Microsoft-Windows-Hyper-V-Hypervisor

EventTitleChannelSampleRule
1Hypervisor successfully started.SystemYN
2Hypervisor scheduler type is SchedulerType.SystemYN
3Hypervisor Eventlog for global system events could not be created!SystemNN
5Hypervisor launch has been disabled through the hypervisorlaunchtype bcdedit …SystemNN
10Hypervisor Eventlog creation failed!Microsoft-Windows-Hyper-V-Hypervisor-OperationalNN
11Hypervisor Eventlog deletion failed!Microsoft-Windows-Hyper-V-Hypervisor-OperationalNN
12Host processor features mask: Host_processor_features_mask.Microsoft-Windows-Hyper-V-Hypervisor-OperationalNN
13Hypervisor fails to start ETW tracing session.SystemNN
14Hypervisor Eventlog flush failed!Microsoft-Windows-Hyper-V-Hypervisor-OperationalNN
20Hypervisor launch failed; sleep and hibernate could not be disabled (status …SystemNN
26Hypervisor launch failed; the hypervisor boot loader's internal logic failed …SystemNN
27Hypervisor launch failed; the hypervisor boot loader was unable to allocate …SystemNN
28Hypervisor launch failed; the hypervisor boot loader does not support the vendor …SystemNN
29Hypervisor launch failed; at least one of the processors in the system does not …SystemNN
31Hyper-V launch failed; the system does not appear to have a sufficient level of …SystemNN
32Hypervisor launch failed; at least one of the processors in the system does not …SystemNN
33Hyper-V launch failed; the image {ImageName} could not be accessed (status …SystemNN
34Hyper-V launch failed; the image ImageName could not be loaded (status Status).SystemNN
35Hyper-V launch failed; the image {ImageName} could not be read (status …SystemNN
36Hypervisor launch failed; the image ImageName failed code integrity checks, and …SystemNN
37Hypervisor launch failed; the image ImageName does not contain the image …SystemNN
38Hyper-V launch failed; at least one of the processors in the system was unable …SystemNN
39Hypervisor Load Options - LoadOptions.Microsoft-Windows-Hyper-V-Hypervisor-AdminYN
40Hypervisor launch failed; the hypervisor image is revision HypervisorVersion, …SystemNN
41Hypervisor launch failed; Either VMX not present or not enabled in BIOS.SystemYN
42Hypervisor launch failed; Either SVM not present or not enabled in BIOS.SystemNN
43Hypervisor launch failed; EL2 not present.SystemNN
44Hypervisor launch failed; Either No Execute feature (NX) not present or not …SystemNN
46Hypervisor launch failed; Processor does not support the minimum features …SystemNN
47Hypervisor launch failed; Processor does not provide the features necessary to …SystemNN
48Hypervisor launch failed; Processor does not provide the features necessary to …SystemNN
54Hypervisor launch failed; Hypervisor image does not match the platform being run …SystemNN
55Hypervisor launch failed; Required firmware table not found.SystemNN
56Hypervisor launch failed; Encountered invalid firmware information.SystemNN
59Hypervisor launch failed; Second Level Address Translation is required to launch …SystemNN
60Hypervisor launch failed; Secure Mode Extensions have been enabled by the BIOS.SystemNN
61Hypervisor launch failed; Minimum CPUID leaves required by the hypervisor are …SystemNN
62Hypervisor launch failed; The physical address limit supported has been …SystemNN
63Hypervisor launch failed; The hypervisor was unable to initialize successfully …SystemNN
64Hypervisor launch failed; Too many runtime services memory ranges described by …SystemNN
65Hypervisor launch failed; Memory ranges validation failure (BalStatus: …SystemNN
80Hypervisor launch failed; The operating systems boot loader failed with error …SystemNN
81Hypervisor launch failed; The operating system boot loader was unable to locate …SystemNN
82Hypervisor launch failed; The operating system boot loader detected a persistent …SystemNN
83Hypervisor launch failed; The operating system boot loader was unable to …SystemNN
84Hypervisor launch failed; The operating system boot loader was unable to …SystemNN
85Hypervisor launch failed; The operating system boot loader detected a memory map …SystemNN
86Hypervisor launch failed; the version of the microcode update dll does not match …SystemNN
96Hypervisor processor startup failed (APIC ID CPU, status ErrorCode).SystemNN
97Hypervisor processor startup failed (APIC ID CPU) due to CPUID feature …SystemNN
129Hypervisor initialized I/O remapping.SystemYN
130Hypervisor I/O remapping is forcibly enabled by policy (the …SystemNN
131There is an I/O remapping problem with the sytem BIOS.SystemNN
144A device is operating with reduced performance because of a problem with the …SystemNN
145A device will not work correctly because of a problem with the system BIOS.SystemNN
146A device will not work correctly because the hypervisor does not have enough …SystemNN
147A device will not work correctly because of a problem with the system BIOS.SystemNN
148A device could not be used by a child partition because of a limitation of the …SystemNN
149A device could not be used by a child partition because of a limitation of the …SystemNN
150The image {ImageName} could not be accessed (status {Status}).SystemNN
151The image {ImageName} could not be loaded (status {Status}).SystemNN
152The image ImageName could not be read (status Status).SystemNN
153The image ImageName failed code integrity checks, and cannot be used.SystemNN
154Hypervisor failed to properly synchronize TSC across logical processors (Max …SystemNN
155Host processor features mask: BankCount.Microsoft-Windows-Hyper-V-Hypervisor-AdminYN
156Hypervisor initial page allocation NUMA policy: .Microsoft-Windows-Hyper-V-Hypervisor-AdminYN
156Hypervisor configured mitigations for CVE-2018-3646 for virtual machines.SystemYN
157The hypervisor did not enable mitigations for side channel vulnerabilities for …SystemNN
158The queried interface version Max is not supported (Min : CurrentVersion, Max : …SystemNN
159The queried interface is incomplete.SystemNN
160Partition persistence services will be unavailable.SystemNN
161The configured Minroot settings are not compatible with the hypervisor core …SystemNN
162Failed to unregister the remote hypercall interface (status NtStatus).SystemNN
163The hypervisor encountered an internal error: nested NMI (processor Processor).Microsoft-Windows-Hyper-V-Hypervisor-OperationalNN
164The hypervisor encountered an internal error: IPI timeout (processor Processor).Microsoft-Windows-Hyper-V-Hypervisor-OperationalNN
165Hypervisor configured mitigations for CVE-2019-11091, CVE-2018-12126, …SystemYN
166Hypervisor Load Options are conflicting - LoadOptions, LoadFlags.Microsoft-Windows-Hyper-V-Hypervisor-AdminNN
167The hypervisor did not enable mitigations for side channel vulnerabilities for …SystemNN
168AMD PSP PCI device discovered.SystemNN
169Secure firmware update status: Secure_firmware_update_status.SystemNN
170Secure firmware image invalid.SystemNN
171Secure firmware version: Secure_firmware_version.SystemNN
172Features are enabled that require all processors be started.Microsoft-Windows-Hyper-V-Hypervisor-AdminNN
173On the prior boot session, the root partition did not respond to the synthetic …SystemNN
8451Hyper-V failed creating a new partition (status Error)!Microsoft-Windows-Hyper-V-Hypervisor-OperationalNN
12288RegisterInterfaceOperationalNN
12289HvldrIoctlOperationalNN
12290RemoteHypercallOperationalNN
12291HvldrCreatePartitionOperationalNN
12292RegisterPartitionIdOperationalNN
12293HvldrDeletePartitionOperationalNN
12294HvldrDepositMemoryOperationalNN
12295HvldrMapGpaPagesOperationalNN
12296HvldrUnmapGpaSpaceOperationalNN
12297HvldrNumaDistributedAllocationOperationalNN
12298HvldrGetLpRegisterMsrOperationalNN
12299HvldrGetLpRegisterCpuidOperationalNN
12300HvldrReadSystemMemoryOperationalNN
12301HvldrGetMtrrsOperationalNN
12302HvldrGetPlatformCapsOperationalNN
12303HvldrHsrInUseOperationalNN
12304HvldrConfigureIommuLiveHandoffOperationalNN
12305HvldrGetIdleStateConfigOperationalNN
12306HvldrGetVpRegistersOperationalNN
12307HvldrGetLogicalProcessorPropertyOperationalNN
12308HvldrDisableHypervisorOperationalNN
12309HvldrDisableHypervisor12309OperationalNN
12310HvldrPrepareProtoHypervisorOperationalNN
12311HvldrImageLoadInfoOperationalNN
12312HvldrReadHvRegisterOperationalNN
12313HvldrProcessInterruptControllersOperationalNN
12314HvldrHsrMirroringInUseOperationalNN
12315HvldrDebugMsgOperationalNN
12316HvldrDebugMsg12316OperationalNN
12317HvldrFailureLocationOperationalNN
12550Hyper-V detected access to a restricted MSR.Microsoft-Windows-Hyper-V-Hypervisor-OperationalNN
16641Hyper-V successfully created a new partition (partition PartitionId).Microsoft-Windows-Hyper-V-Hypervisor-OperationalYN
16642Hyper-V successfully deleted a partition (partition PartitionId).Microsoft-Windows-Hyper-V-Hypervisor-OperationalYN

Event ID 1: Hypervisor successfully started.

#
Channel
System
Level
Informational
Opcode
Info

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Hyper-V-Hypervisor",
    "guid": "52FC89F8-995E-434C-A91E-199986449890",
    "event_source_name": "",
    "event_id": 1,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 9223442405598953472,
    "time_created": "2026-03-11T06:27:08.616827+00:00",
    "event_record_id": 2708,
    "correlation": {},
    "execution": {
      "process_id": 4,
      "thread_id": 8
    },
    "channel": "System",
    "computer": "LAB-WIN11",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 2: Hypervisor scheduler type is SchedulerType.

#
Channel
System
Level
Informational
Opcode
Info

Message #

Hypervisor scheduler type is %1.

Fields #

NameDescription
SchedulerType HexInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Hyper-V-Hypervisor",
    "guid": "52FC89F8-995E-434C-A91E-199986449890",
    "event_source_name": "",
    "event_id": 2,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 9223442405598953472,
    "time_created": "2026-03-11T06:27:08.616840+00:00",
    "event_record_id": 2709,
    "correlation": {},
    "execution": {
      "process_id": 4,
      "thread_id": 8
    },
    "channel": "System",
    "computer": "LAB-WIN11",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "SchedulerType": "0x4"
  },
  "message": ""
}

Event ID 3: Hypervisor Eventlog for global system events could not be created!

#
Channel
System
Opcode
Info

Event ID 5: Hypervisor launch has been disabled through the hypervisorlaunchtype bcdedit setting.

#
Channel
System
Opcode
Info

Event ID 10: Hypervisor Eventlog creation failed!

#
Channel
Microsoft-Windows-Hyper-V-Hypervisor-Operational
Opcode
Info

Fields #

NameDescription
Error HexInt64

Event ID 11: Hypervisor Eventlog deletion failed!

#
Channel
Microsoft-Windows-Hyper-V-Hypervisor-Operational
Opcode
Info

Fields #

NameDescription
Error HexInt64

Event ID 12: Host processor features mask: Host_processor_features_mask.

#
Channel
Microsoft-Windows-Hyper-V-Hypervisor-Operational
Opcode
Info

Message #

Host processor features mask: %1

Host xsave features mask: %2

Host cache line flush size: %3 bytes

Fields #

NameDescription
BankCount UInt8
ProcessorFeatures HexInt64
XsaveFeatures HexInt64
CLFlushSize UInt32

Event ID 13: Hypervisor fails to start ETW tracing session.

#
Channel
System
Opcode
Info

Event ID 14: Hypervisor Eventlog flush failed!

#
Channel
Microsoft-Windows-Hyper-V-Hypervisor-Operational
Opcode
Info

Fields #

NameDescription
Error HexInt64

Event ID 20: Hypervisor launch failed; sleep and hibernate could not be disabled (status ErrorCode).

#
Channel
System
Opcode
Info

Message #

Hypervisor launch failed; sleep and hibernate could not be disabled (status %1).

Fields #

NameDescription
ErrorCode HexInt32

Event ID 26: Hypervisor launch failed; the hypervisor boot loader's internal logic failed (BalStatus BalStatus, sub-status Error).

#
Channel
System
Opcode
Info

Message #

Hypervisor launch failed; the hypervisor boot loader's internal logic failed (BalStatus %1, sub-status %2).

Fields #

NameDescription
BalStatus HexInt64
Error HexInt32

Event ID 27: Hypervisor launch failed; the hypervisor boot loader was unable to allocate sufficient resources to perform the launch.

#
Channel
System
Opcode
Info

Event ID 28: Hypervisor launch failed; the hypervisor boot loader does not support the vendor of at least one of the processors in the system.

#
Channel
System
Opcode
Info

Event ID 29: Hypervisor launch failed; at least one of the processors in the system does not appear to support the features required by the hypervisor.

#
Channel
System

Message #

Hypervisor launch failed; at least one of the processors in the system does not appear to support the features required by the hypervisor.  (leaf: {Leaf}; required features: {FeaturesRequired}; features available: {FeaturesPresent})

Fields #

NameDescription
Leaf
FeaturesRequired
FeaturesPresent

Event ID 31: Hyper-V launch failed; the system does not appear to have a sufficient level of ACPI support to launch the hypervisor.

#
Channel
System
Opcode
Info

Event ID 32: Hypervisor launch failed; at least one of the processors in the system does not appear to provide a virtualization platform supported by the hyperv...

#
Channel
System
Opcode
Info

Description

Hypervisor launch failed; at least one of the processors in the system does not appear to provide a virtualization platform supported by the hypervisor.

Message #

Hypervisor launch failed; at least one of the processors in the system does not appear to provide a virtualization platform supported by the hypervisor.

Event ID 33: Hyper-V launch failed; the image {ImageName} could not be accessed (status {Status}).

#
Channel
System

Fields #

NameDescription
ImageName
StatusNTSTATUS reference

Event ID 34: Hyper-V launch failed; the image ImageName could not be loaded (status Status).

#
Channel
System
Opcode
Info

Message #

Hyper-V launch failed; the image %1 could not be loaded (status %2).

Fields #

NameDescription
ImageName UnicodeString
Status HexInt32NTSTATUS reference

Event ID 35: Hyper-V launch failed; the image {ImageName} could not be read (status {Status}).

#
Channel
System

Fields #

NameDescription
ImageName
StatusNTSTATUS reference

Event ID 36: Hypervisor launch failed; the image ImageName failed code integrity checks, and cannot be used.

#
Channel
System
Opcode
Info

Message #

Hypervisor launch failed; the image %1 failed code integrity checks, and cannot be used.

Fields #

NameDescription
ImageName UnicodeString

Event ID 37: Hypervisor launch failed; the image ImageName does not contain the image description datastructures, and cannot be used.

#
Channel
System
Opcode
Info

Message #

Hypervisor launch failed; the image %1 does not contain the image description datastructures, and cannot be used.

Fields #

NameDescription
ImageName UnicodeString

Event ID 38: Hyper-V launch failed; at least one of the processors in the system was unable to launch the hypervisor (status BalStatus).

#
Channel
System
Opcode
Info

Message #

Hyper-V launch failed; at least one of the processors in the system was unable to launch the hypervisor (status %1).

Fields #

NameDescription
BalStatus HexInt64

Event ID 39: Hypervisor Load Options - LoadOptions.

#
Channel
Microsoft-Windows-Hyper-V-Hypervisor-Admin
Level
Informational
Opcode
Info

Message #

Hypervisor Load Options - %1.

Fields #

NameDescription
LoadOptions AnsiString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Hyper-V-Hypervisor",
    "guid": "52FC89F8-995E-434C-A91E-199986449890",
    "event_source_name": "",
    "event_id": 39,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 4611686018427387904,
    "time_created": "2026-03-14T01:39:45.534226+00:00",
    "event_record_id": 3,
    "correlation": {
      "ActivityID": "E6C8E93F-24DF-B4AB-98D2-D123EDC8427C"
    },
    "execution": {
      "process_id": 4,
      "thread_id": 8
    },
    "channel": "Microsoft-Windows-Hyper-V-Hypervisor-Admin",
    "computer": "LAB-WIN11.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "LoadOptions": " IGNOREMEMPART=1 "
  },
  "message": ""
}

Event ID 40: Hypervisor launch failed; the hypervisor image is revision HypervisorVersion, but the currently installed virtualization software only supports launching revision...

#
Channel
System
Opcode
Info

Description

Hypervisor launch failed; the hypervisor image is revision HypervisorVersion, but the currently installed virtualization software only supports launching revision VersionSupported hypervisor images.

Message #

Hypervisor launch failed; the hypervisor image is revision %1, but the currently installed virtualization software only supports launching revision %2 hypervisor images.

Fields #

NameDescription
HypervisorVersion UInt32
VersionSupported UInt32

Event ID 41: Hypervisor launch failed; Either VMX not present or not enabled in BIOS.

#
Channel
System
Level
Error
Opcode
Info

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Hyper-V-Hypervisor",
    "guid": "52FC89F8-995E-434C-A91E-199986449890",
    "event_source_name": "",
    "event_id": 41,
    "version": 0,
    "level": 2,
    "task": 0,
    "opcode": 0,
    "keywords": 9223442405598953472,
    "time_created": "2023-11-06T06:24:56.254005+00:00",
    "event_record_id": 1627,
    "correlation": {
      "ActivityID": "A94F03D9-96B8-C53E-D5D7-00FBA9067B3F"
    },
    "execution": {
      "process_id": 4,
      "thread_id": 8
    },
    "channel": "System",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {},
  "message": ""
}

References #

Event ID 42: Hypervisor launch failed; Either SVM not present or not enabled in BIOS.

#
Channel
System
Opcode
Info

Event ID 43: Hypervisor launch failed; EL2 not present.

#
Channel
System
Opcode
Info

Event ID 44: Hypervisor launch failed; Either No Execute feature (NX) not present or not enabled in BIOS.

#
Channel
System
Opcode
Info

Event ID 46: Hypervisor launch failed; Processor does not support the minimum features required to run the hypervisor.

#
Channel
System
Opcode
Info

Description

Hypervisor launch failed; Processor does not support the minimum features required to run the hypervisor (MSR index MSRIndex, allowed bits AllowedZeroes, required bits AllowedOnes).

Message #

Hypervisor launch failed; Processor does not support the minimum features required to run the hypervisor (MSR index %1, allowed bits %2, required bits %3).

Fields #

NameDescription
MSRIndex HexInt32
AllowedZeroes HexInt64
AllowedOnes HexInt64

Event ID 47: Hypervisor launch failed; Processor does not provide the features necessary to run the hypervisor.

#
Channel
System

Message #

Hypervisor launch failed; Processor does not provide the features necessary to run the hypervisor (BalStatus {BalStatus}; leaf1 EAX {Leaf1Eax}; VMCR MS EAX {VmCrMsrValue}; SVM CPUID features {SvmFeatureEax}; has working SMM {HasWorkingSmm}).

Fields #

NameDescription
BalStatus
Leaf1Eax
VmCrMsrValue
SvmFeatureEax
HasWorkingSmm

Event ID 48: Hypervisor launch failed; Processor does not provide the features necessary to run the hypervisor.

#
Channel
System
Opcode
Info

Description

Hypervisor launch failed; Processor does not provide the features necessary to run the hypervisor (leaf Leaf, register Register: features needed FeaturesNeeded, features supported FeaturesSupported).

Message #

Hypervisor launch failed; Processor does not provide the features necessary to run the hypervisor (leaf %1, register %2: features needed %3, features supported %4).

Fields #

NameDescription
Leaf HexInt32
Register HexInt32
FeaturesNeeded HexInt32
FeaturesSupported HexInt32

Event ID 54: Hypervisor launch failed; Hypervisor image does not match the platform being run on.

#
Channel
System
Opcode
Info

Event ID 55: Hypervisor launch failed; Required firmware table not found.

#
Channel
System
Opcode
Info

Event ID 56: Hypervisor launch failed; Encountered invalid firmware information.

#
Channel
System
Opcode
Info

Event ID 59: Hypervisor launch failed; Second Level Address Translation is required to launch the hypervisor.

#
Channel
System
Opcode
Info

Event ID 60: Hypervisor launch failed; Secure Mode Extensions have been enabled by the BIOS.

#
Channel
System
Opcode
Info

Description

Hypervisor launch failed; Secure Mode Extensions have been enabled by the BIOS. Please disable Secure Mode Extensions in the BIOS to launch Hyper-V.

Message #

Hypervisor launch failed; Secure Mode Extensions have been enabled by the BIOS. Please disable Secure Mode Extensions in the BIOS to launch Hyper-V.

Event ID 61: Hypervisor launch failed; Minimum CPUID leaves required by the hypervisor are not supported on the system.

#
Channel
System
Opcode
Info

Event ID 62: Hypervisor launch failed; The physical address limit supported has been exceeded.

#
Channel
System
Opcode
Info

Event ID 63: Hypervisor launch failed; The hypervisor was unable to initialize successfully (phase Phase), and was not started.

#
Channel
System
Opcode
Info

Description

Hypervisor launch failed; The hypervisor was unable to initialize successfully (phase Phase), and was not started. This initialization failure may be the result of a platform configuration or firmware issue. Contact your system vendor for more information or updated firmware.

Message #

Hypervisor launch failed; The hypervisor was unable to initialize successfully (phase %1), and was not started.  This initialization failure may be the result of a platform configuration or firmware issue.  Contact your system vendor for more information or updated firmware.

Fields #

NameDescription
Phase HexInt32

Event ID 64: Hypervisor launch failed; Too many runtime services memory ranges described by firmware.

#
Channel
System
Opcode
Info

Event ID 65: Hypervisor launch failed; Memory ranges validation failure (BalStatus: BalStatus, BalInternalError: BalInternalError, Line: Line, MemoryRangesCount: MemoryRangesCount).

#
Channel
System

Message #

Hypervisor launch failed; Memory ranges validation failure (BalStatus: %1, BalInternalError: %2, Line: %3, MemoryRangesCount: %4).

Fields #

NameDescription
BalStatus HexInt64
BalInternalError UInt32
Line UInt16
MemoryRangesCount UInt32
MemoryRanges Int16

Event ID 80: Hypervisor launch failed; The operating systems boot loader failed with error NtStatus.

#
Channel
System
Opcode
Info

Message #

Hypervisor launch failed; The operating systems boot loader failed with error %1.

Fields #

NameDescription
NtStatus HexInt32

Event ID 81: Hypervisor launch failed; The operating system boot loader was unable to locate a required resource.

#
Channel
System
Opcode
Info

Event ID 82: Hypervisor launch failed; The operating system boot loader detected a persistent memory failure.

#
Channel
System
Opcode
Info

Event ID 83: Hypervisor launch failed; The operating system boot loader was unable to allocate sufficient memory to complete the operation.

#
Channel
System
Opcode
Info

Event ID 84: Hypervisor launch failed; The operating system boot loader was unable to allocate sufficient resources to complete the operation.

#
Channel
System
Opcode
Info

Event ID 85: Hypervisor launch failed; The operating system boot loader detected a memory map conflict.

#
Channel
System
Opcode
Info

Event ID 86: Hypervisor launch failed; the version of the microcode update dll does not match the current operating system.

#
Channel
System
Opcode
Info

Fields #

NameDescription
ExpectedVersion UInt32
ActualVersion UInt32
ExpectedFunctionTableSize UInt32
ActualFunctionTableSize UInt32
UpdateDllName UnicodeString

Event ID 96: Hypervisor processor startup failed (APIC ID CPU, status ErrorCode).

#
Channel
System
Opcode
Info

Description

Hypervisor processor startup failed (APIC ID CPU, status ErrorCode). Further processors in the system were not started.

Message #

Hypervisor processor startup failed (APIC ID %1, status %2). Further processors in the system were not started.

Fields #

NameDescription
CPU HexInt32
ErrorCode HexInt32

Event ID 97: Hypervisor processor startup failed (APIC ID CPU) due to CPUID feature validation error.

#
Channel
System
Opcode
Info

Description

Hypervisor processor startup failed (APIC ID CPU) due to CPUID feature validation error. Further processors in the system were not started. Leaf LeafNumber, register Register feature mismatch: BSP has features APCpuidData; AP has features BSPCpuidData

Message #

Hypervisor processor startup failed (APIC ID %1) due to CPUID feature validation error. Further processors in the system were not started. Leaf %2, register %3 feature mismatch: BSP has features %5; AP has features %4

Fields #

NameDescription
CPU HexInt32
LeafNumber HexInt64
Register HexInt64
BSPCpuidData HexInt64
APCpuidData HexInt64

Event ID 129: Hypervisor initialized I/O remapping.

#
Channel
System
Level
Informational
Opcode
Info

Message #

Hypervisor initialized I/O remapping.

Hardware present: %1
Hardware enabled: %2
Policy: %3
Enabled features: %4
Internal information: %5
Problems: %6
Additional information: %7

Fields #

NameDescription
HardwarePresent Boolean
HardwareEnabled Boolean
Policy HexInt64
EnabledFeatures HexInt64
InternalInfo HexInt64
Problems HexInt64
AdditionalInfo HexInt64

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Hyper-V-Hypervisor",
    "guid": "52FC89F8-995E-434C-A91E-199986449890",
    "event_source_name": "",
    "event_id": 129,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 9223442405598953472,
    "time_created": "2026-03-11T06:27:08.616876+00:00",
    "event_record_id": 2710,
    "correlation": {},
    "execution": {
      "process_id": 4,
      "thread_id": 8
    },
    "channel": "System",
    "computer": "LAB-WIN11",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "HardwarePresent": false,
    "HardwareEnabled": false,
    "Policy": "0x0",
    "EnabledFeatures": "0x0",
    "InternalInfo": "0x0",
    "Problems": "0x0",
    "AdditionalInfo": "0x0"
  },
  "message": ""
}

Event ID 130: Hypervisor I/O remapping is forcibly enabled by policy (the hypervisoriommupolicy BCD option is set to enable).

#
Channel
System
Opcode
Info

Description

Hypervisor I/O remapping is forcibly enabled by policy (the hypervisoriommupolicy BCD option is set to enable). If the system exhibits instability or reduced performance, consider restoring the default policy.

Message #

Hypervisor I/O remapping is forcibly enabled by policy (the hypervisoriommupolicy BCD option is set to enable). If the system exhibits instability or reduced performance, consider restoring the default policy.

Event ID 131: There is an I/O remapping problem with the sytem BIOS.

#
Channel
System
Opcode
Info

Message #

There is an I/O remapping problem with the sytem BIOS.

Problems: %1

Fields #

NameDescription
Problems HexInt64

Event ID 144: A device is operating with reduced performance because of a problem with the system BIOS.

#
Channel
System

Message #

A device is operating with reduced performance because of a problem with the system BIOS.



The device is not reported under the scope of a unique I/O remapping unit.



Device ID: %1

Partition ID: %2

Fields #

NameDescription
DeviceId HexInt64
PartitionId UInt64

Event ID 145: A device will not work correctly because of a problem with the system BIOS.

#
Channel
System

Message #

A device will not work correctly because of a problem with the system BIOS.



The Requester IDs reported for the device overlap with those reported for another device.



Device ID: %1

Partition ID: %2

Fields #

NameDescription
DeviceId HexInt64
PartitionId UInt64

Event ID 146: A device will not work correctly because the hypervisor does not have enough resources.

#
Channel
System

Message #

A device will not work correctly because the hypervisor does not have enough resources.



Device ID: %1

Partition ID: %2

Fields #

NameDescription
DeviceId HexInt64
PartitionId UInt64

Event ID 147: A device will not work correctly because of a problem with the system BIOS.

#
Channel
System

Message #

A device will not work correctly because of a problem with the system BIOS.



An IOAPIC is not correctly reported.



IOAPIC ID: %1

Fields #

NameDescription
IoApicId UInt8

Event ID 148: A device could not be used by a child partition because of a limitation of the system hardware and BIOS.

#
Channel
System

Message #

A device could not be used by a child partition because of a limitation of the system hardware and BIOS.



The I/O remapping unit that controls the device does not have sufficient capabilities.



Device ID: %1

I/O remapping unit base address: %2

Partition ID: %3

Fields #

NameDescription
DeviceId HexInt64
UnitBaseAddress HexInt64
PartitionId UInt64

Event ID 149: A device could not be used by a child partition because of a limitation of the system hardware and BIOS.

#
Channel
System

Message #

A device could not be used by a child partition because of a limitation of the system hardware and BIOS.



The device cannot be securely used by a child partition.



Device ID: %1

Partition ID: %2

Fields #

NameDescription
DeviceId HexInt64
PartitionId UInt64

Event ID 150: The image {ImageName} could not be accessed (status {Status}).

#
Channel
System

Fields #

NameDescription
ImageName
StatusNTSTATUS reference

Event ID 151: The image {ImageName} could not be loaded (status {Status}).

#
Channel
System

Fields #

NameDescription
ImageName
StatusNTSTATUS reference

Event ID 152: The image ImageName could not be read (status Status).

#
Channel
System
Opcode
Info

Message #

The image %1 could not be read (status %2).

Fields #

NameDescription
ImageName UnicodeString
Status HexInt32NTSTATUS reference

Event ID 153: The image ImageName failed code integrity checks, and cannot be used.

#
Channel
System
Opcode
Info

Message #

The image %1 failed code integrity checks, and cannot be used.

Fields #

NameDescription
ImageName UnicodeString

Event ID 154: Hypervisor failed to properly synchronize TSC across logical processors (Max delta: MaxDelta, Min delta: MinDelta).

#
Channel
System
Opcode
Info

Message #

Hypervisor failed to properly synchronize TSC across logical processors (Max delta: %1, Min delta: %2).

Fields #

NameDescription
MaxDelta Int64
MinDelta Int64

Event ID 155: Host processor features mask: BankCount.

#
Channel
Microsoft-Windows-Hyper-V-Hypervisor-Admin
Level
Informational
Opcode
Info

Message #

Host processor features mask: %1

Host xsave features mask: %2

Host cache line flush size: %3 bytes

Fields #

NameDescription
BankCount UInt8
ProcessorFeatures HexInt64
XsaveFeatures HexInt64
CLFlushSize UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Hyper-V-Hypervisor",
    "guid": "52FC89F8-995E-434C-A91E-199986449890",
    "event_source_name": "",
    "event_id": 155,
    "version": 1,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 4611686018427387904,
    "time_created": "2026-03-11T06:27:24.431418+00:00",
    "event_record_id": 2,
    "correlation": {},
    "execution": {
      "process_id": 4,
      "thread_id": 364
    },
    "channel": "Microsoft-Windows-Hyper-V-Hypervisor-Admin",
    "computer": "LAB-WIN11",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "BankCount": 2,
    "ProcessorFeatures": "0x800040",
    "XsaveFeatures": "0x1f",
    "CLFlushSize": 64
  },
  "message": ""
}

Event ID 156: Hypervisor initial page allocation NUMA policy: .

#
Channel
Microsoft-Windows-Hyper-V-Hypervisor-Admin
Level
Informational
Opcode
Info

Description

Hypervisor configured mitigations for CVE-2018-3646 for virtual machines.

Message #

Hypervisor initial page allocation NUMA policy: %1

Fields #

NameDescription
InitialAllocationNumaPolicy UInt32Hypervisor initial page allocation NUMA policy.

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Hyper-V-Hypervisor",
    "guid": "52FC89F8-995E-434C-A91E-199986449890",
    "event_source_name": "",
    "event_id": 156,
    "version": 1,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 4611686018427387904,
    "time_created": "2023-11-06T06:24:56.253950+00:00",
    "event_record_id": 6,
    "correlation": {
      "ActivityID": "A94F03D9-96B8-C53E-D5D7-00FBA9067B3F"
    },
    "execution": {
      "process_id": 4,
      "thread_id": 8
    },
    "channel": "Microsoft-Windows-Hyper-V-Hypervisor-Admin",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "InitialAllocationNumaPolicy": 0
  },
  "message": ""
}

Event ID 156: Hypervisor configured mitigations for CVE-2018-3646 for virtual machines.

#
Channel
System
Level
Informational
Opcode
Info

Message #

Hypervisor configured mitigations for CVE-2018-3646 for virtual machines.

Processor not affected: %1
Processor family not affected: %2
Processor supports cache flush: %3
HyperThreading enabled: %4
Parent hypervisor applies mitigations: %5
Mitigations disabled by bcdedit: %6
Mitigations enabled: %7
Cache flush needed: %8

Fields #

NameDescription
InitialAllocationNumaPolicy UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Hyper-V-Hypervisor",
    "guid": "{52FC89F8-995E-434C-A91E-199986449890}",
    "event_source_name": "",
    "event_id": 156,
    "version": 1,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 4611686018427387904,
    "time_created": "2026-06-13T13:53:35.1686229+00:00",
    "event_record_id": 21,
    "correlation": {
      "ActivityID": "{1852914D-A1EE-1312-1B27-5880A2868F7E}"
    },
    "execution": {
      "process_id": 4,
      "thread_id": 8
    },
    "channel": "Microsoft-Windows-Hyper-V-Hypervisor-Admin",
    "computer": "telemetry-W11-d.cell-d.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "InitialAllocationNumaPolicy": "2"
  },
  "message": "Hypervisor initial page allocation NUMA policy: Proportional NUMA distribution"
}

Event ID 157: The hypervisor did not enable mitigations for side channel vulnerabilities for virtual machines because HyperThreading is enabled and the hyperviso...

#
Channel
System
Opcode
Info

Description

The hypervisor did not enable mitigations for CVE-2018-3646, CVE-2019-11091, CVE-2018-12126, CVE-2018-12127, and CVE-2018-12130 for virtual machines because HyperThreading is enabled and the hypervisor core scheduler is not enabled. To enable mitigations for virtual machines, enable the core scheduler by running "bcdedit /set hypervisorschedulertype core" from an elevated command prompt and reboot.

Message #

The hypervisor did not enable mitigations for side channel vulnerabilities for virtual machines because HyperThreading is enabled and the hypervisor core scheduler is not enabled. To enable mitigations for virtual machines, enable the core scheduler by running "bcdedit /set hypervisorschedulertype core" from an elevated command prompt and reboot.

Event ID 158: The queried interface version Max is not supported (Min : CurrentVersion, Max : MinVersion).

#
Channel
System
Opcode
Info

Message #

The queried interface version %1 is not supported (Min : %2, Max : %3).

Fields #

NameDescription
CurrentVersion UInt8
MinVersion UInt8
MaxVersion UInt8

Event ID 159: The queried interface is incomplete.

#
Channel
System
Opcode
Info

Event ID 160: Partition persistence services will be unavailable.

#
Channel
System
Opcode
Info

Event ID 161: The configured Minroot settings are not compatible with the hypervisor core scheduler and have been overriden.

#
Channel
System
Opcode
Info

Description

The configured Minroot settings are not compatible with the hypervisor core scheduler and have been overriden. This may expose a different number of logical processors to the root partition.

Message #

The configured Minroot settings are not compatible with the hypervisor core scheduler and have been overriden. This may expose a different number of logical processors to the root partition.

Event ID 162: Failed to unregister the remote hypercall interface (status NtStatus).

#
Channel
System
Opcode
Info

Message #

Failed to unregister the remote hypercall interface (status %1).

Fields #

NameDescription
NtStatus HexInt32

Event ID 163: The hypervisor encountered an internal error: nested NMI (processor Processor).

#
Channel
Microsoft-Windows-Hyper-V-Hypervisor-Operational

Message #

The hypervisor encountered an internal error: nested NMI (processor %1).

Fields #

NameDescription
Processor UInt32

Event ID 164: The hypervisor encountered an internal error: IPI timeout (processor Processor).

#
Channel
Microsoft-Windows-Hyper-V-Hypervisor-Operational

Message #

The hypervisor encountered an internal error: IPI timeout (processor %1).

Fields #

NameDescription
Processor UInt32

Event ID 165: Hypervisor configured mitigations for CVE-2019-11091, CVE-2018-12126, CVE-2018-12127, CVE-2018-12130 for virtual machines.

#
Channel
System
Level
Informational
Opcode
Info

Message #

Hypervisor configured mitigations for CVE-2019-11091, CVE-2018-12126, CVE-2018-12127, CVE-2018-12130 for virtual machines.

Processor not affected: %1
Processor family not affected: %2
Processor supports microarchitectural buffer flush: %3
Buffer flush needed: %4

Fields #

NameDescription
NotAffectedMdsNo Boolean
NotAffectedAtom Boolean
MdClearSupported Boolean
BufferFlushNeeded Boolean

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Hyper-V-Hypervisor",
    "guid": "52FC89F8-995E-434C-A91E-199986449890",
    "event_source_name": "",
    "event_id": 165,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 9223442405598953472,
    "time_created": "2026-03-11T06:27:08.616931+00:00",
    "event_record_id": 2712,
    "correlation": {},
    "execution": {
      "process_id": 4,
      "thread_id": 8
    },
    "channel": "System",
    "computer": "LAB-WIN11",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "NotAffectedMdsNo": false,
    "NotAffectedAtom": false,
    "MdClearSupported": true,
    "BufferFlushNeeded": true
  },
  "message": ""
}

Event ID 166: Hypervisor Load Options are conflicting - LoadOptions, LoadFlags.

#
Channel
Microsoft-Windows-Hyper-V-Hypervisor-Admin
Opcode
Info

Message #

Hypervisor Load Options are conflicting - %1, %2.

Fields #

NameDescription
LoadOptions AnsiString
LoadFlags HexInt64

Event ID 167: The hypervisor did not enable mitigations for side channel vulnerabilities for virtual machines because HyperThreading is enabled.

#
Channel
System
Opcode
Info

Description

The hypervisor did not enable mitigations for side channel vulnerabilities for virtual machines because HyperThreading is enabled. To enable mitigations for virtual machines, disable HyperThreading.

Message #

The hypervisor did not enable mitigations for side channel vulnerabilities for virtual machines because HyperThreading is enabled. To enable mitigations for virtual machines, disable HyperThreading.

Event ID 168: AMD PSP PCI device discovered.

#
Channel
System
Opcode
Info

Description

AMD PSP PCI device discovered. Segment: AMD_PSP_PCI_device_discovered_Segment, bus: bus, device: device, function: function.

Message #

AMD PSP PCI device discovered. Segment: %1, bus: %2, device: %3, function: %4.

Fields #

NameDescription
Segment UInt16
Bus UInt8
Device UInt8
Function UInt8

Event ID 169: Secure firmware update status: Secure_firmware_update_status.

#
Channel
System
Opcode
Info

Message #

Secure firmware update status: %1.

Fields #

NameDescription
Status UInt32NTSTATUS reference

Event ID 170: Secure firmware image invalid.

#
Channel
System
Opcode
Info

Event ID 171: Secure firmware version: Secure_firmware_version.

#
Channel
System
Opcode
Info

Message #

Secure firmware version: %1.

Fields #

NameDescription
Version UInt64

Event ID 172: Features are enabled that require all processors be started.

#
Channel
Microsoft-Windows-Hyper-V-Hypervisor-Admin
Opcode
Info

Description

Features are enabled that require all processors be started. RunningProcessors of AvailableProcessors processors currently running.

Message #

Features are enabled that require all processors be started. %1 of %2 processors currently running.

Fields #

NameDescription
RunningProcessors UInt32
AvailableProcessors UInt32

Event ID 173: On the prior boot session, the root partition did not respond to the synthetic watchdog in time, triggering a hardware watchdog reboot.

#
Channel
System
Opcode
Info

Event ID 8451: Hyper-V failed creating a new partition (status Error)!

#
Channel
Microsoft-Windows-Hyper-V-Hypervisor-Operational
Opcode
Info

Message #

Hyper-V failed creating a new partition (status %1)!

Fields #

NameDescription
Error HexInt64

Event ID 12288: RegisterInterface

#
Channel
Operational
Task
RegisterInterface

Fields #

NameDescription
FailurePhase UInt32
NtStatus UInt32

Event ID 12289: HvldrIoctl

#
Channel
Operational
Task
HvldrIoctl

Fields #

NameDescription
AuxData UInt64
NtStatus UInt32

Event ID 12290: RemoteHypercall

#
Channel
Operational
Task
RemoteHypercall

Fields #

NameDescription
AuxData UInt64
NtStatus UInt32

Event ID 12291: HvldrCreatePartition

#
Channel
Operational
Task
HvldrCreatePartition

Fields #

NameDescription
PartitionId UInt64
NtStatus UInt32
AuxiliaryData UInt64

Event ID 12292: RegisterPartitionId

#
Channel
Operational
Task
RegisterPartitionId

Fields #

NameDescription
PartitionId UInt64
NtStatus UInt32
AuxiliaryData UInt64

Event ID 12293: HvldrDeletePartition

#
Channel
Operational
Task
HvldrDeletePartition

Fields #

NameDescription
PartitionId UInt64
NtStatus UInt32
AuxiliaryData UInt64

Event ID 12294: HvldrDepositMemory

#
Channel
Operational
Task
HvldrDepositMemory

Fields #

NameDescription
PartitionId UInt64
NtStatus UInt32
AuxiliaryData UInt64

Event ID 12295: HvldrMapGpaPages

#
Channel
Operational
Task
HvldrMapGpaPages

Fields #

NameDescription
PartitionId UInt64
NtStatus UInt32
AuxiliaryData UInt64

Event ID 12296: HvldrUnmapGpaSpace

#
Channel
Operational
Task
HvldrUnmapGpaSpace

Fields #

NameDescription
PartitionId UInt64
NtStatus UInt32
AuxiliaryData UInt64

Event ID 12297: HvldrNumaDistributedAllocation

#
Channel
Operational
Task
HvldrNumaDistributedAllocation

Fields #

NameDescription
TotalSystemPages HexInt64
TotalPagesRequested HexInt32
Policy UInt32
ProximityDomainCount UInt32
AllocationPass UInt32
ProximityDomainIndex UInt32
ProximityDomainId HexInt32
TotalDomainPages HexInt64
PagesRequested HexInt32
BalStatus HexInt64
PagesAllocated HexInt32

Event ID 12298: HvldrGetLpRegisterMsr

#
Channel
Operational
Task
HvldrGetLpRegisterMsr

Fields #

NameDescription
AuxData UInt64
NtStatus UInt32

Event ID 12299: HvldrGetLpRegisterCpuid

#
Channel
Operational
Task
HvldrGetLpRegisterCpuid

Fields #

NameDescription
AuxData UInt64
NtStatus UInt32

Event ID 12300: HvldrReadSystemMemory

#
Channel
Operational
Task
HvldrReadSystemMemory

Fields #

NameDescription
AuxData UInt64
NtStatus UInt32

Event ID 12301: HvldrGetMtrrs

#
Channel
Operational
Task
HvldrGetMtrrs

Fields #

NameDescription
AuxData UInt64
NtStatus UInt32

Event ID 12302: HvldrGetPlatformCaps

#
Channel
Operational
Task
HvldrGetPlatformCaps

Fields #

NameDescription
BalStatus HexInt64

Event ID 12303: HvldrHsrInUse

#
Channel
Operational
Task
HvldrHsrInUse

Fields #

NameDescription
HsrInUse Boolean
Reason UInt32

Event ID 12304: HvldrConfigureIommuLiveHandoff

#
Channel
Operational
Task
HvldrConfigureIommuLiveHandoff

Fields #

NameDescription
AuxData UInt64
NtStatus UInt32

Event ID 12305: HvldrGetIdleStateConfig

#
Channel
Operational
Task
HvldrGetIdleStateConfig

Fields #

NameDescription
AuxData UInt64
NtStatus UInt32

Event ID 12306: HvldrGetVpRegisters

#
Channel
Operational
Task
HvldrGetVpRegisters

Fields #

NameDescription
AuxData UInt64
NtStatus UInt32

Event ID 12307: HvldrGetLogicalProcessorProperty

#
Channel
Operational
Task
HvldrGetLogicalProcessorProperty

Fields #

NameDescription
AuxData UInt64
NtStatus UInt32

Event ID 12308: HvldrDisableHypervisor

#
Channel
Operational
Task
HvldrDisableHypervisor

Fields #

NameDescription
AuxData UInt64
NtStatus UInt32

Event ID 12309: HvldrDisableHypervisor12309

#
Channel
Operational
Task
HvldrDisableHypervisor

Fields #

NameDescription
AuxData UInt64
NtStatus UInt32

Event ID 12310: HvldrPrepareProtoHypervisor

#
Channel
Operational
Task
HvldrPrepareProtoHypervisor

Fields #

NameDescription
AuxData UInt64
NtStatus UInt32

Event ID 12311: HvldrImageLoadInfo

#
Channel
Operational
Task
HvldrImageLoadInfo

Fields #

NameDescription
ImageName UnicodeString
Checksum UInt32
Timestamp UInt32
NtStatus UInt32

Event ID 12312: HvldrReadHvRegister

#
Channel
Operational
Task
HvldrReadHvRegister

Fields #

NameDescription
AuxData UInt64
NtStatus UInt32

Event ID 12313: HvldrProcessInterruptControllers

#
Channel
Operational
Task
HvldrProcessInterruptControllers

Fields #

NameDescription
AuxData UInt64
NtStatus UInt32

Event ID 12314: HvldrHsrMirroringInUse

#
Channel
Operational
Task
HvldrHsrMirroringInUse

Fields #

NameDescription
HsrInUse Boolean
Reason UInt32

Event ID 12315: HvldrDebugMsg

#
Channel
Operational
Task
HvldrDebugMsg

Fields #

NameDescription
LoadOptions AnsiString

Event ID 12316: HvldrDebugMsg12316

#
Channel
Operational
Task
HvldrDebugMsg

Fields #

NameDescription
LoadOptions AnsiString

Event ID 12317: HvldrFailureLocation

#
Channel
Operational
Task
HvldrFailureLocation

Fields #

NameDescription
BaseLocation AnsiString
Line UInt32
BalStatus HexInt64
AuxData UInt64

Event ID 12550: Hyper-V detected access to a restricted MSR.

#
Channel
Microsoft-Windows-Hyper-V-Hypervisor-Operational
Opcode
Info

Description

Hyper-V detected access to a restricted MSR (Msr: Msr, IsWrite: IsWrite, MsrValue: MsrValue, AccessStatus: AccessStatus, Pc: Pc, ImageBase: ImageBase, ImageChecksum: ImageChecksum, ImageTimestamp: ImageTimestamp, ImageName: ImageName).

Message #

Hyper-V detected access to a restricted MSR (Msr: %1, IsWrite: %2, MsrValue: %3, AccessStatus: %4, Pc: %5, ImageBase: %6, ImageChecksum: %7, ImageTimestamp: %8, ImageName: %9).

Fields #

NameDescription
Msr HexInt32
IsWrite UInt8
MsrValue HexInt64
AccessStatus UInt16
Pc HexInt64
ImageBase HexInt64
ImageChecksum HexInt32
ImageTimestamp HexInt32
ImageName AnsiString

Event ID 16641: Hyper-V successfully created a new partition (partition PartitionId).

#
Channel
Microsoft-Windows-Hyper-V-Hypervisor-Operational
Level
Informational
Opcode
Info

Message #

Hyper-V successfully created a new partition (partition %1).

Fields #

NameDescription
PartitionId UInt64

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Hyper-V-Hypervisor",
    "guid": "52FC89F8-995E-434C-A91E-199986449890",
    "event_source_name": "",
    "event_id": 16641,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 2305843009213693952,
    "time_created": "2026-03-11T06:32:05.545260+00:00",
    "event_record_id": 1,
    "correlation": {},
    "execution": {
      "process_id": 4,
      "thread_id": 2472
    },
    "channel": "Microsoft-Windows-Hyper-V-Hypervisor-Operational",
    "computer": "LAB-WIN11",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "PartitionId": 2
  },
  "message": ""
}

Event ID 16642: Hyper-V successfully deleted a partition (partition PartitionId).

#
Channel
Microsoft-Windows-Hyper-V-Hypervisor-Operational
Level
Informational
Opcode
Info

Message #

Hyper-V successfully deleted a partition (partition %1).

Fields #

NameDescription
PartitionId UInt64

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Hyper-V-Hypervisor",
    "guid": "52FC89F8-995E-434C-A91E-199986449890",
    "event_source_name": "",
    "event_id": 16642,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 2305843009213693952,
    "time_created": "2026-03-13T20:09:16.550106+00:00",
    "event_record_id": 2,
    "correlation": {},
    "execution": {
      "process_id": 4,
      "thread_id": 424
    },
    "channel": "Microsoft-Windows-Hyper-V-Hypervisor-Operational",
    "computer": "LAB-WIN11.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "PartitionId": 2
  },
  "message": ""
}

Provenance

ETW provider GUID 52fc89f8-995e-434c-a91e-199986449890

Defined in hvservice.sys, the binary that emits these events.

  • WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.1, captured 2026-06-02 — Manifest XML pack, 1.9 MB
  • Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.1, captured 2026-06-02 — Manifest XML pack, 2.0 MB