Microsoft-Windows-Hyper-V-KMCL
| Event | Title | Channel | Sample | Rule |
|---|---|---|---|---|
| 1 | Fetching a packet from vmbus | Analytic, Operational | N | N |
| 2 | Sending a packet to vmbus | Analytic, Operational | N | N |
| 3 | Finish fetching packets from vmbus | Analytic, Operational | N | N |
| 4 | Incoming packet quota is hit | Analytic, Operational | N | N |
| 5 | DPC cycle limit is hit | Analytic, Operational | N | N |
Event ID 1: Fetching a packet from vmbus
#Fields #
| Name | Description |
|---|---|
VmId GUID | |
InstanceId GUID | |
TransactionId UInt64 | |
IsCompletionPacket Boolean | |
Channel UInt16 |
Event ID 2: Sending a packet to vmbus
#Fields #
| Name | Description |
|---|---|
VmId GUID | |
InstanceId GUID | |
TransactionId UInt64 | |
IsCompletionPacket Boolean | |
Channel UInt16 |
Event ID 3: Finish fetching packets from vmbus
#Fields #
| Name | Description |
|---|---|
VmId GUID | |
InstanceId GUID | |
PacketFetched UInt32 | |
MaximumFetchAllowed UInt32 | |
Channel UInt16 |
Provenance
ETW provider GUID fa3f78ff-ba6d-4ede-96b2-9c5bb803e3ba
Defined in vmbkmclr.sys, the binary that emits these events.
- Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.5074, captured 2026-06-02 — Manifest XML pack, 2.0 MB