Microsoft-Windows-Hyper-V-Shared-VHDX
55 events across 3 channels
Event ID 16: Shared VHDX filter started.
#Description
Shared VHDX filter started.
Message #
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Hyper-V-Shared-VHDX",
"guid": "{BB510E5F-2EB9-491A-81E4-F04654388F2B}",
"event_source_name": "",
"event_id": 16,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": -9223372036854775808,
"time_created": "2026-05-30T02:30:35.6310874+00:00",
"event_record_id": 1,
"correlation": {},
"execution": {
"process_id": 4,
"thread_id": 720
},
"channel": "Microsoft-Windows-Hyper-V-Shared-VHDX/Operational",
"computer": "JD-DC01-2022.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {},
"message": "Shared VHDX filter started."
}
Event ID 48: Successfully attached to volume.
#Event ID 64: Skipped attaching to non-CSV volume.
#Description
Skipped attaching to non-CSV volume. Volume: VolumeName.
Message #
Fields #
| Name | Description |
|---|---|
VolumeNameLength UInt16 | |
VolumeName UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Hyper-V-Shared-VHDX",
"guid": "{BB510E5F-2EB9-491A-81E4-F04654388F2B}",
"event_source_name": "",
"event_id": 64,
"version": 0,
"level": 5,
"task": 0,
"opcode": 0,
"keywords": -9223372036854775808,
"time_created": "2026-06-13T05:12:17.3512172+00:00",
"event_record_id": 1,
"correlation": {},
"execution": {
"process_id": 7116,
"thread_id": 4676
},
"channel": "Microsoft-Windows-Hyper-V-Shared-VHDX/Operational",
"computer": "telemetry-DC-c.cell-c.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"VolumeNameLength": "33",
"VolumeName": "\\Device\\HarddiskVolumeShadowCopy2"
},
"message": "Skipped attaching to non-CSV volume. Volume: \\Device\\HarddiskVolumeShadowCopy2."
}
Event ID 80: Error attaching to volume.
#Description
Error attaching to volume. Volume: VolumeName. Error: Status.
Message #
Fields #
| Name | Description |
|---|---|
VolumeNameLength UInt16 | |
VolumeName UnicodeString | |
Status HexInt32 | NTSTATUS reference |
Event ID 96: Successfully detached from volume.
#Event ID 112: Error detaching from volume.
#Description
Error detaching from volume. Volume: VolumeName. Error: Status.
Message #
Fields #
| Name | Description |
|---|---|
VolumeNameLength UInt16 | |
VolumeName UnicodeString | |
Status HexInt32 | NTSTATUS reference |
Event ID 128: Error opening handle for initiator.
#Description
Error opening handle for initiator. Initiator: Initiator. Hostname: HostName. File: FileName. Error: Status.
Message #
Fields #
| Name | Description |
|---|---|
Initiator GUID | |
HostNameLength UInt16 | |
HostName UnicodeString | |
FileNameLength UInt16 | |
FileName UnicodeString | |
Status HexInt32 | NTSTATUS reference |
Event ID 129: A deduplicated file was detected for a Shared VHDX.
#Event ID 130: A reparse point was detected for a Shared VHDX file.
#Event ID 144: Error while mounting Shared VHDX file.
#Description
Error while mounting Shared VHDX file. File: FileName. Error: Status.
Message #
Fields #
| Name | Description |
|---|---|
FileNameLength UInt16 | |
FileName UnicodeString | |
Status HexInt32 | NTSTATUS reference |
Event ID 256: Shared VHDX file IO Failure.
#Description
Shared VHDX file IO Failure. File: FileName. SCSI operation: ScsiOperation. SRB status: SrbStatus. SCSI status: ScsiStatus. Sense error code: SenseErrorCode. Sense key: SenseKey. Additional sense code: AdditionalSenseCode. Qualifier: AdditionalSenseCodeQualifier. Error: RequestStatus.
Message #
Fields #
| Name | Description |
|---|---|
FileNameLength UInt16 | |
FileName UnicodeString | |
ScsiOperation UInt8 | |
SrbStatus UInt8 | |
ScsiStatus UInt8 | |
SenseErrorCode UInt8 | |
SenseKey UInt8 | |
AdditionalSenseCode UInt8 | |
AdditionalSenseCodeQualifier UInt8 | |
RequestStatus HexInt32 |
Event ID 256
#Description
Shared VHDX file IO Failure. File: . SCSI operation: . SRB status: . SCSI status: . Sense error code: . Sense key: . Additional sense code: . Qualifier: . Error: .
Fields #
| Name | Description |
|---|---|
FileNameLength UInt16 | |
FileName UnicodeString | |
ScsiOperation UInt8 | |
SrbStatus UInt8 | |
ScsiStatus UInt8 | |
SenseErrorCode UInt8 | |
SenseKey UInt8 | |
AdditionalSenseCode UInt8 | |
AdditionalSenseCodeQualifier UInt8 | |
RequestStatus HexInt32 |
Event ID 272: Shared VHDX file IO took longer than TimeoutInMs ms.
#Event ID 304: Error reading metadata from the Shared VHDX file.
#Message #
Fields #
| Name | Description |
|---|---|
FileNameLength UInt16 | |
FileName UnicodeString | |
Status HexInt32 | NTSTATUS reference |
Event ID 305: No metadata found on the Shared VHDX file.
#Message #
Fields #
| Name | Description |
|---|---|
FileNameLength UInt16 | |
FileName UnicodeString | |
Status HexInt32 | NTSTATUS reference |
Event ID 305
#Fields #
| Name | Description |
|---|---|
FileNameLength UInt16 | |
FileName UnicodeString | |
Status HexInt32 | NTSTATUS reference |
Event ID 320: Error writing metadata to Shared VHDX file.
#Description
Error writing metadata to Shared VHDX file. File: FileName. Error: Status.
Message #
Fields #
| Name | Description |
|---|---|
FileNameLength UInt16 | |
FileName UnicodeString | |
Status HexInt32 | NTSTATUS reference |
Event ID 8208
#Description
Persistent Reservation: REGISTER. File: . Initiator . Hostname: .
Fields #
| Name | Description |
|---|---|
FileNameLength UInt16 | |
FileName UnicodeString | |
Initiator GUID | |
HostNameLength UInt16 | |
HostName UnicodeString |
Event ID 8208: Persistent Reservation: REGISTER.
#Event ID 8224
#Description
Persistent Reservation: REGISTER AND IGNORE EXISTING KEY. File: . Initiator . Hostname: .
Fields #
| Name | Description |
|---|---|
FileNameLength UInt16 | |
FileName UnicodeString | |
Initiator GUID | |
HostNameLength UInt16 | |
HostName UnicodeString |
Event ID 8224: Persistent Reservation: REGISTER AND IGNORE EXISTING KEY.
#Event ID 8240
#Description
Persistent Reservation: RESERVE. File: . Initiator . Hostname: .
Fields #
| Name | Description |
|---|---|
FileNameLength UInt16 | |
FileName UnicodeString | |
Initiator GUID | |
HostNameLength UInt16 | |
HostName UnicodeString |
Event ID 8240: Persistent Reservation: RESERVE.
#Event ID 8256
#Description
Persistent Reservation: RELEASE. File: . Initiator . Hostname: .
Fields #
| Name | Description |
|---|---|
FileNameLength UInt16 | |
FileName UnicodeString | |
Initiator GUID | |
HostNameLength UInt16 | |
HostName UnicodeString |
Event ID 8256: Persistent Reservation: RELEASE.
#Event ID 8272
#Description
Persistent Reservation: CLEAR. File: . Initiator . Hostname: .
Fields #
| Name | Description |
|---|---|
FileNameLength UInt16 | |
FileName UnicodeString | |
Initiator GUID | |
HostNameLength UInt16 | |
HostName UnicodeString |
Event ID 8272: Persistent Reservation: CLEAR.
#Event ID 8288
#Description
Persistent Reservation: PREEMPT. File: . Initiator . Hostname: .
Fields #
| Name | Description |
|---|---|
FileNameLength UInt16 | |
FileName UnicodeString | |
Initiator GUID | |
HostNameLength UInt16 | |
HostName UnicodeString |
Event ID 8288: Persistent Reservation: PREEMPT.
#Event ID 8304
#Description
Persistent Reservation: PREEMPT AND ABORT. File: . Initiator . Hostname: .
Fields #
| Name | Description |
|---|---|
FileNameLength UInt16 | |
FileName UnicodeString | |
Initiator GUID | |
HostNameLength UInt16 | |
HostName UnicodeString |
Event ID 8304: Persistent Reservation: PREEMPT AND ABORT.
#Event ID 8320
#Description
Persistent Reservation: Opening state. File: . Holder: . Key: . Scope: . Type: . Generation: .
Fields #
| Name | Description |
|---|---|
FileNameLength UInt16 | |
FileName UnicodeString | |
Holder GUID | |
Key UInt64 | |
Scope UInt8 | |
Type UInt8 | |
Generation UInt32 |
Event ID 8320: Persistent Reservation: Opening state.
#Event ID 8336
#Description
Persistent Reservation: Opening state. File: . Initiator: . Registration key: .
Fields #
| Name | Description |
|---|---|
FileNameLength UInt16 | |
FileName UnicodeString | |
Initiator GUID | |
RegistrationKey UInt64 |
Event ID 8336: Persistent Reservation: Opening state.
#Event ID 16400: Handle opened by initiator.
#Event ID 16400
#Description
Handle opened by initiator. File: . Initiator . Hostname: .
Fields #
| Name | Description |
|---|---|
FileNameLength UInt16 | |
FileName UnicodeString | |
Initiator GUID | |
HostNameLength UInt16 | |
HostName UnicodeString |
Event ID 16416: Handle closed by initiator.
#Event ID 16416
#Description
Handle closed by initiator. File: . Initiator . Hostname: .
Fields #
| Name | Description |
|---|---|
FileNameLength UInt16 | |
FileName UnicodeString | |
Initiator GUID | |
HostNameLength UInt16 | |
HostName UnicodeString |
Event ID 16432: Shared VHDX file was mounted.
#Event ID 16432
#Description
Shared VHDX file was mounted. File: . Mount time: ms. Total Size: . Log Size: .
Fields #
| Name | Description |
|---|---|
FileNameLength UInt16 | |
FileName UnicodeString | |
TimeInMs UInt32 | |
TotalSize UInt64 | |
LogSize UInt64 |
Event ID 16448: Shared VHDX file was dismounted.
#Event ID 16448
#Description
Shared VHDX file was dismounted. File: .
Fields #
| Name | Description |
|---|---|
FileNameLength UInt16 | |
FileName UnicodeString |
Event ID 16464: IO was completed.
#Event ID 16464
#Description
IO was completed. File: . SCSI operation: . Operation time: ms.
Fields #
| Name | Description |
|---|---|
FileNameLength UInt16 | |
FileName UnicodeString | |
ScsiOperation UInt8 | |
TimeInMs UInt32 |
Event ID 16480: Persistent Reservation start.
#Event ID 16480
#Description
Persistent Reservation start. PR: . File: . Initiator . Hostname: .
Fields #
| Name | Description |
|---|---|
PrOperation UInt32 | |
FileNameLength UInt16 | |
FileName UnicodeString | |
Initiator GUID | |
HostNameLength UInt16 | |
HostName UnicodeString |
Event ID 16496: Persistent Reservation end.
#Description
Persistent Reservation end. PR: . File: . Initiator . Hostname: . SRB status: . SCSI status: . Sense error code: . Sense key: . Additional sense code: . Qualifier: . Error: .
Message #
Fields #
| Name | Description |
|---|---|
PrOperation UInt32 | |
FileNameLength UInt16 | |
FileName UnicodeString | |
Initiator GUID | |
HostNameLength UInt16 | |
HostName UnicodeString | |
SrbStatus UInt8 | |
ScsiStatus UInt8 | |
SenseErrorCode UInt8 | |
SenseKey UInt8 | |
AdditionalSenseCode UInt8 | |
AdditionalSenseCodeQualifier UInt8 | |
RequestStatus HexInt32 |
Event ID 16496
#Description
Persistent Reservation end. PR: . File: . Initiator . Hostname: . SRB status: . SCSI status: . Sense error code: . Sense key: . Additional sense code: . Qualifier: . Error: .
Fields #
| Name | Description |
|---|---|
PrOperation UInt32 | |
FileNameLength UInt16 | |
FileName UnicodeString | |
Initiator GUID | |
HostNameLength UInt16 | |
HostName UnicodeString | |
SrbStatus UInt8 | |
ScsiStatus UInt8 | |
SenseErrorCode UInt8 | |
SenseKey UInt8 | |
AdditionalSenseCode UInt8 | |
AdditionalSenseCodeQualifier UInt8 | |
RequestStatus HexInt32 |
Event ID 16512: Persistent Reservation commit start.
#Event ID 16512
#Description
Persistent Reservation commit start. PR . File: . Initiator . Hostname: .
Fields #
| Name | Description |
|---|---|
PrOperation UInt32 | |
FileNameLength UInt16 | |
FileName UnicodeString | |
Initiator GUID | |
HostNameLength UInt16 | |
HostName UnicodeString |
Event ID 16528: Persistent Reservation commit end.
#Description
Persistent Reservation commit end. PR: PrOperation. File: FileName. Initiator Initiator. Hostname: HostName. Status: Status.
Message #
Fields #
| Name | Description |
|---|---|
PrOperation UInt32 | |
FileNameLength UInt16 | |
FileName UnicodeString | |
Initiator GUID | |
HostNameLength UInt16 | |
HostName UnicodeString | |
Status HexInt32 | NTSTATUS reference |
Event ID 16528
#Description
Persistent Reservation commit end. PR: . File: . Initiator . Hostname: . Status: .
Fields #
| Name | Description |
|---|---|
PrOperation UInt32 | |
FileNameLength UInt16 | |
FileName UnicodeString | |
Initiator GUID | |
HostNameLength UInt16 | |
HostName UnicodeString | |
Status HexInt32 | NTSTATUS reference |
Provenance
Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.
ETW provider GUID bb510e5f-2eb9-491a-81e4-f04654388f2b
Defined in svhdxflt.sys, the binary that emits these events.
Observed on:
- WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.1, captured 2026-06-02