Microsoft-Windows-Hyper-V-KMCL
10 events across 2 channels
| Event | Title | Channel | Sample |
|---|---|---|---|
| 1 | Fetching a packet from vmbus. | Analytic | N |
| 1 | Fetching a packet from vmbus | Operational | N |
| 2 | Sending a packet to vmbus. | Analytic | N |
| 2 | Sending a packet to vmbus | Operational | N |
| 3 | Finish fetching packets from vmbus. | Analytic | N |
| 3 | Finish fetching packets from vmbus | Operational | N |
| 4 | Incoming packet quota is hit. | Analytic | N |
| 4 | Incoming packet quota is hit | Operational | N |
| 5 | DPC cycle limit is hit. | Analytic | N |
| 5 | DPC cycle limit is hit | Operational | N |
Event ID 1: Fetching a packet from vmbus.
#Event ID 1: Fetching a packet from vmbus
#Description
Fetching a packet from vmbus.
Fields #
| Name | Description |
|---|---|
VmId GUID | |
InstanceId GUID | |
TransactionId UInt64 | |
IsCompletionPacket Boolean | |
Channel UInt16 |
Event ID 2: Sending a packet to vmbus.
#Event ID 2: Sending a packet to vmbus
#Description
Sending a packet to vmbus.
Fields #
| Name | Description |
|---|---|
VmId GUID | |
InstanceId GUID | |
TransactionId UInt64 | |
IsCompletionPacket Boolean | |
Channel UInt16 |
Event ID 3: Finish fetching packets from vmbus.
#Event ID 3: Finish fetching packets from vmbus
#Description
Finish fetching packets from vmbus.
Fields #
| Name | Description |
|---|---|
VmId GUID | |
InstanceId GUID | |
PacketFetched UInt32 | |
MaximumFetchAllowed UInt32 | |
Channel UInt16 |
Event ID 4: Incoming packet quota is hit.
#Event ID 4: Incoming packet quota is hit
#Description
Incoming packet quota is hit.
Fields #
| Name | Description |
|---|---|
VmId GUID | |
InstanceId GUID | |
Channel UInt16 |
Event ID 5: DPC cycle limit is hit.
#Event ID 5: DPC cycle limit is hit
#Description
DPC cycle limit is hit.
Fields #
| Name | Description |
|---|---|
VmId GUID | |
InstanceId GUID | |
Channel UInt16 |
Provenance
Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.
ETW provider GUID fa3f78ff-ba6d-4ede-96b2-9c5bb803e3ba
Defined in vmbkmclr.sys, the binary that emits these events.
Observed on:
- Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.5074, captured 2026-06-02