOidCode on adapter AdapterLuid failed with NDIS …OperationalNN
76Issued NDIS OID request NdisOidCode is not supported by adapter AdapterLuid.OperationalNN
80Issued NDIS Status Indication NdisStatus over adapter AdapterLuid, payload …OperationalNN
90Begin handling IO Control: IoControlCode.OperationalNN
91Finished handling IO Control: IoControlCode with status StatusCode.OperationalNN
92Failing IO Control: IoControlCode with status StatusCode.OperationalNN
100A DeviceInterfaceKind device was added (internal correlation ID: DeviceID; …OperationalNN
101A DeviceInterfaceKind device was removed (internal correlation ID: DeviceID).OperationalNN
105Multiple devices were found to match the virtualization serial number …OperationalNN

Event ID 10: Begin starting the driver

#
Channel
Operational
Opcode
Start

Event ID 11: Finished starting the driver

#
Channel
Operational
Opcode
Stop

Fields #

NameDescription
StatusCode HexInt32NTSTATUS reference

Event ID 12: Starting the driver failed with status code

#
Channel
Operational

Fields #

NameDescription
StatusCode HexInt32NTSTATUS reference

Event ID 12: Starting the driver failed with status code StatusCode.

#
Channel
System

Message #

Starting the driver failed with status code %1

Fields #

NameDescription
StatusCode HexInt32NTSTATUS reference

Event ID 13: Begin unloading the driver

#
Channel
Operational
Opcode
Start

Event ID 14: Finished unloading the driver

#
Channel
Operational
Opcode
Stop

Event ID 20: Begin attaching to adapter AdapterLuid id AdapterGuid ifAlias ifAlias MAC address MacAddress.

#
Channel
Operational
Opcode
Start

Message #

Begin attaching to adapter %1 id %2 ifAlias %3 MAC address %5

Fields #

NameDescription
AdapterLuid UInt64
AdapterGuid GUID
ifAlias UnicodeString
MacAddressLength UInt32
MacAddress Binary

Event ID 21: Finished attaching to adapter AdapterLuid.

#
Channel
Operational
Opcode
Stop

Message #

Finished attaching to adapter %1

Fields #

NameDescription
AdapterLuid UInt64
StatusCode HexInt32NTSTATUS reference

Event ID 22: Declining to attach to adapter AdapterLuid as it is not necessary.

#
Channel
Operational

Description

Declining to attach to adapter AdapterLuid as it is not necessary. status code StatusCode.

Message #

Declining to attach to adapter %1 as it is not necessary. status code %2

Fields #

NameDescription
AdapterLuid UInt64
StatusCode HexInt32NTSTATUS reference

Event ID 23: Attaching to adapter AdapterLuid failed with status code

#
Channel
Operational

Description

Attaching to adapter failed with status code.

Fields #

NameDescription
AdapterLuid UInt64
StatusCode HexInt32NTSTATUS reference

Event ID 23: Attaching to adapter AdapterLuid failed with status code StatusCode.

#
Channel
System

Message #

Attaching to adapter %1 failed with status code %2

Fields #

NameDescription
AdapterLuid UInt64
StatusCode HexInt32NTSTATUS reference

Event ID 24: Begin detaching from adapter AdapterLuid.

#
Channel
Operational
Opcode
Start

Message #

Begin detaching from adapter %1

Fields #

NameDescription
AdapterLuid UInt64

Event ID 25: Finished detaching from adapter AdapterLuid.

#
Channel
Operational
Opcode
Stop

Message #

Finished detaching from adapter %1

Fields #

NameDescription
AdapterLuid UInt64

Event ID 26: Begin pre-detaching from adapter AdapterLuid.

#
Channel
Operational
Opcode
Start

Message #

Begin pre-detaching from adapter %1

Fields #

NameDescription
AdapterLuid UInt64

Event ID 27: Finished pre-detaching from adapter AdapterLuid.

#
Channel
Operational
Opcode
Stop

Message #

Finished pre-detaching from adapter %1

Fields #

NameDescription
AdapterLuid UInt64

Event ID 28: VF initialize AdapterLuid failed with status code StatusCode.

#
Channel
Operational

Message #

VF initialize %1 failed with status code %2

Fields #

NameDescription
AdapterLuid UInt64
StatusCode HexInt32NTSTATUS reference

Event ID 30: The state machine on adapter AdapterLuid enqueued event 'Event' of type 'StateMachineType'.

#
Channel
Operational

Message #

The state machine on adapter %1 enqueued event '%3' of type '%2'

Fields #

NameDescription
AdapterLuid UInt64
StateMachineType UInt8
Event AnsiString

Event ID 31: The state machine on adapter AdapterLuid transitioned from state 'SourceState' to state 'TargetState' due to event 'Event'.

#
Channel
Operational

Message #

The state machine on adapter %1 transitioned from state '%4' to state '%5' due to event '%6'

Fields #

NameDescription
AdapterLuid UInt64
StateMachineType UInt8
TransitionType UInt8
SourceState AnsiString
TargetState AnsiString
Event AnsiString

Event ID 32: Time elapsed: VF ID = DeviceID and Elapsed Time in ns = SerialNumber.

#
Channel
Operational

Message #

Time elapsed: VF ID = %1 and Elapsed Time in ns = %2

Fields #

NameDescription
DeviceID UInt64
SerialNumber UInt64
ElapsedTime UInt64

Event ID 33

#
Channel
Operational

Fields #

NameDescription
DeviceID UInt64
SerialNumber UInt64
ElapsedTime UInt64

Event ID 40: Cannot create another ObjectType on adapter AdapterLuid: the maximum number of objects of this type already have been created.

#
Channel
Operational

Message #

Cannot create another %2 on adapter %1: the maximum number of objects of this type already have been created

Fields #

NameDescription
AdapterLuid UInt64
ObjectType UInt8

Event ID 41: Cannot find an object of type ObjectType with ID ObjectID on adapter AdapterLuid.

#
Channel
Operational

Message #

Cannot find an object of type %2 with ID %3 on adapter %1

Fields #

NameDescription
AdapterLuid UInt64
ObjectType UInt8
ObjectID HexInt32

Event ID 42: Rejecting attempt to allocate new objects on adapter AdapterLuid while the filter driver has begun detaching.

#
Channel
Operational

Message #

Rejecting attempt to allocate new objects on adapter %1 while the filter driver has begun detaching

Fields #

NameDescription
AdapterLuid UInt64

Event ID 43: Received 'NotificationType' PNP notification for device with device interface class: DeviceSetupClass.

#
Channel
Operational

Message #

Received '%1' PNP notification for device with device interface class: %2.

Fields #

NameDescription
NotificationType UInt8
DeviceSetupClass GUID

Event ID 50: The VF availability on adapter AdapterLuid has changed.

#
Channel
Operational

Message #

The VF availability on adapter %1 has changed

Fields #

NameDescription
AdapterLuid UInt64

Event ID 51: Setting linked device: AdapterLuid: AdapterLuid, DeviceAddress: deviceAddress, LinkedDeviceAddress: linkedDeviceAddress.

#
Channel
Operational

Message #

Setting linked device: AdapterLuid: %1, DeviceAddress: %2, LinkedDeviceAddress: %3

Fields #

NameDescription
AdapterLuid UInt64
deviceAddress Pointer
linkedDeviceAddress Pointer

Event ID 52: Setting MAC address: AdapterLuid: AdapterLuid, PreviousMacAddress: MacAddress1, NewMacAddress: MacAddress2.

#
Channel
Operational

Message #

Setting MAC address: AdapterLuid: %1, PreviousMacAddress: %2, NewMacAddress: %3

Fields #

NameDescription
AdapterLuid UInt64
MacAddress1 Binary
MacAddress2 Binary

Event ID 53: Policy notification: AdapterLuid: AdapterLuid, UniqueEventValue: UniqueEventValue, TargetRole: DeviceRole.

#
Channel
Operational

Message #

Policy notification: AdapterLuid: %1, UniqueEventValue: %2, TargetRole: %3

Fields #

NameDescription
AdapterLuid UInt64
UniqueEventValue UInt32
DeviceRole UInt32

Event ID 54: Applying device policy: AdapterLuid: AdapterLuid, LinkedDeviceAddress: linkedDeviceAddress, TargetRole: DeviceRole.

#
Channel
Operational

Message #

Applying device policy: AdapterLuid: %1, LinkedDeviceAddress: %2, TargetRole: %3

Fields #

NameDescription
AdapterLuid UInt64
linkedDeviceAddress Pointer
DeviceRole UInt32

Event ID 55: Reevaluating the advertised VF state: AdapterLuid: AdapterLuid, ProxyState: ProxyState, TargetRole: DeviceRole.

#
Channel
Operational

Message #

Reevaluating the advertised VF state: AdapterLuid: %1, ProxyState: %2, TargetRole: %3

Fields #

NameDescription
AdapterLuid UInt64
ProxyState Boolean
DeviceRole UInt32

Event ID 56: Received device notification for adapter AdapterLuid: notification kind: NotificationKind, device: deviceAddress, serial number: SerialNumber, authoritative: IsSerialNumberAuthoritative, proxy up: ...

#
Channel
Operational

Description

Received device notification for adapter AdapterLuid: notification kind: NotificationKind, device: deviceAddress, serial number: SerialNumber, authoritative: IsSerialNumberAuthoritative, proxy up: IsProxyUp, PCI proxy LUID: PciProxyLuid, current LUID: mLuid.

Message #

Received device notification for adapter %1: notification kind: %2, device: %3, serial number: %4, authoritative: %5, proxy up: %6, PCI proxy LUID: %7, current LUID: %8

Fields #

NameDescription
AdapterLuid UInt64
NotificationKind UInt32
deviceAddress Pointer
SerialNumber UInt32
IsSerialNumberAuthoritative Boolean
IsProxyUp Boolean
PciProxyLuid UInt64
mLuid UInt64

Event ID 60: A status indication on adapter AdapterLuid was suppressed because the filter driver has replaced that feature with its own capabilities.

#
Channel
Operational

Description

A status indication on adapter AdapterLuid was suppressed because the filter driver has replaced that feature with its own capabilities. NDIS_STATUS indication code: NdisStatus.

Message #

A status indication on adapter %1 was suppressed because the filter driver has replaced that feature with its own capabilities. NDIS_STATUS indication code: %2

Fields #

NameDescription
AdapterLuid UInt64
NdisStatus HexInt32

Event ID 70: Begin handling NDIS OID request NdisOidCode on adapter AdapterLuid.

#
Channel
Operational
Opcode
Start

Message #

Begin handling NDIS OID request %2 on adapter %1

Fields #

NameDescription
AdapterLuid UInt64
NdisOidCode UInt32

Event ID 71: Finished handling NDIS OID request NdisOidCode on adapter AdapterLuid.

#
Channel
Operational
Opcode
Stop

Message #

Finished handling NDIS OID request %2 on adapter %1

Fields #

NameDescription
AdapterLuid UInt64
NdisOidCode UInt32
NdisStatus HexInt32

Event ID 72: Handled NDIS OID request NdisOidCode on adapter AdapterLuid by failing with NDIS status code NdisStatus.

#
Channel
Operational

Message #

Handled NDIS OID request %2 on adapter %1 by failing with NDIS status code %3

Fields #

NameDescription
AdapterLuid UInt64
NdisOidCode UInt32
NdisStatus HexInt32

Event ID 73: Begin issuing NDIS OID request NdisOidCode on adapter AdapterLuid.

#
Channel
Operational
Opcode
Stop

Message #

Begin issuing NDIS OID request %2 on adapter %1

Fields #

NameDescription
AdapterLuid UInt64
NdisOidCode UInt32

Event ID 74: Finished issuing NDIS OID request NdisOidCode on adapter AdapterLuid.

#
Channel
Operational
Opcode
Stop

Message #

Finished issuing NDIS OID request %2 on adapter %1

Fields #

NameDescription
AdapterLuid UInt64
NdisOidCode UInt32
NdisStatus HexInt32

Event ID 75: Issued NDIS OID request NdisOidCode on adapter AdapterLuid failed with NDIS status code NdisStatus.

#
Channel
Operational

Message #

Issued NDIS OID request %2 on adapter %1 failed with NDIS status code %3

Fields #

NameDescription
AdapterLuid UInt64
NdisOidCode UInt32
NdisStatus HexInt32

Event ID 76: Issued NDIS OID request NdisOidCode is not supported by adapter AdapterLuid.

#
Channel
Operational

Message #

Issued NDIS OID request %2 is not supported by adapter %1

Fields #

NameDescription
AdapterLuid UInt64
NdisOidCode UInt32
NdisStatus HexInt32

Event ID 80: Issued NDIS Status Indication NdisStatus over adapter AdapterLuid, payload details: PayloadDetail.

#
Channel
Operational

Message #

Issued NDIS Status Indication %2 over adapter %1, payload details: %3

Fields #

NameDescription
AdapterLuid UInt64
NdisStatus HexInt32
PayloadDetail HexInt32

Event ID 90: Begin handling IO Control: IoControlCode.

#
Channel
Operational
Opcode
Start

Message #

Begin handling IO Control: %1

Fields #

NameDescription
IoControlCode UInt32

Event ID 91: Finished handling IO Control: IoControlCode with status StatusCode.

#
Channel
Operational
Opcode
Stop

Message #

Finished handling IO Control: %1 with status %2

Fields #

NameDescription
IoControlCode UInt32
StatusCode HexInt32NTSTATUS reference

Event ID 92: Failing IO Control: IoControlCode with status StatusCode.

#
Channel
Operational

Message #

Failing IO Control: %1 with status %2

Fields #

NameDescription
IoControlCode UInt32
StatusCode HexInt32NTSTATUS reference

Event ID 100: A DeviceInterfaceKind device was added (internal correlation ID: DeviceID; virtualization serial number: SerialNumber; PNP location path: LocationPath).

#
Channel
Operational

Message #

A %2 device was added (internal correlation ID: %1; virtualization serial number: %3; PNP location path: %4)

Fields #

NameDescription
DeviceID UInt64
DeviceInterfaceKind UInt8
SerialNumber UInt32
LocationPath UnicodeString

Event ID 101: A DeviceInterfaceKind device was removed (internal correlation ID: DeviceID).

#
Channel
Operational

Message #

A %2 device was removed (internal correlation ID: %1)

Fields #

NameDescription
DeviceID UInt64
DeviceInterfaceKind UInt8

Event ID 105: Multiple devices were found to match the virtualization serial number VirtualizationSerialNumber: for example PNP location paths 'LocationPath1' and 'LocationPath2'.

#
Channel
Operational

Message #

Multiple devices were found to match the virtualization serial number %1: for example PNP location paths '%2' and '%3'

Fields #

NameDescription
VirtualizationSerialNumber UInt32
LocationPath1 UnicodeString
LocationPath2 UnicodeString

Provenance

ETW provider GUID 31732ca5-d67c-59fd-dd5c-60a136ee4953

Defined in l1vhlwf.sys, the binary that emits these events.

  • Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.3037, captured 2026-06-02 — Manifest XML pack, 2.0 MB