Microsoft-Windows-Hyper-V-VfpExt

EventTitleChannelSampleRule
1VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) Type …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
1Event ID 1OperationalNN
2VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
2Event ID 2OperationalNN
51VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) dropped …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
51Event ID 51OperationalNN
52VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) dropped …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
52Event ID 52OperationalNN
53VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) dropped …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
53Event ID 53OperationalNN
54VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) dropped …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
54Event ID 54OperationalNN
55VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) dropped …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
55Event ID 55OperationalNN
56VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) dropped …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
56Event ID 56OperationalNN
57VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) dropped …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
57Event ID 57OperationalNN
100VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
100Event ID 100OperationalNN
101RuleTyperule with ID RuleId processed Directionpackets on port PortId (Name = …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
101Event ID 101OperationalNN
102RuleTyperule with ID RuleId processed Directionpackets on port PortId (Name = …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
102Event ID 102OperationalNN
103RuleTyperule with ID RuleId processed Directionpackets on port PortId (Name = …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
103Event ID 103OperationalNN
104RuleTyperule with ID RuleId processed Directionpackets on port PortId (Name = …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
104Event ID 104OperationalNN
105RuleTyperule with ID RuleId processed Directionpackets on port PortId (Name = …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
105Event ID 105OperationalNN
106VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) matched …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
106Event ID 106OperationalNN
107VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) matched …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
107Event ID 107OperationalNN
108VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) matched …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
108Event ID 108OperationalNN
109VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) matched …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
109Event ID 109OperationalNN
110VfpExt has finished processing Directionpackets on port PortId (Name = PortName, …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
110Event ID 110OperationalNN
111VfpExt has finished processing Directionpackets on port PortId (Name = PortName, …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
111Event ID 111OperationalNN
112VfpExt has finished processing Directionpackets on port PortId (Name = PortName, …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
112Event ID 112OperationalNN
113VfpExt has finished processing Directionpackets on port PortId (Name = PortName, …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
113Event ID 113OperationalNN
114VfpExt has finished processing Directionpackets on port PortId (Name = PortName, …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
114Event ID 114OperationalNN
115VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) found …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
115Event ID 115OperationalNN
116VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) found …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
116Event ID 116OperationalNN
117VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) found …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
117Event ID 117OperationalNN
118VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) found …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
118Event ID 118OperationalNN
119VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) found …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
119Event ID 119OperationalNN
120VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) found …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
120Event ID 120OperationalNN
121RuleTyperule with ID RuleId processed Directionpackets on port PortId (Name = …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
121Event ID 121OperationalNN
122VfpExt has finished processing Directionpackets on port PortId (Name = PortName, …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
122Event ID 122OperationalNN
151VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) rewrote …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
151Event ID 151OperationalNN
152VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) rewrote …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
152Event ID 152OperationalNN
153VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) rewrote …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
153Event ID 153OperationalNN
154VfpExt on port PortId (Name = PortUniqueName, FriendlyName = PortFriendlyName) …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
154Event ID 154OperationalNN
155VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
155Event ID 155OperationalNN
156VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
156Event ID 156OperationalNN
157VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
157Event ID 157OperationalNN
158VfpExt on port PortId (Name = PortUniqueName, FriendlyName = PortFriendlyName) …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
158Event ID 158OperationalNN
201VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
201Event ID 201OperationalNN
202VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
202Event ID 202OperationalNN
203VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
203Event ID 203OperationalNN
204VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
204Event ID 204OperationalNN
205VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) removed …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
205Event ID 205OperationalNN
206VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) removed …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
206Event ID 206OperationalNN
207VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
207Event ID 207OperationalNN
208VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
208Event ID 208OperationalNN
251VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) added …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
251Event ID 251OperationalNN
252VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) removed …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
252Event ID 252OperationalNN
253VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) removed …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
253Event ID 253OperationalNN
254VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) pended …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
254Event ID 254OperationalNN
255VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) pended …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
255Event ID 255OperationalNN
256VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) pended …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
256Event ID 256OperationalNN
257VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) pended …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
257Event ID 257OperationalNN
301VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
301Event ID 301OperationalNN
302VfpExt on QoS queue QueueName performing action QosQueueAction for port PortId …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
302Event ID 302OperationalNN
303VfpExt on max cap queue MaxQueuePointer with rate = Rate performing action …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
303Event ID 303OperationalNN
304Subscriber SubscriberContext has subscribed for notifications in compartment id …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
304Event ID 304OperationalNN
305Subscriber SubscriberContext has unsubscribed from notifications in compartment …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
305Event ID 305OperationalNN
310A ND mapping has been added with status Status: { next hop ip NextHop, MAC …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
310Event ID 310OperationalNN
311A ND mapping has been added with status Status: { next hop ip NextHop, MAC …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
311Event ID 311OperationalNN
312A ND mapping has been deleted: { next hop ip NextHop, interface InterfaceLuid, …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
312Event ID 312OperationalNN
313A ND mapping has been deleted: { next hop ip NextHop, interface InterfaceLuid, …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
313Event ID 313OperationalNN
314A flow matched PA route rule: { rule context RuleContext, src ip SrcIP, dst ip …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
314Event ID 314OperationalNN
315A flow matched PA route rule: { rule context RuleContext, src ip SrcIP, dst ip …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
315Event ID 315OperationalNN
316A callback from IP for PA route rule: { rule context RuleContext, flags Flags, …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
316Event ID 316OperationalNN
317A callback from IP for PA route rule: { rule context RuleContext, flags Flags, …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
317Event ID 317OperationalNN
318VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) added …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
318Event ID 318OperationalNN
319VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) removed …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
319Event ID 319OperationalNN
320VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) removed …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
320Event ID 320OperationalNN
321VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) added …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
321Event ID 321OperationalNN
322VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) removed …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
322Event ID 322OperationalNN
323VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) removed …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
323Event ID 323OperationalNN
324VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) added …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
324Event ID 324OperationalNN
325VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) removed …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
325Event ID 325OperationalNN
326VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) removed …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
326Event ID 326OperationalNN
327A flow matched Mapencap rule: {rule context RuleContext, original dest mac = …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
327Event ID 327OperationalNN
328A flow matched Mapencap rule: {rule context RuleContext, original dest mac = …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
328Event ID 328OperationalNN
329A flow matched Mapencap rule: {rule context RuleContext, original dest mac = …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
329Event ID 329OperationalNN
330A flow matched Mapencap rule: {rule context RuleContext, original dest mac = …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
330Event ID 330OperationalNN
331QoS reservation created line LineId on switch SwitchName with …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
331Event ID 331OperationalNN
332QoS reservation updated line LineId on switch SwitchName with …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
332Event ID 332OperationalNN
333QoS reservation deleted line LineId on switch SwitchName with …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
333Event ID 333OperationalNN
334QoS reservation line LineId on switch SwitchName changes available BW with …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
334Event ID 334OperationalNN
335QoS reservation for line LineId on switch SwitchName handles an external NIC …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
335Event ID 335OperationalNN
336QoS reservation for line LineId on switch SwitchName handles an external NIC …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
336Event ID 336OperationalNN
337QoS reservation for line LineId on switch SwitchName handles an external NIC …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
337Event ID 337OperationalNN
338QoS reservation for line LineId handles a new rate allocation event: …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
338Event ID 338OperationalNN
339QoS reservation for line LineId on switch SwitchName adds queue QueueName to the …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
339Event ID 339OperationalNN
340QoS reservation for line LineId on switch SwitchName deletes queue QueueName …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
340Event ID 340OperationalNN
341VfpExt QoS queue QueueName with EnforceIntraHostLimit=EnforceIntraHostLimit, …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
341Event ID 341OperationalNN
342VfpExt QoS queue QueueName with EnforceIntraHostLimit=EnforceIntraHostLimit, …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
342Event ID 342OperationalNN
343VfpExt QoS queue QueueName and port PortId successfully performed action …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
343Event ID 343OperationalNN
344VfpExt QoS queue QueueName and port PortId failed action 'Action' with reason …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
344Event ID 344OperationalNN
345VfpExt QoS reservation on vswitch 'SwitchName' successfully performed action …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
345Event ID 345OperationalNN
346VfpExt QoS reservation on vswitch 'SwitchName' failed action 'Operation' with …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
346Event ID 346OperationalNN
347VfpExt QoS reservation on vswitch 'SwitchName' got external NIC event 'Event', …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
347Event ID 347OperationalNN
348VfpExt QoS reservation on vswitch 'SwitchName' and queue 'QueueName' with …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
348Event ID 348OperationalNN
349VfpExt QoS reservation (line:'LineId') has congestion control event 'Event'.Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
349Event ID 349OperationalNN
351VfpExt dropped a packet from port SrcPortId (Name = SrcPortName, FriendlyName = …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
351Event ID 351OperationalNN
352VfpExt successfully forwarded a packet from port SrcPortId (Name = SrcPortName, …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
352Event ID 352OperationalNN
353VfpExt is skipping destination port DstPortId (Name = DstPortName, FriendlyName …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
353Event ID 353OperationalNN
354VfpExt failed to forward packet from source port SrcPortId (Name = SrcPortName, …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
354Event ID 354OperationalNN
355The save operation for port SrcPortId (Name = PortName, FriendlyName = …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
355Event ID 355OperationalNN
356The save completion operation for port SrcPortId (Name = PortName, FriendlyName …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
356Event ID 356OperationalNN
357The save operation for port SrcPortId (Name = PortName, FriendlyName = …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
357Event ID 357OperationalNN
358Succesfully saved port SrcPortId (Name = PortName, FriendlyName = …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
358Event ID 358OperationalNN
359The overall save operation for port SrcPortId (Name = PortName, FriendlyName = …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
359Event ID 359OperationalNN
360Succesfully restored port SrcPortId (Name = PortName, FriendlyName = …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
360Event ID 360OperationalNN
361Save request for port SrcPortId (Name = PortName, FriendlyName = …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
361Event ID 361OperationalNN
362Save request for port SrcPortId (Name = PortName, FriendlyName = …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
362Event ID 362OperationalNN
363Restore request for port SrcPortId (Name = PortName, FriendlyName = …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
363Event ID 363OperationalNN
364Restore request failure for port SrcPortId (Name = PortName, FriendlyName = …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
364Event ID 364OperationalNN
400RuleTyperule with ID RuleId processed Directionpackets on port PortId (Name = …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
400Event ID 400OperationalNN
401RuleTyperule with ID RuleId processed Directionpackets on port PortId (Name = …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
401Event ID 401OperationalNN
402RuleTyperule with ID RuleId processed Directionpackets on port PortId (Name = …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
402Event ID 402OperationalNN
403RuleTyperule with ID RuleId processed Directionpackets on port PortId (Name = …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
403Event ID 403OperationalNN
404RuleTyperule with ID RuleId processed Directionpackets on port PortId (Name = …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
404Event ID 404OperationalNN
405RuleTyperule with ID RuleId processed Directionpackets on port PortId (Name = …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
405Event ID 405OperationalNN
451Redirect for port PortId (Name = PortName, FriendlyName = PortFriendlyName) …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
451Event ID 451OperationalNN
452OID Oid issued on port ID PortId (Name = PortName, FriendlyName = …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
452Event ID 452OperationalNN
453Status Indication code StatusCode from port ID PortId (Name = PortName, …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
453Event ID 453OperationalNN
454NDIS_OFFLOAD state in the context of Context.Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
454Event ID 454OperationalNN
455OID_RECEIVE_FILTER_SET_FILTER for port ID PortId (Name = PortName, FriendlyName …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
455Event ID 455OperationalNN
456PA route rule update callback: { rule context RuleContext, elapsed time …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
456Event ID 456OperationalNN
500DTLS Session {Port PortId (Name = PortName, FriendlyName = PortFriendlyName), …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
500Event ID 500OperationalNN
501DTLS Session {Port PortId (Name = PortName, FriendlyName = PortFriendlyName), …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
501Event ID 501OperationalNN
502DTLS Session {Port PortId (Name = PortName, FriendlyName = PortFriendlyName), …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
502Event ID 502OperationalNN
503DTLS Session {Port PortId (Name = PortName, FriendlyName = PortFriendlyName), …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
503Event ID 503OperationalNN
504DTLS Session {Port PortId (Name = PortName, FriendlyName = PortFriendlyName), …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
504Event ID 504OperationalNN
505DTLS Session {Port PortId (Name = PortName, FriendlyName = PortFriendlyName), …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
505Event ID 505OperationalNN
506DTLS on Port PortId.Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
506Event ID 506OperationalNN
507DTLS Session {Port PortId (Name = PortName, FriendlyName = PortFriendlyName), …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
507Event ID 507OperationalNN
508DTLS Session {Port PortId (Name = PortName, FriendlyName = PortFriendlyName), …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
508Event ID 508OperationalNN
509PADiscoveryEvent port PortId (Name = PortName, FriendlyName = PortFriendlyName) …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
509Event ID 509OperationalNN
551Port PortId (Name = PortName, FriendlyName = PortFriendlyName) parsed DHCP …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
551Event ID 551OperationalNN
600VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) created …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
600Event ID 600OperationalNN
601VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) created …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
601Event ID 601OperationalNN
602VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) created …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
602Event ID 602OperationalNN
603VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) created …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
603Event ID 603OperationalNN
604VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) matched …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
604Event ID 604OperationalNN
605VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) matched …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
605Event ID 605OperationalNN
606VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) matched …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
606Event ID 606OperationalNN
607VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) matched …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
607Event ID 607OperationalNN
608VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) deleted …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
608Event ID 608OperationalNN
609VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) deleted …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
609Event ID 609OperationalNN
610VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) deleted …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
610Event ID 610OperationalNN
611VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) deleted …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
611Event ID 611OperationalNN
650File operation FileOperation on file FileName with size FileSize completed with …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
650Event ID 650OperationalNN
700Failure in control processing for object.Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
700Event ID 700OperationalNN
701Success during control processing for object.Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
701Event ID 701OperationalNN
702Ioctl completed.Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
702Event ID 702OperationalNN
703Failed when setting port information.Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
703Event ID 703OperationalNN
704Ioctl started.Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
704Event ID 704OperationalNN
705Failed when setting switch information.Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
705Event ID 705OperationalNN
706Ioctl pended.Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
706Event ID 706OperationalNN
751Matched redirect flow for deletion.Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
751Event ID 751OperationalNN
752Matched redirect flow for deletion.Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
752Event ID 752OperationalNN
800GFT offload capabilities in the context of Context.Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
800Event ID 800OperationalNN
801GFT offload counters updated Context.Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
801Event ID 801OperationalNN
802GFT aggregate counters are not freed because either the port could not be …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
802Event ID 802OperationalNN
803VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) reset …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
803Event ID 803OperationalNN
804VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) changed …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
804Event ID 804OperationalNN
805VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) UF …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
805Event ID 805OperationalNN
806VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) UF …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
806Event ID 806OperationalNN
807VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) UF …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
807Event ID 807OperationalNN
808Skipping Sx Port context PortContext (Name = Name, FriendlyName = FriendlyName) …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
808Event ID 808OperationalNN
809Vfp failed to issue OID for VPort PortId with status Status due to …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
809Event ID 809OperationalNN
810Failed to set GFT port parser settings on port PortId (Name = PortName, …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
810Event ID 810OperationalNN
900Tag Id TagId completed operation with status: Status.Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
900Event ID 900OperationalNN
950VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) ignore …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
950Event ID 950OperationalNN
951VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) ignore …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
951Event ID 951OperationalNN
952VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) ignore …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
952Event ID 952OperationalNN
953VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) ignore …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
953Event ID 953OperationalNN
954VfpExt deleted layer flow of type FlowType with flow id {src ip = SrcIpv4Addr, …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
954Event ID 954OperationalNN
955VfpExt deleted layer flow of type FlowType with flow id {src ip = SrcIpv6Addr, …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
955Event ID 955OperationalNN
956VfpExt deleted layer flow of type FlowType with flow id {src ip = SrcIpv4Addr, …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
956Event ID 956OperationalNN
957VfpExt deleted layer flow of type FlowType with flow id {src ip = SrcIpv6Addr, …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
957Event ID 957OperationalNN
958VfpExt deleted layer flow of type FlowType with flow id {src ip = SrcIpv4Addr, …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
958Event ID 958OperationalNN
959VfpExt deleted layer flow of type FlowType with flow id {src ip = SrcIpv6Addr, …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
959Event ID 959OperationalNN
960VfpExt deleted layer flow of type FlowType with flow id {src ip = SrcIpv4Addr, …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
960Event ID 960OperationalNN
961VfpExt deleted layer flow of type FlowType with flow id {src ip = SrcIpv6Addr, …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
961Event ID 961OperationalNN
962VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) failed …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
962Event ID 962OperationalNN
963Replacing layer flow addresses succeeded on port PortId (Name = PortName, …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
963Event ID 963OperationalNN
964Replacing layer flow addresses failed on port PortId (Name = PortName, …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
964Event ID 964OperationalNN
965VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) ran …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
965Event ID 965OperationalNN
966Suspended live migration state change on port PortId (Name = PortName, …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
966Event ID 966OperationalNN
967VfpExt set NDIS_NIC_SWITCH_VPORT_PARAMS_ENFORCE_MAX_SG_LIST on port (name = …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
967Event ID 967OperationalNN
968VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) with …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
968Event ID 968OperationalNN
969Skipping Sx Switch context SwitchContext (Name = Name, FriendlyName = …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
969Event ID 969OperationalNN
970Managing VM Context failed for VMId: VmId on port (name = PortName, FriendlyName …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
970Event ID 970OperationalNN
971VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
971Event ID 971OperationalNN
972VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
972Event ID 972OperationalNN
973VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
973Event ID 973OperationalNN
974VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
974Event ID 974OperationalNN
975VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
975Event ID 975OperationalNN
976VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
976Event ID 976OperationalNN
977VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
977Event ID 977OperationalNN
978VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
978Event ID 978OperationalNN
979VfpExt on port PortId received mappingdesc for following mapping: {mapping index …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
979Event ID 979OperationalNN
980VfpExt on port PortId received mappingdesc for following mapping: {mapping index …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
980Event ID 980OperationalNN
981Applying GFT Multi-Tenant Settings status Status - port VPortId (Name = …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
981Event ID 981OperationalNN
982Reason, status = Status.Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
982Event ID 982OperationalNN
983GFT direct configuration dispatch table for switch SwitchName returned status …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
983Event ID 983OperationalNN
984VfpExt on port PortId layer LayerName matched a redirect rule, using …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
984Event ID 984OperationalNN
990VfpExt hairpin processing dropped packet because destination port after hairpin …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
990Event ID 990OperationalNN
1000VFP PktMon Registration failed for switch SwitchName with status Status and …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
1000Event ID 1000OperationalNN
1010VfpExt QoS config with EnableHardwareCaps=EnableHardwareCaps, …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
1010Event ID 1010OperationalNN
1011VPort OID failed for VportName=PortName, AttachedFunctionId=AttachedFunctionId, …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
1011Event ID 1011OperationalNN
1012RuleTyperule with ID RuleId processed Directionpackets on port PortId (Name = …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
1012Event ID 1012OperationalNN
1013RuleTyperule with ID RuleId processed Directionpackets on port PortId (Name = …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
1013Event ID 1013OperationalNN
1014VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) found …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
1014Event ID 1014OperationalNN
1015VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) found …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
1015Event ID 1015OperationalNN
1016VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) found …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
1016Event ID 1016OperationalNN
1017VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) found …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
1017Event ID 1017OperationalNN
1018RuleTyperule with ID RuleId processed Directionpackets on port PortId (Name = …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
1018Event ID 1018OperationalNN
1019RuleTyperule with ID RuleId processed Directionpackets on port PortId (Name = …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
1019Event ID 1019OperationalNN
1020VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) matched …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
1020Event ID 1020OperationalNN
1021VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) matched …Microsoft-Windows-Hyper-V-VfpExt-AnalyticNN
1021Event ID 1021OperationalNN

Event ID 1: VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) Type Direction raw packets.

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Description

VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) Type Direction raw packets. GftFlags is GftFlags. Contents (up to 64B) of the first packet in the NBL = PktContents.

Message #

VfpExt on port %1 (Name = %6, FriendlyName = %7) %3 %2 raw packets. GftFlags is %8. Contents (up to 64B) of the first packet in the NBL = %5

Fields #

NameDescription
PortId UInt32
Direction UInt8
Known values
%%14592
Inbound
%%14593
Outbound
%%14594
Forward
%%14595
Bidirectional
Type UInt8
PktLen UInt32
PktContents Binary
PortName UnicodeString
PortFriendlyName UnicodeString
GftFlags UInt32

Event ID 1

#
Channel
Operational

Description

VfpExt on port (Name = , FriendlyName = ) raw packets. GftFlags is . Contents (up to 64B) of the first packet in the NBL =.

Fields #

NameDescription
PortId UInt32
Direction UInt8
Known values
%%14592
Inbound
%%14593
Outbound
%%14594
Forward
%%14595
Bidirectional
Type UInt8
PktLen UInt32
PktContents Binary
PortName UnicodeString
PortFriendlyName UnicodeString
GftFlags UInt32

Event ID 2: VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) injected raw packets.

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Description

VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) injected raw packets. Contents (up to 64B) of the first packet in the NBL = PktContents.

Message #

VfpExt on port %1 (Name = %4, FriendlyName = %5) injected raw packets. Contents (up to 64B) of the first packet in the NBL = %3

Fields #

NameDescription
PortId UInt32
PktLen UInt32
PktContents Binary
PortName UnicodeString
PortFriendlyName UnicodeString

Event ID 2

#
Channel
Operational

Description

VfpExt on port (Name = , FriendlyName = ) injected raw packets. Contents (up to 64B) of the first packet in the NBL =.

Fields #

NameDescription
PortId UInt32
PktLen UInt32
PktContents Binary
PortName UnicodeString
PortFriendlyName UnicodeString

Event ID 51: VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) dropped Direction raw packets because of Reason.

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Description

VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) dropped Direction raw packets because of Reason. GftFlags is GftFlags. Contents (up to 64B) of the first packet in the NBL = PktContents (DropStatus=Status, DropLocation = StatusLocation).

Message #

VfpExt on port %1 (Name = %6, FriendlyName = %7) dropped %2 raw packets because of %3. GftFlags is %8. Contents (up to 64B) of the first packet in the NBL = %5 (DropStatus=%9, DropLocation = %10)

Fields #

NameDescription
PortId UInt32
Direction UInt8
Known values
%%14592
Inbound
%%14593
Outbound
%%14594
Forward
%%14595
Bidirectional
Reason UInt8
PktLen UInt32
PktContents Binary
PortName UnicodeString
PortFriendlyName UnicodeString
GftFlags UInt32
Status HexInt32NTSTATUS reference
StatusLocation HexInt32

Event ID 51

#
Channel
Operational

Description

VfpExt on port (Name = , FriendlyName = ) dropped raw packets because of . GftFlags is . Contents (up to 64B) of the first packet in the NBL = (DropStatus=, DropLocation = ).

Fields #

NameDescription
PortId UInt32
Direction UInt8
Known values
%%14592
Inbound
%%14593
Outbound
%%14594
Forward
%%14595
Bidirectional
Reason UInt8
PktLen UInt32
PktContents Binary
PortName UnicodeString
PortFriendlyName UnicodeString
GftFlags UInt32
Status HexInt32NTSTATUS reference
StatusLocation HexInt32

Event ID 52: VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) dropped Directionpackets because of Reason.

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Description

VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) dropped Directionpackets because of Reason. {src mac = SrcMacAddr, dst mac = DstMacAddr, type = Type, gftFlags = GftFlags}.

Message #

VfpExt on port %1 (Name = %7, FriendlyName = %8) dropped %2packets because of %3. {src mac = %4, dst mac = %5, type = %6, gftFlags = %9}

Fields #

NameDescription
PortId UInt32
Direction UInt8
Known values
%%14592
Inbound
%%14593
Outbound
%%14594
Forward
%%14595
Bidirectional
Reason UInt8
SrcMacAddr UnicodeString
DstMacAddr UnicodeString
Type UInt16
PortName UnicodeString
PortFriendlyName UnicodeString
GftFlags UInt32

Event ID 52

#
Channel
Operational

Description

VfpExt on port (Name = , FriendlyName = ) dropped packets because of . {src mac = , dst mac = , type = , gftFlags = }.

Fields #

NameDescription
PortId UInt32
Direction UInt8
Known values
%%14592
Inbound
%%14593
Outbound
%%14594
Forward
%%14595
Bidirectional
Reason UInt8
SrcMacAddr UnicodeString
DstMacAddr UnicodeString
Type UInt16
PortName UnicodeString
PortFriendlyName UnicodeString
GftFlags UInt32

Event ID 53: VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) dropped Directionpackets because of Reason.

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Description

VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) dropped Directionpackets because of Reason. {src mac = SrcMacAddr, dst mac = DstMacAddr}:{src ip = SrcIpv4Addr, dst ip = DstIpv4Addr, protocol = IpProtocol, gftFlags = GftFlags}.

Message #

VfpExt on port %1 (Name = %9, FriendlyName = %10) dropped %2packets because of %3. {src mac = %4, dst mac = %5}:{src ip = %6, dst ip = %7, protocol = %8, gftFlags = %11}

Fields #

NameDescription
PortId UInt32
Direction UInt8
Known values
%%14592
Inbound
%%14593
Outbound
%%14594
Forward
%%14595
Bidirectional
Reason UInt8
SrcMacAddr UnicodeString
DstMacAddr UnicodeString
SrcIpv4Addr UInt32
DstIpv4Addr UInt32
IpProtocol UInt8
PortName UnicodeString
PortFriendlyName UnicodeString
GftFlags UInt32

Event ID 53

#
Channel
Operational

Description

VfpExt on port (Name = , FriendlyName = ) dropped packets because of . {src mac = , dst mac = }:{src ip = , dst ip = , protocol = , gftFlags = }.

Fields #

NameDescription
PortId UInt32
Direction UInt8
Known values
%%14592
Inbound
%%14593
Outbound
%%14594
Forward
%%14595
Bidirectional
Reason UInt8
SrcMacAddr UnicodeString
DstMacAddr UnicodeString
SrcIpv4Addr UInt32
DstIpv4Addr UInt32
IpProtocol UInt8
PortName UnicodeString
PortFriendlyName UnicodeString
GftFlags UInt32

Event ID 54: VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) dropped Directionpackets because of Reason.

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Description

VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) dropped Directionpackets because of Reason. {src mac = SrcMacAddr, dst mac = DstMacAddr}:{src ip = SrcIpv6Addr, dst ip = DstIpv6Addr, protocol = IpProtocol, gftFlags = GftFlags}.

Message #

VfpExt on port %1 (Name = %9, FriendlyName = %10) dropped %2packets because of %3. {src mac = %4, dst mac = %5}:{src ip = %6, dst ip = %7, protocol = %8, gftFlags = %11}

Fields #

NameDescription
PortId UInt32
Direction UInt8
Known values
%%14592
Inbound
%%14593
Outbound
%%14594
Forward
%%14595
Bidirectional
Reason UInt8
SrcMacAddr UnicodeString
DstMacAddr UnicodeString
SrcIpv6Addr Binary
DstIpv6Addr Binary
IpProtocol UInt8
PortName UnicodeString
PortFriendlyName UnicodeString
GftFlags UInt32

Event ID 54

#
Channel
Operational

Description

VfpExt on port (Name = , FriendlyName = ) dropped packets because of . {src mac = , dst mac = }:{src ip = , dst ip = , protocol = , gftFlags = }.

Fields #

NameDescription
PortId UInt32
Direction UInt8
Known values
%%14592
Inbound
%%14593
Outbound
%%14594
Forward
%%14595
Bidirectional
Reason UInt8
SrcMacAddr UnicodeString
DstMacAddr UnicodeString
SrcIpv6Addr Binary
DstIpv6Addr Binary
IpProtocol UInt8
PortName UnicodeString
PortFriendlyName UnicodeString
GftFlags UInt32

Event ID 55: VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) dropped Directionpackets because of Reason.

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Description

VfpExt on port (Name = , FriendlyName = ) dropped packets because of . {src mac = , dst mac = }:{src ip = , dst ip = , protocol = }:{src port = , dst port = , isTcpSyn = , gftFlags = }.

Message #

VfpExt on port %1 (Name = %12, FriendlyName = %13) dropped %2packets because of %3. {src mac = %4, dst mac = %5}:{src ip = %6, dst ip = %7, protocol = %8}:{src port = %9, dst port = %10, isTcpSyn = %11, gftFlags = %14}

Fields #

NameDescription
PortId UInt32
Direction UInt8
Known values
%%14592
Inbound
%%14593
Outbound
%%14594
Forward
%%14595
Bidirectional
Reason UInt8
SrcMacAddr UnicodeString
DstMacAddr UnicodeString
SrcIpv4Addr UInt32
DstIpv4Addr UInt32
IpProtocol UInt8
SrcPort UInt16
DstPort UInt16
IsTcpSyn Boolean
PortName UnicodeString
PortFriendlyName UnicodeString
GftFlags UInt32

Event ID 55

#
Channel
Operational

Description

VfpExt on port (Name = , FriendlyName = ) dropped packets because of . {src mac = , dst mac = }:{src ip = , dst ip = , protocol = }:{src port = , dst port = , isTcpSyn = , gftFlags = }.

Fields #

NameDescription
PortId UInt32
Direction UInt8
Known values
%%14592
Inbound
%%14593
Outbound
%%14594
Forward
%%14595
Bidirectional
Reason UInt8
SrcMacAddr UnicodeString
DstMacAddr UnicodeString
SrcIpv4Addr UInt32
DstIpv4Addr UInt32
IpProtocol UInt8
SrcPort UInt16
DstPort UInt16
IsTcpSyn Boolean
PortName UnicodeString
PortFriendlyName UnicodeString
GftFlags UInt32

Event ID 56: VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) dropped Directionpackets because of Reason.

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Description

VfpExt on port (Name = , FriendlyName = ) dropped packets because of . {src mac = , dst mac = }:{src ip = , dst ip = , protocol = }:{src port = , dst port = , isTcpSyn = , gftFlags = }.

Message #

VfpExt on port %1 (Name = %12, FriendlyName = %13) dropped %2packets because of %3. {src mac = %4, dst mac = %5}:{src ip = %6, dst ip = %7, protocol = %8}:{src port = %9, dst port = %10, isTcpSyn = %11, gftFlags = %14}

Fields #

NameDescription
PortId UInt32
Direction UInt8
Known values
%%14592
Inbound
%%14593
Outbound
%%14594
Forward
%%14595
Bidirectional
Reason UInt8
SrcMacAddr UnicodeString
DstMacAddr UnicodeString
SrcIpv6Addr Binary
DstIpv6Addr Binary
IpProtocol UInt8
SrcPort UInt16
DstPort UInt16
IsTcpSyn Boolean
PortName UnicodeString
PortFriendlyName UnicodeString
GftFlags UInt32

Event ID 56

#
Channel
Operational

Description

VfpExt on port (Name = , FriendlyName = ) dropped packets because of . {src mac = , dst mac = }:{src ip = , dst ip = , protocol = }:{src port = , dst port = , isTcpSyn = , gftFlags = }.

Fields #

NameDescription
PortId UInt32
Direction UInt8
Known values
%%14592
Inbound
%%14593
Outbound
%%14594
Forward
%%14595
Bidirectional
Reason UInt8
SrcMacAddr UnicodeString
DstMacAddr UnicodeString
SrcIpv6Addr Binary
DstIpv6Addr Binary
IpProtocol UInt8
SrcPort UInt16
DstPort UInt16
IsTcpSyn Boolean
PortName UnicodeString
PortFriendlyName UnicodeString
GftFlags UInt32

Event ID 57: VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) dropped DirectionARP packets because of Reason.

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Description

VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) dropped DirectionARP packets because of Reason. ARP type - ArpType, {sender mac = SenderMacAddr, sender ip = SenderIpAddr, target mac = TargetMacAddr, target ip = TargetIpAddr, gftFlags = GftFlags}.

Message #

VfpExt on port %1 (Name = %9, FriendlyName = %10) dropped %2ARP packets because of %3. ARP type - %4, {sender mac = %5, sender ip = %6, target mac = %7, target ip = %8, gftFlags = %11}

Fields #

NameDescription
PortId UInt32
Direction UInt8
Known values
%%14592
Inbound
%%14593
Outbound
%%14594
Forward
%%14595
Bidirectional
Reason UInt8
ArpType UInt16
SenderMacAddr UnicodeString
SenderIpAddr UInt32
TargetMacAddr UnicodeString
TargetIpAddr UInt32
PortName UnicodeString
PortFriendlyName UnicodeString
GftFlags UInt32

Event ID 57

#
Channel
Operational

Description

VfpExt on port (Name = , FriendlyName = ) dropped ARP packets because of . ARP type - , {sender mac = , sender ip = , target mac = , target ip = , gftFlags = }.

Fields #

NameDescription
PortId UInt32
Direction UInt8
Known values
%%14592
Inbound
%%14593
Outbound
%%14594
Forward
%%14595
Bidirectional
Reason UInt8
ArpType UInt16
SenderMacAddr UnicodeString
SenderIpAddr UInt32
TargetMacAddr UnicodeString
TargetIpAddr UInt32
PortName UnicodeString
PortFriendlyName UnicodeString
GftFlags UInt32

Event ID 100: VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) ProcessingType Direction raw packets.

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Description

VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) ProcessingType Direction raw packets. GftFlags is GftFlags, ResumeLayer is ResumeLayer. Contents (up to 64B) of the first packet in the NBL = PktContents.

Message #

VfpExt on port %1 (Name = %6, FriendlyName = %7) %3 %2 raw packets. GftFlags is %8, ResumeLayer is %9. Contents (up to 64B) of the first packet in the NBL = %5

Fields #

NameDescription
PortId UInt32
Direction UInt8
Known values
%%14592
Inbound
%%14593
Outbound
%%14594
Forward
%%14595
Bidirectional
ProcessingType UInt32
PktLen UInt32
PktContents Binary
PortName UnicodeString
PortFriendlyName UnicodeString
GftFlags UInt32
ResumeLayer UInt32

Event ID 100

#
Channel
Operational

Description

VfpExt on port (Name = , FriendlyName = ) raw packets. GftFlags is , ResumeLayer is . Contents (up to 64B) of the first packet in the NBL =.

Fields #

NameDescription
PortId UInt32
Direction UInt8
Known values
%%14592
Inbound
%%14593
Outbound
%%14594
Forward
%%14595
Bidirectional
ProcessingType UInt32
PktLen UInt32
PktContents Binary
PortName UnicodeString
PortFriendlyName UnicodeString
GftFlags UInt32
ResumeLayer UInt32

Event ID 101: RuleTyperule with ID RuleId processed Directionpackets on port PortId (Name = PortName, FriendlyName = PortFriendlyName) with status = Status and statusLocation = StatusLocation: flow ID {src ip = ...

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Message #

%6rule with ID %5 processed %2packets on port %1 (Name = %14, FriendlyName = %15) with status = %13 and statusLocation = %17: flow ID {src ip = %7, dst ip = %8, src port = %9, dst port = %10, protocol = %11, isTcpSyn = %12}, rule {layer = %3, group = %4, rule id = %5, gftFlags = %16}

Fields #

NameDescription
PortId UInt32
Direction UInt8
Known values
%%14592
Inbound
%%14593
Outbound
%%14594
Forward
%%14595
Bidirectional
LayerId UnicodeString
GroupId UnicodeString
RuleId UnicodeString
RuleType UInt8
SrcIpv4Addr UInt32
DstIpv4Addr UInt32
SrcPort UInt16
DstPort UInt16
IpProtocol UInt8
IsTcpSyn Boolean
Status UInt32NTSTATUS reference
PortName UnicodeString
PortFriendlyName UnicodeString
GftFlags UInt32
StatusLocation UInt32

Event ID 101

#
Channel
Operational

Fields #

NameDescription
PortId UInt32
Direction UInt8
Known values
%%14592
Inbound
%%14593
Outbound
%%14594
Forward
%%14595
Bidirectional
LayerId UnicodeString
GroupId UnicodeString
RuleId UnicodeString
RuleType UInt8
SrcIpv4Addr UInt32
DstIpv4Addr UInt32
SrcPort UInt16
DstPort UInt16
IpProtocol UInt8
IsTcpSyn Boolean
Status UInt32NTSTATUS reference
PortName UnicodeString
PortFriendlyName UnicodeString
GftFlags UInt32
StatusLocation UInt32

Event ID 102: RuleTyperule with ID RuleId processed Directionpackets on port PortId (Name = PortName, FriendlyName = PortFriendlyName) with status = Status and statusLocation = StatusLocation: flow ID {src ip = ...

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Message #

%6rule with ID %5 processed %2packets on port %1 (Name = %14, FriendlyName = %15) with status = %13 and statusLocation = %17: flow ID {src ip = %7, dst ip = %8, src port = %9, dst port = %10, protocol = %11, isTcpSyn = %12}, rule {layer = %3, group = %4, rule id = %5, gftFlags = %16}

Fields #

NameDescription
PortId UInt32
Direction UInt8
Known values
%%14592
Inbound
%%14593
Outbound
%%14594
Forward
%%14595
Bidirectional
LayerId UnicodeString
GroupId UnicodeString
RuleId UnicodeString
RuleType UInt8
SrcIpv6Addr Binary
DstIpv6Addr Binary
SrcPort UInt16
DstPort UInt16
IpProtocol UInt8
IsTcpSyn Boolean
Status UInt32NTSTATUS reference
PortName UnicodeString
PortFriendlyName UnicodeString
GftFlags UInt32
StatusLocation UInt32

Event ID 102

#
Channel
Operational

Fields #

NameDescription
PortId UInt32
Direction UInt8
Known values
%%14592
Inbound
%%14593
Outbound
%%14594
Forward
%%14595
Bidirectional
LayerId UnicodeString
GroupId UnicodeString
RuleId UnicodeString
RuleType UInt8
SrcIpv6Addr Binary
DstIpv6Addr Binary
SrcPort UInt16
DstPort UInt16
IpProtocol UInt8
IsTcpSyn Boolean
Status UInt32NTSTATUS reference
PortName UnicodeString
PortFriendlyName UnicodeString
GftFlags UInt32
StatusLocation UInt32

Event ID 103: RuleTyperule with ID RuleId processed Directionpackets on port PortId (Name = PortName, FriendlyName = PortFriendlyName) with status = Status and statusLocation = StatusLocation: flow id {src ip = ...

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Message #

%6rule with ID %5 processed %2packets on port %1 (Name = %12, FriendlyName = %13) with status = %11 and statusLocation = %15: flow id {src ip = %7, dst ip = %8, protocol = %9, icmp type = %10}, rule {layer = %3, group = %4, rule id = %5, gftFlags = %14}

Fields #

NameDescription
PortId UInt32
Direction UInt8
Known values
%%14592
Inbound
%%14593
Outbound
%%14594
Forward
%%14595
Bidirectional
LayerId UnicodeString
GroupId UnicodeString
RuleId UnicodeString
RuleType UInt8
SrcIpv4Addr UInt32
DstIpv4Addr UInt32
IpProtocol UInt8
IcmpType UInt8
Status UInt32NTSTATUS reference
PortName UnicodeString
PortFriendlyName UnicodeString
GftFlags UInt32
StatusLocation UInt32

Event ID 103

#
Channel
Operational

Fields #

NameDescription
PortId UInt32
Direction UInt8
Known values
%%14592
Inbound
%%14593
Outbound
%%14594
Forward
%%14595
Bidirectional
LayerId UnicodeString
GroupId UnicodeString
RuleId UnicodeString
RuleType UInt8
SrcIpv4Addr UInt32
DstIpv4Addr UInt32
IpProtocol UInt8
IcmpType UInt8
Status UInt32NTSTATUS reference
PortName UnicodeString
PortFriendlyName UnicodeString
GftFlags UInt32
StatusLocation UInt32

Event ID 104: RuleTyperule with ID RuleId processed Directionpackets on port PortId (Name = PortName, FriendlyName = PortFriendlyName) with status = Status and statusLocation = StatusLocation: flow id {src ip = ...

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Message #

%6rule with ID %5 processed %2packets on port %1 (Name = %12, FriendlyName = %13) with status = %11 and statusLocation = %15: flow id {src ip = %7, dst ip = %8, protocol = %9, icmp type = %10}, rule {layer = %3, group = %4, rule id = %5, gftFlags = %14}

Fields #

NameDescription
PortId UInt32
Direction UInt8
Known values
%%14592
Inbound
%%14593
Outbound
%%14594
Forward
%%14595
Bidirectional
LayerId UnicodeString
GroupId UnicodeString
RuleId UnicodeString
RuleType UInt8
SrcIpv6Addr Binary
DstIpv6Addr Binary
IpProtocol UInt8
IcmpType UInt8
Status UInt32NTSTATUS reference
PortName UnicodeString
PortFriendlyName UnicodeString
GftFlags UInt32
StatusLocation UInt32

Event ID 104

#
Channel
Operational

Fields #

NameDescription
PortId UInt32
Direction UInt8
Known values
%%14592
Inbound
%%14593
Outbound
%%14594
Forward
%%14595
Bidirectional
LayerId UnicodeString
GroupId UnicodeString
RuleId UnicodeString
RuleType UInt8
SrcIpv6Addr Binary
DstIpv6Addr Binary
IpProtocol UInt8
IcmpType UInt8
Status UInt32NTSTATUS reference
PortName UnicodeString
PortFriendlyName UnicodeString
GftFlags UInt32
StatusLocation UInt32

Event ID 105: RuleTyperule with ID RuleId processed Directionpackets on port PortId (Name = PortName, FriendlyName = PortFriendlyName) with status = Status and statusLocation = StatusLocation: flow id {src ip = ...

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Description

rule with ID processed packets on port (Name = , FriendlyName = ) with status = and statusLocation = : flow id {src ip = , dst ip = , gre key = }, rule {layer = , group = , rule id = , gftFlags = }.

Message #

%6rule with ID %5 processed %2packets on port %1 (Name = %11, FriendlyName = %12) with status = %10 and statusLocation = %14: flow id {src ip = %7, dst ip = %8, gre key = %9}, rule {layer = %3, group = %4, rule id = %5, gftFlags = %13}

Fields #

NameDescription
PortId UInt32
Direction UInt8
Known values
%%14592
Inbound
%%14593
Outbound
%%14594
Forward
%%14595
Bidirectional
LayerId UnicodeString
GroupId UnicodeString
RuleId UnicodeString
RuleType UInt8
SrcIpv4Addr UInt32
DstIpv4Addr UInt32
GreKey UInt32
Status UInt32NTSTATUS reference
PortName UnicodeString
PortFriendlyName UnicodeString
GftFlags UInt32
StatusLocation UInt32

Event ID 105

#
Channel
Operational

Description

rule with ID processed packets on port (Name = , FriendlyName = ) with status = and statusLocation = : flow id {src ip = , dst ip = , gre key = }, rule {layer = , group = , rule id = , gftFlags = }.

Fields #

NameDescription
PortId UInt32
Direction UInt8
Known values
%%14592
Inbound
%%14593
Outbound
%%14594
Forward
%%14595
Bidirectional
LayerId UnicodeString
GroupId UnicodeString
RuleId UnicodeString
RuleType UInt8
SrcIpv4Addr UInt32
DstIpv4Addr UInt32
GreKey UInt32
Status UInt32NTSTATUS reference
PortName UnicodeString
PortFriendlyName UnicodeString
GftFlags UInt32
StatusLocation UInt32

Event ID 106: VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) matched Directionpackets with flow id {src ip = SrcIpv4Addr, dst ip = DstIpv4Addr, src port = SrcPort, dst port = DstPort, p...

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Description

VfpExt on port (Name = , FriendlyName = ) matched packets with flow id {src ip = , dst ip = , src port = , dst port = , protocol = , isTcpSyn = } to flow {layer = , flow type = }. GftFlags = .

Message #

VfpExt on port %1 (Name = %11, FriendlyName = %12) matched %2packets with flow id {src ip = %5, dst ip = %6, src port = %7, dst port = %8, protocol = %9, isTcpSyn = %10} to flow {layer = %3, flow type = %4}. GftFlags = %13.

Fields #

NameDescription
PortId UInt32
Direction UInt8
Known values
%%14592
Inbound
%%14593
Outbound
%%14594
Forward
%%14595
Bidirectional
LayerId UnicodeString
FlowType UInt8
SrcIpv4Addr UInt32
DstIpv4Addr UInt32
SrcPort UInt16
DstPort UInt16
IpProtocol UInt8
IsTcpSyn Boolean
PortName UnicodeString
PortFriendlyName UnicodeString
GftFlags UInt32

Event ID 106

#
Channel
Operational

Description

VfpExt on port (Name = , FriendlyName = ) matched packets with flow id {src ip = , dst ip = , src port = , dst port = , protocol = , isTcpSyn = } to flow {layer = , flow type = }. GftFlags = .

Fields #

NameDescription
PortId UInt32
Direction UInt8
Known values
%%14592
Inbound
%%14593
Outbound
%%14594
Forward
%%14595
Bidirectional
LayerId UnicodeString
FlowType UInt8
SrcIpv4Addr UInt32
DstIpv4Addr UInt32
SrcPort UInt16
DstPort UInt16
IpProtocol UInt8
IsTcpSyn Boolean
PortName UnicodeString
PortFriendlyName UnicodeString
GftFlags UInt32

Event ID 107: VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) matched Directionpackets with flow id {src ip = SrcIpv6Addr, dst ip = DstIpv6Addr, src port = SrcPort, dst port = DstPort, p...

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Description

VfpExt on port (Name = , FriendlyName = ) matched packets with flow id {src ip = , dst ip = , src port = , dst port = , protocol = , isTcpSyn = } to flow {layer = , flow type = }. GftFlags = .

Message #

VfpExt on port %1 (Name = %11, FriendlyName = %12) matched %2packets with flow id {src ip = %5, dst ip = %6, src port = %7, dst port = %8, protocol = %9, isTcpSyn = %10} to flow {layer = %3, flow type = %4}. GftFlags = %13.

Fields #

NameDescription
PortId UInt32
Direction UInt8
Known values
%%14592
Inbound
%%14593
Outbound
%%14594
Forward
%%14595
Bidirectional
LayerId UnicodeString
FlowType UInt8
SrcIpv6Addr Binary
DstIpv6Addr Binary
SrcPort UInt16
DstPort UInt16
IpProtocol UInt8
IsTcpSyn Boolean
PortName UnicodeString
PortFriendlyName UnicodeString
GftFlags UInt32

Event ID 107

#
Channel
Operational

Description

VfpExt on port (Name = , FriendlyName = ) matched packets with flow id {src ip = , dst ip = , src port = , dst port = , protocol = , isTcpSyn = } to flow {layer = , flow type = }. GftFlags = .

Fields #

NameDescription
PortId UInt32
Direction UInt8
Known values
%%14592
Inbound
%%14593
Outbound
%%14594
Forward
%%14595
Bidirectional
LayerId UnicodeString
FlowType UInt8
SrcIpv6Addr Binary
DstIpv6Addr Binary
SrcPort UInt16
DstPort UInt16
IpProtocol UInt8
IsTcpSyn Boolean
PortName UnicodeString
PortFriendlyName UnicodeString
GftFlags UInt32

Event ID 108: VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) matched Directionpackets with flow id {src ip = SrcIpv4Addr, dst ip = DstIpv4Addr, protocol = IpProtocol, icmp type = IcmpTy...

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Description

VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) matched Directionpackets with flow id {src ip = SrcIpv4Addr, dst ip = DstIpv4Addr, protocol = IpProtocol, icmp type = IcmpType} to flow {layer = LayerId, flow type = FlowType}. GftFlags = GftFlags.

Message #

VfpExt on port %1 (Name = %9, FriendlyName = %10) matched %2packets with flow id {src ip = %5, dst ip = %6, protocol = %7, icmp type = %8} to flow {layer = %3, flow type = %4}. GftFlags = %11.

Fields #

NameDescription
PortId UInt32
Direction UInt8
Known values
%%14592
Inbound
%%14593
Outbound
%%14594
Forward
%%14595
Bidirectional
LayerId UnicodeString
FlowType UInt8
SrcIpv4Addr UInt32
DstIpv4Addr UInt32
IpProtocol UInt8
IcmpType UInt8
PortName UnicodeString
PortFriendlyName UnicodeString
GftFlags UInt32

Event ID 108

#
Channel
Operational

Description

VfpExt on port (Name = , FriendlyName = ) matched packets with flow id {src ip = , dst ip = , protocol = , icmp type = } to flow {layer = , flow type = }. GftFlags = .

Fields #

NameDescription
PortId UInt32
Direction UInt8
Known values
%%14592
Inbound
%%14593
Outbound
%%14594
Forward
%%14595
Bidirectional
LayerId UnicodeString
FlowType UInt8
SrcIpv4Addr UInt32
DstIpv4Addr UInt32
IpProtocol UInt8
IcmpType UInt8
PortName UnicodeString
PortFriendlyName UnicodeString
GftFlags UInt32

Event ID 109: VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) matched Directionpackets with flow id {src ip = SrcIpv6Addr, dst ip = DstIpv6Addr, protocol = IpProtocol, icmp type = IcmpTy...

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Description

VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) matched Directionpackets with flow id {src ip = SrcIpv6Addr, dst ip = DstIpv6Addr, protocol = IpProtocol, icmp type = IcmpType} to flow {layer = LayerId, flow type = FlowType}. GftFlags = GftFlags.

Message #

VfpExt on port %1 (Name = %9, FriendlyName = %10) matched %2packets with flow id {src ip = %5, dst ip = %6, protocol = %7, icmp type = %8} to flow {layer = %3, flow type = %4}. GftFlags = %11.

Fields #

NameDescription
PortId UInt32
Direction UInt8
Known values
%%14592
Inbound
%%14593
Outbound
%%14594
Forward
%%14595
Bidirectional
LayerId UnicodeString
FlowType UInt8
SrcIpv6Addr Binary
DstIpv6Addr Binary
IpProtocol UInt8
IcmpType UInt8
PortName UnicodeString
PortFriendlyName UnicodeString
GftFlags UInt32

Event ID 109

#
Channel
Operational

Description

VfpExt on port (Name = , FriendlyName = ) matched packets with flow id {src ip = , dst ip = , protocol = , icmp type = } to flow {layer = , flow type = }. GftFlags = .

Fields #

NameDescription
PortId UInt32
Direction UInt8
Known values
%%14592
Inbound
%%14593
Outbound
%%14594
Forward
%%14595
Bidirectional
LayerId UnicodeString
FlowType UInt8
SrcIpv6Addr Binary
DstIpv6Addr Binary
IpProtocol UInt8
IcmpType UInt8
PortName UnicodeString
PortFriendlyName UnicodeString
GftFlags UInt32

Event ID 110: VfpExt has finished processing Directionpackets on port PortId (Name = PortName, FriendlyName = PortFriendlyName) with status Status and statusLocation StatusLocation with flow id {src ip = %...

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Message #

VfpExt has finished processing %2packets on port %1 (Name = %10, FriendlyName = %11) with status %3 and statusLocation %13 with flow id {src ip = %4, dst ip = %5, src port = %6, dst port = %7, protocol = %8, isTcpSyn = %9}. GftFlags = %12.

Fields #

NameDescription
PortId UInt32
Direction UInt8
Known values
%%14592
Inbound
%%14593
Outbound
%%14594
Forward
%%14595
Bidirectional
Status UInt32NTSTATUS reference
SrcIpv4Addr UInt32
DstIpv4Addr UInt32
SrcPort UInt16
DstPort UInt16
IpProtocol UInt8
IsTcpSyn Boolean
PortName UnicodeString
PortFriendlyName UnicodeString
GftFlags UInt32
StatusLocation UInt32

Event ID 110

#
Channel
Operational

Fields #

NameDescription
PortId UInt32
Direction UInt8
Known values
%%14592
Inbound
%%14593
Outbound
%%14594
Forward
%%14595
Bidirectional
Status UInt32NTSTATUS reference
SrcIpv4Addr UInt32
DstIpv4Addr UInt32
SrcPort UInt16
DstPort UInt16
IpProtocol UInt8
IsTcpSyn Boolean
PortName UnicodeString
PortFriendlyName UnicodeString
GftFlags UInt32
StatusLocation UInt32

Event ID 111: VfpExt has finished processing Directionpackets on port PortId (Name = PortName, FriendlyName = PortFriendlyName) with status Status and statusLocation StatusLocation with flow id {src ip = %...

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Message #

VfpExt has finished processing %2packets on port %1 (Name = %10, FriendlyName = %11) with status %3 and statusLocation %13 with flow id {src ip = %4, dst ip = %5, src port = %6, dst port = %7, protocol = %8, isTcpSyn = %9}. GftFlags = %12.

Fields #

NameDescription
PortId UInt32
Direction UInt8
Known values
%%14592
Inbound
%%14593
Outbound
%%14594
Forward
%%14595
Bidirectional
Status UInt32NTSTATUS reference
SrcIpv6Addr Binary
DstIpv6Addr Binary
SrcPort UInt16
DstPort UInt16
IpProtocol UInt8
IsTcpSyn Boolean
PortName UnicodeString
PortFriendlyName UnicodeString
GftFlags UInt32
StatusLocation UInt32

Event ID 111

#
Channel
Operational

Fields #

NameDescription
PortId UInt32
Direction UInt8
Known values
%%14592
Inbound
%%14593
Outbound
%%14594
Forward
%%14595
Bidirectional
Status UInt32NTSTATUS reference
SrcIpv6Addr Binary
DstIpv6Addr Binary
SrcPort UInt16
DstPort UInt16
IpProtocol UInt8
IsTcpSyn Boolean
PortName UnicodeString
PortFriendlyName UnicodeString
GftFlags UInt32
StatusLocation UInt32

Event ID 112: VfpExt has finished processing Directionpackets on port PortId (Name = PortName, FriendlyName = PortFriendlyName) with status Status and statusLocation StatusLocation with flow id {src ip = SrcIpv4...

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Description

VfpExt has finished processing packets on port (Name = , FriendlyName = ) with status and statusLocation with flow id {src ip = , dst ip = , protocol = , icmp type = }. GftFlags = .

Message #

VfpExt has finished processing %2packets on port %1 (Name = %8, FriendlyName = %9) with status %3 and statusLocation %11 with flow id {src ip = %4, dst ip = %5, protocol = %6, icmp type = %7}. GftFlags = %10.

Fields #

NameDescription
PortId UInt32
Direction UInt8
Known values
%%14592
Inbound
%%14593
Outbound
%%14594
Forward
%%14595
Bidirectional
Status UInt32NTSTATUS reference
SrcIpv4Addr UInt32
DstIpv4Addr UInt32
IpProtocol UInt8
IcmpType UInt8
PortName UnicodeString
PortFriendlyName UnicodeString
GftFlags UInt32
StatusLocation UInt32

Event ID 112

#
Channel
Operational

Description

VfpExt has finished processing packets on port (Name = , FriendlyName = ) with status and statusLocation with flow id {src ip = , dst ip = , protocol = , icmp type = }. GftFlags = .

Fields #

NameDescription
PortId UInt32
Direction UInt8
Known values
%%14592
Inbound
%%14593
Outbound
%%14594
Forward
%%14595
Bidirectional
Status UInt32NTSTATUS reference
SrcIpv4Addr UInt32
DstIpv4Addr UInt32
IpProtocol UInt8
IcmpType UInt8
PortName UnicodeString
PortFriendlyName UnicodeString
GftFlags UInt32
StatusLocation UInt32

Event ID 113: VfpExt has finished processing Directionpackets on port PortId (Name = PortName, FriendlyName = PortFriendlyName) with status Status and statusLocation StatusLocation with flow id {src ip = SrcIpv6...

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Description

VfpExt has finished processing packets on port (Name = , FriendlyName = ) with status and statusLocation with flow id {src ip = , dst ip = , protocol = , icmp type = }. GftFlags = .

Message #

VfpExt has finished processing %2packets on port %1 (Name = %8, FriendlyName = %9) with status %3 and statusLocation %11 with flow id {src ip = %4, dst ip = %5, protocol = %6, icmp type = %7}. GftFlags = %10.

Fields #

NameDescription
PortId UInt32
Direction UInt8
Known values
%%14592
Inbound
%%14593
Outbound
%%14594
Forward
%%14595
Bidirectional
Status UInt32NTSTATUS reference
SrcIpv6Addr Binary
DstIpv6Addr Binary
IpProtocol UInt8
IcmpType UInt8
PortName UnicodeString
PortFriendlyName UnicodeString
GftFlags UInt32
StatusLocation UInt32

Event ID 113

#
Channel
Operational

Description

VfpExt has finished processing packets on port (Name = , FriendlyName = ) with status and statusLocation with flow id {src ip = , dst ip = , protocol = , icmp type = }. GftFlags = .

Fields #

NameDescription
PortId UInt32
Direction UInt8
Known values
%%14592
Inbound
%%14593
Outbound
%%14594
Forward
%%14595
Bidirectional
Status UInt32NTSTATUS reference
SrcIpv6Addr Binary
DstIpv6Addr Binary
IpProtocol UInt8
IcmpType UInt8
PortName UnicodeString
PortFriendlyName UnicodeString
GftFlags UInt32
StatusLocation UInt32

Event ID 114: VfpExt has finished processing Directionpackets on port PortId (Name = PortName, FriendlyName = PortFriendlyName) with status Status and statusLocation StatusLocation with flow id {src ip = SrcIpv4...

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Description

VfpExt has finished processing Directionpackets on port PortId (Name = PortName, FriendlyName = PortFriendlyName) with status Status and statusLocation StatusLocation with flow id {src ip = SrcIpv4Addr, dst ip = DstIpv4Addr, gre key = GreKey}. GftFlags = GftFlags.

Message #

VfpExt has finished processing %2packets on port %1 (Name = %7, FriendlyName = %8) with status %3 and statusLocation %10 with flow id {src ip = %4, dst ip = %5, gre key = %6}. GftFlags = %9

Fields #

NameDescription
PortId UInt32
Direction UInt8
Known values
%%14592
Inbound
%%14593
Outbound
%%14594
Forward
%%14595
Bidirectional
Status UInt32NTSTATUS reference
SrcIpv4Addr UInt32
DstIpv4Addr UInt32
GreKey UInt32
PortName UnicodeString
PortFriendlyName UnicodeString
GftFlags UInt32
StatusLocation UInt32

Event ID 114

#
Channel
Operational

Description

VfpExt has finished processing packets on port (Name = , FriendlyName = ) with status and statusLocation with flow id {src ip = , dst ip = , gre key = }. GftFlags =.

Fields #

NameDescription
PortId UInt32
Direction UInt8
Known values
%%14592
Inbound
%%14593
Outbound
%%14594
Forward
%%14595
Bidirectional
Status UInt32NTSTATUS reference
SrcIpv4Addr UInt32
DstIpv4Addr UInt32
GreKey UInt32
PortName UnicodeString
PortFriendlyName UnicodeString
GftFlags UInt32
StatusLocation UInt32

Event ID 115: VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) found no match in layer LayerId for Directionpackets with flow id {src ip = SrcIpv4Addr, dst ip = DstIpv4Addr, src port = Sr...

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Description

VfpExt on port (Name = , FriendlyName = ) found no match in layer for packets with flow id {src ip = , dst ip = , src port = , dst port = , protocol = , isTcpSyn = }, gftFlags =.

Message #

VfpExt on port %1 (Name = %10, FriendlyName = %11) found no match in layer %3 for %2packets with flow id {src ip = %4, dst ip = %5, src port = %6, dst port = %7, protocol = %8, isTcpSyn = %9}, gftFlags = %12

Fields #

NameDescription
PortId UInt32
Direction UInt8
Known values
%%14592
Inbound
%%14593
Outbound
%%14594
Forward
%%14595
Bidirectional
LayerId UnicodeString
SrcIpv4Addr UInt32
DstIpv4Addr UInt32
SrcPort UInt16
DstPort UInt16
IpProtocol UInt8
IsTcpSyn Boolean
PortName UnicodeString
PortFriendlyName UnicodeString
GftFlags UInt32

Event ID 115

#
Channel
Operational

Description

VfpExt on port (Name = , FriendlyName = ) found no match in layer for packets with flow id {src ip = , dst ip = , src port = , dst port = , protocol = , isTcpSyn = }, gftFlags =.

Fields #

NameDescription
PortId UInt32
Direction UInt8
Known values
%%14592
Inbound
%%14593
Outbound
%%14594
Forward
%%14595
Bidirectional
LayerId UnicodeString
SrcIpv4Addr UInt32
DstIpv4Addr UInt32
SrcPort UInt16
DstPort UInt16
IpProtocol UInt8
IsTcpSyn Boolean
PortName UnicodeString
PortFriendlyName UnicodeString
GftFlags UInt32

Event ID 116: VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) found no match in layer LayerId for Directionpackets with flow id {src ip = SrcIpv6Addr, dst ip = DstIpv6Addr, src port = Sr...

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Description

VfpExt on port (Name = , FriendlyName = ) found no match in layer for packets with flow id {src ip = , dst ip = , src port = , dst port = , protocol = , isTcpSyn = }, gftFlags =.

Message #

VfpExt on port %1 (Name = %10, FriendlyName = %11) found no match in layer %3 for %2packets with flow id {src ip = %4, dst ip = %5, src port = %6, dst port = %7, protocol = %8, isTcpSyn = %9}, gftFlags = %12

Fields #

NameDescription
PortId UInt32
Direction UInt8
Known values
%%14592
Inbound
%%14593
Outbound
%%14594
Forward
%%14595
Bidirectional
LayerId UnicodeString
SrcIpv6Addr Binary
DstIpv6Addr Binary
SrcPort UInt16
DstPort UInt16
IpProtocol UInt8
IsTcpSyn Boolean
PortName UnicodeString
PortFriendlyName UnicodeString
GftFlags UInt32

Event ID 116

#
Channel
Operational

Description

VfpExt on port (Name = , FriendlyName = ) found no match in layer for packets with flow id {src ip = , dst ip = , src port = , dst port = , protocol = , isTcpSyn = }, gftFlags =.

Fields #

NameDescription
PortId UInt32
Direction UInt8
Known values
%%14592
Inbound
%%14593
Outbound
%%14594
Forward
%%14595
Bidirectional
LayerId UnicodeString
SrcIpv6Addr Binary
DstIpv6Addr Binary
SrcPort UInt16
DstPort UInt16
IpProtocol UInt8
IsTcpSyn Boolean
PortName UnicodeString
PortFriendlyName UnicodeString
GftFlags UInt32

Event ID 117: VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) found no match in layer LayerId for Directionpackets with flow id {src ip = SrcIpv4Addr, dst ip = DstIpv4Addr, protocol = Ip...

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Description

VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) found no match in layer LayerId for Directionpackets with flow id {src ip = SrcIpv4Addr, dst ip = DstIpv4Addr, protocol = IpProtocol, icmp type = IcmpType}. GftFlags = GftFlags.

Message #

VfpExt on port %1 (Name = %8, FriendlyName = %9) found no match in layer %3 for %2packets with flow id {src ip = %4, dst ip = %5, protocol = %6, icmp type = %7}. GftFlags = %10

Fields #

NameDescription
PortId UInt32
Direction UInt8
Known values
%%14592
Inbound
%%14593
Outbound
%%14594
Forward
%%14595
Bidirectional
LayerId UnicodeString
SrcIpv4Addr UInt32
DstIpv4Addr UInt32
IpProtocol UInt8
IcmpType UInt8
PortName UnicodeString
PortFriendlyName UnicodeString
GftFlags UInt32

Event ID 117

#
Channel
Operational

Description

VfpExt on port (Name = , FriendlyName = ) found no match in layer for packets with flow id {src ip = , dst ip = , protocol = , icmp type = }. GftFlags =.

Fields #

NameDescription
PortId UInt32
Direction UInt8
Known values
%%14592
Inbound
%%14593
Outbound
%%14594
Forward
%%14595
Bidirectional
LayerId UnicodeString
SrcIpv4Addr UInt32
DstIpv4Addr UInt32
IpProtocol UInt8
IcmpType UInt8
PortName UnicodeString
PortFriendlyName UnicodeString
GftFlags UInt32

Event ID 118: VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) found no match in layer LayerId for Directionpackets with flow id {src ip = SrcIpv6Addr, dst ip = DstIpv6Addr, protocol = Ip...

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Description

VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) found no match in layer LayerId for Directionpackets with flow id {src ip = SrcIpv6Addr, dst ip = DstIpv6Addr, protocol = IpProtocol, icmp type = IcmpType}. GftFlags = GftFlags.

Message #

VfpExt on port %1 (Name = %8, FriendlyName = %9) found no match in layer %3 for %2packets with flow id {src ip = %4, dst ip = %5, protocol = %6, icmp type = %7}. GftFlags = %10

Fields #

NameDescription
PortId UInt32
Direction UInt8
Known values
%%14592
Inbound
%%14593
Outbound
%%14594
Forward
%%14595
Bidirectional
LayerId UnicodeString
SrcIpv6Addr Binary
DstIpv6Addr Binary
IpProtocol UInt8
IcmpType UInt8
PortName UnicodeString
PortFriendlyName UnicodeString
GftFlags UInt32

Event ID 118

#
Channel
Operational

Description

VfpExt on port (Name = , FriendlyName = ) found no match in layer for packets with flow id {src ip = , dst ip = , protocol = , icmp type = }. GftFlags =.

Fields #

NameDescription
PortId UInt32
Direction UInt8
Known values
%%14592
Inbound
%%14593
Outbound
%%14594
Forward
%%14595
Bidirectional
LayerId UnicodeString
SrcIpv6Addr Binary
DstIpv6Addr Binary
IpProtocol UInt8
IcmpType UInt8
PortName UnicodeString
PortFriendlyName UnicodeString
GftFlags UInt32

Event ID 119: VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) found no match in layer LayerId for Directionpackets with flow id {src ip = SrcIpv4Addr, dst ip = DstIpv4Addr, gre key = Gre...

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Description

VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) found no match in layer LayerId for Directionpackets with flow id {src ip = SrcIpv4Addr, dst ip = DstIpv4Addr, gre key = GreKey}. GftFlags = GftFlags.

Message #

VfpExt on port %1 (Name = %7, FriendlyName = %8) found no match in layer %3 for %2packets with flow id {src ip = %4, dst ip = %5, gre key = %6}. GftFlags = %9

Fields #

NameDescription
PortId UInt32
Direction UInt8
Known values
%%14592
Inbound
%%14593
Outbound
%%14594
Forward
%%14595
Bidirectional
LayerId UnicodeString
SrcIpv4Addr UInt32
DstIpv4Addr UInt32
GreKey UInt32
PortName UnicodeString
PortFriendlyName UnicodeString
GftFlags UInt32

Event ID 119

#
Channel
Operational

Description

VfpExt on port (Name = , FriendlyName = ) found no match in layer for packets with flow id {src ip = , dst ip = , gre key = }. GftFlags =.

Fields #

NameDescription
PortId UInt32
Direction UInt8
Known values
%%14592
Inbound
%%14593
Outbound
%%14594
Forward
%%14595
Bidirectional
LayerId UnicodeString
SrcIpv4Addr UInt32
DstIpv4Addr UInt32
GreKey UInt32
PortName UnicodeString
PortFriendlyName UnicodeString
GftFlags UInt32

Event ID 120: VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) found no match in layer LayerId for Directionpackets with flow id {src ip = SrcIpv6Addr, dst ip = DstIpv6Addr, gre key = Gre...

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Description

VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) found no match in layer LayerId for Directionpackets with flow id {src ip = SrcIpv6Addr, dst ip = DstIpv6Addr, gre key = GreKey}. GftFlags = GftFlags.

Message #

VfpExt on port %1 (Name = %7, FriendlyName = %8) found no match in layer %3 for %2packets with flow id {src ip = %4, dst ip = %5, gre key = %6}. GftFlags = %9

Fields #

NameDescription
PortId UInt32
Direction UInt8
Known values
%%14592
Inbound
%%14593
Outbound
%%14594
Forward
%%14595
Bidirectional
LayerId UnicodeString
SrcIpv6Addr Binary
DstIpv6Addr Binary
GreKey UInt32
PortName UnicodeString
PortFriendlyName UnicodeString
GftFlags UInt32

Event ID 120

#
Channel
Operational

Description

VfpExt on port (Name = , FriendlyName = ) found no match in layer for packets with flow id {src ip = , dst ip = , gre key = }. GftFlags =.

Fields #

NameDescription
PortId UInt32
Direction UInt8
Known values
%%14592
Inbound
%%14593
Outbound
%%14594
Forward
%%14595
Bidirectional
LayerId UnicodeString
SrcIpv6Addr Binary
DstIpv6Addr Binary
GreKey UInt32
PortName UnicodeString
PortFriendlyName UnicodeString
GftFlags UInt32

Event ID 121: RuleTyperule with ID RuleId processed Directionpackets on port PortId (Name = PortName, FriendlyName = PortFriendlyName) with status = Status and statusLocation = StatusLocation: flow id {src ip = ...

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Description

rule with ID processed packets on port (Name = , FriendlyName = ) with status = and statusLocation = : flow id {src ip = , dst ip = , gre key = }, rule {layer = , group = , rule id = , gftFlags = }.

Message #

%6rule with ID %5 processed %2packets on port %1 (Name = %11, FriendlyName = %12) with status = %10 and statusLocation = %14: flow id {src ip = %7, dst ip = %8, gre key = %9}, rule {layer = %3, group = %4, rule id = %5, gftFlags = %13}

Fields #

NameDescription
PortId UInt32
Direction UInt8
Known values
%%14592
Inbound
%%14593
Outbound
%%14594
Forward
%%14595
Bidirectional
LayerId UnicodeString
GroupId UnicodeString
RuleId UnicodeString
RuleType UInt8
SrcIpv6Addr Binary
DstIpv6Addr Binary
GreKey UInt32
Status UInt32NTSTATUS reference
PortName UnicodeString
PortFriendlyName UnicodeString
GftFlags UInt32
StatusLocation UInt32

Event ID 121

#
Channel
Operational

Description

rule with ID processed packets on port (Name = , FriendlyName = ) with status = and statusLocation = : flow id {src ip = , dst ip = , gre key = }, rule {layer = , group = , rule id = , gftFlags = }.

Fields #

NameDescription
PortId UInt32
Direction UInt8
Known values
%%14592
Inbound
%%14593
Outbound
%%14594
Forward
%%14595
Bidirectional
LayerId UnicodeString
GroupId UnicodeString
RuleId UnicodeString
RuleType UInt8
SrcIpv6Addr Binary
DstIpv6Addr Binary
GreKey UInt32
Status UInt32NTSTATUS reference
PortName UnicodeString
PortFriendlyName UnicodeString
GftFlags UInt32
StatusLocation UInt32

Event ID 122: VfpExt has finished processing Directionpackets on port PortId (Name = PortName, FriendlyName = PortFriendlyName) with status Status and statusLocation StatusLocation with flow id {src ip = SrcIpv6...

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Description

VfpExt has finished processing Directionpackets on port PortId (Name = PortName, FriendlyName = PortFriendlyName) with status Status and statusLocation StatusLocation with flow id {src ip = SrcIpv6Addr, dst ip = DstIpv6Addr, gre key = GreKey}. GftFlags = GftFlags.

Message #

VfpExt has finished processing %2packets on port %1 (Name = %7, FriendlyName = %8) with status %3 and statusLocation %10 with flow id {src ip = %4, dst ip = %5, gre key = %6}. GftFlags = %9

Fields #

NameDescription
PortId UInt32
Direction UInt8
Known values
%%14592
Inbound
%%14593
Outbound
%%14594
Forward
%%14595
Bidirectional
Status UInt32NTSTATUS reference
SrcIpv6Addr Binary
DstIpv6Addr Binary
GreKey UInt32
PortName UnicodeString
PortFriendlyName UnicodeString
GftFlags UInt32
StatusLocation UInt32

Event ID 122

#
Channel
Operational

Description

VfpExt has finished processing packets on port (Name = , FriendlyName = ) with status and statusLocation with flow id {src ip = , dst ip = , gre key = }. GftFlags =.

Fields #

NameDescription
PortId UInt32
Direction UInt8
Known values
%%14592
Inbound
%%14593
Outbound
%%14594
Forward
%%14595
Bidirectional
Status UInt32NTSTATUS reference
SrcIpv6Addr Binary
DstIpv6Addr Binary
GreKey UInt32
PortName UnicodeString
PortFriendlyName UnicodeString
GftFlags UInt32
StatusLocation UInt32

Event ID 151: VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) rewrote Directionpackets with following header: {src mac = SrcMacAddr, dst mac = DstMacAddr}.

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Message #

VfpExt on port %1 (Name = %5, FriendlyName = %6) rewrote %2packets with following header: {src mac = %3, dst mac = %4}

Fields #

NameDescription
PortId UInt32
Direction UInt8
Known values
%%14592
Inbound
%%14593
Outbound
%%14594
Forward
%%14595
Bidirectional
SrcMacAddr UnicodeString
DstMacAddr UnicodeString
PortName UnicodeString
PortFriendlyName UnicodeString

Event ID 151

#
Channel
Operational

Description

VfpExt on port (Name = , FriendlyName = ) rewrote packets with following header: {src mac = , dst mac = }.

Fields #

NameDescription
PortId UInt32
Direction UInt8
Known values
%%14592
Inbound
%%14593
Outbound
%%14594
Forward
%%14595
Bidirectional
SrcMacAddr UnicodeString
DstMacAddr UnicodeString
PortName UnicodeString
PortFriendlyName UnicodeString

Event ID 152: VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) rewrote Directionpackets with following header: {src ip = SrcIpv4Addr, dst ip = DstIpv4Addr}:{src port = SrcPort, dst port =...

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Description

VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) rewrote Directionpackets with following header: {src ip = SrcIpv4Addr, dst ip = DstIpv4Addr}:{src port = SrcPort, dst port = DstPort}.

Message #

VfpExt on port %1 (Name = %7, FriendlyName = %8) rewrote %2packets with following header: {src ip = %3, dst ip = %4}:{src port = %5, dst port = %6}

Fields #

NameDescription
PortId UInt32
Direction UInt8
Known values
%%14592
Inbound
%%14593
Outbound
%%14594
Forward
%%14595
Bidirectional
SrcIpv4Addr UInt32
DstIpv4Addr UInt32
SrcPort UInt16
DstPort UInt16
PortName UnicodeString
PortFriendlyName UnicodeString

Event ID 152

#
Channel
Operational

Description

VfpExt on port (Name = , FriendlyName = ) rewrote packets with following header: {src ip = , dst ip = }:{src port = , dst port = }.

Fields #

NameDescription
PortId UInt32
Direction UInt8
Known values
%%14592
Inbound
%%14593
Outbound
%%14594
Forward
%%14595
Bidirectional
SrcIpv4Addr UInt32
DstIpv4Addr UInt32
SrcPort UInt16
DstPort UInt16
PortName UnicodeString
PortFriendlyName UnicodeString

Event ID 153: VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) rewrote Directionpackets with following header: {src ip = SrcIpv6Addr, dst ip = DstIpv6Addr}:{src port = SrcPort, dst port =...

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Description

VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) rewrote Directionpackets with following header: {src ip = SrcIpv6Addr, dst ip = DstIpv6Addr}:{src port = SrcPort, dst port = DstPort}.

Message #

VfpExt on port %1 (Name = %7, FriendlyName = %8) rewrote %2packets with following header: {src ip = %3, dst ip = %4}:{src port = %5, dst port = %6}

Fields #

NameDescription
PortId UInt32
Direction UInt8
Known values
%%14592
Inbound
%%14593
Outbound
%%14594
Forward
%%14595
Bidirectional
SrcIpv6Addr Binary
DstIpv6Addr Binary
SrcPort UInt16
DstPort UInt16
PortName UnicodeString
PortFriendlyName UnicodeString

Event ID 153

#
Channel
Operational

Description

VfpExt on port (Name = , FriendlyName = ) rewrote packets with following header: {src ip = , dst ip = }:{src port = , dst port = }.

Fields #

NameDescription
PortId UInt32
Direction UInt8
Known values
%%14592
Inbound
%%14593
Outbound
%%14594
Forward
%%14595
Bidirectional
SrcIpv6Addr Binary
DstIpv6Addr Binary
SrcPort UInt16
DstPort UInt16
PortName UnicodeString
PortFriendlyName UnicodeString

Event ID 154: VfpExt on port PortId (Name = PortUniqueName, FriendlyName = PortFriendlyName) encapped Directionpackets with following header: {src mac = SrcMacAddr, dst mac = DstMacAddr}:{src ip = SrcIpv4Addr, d...

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Description

VfpExt on port PortId (Name = PortUniqueName, FriendlyName = PortFriendlyName) encapped Directionpackets with following header: {src mac = SrcMacAddr, dst mac = DstMacAddr}:{src ip = SrcIpv4Addr, dst ip = DstIpv4Addr, encap type = EncapType, isolation id = GreKey}.

Message #

VfpExt on port %1 (Name = %9, FriendlyName = %10) encapped %2packets with following header: {src mac = %3, dst mac = %4}:{src ip = %5, dst ip = %6, encap type = %7, isolation id = %8}

Fields #

NameDescription
PortId UInt32
Direction UInt8
Known values
%%14592
Inbound
%%14593
Outbound
%%14594
Forward
%%14595
Bidirectional
SrcMacAddr UnicodeString
DstMacAddr UnicodeString
SrcIpv4Addr UInt32
DstIpv4Addr UInt32
EncapType UInt8
GreKey UInt32
PortUniqueName UnicodeString
PortFriendlyName UnicodeString

Event ID 154

#
Channel
Operational

Description

VfpExt on port (Name = , FriendlyName = ) encapped packets with following header: {src mac = , dst mac = }:{src ip = , dst ip = , encap type = , isolation id = }.

Fields #

NameDescription
PortId UInt32
Direction UInt8
Known values
%%14592
Inbound
%%14593
Outbound
%%14594
Forward
%%14595
Bidirectional
SrcMacAddr UnicodeString
DstMacAddr UnicodeString
SrcIpv4Addr UInt32
DstIpv4Addr UInt32
EncapType UInt8
GreKey UInt32
PortUniqueName UnicodeString
PortFriendlyName UnicodeString

Event ID 155: VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) decapped Directionpackets.

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Message #

VfpExt on port %1 (Name = %3, FriendlyName = %4) decapped %2packets

Fields #

NameDescription
PortId UInt32
Direction UInt8
Known values
%%14592
Inbound
%%14593
Outbound
%%14594
Forward
%%14595
Bidirectional
PortName UnicodeString
PortFriendlyName UnicodeString

Event ID 155

#
Channel
Operational

Description

VfpExt on port (Name = , FriendlyName = ) decapped packets.

Fields #

NameDescription
PortId UInt32
Direction UInt8
Known values
%%14592
Inbound
%%14593
Outbound
%%14594
Forward
%%14595
Bidirectional
PortName UnicodeString
PortFriendlyName UnicodeString

Event ID 156: VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) duplicated Directionpackets.

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Description

VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) duplicated Directionpackets. GftFlags = GftFlags. Contents (up to 64B) of the first packet = PktContents.

Message #

VfpExt on port %1 (Name = %5, FriendlyName = %6) duplicated %2packets. GftFlags = %7. Contents (up to 64B) of the first packet = %4

Fields #

NameDescription
PortId UInt32
Direction UInt8
Known values
%%14592
Inbound
%%14593
Outbound
%%14594
Forward
%%14595
Bidirectional
PktLen UInt32
PktContents Binary
PortName UnicodeString
PortFriendlyName UnicodeString
GftFlags UInt32

Event ID 156

#
Channel
Operational

Description

VfpExt on port (Name = , FriendlyName = ) duplicated packets. GftFlags = . Contents (up to 64B) of the first packet =.

Fields #

NameDescription
PortId UInt32
Direction UInt8
Known values
%%14592
Inbound
%%14593
Outbound
%%14594
Forward
%%14595
Bidirectional
PktLen UInt32
PktContents Binary
PortName UnicodeString
PortFriendlyName UnicodeString
GftFlags UInt32

Event ID 157: VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) swallowed Directionpacket.

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Description

VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) swallowed Directionpacket. GftFlags = GftFlags. Contents (up to 64B) of the first packet = PktContents.

Message #

VfpExt on port %1 (Name = %5, FriendlyName = %6) swallowed %2packet. GftFlags = %7. Contents (up to 64B) of the first packet = %4

Fields #

NameDescription
PortId UInt32
Direction UInt8
Known values
%%14592
Inbound
%%14593
Outbound
%%14594
Forward
%%14595
Bidirectional
PktLen UInt32
PktContents Binary
PortName UnicodeString
PortFriendlyName UnicodeString
GftFlags UInt32

Event ID 157

#
Channel
Operational

Description

VfpExt on port (Name = , FriendlyName = ) swallowed packet. GftFlags = . Contents (up to 64B) of the first packet =.

Fields #

NameDescription
PortId UInt32
Direction UInt8
Known values
%%14592
Inbound
%%14593
Outbound
%%14594
Forward
%%14595
Bidirectional
PktLen UInt32
PktContents Binary
PortName UnicodeString
PortFriendlyName UnicodeString
GftFlags UInt32

Event ID 158: VfpExt on port PortId (Name = PortUniqueName, FriendlyName = PortFriendlyName) encapped Directionpackets with following header: {src mac = SrcMacAddr, dst mac = DstMacAddr}:{src ip = SrcIpv6Addr, d...

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Description

VfpExt on port PortId (Name = PortUniqueName, FriendlyName = PortFriendlyName) encapped Directionpackets with following header: {src mac = SrcMacAddr, dst mac = DstMacAddr}:{src ip = SrcIpv6Addr, dst ip = DstIpv6Addr, encap type = EncapType, isolation id = GreKey}.

Message #

VfpExt on port %1 (Name = %9, FriendlyName = %10) encapped %2packets with following header: {src mac = %3, dst mac = %4}:{src ip = %5, dst ip = %6, encap type = %7, isolation id = %8}

Fields #

NameDescription
PortId UInt32
Direction UInt8
Known values
%%14592
Inbound
%%14593
Outbound
%%14594
Forward
%%14595
Bidirectional
SrcMacAddr UnicodeString
DstMacAddr UnicodeString
SrcIpv6Addr Binary
DstIpv6Addr Binary
EncapType UInt8
GreKey UInt32
PortUniqueName UnicodeString
PortFriendlyName UnicodeString

Event ID 158

#
Channel
Operational

Description

VfpExt on port (Name = , FriendlyName = ) encapped packets with following header: {src mac = , dst mac = }:{src ip = , dst ip = , encap type = , isolation id = }.

Fields #

NameDescription
PortId UInt32
Direction UInt8
Known values
%%14592
Inbound
%%14593
Outbound
%%14594
Forward
%%14595
Bidirectional
SrcMacAddr UnicodeString
DstMacAddr UnicodeString
SrcIpv6Addr Binary
DstIpv6Addr Binary
EncapType UInt8
GreKey UInt32
PortUniqueName UnicodeString
PortFriendlyName UnicodeString

Event ID 201: VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) deposited into nat pool NatPoolId the following nat range: {range type = NatRangeType, addr = Ipv4Addr, start port = StartPo...

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Description

VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) deposited into nat pool NatPoolId the following nat range: {range type = NatRangeType, addr = Ipv4Addr, start port = StartPort, end port = EndPort, ref limit = RefLimit}.

Message #

VfpExt on port %1 (Name = %8, FriendlyName = %9) deposited into nat pool %2 the following nat range: {range type = %3, addr = %4, start port = %5, end port = %6, ref limit = %7}

Fields #

NameDescription
PortId UInt32
NatPoolId UnicodeString
NatRangeType UInt8
Ipv4Addr UInt32
StartPort UInt16
EndPort UInt16
RefLimit UInt32
PortName UnicodeString
PortFriendlyName UnicodeString

Event ID 201

#
Channel
Operational

Description

VfpExt on port (Name = , FriendlyName = ) deposited into nat pool the following nat range: {range type = , addr = , start port = , end port = , ref limit = }.

Fields #

NameDescription
PortId UInt32
NatPoolId UnicodeString
NatRangeType UInt8
Ipv4Addr UInt32
StartPort UInt16
EndPort UInt16
RefLimit UInt32
PortName UnicodeString
PortFriendlyName UnicodeString

Event ID 202: VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) deposited into nat pool NatPoolId the following nat range: {range type = NatRangeType, addr = Ipv6Addr, start port = StartPo...

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Description

VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) deposited into nat pool NatPoolId the following nat range: {range type = NatRangeType, addr = Ipv6Addr, start port = StartPort, end port = EndPort, ref limit = RefLimit}.

Message #

VfpExt on port %1 (Name = %8, FriendlyName = %9) deposited into nat pool %2 the following nat range: {range type = %3, addr = %4, start port = %5, end port = %6, ref limit = %7}

Fields #

NameDescription
PortId UInt32
NatPoolId UnicodeString
NatRangeType UInt8
Ipv6Addr Binary
StartPort UInt16
EndPort UInt16
RefLimit UInt32
PortName UnicodeString
PortFriendlyName UnicodeString

Event ID 202

#
Channel
Operational

Description

VfpExt on port (Name = , FriendlyName = ) deposited into nat pool the following nat range: {range type = , addr = , start port = , end port = , ref limit = }.

Fields #

NameDescription
PortId UInt32
NatPoolId UnicodeString
NatRangeType UInt8
Ipv6Addr Binary
StartPort UInt16
EndPort UInt16
RefLimit UInt32
PortName UnicodeString
PortFriendlyName UnicodeString

Event ID 203: VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) withdrawed from nat pool NatPoolId the following nat range: {range type = NatRangeType, addr = Ipv4Addr, start port = StartP...

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Description

VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) withdrawed from nat pool NatPoolId the following nat range: {range type = NatRangeType, addr = Ipv4Addr, start port = StartPort, end port = EndPort, ref limit = RefLimit}.

Message #

VfpExt on port %1 (Name = %8, FriendlyName = %9) withdrawed from nat pool %2 the following nat range: {range type = %3, addr = %4, start port = %5, end port = %6, ref limit = %7}

Fields #

NameDescription
PortId UInt32
NatPoolId UnicodeString
NatRangeType UInt8
Ipv4Addr UInt32
StartPort UInt16
EndPort UInt16
RefLimit UInt32
PortName UnicodeString
PortFriendlyName UnicodeString

Event ID 203

#
Channel
Operational

Description

VfpExt on port (Name = , FriendlyName = ) withdrawed from nat pool the following nat range: {range type = , addr = , start port = , end port = , ref limit = }.

Fields #

NameDescription
PortId UInt32
NatPoolId UnicodeString
NatRangeType UInt8
Ipv4Addr UInt32
StartPort UInt16
EndPort UInt16
RefLimit UInt32
PortName UnicodeString
PortFriendlyName UnicodeString

Event ID 204: VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) withdrawed from nat pool NatPoolId the following nat range: {range type = NatRangeType, addr = Ipv6Addr, start port = StartP...

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Description

VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) withdrawed from nat pool NatPoolId the following nat range: {range type = NatRangeType, addr = Ipv6Addr, start port = StartPort, end port = EndPort, ref limit = RefLimit}.

Message #

VfpExt on port %1 (Name = %8, FriendlyName = %9) withdrawed from nat pool %2 the following nat range: {range type = %3, addr = %4, start port = %5, end port = %6, ref limit = %7}

Fields #

NameDescription
PortId UInt32
NatPoolId UnicodeString
NatRangeType UInt8
Ipv6Addr Binary
StartPort UInt16
EndPort UInt16
RefLimit UInt32
PortName UnicodeString
PortFriendlyName UnicodeString

Event ID 204

#
Channel
Operational

Description

VfpExt on port (Name = , FriendlyName = ) withdrawed from nat pool the following nat range: {range type = , addr = , start port = , end port = , ref limit = }.

Fields #

NameDescription
PortId UInt32
NatPoolId UnicodeString
NatRangeType UInt8
Ipv6Addr Binary
StartPort UInt16
EndPort UInt16
RefLimit UInt32
PortName UnicodeString
PortFriendlyName UnicodeString

Event ID 205: VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) removed from nat pool NatPoolId the following nat range: {range type = NatRangeType, addr = Ipv4Addr, start port = StartPort...

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Description

VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) removed from nat pool NatPoolId the following nat range: {range type = NatRangeType, addr = Ipv4Addr, start port = StartPort, end port = EndPort, ref limit = RefLimit}.

Message #

VfpExt on port %1 (Name = %8, FriendlyName = %9) removed from nat pool %2 the following nat range: {range type = %3, addr = %4, start port = %5, end port = %6, ref limit = %7}

Fields #

NameDescription
PortId UInt32
NatPoolId UnicodeString
NatRangeType UInt8
Ipv4Addr UInt32
StartPort UInt16
EndPort UInt16
RefLimit UInt32
PortName UnicodeString
PortFriendlyName UnicodeString

Event ID 205

#
Channel
Operational

Description

VfpExt on port (Name = , FriendlyName = ) removed from nat pool the following nat range: {range type = , addr = , start port = , end port = , ref limit = }.

Fields #

NameDescription
PortId UInt32
NatPoolId UnicodeString
NatRangeType UInt8
Ipv4Addr UInt32
StartPort UInt16
EndPort UInt16
RefLimit UInt32
PortName UnicodeString
PortFriendlyName UnicodeString

Event ID 206: VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) removed from nat pool NatPoolId the following nat range: {range type = NatRangeType, addr = Ipv6Addr, start port = StartPort...

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Description

VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) removed from nat pool NatPoolId the following nat range: {range type = NatRangeType, addr = Ipv6Addr, start port = StartPort, end port = EndPort, ref limit = RefLimit}.

Message #

VfpExt on port %1 (Name = %8, FriendlyName = %9) removed from nat pool %2 the following nat range: {range type = %3, addr = %4, start port = %5, end port = %6, ref limit = %7}

Fields #

NameDescription
PortId UInt32
NatPoolId UnicodeString
NatRangeType UInt8
Ipv6Addr Binary
StartPort UInt16
EndPort UInt16
RefLimit UInt32
PortName UnicodeString
PortFriendlyName UnicodeString

Event ID 206

#
Channel
Operational

Description

VfpExt on port (Name = , FriendlyName = ) removed from nat pool the following nat range: {range type = , addr = , start port = , end port = , ref limit = }.

Fields #

NameDescription
PortId UInt32
NatPoolId UnicodeString
NatRangeType UInt8
Ipv6Addr Binary
StartPort UInt16
EndPort UInt16
RefLimit UInt32
PortName UnicodeString
PortFriendlyName UnicodeString

Event ID 207: VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) NatPortBindingAction NatPortBinding: {internal addr = InternalIpv4Addr, internal port = InternalIpv4Port, external addr = Ex...

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Description

VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) NatPortBindingAction NatPortBinding: {internal addr = InternalIpv4Addr, internal port = InternalIpv4Port, external addr = ExternalIpv4Addr, external port = ExternalIpv4Port, reference = Reference}.

Message #

VfpExt on port %1 (Name = %8, FriendlyName = %9) %2 NatPortBinding: {internal addr = %3, internal port = %4, external addr = %5, external port = %6, reference = %7}

Fields #

NameDescription
PortId UInt32
NatPortBindingAction UInt8
InternalIpv4Addr UInt32
InternalIpv4Port UInt16
ExternalIpv4Addr UInt32
ExternalIpv4Port UInt16
Reference UInt32
PortName UnicodeString
PortFriendlyName UnicodeString

Event ID 207

#
Channel
Operational

Description

VfpExt on port (Name = , FriendlyName = ) NatPortBinding: {internal addr = , internal port = , external addr = , external port = , reference = }.

Fields #

NameDescription
PortId UInt32
NatPortBindingAction UInt8
InternalIpv4Addr UInt32
InternalIpv4Port UInt16
ExternalIpv4Addr UInt32
ExternalIpv4Port UInt16
Reference UInt32
PortName UnicodeString
PortFriendlyName UnicodeString

Event ID 208: VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) NatPortBindingAction NatPortBinding: {internal addr = InternalIpv6Addr, internal port = InternalIpv6Port, external addr = Ex...

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Description

VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) NatPortBindingAction NatPortBinding: {internal addr = InternalIpv6Addr, internal port = InternalIpv6Port, external addr = ExternalIpv6Addr, external port = ExternalIpv6Port, reference = Reference}.

Message #

VfpExt on port %1 (Name = %8, FriendlyName = %9) %2 NatPortBinding: {internal addr = %3, internal port = %4, external addr = %5, external port = %6, reference = %7}

Fields #

NameDescription
PortId UInt32
NatPortBindingAction UInt8
InternalIpv6Addr Binary
InternalIpv6Port UInt16
ExternalIpv6Addr Binary
ExternalIpv6Port UInt16
Reference UInt32
PortName UnicodeString
PortFriendlyName UnicodeString

Event ID 208

#
Channel
Operational

Description

VfpExt on port (Name = , FriendlyName = ) NatPortBinding: {internal addr = , internal port = , external addr = , external port = , reference = }.

Fields #

NameDescription
PortId UInt32
NatPortBindingAction UInt8
InternalIpv6Addr Binary
InternalIpv6Port UInt16
ExternalIpv6Addr Binary
ExternalIpv6Port UInt16
Reference UInt32
PortName UnicodeString
PortFriendlyName UnicodeString

Event ID 251: VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) added into space SpaceId the following mapping: {mapping type = MappingType, ca = CustomerIpv4Addr, pa = ProviderIpv4Addr, m...

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Message #

VfpExt on port %1 (Name = %19, FriendlyName = %20) added into space %2 the following mapping: {mapping type = %3, ca = %4, pa = %7, mac addr = %10, customer mac addr = %11, isolation id = %12, flags = {all = %13, permanent = %14, non unique PA = %15, mac mapping = %16, L4-load-balanced mapping = %17, L3-load-balanced mapping = %18}}

Fields #

NameDescription
PortId UInt32
SpaceId UnicodeString
MappingType UInt8
CustomerIpv4Addr UInt32
CustomerIpv6AddrLength UInt32
CustomerIpv6Addr Binary
ProviderIpv4Addr UInt32
ProviderIpv6AddrLength UInt32
ProviderIpv6Addr Binary
MacAddr UnicodeString
CustomerMacAddr UnicodeString
IsolationId UInt32
Flags UInt32
PermanentFlag Boolean
NonUniquePAFlag Boolean
MacMappingFlag Boolean
L4LoadBalanced Boolean
L3LoadBalanced Boolean
PortName UnicodeString
PortFriendlyName UnicodeString

Event ID 251

#
Channel
Operational

Fields #

NameDescription
PortId UInt32
SpaceId UnicodeString
MappingType UInt8
CustomerIpv4Addr UInt32
CustomerIpv6AddrLength UInt32
CustomerIpv6Addr Binary
ProviderIpv4Addr UInt32
ProviderIpv6AddrLength UInt32
ProviderIpv6Addr Binary
MacAddr UnicodeString
CustomerMacAddr UnicodeString
IsolationId UInt32
Flags UInt32
PermanentFlag Boolean
NonUniquePAFlag Boolean
MacMappingFlag Boolean
L4LoadBalanced Boolean
L3LoadBalanced Boolean
PortName UnicodeString
PortFriendlyName UnicodeString

Event ID 252: VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) removed from space SpaceId the following mapping: {mapping type = MappingType, ca = CustomerIpv4Addr, pa = ProviderIpv4Addr,...

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Message #

VfpExt on port %1 (Name = %19, FriendlyName = %20) removed from space %2 the following mapping: {mapping type = %3, ca = %4, pa = %7, mac addr = %10, customer mac addr = %11, isolation id = %12, flags = {all = %13, permanent = %14, non unique PA = %15, mac mapping = %16, L4-load-balanced mapping = %17, L3-load-balanced mapping = %18}}

Fields #

NameDescription
PortId UInt32
SpaceId UnicodeString
MappingType UInt8
CustomerIpv4Addr UInt32
CustomerIpv6AddrLength UInt32
CustomerIpv6Addr Binary
ProviderIpv4Addr UInt32
ProviderIpv6AddrLength UInt32
ProviderIpv6Addr Binary
MacAddr UnicodeString
CustomerMacAddr UnicodeString
IsolationId UInt32
Flags UInt32
PermanentFlag Boolean
NonUniquePAFlag Boolean
MacMappingFlag Boolean
L4LoadBalanced Boolean
L3LoadBalanced Boolean
PortName UnicodeString
PortFriendlyName UnicodeString

Event ID 252

#
Channel
Operational

Fields #

NameDescription
PortId UInt32
SpaceId UnicodeString
MappingType UInt8
CustomerIpv4Addr UInt32
CustomerIpv6AddrLength UInt32
CustomerIpv6Addr Binary
ProviderIpv4Addr UInt32
ProviderIpv6AddrLength UInt32
ProviderIpv6Addr Binary
MacAddr UnicodeString
CustomerMacAddr UnicodeString
IsolationId UInt32
Flags UInt32
PermanentFlag Boolean
NonUniquePAFlag Boolean
MacMappingFlag Boolean
L4LoadBalanced Boolean
L3LoadBalanced Boolean
PortName UnicodeString
PortFriendlyName UnicodeString

Event ID 253: VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) removed (timer expiration) from space SpaceId the following mapping: {mapping type = MappingType, ca = CustomerIpv4Addr, pa ...

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Message #

VfpExt on port %1 (Name = %19, FriendlyName = %20) removed (timer expiration) from space %2 the following mapping: {mapping type = %3, ca = %4, pa = %7, mac addr = %10, customer mac addr = %11, isolation id = %12, flags = {all = %13, permanent = %14, non unique PA = %15, mac mapping = %16, L4-load-balanced mapping = %17, L3-load-balanced mapping = %18}}

Fields #

NameDescription
PortId UInt32
SpaceId UnicodeString
MappingType UInt8
CustomerIpv4Addr UInt32
CustomerIpv6AddrLength UInt32
CustomerIpv6Addr Binary
ProviderIpv4Addr UInt32
ProviderIpv6AddrLength UInt32
ProviderIpv6Addr Binary
MacAddr UnicodeString
CustomerMacAddr UnicodeString
IsolationId UInt32
Flags UInt32
PermanentFlag Boolean
NonUniquePAFlag Boolean
MacMappingFlag Boolean
L4LoadBalanced Boolean
L3LoadBalanced Boolean
PortName UnicodeString
PortFriendlyName UnicodeString

Event ID 253

#
Channel
Operational

Fields #

NameDescription
PortId UInt32
SpaceId UnicodeString
MappingType UInt8
CustomerIpv4Addr UInt32
CustomerIpv6AddrLength UInt32
CustomerIpv6Addr Binary
ProviderIpv4Addr UInt32
ProviderIpv6AddrLength UInt32
ProviderIpv6Addr Binary
MacAddr UnicodeString
CustomerMacAddr UnicodeString
IsolationId UInt32
Flags UInt32
PermanentFlag Boolean
NonUniquePAFlag Boolean
MacMappingFlag Boolean
L4LoadBalanced Boolean
L3LoadBalanced Boolean
PortName UnicodeString
PortFriendlyName UnicodeString

Event ID 254: VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) pended into space SpaceId the following mapping with notify Irp sent : {index type = IndexType, ip = ProviderIpv4Addr, mac =...

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Description

VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) pended into space SpaceId the following mapping with notify Irp sent : {index type = IndexType, ip = ProviderIpv4Addr, mac = MacAddr, mapping type = MappingType}.

Message #

VfpExt on port %1 (Name = %7, FriendlyName = %8) pended into space %2 the following mapping with notify Irp sent : {index type = %3, ip = %9, mac = %5, mapping type = %6}

Fields #

NameDescription
PortId UInt32
SpaceId UnicodeString
IndexType UInt8
IpAddr Binary
MacAddr UnicodeString
MappingType UInt8
PortName UnicodeString
PortFriendlyName UnicodeString
ProviderIpv4Addr UInt32

Event ID 254

#
Channel
Operational

Description

VfpExt on port (Name = , FriendlyName = ) pended into space the following mapping with notify Irp sent : {index type = , ip = , mac = , mapping type = }.

Fields #

NameDescription
PortId UInt32
SpaceId UnicodeString
IndexType UInt8
IpAddr Binary
MacAddr UnicodeString
MappingType UInt8
PortName UnicodeString
PortFriendlyName UnicodeString
ProviderIpv4Addr UInt32

Event ID 255: VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) pended into space SpaceId the following mapping with notify Irp missed: {index type = IndexType, ip = ProviderIpv4Addr, mac ...

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Description

VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) pended into space SpaceId the following mapping with notify Irp missed: {index type = IndexType, ip = ProviderIpv4Addr, mac = MacAddr, mapping type = MappingType}.

Message #

VfpExt on port %1 (Name = %7, FriendlyName = %8) pended into space %2 the following mapping with notify Irp missed: {index type = %3, ip = %9, mac = %5, mapping type = %6}

Fields #

NameDescription
PortId UInt32
SpaceId UnicodeString
IndexType UInt8
IpAddr Binary
MacAddr UnicodeString
MappingType UInt8
PortName UnicodeString
PortFriendlyName UnicodeString
ProviderIpv4Addr UInt32

Event ID 255

#
Channel
Operational

Description

VfpExt on port (Name = , FriendlyName = ) pended into space the following mapping with notify Irp missed: {index type = , ip = , mac = , mapping type = }.

Fields #

NameDescription
PortId UInt32
SpaceId UnicodeString
IndexType UInt8
IpAddr Binary
MacAddr UnicodeString
MappingType UInt8
PortName UnicodeString
PortFriendlyName UnicodeString
ProviderIpv4Addr UInt32

Event ID 256: VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) pended into space SpaceId the following mapping with notify Irp sent : {index type = IndexType, ip = IpAddr, mac =...

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Description

VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) pended into space SpaceId the following mapping with notify Irp sent : {index type = IndexType, ip = IpAddr, mac = MacAddr, mapping type = MappingType}.

Message #

VfpExt on port %1 (Name = %7, FriendlyName = %8) pended into space %2 the following mapping with notify Irp sent : {index type = %3, ip = %4, mac = %5, mapping type = %6}

Fields #

NameDescription
PortId UInt32
SpaceId UnicodeString
IndexType UInt8
IpAddr Binary
MacAddr UnicodeString
MappingType UInt8
PortName UnicodeString
PortFriendlyName UnicodeString
ProviderIpv4Addr UInt32

Event ID 256

#
Channel
Operational

Description

VfpExt on port (Name = , FriendlyName = ) pended into space the following mapping with notify Irp sent : {index type = , ip = , mac = , mapping type = }.

Fields #

NameDescription
PortId UInt32
SpaceId UnicodeString
IndexType UInt8
IpAddr Binary
MacAddr UnicodeString
MappingType UInt8
PortName UnicodeString
PortFriendlyName UnicodeString
ProviderIpv4Addr UInt32

Event ID 257: VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) pended into space SpaceId the following mapping with notify Irp missed: {index type = IndexType, ip = IpAddr, mac ...

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Description

VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) pended into space SpaceId the following mapping with notify Irp missed: {index type = IndexType, ip = IpAddr, mac = MacAddr, mapping type = MappingType}.

Message #

VfpExt on port %1 (Name = %7, FriendlyName = %8) pended into space %2 the following mapping with notify Irp missed: {index type = %3, ip = %4, mac = %5, mapping type = %6}

Fields #

NameDescription
PortId UInt32
SpaceId UnicodeString
IndexType UInt8
IpAddr Binary
MacAddr UnicodeString
MappingType UInt8
PortName UnicodeString
PortFriendlyName UnicodeString
ProviderIpv4Addr UInt32

Event ID 257

#
Channel
Operational

Description

VfpExt on port (Name = , FriendlyName = ) pended into space the following mapping with notify Irp missed: {index type = , ip = , mac = , mapping type = }.

Fields #

NameDescription
PortId UInt32
SpaceId UnicodeString
IndexType UInt8
IpAddr Binary
MacAddr UnicodeString
MappingType UInt8
PortName UnicodeString
PortFriendlyName UnicodeString
ProviderIpv4Addr UInt32

Event ID 301: VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) performing action SerializationAction for item SerializationItemType with size ItemSize reference ItemReference version Item...

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Description

VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) performing action SerializationAction for item SerializationItemType with size ItemSize reference ItemReference version ItemVersion status Status: {additional context AdditionalContext}.

Message #

VfpExt on port %1 (Name = %9, FriendlyName = %10) performing action %2 for item %3 with size %4 reference %5 version %6 status %7: {additional context %8}

Fields #

NameDescription
PortId UInt32
SerializationAction UInt8
SerializationItemType UInt32
ItemSize UInt64
ItemReference UInt64
ItemVersion UInt64
Status UInt32NTSTATUS reference
AdditionalContext UInt64
PortName UnicodeString
PortFriendlyName UnicodeString

Event ID 301

#
Channel
Operational

Description

VfpExt on port (Name = , FriendlyName = ) performing action for item with size reference version status : {additional context }.

Fields #

NameDescription
PortId UInt32
SerializationAction UInt8
SerializationItemType UInt32
ItemSize UInt64
ItemReference UInt64
ItemVersion UInt64
Status UInt32NTSTATUS reference
AdditionalContext UInt64
PortName UnicodeString
PortFriendlyName UnicodeString

Event ID 302: VfpExt on QoS queue QueueName performing action QosQueueAction for port PortId with EnforceIntraHostLimit = EnforceIntraHostLimit, TxCap = TransmitCap, TxMin = TransmitReservation, RxCap = ReceiveC...

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Description

VfpExt on QoS queue QueueName performing action QosQueueAction for port PortId with EnforceIntraHostLimit = EnforceIntraHostLimit, TxCap = TransmitCap, TxMin = TransmitReservation, RxCap = ReceiveCap, TxQueue = TransmitMaxQueue, RxQueue = ReceiveMaxQueue.

Message #

VfpExt on QoS queue %1 performing action %2 for port %3 with EnforceIntraHostLimit = %4, TxCap = %5, TxMin = %6, RxCap = %7, TxQueue = %8, RxQueue = %9

Fields #

NameDescription
QueueName UnicodeString
QosQueueAction UInt8
PortId UInt32
EnforceIntraHostLimit Boolean
TransmitCap UInt32
TransmitReservation UInt32
ReceiveCap UInt32
TransmitMaxQueue UInt64
ReceiveMaxQueue UInt64

Event ID 302

#
Channel
Operational

Description

VfpExt on QoS queue performing action for port with EnforceIntraHostLimit = , TxCap = , TxMin = , RxCap = , TxQueue = , RxQueue =.

Fields #

NameDescription
QueueName UnicodeString
QosQueueAction UInt8
PortId UInt32
EnforceIntraHostLimit Boolean
TransmitCap UInt32
TransmitReservation UInt32
ReceiveCap UInt32
TransmitMaxQueue UInt64
ReceiveMaxQueue UInt64

Event ID 303: VfpExt on max cap queue MaxQueuePointer with rate = Rate performing action MaxQueueAction.

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Message #

VfpExt on max cap queue %1 with rate = %2 performing action %3

Fields #

NameDescription
MaxQueuePointer UInt64
Rate UInt64
MaxQueueAction UInt8

Event ID 303

#
Channel
Operational

Description

VfpExt on max cap queue with rate = performing action.

Fields #

NameDescription
MaxQueuePointer UInt64
Rate UInt64
MaxQueueAction UInt8

Event ID 304: Subscriber SubscriberContext has subscribed for notifications in compartment id CompartmentId with status = Status, flags = {all = Flags, neighbor changes = NeighborChangesFlags, route changes = Ro...

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Description

Subscriber SubscriberContext has subscribed for notifications in compartment id CompartmentId with status = Status, flags = {all = Flags, neighbor changes = NeighborChangesFlags, route changes = RouteChangesFlags}.

Message #

Subscriber %2 has subscribed for notifications in compartment id %1 with status = %3, flags = {all = %4, neighbor changes = %5, route changes = %6}

Fields #

NameDescription
CompartmentId UInt32
SubscriberContext Pointer
Status UInt32NTSTATUS reference
Flags UInt32
NeighborChangesFlags Boolean
RouteChangesFlags Boolean

Event ID 304

#
Channel
Operational

Description

Subscriber has subscribed for notifications in compartment id with status = , flags = {all = , neighbor changes = , route changes = }.

Fields #

NameDescription
CompartmentId UInt32
SubscriberContext Pointer
Status UInt32NTSTATUS reference
Flags UInt32
NeighborChangesFlags Boolean
RouteChangesFlags Boolean

Event ID 305: Subscriber SubscriberContext has unsubscribed from notifications in compartment ID CompartmentId.

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Message #

Subscriber %2 has unsubscribed from notifications in compartment ID %1

Fields #

NameDescription
CompartmentId UInt32
SubscriberContext Pointer
Status UInt32NTSTATUS reference
Flags UInt32
NeighborChangesFlags Boolean
RouteChangesFlags Boolean

Event ID 305

#
Channel
Operational

Description

Subscriber has unsubscribed from notifications in compartment ID.

Fields #

NameDescription
CompartmentId UInt32
SubscriberContext Pointer
Status UInt32NTSTATUS reference
Flags UInt32
NeighborChangesFlags Boolean
RouteChangesFlags Boolean

Event ID 310: A ND mapping has been added with status Status: { next hop ip NextHop, MAC address MacAddr, interface InterfaceLuid, type MappingType }.

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Message #

A ND mapping has been added with status %6: { next hop ip %1, MAC address %4, interface %2, type %5 }

Fields #

NameDescription
NextHop UInt32
InterfaceLuid UInt64
AccessTime UInt64
MacAddr UnicodeString
MappingType UInt32
Status UInt32NTSTATUS reference

Event ID 310

#
Channel
Operational

Description

A ND mapping has been added with status : { next hop ip , MAC address , interface , type }.

Fields #

NameDescription
NextHop UInt32
InterfaceLuid UInt64
AccessTime UInt64
MacAddr UnicodeString
MappingType UInt32
Status UInt32NTSTATUS reference

Event ID 311: A ND mapping has been added with status Status: { next hop ip NextHop, MAC address MacAddr, interface InterfaceLuid, type MappingType }.

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Message #

A ND mapping has been added with status %6: { next hop ip %1, MAC address %4, interface %2, type %5 }

Fields #

NameDescription
NextHop Binary
InterfaceLuid UInt64
AccessTime UInt64
MacAddr UnicodeString
MappingType UInt32
Status UInt32NTSTATUS reference

Event ID 311

#
Channel
Operational

Description

A ND mapping has been added with status : { next hop ip , MAC address , interface , type }.

Fields #

NameDescription
NextHop Binary
InterfaceLuid UInt64
AccessTime UInt64
MacAddr UnicodeString
MappingType UInt32
Status UInt32NTSTATUS reference

Event ID 312: A ND mapping has been deleted: { next hop ip NextHop, interface InterfaceLuid, MAC address MacAddr, type MappingType, access time AccessTime }.

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Message #

A ND mapping has been deleted: { next hop ip %1, interface %2, MAC address %4, type %5, access time %3 }

Fields #

NameDescription
NextHop UInt32
InterfaceLuid UInt64
AccessTime UInt64
MacAddr UnicodeString
MappingType UInt32
Status UInt32NTSTATUS reference

Event ID 312

#
Channel
Operational

Description

A ND mapping has been deleted: { next hop ip , interface , MAC address , type , access time }.

Fields #

NameDescription
NextHop UInt32
InterfaceLuid UInt64
AccessTime UInt64
MacAddr UnicodeString
MappingType UInt32
Status UInt32NTSTATUS reference

Event ID 313: A ND mapping has been deleted: { next hop ip NextHop, interface InterfaceLuid, MAC address MacAddr, type MappingType, access time AccessTime }.

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Message #

A ND mapping has been deleted: { next hop ip %1, interface %2, MAC address %4, type %5, access time %3 }

Fields #

NameDescription
NextHop Binary
InterfaceLuid UInt64
AccessTime UInt64
MacAddr UnicodeString
MappingType UInt32
Status UInt32NTSTATUS reference

Event ID 313

#
Channel
Operational

Description

A ND mapping has been deleted: { next hop ip , interface , MAC address , type , access time }.

Fields #

NameDescription
NextHop Binary
InterfaceLuid UInt64
AccessTime UInt64
MacAddr UnicodeString
MappingType UInt32
Status UInt32NTSTATUS reference

Event ID 314: A flow matched PA route rule: { rule context RuleContext, src ip SrcIP, dst ip DstIP, next hop ip NextHop, resolved MAC address MacAddr }.

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Message #

A flow matched PA route rule: { rule context %1, src ip %2, dst ip %3, next hop ip %4, resolved MAC address %5 }

Fields #

NameDescription
RuleContext Pointer
SrcIP UInt32
DstIP UInt32
NextHop UInt32
MacAddr UnicodeString

Event ID 314

#
Channel
Operational

Description

A flow matched PA route rule: { rule context , src ip , dst ip , next hop ip , resolved MAC address }.

Fields #

NameDescription
RuleContext Pointer
SrcIP UInt32
DstIP UInt32
NextHop UInt32
MacAddr UnicodeString

Event ID 315: A flow matched PA route rule: { rule context RuleContext, src ip SrcIP, dst ip DstIP, next hop ip NextHop, resolved MAC address MacAddr }.

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Message #

A flow matched PA route rule: { rule context %1, src ip %2, dst ip %3, next hop ip %4, resolved MAC address %5 }

Fields #

NameDescription
RuleContext Pointer
SrcIP Binary
DstIP Binary
NextHop Binary
MacAddr UnicodeString

Event ID 315

#
Channel
Operational

Description

A flow matched PA route rule: { rule context , src ip , dst ip , next hop ip , resolved MAC address }.

Fields #

NameDescription
RuleContext Pointer
SrcIP Binary
DstIP Binary
NextHop Binary
MacAddr UnicodeString

Event ID 316: A callback from IP for PA route rule: { rule context RuleContext, flags Flags, dest ip DstIP, MAC address MacAddr }.

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Message #

A callback from IP for PA route rule: { rule context %1, flags %2, dest ip %3, MAC address %4 }

Fields #

NameDescription
RuleContext Pointer
Flags UInt32
DstIP UInt32
MacAddr UnicodeString

Event ID 316

#
Channel
Operational

Description

A callback from IP for PA route rule: { rule context , flags , dest ip , MAC address }.

Fields #

NameDescription
RuleContext Pointer
Flags UInt32
DstIP UInt32
MacAddr UnicodeString

Event ID 317: A callback from IP for PA route rule: { rule context RuleContext, flags Flags, dest ip DstIP, MAC address MacAddr }.

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Message #

A callback from IP for PA route rule: { rule context %1, flags %2, dest ip %3, MAC address %4 }

Fields #

NameDescription
RuleContext Pointer
Flags UInt32
DstIP Binary
MacAddr UnicodeString

Event ID 317

#
Channel
Operational

Description

A callback from IP for PA route rule: { rule context , flags , dest ip , MAC address }.

Fields #

NameDescription
RuleContext Pointer
Flags UInt32
DstIP Binary
MacAddr UnicodeString

Event ID 318: VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) added into space SpaceId the following mapping: {mapping type = MappingType, ca = CustomerIpv6Addr, pa = ProviderIpv4Addr, m...

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Message #

VfpExt on port %1 (Name = %19, FriendlyName = %20) added into space %2 the following mapping: {mapping type = %3, ca = %6, pa = %7, mac addr = %10, customer mac addr = %11, isolation id = %12, flags = {all = %13, permanent = %14, non unique PA = %15, mac mapping = %16, L4-load-balanced mapping = %17, L3-load-balanced mapping = %18}}

Fields #

NameDescription
PortId UInt32
SpaceId UnicodeString
MappingType UInt8
CustomerIpv4Addr UInt32
CustomerIpv6AddrLength UInt32
CustomerIpv6Addr Binary
ProviderIpv4Addr UInt32
ProviderIpv6AddrLength UInt32
ProviderIpv6Addr Binary
MacAddr UnicodeString
CustomerMacAddr UnicodeString
IsolationId UInt32
Flags UInt32
PermanentFlag Boolean
NonUniquePAFlag Boolean
MacMappingFlag Boolean
L4LoadBalanced Boolean
L3LoadBalanced Boolean
PortName UnicodeString
PortFriendlyName UnicodeString

Event ID 318

#
Channel
Operational

Fields #

NameDescription
PortId UInt32
SpaceId UnicodeString
MappingType UInt8
CustomerIpv4Addr UInt32
CustomerIpv6AddrLength UInt32
CustomerIpv6Addr Binary
ProviderIpv4Addr UInt32
ProviderIpv6AddrLength UInt32
ProviderIpv6Addr Binary
MacAddr UnicodeString
CustomerMacAddr UnicodeString
IsolationId UInt32
Flags UInt32
PermanentFlag Boolean
NonUniquePAFlag Boolean
MacMappingFlag Boolean
L4LoadBalanced Boolean
L3LoadBalanced Boolean
PortName UnicodeString
PortFriendlyName UnicodeString

Event ID 319: VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) removed from space SpaceId the following mapping: {mapping type = MappingType, ca = CustomerIpv6Addr, pa = ProviderIpv4Addr,...

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Message #

VfpExt on port %1 (Name = %19, FriendlyName = %20) removed from space %2 the following mapping: {mapping type = %3, ca = %6, pa = %7, mac addr = %10, customer mac addr = %11, isolation id = %12, flags = {all = %13, permanent = %14, non unique PA = %15, mac mapping = %16, L4-load-balanced mapping = %17, L3-load-balanced mapping = %18}}

Fields #

NameDescription
PortId UInt32
SpaceId UnicodeString
MappingType UInt8
CustomerIpv4Addr UInt32
CustomerIpv6AddrLength UInt32
CustomerIpv6Addr Binary
ProviderIpv4Addr UInt32
ProviderIpv6AddrLength UInt32
ProviderIpv6Addr Binary
MacAddr UnicodeString
CustomerMacAddr UnicodeString
IsolationId UInt32
Flags UInt32
PermanentFlag Boolean
NonUniquePAFlag Boolean
MacMappingFlag Boolean
L4LoadBalanced Boolean
L3LoadBalanced Boolean
PortName UnicodeString
PortFriendlyName UnicodeString

Event ID 319

#
Channel
Operational

Fields #

NameDescription
PortId UInt32
SpaceId UnicodeString
MappingType UInt8
CustomerIpv4Addr UInt32
CustomerIpv6AddrLength UInt32
CustomerIpv6Addr Binary
ProviderIpv4Addr UInt32
ProviderIpv6AddrLength UInt32
ProviderIpv6Addr Binary
MacAddr UnicodeString
CustomerMacAddr UnicodeString
IsolationId UInt32
Flags UInt32
PermanentFlag Boolean
NonUniquePAFlag Boolean
MacMappingFlag Boolean
L4LoadBalanced Boolean
L3LoadBalanced Boolean
PortName UnicodeString
PortFriendlyName UnicodeString

Event ID 320: VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) removed (timer expiration) from space SpaceId the following mapping: {mapping type = MappingType, ca = CustomerIpv6Addr, pa ...

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Message #

VfpExt on port %1 (Name = %19, FriendlyName = %20) removed (timer expiration) from space %2 the following mapping: {mapping type = %3, ca = %6, pa = %7, mac addr = %10, customer mac addr = %11, isolation id = %12, flags = {all = %13, permanent = %14, non unique PA = %15, mac mapping = %16, L4-load-balanced mapping = %17, L3-load-balanced mapping = %18}}

Fields #

NameDescription
PortId UInt32
SpaceId UnicodeString
MappingType UInt8
CustomerIpv4Addr UInt32
CustomerIpv6AddrLength UInt32
CustomerIpv6Addr Binary
ProviderIpv4Addr UInt32
ProviderIpv6AddrLength UInt32
ProviderIpv6Addr Binary
MacAddr UnicodeString
CustomerMacAddr UnicodeString
IsolationId UInt32
Flags UInt32
PermanentFlag Boolean
NonUniquePAFlag Boolean
MacMappingFlag Boolean
L4LoadBalanced Boolean
L3LoadBalanced Boolean
PortName UnicodeString
PortFriendlyName UnicodeString

Event ID 320

#
Channel
Operational

Fields #

NameDescription
PortId UInt32
SpaceId UnicodeString
MappingType UInt8
CustomerIpv4Addr UInt32
CustomerIpv6AddrLength UInt32
CustomerIpv6Addr Binary
ProviderIpv4Addr UInt32
ProviderIpv6AddrLength UInt32
ProviderIpv6Addr Binary
MacAddr UnicodeString
CustomerMacAddr UnicodeString
IsolationId UInt32
Flags UInt32
PermanentFlag Boolean
NonUniquePAFlag Boolean
MacMappingFlag Boolean
L4LoadBalanced Boolean
L3LoadBalanced Boolean
PortName UnicodeString
PortFriendlyName UnicodeString

Event ID 321: VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) added into space SpaceId the following mapping: {mapping type = MappingType, ca = CustomerIpv4Addr, pa = ProviderIpv6Addr, m...

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Message #

VfpExt on port %1 (Name = %19, FriendlyName = %20) added into space %2 the following mapping: {mapping type = %3, ca = %4, pa = %9, mac addr = %10, customer mac addr = %11, isolation id = %12, flags = {all = %13, permanent = %14, non unique PA = %15, mac mapping = %16, L4-load-balanced mapping = %17, L3-load-balanced mapping = %18}}

Fields #

NameDescription
PortId UInt32
SpaceId UnicodeString
MappingType UInt8
CustomerIpv4Addr UInt32
CustomerIpv6AddrLength UInt32
CustomerIpv6Addr Binary
ProviderIpv4Addr UInt32
ProviderIpv6AddrLength UInt32
ProviderIpv6Addr Binary
MacAddr UnicodeString
CustomerMacAddr UnicodeString
IsolationId UInt32
Flags UInt32
PermanentFlag Boolean
NonUniquePAFlag Boolean
MacMappingFlag Boolean
L4LoadBalanced Boolean
L3LoadBalanced Boolean
PortName UnicodeString
PortFriendlyName UnicodeString

Event ID 321

#
Channel
Operational

Fields #

NameDescription
PortId UInt32
SpaceId UnicodeString
MappingType UInt8
CustomerIpv4Addr UInt32
CustomerIpv6AddrLength UInt32
CustomerIpv6Addr Binary
ProviderIpv4Addr UInt32
ProviderIpv6AddrLength UInt32
ProviderIpv6Addr Binary
MacAddr UnicodeString
CustomerMacAddr UnicodeString
IsolationId UInt32
Flags UInt32
PermanentFlag Boolean
NonUniquePAFlag Boolean
MacMappingFlag Boolean
L4LoadBalanced Boolean
L3LoadBalanced Boolean
PortName UnicodeString
PortFriendlyName UnicodeString

Event ID 322: VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) removed from space SpaceId the following mapping: {mapping type = MappingType, ca = CustomerIpv4Addr, pa = ProviderIpv6Addr,...

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Message #

VfpExt on port %1 (Name = %19, FriendlyName = %20) removed from space %2 the following mapping: {mapping type = %3, ca = %4, pa = %9, mac addr = %10, customer mac addr = %11, isolation id = %12, flags = {all = %13, permanent = %14, non unique PA = %15, mac mapping = %16, L4-load-balanced mapping = %17, L3-load-balanced mapping = %18}}

Fields #

NameDescription
PortId UInt32
SpaceId UnicodeString
MappingType UInt8
CustomerIpv4Addr UInt32
CustomerIpv6AddrLength UInt32
CustomerIpv6Addr Binary
ProviderIpv4Addr UInt32
ProviderIpv6AddrLength UInt32
ProviderIpv6Addr Binary
MacAddr UnicodeString
CustomerMacAddr UnicodeString
IsolationId UInt32
Flags UInt32
PermanentFlag Boolean
NonUniquePAFlag Boolean
MacMappingFlag Boolean
L4LoadBalanced Boolean
L3LoadBalanced Boolean
PortName UnicodeString
PortFriendlyName UnicodeString

Event ID 322

#
Channel
Operational

Fields #

NameDescription
PortId UInt32
SpaceId UnicodeString
MappingType UInt8
CustomerIpv4Addr UInt32
CustomerIpv6AddrLength UInt32
CustomerIpv6Addr Binary
ProviderIpv4Addr UInt32
ProviderIpv6AddrLength UInt32
ProviderIpv6Addr Binary
MacAddr UnicodeString
CustomerMacAddr UnicodeString
IsolationId UInt32
Flags UInt32
PermanentFlag Boolean
NonUniquePAFlag Boolean
MacMappingFlag Boolean
L4LoadBalanced Boolean
L3LoadBalanced Boolean
PortName UnicodeString
PortFriendlyName UnicodeString

Event ID 323: VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) removed (timer expiration) from space SpaceId the following mapping: {mapping type = MappingType, ca = CustomerIpv4Addr, pa ...

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Message #

VfpExt on port %1 (Name = %19, FriendlyName = %20) removed (timer expiration) from space %2 the following mapping: {mapping type = %3, ca = %4, pa = %9, mac addr = %10, customer mac addr = %11, isolation id = %12, flags = {all = %13, permanent = %14, non unique PA = %15, mac mapping = %16, L4-load-balanced mapping = %17, L3-load-balanced mapping = %18}}

Fields #

NameDescription
PortId UInt32
SpaceId UnicodeString
MappingType UInt8
CustomerIpv4Addr UInt32
CustomerIpv6AddrLength UInt32
CustomerIpv6Addr Binary
ProviderIpv4Addr UInt32
ProviderIpv6AddrLength UInt32
ProviderIpv6Addr Binary
MacAddr UnicodeString
CustomerMacAddr UnicodeString
IsolationId UInt32
Flags UInt32
PermanentFlag Boolean
NonUniquePAFlag Boolean
MacMappingFlag Boolean
L4LoadBalanced Boolean
L3LoadBalanced Boolean
PortName UnicodeString
PortFriendlyName UnicodeString

Event ID 323

#
Channel
Operational

Fields #

NameDescription
PortId UInt32
SpaceId UnicodeString
MappingType UInt8
CustomerIpv4Addr UInt32
CustomerIpv6AddrLength UInt32
CustomerIpv6Addr Binary
ProviderIpv4Addr UInt32
ProviderIpv6AddrLength UInt32
ProviderIpv6Addr Binary
MacAddr UnicodeString
CustomerMacAddr UnicodeString
IsolationId UInt32
Flags UInt32
PermanentFlag Boolean
NonUniquePAFlag Boolean
MacMappingFlag Boolean
L4LoadBalanced Boolean
L3LoadBalanced Boolean
PortName UnicodeString
PortFriendlyName UnicodeString

Event ID 324: VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) added into space SpaceId the following mapping: {mapping type = MappingType, ca = CustomerIpv6Addr, pa = ProviderIpv6Addr, m...

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Message #

VfpExt on port %1 (Name = %19, FriendlyName = %20) added into space %2 the following mapping: {mapping type = %3, ca = %6, pa = %9, mac addr = %10, customer mac addr = %11, isolation id = %12, flags = {all = %13, permanent = %14, non unique PA = %15, mac mapping = %16, L4-load-balanced mapping = %17, L3-load-balanced mapping = %18}}

Fields #

NameDescription
PortId UInt32
SpaceId UnicodeString
MappingType UInt8
CustomerIpv4Addr UInt32
CustomerIpv6AddrLength UInt32
CustomerIpv6Addr Binary
ProviderIpv4Addr UInt32
ProviderIpv6AddrLength UInt32
ProviderIpv6Addr Binary
MacAddr UnicodeString
CustomerMacAddr UnicodeString
IsolationId UInt32
Flags UInt32
PermanentFlag Boolean
NonUniquePAFlag Boolean
MacMappingFlag Boolean
L4LoadBalanced Boolean
L3LoadBalanced Boolean
PortName UnicodeString
PortFriendlyName UnicodeString

Event ID 324

#
Channel
Operational

Fields #

NameDescription
PortId UInt32
SpaceId UnicodeString
MappingType UInt8
CustomerIpv4Addr UInt32
CustomerIpv6AddrLength UInt32
CustomerIpv6Addr Binary
ProviderIpv4Addr UInt32
ProviderIpv6AddrLength UInt32
ProviderIpv6Addr Binary
MacAddr UnicodeString
CustomerMacAddr UnicodeString
IsolationId UInt32
Flags UInt32
PermanentFlag Boolean
NonUniquePAFlag Boolean
MacMappingFlag Boolean
L4LoadBalanced Boolean
L3LoadBalanced Boolean
PortName UnicodeString
PortFriendlyName UnicodeString

Event ID 325: VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) removed from space SpaceId the following mapping: {mapping type = MappingType, ca = CustomerIpv6Addr, pa = ProviderIpv6Addr,...

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Message #

VfpExt on port %1 (Name = %19, FriendlyName = %20) removed from space %2 the following mapping: {mapping type = %3, ca = %6, pa = %9, mac addr = %10, customer mac addr = %11, isolation id = %12, flags = {all = %13, permanent = %14, non unique PA = %15, mac mapping = %16, L4-load-balanced mapping = %17, L3-load-balanced mapping = %18}}

Fields #

NameDescription
PortId UInt32
SpaceId UnicodeString
MappingType UInt8
CustomerIpv4Addr UInt32
CustomerIpv6AddrLength UInt32
CustomerIpv6Addr Binary
ProviderIpv4Addr UInt32
ProviderIpv6AddrLength UInt32
ProviderIpv6Addr Binary
MacAddr UnicodeString
CustomerMacAddr UnicodeString
IsolationId UInt32
Flags UInt32
PermanentFlag Boolean
NonUniquePAFlag Boolean
MacMappingFlag Boolean
L4LoadBalanced Boolean
L3LoadBalanced Boolean
PortName UnicodeString
PortFriendlyName UnicodeString

Event ID 325

#
Channel
Operational

Fields #

NameDescription
PortId UInt32
SpaceId UnicodeString
MappingType UInt8
CustomerIpv4Addr UInt32
CustomerIpv6AddrLength UInt32
CustomerIpv6Addr Binary
ProviderIpv4Addr UInt32
ProviderIpv6AddrLength UInt32
ProviderIpv6Addr Binary
MacAddr UnicodeString
CustomerMacAddr UnicodeString
IsolationId UInt32
Flags UInt32
PermanentFlag Boolean
NonUniquePAFlag Boolean
MacMappingFlag Boolean
L4LoadBalanced Boolean
L3LoadBalanced Boolean
PortName UnicodeString
PortFriendlyName UnicodeString

Event ID 326: VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) removed (timer expiration) from space SpaceId the following mapping: {mapping type = MappingType, ca = CustomerIpv6Addr, pa ...

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Message #

VfpExt on port %1 (Name = %19, FriendlyName = %20) removed (timer expiration) from space %2 the following mapping: {mapping type = %3, ca = %6, pa = %9, mac addr = %10, customer mac addr = %11, isolation id = %12, flags = {all = %13, permanent = %14, non unique PA = %15, mac mapping = %16, L4-load-balanced mapping = %17, L3-load-balanced mapping = %18}}

Fields #

NameDescription
PortId UInt32
SpaceId UnicodeString
MappingType UInt8
CustomerIpv4Addr UInt32
CustomerIpv6AddrLength UInt32
CustomerIpv6Addr Binary
ProviderIpv4Addr UInt32
ProviderIpv6AddrLength UInt32
ProviderIpv6Addr Binary
MacAddr UnicodeString
CustomerMacAddr UnicodeString
IsolationId UInt32
Flags UInt32
PermanentFlag Boolean
NonUniquePAFlag Boolean
MacMappingFlag Boolean
L4LoadBalanced Boolean
L3LoadBalanced Boolean
PortName UnicodeString
PortFriendlyName UnicodeString

Event ID 326

#
Channel
Operational

Fields #

NameDescription
PortId UInt32
SpaceId UnicodeString
MappingType UInt8
CustomerIpv4Addr UInt32
CustomerIpv6AddrLength UInt32
CustomerIpv6Addr Binary
ProviderIpv4Addr UInt32
ProviderIpv6AddrLength UInt32
ProviderIpv6Addr Binary
MacAddr UnicodeString
CustomerMacAddr UnicodeString
IsolationId UInt32
Flags UInt32
PermanentFlag Boolean
NonUniquePAFlag Boolean
MacMappingFlag Boolean
L4LoadBalanced Boolean
L3LoadBalanced Boolean
PortName UnicodeString
PortFriendlyName UnicodeString

Event ID 327: A flow matched Mapencap rule: {rule context RuleContext, original dest mac = OriginalDestMacAddr, new dest mac = NewDestMacAddr, src ca = SrcCustomerIpv4Addr, dest ca = DestCustomerIpv4Addr, src pa...

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Message #

A flow matched Mapencap rule: {rule context %1, original dest mac = %2, new dest mac = %3, src ca = %4, dest ca = %7, src pa = %10, dest pa = %13, isolation id = %16, flags = {all = %17, encap type = %18, mac lookup = %19, ca route = %20, use mapping isolation id = %21}}

Fields #

NameDescription
RuleContext Pointer
OriginalDestMacAddr UnicodeString
NewDestMacAddr UnicodeString
SrcCustomerIpv4Addr UInt32
SrcCustomerIpv6AddrLength UInt32
SrcCustomerIpv6Addr Binary
DestCustomerIpv4Addr UInt32
DestCustomerIpv6AddrLength UInt32
DestCustomerIpv6Addr Binary
SrcProviderIpv4Addr UInt32
SrcProviderIpv6AddrLength UInt32
SrcProviderIpv6Addr Binary
DestProviderIpv4Addr UInt32
DestProviderIpv6AddrLength UInt32
DestProviderIpv6Addr Binary
IsolationId UInt32
Flags UInt32
EncapType UInt32
MacLookupFlag Boolean
CaRouteFlag Boolean
UseMappingIsolationIdFlag Boolean

Event ID 327

#
Channel
Operational

Fields #

NameDescription
RuleContext Pointer
OriginalDestMacAddr UnicodeString
NewDestMacAddr UnicodeString
SrcCustomerIpv4Addr UInt32
SrcCustomerIpv6AddrLength UInt32
SrcCustomerIpv6Addr Binary
DestCustomerIpv4Addr UInt32
DestCustomerIpv6AddrLength UInt32
DestCustomerIpv6Addr Binary
SrcProviderIpv4Addr UInt32
SrcProviderIpv6AddrLength UInt32
SrcProviderIpv6Addr Binary
DestProviderIpv4Addr UInt32
DestProviderIpv6AddrLength UInt32
DestProviderIpv6Addr Binary
IsolationId UInt32
Flags UInt32
EncapType UInt32
MacLookupFlag Boolean
CaRouteFlag Boolean
UseMappingIsolationIdFlag Boolean

Event ID 328: A flow matched Mapencap rule: {rule context RuleContext, original dest mac = OriginalDestMacAddr, new dest mac = NewDestMacAddr, src ca = SrcCustomerIpv6Addr, dest ca = DestCustomerIpv6Addr, src pa...

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Message #

A flow matched Mapencap rule: {rule context %1, original dest mac = %2, new dest mac = %3, src ca = %6, dest ca = %9, src pa = %10, dest pa = %13, isolation id = %16, flags = {all = %17, encap type = %18, mac lookup = %19, ca route = %20, use mapping isolation id = %21}}

Fields #

NameDescription
RuleContext Pointer
OriginalDestMacAddr UnicodeString
NewDestMacAddr UnicodeString
SrcCustomerIpv4Addr UInt32
SrcCustomerIpv6AddrLength UInt32
SrcCustomerIpv6Addr Binary
DestCustomerIpv4Addr UInt32
DestCustomerIpv6AddrLength UInt32
DestCustomerIpv6Addr Binary
SrcProviderIpv4Addr UInt32
SrcProviderIpv6AddrLength UInt32
SrcProviderIpv6Addr Binary
DestProviderIpv4Addr UInt32
DestProviderIpv6AddrLength UInt32
DestProviderIpv6Addr Binary
IsolationId UInt32
Flags UInt32
EncapType UInt32
MacLookupFlag Boolean
CaRouteFlag Boolean
UseMappingIsolationIdFlag Boolean

Event ID 328

#
Channel
Operational

Fields #

NameDescription
RuleContext Pointer
OriginalDestMacAddr UnicodeString
NewDestMacAddr UnicodeString
SrcCustomerIpv4Addr UInt32
SrcCustomerIpv6AddrLength UInt32
SrcCustomerIpv6Addr Binary
DestCustomerIpv4Addr UInt32
DestCustomerIpv6AddrLength UInt32
DestCustomerIpv6Addr Binary
SrcProviderIpv4Addr UInt32
SrcProviderIpv6AddrLength UInt32
SrcProviderIpv6Addr Binary
DestProviderIpv4Addr UInt32
DestProviderIpv6AddrLength UInt32
DestProviderIpv6Addr Binary
IsolationId UInt32
Flags UInt32
EncapType UInt32
MacLookupFlag Boolean
CaRouteFlag Boolean
UseMappingIsolationIdFlag Boolean

Event ID 329: A flow matched Mapencap rule: {rule context RuleContext, original dest mac = OriginalDestMacAddr, new dest mac = NewDestMacAddr, src ca = SrcCustomerIpv4Addr, dest ca = DestCustomerIpv4Addr, src pa...

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Message #

A flow matched Mapencap rule: {rule context %1, original dest mac = %2, new dest mac = %3, src ca = %4, dest ca = %7, src pa = %12, dest pa = %15, isolation id = %16, flags = {all = %17, encap type = %18, mac lookup = %19, ca route = %20, use mapping isolation id = %21}}

Fields #

NameDescription
RuleContext Pointer
OriginalDestMacAddr UnicodeString
NewDestMacAddr UnicodeString
SrcCustomerIpv4Addr UInt32
SrcCustomerIpv6AddrLength UInt32
SrcCustomerIpv6Addr Binary
DestCustomerIpv4Addr UInt32
DestCustomerIpv6AddrLength UInt32
DestCustomerIpv6Addr Binary
SrcProviderIpv4Addr UInt32
SrcProviderIpv6AddrLength UInt32
SrcProviderIpv6Addr Binary
DestProviderIpv4Addr UInt32
DestProviderIpv6AddrLength UInt32
DestProviderIpv6Addr Binary
IsolationId UInt32
Flags UInt32
EncapType UInt32
MacLookupFlag Boolean
CaRouteFlag Boolean
UseMappingIsolationIdFlag Boolean

Event ID 329

#
Channel
Operational

Fields #

NameDescription
RuleContext Pointer
OriginalDestMacAddr UnicodeString
NewDestMacAddr UnicodeString
SrcCustomerIpv4Addr UInt32
SrcCustomerIpv6AddrLength UInt32
SrcCustomerIpv6Addr Binary
DestCustomerIpv4Addr UInt32
DestCustomerIpv6AddrLength UInt32
DestCustomerIpv6Addr Binary
SrcProviderIpv4Addr UInt32
SrcProviderIpv6AddrLength UInt32
SrcProviderIpv6Addr Binary
DestProviderIpv4Addr UInt32
DestProviderIpv6AddrLength UInt32
DestProviderIpv6Addr Binary
IsolationId UInt32
Flags UInt32
EncapType UInt32
MacLookupFlag Boolean
CaRouteFlag Boolean
UseMappingIsolationIdFlag Boolean

Event ID 330: A flow matched Mapencap rule: {rule context RuleContext, original dest mac = OriginalDestMacAddr, new dest mac = NewDestMacAddr, src ca = SrcCustomerIpv6Addr, dest ca = DestCustomerIpv6Addr, src pa...

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Message #

A flow matched Mapencap rule: {rule context %1, original dest mac = %2, new dest mac = %3, src ca = %6, dest ca = %9, src pa = %12, dest pa = %15, isolation id = %16, flags = {all = %17, encap type = %18, mac lookup = %19, ca route = %20, use mapping isolation id = %21}}

Fields #

NameDescription
RuleContext Pointer
OriginalDestMacAddr UnicodeString
NewDestMacAddr UnicodeString
SrcCustomerIpv4Addr UInt32
SrcCustomerIpv6AddrLength UInt32
SrcCustomerIpv6Addr Binary
DestCustomerIpv4Addr UInt32
DestCustomerIpv6AddrLength UInt32
DestCustomerIpv6Addr Binary
SrcProviderIpv4Addr UInt32
SrcProviderIpv6AddrLength UInt32
SrcProviderIpv6Addr Binary
DestProviderIpv4Addr UInt32
DestProviderIpv6AddrLength UInt32
DestProviderIpv6Addr Binary
IsolationId UInt32
Flags UInt32
EncapType UInt32
MacLookupFlag Boolean
CaRouteFlag Boolean
UseMappingIsolationIdFlag Boolean

Event ID 330

#
Channel
Operational

Fields #

NameDescription
RuleContext Pointer
OriginalDestMacAddr UnicodeString
NewDestMacAddr UnicodeString
SrcCustomerIpv4Addr UInt32
SrcCustomerIpv6AddrLength UInt32
SrcCustomerIpv6Addr Binary
DestCustomerIpv4Addr UInt32
DestCustomerIpv6AddrLength UInt32
DestCustomerIpv6Addr Binary
SrcProviderIpv4Addr UInt32
SrcProviderIpv6AddrLength UInt32
SrcProviderIpv6Addr Binary
DestProviderIpv4Addr UInt32
DestProviderIpv6AddrLength UInt32
DestProviderIpv6Addr Binary
IsolationId UInt32
Flags UInt32
EncapType UInt32
MacLookupFlag Boolean
CaRouteFlag Boolean
UseMappingIsolationIdFlag Boolean

Event ID 331: QoS reservation created line LineId on switch SwitchName with status=FailedReason.

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Description

QoS reservation created line on switch with status=. Line's config is {res mode = , default res = , link speed pct = , NIC link speed = , NIC min guarantee pct = reservable bw = , avail bw = }.

Message #

QoS reservation created line %2 on switch %1 with status=%3. Line's config is {res mode = %4, default res = %5, link speed pct = %6, NIC link speed = %7, NIC min guarantee pct = %8 reservable bw = %9, avail bw = %10}

Fields #

NameDescription
SwitchName UnicodeString
LineId UInt64
FailedReason UInt32
ReservationMode UInt32
DefaultReservation UInt64
LinkSpeedPct UInt32
LinkSpeed UInt64
LinkSpeedGuaranteePct UInt32
ReservableBw UInt64
AvailableBw Int64

Event ID 331

#
Channel
Operational

Description

QoS reservation created line on switch with status=. Line's config is {res mode = , default res = , link speed pct = , NIC link speed = , NIC min guarantee pct = reservable bw = , avail bw = }.

Fields #

NameDescription
SwitchName UnicodeString
LineId UInt64
FailedReason UInt32
ReservationMode UInt32
DefaultReservation UInt64
LinkSpeedPct UInt32
LinkSpeed UInt64
LinkSpeedGuaranteePct UInt32
ReservableBw UInt64
AvailableBw Int64

Event ID 332: QoS reservation updated line LineId on switch SwitchName with status=FailedReason.

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Description

QoS reservation updated line on switch with status=. Line's config is {res mode = , default res = , link speed pct = , NIC link speed = , NIC min guarantee pct = reservable bw = , avail bw = }.

Message #

QoS reservation updated line %2 on switch %1 with status=%3. Line's config is {res mode = %4, default res = %5, link speed pct = %6, NIC link speed = %7, NIC min guarantee pct = %8 reservable bw = %9, avail bw = %10}

Fields #

NameDescription
SwitchName UnicodeString
LineId UInt64
FailedReason UInt32
ReservationMode UInt32
DefaultReservation UInt64
LinkSpeedPct UInt32
LinkSpeed UInt64
LinkSpeedGuaranteePct UInt32
ReservableBw UInt64
AvailableBw Int64

Event ID 332

#
Channel
Operational

Description

QoS reservation updated line on switch with status=. Line's config is {res mode = , default res = , link speed pct = , NIC link speed = , NIC min guarantee pct = reservable bw = , avail bw = }.

Fields #

NameDescription
SwitchName UnicodeString
LineId UInt64
FailedReason UInt32
ReservationMode UInt32
DefaultReservation UInt64
LinkSpeedPct UInt32
LinkSpeed UInt64
LinkSpeedGuaranteePct UInt32
ReservableBw UInt64
AvailableBw Int64

Event ID 333: QoS reservation deleted line LineId on switch SwitchName with status=FailedReason.

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Message #

QoS reservation deleted line %2 on switch %1 with status=%3.

Fields #

NameDescription
SwitchName UnicodeString
LineId UInt64
FailedReason UInt32
ReservationMode UInt32
DefaultReservation UInt64
LinkSpeedPct UInt32
LinkSpeed UInt64
LinkSpeedGuaranteePct UInt32
ReservableBw UInt64
AvailableBw Int64

Event ID 333

#
Channel
Operational

Description

QoS reservation deleted line on switch with status=.

Fields #

NameDescription
SwitchName UnicodeString
LineId UInt64
FailedReason UInt32
ReservationMode UInt32
DefaultReservation UInt64
LinkSpeedPct UInt32
LinkSpeed UInt64
LinkSpeedGuaranteePct UInt32
ReservableBw UInt64
AvailableBw Int64

Event ID 334: QoS reservation line LineId on switch SwitchName changes available BW with status=FailedReason.

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Message #

QoS reservation line %2 on switch %1 changes available BW with status=%3. Line's config is {res mode = %4, default res = %5, link speed pct = %6, NIC link speed = %7, NIC min guarantee pct = %8 reservable bw = %9, avail bw = %10}

Fields #

NameDescription
SwitchName UnicodeString
LineId UInt64
FailedReason UInt32
ReservationMode UInt32
DefaultReservation UInt64
LinkSpeedPct UInt32
LinkSpeed UInt64
LinkSpeedGuaranteePct UInt32
ReservableBw UInt64
AvailableBw Int64

Event ID 334

#
Channel
Operational

Fields #

NameDescription
SwitchName UnicodeString
LineId UInt64
FailedReason UInt32
ReservationMode UInt32
DefaultReservation UInt64
LinkSpeedPct UInt32
LinkSpeed UInt64
LinkSpeedGuaranteePct UInt32
ReservableBw UInt64
AvailableBw Int64

Event ID 335: QoS reservation for line LineId on switch SwitchName handles an external NIC connect event with status=FailedReason.

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Message #

QoS reservation for line %2 on switch %1 handles an external NIC connect event with status=%3. Line's config is {res mode = %4, default res = %5, link speed pct = %6, NIC link speed = %7, NIC min guarantee pct = %8 reservable bw = %9, avail bw = %10}

Fields #

NameDescription
SwitchName UnicodeString
LineId UInt64
FailedReason UInt32
ReservationMode UInt32
DefaultReservation UInt64
LinkSpeedPct UInt32
LinkSpeed UInt64
LinkSpeedGuaranteePct UInt32
ReservableBw UInt64
AvailableBw Int64

Event ID 335

#
Channel
Operational

Fields #

NameDescription
SwitchName UnicodeString
LineId UInt64
FailedReason UInt32
ReservationMode UInt32
DefaultReservation UInt64
LinkSpeedPct UInt32
LinkSpeed UInt64
LinkSpeedGuaranteePct UInt32
ReservableBw UInt64
AvailableBw Int64

Event ID 336: QoS reservation for line LineId on switch SwitchName handles an external NIC link state event with status=FailedReason.

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Message #

QoS reservation for line %2 on switch %1 handles an external NIC link state event with status=%3. Line's config is {res mode = %4, default res = %5, link speed pct = %6, NIC link speed = %7, NIC min guarantee pct = %8 reservable bw = %9, avail bw = %10}

Fields #

NameDescription
SwitchName UnicodeString
LineId UInt64
FailedReason UInt32
ReservationMode UInt32
DefaultReservation UInt64
LinkSpeedPct UInt32
LinkSpeed UInt64
LinkSpeedGuaranteePct UInt32
ReservableBw UInt64
AvailableBw Int64

Event ID 336

#
Channel
Operational

Fields #

NameDescription
SwitchName UnicodeString
LineId UInt64
FailedReason UInt32
ReservationMode UInt32
DefaultReservation UInt64
LinkSpeedPct UInt32
LinkSpeed UInt64
LinkSpeedGuaranteePct UInt32
ReservableBw UInt64
AvailableBw Int64

Event ID 337: QoS reservation for line LineId on switch SwitchName handles an external NIC link speed change event with status=FailedReason.

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Message #

QoS reservation for line %2 on switch %1 handles an external NIC link speed change event with status=%3. Line's config is {res mode = %4, default res = %5, link speed pct = %6, NIC link speed = %7, NIC min guarantee pct = %8 reservable bw = %9, avail bw = %10}

Fields #

NameDescription
SwitchName UnicodeString
LineId UInt64
FailedReason UInt32
ReservationMode UInt32
DefaultReservation UInt64
LinkSpeedPct UInt32
LinkSpeed UInt64
LinkSpeedGuaranteePct UInt32
ReservableBw UInt64
AvailableBw Int64

Event ID 337

#
Channel
Operational

Fields #

NameDescription
SwitchName UnicodeString
LineId UInt64
FailedReason UInt32
ReservationMode UInt32
DefaultReservation UInt64
LinkSpeedPct UInt32
LinkSpeed UInt64
LinkSpeedGuaranteePct UInt32
ReservableBw UInt64
AvailableBw Int64

Event ID 338: QoS reservation for line LineId handles a new rate allocation event: AllocationEvent.

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Message #

QoS reservation for line %1 handles a new rate allocation event: %2

Fields #

NameDescription
LineId UInt64
AllocationEvent UInt32

Event ID 338

#
Channel
Operational

Description

QoS reservation for line handles a new rate allocation event.

Fields #

NameDescription
LineId UInt64
AllocationEvent UInt32

Event ID 339: QoS reservation for line LineId on switch SwitchName adds queue QueueName to the line.

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Message #

QoS reservation for line %2 on switch %1 adds queue %3 to the line

Fields #

NameDescription
SwitchName UnicodeString
LineId UInt64
QueueName UnicodeString

Event ID 339

#
Channel
Operational

Description

QoS reservation for line on switch adds queue to the line.

Fields #

NameDescription
SwitchName UnicodeString
LineId UInt64
QueueName UnicodeString

Event ID 340: QoS reservation for line LineId on switch SwitchName deletes queue QueueName from the line.

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Message #

QoS reservation for line %2 on switch %1 deletes queue %3 from the line

Fields #

NameDescription
SwitchName UnicodeString
LineId UInt64
QueueName UnicodeString

Event ID 340

#
Channel
Operational

Description

QoS reservation for line on switch deletes queue from the line.

Fields #

NameDescription
SwitchName UnicodeString
LineId UInt64
QueueName UnicodeString

Event ID 341: VfpExt QoS queue QueueName with EnforceIntraHostLimit=EnforceIntraHostLimit, TxCap=TransmitCap, TxMin=TransmitReservation, RxCap=ReceiveCap, TxQueueDepth=TransmitQueueDepth, RxQueueDepth=ReceiveQue...

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Message #

VfpExt QoS queue %1 with EnforceIntraHostLimit=%3, TxCap=%4, TxMin=%5, RxCap=%6, TxQueueDepth=%7, RxQueueDepth=%8, TxBurstSize=%9, RxBurstSize=%10, ResLowPct=%11, ResHighPct=%12, ResHeadroomPct=%13, ResRampupTime=%14, ResMinRate=%15, successfully performed action '%2'

Fields #

NameDescription
QueueName UnicodeString
Action UInt8
EnforceIntraHostLimit Boolean
TransmitCap UInt32
TransmitReservation UInt32
ReceiveCap UInt32
TransmitQueueDepth UInt32
ReceiveQueueDepth UInt32
TransmitBurstSize UInt32
ReceiveBurstSize UInt32
UnderUtilizedPct UInt8
OverUtilizedPct UInt8
HeadroomPct UInt8
RampupTimeMs UInt32
MinRateMbps UInt32

Event ID 341

#
Channel
Operational

Fields #

NameDescription
QueueName UnicodeString
Action UInt8
EnforceIntraHostLimit Boolean
TransmitCap UInt32
TransmitReservation UInt32
ReceiveCap UInt32
TransmitQueueDepth UInt32
ReceiveQueueDepth UInt32
TransmitBurstSize UInt32
ReceiveBurstSize UInt32
UnderUtilizedPct UInt8
OverUtilizedPct UInt8
HeadroomPct UInt8
RampupTimeMs UInt32
MinRateMbps UInt32

Event ID 342: VfpExt QoS queue QueueName with EnforceIntraHostLimit=EnforceIntraHostLimit, TxCap=TransmitCap, TxMin=TransmitReservation, RxCap=ReceiveCap, TxQueueDepth=TransmitQueueDepth, RxQueueDepth=ReceiveQue...

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Message #

VfpExt QoS queue %1 with EnforceIntraHostLimit=%3, TxCap=%4, TxMin=%5, RxCap=%6, TxQueueDepth=%9, RxQueueDepth=%10, TxBurstSize=%11, RxBurstSize=%12, ResLowPct=%13, ResHighPct=%14, ResHeadroomPct=%15, ResRampupTime=%16, ResMinRate=%17, failed action '%2' with reason '%8', status=%7

Fields #

NameDescription
QueueName UnicodeString
Action UInt8
EnforceIntraHostLimit Boolean
TransmitCap UInt32
TransmitReservation UInt32
ReceiveCap UInt32
Status UInt32NTSTATUS reference
FailReason UInt8
TransmitQueueDepth UInt32
ReceiveQueueDepth UInt32
TransmitBurstSize UInt32
ReceiveBurstSize UInt32
UnderUtilizedPct UInt8
OverUtilizedPct UInt8
HeadroomPct UInt8
RampupTimeMs UInt32
MinRateMbps UInt32

Event ID 342

#
Channel
Operational

Fields #

NameDescription
QueueName UnicodeString
Action UInt8
EnforceIntraHostLimit Boolean
TransmitCap UInt32
TransmitReservation UInt32
ReceiveCap UInt32
Status UInt32NTSTATUS reference
FailReason UInt8
TransmitQueueDepth UInt32
ReceiveQueueDepth UInt32
TransmitBurstSize UInt32
ReceiveBurstSize UInt32
UnderUtilizedPct UInt8
OverUtilizedPct UInt8
HeadroomPct UInt8
RampupTimeMs UInt32
MinRateMbps UInt32

Event ID 343: VfpExt QoS queue QueueName and port PortId successfully performed action 'Action'.

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Message #

VfpExt QoS queue %1 and port %2 successfully performed action '%3'

Fields #

NameDescription
QueueName UnicodeString
PortId UInt32
Action UInt8

Event ID 343

#
Channel
Operational

Description

VfpExt QoS queue QueueName and port PortId successfully performed action 'Action'.

Fields #

NameDescription
QueueName UnicodeString
PortId UInt32
Action UInt8

Event ID 344: VfpExt QoS queue QueueName and port PortId failed action 'Action' with reason 'FailReason', status=Status.

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Message #

VfpExt QoS queue %1 and port %2 failed action '%3' with reason '%5', status=%4

Fields #

NameDescription
QueueName UnicodeString
PortId UInt32
Action UInt8
Status UInt32NTSTATUS reference
FailReason UInt8

Event ID 344

#
Channel
Operational

Description

VfpExt QoS queue QueueName and port PortId failed action 'Action' with reason 'FailReason', status=Status.

Fields #

NameDescription
QueueName UnicodeString
PortId UInt32
Action UInt8
Status UInt32NTSTATUS reference
FailReason UInt8

Event ID 345: VfpExt QoS reservation on vswitch 'SwitchName' successfully performed action 'Operation', line info = {mode=ReservationMode, defaultRes=DefaultReservation, defaultQDepth=DefaultQueueDepth, defaultQ...

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Message #

VfpExt QoS reservation on vswitch '%1' successfully performed action '%2', line info = {mode=%3, defaultRes=%4, defaultQDepth=%11, defaultQBurstSize=%12, defaultQUnderUtilized=%13, defaultQOverUtilized=%14, defaultQHeadroom=%15, defaultQRampup=%16, defaultQueueMinRate=%17, NIC linkspeed=%6, res linkspeed pct=%5, DCB0 pct=%7, reservableBW=%8, availableBW=%9, numActiveQueues=%10}

Fields #

NameDescription
SwitchName UnicodeString
Operation UInt8
Known values
%%2456
Open key file.
%%2457
Delete key file.
%%2458
Read persisted key from file.
%%2459
Write persisted key to file.
%%2464
Export of persistent cryptographic key.
%%2465
Import of persistent cryptographic key.
%%2480
Open Key.
%%2481
Create Key.
%%2482
Delete Key.
%%2483
Encrypt.
%%2484
Decrypt.
%%2485
Sign hash.
%%2486
Secret agreement.
%%2487
Domain settings.
%%2488
Local settings.
%%2489
Add provider.
%%2490
Remove provider.
%%2491
Add context.
%%2492
Remove context.
%%2493
Add function.
%%2494
Remove function.
%%2495
Add function provider.
%%2496
Remove function provider.
%%2497
Add function property.
%%2498
Remove function property.
%%2499
Machine key.
%%2500
User key.
%%2501
Key Derivation.
%%2502
Claim Creation.
%%2503
Claim Verification.
ReservationMode UInt8
DefaultReservation UInt64
LinkSpeedPct UInt32
NicLinkSpeed UInt64
NicLinkSpeedGuarantee UInt32
ReservableBw UInt64
AvailableBw Int64
NumQueues UInt32
DefaultQueueDepth UInt32
DefaultQueueBurstSize UInt32
DefaultQueueUnderUtilizedPct UInt8
DefaultQueueOverUtilizedPct UInt8
DefaultQueueHeadroomPct UInt8
DefaultQueueRampupTimeMs UInt32
DefaultQueueMinRateMbps UInt32

Event ID 345

#
Channel
Operational

Fields #

NameDescription
SwitchName UnicodeString
Operation UInt8
Known values
%%2456
Open key file.
%%2457
Delete key file.
%%2458
Read persisted key from file.
%%2459
Write persisted key to file.
%%2464
Export of persistent cryptographic key.
%%2465
Import of persistent cryptographic key.
%%2480
Open Key.
%%2481
Create Key.
%%2482
Delete Key.
%%2483
Encrypt.
%%2484
Decrypt.
%%2485
Sign hash.
%%2486
Secret agreement.
%%2487
Domain settings.
%%2488
Local settings.
%%2489
Add provider.
%%2490
Remove provider.
%%2491
Add context.
%%2492
Remove context.
%%2493
Add function.
%%2494
Remove function.
%%2495
Add function provider.
%%2496
Remove function provider.
%%2497
Add function property.
%%2498
Remove function property.
%%2499
Machine key.
%%2500
User key.
%%2501
Key Derivation.
%%2502
Claim Creation.
%%2503
Claim Verification.
ReservationMode UInt8
DefaultReservation UInt64
LinkSpeedPct UInt32
NicLinkSpeed UInt64
NicLinkSpeedGuarantee UInt32
ReservableBw UInt64
AvailableBw Int64
NumQueues UInt32
DefaultQueueDepth UInt32
DefaultQueueBurstSize UInt32
DefaultQueueUnderUtilizedPct UInt8
DefaultQueueOverUtilizedPct UInt8
DefaultQueueHeadroomPct UInt8
DefaultQueueRampupTimeMs UInt32
DefaultQueueMinRateMbps UInt32

Event ID 346: VfpExt QoS reservation on vswitch 'SwitchName' failed action 'Operation' with reason 'FailReason', status=Status, failed config={mode=ReservationMode, defaultRes=DefaultReservation, defaultQDepth=D...

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Message #

VfpExt QoS reservation on vswitch '%1' failed action '%2' with reason '%11', status=%10, failed config={mode=%3, defaultRes=%4, defaultQDepth=%13, defaultQBurstSize=%14, defaultQUnderUtilized=%15, defaultQOverUtilized=%16, defaultQHeadroom=%17, defaultQRampup=%18, defaultQueueMinRate=%19, res linkspeed pct=%5}, line info= {NIC linkspeed=%6, DCB0 pct=%7, reservableBW=%8, availableBW=%9, numActiveQueues=%12}

Fields #

NameDescription
SwitchName UnicodeString
Operation UInt8
Known values
%%2456
Open key file.
%%2457
Delete key file.
%%2458
Read persisted key from file.
%%2459
Write persisted key to file.
%%2464
Export of persistent cryptographic key.
%%2465
Import of persistent cryptographic key.
%%2480
Open Key.
%%2481
Create Key.
%%2482
Delete Key.
%%2483
Encrypt.
%%2484
Decrypt.
%%2485
Sign hash.
%%2486
Secret agreement.
%%2487
Domain settings.
%%2488
Local settings.
%%2489
Add provider.
%%2490
Remove provider.
%%2491
Add context.
%%2492
Remove context.
%%2493
Add function.
%%2494
Remove function.
%%2495
Add function provider.
%%2496
Remove function provider.
%%2497
Add function property.
%%2498
Remove function property.
%%2499
Machine key.
%%2500
User key.
%%2501
Key Derivation.
%%2502
Claim Creation.
%%2503
Claim Verification.
ReservationMode UInt8
DefaultReservation UInt64
LinkSpeedPct UInt32
NicLinkSpeed UInt64
NicLinkSpeedGuarantee UInt32
ReservableBw UInt64
AvailableBw Int64
Status UInt32NTSTATUS reference
FailReason UInt8
NumQueues UInt32
DefaultQueueDepth UInt32
DefaultQueueBurstSize UInt32
DefaultQueueUnderUtilizedPct UInt8
DefaultQueueOverUtilizedPct UInt8
DefaultQueueHeadroomPct UInt8
DefaultQueueRampupTimeMs UInt32
DefaultQueueMinRateMbps UInt32

Event ID 346

#
Channel
Operational

Fields #

NameDescription
SwitchName UnicodeString
Operation UInt8
Known values
%%2456
Open key file.
%%2457
Delete key file.
%%2458
Read persisted key from file.
%%2459
Write persisted key to file.
%%2464
Export of persistent cryptographic key.
%%2465
Import of persistent cryptographic key.
%%2480
Open Key.
%%2481
Create Key.
%%2482
Delete Key.
%%2483
Encrypt.
%%2484
Decrypt.
%%2485
Sign hash.
%%2486
Secret agreement.
%%2487
Domain settings.
%%2488
Local settings.
%%2489
Add provider.
%%2490
Remove provider.
%%2491
Add context.
%%2492
Remove context.
%%2493
Add function.
%%2494
Remove function.
%%2495
Add function provider.
%%2496
Remove function provider.
%%2497
Add function property.
%%2498
Remove function property.
%%2499
Machine key.
%%2500
User key.
%%2501
Key Derivation.
%%2502
Claim Creation.
%%2503
Claim Verification.
ReservationMode UInt8
DefaultReservation UInt64
LinkSpeedPct UInt32
NicLinkSpeed UInt64
NicLinkSpeedGuarantee UInt32
ReservableBw UInt64
AvailableBw Int64
Status UInt32NTSTATUS reference
FailReason UInt8
NumQueues UInt32
DefaultQueueDepth UInt32
DefaultQueueBurstSize UInt32
DefaultQueueUnderUtilizedPct UInt8
DefaultQueueOverUtilizedPct UInt8
DefaultQueueHeadroomPct UInt8
DefaultQueueRampupTimeMs UInt32
DefaultQueueMinRateMbps UInt32

Event ID 347: VfpExt QoS reservation on vswitch 'SwitchName' got external NIC event 'Event', status='Status', line info = {mode=ReservationMode, default res=DefaultReservation, NIC linkspeed=NicLinkSpeed, res li...

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Message #

VfpExt QoS reservation on vswitch '%1' got external NIC event '%2', status='%10', line info = {mode=%3, default res=%4, NIC linkspeed=%6, res linkspeed pct=%5, DCB0 pct=%7, reservableBW=%8, availableBW=%9, numActiveQueues=%11}

Fields #

NameDescription
SwitchName UnicodeString
Event UInt8
ReservationMode UInt8
DefaultReservation UInt64
LinkSpeedPct UInt32
NicLinkSpeed UInt64
NicLinkSpeedGuarantee UInt32
ReservableBw UInt64
AvailableBw Int64
Status UInt32NTSTATUS reference
NumQueues UInt32

Event ID 347

#
Channel
Operational

Fields #

NameDescription
SwitchName UnicodeString
Event UInt8
ReservationMode UInt8
DefaultReservation UInt64
LinkSpeedPct UInt32
NicLinkSpeed UInt64
NicLinkSpeedGuarantee UInt32
ReservableBw UInt64
AvailableBw Int64
Status UInt32NTSTATUS reference
NumQueues UInt32

Event ID 348: VfpExt QoS reservation on vswitch 'SwitchName' and queue 'QueueName' with reservation QueueReservation successfully performed action 'Operation', line info = {mode=ReservationMode, default res=Defa...

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Message #

VfpExt QoS reservation on vswitch '%1' and queue '%2' with reservation %3 successfully performed action '%4', line info = {mode=%5, default res=%6, NIC linkspeed=%8, res linkspeed pct=%7, DCB0 pct=%9, reservableBW=%10, availableBW=%11, numActiveQueues=%12}

Fields #

NameDescription
SwitchName UnicodeString
QueueName UnicodeString
QueueReservation UInt64
Operation UInt8
Known values
%%2456
Open key file.
%%2457
Delete key file.
%%2458
Read persisted key from file.
%%2459
Write persisted key to file.
%%2464
Export of persistent cryptographic key.
%%2465
Import of persistent cryptographic key.
%%2480
Open Key.
%%2481
Create Key.
%%2482
Delete Key.
%%2483
Encrypt.
%%2484
Decrypt.
%%2485
Sign hash.
%%2486
Secret agreement.
%%2487
Domain settings.
%%2488
Local settings.
%%2489
Add provider.
%%2490
Remove provider.
%%2491
Add context.
%%2492
Remove context.
%%2493
Add function.
%%2494
Remove function.
%%2495
Add function provider.
%%2496
Remove function provider.
%%2497
Add function property.
%%2498
Remove function property.
%%2499
Machine key.
%%2500
User key.
%%2501
Key Derivation.
%%2502
Claim Creation.
%%2503
Claim Verification.
ReservationMode UInt8
DefaultReservation UInt64
LinkSpeedPct UInt32
NicLinkSpeed UInt64
NicLinkSpeedGuarantee UInt32
ReservableBw UInt64
AvailableBw Int64
NumQueues UInt32

Event ID 348

#
Channel
Operational

Fields #

NameDescription
SwitchName UnicodeString
QueueName UnicodeString
QueueReservation UInt64
Operation UInt8
Known values
%%2456
Open key file.
%%2457
Delete key file.
%%2458
Read persisted key from file.
%%2459
Write persisted key to file.
%%2464
Export of persistent cryptographic key.
%%2465
Import of persistent cryptographic key.
%%2480
Open Key.
%%2481
Create Key.
%%2482
Delete Key.
%%2483
Encrypt.
%%2484
Decrypt.
%%2485
Sign hash.
%%2486
Secret agreement.
%%2487
Domain settings.
%%2488
Local settings.
%%2489
Add provider.
%%2490
Remove provider.
%%2491
Add context.
%%2492
Remove context.
%%2493
Add function.
%%2494
Remove function.
%%2495
Add function provider.
%%2496
Remove function provider.
%%2497
Add function property.
%%2498
Remove function property.
%%2499
Machine key.
%%2500
User key.
%%2501
Key Derivation.
%%2502
Claim Creation.
%%2503
Claim Verification.
ReservationMode UInt8
DefaultReservation UInt64
LinkSpeedPct UInt32
NicLinkSpeed UInt64
NicLinkSpeedGuarantee UInt32
ReservableBw UInt64
AvailableBw Int64
NumQueues UInt32

Event ID 349: VfpExt QoS reservation (line:'LineId') has congestion control event 'Event'.

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Message #

VfpExt QoS reservation (line:'%1') has congestion control event '%2'

Fields #

NameDescription
LineId Pointer
Event UInt8

Event ID 349

#
Channel
Operational

Description

VfpExt QoS reservation (line:'LineId') has congestion control event 'Event'.

Fields #

NameDescription
LineId Pointer
Event UInt8

Event ID 351: VfpExt dropped a packet from port SrcPortId (Name = SrcPortName, FriendlyName = SrcPortFriendlyName) in forwarding because of Reason.

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Description

VfpExt dropped a packet from port SrcPortId (Name = SrcPortName, FriendlyName = SrcPortFriendlyName) in forwarding because of Reason. {src mac = SrcMacAddr, dst mac = DstMacAddr, type = Type, vlanID = VLAN}, gftFlags = GftFlags.

Message #

VfpExt dropped a packet from port %1 (Name = %7, FriendlyName = %8) in forwarding because of %2. {src mac = %3, dst mac = %4, type = %5, vlanID = %6}, gftFlags = %9

Fields #

NameDescription
SrcPortId UInt32
Reason UInt8
SrcMacAddr UnicodeString
DstMacAddr UnicodeString
Type UInt16
VLAN UInt32
SrcPortName UnicodeString
SrcPortFriendlyName UnicodeString
GftFlags UInt32

Event ID 351

#
Channel
Operational

Description

VfpExt dropped a packet from port (Name = , FriendlyName = ) in forwarding because of . {src mac = , dst mac = , type = , vlanID = }, gftFlags =.

Fields #

NameDescription
SrcPortId UInt32
Reason UInt8
SrcMacAddr UnicodeString
DstMacAddr UnicodeString
Type UInt16
VLAN UInt32
SrcPortName UnicodeString
SrcPortFriendlyName UnicodeString
GftFlags UInt32

Event ID 352: VfpExt successfully forwarded a packet from port SrcPortId (Name = SrcPortName, FriendlyName = SrcPortFriendlyName) to destination DstPortId (Name = DstPortName, FriendlyName = DstPortFriendlyName).

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Message #

VfpExt successfully forwarded a packet from port %1 (Name = %9, FriendlyName = %10) to destination %2 (Name = %11, FriendlyName = %12). {src mac = %3, dst mac = %4, type = %5, vlanID = %6, isBroadcast = %7, innerForwardingUsed = %8}, gftFlags = %13

Fields #

NameDescription
SrcPortId UInt32
DstPortId UInt32
SrcMacAddr UnicodeString
DstMacAddr UnicodeString
Type UInt16
VLAN UInt32
IsBroadcast Boolean
InnerForwarding Boolean
SrcPortName UnicodeString
SrcPortFriendlyName UnicodeString
DstPortName UnicodeString
DstPortFriendlyName UnicodeString
GftFlags UInt32

Event ID 352

#
Channel
Operational

Fields #

NameDescription
SrcPortId UInt32
DstPortId UInt32
SrcMacAddr UnicodeString
DstMacAddr UnicodeString
Type UInt16
VLAN UInt32
IsBroadcast Boolean
InnerForwarding Boolean
SrcPortName UnicodeString
SrcPortFriendlyName UnicodeString
DstPortName UnicodeString
DstPortFriendlyName UnicodeString
GftFlags UInt32

Event ID 353: VfpExt is skipping destination port DstPortId (Name = DstPortName, FriendlyName = DstPortFriendlyName) in broadcast list of packet from source port SrcPortId (Name = SrcPortName, FriendlyName = Src...

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Description

VfpExt is skipping destination port (Name = , FriendlyName = ) in broadcast list of packet from source port (Name = , FriendlyName = ). {src mac = , dst mac = , type = , vlanID = }, gftFlags =.

Message #

VfpExt is skipping destination port %2 (Name = %9, FriendlyName = %10) in broadcast list of packet from source port %1 (Name = %7, FriendlyName = %8). {src mac = %3, dst mac = %4, type = %5, vlanID = %6}, gftFlags = %11

Fields #

NameDescription
SrcPortId UInt32
DstPortId UInt32
SrcMacAddr UnicodeString
DstMacAddr UnicodeString
Type UInt16
VLAN UInt32
SrcPortName UnicodeString
SrcPortFriendlyName UnicodeString
DstPortName UnicodeString
DstPortFriendlyName UnicodeString
GftFlags UInt32

Event ID 353

#
Channel
Operational

Description

VfpExt is skipping destination port (Name = , FriendlyName = ) in broadcast list of packet from source port (Name = , FriendlyName = ). {src mac = , dst mac = , type = , vlanID = }, gftFlags =.

Fields #

NameDescription
SrcPortId UInt32
DstPortId UInt32
SrcMacAddr UnicodeString
DstMacAddr UnicodeString
Type UInt16
VLAN UInt32
SrcPortName UnicodeString
SrcPortFriendlyName UnicodeString
DstPortName UnicodeString
DstPortFriendlyName UnicodeString
GftFlags UInt32

Event ID 354: VfpExt failed to forward packet from source port SrcPortId (Name = SrcPortName, FriendlyName = SrcPortFriendlyName) based on inner headers, attempting to forward based on outer hea...

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Message #

VfpExt failed to forward packet from source port %1 (Name = %8, FriendlyName = %9) based on inner headers, attempting to forward based on outer headers. {outer src mac = %2, outer dst mac = %3, type = %4, inner dest mac = %5, vlan id = %6, isolation id = %7}, gftFlags = %10

Fields #

NameDescription
SrcPortId UInt32
OutSrcMacAddr UnicodeString
OutDstMacAddr UnicodeString
Type UInt16
InnerDstMacAddr UnicodeString
VLAN UInt32
IsolationId UInt32
SrcPortName UnicodeString
SrcPortFriendlyName UnicodeString
GftFlags UInt32

Event ID 354

#
Channel
Operational

Fields #

NameDescription
SrcPortId UInt32
OutSrcMacAddr UnicodeString
OutDstMacAddr UnicodeString
Type UInt16
InnerDstMacAddr UnicodeString
VLAN UInt32
IsolationId UInt32
SrcPortName UnicodeString
SrcPortFriendlyName UnicodeString
GftFlags UInt32

Event ID 355: The save operation for port SrcPortId (Name = PortName, FriendlyName = PortFriendlyName) failed with reason 'Reason'.

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Description

The save operation for port SrcPortId (Name = PortName, FriendlyName = PortFriendlyName) failed with reason 'Reason'. ExtendedData1: Ext1, ExtendedData2: Ext2.

Message #

The save operation for port %1 (Name = %5, FriendlyName = %6) failed with reason '%2'. ExtendedData1: %3, ExtendedData2: %4.

Fields #

NameDescription
SrcPortId UInt32
Reason UInt8
Ext1 UInt32
Ext2 UInt32
PortName UnicodeString
PortFriendlyName UnicodeString

Event ID 355

#
Channel
Operational

Description

The save operation for port SrcPortId (Name = PortName, FriendlyName = PortFriendlyName) failed with reason 'Reason'. ExtendedData1: Ext1, ExtendedData2: Ext2.

Fields #

NameDescription
SrcPortId UInt32
Reason UInt8
Ext1 UInt32
Ext2 UInt32
PortName UnicodeString
PortFriendlyName UnicodeString

Event ID 356: The save completion operation for port SrcPortId (Name = PortName, FriendlyName = PortFriendlyName) failed with reason 'Reason'.

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Description

The save completion operation for port SrcPortId (Name = PortName, FriendlyName = PortFriendlyName) failed with reason 'Reason'. ExtendedData1: Ext1, ExtendedData2: Ext2.

Message #

The save completion operation for port %1 (Name = %5, FriendlyName = %6) failed with reason '%2'. ExtendedData1: %3, ExtendedData2: %4.

Fields #

NameDescription
SrcPortId UInt32
Reason UInt8
Ext1 UInt32
Ext2 UInt32
PortName UnicodeString
PortFriendlyName UnicodeString

Event ID 356

#
Channel
Operational

Description

The save completion operation for port SrcPortId (Name = PortName, FriendlyName = PortFriendlyName) failed with reason 'Reason'. ExtendedData1: Ext1, ExtendedData2: Ext2.

Fields #

NameDescription
SrcPortId UInt32
Reason UInt8
Ext1 UInt32
Ext2 UInt32
PortName UnicodeString
PortFriendlyName UnicodeString

Event ID 357: The save operation for port SrcPortId (Name = PortName, FriendlyName = PortFriendlyName) failed with reason 'Reason'.

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Description

The save operation for port SrcPortId (Name = PortName, FriendlyName = PortFriendlyName) failed with reason 'Reason'. ExtendedData1: Ext1, ExtendedData2: Ext2.

Message #

The save operation for port %1 (Name = %5, FriendlyName = %6) failed with reason '%2'. ExtendedData1: %3, ExtendedData2: %4.

Fields #

NameDescription
SrcPortId UInt32
Reason UInt8
Ext1 UInt32
Ext2 UInt32
PortName UnicodeString
PortFriendlyName UnicodeString

Event ID 357

#
Channel
Operational

Description

The save operation for port SrcPortId (Name = PortName, FriendlyName = PortFriendlyName) failed with reason 'Reason'. ExtendedData1: Ext1, ExtendedData2: Ext2.

Fields #

NameDescription
SrcPortId UInt32
Reason UInt8
Ext1 UInt32
Ext2 UInt32
PortName UnicodeString
PortFriendlyName UnicodeString

Event ID 358: Succesfully saved port SrcPortId (Name = PortName, FriendlyName = PortFriendlyName).

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Description

Succesfully saved port SrcPortId (Name = PortName, FriendlyName = PortFriendlyName). Size: SaveDataSize, BlockPortOnRestore: BlockOnRestore.

Message #

Succesfully saved port %1 (Name = %4, FriendlyName = %5). Size: %2, BlockPortOnRestore: %3.

Fields #

NameDescription
SrcPortId UInt32
SaveDataSize UInt32
BlockOnRestore Boolean
PortName UnicodeString
PortFriendlyName UnicodeString

Event ID 358

#
Channel
Operational

Description

Succesfully saved port (Name = , FriendlyName = ). Size: , BlockPortOnRestore: .

Fields #

NameDescription
SrcPortId UInt32
SaveDataSize UInt32
BlockOnRestore Boolean
PortName UnicodeString
PortFriendlyName UnicodeString

Event ID 359: The overall save operation for port SrcPortId (Name = PortName, FriendlyName = PortFriendlyName) is complete.

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Message #

The overall save operation for port %1 (Name = %4, FriendlyName = %5) is complete.

Fields #

NameDescription
SrcPortId UInt32
SaveDataSize UInt32
BlockOnRestore Boolean
PortName UnicodeString
PortFriendlyName UnicodeString

Event ID 359

#
Channel
Operational

Description

The overall save operation for port (Name = , FriendlyName = ) is complete.

Fields #

NameDescription
SrcPortId UInt32
SaveDataSize UInt32
BlockOnRestore Boolean
PortName UnicodeString
PortFriendlyName UnicodeString

Event ID 360: Succesfully restored port SrcPortId (Name = PortName, FriendlyName = PortFriendlyName).

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Description

Succesfully restored port SrcPortId (Name = PortName, FriendlyName = PortFriendlyName). Size: SaveDataSize, Block State: BlockOnRestore.

Message #

Succesfully restored port %1 (Name = %4, FriendlyName = %5). Size: %2, Block State: %3.

Fields #

NameDescription
SrcPortId UInt32
SaveDataSize UInt32
BlockOnRestore Boolean
PortName UnicodeString
PortFriendlyName UnicodeString

Event ID 360

#
Channel
Operational

Description

Succesfully restored port (Name = , FriendlyName = ). Size: , Block State: .

Fields #

NameDescription
SrcPortId UInt32
SaveDataSize UInt32
BlockOnRestore Boolean
PortName UnicodeString
PortFriendlyName UnicodeString

Event ID 361: Save request for port SrcPortId (Name = PortName, FriendlyName = PortFriendlyName) returned to caller with a size request of SaveDataSize.

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Message #

Save request for port %1 (Name = %3, FriendlyName = %4) returned to caller with a size request of %2.

Fields #

NameDescription
SrcPortId UInt32
SaveDataSize UInt32
PortName UnicodeString
PortFriendlyName UnicodeString

Event ID 361

#
Channel
Operational

Description

Save request for port (Name = , FriendlyName = ) returned to caller with a size request of .

Fields #

NameDescription
SrcPortId UInt32
SaveDataSize UInt32
PortName UnicodeString
PortFriendlyName UnicodeString

Event ID 362: Save request for port SrcPortId (Name = PortName, FriendlyName = PortFriendlyName) allowed to proceed to the next component with reason 'Reason'.

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Message #

Save request for port %1 (Name = %5, FriendlyName = %6) allowed to proceed to the next component with reason '%4'.

Fields #

NameDescription
SrcPortId UInt32
MessageLength UInt32
Message UnicodeString
Reason UInt8
PortName UnicodeString
PortFriendlyName UnicodeString

Event ID 362

#
Channel
Operational

Description

Save request for port SrcPortId (Name = PortName, FriendlyName = PortFriendlyName) allowed to proceed to the next component with reason 'Reason'.

Fields #

NameDescription
SrcPortId UInt32
MessageLength UInt32
Message UnicodeString
Reason UInt8
PortName UnicodeString
PortFriendlyName UnicodeString

Event ID 363: Restore request for port SrcPortId (Name = PortName, FriendlyName = PortFriendlyName) ignored by extension 'Message' with reason 'Reason'.

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Message #

Restore request for port %1 (Name = %5, FriendlyName = %6) ignored by extension '%3' with reason '%4'.

Fields #

NameDescription
SrcPortId UInt32
MessageLength UInt32
Message UnicodeString
Reason UInt8
PortName UnicodeString
PortFriendlyName UnicodeString

Event ID 363

#
Channel
Operational

Description

Restore request for port SrcPortId (Name = PortName, FriendlyName = PortFriendlyName) ignored by extension 'Message' with reason 'Reason'.

Fields #

NameDescription
SrcPortId UInt32
MessageLength UInt32
Message UnicodeString
Reason UInt8
PortName UnicodeString
PortFriendlyName UnicodeString

Event ID 364: Restore request failure for port SrcPortId (Name = PortName, FriendlyName = PortFriendlyName) suppressed.

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Message #

Restore request failure for port %1 (Name = %4, FriendlyName = %5) suppressed

Fields #

NameDescription
SrcPortId UInt32
MessageLength UInt32
Message UnicodeString
PortName UnicodeString
PortFriendlyName UnicodeString

Event ID 364

#
Channel
Operational

Description

Restore request failure for port (Name = , FriendlyName = ) suppressed.

Fields #

NameDescription
SrcPortId UInt32
MessageLength UInt32
Message UnicodeString
PortName UnicodeString
PortFriendlyName UnicodeString

Event ID 400: RuleTyperule with ID RuleId processed Directionpackets on port PortId (Name = PortName, FriendlyName = PortFriendlyName) with status = Status and statusLocation = StatusLocation: flow ID {src ip = ...

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Message #

%6rule with ID %5 processed %2packets on port %1 (Name = %14, FriendlyName = %15) with status = %13 and statusLocation = %17: flow ID {src ip = %7, dst ip = %8, src port = %9, dst port = %10, protocol = %11, isTcpSyn = %12}, rule {layer = %3, group = %4, rule id = %5, gftFlags = %16}

Fields #

NameDescription
PortId UInt32
Direction UInt8
Known values
%%14592
Inbound
%%14593
Outbound
%%14594
Forward
%%14595
Bidirectional
LayerId UnicodeString
GroupId UnicodeString
RuleId UnicodeString
RuleType UInt8
SrcIpv4Addr UInt32
DstIpv4Addr UInt32
SrcPort UInt16
DstPort UInt16
IpProtocol UInt8
IsTcpSyn Boolean
Status UInt32NTSTATUS reference
PortName UnicodeString
PortFriendlyName UnicodeString
GftFlags UInt32
StatusLocation UInt32

Event ID 400

#
Channel
Operational

Fields #

NameDescription
PortId UInt32
Direction UInt8
Known values
%%14592
Inbound
%%14593
Outbound
%%14594
Forward
%%14595
Bidirectional
LayerId UnicodeString
GroupId UnicodeString
RuleId UnicodeString
RuleType UInt8
SrcIpv4Addr UInt32
DstIpv4Addr UInt32
SrcPort UInt16
DstPort UInt16
IpProtocol UInt8
IsTcpSyn Boolean
Status UInt32NTSTATUS reference
PortName UnicodeString
PortFriendlyName UnicodeString
GftFlags UInt32
StatusLocation UInt32

Event ID 401: RuleTyperule with ID RuleId processed Directionpackets on port PortId (Name = PortName, FriendlyName = PortFriendlyName) with status = Status and statusLocation = StatusLocation: flow ID {src ip = ...

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Message #

%6rule with ID %5 processed %2packets on port %1 (Name = %14, FriendlyName = %15) with status = %13 and statusLocation = %17: flow ID {src ip = %7, dst ip = %8, src port = %9, dst port = %10, protocol = %11, isTcpSyn = %12}, rule {layer = %3, group = %4, rule id = %5, gftFlags = %16}

Fields #

NameDescription
PortId UInt32
Direction UInt8
Known values
%%14592
Inbound
%%14593
Outbound
%%14594
Forward
%%14595
Bidirectional
LayerId UnicodeString
GroupId UnicodeString
RuleId UnicodeString
RuleType UInt8
SrcIpv6Addr Binary
DstIpv6Addr Binary
SrcPort UInt16
DstPort UInt16
IpProtocol UInt8
IsTcpSyn Boolean
Status UInt32NTSTATUS reference
PortName UnicodeString
PortFriendlyName UnicodeString
GftFlags UInt32
StatusLocation UInt32

Event ID 401

#
Channel
Operational

Fields #

NameDescription
PortId UInt32
Direction UInt8
Known values
%%14592
Inbound
%%14593
Outbound
%%14594
Forward
%%14595
Bidirectional
LayerId UnicodeString
GroupId UnicodeString
RuleId UnicodeString
RuleType UInt8
SrcIpv6Addr Binary
DstIpv6Addr Binary
SrcPort UInt16
DstPort UInt16
IpProtocol UInt8
IsTcpSyn Boolean
Status UInt32NTSTATUS reference
PortName UnicodeString
PortFriendlyName UnicodeString
GftFlags UInt32
StatusLocation UInt32

Event ID 402: RuleTyperule with ID RuleId processed Directionpackets on port PortId (Name = PortName, FriendlyName = PortFriendlyName) with status = Status and statusLocation = StatusLocation: flow id {src ip = ...

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Message #

%6rule with ID %5 processed %2packets on port %1 (Name = %12, FriendlyName = %13) with status = %11 and statusLocation = %15: flow id {src ip = %7, dst ip = %8, protocol = %9, icmp type = %10}, rule {layer = %3, group = %4, rule id = %5, gftFlags = %14}

Fields #

NameDescription
PortId UInt32
Direction UInt8
Known values
%%14592
Inbound
%%14593
Outbound
%%14594
Forward
%%14595
Bidirectional
LayerId UnicodeString
GroupId UnicodeString
RuleId UnicodeString
RuleType UInt8
SrcIpv4Addr UInt32
DstIpv4Addr UInt32
IpProtocol UInt8
IcmpType UInt8
Status UInt32NTSTATUS reference
PortName UnicodeString
PortFriendlyName UnicodeString
GftFlags UInt32
StatusLocation UInt32

Event ID 402

#
Channel
Operational

Fields #

NameDescription
PortId UInt32
Direction UInt8
Known values
%%14592
Inbound
%%14593
Outbound
%%14594
Forward
%%14595
Bidirectional
LayerId UnicodeString
GroupId UnicodeString
RuleId UnicodeString
RuleType UInt8
SrcIpv4Addr UInt32
DstIpv4Addr UInt32
IpProtocol UInt8
IcmpType UInt8
Status UInt32NTSTATUS reference
PortName UnicodeString
PortFriendlyName UnicodeString
GftFlags UInt32
StatusLocation UInt32

Event ID 403: RuleTyperule with ID RuleId processed Directionpackets on port PortId (Name = PortName, FriendlyName = PortFriendlyName) with status = Status and statusLocation = StatusLocation: flow id {src ip = ...

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Message #

%6rule with ID %5 processed %2packets on port %1 (Name = %12, FriendlyName = %13) with status = %11 and statusLocation = %15: flow id {src ip = %7, dst ip = %8, protocol = %9, icmp type = %10}, rule {layer = %3, group = %4, rule id = %5, gftFlags = %14}

Fields #

NameDescription
PortId UInt32
Direction UInt8
Known values
%%14592
Inbound
%%14593
Outbound
%%14594
Forward
%%14595
Bidirectional
LayerId UnicodeString
GroupId UnicodeString
RuleId UnicodeString
RuleType UInt8
SrcIpv6Addr Binary
DstIpv6Addr Binary
IpProtocol UInt8
IcmpType UInt8
Status UInt32NTSTATUS reference
PortName UnicodeString
PortFriendlyName UnicodeString
GftFlags UInt32
StatusLocation UInt32

Event ID 403

#
Channel
Operational

Fields #

NameDescription
PortId UInt32
Direction UInt8
Known values
%%14592
Inbound
%%14593
Outbound
%%14594
Forward
%%14595
Bidirectional
LayerId UnicodeString
GroupId UnicodeString
RuleId UnicodeString
RuleType UInt8
SrcIpv6Addr Binary
DstIpv6Addr Binary
IpProtocol UInt8
IcmpType UInt8
Status UInt32NTSTATUS reference
PortName UnicodeString
PortFriendlyName UnicodeString
GftFlags UInt32
StatusLocation UInt32

Event ID 404: RuleTyperule with ID RuleId processed Directionpackets on port PortId (Name = PortName, FriendlyName = PortFriendlyName) with status = Status and statusLocation = StatusLocation: flow id {src ip = ...

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Description

rule with ID processed packets on port (Name = , FriendlyName = ) with status = and statusLocation = : flow id {src ip = , dst ip = , gre key = }, rule {layer = , group = , rule id = , gftFlags = }.

Message #

%6rule with ID %5 processed %2packets on port %1 (Name = %11, FriendlyName = %12) with status = %10 and statusLocation = %14: flow id {src ip = %7, dst ip = %8, gre key = %9}, rule {layer = %3, group = %4, rule id = %5, gftFlags = %13}

Fields #

NameDescription
PortId UInt32
Direction UInt8
Known values
%%14592
Inbound
%%14593
Outbound
%%14594
Forward
%%14595
Bidirectional
LayerId UnicodeString
GroupId UnicodeString
RuleId UnicodeString
RuleType UInt8
SrcIpv4Addr UInt32
DstIpv4Addr UInt32
GreKey UInt32
Status UInt32NTSTATUS reference
PortName UnicodeString
PortFriendlyName UnicodeString
GftFlags UInt32
StatusLocation UInt32

Event ID 404

#
Channel
Operational

Description

rule with ID processed packets on port (Name = , FriendlyName = ) with status = and statusLocation = : flow id {src ip = , dst ip = , gre key = }, rule {layer = , group = , rule id = , gftFlags = }.

Fields #

NameDescription
PortId UInt32
Direction UInt8
Known values
%%14592
Inbound
%%14593
Outbound
%%14594
Forward
%%14595
Bidirectional
LayerId UnicodeString
GroupId UnicodeString
RuleId UnicodeString
RuleType UInt8
SrcIpv4Addr UInt32
DstIpv4Addr UInt32
GreKey UInt32
Status UInt32NTSTATUS reference
PortName UnicodeString
PortFriendlyName UnicodeString
GftFlags UInt32
StatusLocation UInt32

Event ID 405: RuleTyperule with ID RuleId processed Directionpackets on port PortId (Name = PortName, FriendlyName = PortFriendlyName) with status = Status and statusLocation = StatusLocation: flow id {src ip = ...

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Description

rule with ID processed packets on port (Name = , FriendlyName = ) with status = and statusLocation = : flow id {src ip = , dst ip = , gre key = }, rule {layer = , group = , rule id = , gftFlags = }.

Message #

%6rule with ID %5 processed %2packets on port %1 (Name = %11, FriendlyName = %12) with status = %10 and statusLocation = %14: flow id {src ip = %7, dst ip = %8, gre key = %9}, rule {layer = %3, group = %4, rule id = %5, gftFlags = %13}

Fields #

NameDescription
PortId UInt32
Direction UInt8
Known values
%%14592
Inbound
%%14593
Outbound
%%14594
Forward
%%14595
Bidirectional
LayerId UnicodeString
GroupId UnicodeString
RuleId UnicodeString
RuleType UInt8
SrcIpv6Addr Binary
DstIpv6Addr Binary
GreKey UInt32
Status UInt32NTSTATUS reference
PortName UnicodeString
PortFriendlyName UnicodeString
GftFlags UInt32
StatusLocation UInt32

Event ID 405

#
Channel
Operational

Description

rule with ID processed packets on port (Name = , FriendlyName = ) with status = and statusLocation = : flow id {src ip = , dst ip = , gre key = }, rule {layer = , group = , rule id = , gftFlags = }.

Fields #

NameDescription
PortId UInt32
Direction UInt8
Known values
%%14592
Inbound
%%14593
Outbound
%%14594
Forward
%%14595
Bidirectional
LayerId UnicodeString
GroupId UnicodeString
RuleId UnicodeString
RuleType UInt8
SrcIpv6Addr Binary
DstIpv6Addr Binary
GreKey UInt32
Status UInt32NTSTATUS reference
PortName UnicodeString
PortFriendlyName UnicodeString
GftFlags UInt32
StatusLocation UInt32

Event ID 451: Redirect for port PortId (Name = PortName, FriendlyName = PortFriendlyName) failed.

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Description

Redirect for port PortId (Name = PortName, FriendlyName = PortFriendlyName) failed. Reason: 'Reason'.

Message #

Redirect for port %1 (Name = %3, FriendlyName = %4) failed. Reason: '%2'.

Fields #

NameDescription
PortId UInt32
Reason UInt8
PortName UnicodeString
PortFriendlyName UnicodeString

Event ID 451

#
Channel
Operational

Description

Redirect for port PortId (Name = PortName, FriendlyName = PortFriendlyName) failed. Reason: 'Reason'.

Fields #

NameDescription
PortId UInt32
Reason UInt8
PortName UnicodeString
PortFriendlyName UnicodeString

Event ID 452: OID Oid issued on port ID PortId (Name = PortName, FriendlyName = PortFriendlyName).

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Description

OID Oid issued on port ID PortId (Name = PortName, FriendlyName = PortFriendlyName). Status: Status.

Message #

OID %2 issued on port ID %1 (Name = %4, FriendlyName = %5). Status: %3.

Fields #

NameDescription
PortId UInt32
Oid UInt32
Status UInt32NTSTATUS reference
PortName UnicodeString
PortFriendlyName UnicodeString

Event ID 452

#
Channel
Operational

Description

OID issued on port ID (Name = , FriendlyName = ). Status: .

Fields #

NameDescription
PortId UInt32
Oid UInt32
Status UInt32NTSTATUS reference
PortName UnicodeString
PortFriendlyName UnicodeString

Event ID 453: Status Indication code StatusCode from port ID PortId (Name = PortName, FriendlyName = PortFriendlyName).

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Message #

Status Indication code %2 from port ID %1 (Name = %3, FriendlyName = %4).

Fields #

NameDescription
PortId UInt32
StatusCode UInt32NTSTATUS reference
PortName UnicodeString
PortFriendlyName UnicodeString

Event ID 453

#
Channel
Operational

Description

Status Indication code from port ID (Name = , FriendlyName = ).

Fields #

NameDescription
PortId UInt32
StatusCode UInt32NTSTATUS reference
PortName UnicodeString
PortFriendlyName UnicodeString

Event ID 454: NDIS_OFFLOAD state in the context of Context.

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Message #

NDIS_OFFLOAD state in the context of %1. HeaderRevision %2, EncapsulationTypes %3, MaxHeaderSizeSupported %4, NvgreTransmitChecksumOffloadSupported %5, NvgreReceiveChecksumOffloadSupported %6, NvgreLsoV2Supported %7, NvgreRssSupported %8, NvgreVmqSupported %9, VxlanTransmitChecksumOffloadSupported %10, VxlanReceiveChecksumOffloadSupported %11, VxlanLsoV2Supported %12, VxlanRssSupported %13, VxlanVmqSupported %14, VxlanUDPPortNumber %15, VxlanUDPPortNumberConfigurable %16.

Fields #

NameDescription
Context UnicodeString
HeaderRevision UInt32
EncapsulationTypes UInt32
MaxHeaderSizeSupported UInt32
NvgreTransmitChecksumOffloadSupported UInt8
NvgreReceiveChecksumOffloadSupported UInt8
NvgreLsoV2Supported UInt8
NvgreRssSupported UInt8
NvgreVmqSupported UInt8
VxlanTransmitChecksumOffloadSupported UInt8
VxlanReceiveChecksumOffloadSupported UInt8
VxlanLsoV2Supported UInt8
VxlanRssSupported UInt8
VxlanVmqSupported UInt8
VxlanUDPPortNumber UInt16
VxlanUDPPortNumberConfigurable Boolean

Event ID 454

#
Channel
Operational

Fields #

NameDescription
Context UnicodeString
HeaderRevision UInt32
EncapsulationTypes UInt32
MaxHeaderSizeSupported UInt32
NvgreTransmitChecksumOffloadSupported UInt8
NvgreReceiveChecksumOffloadSupported UInt8
NvgreLsoV2Supported UInt8
NvgreRssSupported UInt8
NvgreVmqSupported UInt8
VxlanTransmitChecksumOffloadSupported UInt8
VxlanReceiveChecksumOffloadSupported UInt8
VxlanLsoV2Supported UInt8
VxlanRssSupported UInt8
VxlanVmqSupported UInt8
VxlanUDPPortNumber UInt16
VxlanUDPPortNumberConfigurable Boolean

Event ID 455: OID_RECEIVE_FILTER_SET_FILTER for port ID PortId (Name = PortName, FriendlyName = PortFriendlyName).

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Description

OID_RECEIVE_FILTER_SET_FILTER for port ID PortId (Name = PortName, FriendlyName = PortFriendlyName). Inner Mac VMQ Setting Enabled = InnerMacVmqSettingEnabled, MAC address on filter MacAddress, Inner Mac Flag Set = InnerMacFilterSet.

Message #

OID_RECEIVE_FILTER_SET_FILTER for port ID %2 (Name = %5, FriendlyName = %6). Inner Mac VMQ Setting Enabled = %1, MAC address on filter %3, Inner Mac Flag Set = %4.

Fields #

NameDescription
InnerMacVmqSettingEnabled Boolean
PortId UInt32
MacAddress UnicodeString
InnerMacFilterSet Boolean
PortName UnicodeString
PortFriendlyName UnicodeString

Event ID 455

#
Channel
Operational

Description

OID_RECEIVE_FILTER_SET_FILTER for port ID (Name = , FriendlyName = ). Inner Mac VMQ Setting Enabled = , MAC address on filter , Inner Mac Flag Set = .

Fields #

NameDescription
InnerMacVmqSettingEnabled Boolean
PortId UInt32
MacAddress UnicodeString
InnerMacFilterSet Boolean
PortName UnicodeString
PortFriendlyName UnicodeString

Event ID 456: PA route rule update callback: { rule context RuleContext, elapsed time ElapsedTime, cache pruning timeout CachePruningTimeout, cache pruning threshold CachePruningThreshold, ND entries NumNdEntrie...

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Description

PA route rule update callback: { rule context RuleContext, elapsed time ElapsedTime, cache pruning timeout CachePruningTimeout, cache pruning threshold CachePruningThreshold, ND entries NumNdEntries }.

Message #

PA route rule update callback: { rule context %1, elapsed time %2, cache pruning timeout %3, cache pruning threshold %4, ND entries %5 }

Fields #

NameDescription
RuleContext Pointer
ElapsedTime UInt32
CachePruningTimeout UInt32
CachePruningThreshold UInt32
NumNdEntries UInt32

Event ID 456

#
Channel
Operational

Description

PA route rule update callback: { rule context , elapsed time , cache pruning timeout , cache pruning threshold , ND entries }.

Fields #

NameDescription
RuleContext Pointer
ElapsedTime UInt32
CachePruningTimeout UInt32
CachePruningThreshold UInt32
NumNdEntries UInt32

Event ID 500: DTLS Session {Port PortId (Name = PortName, FriendlyName = PortFriendlyName), Session ID SessionId} {Port PortId Peer Outer IP PeerOuterIpv4Addr, Peer Inner MAC PeerInnerMacAddr, TNI TNI, Tunnel ID...

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Description

DTLS Session {Port (Name = , FriendlyName = ), Session ID } {Port Peer Outer IP , Peer Inner MAC , TNI , Tunnel ID } Called security API with select params , , and returned status .

Message #

DTLS Session {Port %1 (Name = %13, FriendlyName = %14), Session ID %2} {Port %1 Peer Outer IP %3, Peer Inner MAC %4, TNI %5, Tunnel ID %6} Called  security API %7 with select params %8, %9, %10 and %11 returned status %12.

Fields #

NameDescription
PortId UInt32
SessionId UInt32
PeerOuterIpv4Addr UInt32
PeerInnerMacAddr UnicodeString
TNI UInt64
TunnelID UInt32
SecurityApiName UnicodeString
SelectParamInfo1 UnicodeString
SelectParamInfo2 UnicodeString
SelectParamInfo3 UInt64
SelectParamInfo4 UInt64
Status UInt32NTSTATUS reference
PortName UnicodeString
PortFriendlyName UnicodeString

Event ID 500

#
Channel
Operational

Description

DTLS Session {Port (Name = , FriendlyName = ), Session ID } {Port Peer Outer IP , Peer Inner MAC , TNI , Tunnel ID } Called security API with select params , , and returned status .

Fields #

NameDescription
PortId UInt32
SessionId UInt32
PeerOuterIpv4Addr UInt32
PeerInnerMacAddr UnicodeString
TNI UInt64
TunnelID UInt32
SecurityApiName UnicodeString
SelectParamInfo1 UnicodeString
SelectParamInfo2 UnicodeString
SelectParamInfo3 UInt64
SelectParamInfo4 UInt64
Status UInt32NTSTATUS reference
PortName UnicodeString
PortFriendlyName UnicodeString

Event ID 501: DTLS Session {Port PortId (Name = PortName, FriendlyName = PortFriendlyName), Session ID SessionId} {Port PortId Peer Outer IP PeerOuterIpv4Addr, Peer Inner MAC PeerInnerMacAddr, TNI TNI, Tunnel ID...

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Description

DTLS Session {Port PortId (Name = PortName, FriendlyName = PortFriendlyName), Session ID SessionId} {Port PortId Peer Outer IP PeerOuterIpv4Addr, Peer Inner MAC PeerInnerMacAddr, TNI TNI, Tunnel ID TunnelID} Handshake fatal error: FailureReason.

Message #

DTLS Session {Port %1 (Name = %8, FriendlyName = %9), Session ID %2} {Port %1 Peer Outer IP %3, Peer Inner MAC %4, TNI %5, Tunnel ID %6}  Handshake fatal error: %7.

Fields #

NameDescription
PortId UInt32
SessionId UInt32
PeerOuterIpv4Addr UInt32
PeerInnerMacAddr UnicodeString
TNI UInt64
TunnelID UInt32
FailureReason UnicodeString
Known values
%%2304
An Error occured during Logon.
%%2305
The specified user account has expired.
%%2306
The NetLogon component is not active.
%%2307
Account locked out.
%%2308
The user has not been granted the requested logon type at this machine.
%%2309
The specified account's password has expired.
%%2310
Account currently disabled.
%%2311
Account logon time restriction violation.
%%2312
User not allowed to logon at this computer.
%%2313
Unknown user name or bad password.
%%2314
Domain sid inconsistent.
%%2315
Smartcard logon is required and was not used.
PortName UnicodeString
PortFriendlyName UnicodeString

Event ID 501

#
Channel
Operational

Description

DTLS Session {Port (Name = , FriendlyName = ), Session ID } {Port Peer Outer IP , Peer Inner MAC , TNI , Tunnel ID } Handshake fatal error: .

Fields #

NameDescription
PortId UInt32
SessionId UInt32
PeerOuterIpv4Addr UInt32
PeerInnerMacAddr UnicodeString
TNI UInt64
TunnelID UInt32
FailureReason UnicodeString
Known values
%%2304
An Error occured during Logon.
%%2305
The specified user account has expired.
%%2306
The NetLogon component is not active.
%%2307
Account locked out.
%%2308
The user has not been granted the requested logon type at this machine.
%%2309
The specified account's password has expired.
%%2310
Account currently disabled.
%%2311
Account logon time restriction violation.
%%2312
User not allowed to logon at this computer.
%%2313
Unknown user name or bad password.
%%2314
Domain sid inconsistent.
%%2315
Smartcard logon is required and was not used.
PortName UnicodeString
PortFriendlyName UnicodeString

Event ID 502: DTLS Session {Port PortId (Name = PortName, FriendlyName = PortFriendlyName), Session ID SessionId} {Port PortId Peer Outer IP PeerOuterIpv4Addr, Peer Inner MAC PeerInnerMacAddr, TNI TNI, Tunnel ID...

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Description

DTLS Session {Port PortId (Name = PortName, FriendlyName = PortFriendlyName), Session ID SessionId} {Port PortId Peer Outer IP PeerOuterIpv4Addr, Peer Inner MAC PeerInnerMacAddr, TNI TNI, Tunnel ID TunnelID} Transition state from OldState to NewState. Reason: DeactivateReason.

Message #

DTLS Session {Port %1 (Name = %10, FriendlyName = %11), Session ID %2} {Port %1 Peer Outer IP %3, Peer Inner MAC %4, TNI %5, Tunnel ID %6}  Transition state from %7 to %8. Reason: %9

Fields #

NameDescription
PortId UInt32
SessionId UInt32
PeerOuterIpv4Addr UInt32
PeerInnerMacAddr UnicodeString
TNI UInt64
TunnelID UInt32
OldState UInt8
NewState UInt8
DeactivateReason UInt8
PortName UnicodeString
PortFriendlyName UnicodeString

Event ID 502

#
Channel
Operational

Description

DTLS Session {Port (Name = , FriendlyName = ), Session ID } {Port Peer Outer IP , Peer Inner MAC , TNI , Tunnel ID } Transition state from to . Reason.

Fields #

NameDescription
PortId UInt32
SessionId UInt32
PeerOuterIpv4Addr UInt32
PeerInnerMacAddr UnicodeString
TNI UInt64
TunnelID UInt32
OldState UInt8
NewState UInt8
DeactivateReason UInt8
PortName UnicodeString
PortFriendlyName UnicodeString

Event ID 503: DTLS Session {Port PortId (Name = PortName, FriendlyName = PortFriendlyName), Session ID SessionId} {Port PortId Peer Outer IP PeerOuterIpv4Addr, Peer Inner MAC PeerInnerMacAddr, TNI TNI, Tunnel ID...

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Description

DTLS Session {Port (Name = , FriendlyName = ), Session ID } {Port Peer Outer IP , Peer Inner MAC , TNI , Tunnel ID } DTLS packet direction Content Type , Handshake Protocol.

Message #

DTLS Session {Port %1 (Name = %10, FriendlyName = %11), Session ID %2} {Port %1 Peer Outer IP %3, Peer Inner MAC %4, TNI %5, Tunnel ID %6}  DTLS packet direction %7 Content Type %8, Handshake Protocol %9

Fields #

NameDescription
PortId UInt32
SessionId UInt32
PeerOuterIpv4Addr UInt32
PeerInnerMacAddr UnicodeString
TNI UInt64
TunnelID UInt32
Direction UInt8
Known values
%%14592
Inbound
%%14593
Outbound
%%14594
Forward
%%14595
Bidirectional
DtlsContentType UInt8
DtlsHandshakeProtocol UInt8
PortName UnicodeString
PortFriendlyName UnicodeString

Event ID 503

#
Channel
Operational

Description

DTLS Session {Port (Name = , FriendlyName = ), Session ID } {Port Peer Outer IP , Peer Inner MAC , TNI , Tunnel ID } DTLS packet direction Content Type , Handshake Protocol.

Fields #

NameDescription
PortId UInt32
SessionId UInt32
PeerOuterIpv4Addr UInt32
PeerInnerMacAddr UnicodeString
TNI UInt64
TunnelID UInt32
Direction UInt8
Known values
%%14592
Inbound
%%14593
Outbound
%%14594
Forward
%%14595
Bidirectional
DtlsContentType UInt8
DtlsHandshakeProtocol UInt8
PortName UnicodeString
PortFriendlyName UnicodeString

Event ID 504: DTLS Session {Port PortId (Name = PortName, FriendlyName = PortFriendlyName), Session ID SessionId} {Port PortId Peer Outer IP PeerOuterIpv4Addr, Peer Inner MAC PeerInnerMacAddr, TNI TNI, Tunnel ID...

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Description

DTLS Session {Port PortId (Name = PortName, FriendlyName = PortFriendlyName), Session ID SessionId} {Port PortId Peer Outer IP PeerOuterIpv4Addr, Peer Inner MAC PeerInnerMacAddr, TNI TNI, Tunnel ID TunnelID} TraceString.

Message #

DTLS Session {Port %1 (Name = %8, FriendlyName = %9), Session ID %2} {Port %1 Peer Outer IP %3, Peer Inner MAC %4, TNI %5, Tunnel ID %6}  %7

Fields #

NameDescription
PortId UInt32
SessionId UInt32
PeerOuterIpv4Addr UInt32
PeerInnerMacAddr UnicodeString
TNI UInt64
TunnelID UInt32
TraceString UnicodeString
PortName UnicodeString
PortFriendlyName UnicodeString

Event ID 504

#
Channel
Operational

Description

DTLS Session {Port (Name = , FriendlyName = ), Session ID } {Port Peer Outer IP , Peer Inner MAC , TNI , Tunnel ID }.

Fields #

NameDescription
PortId UInt32
SessionId UInt32
PeerOuterIpv4Addr UInt32
PeerInnerMacAddr UnicodeString
TNI UInt64
TunnelID UInt32
TraceString UnicodeString
PortName UnicodeString
PortFriendlyName UnicodeString

Event ID 505: DTLS Session {Port PortId (Name = PortName, FriendlyName = PortFriendlyName), Session ID SessionId} {Port PortId Peer Outer IP PeerOuterIpv4Addr, Peer Inner MAC PeerInnerMacAddr, TNI TNI, Tunnel ID...

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Description

DTLS Session {Port (Name = , FriendlyName = ), Session ID } {Port Peer Outer IP , Peer Inner MAC , TNI , Tunnel ID } . Numeric params: Str params.

Message #

DTLS Session {Port %1 (Name = %12, FriendlyName = %13), Session ID %2} {Port %1 Peer Outer IP %3, Peer Inner MAC %4, TNI %5, Tunnel ID %6}  %7.  Numeric params:%8 %9 Str params: %10 %11

Fields #

NameDescription
PortId UInt32
SessionId UInt32
PeerOuterIpv4Addr UInt32
PeerInnerMacAddr UnicodeString
TNI UInt64
TunnelID UInt32
TraceString UnicodeString
GenericNumericParam1 UInt64
GenericNumericParam2 UInt64
GenericStringParam1 UnicodeString
GenericStringParam2 UnicodeString
PortName UnicodeString
PortFriendlyName UnicodeString

Event ID 505

#
Channel
Operational

Description

DTLS Session {Port (Name = , FriendlyName = ), Session ID } {Port Peer Outer IP , Peer Inner MAC , TNI , Tunnel ID } . Numeric params: Str params.

Fields #

NameDescription
PortId UInt32
SessionId UInt32
PeerOuterIpv4Addr UInt32
PeerInnerMacAddr UnicodeString
TNI UInt64
TunnelID UInt32
TraceString UnicodeString
GenericNumericParam1 UInt64
GenericNumericParam2 UInt64
GenericStringParam1 UnicodeString
GenericStringParam2 UnicodeString
PortName UnicodeString
PortFriendlyName UnicodeString

Event ID 506: DTLS on Port PortId.

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Description

DTLS on Port PortId ((Name = PortName, FriendlyName = PortFriendlyName) TraceString.

Message #

DTLS on Port %1 ((Name = %3, FriendlyName = %4) %2

Fields #

NameDescription
PortId UInt32
TraceString UnicodeString
PortName UnicodeString
PortFriendlyName UnicodeString

Event ID 506

#
Channel
Operational

Description

DTLS on Port ((Name = , FriendlyName = ).

Fields #

NameDescription
PortId UInt32
TraceString UnicodeString
PortName UnicodeString
PortFriendlyName UnicodeString

Event ID 507: DTLS Session {Port PortId (Name = PortName, FriendlyName = PortFriendlyName), Session ID SessionId} {Port PortId Peer Outer IP PeerOuterIpv4Addr, Peer Inner MAC PeerInnerMacAddr, TNI TNI, Tunnel ID...

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Description

DTLS Session {Port PortId (Name = PortName, FriendlyName = PortFriendlyName), Session ID SessionId} {Port PortId Peer Outer IP PeerOuterIpv4Addr, Peer Inner MAC PeerInnerMacAddr, TNI TNI, Tunnel ID TunnelID} TraceString.

Message #

DTLS Session {Port %1 (Name = %8, FriendlyName = %9), Session ID %2} {Port %1 Peer Outer IP %3, Peer Inner MAC %4, TNI %5, Tunnel ID %6}  %7

Fields #

NameDescription
PortId UInt32
SessionId UInt32
PeerOuterIpv4Addr UInt32
PeerInnerMacAddr UnicodeString
TNI UInt64
TunnelID UInt32
TraceString UnicodeString
PortName UnicodeString
PortFriendlyName UnicodeString

Event ID 507

#
Channel
Operational

Description

DTLS Session {Port (Name = , FriendlyName = ), Session ID } {Port Peer Outer IP , Peer Inner MAC , TNI , Tunnel ID }.

Fields #

NameDescription
PortId UInt32
SessionId UInt32
PeerOuterIpv4Addr UInt32
PeerInnerMacAddr UnicodeString
TNI UInt64
TunnelID UInt32
TraceString UnicodeString
PortName UnicodeString
PortFriendlyName UnicodeString

Event ID 508: DTLS Session {Port PortId (Name = PortName, FriendlyName = PortFriendlyName), Session ID SessionId} {Port PortId Peer Outer IP PeerOuterIpv4Addr, Peer Inner MAC PeerInnerMacAddr, TNI TNI, Tunnel ID...

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Description

DTLS Session {Port (Name = , FriendlyName = ), Session ID } {Port Peer Outer IP , Peer Inner MAC , TNI , Tunnel ID } . Numeric params: Str params.

Message #

DTLS Session {Port %1 (Name = %12, FriendlyName = %13), Session ID %2} {Port %1 Peer Outer IP %3, Peer Inner MAC %4, TNI %5, Tunnel ID %6}  %7.  Numeric params:%8 %9 Str params: %10 %11

Fields #

NameDescription
PortId UInt32
SessionId UInt32
PeerOuterIpv4Addr UInt32
PeerInnerMacAddr UnicodeString
TNI UInt64
TunnelID UInt32
TraceString UnicodeString
GenericNumericParam1 UInt64
GenericNumericParam2 UInt64
GenericStringParam1 UnicodeString
GenericStringParam2 UnicodeString
PortName UnicodeString
PortFriendlyName UnicodeString

Event ID 508

#
Channel
Operational

Description

DTLS Session {Port (Name = , FriendlyName = ), Session ID } {Port Peer Outer IP , Peer Inner MAC , TNI , Tunnel ID } . Numeric params: Str params.

Fields #

NameDescription
PortId UInt32
SessionId UInt32
PeerOuterIpv4Addr UInt32
PeerInnerMacAddr UnicodeString
TNI UInt64
TunnelID UInt32
TraceString UnicodeString
GenericNumericParam1 UInt64
GenericNumericParam2 UInt64
GenericStringParam1 UnicodeString
GenericStringParam2 UnicodeString
PortName UnicodeString
PortFriendlyName UnicodeString

Event ID 509: PADiscoveryEvent port PortId (Name = PortName, FriendlyName = PortFriendlyName) direction Direction state PADiscoveryFlowState flow id {src ip = SrcIpv4Addr, dst ip = DstIpv4Addr, src port = SrcPor...

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Description

PADiscoveryEvent port (Name = , FriendlyName = ) direction state flow id {src ip = , dst ip = , src port = , dst port = , protocol = } DiscoveryType = PADiscovered = message =.

Message #

PADiscoveryEvent port %1 (Name = %12, FriendlyName = %13) direction %2 state %3 flow id {src ip = %4, dst ip = %5, src port = %6, dst port = %7, protocol = %8} DiscoveryType = %9 PADiscovered = %10  message = %11

Fields #

NameDescription
PortId UInt32
Direction UInt8
Known values
%%14592
Inbound
%%14593
Outbound
%%14594
Forward
%%14595
Bidirectional
PADiscoveryFlowState UInt8
SrcIpv4Addr UInt32
DstIpv4Addr UInt32
SrcPort UInt16
DstPort UInt16
IpProtocol UInt8
PADiscoveryType UInt8
DiscoveredIpv4Addr UInt32
TraceString UnicodeString
PortName UnicodeString
PortFriendlyName UnicodeString

Event ID 509

#
Channel
Operational

Description

PADiscoveryEvent port (Name = , FriendlyName = ) direction state flow id {src ip = , dst ip = , src port = , dst port = , protocol = } DiscoveryType = PADiscovered = message =.

Fields #

NameDescription
PortId UInt32
Direction UInt8
Known values
%%14592
Inbound
%%14593
Outbound
%%14594
Forward
%%14595
Bidirectional
PADiscoveryFlowState UInt8
SrcIpv4Addr UInt32
DstIpv4Addr UInt32
SrcPort UInt16
DstPort UInt16
IpProtocol UInt8
PADiscoveryType UInt8
DiscoveredIpv4Addr UInt32
TraceString UnicodeString
PortName UnicodeString
PortFriendlyName UnicodeString

Event ID 551: Port PortId (Name = PortName, FriendlyName = PortFriendlyName) parsed DHCP packet Operation:Operation MessageType:Message ClientIp:ClientIp ClientMac:ClientMac TransactionId:TransactionId AssignedI...

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Message #

Port %1 (Name = %16, FriendlyName = %17) parsed DHCP packet Operation:%2 MessageType:%3 ClientIp:%4 ClientMac:%5 TransactionId:%6 AssignedIp:%7 ServerIp:%8 RequestedIp:%9 RelayIp:%10 DnsIp:%11 SrcIp=>SrcPort:%12=>%13 DstIp=>DstPort:%14=>%15. GftFlags = %18

Fields #

NameDescription
PortId UInt32
Operation UInt8
Known values
%%2456
Open key file.
%%2457
Delete key file.
%%2458
Read persisted key from file.
%%2459
Write persisted key to file.
%%2464
Export of persistent cryptographic key.
%%2465
Import of persistent cryptographic key.
%%2480
Open Key.
%%2481
Create Key.
%%2482
Delete Key.
%%2483
Encrypt.
%%2484
Decrypt.
%%2485
Sign hash.
%%2486
Secret agreement.
%%2487
Domain settings.
%%2488
Local settings.
%%2489
Add provider.
%%2490
Remove provider.
%%2491
Add context.
%%2492
Remove context.
%%2493
Add function.
%%2494
Remove function.
%%2495
Add function provider.
%%2496
Remove function provider.
%%2497
Add function property.
%%2498
Remove function property.
%%2499
Machine key.
%%2500
User key.
%%2501
Key Derivation.
%%2502
Claim Creation.
%%2503
Claim Verification.
Message UInt8
ClientIp UInt32
ClientMac UnicodeString
TransactionId UInt32
AssignedIp UInt32
ServerIp UInt32
RequestedIp UInt32
RelayIp UInt32
DnsIp UInt32
SrcIp UInt32
SrcPort UInt16
DstIp UInt32
DstPort UInt16
PortName UnicodeString
PortFriendlyName UnicodeString
GftFlags UInt32

Event ID 551

#
Channel
Operational

Fields #

NameDescription
PortId UInt32
Operation UInt8
Known values
%%2456
Open key file.
%%2457
Delete key file.
%%2458
Read persisted key from file.
%%2459
Write persisted key to file.
%%2464
Export of persistent cryptographic key.
%%2465
Import of persistent cryptographic key.
%%2480
Open Key.
%%2481
Create Key.
%%2482
Delete Key.
%%2483
Encrypt.
%%2484
Decrypt.
%%2485
Sign hash.
%%2486
Secret agreement.
%%2487
Domain settings.
%%2488
Local settings.
%%2489
Add provider.
%%2490
Remove provider.
%%2491
Add context.
%%2492
Remove context.
%%2493
Add function.
%%2494
Remove function.
%%2495
Add function provider.
%%2496
Remove function provider.
%%2497
Add function property.
%%2498
Remove function property.
%%2499
Machine key.
%%2500
User key.
%%2501
Key Derivation.
%%2502
Claim Creation.
%%2503
Claim Verification.
Message UInt8
ClientIp UInt32
ClientMac UnicodeString
TransactionId UInt32
AssignedIp UInt32
ServerIp UInt32
RequestedIp UInt32
RelayIp UInt32
DnsIp UInt32
SrcIp UInt32
SrcPort UInt16
DstIp UInt32
DstPort UInt16
PortName UnicodeString
PortFriendlyName UnicodeString
GftFlags UInt32

Event ID 600: VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) created Direction unified flow UnifiedFlow: IsMain=IsMain, IsPending=IsPending, IsSecondary=IsSecondary, IsMirror=IsMirror, ...

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Message #

VfpExt on port %1 (Name = %33, FriendlyName = %34) created %2 unified flow %35: IsMain=%3, IsPending=%4, IsSecondary=%36, IsMirror=%37, IsHairpin=%38, HairpinChecked=%39, OriginalInbound=%40, IsTcpSyn=%29, Tni=%5, VlanId=%6, NumEncaps=%7, {EncapFlowId0 (EncapType=%8, SrcMac=%9, DestMac=%10, SrcIp=%11, DestIp=%12, TenantId=%13, EncryptVlanId=%14) EncapFlowId1 (EncapType=%15, SrcMac=%16, DestMac=%17, SrcIp=%18, DestIp=%19, TenantId=%20, EncryptVlanId=%21) InnerFlowId (Protocol=%22, SrcMac=%23, DestMac=%24, SrcIp=%25, DestIp=%26, SrcPort=%27, DestPort=%28)}, {EncapTransposition0 (%30), EncapTransposition1 (%31), InnerTransposition (%32)}

Fields #

NameDescription
PortId UInt32
Direction UInt8
Known values
%%14592
Inbound
%%14593
Outbound
%%14594
Forward
%%14595
Bidirectional
IsMain UInt8
IsPending UInt8
TNI UInt64
VLAN UInt32
NumEncaps UInt8
EncapType0 AnsiString
EncapSrcMacAddr0 UnicodeString
EncapDestMacAddr0 UnicodeString
EncapSrcIpv4Addr0 UInt32
EncapDstIpv4Addr0 UInt32
TenantId0 UInt32
EncryptVxlanId0 UInt32
EncapType1 AnsiString
EncapSrcMacAddr1 UnicodeString
EncapDestMacAddr1 UnicodeString
EncapSrcIpv4Addr1 UInt32
EncapDstIpv4Addr1 UInt32
TenantId1 UInt32
EncryptVxlanId1 UInt32
IpProtocol UInt8
SrcMacAddr UnicodeString
DestMacAddr UnicodeString
SrcIpv4Addr UInt32
DstIpv4Addr UInt32
SrcPort UInt16
DstPort UInt16
IsTcpSyn Boolean
EncapTransposition0 AnsiString
EncapTransposition1 AnsiString
Transposition AnsiString
PortName UnicodeString
PortFriendlyName UnicodeString
UnifiedFlow UInt64
IsSecondary UInt8
IsMirror UInt8
IsHairpin UInt8
HairpinChecked UInt8
OriginalInbound UInt8

Event ID 600

#
Channel
Operational

Fields #

NameDescription
PortId UInt32
Direction UInt8
Known values
%%14592
Inbound
%%14593
Outbound
%%14594
Forward
%%14595
Bidirectional
IsMain UInt8
IsPending UInt8
TNI UInt64
VLAN UInt32
NumEncaps UInt8
EncapType0 AnsiString
EncapSrcMacAddr0 UnicodeString
EncapDestMacAddr0 UnicodeString
EncapSrcIpv4Addr0 UInt32
EncapDstIpv4Addr0 UInt32
TenantId0 UInt32
EncryptVxlanId0 UInt32
EncapType1 AnsiString
EncapSrcMacAddr1 UnicodeString
EncapDestMacAddr1 UnicodeString
EncapSrcIpv4Addr1 UInt32
EncapDstIpv4Addr1 UInt32
TenantId1 UInt32
EncryptVxlanId1 UInt32
IpProtocol UInt8
SrcMacAddr UnicodeString
DestMacAddr UnicodeString
SrcIpv4Addr UInt32
DstIpv4Addr UInt32
SrcPort UInt16
DstPort UInt16
IsTcpSyn Boolean
EncapTransposition0 AnsiString
EncapTransposition1 AnsiString
Transposition AnsiString
PortName UnicodeString
PortFriendlyName UnicodeString
UnifiedFlow UInt64
IsSecondary UInt8
IsMirror UInt8
IsHairpin UInt8
HairpinChecked UInt8
OriginalInbound UInt8

Event ID 601: VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) created Direction unified flow UnifiedFlow: IsMain=IsMain, IsPending=IsPending, IsSecondary=IsSecondary, IsMirror=IsMirror, ...

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Message #

VfpExt on port %1 (Name = %33, FriendlyName = %34) created %2 unified flow %35: IsMain=%3, IsPending=%4, IsSecondary=%36, IsMirror=%37, IsHairpin=%38, HairpinChecked=%39, OriginalInbound=%40, IsTcpSyn=%29, Tni=%5, VlanId=%6, NumEncaps=%7, {EncapFlowId0 (EncapType=%8, SrcMac=%9, DestMac=%10, SrcIp=%11, DestIp=%12, TenantId=%13, EncryptVlanId=%14) EncapFlowId1 (EncapType=%15, SrcMac=%16, DestMac=%17, SrcIp=%18, DestIp=%19, TenantId=%20, EncryptVlanId=%21) InnerFlowId (Protocol=%22, SrcMac=%23, DestMac=%24, SrcIp=%25, DestIp=%26, SrcPort=%27, DestPort=%28)}, {EncapTransposition0 (%30), EncapTransposition1 (%31), InnerTransposition (%32)}

Fields #

NameDescription
PortId UInt32
Direction UInt8
Known values
%%14592
Inbound
%%14593
Outbound
%%14594
Forward
%%14595
Bidirectional
IsMain UInt8
IsPending UInt8
TNI UInt64
VLAN UInt32
NumEncaps UInt8
EncapType0 AnsiString
EncapSrcMacAddr0 UnicodeString
EncapDestMacAddr0 UnicodeString
EncapSrcIpv4Addr0 Binary
EncapDstIpv6Addr0 Binary
TenantId0 UInt32
EncryptVxlanId0 UInt32
EncapType1 AnsiString
EncapSrcMacAddr1 UnicodeString
EncapDestMacAddr1 UnicodeString
EncapSrcIpv4Addr1 Binary
EncapDstIpv6Addr1 Binary
TenantId1 UInt32
EncryptVxlanId1 UInt32
IpProtocol UInt8
SrcMacAddr UnicodeString
DestMacAddr UnicodeString
SrcIpv6Addr Binary
DstIpv6Addr Binary
SrcPort UInt16
DstPort UInt16
IsTcpSyn Boolean
EncapTransposition0 AnsiString
EncapTransposition1 AnsiString
Transposition AnsiString
PortName UnicodeString
PortFriendlyName UnicodeString
UnifiedFlow UInt64
IsSecondary UInt8
IsMirror UInt8
IsHairpin UInt8
HairpinChecked UInt8
OriginalInbound UInt8

Event ID 601

#
Channel
Operational

Fields #

NameDescription
PortId UInt32
Direction UInt8
Known values
%%14592
Inbound
%%14593
Outbound
%%14594
Forward
%%14595
Bidirectional
IsMain UInt8
IsPending UInt8
TNI UInt64
VLAN UInt32
NumEncaps UInt8
EncapType0 AnsiString
EncapSrcMacAddr0 UnicodeString
EncapDestMacAddr0 UnicodeString
EncapSrcIpv4Addr0 Binary
EncapDstIpv6Addr0 Binary
TenantId0 UInt32
EncryptVxlanId0 UInt32
EncapType1 AnsiString
EncapSrcMacAddr1 UnicodeString
EncapDestMacAddr1 UnicodeString
EncapSrcIpv4Addr1 Binary
EncapDstIpv6Addr1 Binary
TenantId1 UInt32
EncryptVxlanId1 UInt32
IpProtocol UInt8
SrcMacAddr UnicodeString
DestMacAddr UnicodeString
SrcIpv6Addr Binary
DstIpv6Addr Binary
SrcPort UInt16
DstPort UInt16
IsTcpSyn Boolean
EncapTransposition0 AnsiString
EncapTransposition1 AnsiString
Transposition AnsiString
PortName UnicodeString
PortFriendlyName UnicodeString
UnifiedFlow UInt64
IsSecondary UInt8
IsMirror UInt8
IsHairpin UInt8
HairpinChecked UInt8
OriginalInbound UInt8

Event ID 602: VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) created Direction unified flow: IsMain=IsMain, IsPending=IsPending, Tni=TNI, VlanId=VLAN, NumEncaps=NumEncaps, {EncapFlowId0...

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Message #

VfpExt on port %1 (Name = %31, FriendlyName = %32) created %2 unified flow: IsMain=%3, IsPending=%4, Tni=%5, VlanId=%6, NumEncaps=%7, {EncapFlowId0 (EncapType=%8, SrcMac=%9, DestMac=%10, SrcIp=%11, DestIp=%12, TenantId=%13, EncryptVlanId=%14) EncapFlowId1 (EncapType=%15, SrcMac=%16, DestMac=%17, SrcIp=%18, DestIp=%19, TenantId=%20, EncryptVlanId=%21) InnerFlowId (Protocol=%22, SrcMac=%23, DestMac=%24, SrcIp=%25, DestIp=%26, IcmpType=%27)}, {EncapTransposition0 (%28), EncapTransposition1 (%29), InnerTransposition (%30)}

Fields #

NameDescription
PortId UInt32
Direction UInt8
Known values
%%14592
Inbound
%%14593
Outbound
%%14594
Forward
%%14595
Bidirectional
IsMain UInt8
IsPending UInt8
TNI UInt64
VLAN UInt32
NumEncaps UInt8
EncapType0 AnsiString
EncapSrcMacAddr0 UnicodeString
EncapDestMacAddr0 UnicodeString
EncapSrcIpv4Addr0 UInt32
EncapDstIpv4Addr0 UInt32
TenantId0 UInt32
EncryptVxlanId0 UInt32
EncapType1 AnsiString
EncapSrcMacAddr1 UnicodeString
EncapDestMacAddr1 UnicodeString
EncapSrcIpv4Addr1 UInt32
EncapDstIpv4Addr1 UInt32
TenantId1 UInt32
EncryptVxlanId1 UInt32
IpProtocol UInt8
SrcMacAddr UnicodeString
DestMacAddr UnicodeString
SrcIpv4Addr UInt32
DstIpv4Addr UInt32
IcmpType UInt8
EncapTransposition0 AnsiString
EncapTransposition1 AnsiString
Transposition AnsiString
PortName UnicodeString
PortFriendlyName UnicodeString

Event ID 602

#
Channel
Operational

Fields #

NameDescription
PortId UInt32
Direction UInt8
Known values
%%14592
Inbound
%%14593
Outbound
%%14594
Forward
%%14595
Bidirectional
IsMain UInt8
IsPending UInt8
TNI UInt64
VLAN UInt32
NumEncaps UInt8
EncapType0 AnsiString
EncapSrcMacAddr0 UnicodeString
EncapDestMacAddr0 UnicodeString
EncapSrcIpv4Addr0 UInt32
EncapDstIpv4Addr0 UInt32
TenantId0 UInt32
EncryptVxlanId0 UInt32
EncapType1 AnsiString
EncapSrcMacAddr1 UnicodeString
EncapDestMacAddr1 UnicodeString
EncapSrcIpv4Addr1 UInt32
EncapDstIpv4Addr1 UInt32
TenantId1 UInt32
EncryptVxlanId1 UInt32
IpProtocol UInt8
SrcMacAddr UnicodeString
DestMacAddr UnicodeString
SrcIpv4Addr UInt32
DstIpv4Addr UInt32
IcmpType UInt8
EncapTransposition0 AnsiString
EncapTransposition1 AnsiString
Transposition AnsiString
PortName UnicodeString
PortFriendlyName UnicodeString

Event ID 603: VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) created Direction unified flow: IsMain=IsMain, IsPending=IsPending, Tni=TNI, VlanId=VLAN, NumEncaps=NumEncaps, {EncapFlowId0...

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Message #

VfpExt on port %1 (Name = %31, FriendlyName = %32) created %2 unified flow: IsMain=%3, IsPending=%4, Tni=%5, VlanId=%6, NumEncaps=%7, {EncapFlowId0 (EncapType=%8, SrcMac=%9, DestMac=%10, SrcIp=%11, DestIp=%12, TenantId=%13, EncryptVlanId=%14) EncapFlowId1 (EncapType=%15, SrcMac=%16, DestMac=%17, SrcIp=%18, DestIp=%19, TenantId=%20, EncryptVlanId=%21) InnerFlowId (Protocol=%22, SrcMac=%23, DestMac=%24, SrcIp=%25, DestIp=%26, IcmpType=%27)}, {EncapTransposition0 (%28), EncapTransposition1 (%29), InnerTransposition (%30)}

Fields #

NameDescription
PortId UInt32
Direction UInt8
Known values
%%14592
Inbound
%%14593
Outbound
%%14594
Forward
%%14595
Bidirectional
IsMain UInt8
IsPending UInt8
TNI UInt64
VLAN UInt32
NumEncaps UInt8
EncapType0 AnsiString
EncapSrcMacAddr0 UnicodeString
EncapDestMacAddr0 UnicodeString
EncapSrcIpv4Addr0 Binary
EncapDstIpv6Addr0 Binary
TenantId0 UInt32
EncryptVxlanId0 UInt32
EncapType1 AnsiString
EncapSrcMacAddr1 UnicodeString
EncapDestMacAddr1 UnicodeString
EncapSrcIpv4Addr1 Binary
EncapDstIpv6Addr1 Binary
TenantId1 UInt32
EncryptVxlanId1 UInt32
IpProtocol UInt8
SrcMacAddr UnicodeString
DestMacAddr UnicodeString
SrcIpv6Addr Binary
DstIpv6Addr Binary
IcmpType UInt8
EncapTransposition0 AnsiString
EncapTransposition1 AnsiString
Transposition AnsiString
PortName UnicodeString
PortFriendlyName UnicodeString

Event ID 603

#
Channel
Operational

Fields #

NameDescription
PortId UInt32
Direction UInt8
Known values
%%14592
Inbound
%%14593
Outbound
%%14594
Forward
%%14595
Bidirectional
IsMain UInt8
IsPending UInt8
TNI UInt64
VLAN UInt32
NumEncaps UInt8
EncapType0 AnsiString
EncapSrcMacAddr0 UnicodeString
EncapDestMacAddr0 UnicodeString
EncapSrcIpv4Addr0 Binary
EncapDstIpv6Addr0 Binary
TenantId0 UInt32
EncryptVxlanId0 UInt32
EncapType1 AnsiString
EncapSrcMacAddr1 UnicodeString
EncapDestMacAddr1 UnicodeString
EncapSrcIpv4Addr1 Binary
EncapDstIpv6Addr1 Binary
TenantId1 UInt32
EncryptVxlanId1 UInt32
IpProtocol UInt8
SrcMacAddr UnicodeString
DestMacAddr UnicodeString
SrcIpv6Addr Binary
DstIpv6Addr Binary
IcmpType UInt8
EncapTransposition0 AnsiString
EncapTransposition1 AnsiString
Transposition AnsiString
PortName UnicodeString
PortFriendlyName UnicodeString

Event ID 604: VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) matched Direction unified flow UnifiedFlow: IsMain=IsMain, IsSecondary=IsSecondary, IsMirror=IsMirror, IsHairpin=IsHairpin, ...

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Message #

VfpExt on port %1 (Name = %33, FriendlyName = %34) matched %2 unified flow %35: IsMain=%3, IsSecondary=%36, IsMirror=%37, IsHairpin=%38, HairpinChecked=%39, OriginalInbound=%40, IsPending=%4, IsTcpSyn=%29, Tni=%5, VlanId=%6, NumEncaps=%7, {EncapFlowId0 (EncapType=%8, SrcMac=%9, DestMac=%10, SrcIp=%11, DestIp=%12, TenantId=%13, EncryptVlanId=%14) EncapFlowId1 (EncapType=%15, SrcMac=%16, DestMac=%17, SrcIp=%18, DestIp=%19, TenantId=%20, EncryptVlanId=%21) InnerFlowId (Protocol=%22, SrcMac=%23, DestMac=%24, SrcIp=%25, DestIp=%26, SrcPort=%27, DestPort=%28)}, {EncapTransposition0 (%30), EncapTransposition1 (%31), InnerTransposition (%32)}

Fields #

NameDescription
PortId UInt32
Direction UInt8
Known values
%%14592
Inbound
%%14593
Outbound
%%14594
Forward
%%14595
Bidirectional
IsMain UInt8
IsPending UInt8
TNI UInt64
VLAN UInt32
NumEncaps UInt8
EncapType0 AnsiString
EncapSrcMacAddr0 UnicodeString
EncapDestMacAddr0 UnicodeString
EncapSrcIpv4Addr0 UInt32
EncapDstIpv4Addr0 UInt32
TenantId0 UInt32
EncryptVxlanId0 UInt32
EncapType1 AnsiString
EncapSrcMacAddr1 UnicodeString
EncapDestMacAddr1 UnicodeString
EncapSrcIpv4Addr1 UInt32
EncapDstIpv4Addr1 UInt32
TenantId1 UInt32
EncryptVxlanId1 UInt32
IpProtocol UInt8
SrcMacAddr UnicodeString
DestMacAddr UnicodeString
SrcIpv4Addr UInt32
DstIpv4Addr UInt32
SrcPort UInt16
DstPort UInt16
IsTcpSyn Boolean
EncapTransposition0 AnsiString
EncapTransposition1 AnsiString
Transposition AnsiString
PortName UnicodeString
PortFriendlyName UnicodeString
UnifiedFlow UInt64
IsSecondary UInt8
IsMirror UInt8
IsHairpin UInt8
HairpinChecked UInt8
OriginalInbound UInt8

Event ID 604

#
Channel
Operational

Fields #

NameDescription
PortId UInt32
Direction UInt8
Known values
%%14592
Inbound
%%14593
Outbound
%%14594
Forward
%%14595
Bidirectional
IsMain UInt8
IsPending UInt8
TNI UInt64
VLAN UInt32
NumEncaps UInt8
EncapType0 AnsiString
EncapSrcMacAddr0 UnicodeString
EncapDestMacAddr0 UnicodeString
EncapSrcIpv4Addr0 UInt32
EncapDstIpv4Addr0 UInt32
TenantId0 UInt32
EncryptVxlanId0 UInt32
EncapType1 AnsiString
EncapSrcMacAddr1 UnicodeString
EncapDestMacAddr1 UnicodeString
EncapSrcIpv4Addr1 UInt32
EncapDstIpv4Addr1 UInt32
TenantId1 UInt32
EncryptVxlanId1 UInt32
IpProtocol UInt8
SrcMacAddr UnicodeString
DestMacAddr UnicodeString
SrcIpv4Addr UInt32
DstIpv4Addr UInt32
SrcPort UInt16
DstPort UInt16
IsTcpSyn Boolean
EncapTransposition0 AnsiString
EncapTransposition1 AnsiString
Transposition AnsiString
PortName UnicodeString
PortFriendlyName UnicodeString
UnifiedFlow UInt64
IsSecondary UInt8
IsMirror UInt8
IsHairpin UInt8
HairpinChecked UInt8
OriginalInbound UInt8

Event ID 605: VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) matched Direction unified flow UnifiedFlow: IsMain=IsMain, IsSecondary=IsSecondary, IsMirror=IsMirror, IsHairpin=IsHairpin, ...

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Message #

VfpExt on port %1 (Name = %33, FriendlyName = %34) matched %2 unified flow %35: IsMain=%3, IsSecondary=%36, IsMirror=%37, IsHairpin=%38, HairpinChecked=%39, OriginalInbound=%40, IsPending=%4, IsTcpSyn=%29, Tni=%5, VlanId=%6, NumEncaps=%7, {EncapFlowId0 (EncapType=%8, SrcMac=%9, DestMac=%10, SrcIp=%11, DestIp=%12, TenantId=%13, EncryptVlanId=%14) EncapFlowId1 (EncapType=%15, SrcMac=%16, DestMac=%17, SrcIp=%18, DestIp=%19, TenantId=%20, EncryptVlanId=%21) InnerFlowId (Protocol=%22, SrcMac=%23, DestMac=%24, SrcIp=%25, DestIp=%26, SrcPort=%27, DestPort=%28)}, {EncapTransposition0 (%30), EncapTransposition1 (%31), InnerTransposition (%32)}

Fields #

NameDescription
PortId UInt32
Direction UInt8
Known values
%%14592
Inbound
%%14593
Outbound
%%14594
Forward
%%14595
Bidirectional
IsMain UInt8
IsPending UInt8
TNI UInt64
VLAN UInt32
NumEncaps UInt8
EncapType0 AnsiString
EncapSrcMacAddr0 UnicodeString
EncapDestMacAddr0 UnicodeString
EncapSrcIpv4Addr0 Binary
EncapDstIpv6Addr0 Binary
TenantId0 UInt32
EncryptVxlanId0 UInt32
EncapType1 AnsiString
EncapSrcMacAddr1 UnicodeString
EncapDestMacAddr1 UnicodeString
EncapSrcIpv4Addr1 Binary
EncapDstIpv6Addr1 Binary
TenantId1 UInt32
EncryptVxlanId1 UInt32
IpProtocol UInt8
SrcMacAddr UnicodeString
DestMacAddr UnicodeString
SrcIpv6Addr Binary
DstIpv6Addr Binary
SrcPort UInt16
DstPort UInt16
IsTcpSyn Boolean
EncapTransposition0 AnsiString
EncapTransposition1 AnsiString
Transposition AnsiString
PortName UnicodeString
PortFriendlyName UnicodeString
UnifiedFlow UInt64
IsSecondary UInt8
IsMirror UInt8
IsHairpin UInt8
HairpinChecked UInt8
OriginalInbound UInt8

Event ID 605

#
Channel
Operational

Fields #

NameDescription
PortId UInt32
Direction UInt8
Known values
%%14592
Inbound
%%14593
Outbound
%%14594
Forward
%%14595
Bidirectional
IsMain UInt8
IsPending UInt8
TNI UInt64
VLAN UInt32
NumEncaps UInt8
EncapType0 AnsiString
EncapSrcMacAddr0 UnicodeString
EncapDestMacAddr0 UnicodeString
EncapSrcIpv4Addr0 Binary
EncapDstIpv6Addr0 Binary
TenantId0 UInt32
EncryptVxlanId0 UInt32
EncapType1 AnsiString
EncapSrcMacAddr1 UnicodeString
EncapDestMacAddr1 UnicodeString
EncapSrcIpv4Addr1 Binary
EncapDstIpv6Addr1 Binary
TenantId1 UInt32
EncryptVxlanId1 UInt32
IpProtocol UInt8
SrcMacAddr UnicodeString
DestMacAddr UnicodeString
SrcIpv6Addr Binary
DstIpv6Addr Binary
SrcPort UInt16
DstPort UInt16
IsTcpSyn Boolean
EncapTransposition0 AnsiString
EncapTransposition1 AnsiString
Transposition AnsiString
PortName UnicodeString
PortFriendlyName UnicodeString
UnifiedFlow UInt64
IsSecondary UInt8
IsMirror UInt8
IsHairpin UInt8
HairpinChecked UInt8
OriginalInbound UInt8

Event ID 606: VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) matched Direction unified flow: IsMain=IsMain, IsPending=IsPending, Tni=TNI, VlanId=VLAN, NumEncaps=NumEncaps, {EncapFlowId0...

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Message #

VfpExt on port %1 (Name = %31, FriendlyName = %32) matched %2 unified flow: IsMain=%3, IsPending=%4, Tni=%5, VlanId=%6, NumEncaps=%7, {EncapFlowId0 (EncapType=%8, SrcMac=%9, DestMac=%10, SrcIp=%11, DestIp=%12, TenantId=%13, EncryptVlanId=%14) EncapFlowId1 (EncapType=%15, SrcMac=%16, DestMac=%17, SrcIp=%18, DestIp=%19, TenantId=%20, EncryptVlanId=%21) InnerFlowId (Protocol=%22, SrcMac=%23, DestMac=%24, SrcIp=%25, DestIp=%26, IcmpType=%27)}, {EncapTransposition0 (%28), EncapTransposition1 (%29), InnerTransposition (%30)}

Fields #

NameDescription
PortId UInt32
Direction UInt8
Known values
%%14592
Inbound
%%14593
Outbound
%%14594
Forward
%%14595
Bidirectional
IsMain UInt8
IsPending UInt8
TNI UInt64
VLAN UInt32
NumEncaps UInt8
EncapType0 AnsiString
EncapSrcMacAddr0 UnicodeString
EncapDestMacAddr0 UnicodeString
EncapSrcIpv4Addr0 UInt32
EncapDstIpv4Addr0 UInt32
TenantId0 UInt32
EncryptVxlanId0 UInt32
EncapType1 AnsiString
EncapSrcMacAddr1 UnicodeString
EncapDestMacAddr1 UnicodeString
EncapSrcIpv4Addr1 UInt32
EncapDstIpv4Addr1 UInt32
TenantId1 UInt32
EncryptVxlanId1 UInt32
IpProtocol UInt8
SrcMacAddr UnicodeString
DestMacAddr UnicodeString
SrcIpv4Addr UInt32
DstIpv4Addr UInt32
IcmpType UInt8
EncapTransposition0 AnsiString
EncapTransposition1 AnsiString
Transposition AnsiString
PortName UnicodeString
PortFriendlyName UnicodeString

Event ID 606

#
Channel
Operational

Fields #

NameDescription
PortId UInt32
Direction UInt8
Known values
%%14592
Inbound
%%14593
Outbound
%%14594
Forward
%%14595
Bidirectional
IsMain UInt8
IsPending UInt8
TNI UInt64
VLAN UInt32
NumEncaps UInt8
EncapType0 AnsiString
EncapSrcMacAddr0 UnicodeString
EncapDestMacAddr0 UnicodeString
EncapSrcIpv4Addr0 UInt32
EncapDstIpv4Addr0 UInt32
TenantId0 UInt32
EncryptVxlanId0 UInt32
EncapType1 AnsiString
EncapSrcMacAddr1 UnicodeString
EncapDestMacAddr1 UnicodeString
EncapSrcIpv4Addr1 UInt32
EncapDstIpv4Addr1 UInt32
TenantId1 UInt32
EncryptVxlanId1 UInt32
IpProtocol UInt8
SrcMacAddr UnicodeString
DestMacAddr UnicodeString
SrcIpv4Addr UInt32
DstIpv4Addr UInt32
IcmpType UInt8
EncapTransposition0 AnsiString
EncapTransposition1 AnsiString
Transposition AnsiString
PortName UnicodeString
PortFriendlyName UnicodeString

Event ID 607: VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) matched Direction unified flow: IsMain=IsMain, IsPending=IsPending, Tni=TNI, VlanId=VLAN, NumEncaps=NumEncaps, {EncapFlowId0...

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Message #

VfpExt on port %1 (Name = %31, FriendlyName = %32) matched %2 unified flow: IsMain=%3, IsPending=%4, Tni=%5, VlanId=%6, NumEncaps=%7, {EncapFlowId0 (EncapType=%8, SrcMac=%9, DestMac=%10, SrcIp=%11, DestIp=%12, TenantId=%13, EncryptVlanId=%14) EncapFlowId1 (EncapType=%15, SrcMac=%16, DestMac=%17, SrcIp=%18, DestIp=%19, TenantId=%20, EncryptVlanId=%21) InnerFlowId (Protocol=%22, SrcMac=%23, DestMac=%24, SrcIp=%25, DestIp=%26, IcmpType=%27)}, {EncapTransposition0 (%28), EncapTransposition1 (%29), InnerTransposition (%30)}

Fields #

NameDescription
PortId UInt32
Direction UInt8
Known values
%%14592
Inbound
%%14593
Outbound
%%14594
Forward
%%14595
Bidirectional
IsMain UInt8
IsPending UInt8
TNI UInt64
VLAN UInt32
NumEncaps UInt8
EncapType0 AnsiString
EncapSrcMacAddr0 UnicodeString
EncapDestMacAddr0 UnicodeString
EncapSrcIpv4Addr0 Binary
EncapDstIpv6Addr0 Binary
TenantId0 UInt32
EncryptVxlanId0 UInt32
EncapType1 AnsiString
EncapSrcMacAddr1 UnicodeString
EncapDestMacAddr1 UnicodeString
EncapSrcIpv4Addr1 Binary
EncapDstIpv6Addr1 Binary
TenantId1 UInt32
EncryptVxlanId1 UInt32
IpProtocol UInt8
SrcMacAddr UnicodeString
DestMacAddr UnicodeString
SrcIpv6Addr Binary
DstIpv6Addr Binary
IcmpType UInt8
EncapTransposition0 AnsiString
EncapTransposition1 AnsiString
Transposition AnsiString
PortName UnicodeString
PortFriendlyName UnicodeString

Event ID 607

#
Channel
Operational

Fields #

NameDescription
PortId UInt32
Direction UInt8
Known values
%%14592
Inbound
%%14593
Outbound
%%14594
Forward
%%14595
Bidirectional
IsMain UInt8
IsPending UInt8
TNI UInt64
VLAN UInt32
NumEncaps UInt8
EncapType0 AnsiString
EncapSrcMacAddr0 UnicodeString
EncapDestMacAddr0 UnicodeString
EncapSrcIpv4Addr0 Binary
EncapDstIpv6Addr0 Binary
TenantId0 UInt32
EncryptVxlanId0 UInt32
EncapType1 AnsiString
EncapSrcMacAddr1 UnicodeString
EncapDestMacAddr1 UnicodeString
EncapSrcIpv4Addr1 Binary
EncapDstIpv6Addr1 Binary
TenantId1 UInt32
EncryptVxlanId1 UInt32
IpProtocol UInt8
SrcMacAddr UnicodeString
DestMacAddr UnicodeString
SrcIpv6Addr Binary
DstIpv6Addr Binary
IcmpType UInt8
EncapTransposition0 AnsiString
EncapTransposition1 AnsiString
Transposition AnsiString
PortName UnicodeString
PortFriendlyName UnicodeString

Event ID 608: VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) deleted Direction unified flow UnifiedFlow: IsMain=IsMain, IsPending=IsPending, IsSecondary=IsSecondary, IsMirror=IsMirror, ...

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Message #

VfpExt on port %1 (Name = %29, FriendlyName = %30) deleted %2 unified flow %31: IsMain=%3, IsPending=%4, IsSecondary=%32, IsMirror=%33, IsHairpin=%34, HairpinChecked=%35, OriginalInbound=%36, Tni=%5, VlanId=%6, NumEncaps=%7, {EncapFlowId0 (EncapType=%8, SrcMac=%9, DestMac=%10, SrcIp=%11, DestIp=%12, TenantId=%13, EncryptVlanId=%14) EncapFlowId1 (EncapType=%15, SrcMac=%16, DestMac=%17, SrcIp=%18, DestIp=%19, TenantId=%20, EncryptVlanId=%21) InnerFlowId (Protocol=%22, SrcMac=%23, DestMac=%24, SrcIp=%25, DestIp=%26, SrcPort=%27, DestPort=%28)}

Fields #

NameDescription
PortId UInt32
Direction UInt8
Known values
%%14592
Inbound
%%14593
Outbound
%%14594
Forward
%%14595
Bidirectional
IsMain UInt8
IsPending UInt8
TNI UInt64
VLAN UInt32
NumEncaps UInt8
EncapType0 AnsiString
EncapSrcMacAddr0 UnicodeString
EncapDestMacAddr0 UnicodeString
EncapSrcIpv4Addr0 UInt32
EncapDstIpv4Addr0 UInt32
TenantId0 UInt32
EncryptVxlanId0 UInt32
EncapType1 AnsiString
EncapSrcMacAddr1 UnicodeString
EncapDestMacAddr1 UnicodeString
EncapSrcIpv4Addr1 UInt32
EncapDstIpv4Addr1 UInt32
TenantId1 UInt32
EncryptVxlanId1 UInt32
IpProtocol UInt8
SrcMacAddr UnicodeString
DestMacAddr UnicodeString
SrcIpv4Addr UInt32
DstIpv4Addr UInt32
SrcPort UInt16
DstPort UInt16
PortName UnicodeString
PortFriendlyName UnicodeString
UnifiedFlow UInt64
IsSecondary UInt8
IsMirror UInt8
IsHairpin UInt8
HairpinChecked UInt8
OriginalInbound UInt8

Event ID 608

#
Channel
Operational

Fields #

NameDescription
PortId UInt32
Direction UInt8
Known values
%%14592
Inbound
%%14593
Outbound
%%14594
Forward
%%14595
Bidirectional
IsMain UInt8
IsPending UInt8
TNI UInt64
VLAN UInt32
NumEncaps UInt8
EncapType0 AnsiString
EncapSrcMacAddr0 UnicodeString
EncapDestMacAddr0 UnicodeString
EncapSrcIpv4Addr0 UInt32
EncapDstIpv4Addr0 UInt32
TenantId0 UInt32
EncryptVxlanId0 UInt32
EncapType1 AnsiString
EncapSrcMacAddr1 UnicodeString
EncapDestMacAddr1 UnicodeString
EncapSrcIpv4Addr1 UInt32
EncapDstIpv4Addr1 UInt32
TenantId1 UInt32
EncryptVxlanId1 UInt32
IpProtocol UInt8
SrcMacAddr UnicodeString
DestMacAddr UnicodeString
SrcIpv4Addr UInt32
DstIpv4Addr UInt32
SrcPort UInt16
DstPort UInt16
PortName UnicodeString
PortFriendlyName UnicodeString
UnifiedFlow UInt64
IsSecondary UInt8
IsMirror UInt8
IsHairpin UInt8
HairpinChecked UInt8
OriginalInbound UInt8

Event ID 609: VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) deleted Direction unified flow UnifiedFlow: IsMain=IsMain, IsPending=IsPending, IsSecondary=IsSecondary, IsMirror=IsMirror, ...

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Message #

VfpExt on port %1 (Name = %29, FriendlyName = %30) deleted %2 unified flow %31: IsMain=%3, IsPending=%4, IsSecondary=%32, IsMirror=%33, IsHairpin=%34, HairpinChecked=%35, OriginalInbound=%36, Tni=%5, VlanId=%6, NumEncaps=%7, {EncapFlowId0 (EncapType=%8, SrcMac=%9, DestMac=%10, SrcIp=%11, DestIp=%12, TenantId=%13, EncryptVlanId=%14) EncapFlowId1 (EncapType=%15, SrcMac=%16, DestMac=%17, SrcIp=%18, DestIp=%19, TenantId=%20, EncryptVlanId=%21) InnerFlowId (Protocol=%22, SrcMac=%23, DestMac=%24, SrcIp=%25, DestIp=%26, SrcPort=%27, DestPort=%28)}

Fields #

NameDescription
PortId UInt32
Direction UInt8
Known values
%%14592
Inbound
%%14593
Outbound
%%14594
Forward
%%14595
Bidirectional
IsMain UInt8
IsPending UInt8
TNI UInt64
VLAN UInt32
NumEncaps UInt8
EncapType0 AnsiString
EncapSrcMacAddr0 UnicodeString
EncapDestMacAddr0 UnicodeString
EncapSrcIpv4Addr0 Binary
EncapDstIpv6Addr0 Binary
TenantId0 UInt32
EncryptVxlanId0 UInt32
EncapType1 AnsiString
EncapSrcMacAddr1 UnicodeString
EncapDestMacAddr1 UnicodeString
EncapSrcIpv4Addr1 Binary
EncapDstIpv6Addr1 Binary
TenantId1 UInt32
EncryptVxlanId1 UInt32
IpProtocol UInt8
SrcMacAddr UnicodeString
DestMacAddr UnicodeString
SrcIpv6Addr Binary
DstIpv6Addr Binary
SrcPort UInt16
DstPort UInt16
PortName UnicodeString
PortFriendlyName UnicodeString
UnifiedFlow UInt64
IsSecondary UInt8
IsMirror UInt8
IsHairpin UInt8
HairpinChecked UInt8
OriginalInbound UInt8

Event ID 609

#
Channel
Operational

Fields #

NameDescription
PortId UInt32
Direction UInt8
Known values
%%14592
Inbound
%%14593
Outbound
%%14594
Forward
%%14595
Bidirectional
IsMain UInt8
IsPending UInt8
TNI UInt64
VLAN UInt32
NumEncaps UInt8
EncapType0 AnsiString
EncapSrcMacAddr0 UnicodeString
EncapDestMacAddr0 UnicodeString
EncapSrcIpv4Addr0 Binary
EncapDstIpv6Addr0 Binary
TenantId0 UInt32
EncryptVxlanId0 UInt32
EncapType1 AnsiString
EncapSrcMacAddr1 UnicodeString
EncapDestMacAddr1 UnicodeString
EncapSrcIpv4Addr1 Binary
EncapDstIpv6Addr1 Binary
TenantId1 UInt32
EncryptVxlanId1 UInt32
IpProtocol UInt8
SrcMacAddr UnicodeString
DestMacAddr UnicodeString
SrcIpv6Addr Binary
DstIpv6Addr Binary
SrcPort UInt16
DstPort UInt16
PortName UnicodeString
PortFriendlyName UnicodeString
UnifiedFlow UInt64
IsSecondary UInt8
IsMirror UInt8
IsHairpin UInt8
HairpinChecked UInt8
OriginalInbound UInt8

Event ID 610: VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) deleted Direction unified flow: IsMain=IsMain, IsPending=IsPending, Tni=TNI, VlanId=VLAN, NumEncaps=NumEncaps, {EncapFlowId0...

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Message #

VfpExt on port %1 (Name = %28, FriendlyName = %29) deleted %2 unified flow: IsMain=%3, IsPending=%4, Tni=%5, VlanId=%6, NumEncaps=%7, {EncapFlowId0 (EncapType=%8, SrcMac=%9, DestMac=%10, SrcIp=%11, DestIp=%12, TenantId=%13, EncryptVlanId=%14) EncapFlowId1 (EncapType=%15, SrcMac=%16, DestMac=%17, SrcIp=%18, DestIp=%19, TenantId=%20, EncryptVlanId=%21) InnerFlowId (Protocol=%22, SrcMac=%23, DestMac=%24, SrcIp=%25, DestIp=%26, IcmpType=%27)}

Fields #

NameDescription
PortId UInt32
Direction UInt8
Known values
%%14592
Inbound
%%14593
Outbound
%%14594
Forward
%%14595
Bidirectional
IsMain UInt8
IsPending UInt8
TNI UInt64
VLAN UInt32
NumEncaps UInt8
EncapType0 AnsiString
EncapSrcMacAddr0 UnicodeString
EncapDestMacAddr0 UnicodeString
EncapSrcIpv4Addr0 UInt32
EncapDstIpv4Addr0 UInt32
TenantId0 UInt32
EncryptVxlanId0 UInt32
EncapType1 AnsiString
EncapSrcMacAddr1 UnicodeString
EncapDestMacAddr1 UnicodeString
EncapSrcIpv4Addr1 UInt32
EncapDstIpv4Addr1 UInt32
TenantId1 UInt32
EncryptVxlanId1 UInt32
IpProtocol UInt8
SrcMacAddr UnicodeString
DestMacAddr UnicodeString
SrcIpv4Addr UInt32
DstIpv4Addr UInt32
IcmpType UInt8
PortName UnicodeString
PortFriendlyName UnicodeString

Event ID 610

#
Channel
Operational

Fields #

NameDescription
PortId UInt32
Direction UInt8
Known values
%%14592
Inbound
%%14593
Outbound
%%14594
Forward
%%14595
Bidirectional
IsMain UInt8
IsPending UInt8
TNI UInt64
VLAN UInt32
NumEncaps UInt8
EncapType0 AnsiString
EncapSrcMacAddr0 UnicodeString
EncapDestMacAddr0 UnicodeString
EncapSrcIpv4Addr0 UInt32
EncapDstIpv4Addr0 UInt32
TenantId0 UInt32
EncryptVxlanId0 UInt32
EncapType1 AnsiString
EncapSrcMacAddr1 UnicodeString
EncapDestMacAddr1 UnicodeString
EncapSrcIpv4Addr1 UInt32
EncapDstIpv4Addr1 UInt32
TenantId1 UInt32
EncryptVxlanId1 UInt32
IpProtocol UInt8
SrcMacAddr UnicodeString
DestMacAddr UnicodeString
SrcIpv4Addr UInt32
DstIpv4Addr UInt32
IcmpType UInt8
PortName UnicodeString
PortFriendlyName UnicodeString

Event ID 611: VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) deleted Direction unified flow: IsMain=IsMain, IsPending=IsPending, Tni=TNI, VlanId=VLAN, NumEncaps=NumEncaps, {EncapFlowId0...

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Message #

VfpExt on port %1 (Name = %28, FriendlyName = %29) deleted %2 unified flow: IsMain=%3, IsPending=%4, Tni=%5, VlanId=%6, NumEncaps=%7, {EncapFlowId0 (EncapType=%8, SrcMac=%9, DestMac=%10, SrcIp=%11, DestIp=%12, TenantId=%13, EncryptVlanId=%14) EncapFlowId1 (EncapType=%15, SrcMac=%16, DestMac=%17, SrcIp=%18, DestIp=%19, TenantId=%20, EncryptVlanId=%21) InnerFlowId (Protocol=%22, SrcMac=%23, DestMac=%24, SrcIp=%25, DestIp=%26, IcmpType=%27)}

Fields #

NameDescription
PortId UInt32
Direction UInt8
Known values
%%14592
Inbound
%%14593
Outbound
%%14594
Forward
%%14595
Bidirectional
IsMain UInt8
IsPending UInt8
TNI UInt64
VLAN UInt32
NumEncaps UInt8
EncapType0 AnsiString
EncapSrcMacAddr0 UnicodeString
EncapDestMacAddr0 UnicodeString
EncapSrcIpv4Addr0 Binary
EncapDstIpv6Addr0 Binary
TenantId0 UInt32
EncryptVxlanId0 UInt32
EncapType1 AnsiString
EncapSrcMacAddr1 UnicodeString
EncapDestMacAddr1 UnicodeString
EncapSrcIpv4Addr1 Binary
EncapDstIpv6Addr1 Binary
TenantId1 UInt32
EncryptVxlanId1 UInt32
IpProtocol UInt8
SrcMacAddr UnicodeString
DestMacAddr UnicodeString
SrcIpv6Addr Binary
DstIpv6Addr Binary
IcmpType UInt8
PortName UnicodeString
PortFriendlyName UnicodeString

Event ID 611

#
Channel
Operational

Fields #

NameDescription
PortId UInt32
Direction UInt8
Known values
%%14592
Inbound
%%14593
Outbound
%%14594
Forward
%%14595
Bidirectional
IsMain UInt8
IsPending UInt8
TNI UInt64
VLAN UInt32
NumEncaps UInt8
EncapType0 AnsiString
EncapSrcMacAddr0 UnicodeString
EncapDestMacAddr0 UnicodeString
EncapSrcIpv4Addr0 Binary
EncapDstIpv6Addr0 Binary
TenantId0 UInt32
EncryptVxlanId0 UInt32
EncapType1 AnsiString
EncapSrcMacAddr1 UnicodeString
EncapDestMacAddr1 UnicodeString
EncapSrcIpv4Addr1 Binary
EncapDstIpv6Addr1 Binary
TenantId1 UInt32
EncryptVxlanId1 UInt32
IpProtocol UInt8
SrcMacAddr UnicodeString
DestMacAddr UnicodeString
SrcIpv6Addr Binary
DstIpv6Addr Binary
IcmpType UInt8
PortName UnicodeString
PortFriendlyName UnicodeString

Event ID 650: File operation FileOperation on file FileName with size FileSize completed with status OperationStatus, hex Status.

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Message #

File operation %1 on file %2 with size %3 completed with status %4, hex %5

Fields #

NameDescription
FileOperation UInt8
FileName UnicodeString
FileSize UInt64
OperationStatus UInt32NTSTATUS reference
Status UInt32NTSTATUS reference

Event ID 650

#
Channel
Operational

Description

File operation on file with size completed with status , hex.

Fields #

NameDescription
FileOperation UInt8
FileName UnicodeString
FileSize UInt64
OperationStatus UInt32NTSTATUS reference
Status UInt32NTSTATUS reference

Event ID 700: Failure in control processing for object.

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Description

Failure in control processing for object. Id: Id, Name: Name, Operation Type: TraceObjectOperationType, Type: ItemType, SubType: SubType, Flags: Flags, Port id: PortId, Port name: PortName, Status: Status, Failure reason (value = FailureReason): ControlFailureReason.

Message #

Failure in control processing for object. Id: %1, Name: %11, Operation Type: %2, Type: %3, SubType: %4, Flags: %5, Port id: %6, Port name: %7, Status: %8, Failure reason (value = %10): %9

Fields #

NameDescription
Id UnicodeString
TraceObjectOperationType UInt32
ItemType UInt32
SubType UInt8
Flags UInt16
PortId UInt32
PortName UnicodeString
Status UInt32NTSTATUS reference
ControlFailureReason UInt32
FailureReason UInt32
Known values
%%2304
An Error occured during Logon.
%%2305
The specified user account has expired.
%%2306
The NetLogon component is not active.
%%2307
Account locked out.
%%2308
The user has not been granted the requested logon type at this machine.
%%2309
The specified account's password has expired.
%%2310
Account currently disabled.
%%2311
Account logon time restriction violation.
%%2312
User not allowed to logon at this computer.
%%2313
Unknown user name or bad password.
%%2314
Domain sid inconsistent.
%%2315
Smartcard logon is required and was not used.
Name UnicodeString

Event ID 700

#
Channel
Operational

Description

Failure in control processing for object. Id: , Name: , Operation Type: , Type: , SubType: , Flags: , Port id: , Port name: , Status: , Failure reason (value = ).

Fields #

NameDescription
Id UnicodeString
TraceObjectOperationType UInt32
ItemType UInt32
SubType UInt8
Flags UInt16
PortId UInt32
PortName UnicodeString
Status UInt32NTSTATUS reference
ControlFailureReason UInt32
FailureReason UInt32
Known values
%%2304
An Error occured during Logon.
%%2305
The specified user account has expired.
%%2306
The NetLogon component is not active.
%%2307
Account locked out.
%%2308
The user has not been granted the requested logon type at this machine.
%%2309
The specified account's password has expired.
%%2310
Account currently disabled.
%%2311
Account logon time restriction violation.
%%2312
User not allowed to logon at this computer.
%%2313
Unknown user name or bad password.
%%2314
Domain sid inconsistent.
%%2315
Smartcard logon is required and was not used.
Name UnicodeString

Event ID 701: Success during control processing for object.

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Description

Success during control processing for object. Id: Id, Name: Name, Operation Type: TraceObjectOperationType, Type: ItemType, SubType: SubType, Flags: Flags, Port id: PortId, Port name: PortName.

Message #

Success during control processing for object. Id: %1, Name: %11, Operation Type: %2, Type: %3, SubType: %4, Flags: %5, Port id: %6, Port name: %7

Fields #

NameDescription
Id UnicodeString
TraceObjectOperationType UInt32
ItemType UInt32
SubType UInt8
Flags UInt16
PortId UInt32
PortName UnicodeString
Status UInt32NTSTATUS reference
ControlFailureReason UInt32
FailureReason UInt32
Known values
%%2304
An Error occured during Logon.
%%2305
The specified user account has expired.
%%2306
The NetLogon component is not active.
%%2307
Account locked out.
%%2308
The user has not been granted the requested logon type at this machine.
%%2309
The specified account's password has expired.
%%2310
Account currently disabled.
%%2311
Account logon time restriction violation.
%%2312
User not allowed to logon at this computer.
%%2313
Unknown user name or bad password.
%%2314
Domain sid inconsistent.
%%2315
Smartcard logon is required and was not used.
Name UnicodeString

Event ID 701

#
Channel
Operational

Description

Success during control processing for object. Id: , Name: , Operation Type: , Type: , SubType: , Flags: , Port id: , Port name.

Fields #

NameDescription
Id UnicodeString
TraceObjectOperationType UInt32
ItemType UInt32
SubType UInt8
Flags UInt16
PortId UInt32
PortName UnicodeString
Status UInt32NTSTATUS reference
ControlFailureReason UInt32
FailureReason UInt32
Known values
%%2304
An Error occured during Logon.
%%2305
The specified user account has expired.
%%2306
The NetLogon component is not active.
%%2307
Account locked out.
%%2308
The user has not been granted the requested logon type at this machine.
%%2309
The specified account's password has expired.
%%2310
Account currently disabled.
%%2311
Account logon time restriction violation.
%%2312
User not allowed to logon at this computer.
%%2313
Unknown user name or bad password.
%%2314
Domain sid inconsistent.
%%2315
Smartcard logon is required and was not used.
Name UnicodeString

Event ID 702: Ioctl completed.

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Description

Ioctl completed. Switch name: SwitchName, Port id: PortId, Port name: PortName, Process id: ProcessId, Irp: Irp, Status: Status.

Message #

Ioctl completed. Switch name: %1, Port id: %2, Port name: %3, Process id: %5, Irp: %6, Status: %7

Fields #

NameDescription
SwitchName UnicodeString
PortId UInt32
PortName UnicodeString
Operation UInt16
Known values
%%2456
Open key file.
%%2457
Delete key file.
%%2458
Read persisted key from file.
%%2459
Write persisted key to file.
%%2464
Export of persistent cryptographic key.
%%2465
Import of persistent cryptographic key.
%%2480
Open Key.
%%2481
Create Key.
%%2482
Delete Key.
%%2483
Encrypt.
%%2484
Decrypt.
%%2485
Sign hash.
%%2486
Secret agreement.
%%2487
Domain settings.
%%2488
Local settings.
%%2489
Add provider.
%%2490
Remove provider.
%%2491
Add context.
%%2492
Remove context.
%%2493
Add function.
%%2494
Remove function.
%%2495
Add function provider.
%%2496
Remove function provider.
%%2497
Add function property.
%%2498
Remove function property.
%%2499
Machine key.
%%2500
User key.
%%2501
Key Derivation.
%%2502
Claim Creation.
%%2503
Claim Verification.
ProcessId UInt32
Irp Pointer
Status UInt32NTSTATUS reference

Event ID 702

#
Channel
Operational

Description

Ioctl completed. Switch name: , Port id: , Port name: , Process id: , Irp: , Status.

Fields #

NameDescription
SwitchName UnicodeString
PortId UInt32
PortName UnicodeString
Operation UInt16
Known values
%%2456
Open key file.
%%2457
Delete key file.
%%2458
Read persisted key from file.
%%2459
Write persisted key to file.
%%2464
Export of persistent cryptographic key.
%%2465
Import of persistent cryptographic key.
%%2480
Open Key.
%%2481
Create Key.
%%2482
Delete Key.
%%2483
Encrypt.
%%2484
Decrypt.
%%2485
Sign hash.
%%2486
Secret agreement.
%%2487
Domain settings.
%%2488
Local settings.
%%2489
Add provider.
%%2490
Remove provider.
%%2491
Add context.
%%2492
Remove context.
%%2493
Add function.
%%2494
Remove function.
%%2495
Add function provider.
%%2496
Remove function provider.
%%2497
Add function property.
%%2498
Remove function property.
%%2499
Machine key.
%%2500
User key.
%%2501
Key Derivation.
%%2502
Claim Creation.
%%2503
Claim Verification.
ProcessId UInt32
Irp Pointer
Status UInt32NTSTATUS reference

Event ID 703: Failed when setting port information.

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Description

Failed when setting port information. Port Id: PortId, Port Name: PortName, Operation: Operation, Status: Status, Failure reason (value = FailureReason): ControlFailureReason.

Message #

Failed when setting port information. Port Id: %1, Port Name: %2, Operation: %3, Status: %4, Failure reason (value = %6): %5

Fields #

NameDescription
PortId UInt32
PortName UnicodeString
Operation UInt16
Known values
%%2456
Open key file.
%%2457
Delete key file.
%%2458
Read persisted key from file.
%%2459
Write persisted key to file.
%%2464
Export of persistent cryptographic key.
%%2465
Import of persistent cryptographic key.
%%2480
Open Key.
%%2481
Create Key.
%%2482
Delete Key.
%%2483
Encrypt.
%%2484
Decrypt.
%%2485
Sign hash.
%%2486
Secret agreement.
%%2487
Domain settings.
%%2488
Local settings.
%%2489
Add provider.
%%2490
Remove provider.
%%2491
Add context.
%%2492
Remove context.
%%2493
Add function.
%%2494
Remove function.
%%2495
Add function provider.
%%2496
Remove function provider.
%%2497
Add function property.
%%2498
Remove function property.
%%2499
Machine key.
%%2500
User key.
%%2501
Key Derivation.
%%2502
Claim Creation.
%%2503
Claim Verification.
Status UInt32NTSTATUS reference
ControlFailureReason UInt32
FailureReason UInt32
Known values
%%2304
An Error occured during Logon.
%%2305
The specified user account has expired.
%%2306
The NetLogon component is not active.
%%2307
Account locked out.
%%2308
The user has not been granted the requested logon type at this machine.
%%2309
The specified account's password has expired.
%%2310
Account currently disabled.
%%2311
Account logon time restriction violation.
%%2312
User not allowed to logon at this computer.
%%2313
Unknown user name or bad password.
%%2314
Domain sid inconsistent.
%%2315
Smartcard logon is required and was not used.

Event ID 703

#
Channel
Operational

Description

Failed when setting port information. Port Id: , Port Name: , Operation: , Status: , Failure reason (value = ).

Fields #

NameDescription
PortId UInt32
PortName UnicodeString
Operation UInt16
Known values
%%2456
Open key file.
%%2457
Delete key file.
%%2458
Read persisted key from file.
%%2459
Write persisted key to file.
%%2464
Export of persistent cryptographic key.
%%2465
Import of persistent cryptographic key.
%%2480
Open Key.
%%2481
Create Key.
%%2482
Delete Key.
%%2483
Encrypt.
%%2484
Decrypt.
%%2485
Sign hash.
%%2486
Secret agreement.
%%2487
Domain settings.
%%2488
Local settings.
%%2489
Add provider.
%%2490
Remove provider.
%%2491
Add context.
%%2492
Remove context.
%%2493
Add function.
%%2494
Remove function.
%%2495
Add function provider.
%%2496
Remove function provider.
%%2497
Add function property.
%%2498
Remove function property.
%%2499
Machine key.
%%2500
User key.
%%2501
Key Derivation.
%%2502
Claim Creation.
%%2503
Claim Verification.
Status UInt32NTSTATUS reference
ControlFailureReason UInt32
FailureReason UInt32
Known values
%%2304
An Error occured during Logon.
%%2305
The specified user account has expired.
%%2306
The NetLogon component is not active.
%%2307
Account locked out.
%%2308
The user has not been granted the requested logon type at this machine.
%%2309
The specified account's password has expired.
%%2310
Account currently disabled.
%%2311
Account logon time restriction violation.
%%2312
User not allowed to logon at this computer.
%%2313
Unknown user name or bad password.
%%2314
Domain sid inconsistent.
%%2315
Smartcard logon is required and was not used.

Event ID 704: Ioctl started.

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Description

Ioctl started. Switch name: SwitchName, Port id: PortId, Port name: PortName, Operation: Operation, Process id: ProcessId, Irp: Irp.

Message #

Ioctl started. Switch name: %1, Port id: %2, Port name: %3, Operation: %4, Process id: %5, Irp: %6

Fields #

NameDescription
SwitchName UnicodeString
PortId UInt32
PortName UnicodeString
Operation UInt16
Known values
%%2456
Open key file.
%%2457
Delete key file.
%%2458
Read persisted key from file.
%%2459
Write persisted key to file.
%%2464
Export of persistent cryptographic key.
%%2465
Import of persistent cryptographic key.
%%2480
Open Key.
%%2481
Create Key.
%%2482
Delete Key.
%%2483
Encrypt.
%%2484
Decrypt.
%%2485
Sign hash.
%%2486
Secret agreement.
%%2487
Domain settings.
%%2488
Local settings.
%%2489
Add provider.
%%2490
Remove provider.
%%2491
Add context.
%%2492
Remove context.
%%2493
Add function.
%%2494
Remove function.
%%2495
Add function provider.
%%2496
Remove function provider.
%%2497
Add function property.
%%2498
Remove function property.
%%2499
Machine key.
%%2500
User key.
%%2501
Key Derivation.
%%2502
Claim Creation.
%%2503
Claim Verification.
ProcessId UInt32
Irp Pointer
Status UInt32NTSTATUS reference

Event ID 704

#
Channel
Operational

Description

Ioctl started. Switch name: , Port id: , Port name: , Operation: , Process id: , Irp.

Fields #

NameDescription
SwitchName UnicodeString
PortId UInt32
PortName UnicodeString
Operation UInt16
Known values
%%2456
Open key file.
%%2457
Delete key file.
%%2458
Read persisted key from file.
%%2459
Write persisted key to file.
%%2464
Export of persistent cryptographic key.
%%2465
Import of persistent cryptographic key.
%%2480
Open Key.
%%2481
Create Key.
%%2482
Delete Key.
%%2483
Encrypt.
%%2484
Decrypt.
%%2485
Sign hash.
%%2486
Secret agreement.
%%2487
Domain settings.
%%2488
Local settings.
%%2489
Add provider.
%%2490
Remove provider.
%%2491
Add context.
%%2492
Remove context.
%%2493
Add function.
%%2494
Remove function.
%%2495
Add function provider.
%%2496
Remove function provider.
%%2497
Add function property.
%%2498
Remove function property.
%%2499
Machine key.
%%2500
User key.
%%2501
Key Derivation.
%%2502
Claim Creation.
%%2503
Claim Verification.
ProcessId UInt32
Irp Pointer
Status UInt32NTSTATUS reference

Event ID 705: Failed when setting switch information.

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Description

Failed when setting switch information. Switch name: SwitchName, Operation: Operation, Status: Status, Failure reason (value = FailureReason): ControlFailureReason.

Message #

Failed when setting switch information. Switch name: %1, Operation: %2, Status: %3, Failure reason (value = %5): %4

Fields #

NameDescription
SwitchName UnicodeString
Operation UInt16
Known values
%%2456
Open key file.
%%2457
Delete key file.
%%2458
Read persisted key from file.
%%2459
Write persisted key to file.
%%2464
Export of persistent cryptographic key.
%%2465
Import of persistent cryptographic key.
%%2480
Open Key.
%%2481
Create Key.
%%2482
Delete Key.
%%2483
Encrypt.
%%2484
Decrypt.
%%2485
Sign hash.
%%2486
Secret agreement.
%%2487
Domain settings.
%%2488
Local settings.
%%2489
Add provider.
%%2490
Remove provider.
%%2491
Add context.
%%2492
Remove context.
%%2493
Add function.
%%2494
Remove function.
%%2495
Add function provider.
%%2496
Remove function provider.
%%2497
Add function property.
%%2498
Remove function property.
%%2499
Machine key.
%%2500
User key.
%%2501
Key Derivation.
%%2502
Claim Creation.
%%2503
Claim Verification.
Status UInt32NTSTATUS reference
ControlFailureReason UInt32
FailureReason UInt32
Known values
%%2304
An Error occured during Logon.
%%2305
The specified user account has expired.
%%2306
The NetLogon component is not active.
%%2307
Account locked out.
%%2308
The user has not been granted the requested logon type at this machine.
%%2309
The specified account's password has expired.
%%2310
Account currently disabled.
%%2311
Account logon time restriction violation.
%%2312
User not allowed to logon at this computer.
%%2313
Unknown user name or bad password.
%%2314
Domain sid inconsistent.
%%2315
Smartcard logon is required and was not used.

Event ID 705

#
Channel
Operational

Description

Failed when setting switch information. Switch name: , Operation: , Status: , Failure reason (value = ).

Fields #

NameDescription
SwitchName UnicodeString
Operation UInt16
Known values
%%2456
Open key file.
%%2457
Delete key file.
%%2458
Read persisted key from file.
%%2459
Write persisted key to file.
%%2464
Export of persistent cryptographic key.
%%2465
Import of persistent cryptographic key.
%%2480
Open Key.
%%2481
Create Key.
%%2482
Delete Key.
%%2483
Encrypt.
%%2484
Decrypt.
%%2485
Sign hash.
%%2486
Secret agreement.
%%2487
Domain settings.
%%2488
Local settings.
%%2489
Add provider.
%%2490
Remove provider.
%%2491
Add context.
%%2492
Remove context.
%%2493
Add function.
%%2494
Remove function.
%%2495
Add function provider.
%%2496
Remove function provider.
%%2497
Add function property.
%%2498
Remove function property.
%%2499
Machine key.
%%2500
User key.
%%2501
Key Derivation.
%%2502
Claim Creation.
%%2503
Claim Verification.
Status UInt32NTSTATUS reference
ControlFailureReason UInt32
FailureReason UInt32
Known values
%%2304
An Error occured during Logon.
%%2305
The specified user account has expired.
%%2306
The NetLogon component is not active.
%%2307
Account locked out.
%%2308
The user has not been granted the requested logon type at this machine.
%%2309
The specified account's password has expired.
%%2310
Account currently disabled.
%%2311
Account logon time restriction violation.
%%2312
User not allowed to logon at this computer.
%%2313
Unknown user name or bad password.
%%2314
Domain sid inconsistent.
%%2315
Smartcard logon is required and was not used.

Event ID 706: Ioctl pended.

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Description

Ioctl pended. Switch name: SwitchName, Port id: PortId, Port name: PortName, Operation: Operation, Process id: ProcessId, Irp: Irp.

Message #

Ioctl pended. Switch name: %1, Port id: %2, Port name: %3, Operation: %4, Process id: %5, Irp: %6

Fields #

NameDescription
SwitchName UnicodeString
PortId UInt32
PortName UnicodeString
Operation UInt16
Known values
%%2456
Open key file.
%%2457
Delete key file.
%%2458
Read persisted key from file.
%%2459
Write persisted key to file.
%%2464
Export of persistent cryptographic key.
%%2465
Import of persistent cryptographic key.
%%2480
Open Key.
%%2481
Create Key.
%%2482
Delete Key.
%%2483
Encrypt.
%%2484
Decrypt.
%%2485
Sign hash.
%%2486
Secret agreement.
%%2487
Domain settings.
%%2488
Local settings.
%%2489
Add provider.
%%2490
Remove provider.
%%2491
Add context.
%%2492
Remove context.
%%2493
Add function.
%%2494
Remove function.
%%2495
Add function provider.
%%2496
Remove function provider.
%%2497
Add function property.
%%2498
Remove function property.
%%2499
Machine key.
%%2500
User key.
%%2501
Key Derivation.
%%2502
Claim Creation.
%%2503
Claim Verification.
ProcessId UInt32
Irp Pointer
Status UInt32NTSTATUS reference

Event ID 706

#
Channel
Operational

Description

Ioctl pended. Switch name: , Port id: , Port name: , Operation: , Process id: , Irp.

Fields #

NameDescription
SwitchName UnicodeString
PortId UInt32
PortName UnicodeString
Operation UInt16
Known values
%%2456
Open key file.
%%2457
Delete key file.
%%2458
Read persisted key from file.
%%2459
Write persisted key to file.
%%2464
Export of persistent cryptographic key.
%%2465
Import of persistent cryptographic key.
%%2480
Open Key.
%%2481
Create Key.
%%2482
Delete Key.
%%2483
Encrypt.
%%2484
Decrypt.
%%2485
Sign hash.
%%2486
Secret agreement.
%%2487
Domain settings.
%%2488
Local settings.
%%2489
Add provider.
%%2490
Remove provider.
%%2491
Add context.
%%2492
Remove context.
%%2493
Add function.
%%2494
Remove function.
%%2495
Add function provider.
%%2496
Remove function provider.
%%2497
Add function property.
%%2498
Remove function property.
%%2499
Machine key.
%%2500
User key.
%%2501
Key Derivation.
%%2502
Claim Creation.
%%2503
Claim Verification.
ProcessId UInt32
Irp Pointer
Status UInt32NTSTATUS reference

Event ID 751: Matched redirect flow for deletion.

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Description

Matched redirect flow for deletion. Port id: , Layer id: , Src ip: , Dst ip: , Src port: , Dst port: , Protocol: , Encap dest ip: , Encap src ip: , Inner dest mac: , Gre key: , Port name.

Message #

Matched redirect flow for deletion. Port id: %1, Layer id: %2, Src ip: %3, Dst ip: %4, Src port: %5, Dst port: %6, Protocol: %7, Encap dest ip: %8, Encap src ip: %9, Inner dest mac: %10, Gre key: %11, Port name: %12

Fields #

NameDescription
PortId UInt32
LayerId UnicodeString
SrcIpv4Addr UInt32
DstIpv4Addr UInt32
SrcPort UInt16
DstPort UInt16
IpProtocol UInt8
EncapDstIpv4Addr UInt32
EncapSrcIpv4Addr UInt32
InnerDestMacAddr UnicodeString
GreKey UInt32
PortName UnicodeString

Event ID 751

#
Channel
Operational

Description

Matched redirect flow for deletion. Port id: , Layer id: , Src ip: , Dst ip: , Src port: , Dst port: , Protocol: , Encap dest ip: , Encap src ip: , Inner dest mac: , Gre key: , Port name.

Fields #

NameDescription
PortId UInt32
LayerId UnicodeString
SrcIpv4Addr UInt32
DstIpv4Addr UInt32
SrcPort UInt16
DstPort UInt16
IpProtocol UInt8
EncapDstIpv4Addr UInt32
EncapSrcIpv4Addr UInt32
InnerDestMacAddr UnicodeString
GreKey UInt32
PortName UnicodeString

Event ID 752: Matched redirect flow for deletion.

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Description

Matched redirect flow for deletion. Port id: , Layer id: , Src ip: , Dst ip: , Src port: , Dst port: , Protocol: , Encap dest ip: , Encap src ip: , Inner dest mac: , Gre key: , Port name.

Message #

Matched redirect flow for deletion. Port id: %1, Layer id: %2, Src ip: %3, Dst ip: %4, Src port: %5, Dst port: %6, Protocol: %7, Encap dest ip: %8, Encap src ip: %9, Inner dest mac: %10, Gre key: %11, Port name: %12

Fields #

NameDescription
PortId UInt32
LayerId UnicodeString
SrcIpv6Addr Binary
DstIpv6Addr Binary
SrcPort UInt16
DstPort UInt16
IpProtocol UInt8
EncapDstIpv6Addr Binary
EncapSrcIpv6Addr Binary
InnerDestMacAddr UnicodeString
GreKey UInt32
PortName UnicodeString

Event ID 752

#
Channel
Operational

Description

Matched redirect flow for deletion. Port id: , Layer id: , Src ip: , Dst ip: , Src port: , Dst port: , Protocol: , Encap dest ip: , Encap src ip: , Inner dest mac: , Gre key: , Port name.

Fields #

NameDescription
PortId UInt32
LayerId UnicodeString
SrcIpv6Addr Binary
DstIpv6Addr Binary
SrcPort UInt16
DstPort UInt16
IpProtocol UInt8
EncapDstIpv6Addr Binary
EncapSrcIpv6Addr Binary
InnerDestMacAddr UnicodeString
GreKey UInt32
PortName UnicodeString

Event ID 800: GFT offload capabilities in the context of Context.

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Message #

GFT offload capabilities in the context of %1. Flags %2, CounterCapabilities %3, SupportedTableTypes %4, SupportedEncapsulationTypes %5, SupportedIngressExactMatchTableActions %6, SupportedEgressExactMatchTableActions %7, SoftwareSupportedIngressExactMatchTableActions %8, SoftwareSupportedEgressExactMatchTableActions %9, SupportedIngressWildcardMatchTableActions %10, SupportedEgressWildcardMatchTableActions %11, SoftwareSupportedIngressWildcardMatchTableActions %12, SoftwareSupportedEgressWildcardMatchTableActions %13, NumPacketCounterObjects %14, NumByteCounterObjects %15, NumPacketByteCounterObjects %16, NumPacketByteCounterAndStateObjects %17, NumCounterObjectsPerIngressExactMatchFlowEntry %18, NumCounterObjectsPerEgressExactMatchFlowEntry %19 NumCounterObjectsPerIngressWildcardMatchFlowEntry %20, NumCounterObjectsPerEgressWildcardMatchFlowEntry %21.

Fields #

NameDescription
Context UnicodeString
Flags UInt32
CounterCapabilities UInt32
SupportedTableTypes UInt32
SupportedEncapsulationTypes UInt32
SupportedIngressExactMatchTableActions UInt32
SupportedEgressExactMatchTableActions UInt32
SoftwareSupportedIngressExactMatchTableActions UInt32
SoftwareSupportedEgressExactMatchTableActions UInt32
SupportedIngressWildcardMatchTableActions UInt32
SupportedEgressWildcardMatchTableActions UInt32
SoftwareSupportedIngressWildcardMatchTableActions UInt32
SoftwareSupportedEgressWildcardMatchTableActions UInt32
NumPacketCounterObjects UInt32
NumByteCounterObjects UInt32
NumPacketByteCounterObjects UInt32
NumPacketByteCounterAndStateObjects UInt32
NumCounterObjectsPerIngressExactMatchFlowEntry UInt32
NumCounterObjectsPerEgressExactMatchFlowEntry UInt32
NumCounterObjectsPerIngressWildcardMatchFlowEntry UInt32
NumCounterObjectsPerEgressWildcardMatchFlowEntry UInt32

Event ID 800

#
Channel
Operational

Fields #

NameDescription
Context UnicodeString
Flags UInt32
CounterCapabilities UInt32
SupportedTableTypes UInt32
SupportedEncapsulationTypes UInt32
SupportedIngressExactMatchTableActions UInt32
SupportedEgressExactMatchTableActions UInt32
SoftwareSupportedIngressExactMatchTableActions UInt32
SoftwareSupportedEgressExactMatchTableActions UInt32
SupportedIngressWildcardMatchTableActions UInt32
SupportedEgressWildcardMatchTableActions UInt32
SoftwareSupportedIngressWildcardMatchTableActions UInt32
SoftwareSupportedEgressWildcardMatchTableActions UInt32
NumPacketCounterObjects UInt32
NumByteCounterObjects UInt32
NumPacketByteCounterObjects UInt32
NumPacketByteCounterAndStateObjects UInt32
NumCounterObjectsPerIngressExactMatchFlowEntry UInt32
NumCounterObjectsPerEgressExactMatchFlowEntry UInt32
NumCounterObjectsPerIngressWildcardMatchFlowEntry UInt32
NumCounterObjectsPerEgressWildcardMatchFlowEntry UInt32

Event ID 801: GFT offload counters updated Context.

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Message #

GFT offload counters updated %1.

Fields #

NameDescription
Context UnicodeString

Event ID 801

#
Channel
Operational

Description

GFT offload counters updated .

Fields #

NameDescription
Context UnicodeString

Event ID 802: GFT aggregate counters are not freed because either the port could not be referenced or the OID request failed.

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Description

GFT aggregate counters are not freed because either the port could not be referenced or the OID request failed. Status: Status, GFT Counter id: GftCounterId, Port id: PortId, Port name: PortName.

Message #

GFT aggregate counters are not freed because either the port could not be referenced or the OID request failed. Status: %1, GFT Counter id: %2, Port id: %3, Port name: %4.

Fields #

NameDescription
Status UInt32NTSTATUS reference
GftCounterId UInt32
PortId UInt32
PortName UnicodeString

Event ID 802

#
Channel
Operational

Description

GFT aggregate counters are not freed because either the port could not be referenced or the OID request failed. Status: , GFT Counter id: , Port id: , Port name: .

Fields #

NameDescription
Status UInt32NTSTATUS reference
GftCounterId UInt32
PortId UInt32
PortName UnicodeString

Event ID 803: VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) reset TTL for GFT offloaded unified flow UnifiedFlow , GftProviderFlowEntryId GftProviderFlowEntryId.

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Message #

VfpExt on port %1 (Name = %2, FriendlyName = %3) reset TTL for GFT offloaded unified flow %4  , GftProviderFlowEntryId %5. CurrSysTime %6, GftTimeStamp %7, GftUpdateInTtlUnits %8, MaxTtl %9, Ttl %10, PrevNumPackets %13, PrevNumBytes %14 NumPackets %11, NumBytes %12

Fields #

NameDescription
PortId UInt32
PortName UnicodeString
PortFriendlyName UnicodeString
UnifiedFlow UInt64
GftProviderFlowEntryId UInt64
CurrSysTime UInt64
GftTimeStamp UInt64
GftUpdateElapsedInTtlUnits UInt32
MaxTtl UInt32
TTL UInt32
NumPackets UInt64
NumBytes UInt64
PrevNumPackets UInt64
PrevNumBytes UInt64

Event ID 803

#
Channel
Operational

Fields #

NameDescription
PortId UInt32
PortName UnicodeString
PortFriendlyName UnicodeString
UnifiedFlow UInt64
GftProviderFlowEntryId UInt64
CurrSysTime UInt64
GftTimeStamp UInt64
GftUpdateElapsedInTtlUnits UInt32
MaxTtl UInt32
TTL UInt32
NumPackets UInt64
NumBytes UInt64
PrevNumPackets UInt64
PrevNumBytes UInt64

Event ID 804: VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) changed GFT flow state of UF UnifiedFlow from OldGftFlowState to NewGftFlowState.

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Description

VfpExt on port (Name = , FriendlyName = ) changed GFT flow state of UF from to . GftPendingDelete is , GftMarkedForHwDeletion is , ReoffloadReqd is , RetryOffload is , BlockReason , RetryReason.

Message #

VfpExt on port %1 (Name = %2, FriendlyName = %3) changed GFT flow state of UF %4 from %5 to %6. GftPendingDelete is %7, GftMarkedForHwDeletion is %8, ReoffloadReqd is %9, RetryOffload is %10, BlockReason %11, RetryReason %12

Fields #

NameDescription
PortId UInt32
PortName UnicodeString
PortFriendlyName UnicodeString
UnifiedFlow UInt64
OldGftFlowState UInt8
NewGftFlowState UInt8
IsPendingDelete Boolean
IsMarkedForHwDeletion Boolean
ReoffloadReqd Boolean
RetryOffload Boolean
GftFlowBlockReason UInt8
GftFlowRetryReason UInt8

Event ID 804

#
Channel
Operational

Description

VfpExt on port (Name = , FriendlyName = ) changed GFT flow state of UF from to . GftPendingDelete is , GftMarkedForHwDeletion is , ReoffloadReqd is , RetryOffload is , BlockReason , RetryReason.

Fields #

NameDescription
PortId UInt32
PortName UnicodeString
PortFriendlyName UnicodeString
UnifiedFlow UInt64
OldGftFlowState UInt8
NewGftFlowState UInt8
IsPendingDelete Boolean
IsMarkedForHwDeletion Boolean
ReoffloadReqd Boolean
RetryOffload Boolean
GftFlowBlockReason UInt8
GftFlowRetryReason UInt8

Event ID 805: VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) UF UnifiedFlow add_flow failed with status Status due to FailureReason.

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Message #

VfpExt on port %1 (Name = %2, FriendlyName = %3) UF %4 add_flow failed with status %5 due to %6

Fields #

NameDescription
PortId UInt32
PortName UnicodeString
PortFriendlyName UnicodeString
UnifiedFlow UInt64
Status UInt32NTSTATUS reference
FailureReason UnicodeString
Known values
%%2304
An Error occured during Logon.
%%2305
The specified user account has expired.
%%2306
The NetLogon component is not active.
%%2307
Account locked out.
%%2308
The user has not been granted the requested logon type at this machine.
%%2309
The specified account's password has expired.
%%2310
Account currently disabled.
%%2311
Account logon time restriction violation.
%%2312
User not allowed to logon at this computer.
%%2313
Unknown user name or bad password.
%%2314
Domain sid inconsistent.
%%2315
Smartcard logon is required and was not used.

Event ID 805

#
Channel
Operational

Description

VfpExt on port (Name = , FriendlyName = ) UF add_flow failed with status due to.

Fields #

NameDescription
PortId UInt32
PortName UnicodeString
PortFriendlyName UnicodeString
UnifiedFlow UInt64
Status UInt32NTSTATUS reference
FailureReason UnicodeString
Known values
%%2304
An Error occured during Logon.
%%2305
The specified user account has expired.
%%2306
The NetLogon component is not active.
%%2307
Account locked out.
%%2308
The user has not been granted the requested logon type at this machine.
%%2309
The specified account's password has expired.
%%2310
Account currently disabled.
%%2311
Account logon time restriction violation.
%%2312
User not allowed to logon at this computer.
%%2313
Unknown user name or bad password.
%%2314
Domain sid inconsistent.
%%2315
Smartcard logon is required and was not used.

Event ID 806: VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) UF UnifiedFlow, ProviderFlowEntry ProviderFlowEntryId add_flow succeded.

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Description

VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) UF UnifiedFlow, ProviderFlowEntry ProviderFlowEntryId add_flow succeded. Flow state GftFlowState, Offload reason GftFlowOffloadReason, GftPendingDelete IsPendingDelete.

Message #

VfpExt on port %1 (Name = %2, FriendlyName = %3) UF %4, ProviderFlowEntry %5 add_flow succeded. Flow state %6, Offload reason %7, GftPendingDelete %8

Fields #

NameDescription
PortId UInt32
PortName UnicodeString
PortFriendlyName UnicodeString
UnifiedFlow UInt64
ProviderFlowEntryId UInt64
GftFlowState UInt8
GftFlowOffloadReason UInt8
IsPendingDelete Boolean

Event ID 806

#
Channel
Operational

Description

VfpExt on port (Name = , FriendlyName = ) UF , ProviderFlowEntry add_flow succeded. Flow state , Offload reason , GftPendingDelete.

Fields #

NameDescription
PortId UInt32
PortName UnicodeString
PortFriendlyName UnicodeString
UnifiedFlow UInt64
ProviderFlowEntryId UInt64
GftFlowState UInt8
GftFlowOffloadReason UInt8
IsPendingDelete Boolean

Event ID 807: VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) UF UnifiedFlow delete_flow failed with status Status due to FailureReason.

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Message #

VfpExt on port %1 (Name = %2, FriendlyName = %3) UF %4 delete_flow failed with status %5 due to %6

Fields #

NameDescription
PortId UInt32
PortName UnicodeString
PortFriendlyName UnicodeString
UnifiedFlow UInt64
Status UInt32NTSTATUS reference
FailureReason UnicodeString
Known values
%%2304
An Error occured during Logon.
%%2305
The specified user account has expired.
%%2306
The NetLogon component is not active.
%%2307
Account locked out.
%%2308
The user has not been granted the requested logon type at this machine.
%%2309
The specified account's password has expired.
%%2310
Account currently disabled.
%%2311
Account logon time restriction violation.
%%2312
User not allowed to logon at this computer.
%%2313
Unknown user name or bad password.
%%2314
Domain sid inconsistent.
%%2315
Smartcard logon is required and was not used.

Event ID 807

#
Channel
Operational

Description

VfpExt on port (Name = , FriendlyName = ) UF delete_flow failed with status due to.

Fields #

NameDescription
PortId UInt32
PortName UnicodeString
PortFriendlyName UnicodeString
UnifiedFlow UInt64
Status UInt32NTSTATUS reference
FailureReason UnicodeString
Known values
%%2304
An Error occured during Logon.
%%2305
The specified user account has expired.
%%2306
The NetLogon component is not active.
%%2307
Account locked out.
%%2308
The user has not been granted the requested logon type at this machine.
%%2309
The specified account's password has expired.
%%2310
Account currently disabled.
%%2311
Account logon time restriction violation.
%%2312
User not allowed to logon at this computer.
%%2313
Unknown user name or bad password.
%%2314
Domain sid inconsistent.
%%2315
Smartcard logon is required and was not used.

Event ID 808: Skipping Sx Port context PortContext (Name = Name, FriendlyName = FriendlyName) as a match with reason 'FailureReason'.

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Message #

Skipping Sx Port context %1 (Name = %2, FriendlyName = %3) as a match with reason '%4'

Fields #

NameDescription
PortContext UInt64
Name UnicodeString
FriendlyName UnicodeString
FailureReason UInt8
Known values
%%2304
An Error occured during Logon.
%%2305
The specified user account has expired.
%%2306
The NetLogon component is not active.
%%2307
Account locked out.
%%2308
The user has not been granted the requested logon type at this machine.
%%2309
The specified account's password has expired.
%%2310
Account currently disabled.
%%2311
Account logon time restriction violation.
%%2312
User not allowed to logon at this computer.
%%2313
Unknown user name or bad password.
%%2314
Domain sid inconsistent.
%%2315
Smartcard logon is required and was not used.

Event ID 808

#
Channel
Operational

Description

Skipping Sx Port context PortContext (Name = Name, FriendlyName = FriendlyName) as a match with reason 'FailureReason'.

Fields #

NameDescription
PortContext UInt64
Name UnicodeString
FriendlyName UnicodeString
FailureReason UInt8
Known values
%%2304
An Error occured during Logon.
%%2305
The specified user account has expired.
%%2306
The NetLogon component is not active.
%%2307
Account locked out.
%%2308
The user has not been granted the requested logon type at this machine.
%%2309
The specified account's password has expired.
%%2310
Account currently disabled.
%%2311
Account logon time restriction violation.
%%2312
User not allowed to logon at this computer.
%%2313
Unknown user name or bad password.
%%2314
Domain sid inconsistent.
%%2315
Smartcard logon is required and was not used.

Event ID 809: Vfp failed to issue OID for VPort PortId with status Status due to FailureReason.

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Message #

Vfp failed to issue OID for VPort %1 with status %2 due to %3

Fields #

NameDescription
PortId UInt32
Status UInt32NTSTATUS reference
FailureReason UnicodeString
Known values
%%2304
An Error occured during Logon.
%%2305
The specified user account has expired.
%%2306
The NetLogon component is not active.
%%2307
Account locked out.
%%2308
The user has not been granted the requested logon type at this machine.
%%2309
The specified account's password has expired.
%%2310
Account currently disabled.
%%2311
Account logon time restriction violation.
%%2312
User not allowed to logon at this computer.
%%2313
Unknown user name or bad password.
%%2314
Domain sid inconsistent.
%%2315
Smartcard logon is required and was not used.

Event ID 809

#
Channel
Operational

Description

Vfp failed to issue OID for VPort with status due to.

Fields #

NameDescription
PortId UInt32
Status UInt32NTSTATUS reference
FailureReason UnicodeString
Known values
%%2304
An Error occured during Logon.
%%2305
The specified user account has expired.
%%2306
The NetLogon component is not active.
%%2307
Account locked out.
%%2308
The user has not been granted the requested logon type at this machine.
%%2309
The specified account's password has expired.
%%2310
Account currently disabled.
%%2311
Account logon time restriction violation.
%%2312
User not allowed to logon at this computer.
%%2313
Unknown user name or bad password.
%%2314
Domain sid inconsistent.
%%2315
Smartcard logon is required and was not used.

Event ID 810: Failed to set GFT port parser settings on port PortId (Name = PortName, FriendlyName = FriendlyName) with status Status due to FailureReason.

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Message #

Failed to set GFT port parser settings on port %1 (Name = %2, FriendlyName = %3) with status %4 due to %5

Fields #

NameDescription
PortId UInt32
PortName UnicodeString
FriendlyName UnicodeString
Status UInt32NTSTATUS reference
FailureReason UnicodeString
Known values
%%2304
An Error occured during Logon.
%%2305
The specified user account has expired.
%%2306
The NetLogon component is not active.
%%2307
Account locked out.
%%2308
The user has not been granted the requested logon type at this machine.
%%2309
The specified account's password has expired.
%%2310
Account currently disabled.
%%2311
Account logon time restriction violation.
%%2312
User not allowed to logon at this computer.
%%2313
Unknown user name or bad password.
%%2314
Domain sid inconsistent.
%%2315
Smartcard logon is required and was not used.

Event ID 810

#
Channel
Operational

Description

Failed to set GFT port parser settings on port (Name = , FriendlyName = ) with status due to.

Fields #

NameDescription
PortId UInt32
PortName UnicodeString
FriendlyName UnicodeString
Status UInt32NTSTATUS reference
FailureReason UnicodeString
Known values
%%2304
An Error occured during Logon.
%%2305
The specified user account has expired.
%%2306
The NetLogon component is not active.
%%2307
Account locked out.
%%2308
The user has not been granted the requested logon type at this machine.
%%2309
The specified account's password has expired.
%%2310
Account currently disabled.
%%2311
Account logon time restriction violation.
%%2312
User not allowed to logon at this computer.
%%2313
Unknown user name or bad password.
%%2314
Domain sid inconsistent.
%%2315
Smartcard logon is required and was not used.

Event ID 900: Tag Id TagId completed operation with status: Status.

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Description

Tag Id TagId completed operation with status: Status. Extended operation status: Reason.

Message #

Tag Id %1 completed operation with status: %2. Extended operation status: %3

Fields #

NameDescription
TagId UnicodeString
Status UInt32NTSTATUS reference
Reason UInt8

Event ID 900

#
Channel
Operational

Description

Tag Id completed operation with status: . Extended operation status.

Fields #

NameDescription
TagId UnicodeString
Status UInt32NTSTATUS reference
Reason UInt8

Event ID 950: VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) ignore adding into space SpaceId the following mapping: {mapping type = MappingType, ca = CustomerIpv4Addr, pa = ProviderIpv...

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Message #

VfpExt on port %1 (Name = %19, FriendlyName = %20) ignore adding into space %2 the following mapping: {mapping type = %3, ca = %4, pa = %7, mac addr = %10, customer mac addr = %11, isolation id = %12, flags = {all = %13, permanent = %14, non unique PA = %15, mac mapping = %16, L4-load-balanced mapping = %17, L3-load-balanced mapping = %18}}

Fields #

NameDescription
PortId UInt32
SpaceId UnicodeString
MappingType UInt8
CustomerIpv4Addr UInt32
CustomerIpv6AddrLength UInt32
CustomerIpv6Addr Binary
ProviderIpv4Addr UInt32
ProviderIpv6AddrLength UInt32
ProviderIpv6Addr Binary
MacAddr UnicodeString
CustomerMacAddr UnicodeString
IsolationId UInt32
Flags UInt32
PermanentFlag Boolean
NonUniquePAFlag Boolean
MacMappingFlag Boolean
L4LoadBalanced Boolean
L3LoadBalanced Boolean
PortName UnicodeString
PortFriendlyName UnicodeString

Event ID 950

#
Channel
Operational

Fields #

NameDescription
PortId UInt32
SpaceId UnicodeString
MappingType UInt8
CustomerIpv4Addr UInt32
CustomerIpv6AddrLength UInt32
CustomerIpv6Addr Binary
ProviderIpv4Addr UInt32
ProviderIpv6AddrLength UInt32
ProviderIpv6Addr Binary
MacAddr UnicodeString
CustomerMacAddr UnicodeString
IsolationId UInt32
Flags UInt32
PermanentFlag Boolean
NonUniquePAFlag Boolean
MacMappingFlag Boolean
L4LoadBalanced Boolean
L3LoadBalanced Boolean
PortName UnicodeString
PortFriendlyName UnicodeString

Event ID 951: VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) ignore adding into space SpaceId the following mapping: {mapping type = MappingType, ca = CustomerIpv6Addr, pa = ProviderIpv...

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Message #

VfpExt on port %1 (Name = %19, FriendlyName = %20) ignore adding into space %2 the following mapping: {mapping type = %3, ca = %6, pa = %7, mac addr = %10, customer mac addr = %11, isolation id = %12, flags = {all = %13, permanent = %14, non unique PA = %15, mac mapping = %16, L4-load-balanced mapping = %17, L3-load-balanced mapping = %18}}

Fields #

NameDescription
PortId UInt32
SpaceId UnicodeString
MappingType UInt8
CustomerIpv4Addr UInt32
CustomerIpv6AddrLength UInt32
CustomerIpv6Addr Binary
ProviderIpv4Addr UInt32
ProviderIpv6AddrLength UInt32
ProviderIpv6Addr Binary
MacAddr UnicodeString
CustomerMacAddr UnicodeString
IsolationId UInt32
Flags UInt32
PermanentFlag Boolean
NonUniquePAFlag Boolean
MacMappingFlag Boolean
L4LoadBalanced Boolean
L3LoadBalanced Boolean
PortName UnicodeString
PortFriendlyName UnicodeString

Event ID 951

#
Channel
Operational

Fields #

NameDescription
PortId UInt32
SpaceId UnicodeString
MappingType UInt8
CustomerIpv4Addr UInt32
CustomerIpv6AddrLength UInt32
CustomerIpv6Addr Binary
ProviderIpv4Addr UInt32
ProviderIpv6AddrLength UInt32
ProviderIpv6Addr Binary
MacAddr UnicodeString
CustomerMacAddr UnicodeString
IsolationId UInt32
Flags UInt32
PermanentFlag Boolean
NonUniquePAFlag Boolean
MacMappingFlag Boolean
L4LoadBalanced Boolean
L3LoadBalanced Boolean
PortName UnicodeString
PortFriendlyName UnicodeString

Event ID 952: VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) ignore adding into space SpaceId the following mapping: {mapping type = MappingType, ca = CustomerIpv4Addr, pa = ProviderIpv...

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Message #

VfpExt on port %1 (Name = %19, FriendlyName = %20) ignore adding into space %2 the following mapping: {mapping type = %3, ca = %4, pa = %9, mac addr = %10, customer mac addr = %11, isolation id = %12, flags = {all = %13, permanent = %14, non unique PA = %15, mac mapping = %16, L4-load-balanced mapping = %17, L3-load-balanced mapping = %18}}

Fields #

NameDescription
PortId UInt32
SpaceId UnicodeString
MappingType UInt8
CustomerIpv4Addr UInt32
CustomerIpv6AddrLength UInt32
CustomerIpv6Addr Binary
ProviderIpv4Addr UInt32
ProviderIpv6AddrLength UInt32
ProviderIpv6Addr Binary
MacAddr UnicodeString
CustomerMacAddr UnicodeString
IsolationId UInt32
Flags UInt32
PermanentFlag Boolean
NonUniquePAFlag Boolean
MacMappingFlag Boolean
L4LoadBalanced Boolean
L3LoadBalanced Boolean
PortName UnicodeString
PortFriendlyName UnicodeString

Event ID 952

#
Channel
Operational

Fields #

NameDescription
PortId UInt32
SpaceId UnicodeString
MappingType UInt8
CustomerIpv4Addr UInt32
CustomerIpv6AddrLength UInt32
CustomerIpv6Addr Binary
ProviderIpv4Addr UInt32
ProviderIpv6AddrLength UInt32
ProviderIpv6Addr Binary
MacAddr UnicodeString
CustomerMacAddr UnicodeString
IsolationId UInt32
Flags UInt32
PermanentFlag Boolean
NonUniquePAFlag Boolean
MacMappingFlag Boolean
L4LoadBalanced Boolean
L3LoadBalanced Boolean
PortName UnicodeString
PortFriendlyName UnicodeString

Event ID 953: VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) ignore adding into space SpaceId the following mapping: {mapping type = MappingType, ca = CustomerIpv6Addr, pa = ProviderIpv...

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Message #

VfpExt on port %1 (Name = %19, FriendlyName = %20) ignore adding into space %2 the following mapping: {mapping type = %3, ca = %6, pa = %9, mac addr = %10, customer mac addr = %11, isolation id = %12, flags = {all = %13, permanent = %14, non unique PA = %15, mac mapping = %16, L4-load-balanced mapping = %17, L3-load-balanced mapping = %18}}

Fields #

NameDescription
PortId UInt32
SpaceId UnicodeString
MappingType UInt8
CustomerIpv4Addr UInt32
CustomerIpv6AddrLength UInt32
CustomerIpv6Addr Binary
ProviderIpv4Addr UInt32
ProviderIpv6AddrLength UInt32
ProviderIpv6Addr Binary
MacAddr UnicodeString
CustomerMacAddr UnicodeString
IsolationId UInt32
Flags UInt32
PermanentFlag Boolean
NonUniquePAFlag Boolean
MacMappingFlag Boolean
L4LoadBalanced Boolean
L3LoadBalanced Boolean
PortName UnicodeString
PortFriendlyName UnicodeString

Event ID 953

#
Channel
Operational

Fields #

NameDescription
PortId UInt32
SpaceId UnicodeString
MappingType UInt8
CustomerIpv4Addr UInt32
CustomerIpv6AddrLength UInt32
CustomerIpv6Addr Binary
ProviderIpv4Addr UInt32
ProviderIpv6AddrLength UInt32
ProviderIpv6Addr Binary
MacAddr UnicodeString
CustomerMacAddr UnicodeString
IsolationId UInt32
Flags UInt32
PermanentFlag Boolean
NonUniquePAFlag Boolean
MacMappingFlag Boolean
L4LoadBalanced Boolean
L3LoadBalanced Boolean
PortName UnicodeString
PortFriendlyName UnicodeString

Event ID 954: VfpExt deleted layer flow of type FlowType with flow id {src ip = SrcIpv4Addr, dst ip = DstIpv4Addr, src port = SrcPort, dst port = DstPort, protocol = IpProtocol}.

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Message #

VfpExt deleted layer flow of type %1 with flow id {src ip = %2, dst ip = %3, src port = %4, dst port = %5, protocol = %6}.

Fields #

NameDescription
FlowType UInt8
SrcIpv4Addr UInt32
DstIpv4Addr UInt32
SrcPort UInt16
DstPort UInt16
IpProtocol UInt8

Event ID 954

#
Channel
Operational

Description

VfpExt deleted layer flow of type with flow id {src ip = , dst ip = , src port = , dst port = , protocol = }.

Fields #

NameDescription
FlowType UInt8
SrcIpv4Addr UInt32
DstIpv4Addr UInt32
SrcPort UInt16
DstPort UInt16
IpProtocol UInt8

Event ID 955: VfpExt deleted layer flow of type FlowType with flow id {src ip = SrcIpv6Addr, dst ip = DstIpv6Addr, src port = SrcPort, dst port = DstPort, protocol = IpProtocol}.

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Message #

VfpExt deleted layer flow of type %1 with flow id {src ip = %2, dst ip = %3, src port = %4, dst port = %5, protocol = %6}.

Fields #

NameDescription
FlowType UInt8
SrcIpv6Addr Binary
DstIpv6Addr Binary
SrcPort UInt16
DstPort UInt16
IpProtocol UInt8

Event ID 955

#
Channel
Operational

Description

VfpExt deleted layer flow of type with flow id {src ip = , dst ip = , src port = , dst port = , protocol = }.

Fields #

NameDescription
FlowType UInt8
SrcIpv6Addr Binary
DstIpv6Addr Binary
SrcPort UInt16
DstPort UInt16
IpProtocol UInt8

Event ID 956: VfpExt deleted layer flow of type FlowType with flow id {src ip = SrcIpv4Addr, dst ip = DstIpv4Addr, protocol = IpProtocol, icmp type = IcmpType}.

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Message #

VfpExt deleted layer flow of type %1 with flow id {src ip = %2, dst ip = %3, protocol = %4, icmp type = %5}.

Fields #

NameDescription
FlowType UInt8
SrcIpv4Addr UInt32
DstIpv4Addr UInt32
IpProtocol UInt8
IcmpType UInt8

Event ID 956

#
Channel
Operational

Description

VfpExt deleted layer flow of type with flow id {src ip = , dst ip = , protocol = , icmp type = }.

Fields #

NameDescription
FlowType UInt8
SrcIpv4Addr UInt32
DstIpv4Addr UInt32
IpProtocol UInt8
IcmpType UInt8

Event ID 957: VfpExt deleted layer flow of type FlowType with flow id {src ip = SrcIpv6Addr, dst ip = DstIpv6Addr, protocol = IpProtocol, icmp type = IcmpType}.

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Message #

VfpExt deleted layer flow of type %1 with flow id {src ip = %2, dst ip = %3, protocol = %4, icmp type = %5}.

Fields #

NameDescription
FlowType UInt8
SrcIpv6Addr Binary
DstIpv6Addr Binary
IpProtocol UInt8
IcmpType UInt8

Event ID 957

#
Channel
Operational

Description

VfpExt deleted layer flow of type with flow id {src ip = , dst ip = , protocol = , icmp type = }.

Fields #

NameDescription
FlowType UInt8
SrcIpv6Addr Binary
DstIpv6Addr Binary
IpProtocol UInt8
IcmpType UInt8

Event ID 958: VfpExt deleted layer flow of type FlowType with flow id {src ip = SrcIpv4Addr, dst ip = DstIpv4Addr, src port = SrcPort, dst port = DstPort, protocol = IpProtocol}.

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Description

VfpExt deleted layer flow of type with flow id {src ip = , dst ip = , src port = , dst port = , protocol = }. IsMain = , NumPackets = , NumBytes = , NumPackets = , NumBytes =.

Message #

VfpExt deleted layer flow of type %1 with flow id {src ip = %3, dst ip = %4, src port = %5, dst port = %6, protocol = %7}. IsMain = %2, NumPackets = %8, NumBytes = %9, NumPackets = %10, NumBytes = %11

Fields #

NameDescription
FlowType UInt8
IsMain UInt8
SrcIpv4Addr UInt32
DstIpv4Addr UInt32
SrcPort UInt16
DstPort UInt16
IpProtocol UInt8
NumPackets UInt64
NumBytes UInt64
NumReversePackets UInt64
NumReverseBytes UInt64

Event ID 958

#
Channel
Operational

Description

VfpExt deleted layer flow of type with flow id {src ip = , dst ip = , src port = , dst port = , protocol = }. IsMain = , NumPackets = , NumBytes = , NumPackets = , NumBytes =.

Fields #

NameDescription
FlowType UInt8
IsMain UInt8
SrcIpv4Addr UInt32
DstIpv4Addr UInt32
SrcPort UInt16
DstPort UInt16
IpProtocol UInt8
NumPackets UInt64
NumBytes UInt64
NumReversePackets UInt64
NumReverseBytes UInt64

Event ID 959: VfpExt deleted layer flow of type FlowType with flow id {src ip = SrcIpv6Addr, dst ip = DstIpv6Addr, src port = SrcPort, dst port = DstPort, protocol = IpProtocol}.

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Description

VfpExt deleted layer flow of type with flow id {src ip = , dst ip = , src port = , dst port = , protocol = }. IsMain = , NumPackets = , NumBytes = , NumPackets = , NumBytes =.

Message #

VfpExt deleted layer flow of type %1 with flow id {src ip = %3, dst ip = %4, src port = %5, dst port = %6, protocol = %7}. IsMain = %2, NumPackets = %8, NumBytes = %9, NumPackets = %10, NumBytes = %11

Fields #

NameDescription
FlowType UInt8
IsMain UInt8
SrcIpv6Addr Binary
DstIpv6Addr Binary
SrcPort UInt16
DstPort UInt16
IpProtocol UInt8
NumPackets UInt64
NumBytes UInt64
NumReversePackets UInt64
NumReverseBytes UInt64

Event ID 959

#
Channel
Operational

Description

VfpExt deleted layer flow of type with flow id {src ip = , dst ip = , src port = , dst port = , protocol = }. IsMain = , NumPackets = , NumBytes = , NumPackets = , NumBytes =.

Fields #

NameDescription
FlowType UInt8
IsMain UInt8
SrcIpv6Addr Binary
DstIpv6Addr Binary
SrcPort UInt16
DstPort UInt16
IpProtocol UInt8
NumPackets UInt64
NumBytes UInt64
NumReversePackets UInt64
NumReverseBytes UInt64

Event ID 960: VfpExt deleted layer flow of type FlowType with flow id {src ip = SrcIpv4Addr, dst ip = DstIpv4Addr, protocol = IpProtocol, icmp type = IcmpType}.

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Description

VfpExt deleted layer flow of type FlowType with flow id {src ip = SrcIpv4Addr, dst ip = DstIpv4Addr, protocol = IpProtocol, icmp type = IcmpType}. IsMain = IsMain, NumPackets = NumPackets, NumBytes = NumBytes. NumPackets = NumReversePackets, NumBytes = NumReverseBytes.

Message #

VfpExt deleted layer flow of type %1 with flow id {src ip = %3, dst ip = %4, protocol = %5, icmp type = %6}. IsMain = %2, NumPackets = %7, NumBytes = %8. NumPackets = %9, NumBytes = %10

Fields #

NameDescription
FlowType UInt8
IsMain UInt8
SrcIpv4Addr UInt32
DstIpv4Addr UInt32
IpProtocol UInt8
IcmpType UInt8
NumPackets UInt64
NumBytes UInt64
NumReversePackets UInt64
NumReverseBytes UInt64

Event ID 960

#
Channel
Operational

Description

VfpExt deleted layer flow of type with flow id {src ip = , dst ip = , protocol = , icmp type = }. IsMain = , NumPackets = , NumBytes = . NumPackets = , NumBytes =.

Fields #

NameDescription
FlowType UInt8
IsMain UInt8
SrcIpv4Addr UInt32
DstIpv4Addr UInt32
IpProtocol UInt8
IcmpType UInt8
NumPackets UInt64
NumBytes UInt64
NumReversePackets UInt64
NumReverseBytes UInt64

Event ID 961: VfpExt deleted layer flow of type FlowType with flow id {src ip = SrcIpv6Addr, dst ip = DstIpv6Addr, protocol = IpProtocol, icmp type = IcmpType}.

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Description

VfpExt deleted layer flow of type FlowType with flow id {src ip = SrcIpv6Addr, dst ip = DstIpv6Addr, protocol = IpProtocol, icmp type = IcmpType}. IsMain = IsMain, NumPackets = NumPackets, NumBytes = NumBytes. NumPackets = NumReversePackets, NumBytes = NumReverseBytes.

Message #

VfpExt deleted layer flow of type %1 with flow id {src ip = %3, dst ip = %4, protocol = %5, icmp type = %6}. IsMain = %2, NumPackets = %7, NumBytes = %8. NumPackets = %9, NumBytes = %10

Fields #

NameDescription
FlowType UInt8
IsMain UInt8
SrcIpv6Addr Binary
DstIpv6Addr Binary
IpProtocol UInt8
IcmpType UInt8
NumPackets UInt64
NumBytes UInt64
NumReversePackets UInt64
NumReverseBytes UInt64

Event ID 961

#
Channel
Operational

Description

VfpExt deleted layer flow of type with flow id {src ip = , dst ip = , protocol = , icmp type = }. IsMain = , NumPackets = , NumBytes = . NumPackets = , NumBytes =.

Fields #

NameDescription
FlowType UInt8
IsMain UInt8
SrcIpv6Addr Binary
DstIpv6Addr Binary
IpProtocol UInt8
IcmpType UInt8
NumPackets UInt64
NumBytes UInt64
NumReversePackets UInt64
NumReverseBytes UInt64

Event ID 962: VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) failed to schedule work item due to status Status.

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Message #

VfpExt on port %1 (Name = %2, FriendlyName = %3) failed to schedule work item due to status %4

Fields #

NameDescription
PortId UInt32
PortName UnicodeString
PortFriendlyName UnicodeString
Status UInt32NTSTATUS reference

Event ID 962

#
Channel
Operational

Description

VfpExt on port (Name = , FriendlyName = ) failed to schedule work item due to status.

Fields #

NameDescription
PortId UInt32
PortName UnicodeString
PortFriendlyName UnicodeString
Status UInt32NTSTATUS reference

Event ID 963: Replacing layer flow addresses succeeded on port PortId (Name = PortName, FriendlyName = PortFriendlyName), layer LayerId, status Status, number of outbound flows replaced = NumOutboundFlowsReplace...

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Description

Replacing layer flow addresses succeeded on port PortId (Name = PortName, FriendlyName = PortFriendlyName), layer LayerId, status Status, number of outbound flows replaced = NumOutboundFlowsReplaced, number of inbound flows replaced = NumInboundFlowsReplaced.

Message #

Replacing layer flow addresses succeeded on port %1 (Name = %2, FriendlyName = %3), layer %4, status %5, number of outbound flows replaced = %6, number of inbound flows replaced = %7

Fields #

NameDescription
PortId UInt32
PortName UnicodeString
PortFriendlyName UnicodeString
LayerId UnicodeString
Status UInt32NTSTATUS reference
NumOutboundFlowsReplaced UInt32
NumInboundFlowsReplaced UInt32

Event ID 963

#
Channel
Operational

Description

Replacing layer flow addresses succeeded on port (Name = , FriendlyName = ), layer , status , number of outbound flows replaced = , number of inbound flows replaced =.

Fields #

NameDescription
PortId UInt32
PortName UnicodeString
PortFriendlyName UnicodeString
LayerId UnicodeString
Status UInt32NTSTATUS reference
NumOutboundFlowsReplaced UInt32
NumInboundFlowsReplaced UInt32

Event ID 964: Replacing layer flow addresses failed on port PortId (Name = PortName, FriendlyName = PortFriendlyName), layer LayerId, status Status, number of outbound flows replaced = NumOutboundFlowsReplaced, ...

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Description

Replacing layer flow addresses failed on port PortId (Name = PortName, FriendlyName = PortFriendlyName), layer LayerId, status Status, number of outbound flows replaced = NumOutboundFlowsReplaced, number of inbound flows replaced = NumInboundFlowsReplaced.

Message #

Replacing layer flow addresses failed on port %1 (Name = %2, FriendlyName = %3), layer %4, status %5, number of outbound flows replaced = %6, number of inbound flows replaced = %7

Fields #

NameDescription
PortId UInt32
PortName UnicodeString
PortFriendlyName UnicodeString
LayerId UnicodeString
Status UInt32NTSTATUS reference
NumOutboundFlowsReplaced UInt32
NumInboundFlowsReplaced UInt32

Event ID 964

#
Channel
Operational

Description

Replacing layer flow addresses failed on port (Name = , FriendlyName = ), layer , status , number of outbound flows replaced = , number of inbound flows replaced =.

Fields #

NameDescription
PortId UInt32
PortName UnicodeString
PortFriendlyName UnicodeString
LayerId UnicodeString
Status UInt32NTSTATUS reference
NumOutboundFlowsReplaced UInt32
NumInboundFlowsReplaced UInt32

Event ID 965: VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) ran port timer function PortTimerFunction.

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Message #

VfpExt on port %1 (Name = %2, FriendlyName = %3) ran port timer function %4

Fields #

NameDescription
PortId UInt32
PortName UnicodeString
PortFriendlyName UnicodeString
PortTimerFunction UInt8

Event ID 965

#
Channel
Operational

Description

VfpExt on port (Name = , FriendlyName = ) ran port timer function.

Fields #

NameDescription
PortId UInt32
PortName UnicodeString
PortFriendlyName UnicodeString
PortTimerFunction UInt8

Event ID 966: Suspended live migration state change on port PortId (Name = PortName, FriendlyName = PortFriendlyName), new live migration state = SuspendedLmState.

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Message #

Suspended live migration state change on port %1 (Name = %2, FriendlyName = %3), new live migration state = %4

Fields #

NameDescription
PortId UInt32
PortName UnicodeString
PortFriendlyName UnicodeString
SuspendedLmState UInt8

Event ID 966

#
Channel
Operational

Description

Suspended live migration state change on port (Name = , FriendlyName = ), new live migration state =.

Fields #

NameDescription
PortId UInt32
PortName UnicodeString
PortFriendlyName UnicodeString
SuspendedLmState UInt8

Event ID 967: VfpExt set NDIS_NIC_SWITCH_VPORT_PARAMS_ENFORCE_MAX_SG_LIST on port (name = PortName, Friendlyname = PortFriendlyName) during VF VPort Creation.

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Message #

VfpExt set NDIS_NIC_SWITCH_VPORT_PARAMS_ENFORCE_MAX_SG_LIST on port (name = %1, Friendlyname = %2) during VF VPort Creation

Fields #

NameDescription
PortName UnicodeString
PortFriendlyName UnicodeString

Event ID 967

#
Channel
Operational

Description

VfpExt set NDIS_NIC_SWITCH_VPORT_PARAMS_ENFORCE_MAX_SG_LIST on port (name = , Friendlyname = ) during VF VPort Creation.

Fields #

NameDescription
PortName UnicodeString
PortFriendlyName UnicodeString

Event ID 968: VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) with numFlows MaxEntries with StepDownMinItem enabled : StepDownMinItem with timer interval NextTimerUpdateInterval is sched...

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Description

VfpExt on port (Name = , FriendlyName = ) with numFlows with StepDownMinItem enabled : with timer interval is scheduled with status with outstanding work times and heurstic is enabled.

Message #

VfpExt on port %1 (Name = %2, FriendlyName = %3) with numFlows %4 with StepDownMinItem enabled : %5 with timer interval %6 is scheduled with status %7 with %8 outstanding work times and heurstic is enabled: %9

Fields #

NameDescription
PortId UInt32
PortName UnicodeString
PortFriendlyName UnicodeString
MaxEntries UInt32
StepDownMinItem Boolean
NextTimerUpdateInterval Int64
Status UInt32NTSTATUS reference
OutstandingWorkItems UInt32
HeuristicTimerUpdatesEnabled Boolean

Event ID 968

#
Channel
Operational

Description

VfpExt on port (Name = , FriendlyName = ) with numFlows with StepDownMinItem enabled : with timer interval is scheduled with status with outstanding work times and heurstic is enabled.

Fields #

NameDescription
PortId UInt32
PortName UnicodeString
PortFriendlyName UnicodeString
MaxEntries UInt32
StepDownMinItem Boolean
NextTimerUpdateInterval Int64
Status UInt32NTSTATUS reference
OutstandingWorkItems UInt32
HeuristicTimerUpdatesEnabled Boolean

Event ID 969: Skipping Sx Switch context SwitchContext (Name = Name, FriendlyName = FriendlyName) as a match with reason 'FailureReason'.

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Message #

Skipping Sx Switch context %1 (Name = %2, FriendlyName = %3) as a match with reason '%4'

Fields #

NameDescription
SwitchContext UInt64
Name UnicodeString
FriendlyName UnicodeString
FailureReason UInt8
Known values
%%2304
An Error occured during Logon.
%%2305
The specified user account has expired.
%%2306
The NetLogon component is not active.
%%2307
Account locked out.
%%2308
The user has not been granted the requested logon type at this machine.
%%2309
The specified account's password has expired.
%%2310
Account currently disabled.
%%2311
Account logon time restriction violation.
%%2312
User not allowed to logon at this computer.
%%2313
Unknown user name or bad password.
%%2314
Domain sid inconsistent.
%%2315
Smartcard logon is required and was not used.

Event ID 969

#
Channel
Operational

Description

Skipping Sx Switch context SwitchContext (Name = Name, FriendlyName = FriendlyName) as a match with reason 'FailureReason'.

Fields #

NameDescription
SwitchContext UInt64
Name UnicodeString
FriendlyName UnicodeString
FailureReason UInt8
Known values
%%2304
An Error occured during Logon.
%%2305
The specified user account has expired.
%%2306
The NetLogon component is not active.
%%2307
Account locked out.
%%2308
The user has not been granted the requested logon type at this machine.
%%2309
The specified account's password has expired.
%%2310
Account currently disabled.
%%2311
Account logon time restriction violation.
%%2312
User not allowed to logon at this computer.
%%2313
Unknown user name or bad password.
%%2314
Domain sid inconsistent.
%%2315
Smartcard logon is required and was not used.

Event ID 970: Managing VM Context failed for VMId: VmId on port (name = PortName, FriendlyName = PortFriendlyName) with status = Status, internal reason: FailureReason.

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Message #

Managing VM Context failed for VMId: %1 on port (name = %2, FriendlyName = %3) with status = %4, internal reason: %5

Fields #

NameDescription
VmId UnicodeString
PortName UnicodeString
PortFriendlyName UnicodeString
Status UInt32NTSTATUS reference
FailureReason UnicodeString
Known values
%%2304
An Error occured during Logon.
%%2305
The specified user account has expired.
%%2306
The NetLogon component is not active.
%%2307
Account locked out.
%%2308
The user has not been granted the requested logon type at this machine.
%%2309
The specified account's password has expired.
%%2310
Account currently disabled.
%%2311
Account logon time restriction violation.
%%2312
User not allowed to logon at this computer.
%%2313
Unknown user name or bad password.
%%2314
Domain sid inconsistent.
%%2315
Smartcard logon is required and was not used.

Event ID 970

#
Channel
Operational

Description

Managing VM Context failed for VMId: on port (name = , FriendlyName = ) with status = , internal reason.

Fields #

NameDescription
VmId UnicodeString
PortName UnicodeString
PortFriendlyName UnicodeString
Status UInt32NTSTATUS reference
FailureReason UnicodeString
Known values
%%2304
An Error occured during Logon.
%%2305
The specified user account has expired.
%%2306
The NetLogon component is not active.
%%2307
Account locked out.
%%2308
The user has not been granted the requested logon type at this machine.
%%2309
The specified account's password has expired.
%%2310
Account currently disabled.
%%2311
Account logon time restriction violation.
%%2312
User not allowed to logon at this computer.
%%2313
Unknown user name or bad password.
%%2314
Domain sid inconsistent.
%%2315
Smartcard logon is required and was not used.

Event ID 971: VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) refreshing into space SpaceId the following mapping: {mapping type = MappingType, ca = CustomerIpv4Addr, pa = ProviderIpv4Ad...

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Message #

VfpExt on port %1 (Name = %19, FriendlyName = %20) refreshing into space %2 the following mapping: {mapping type = %3, ca = %4, pa = %7, mac addr = %10, customer mac addr = %11, isolation id = %12, flags = {all = %13, permanent = %14, non unique PA = %15, mac mapping = %16, L4-load-balanced mapping = %17, L3-load-balanced mapping = %18}}

Fields #

NameDescription
PortId UInt32
SpaceId UnicodeString
MappingType UInt8
CustomerIpv4Addr UInt32
CustomerIpv6AddrLength UInt32
CustomerIpv6Addr Binary
ProviderIpv4Addr UInt32
ProviderIpv6AddrLength UInt32
ProviderIpv6Addr Binary
MacAddr UnicodeString
CustomerMacAddr UnicodeString
IsolationId UInt32
Flags UInt32
PermanentFlag Boolean
NonUniquePAFlag Boolean
MacMappingFlag Boolean
L4LoadBalanced Boolean
L3LoadBalanced Boolean
PortName UnicodeString
PortFriendlyName UnicodeString

Event ID 971

#
Channel
Operational

Fields #

NameDescription
PortId UInt32
SpaceId UnicodeString
MappingType UInt8
CustomerIpv4Addr UInt32
CustomerIpv6AddrLength UInt32
CustomerIpv6Addr Binary
ProviderIpv4Addr UInt32
ProviderIpv6AddrLength UInt32
ProviderIpv6Addr Binary
MacAddr UnicodeString
CustomerMacAddr UnicodeString
IsolationId UInt32
Flags UInt32
PermanentFlag Boolean
NonUniquePAFlag Boolean
MacMappingFlag Boolean
L4LoadBalanced Boolean
L3LoadBalanced Boolean
PortName UnicodeString
PortFriendlyName UnicodeString

Event ID 972: VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) refreshing into space SpaceId the following mapping: {mapping type = MappingType, ca = CustomerIpv6Addr, pa = ProviderIpv4Ad...

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Message #

VfpExt on port %1 (Name = %19, FriendlyName = %20) refreshing into space %2 the following mapping: {mapping type = %3, ca = %6, pa = %7, mac addr = %10, customer mac addr = %11, isolation id = %12, flags = {all = %13, permanent = %14, non unique PA = %15, mac mapping = %16, L4-load-balanced mapping = %17, L3-load-balanced mapping = %18}}

Fields #

NameDescription
PortId UInt32
SpaceId UnicodeString
MappingType UInt8
CustomerIpv4Addr UInt32
CustomerIpv6AddrLength UInt32
CustomerIpv6Addr Binary
ProviderIpv4Addr UInt32
ProviderIpv6AddrLength UInt32
ProviderIpv6Addr Binary
MacAddr UnicodeString
CustomerMacAddr UnicodeString
IsolationId UInt32
Flags UInt32
PermanentFlag Boolean
NonUniquePAFlag Boolean
MacMappingFlag Boolean
L4LoadBalanced Boolean
L3LoadBalanced Boolean
PortName UnicodeString
PortFriendlyName UnicodeString

Event ID 972

#
Channel
Operational

Fields #

NameDescription
PortId UInt32
SpaceId UnicodeString
MappingType UInt8
CustomerIpv4Addr UInt32
CustomerIpv6AddrLength UInt32
CustomerIpv6Addr Binary
ProviderIpv4Addr UInt32
ProviderIpv6AddrLength UInt32
ProviderIpv6Addr Binary
MacAddr UnicodeString
CustomerMacAddr UnicodeString
IsolationId UInt32
Flags UInt32
PermanentFlag Boolean
NonUniquePAFlag Boolean
MacMappingFlag Boolean
L4LoadBalanced Boolean
L3LoadBalanced Boolean
PortName UnicodeString
PortFriendlyName UnicodeString

Event ID 973: VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) refreshing into space SpaceId the following mapping: {mapping type = MappingType, ca = CustomerIpv4Addr, pa = ProviderIpv6Ad...

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Message #

VfpExt on port %1 (Name = %19, FriendlyName = %20) refreshing into space %2 the following mapping: {mapping type = %3, ca = %4, pa = %9, mac addr = %10, customer mac addr = %11, isolation id = %12, flags = {all = %13, permanent = %14, non unique PA = %15, mac mapping = %16, L4-load-balanced mapping = %17, L3-load-balanced mapping = %18}}

Fields #

NameDescription
PortId UInt32
SpaceId UnicodeString
MappingType UInt8
CustomerIpv4Addr UInt32
CustomerIpv6AddrLength UInt32
CustomerIpv6Addr Binary
ProviderIpv4Addr UInt32
ProviderIpv6AddrLength UInt32
ProviderIpv6Addr Binary
MacAddr UnicodeString
CustomerMacAddr UnicodeString
IsolationId UInt32
Flags UInt32
PermanentFlag Boolean
NonUniquePAFlag Boolean
MacMappingFlag Boolean
L4LoadBalanced Boolean
L3LoadBalanced Boolean
PortName UnicodeString
PortFriendlyName UnicodeString

Event ID 973

#
Channel
Operational

Fields #

NameDescription
PortId UInt32
SpaceId UnicodeString
MappingType UInt8
CustomerIpv4Addr UInt32
CustomerIpv6AddrLength UInt32
CustomerIpv6Addr Binary
ProviderIpv4Addr UInt32
ProviderIpv6AddrLength UInt32
ProviderIpv6Addr Binary
MacAddr UnicodeString
CustomerMacAddr UnicodeString
IsolationId UInt32
Flags UInt32
PermanentFlag Boolean
NonUniquePAFlag Boolean
MacMappingFlag Boolean
L4LoadBalanced Boolean
L3LoadBalanced Boolean
PortName UnicodeString
PortFriendlyName UnicodeString

Event ID 974: VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) refreshing into space SpaceId the following mapping: {mapping type = MappingType, ca = CustomerIpv6Addr, pa = ProviderIpv6Ad...

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Message #

VfpExt on port %1 (Name = %19, FriendlyName = %20) refreshing into space %2 the following mapping: {mapping type = %3, ca = %6, pa = %9, mac addr = %10, customer mac addr = %11, isolation id = %12, flags = {all = %13, permanent = %14, non unique PA = %15, mac mapping = %16, L4-load-balanced mapping = %17, L3-load-balanced mapping = %18}}

Fields #

NameDescription
PortId UInt32
SpaceId UnicodeString
MappingType UInt8
CustomerIpv4Addr UInt32
CustomerIpv6AddrLength UInt32
CustomerIpv6Addr Binary
ProviderIpv4Addr UInt32
ProviderIpv6AddrLength UInt32
ProviderIpv6Addr Binary
MacAddr UnicodeString
CustomerMacAddr UnicodeString
IsolationId UInt32
Flags UInt32
PermanentFlag Boolean
NonUniquePAFlag Boolean
MacMappingFlag Boolean
L4LoadBalanced Boolean
L3LoadBalanced Boolean
PortName UnicodeString
PortFriendlyName UnicodeString

Event ID 974

#
Channel
Operational

Fields #

NameDescription
PortId UInt32
SpaceId UnicodeString
MappingType UInt8
CustomerIpv4Addr UInt32
CustomerIpv6AddrLength UInt32
CustomerIpv6Addr Binary
ProviderIpv4Addr UInt32
ProviderIpv6AddrLength UInt32
ProviderIpv6Addr Binary
MacAddr UnicodeString
CustomerMacAddr UnicodeString
IsolationId UInt32
Flags UInt32
PermanentFlag Boolean
NonUniquePAFlag Boolean
MacMappingFlag Boolean
L4LoadBalanced Boolean
L3LoadBalanced Boolean
PortName UnicodeString
PortFriendlyName UnicodeString

Event ID 975: VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) Negative caching into space SpaceId the following mapping: {mapping type = MappingType, ca = CustomerIpv4Addr, pa = Provider...

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Message #

VfpExt on port %1 (Name = %19, FriendlyName = %20) Negative caching into space %2 the following mapping: {mapping type = %3, ca = %4, pa = %7, mac addr = %10, customer mac addr = %11, isolation id = %12, flags = {all = %13, permanent = %14, non unique PA = %15, mac mapping = %16, L4-load-balanced mapping = %17, L3-load-balanced mapping = %18}}

Fields #

NameDescription
PortId UInt32
SpaceId UnicodeString
MappingType UInt8
CustomerIpv4Addr UInt32
CustomerIpv6AddrLength UInt32
CustomerIpv6Addr Binary
ProviderIpv4Addr UInt32
ProviderIpv6AddrLength UInt32
ProviderIpv6Addr Binary
MacAddr UnicodeString
CustomerMacAddr UnicodeString
IsolationId UInt32
Flags UInt32
PermanentFlag Boolean
NonUniquePAFlag Boolean
MacMappingFlag Boolean
L4LoadBalanced Boolean
L3LoadBalanced Boolean
PortName UnicodeString
PortFriendlyName UnicodeString

Event ID 975

#
Channel
Operational

Fields #

NameDescription
PortId UInt32
SpaceId UnicodeString
MappingType UInt8
CustomerIpv4Addr UInt32
CustomerIpv6AddrLength UInt32
CustomerIpv6Addr Binary
ProviderIpv4Addr UInt32
ProviderIpv6AddrLength UInt32
ProviderIpv6Addr Binary
MacAddr UnicodeString
CustomerMacAddr UnicodeString
IsolationId UInt32
Flags UInt32
PermanentFlag Boolean
NonUniquePAFlag Boolean
MacMappingFlag Boolean
L4LoadBalanced Boolean
L3LoadBalanced Boolean
PortName UnicodeString
PortFriendlyName UnicodeString

Event ID 976: VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) Negative caching into space SpaceId the following mapping: {mapping type = MappingType, ca = CustomerIpv6Addr, pa = Provider...

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Message #

VfpExt on port %1 (Name = %19, FriendlyName = %20) Negative caching into space %2 the following mapping: {mapping type = %3, ca = %6, pa = %7, mac addr = %10, customer mac addr = %11, isolation id = %12, flags = {all = %13, permanent = %14, non unique PA = %15, mac mapping = %16, L4-load-balanced mapping = %17, L3-load-balanced mapping = %18}}

Fields #

NameDescription
PortId UInt32
SpaceId UnicodeString
MappingType UInt8
CustomerIpv4Addr UInt32
CustomerIpv6AddrLength UInt32
CustomerIpv6Addr Binary
ProviderIpv4Addr UInt32
ProviderIpv6AddrLength UInt32
ProviderIpv6Addr Binary
MacAddr UnicodeString
CustomerMacAddr UnicodeString
IsolationId UInt32
Flags UInt32
PermanentFlag Boolean
NonUniquePAFlag Boolean
MacMappingFlag Boolean
L4LoadBalanced Boolean
L3LoadBalanced Boolean
PortName UnicodeString
PortFriendlyName UnicodeString

Event ID 976

#
Channel
Operational

Fields #

NameDescription
PortId UInt32
SpaceId UnicodeString
MappingType UInt8
CustomerIpv4Addr UInt32
CustomerIpv6AddrLength UInt32
CustomerIpv6Addr Binary
ProviderIpv4Addr UInt32
ProviderIpv6AddrLength UInt32
ProviderIpv6Addr Binary
MacAddr UnicodeString
CustomerMacAddr UnicodeString
IsolationId UInt32
Flags UInt32
PermanentFlag Boolean
NonUniquePAFlag Boolean
MacMappingFlag Boolean
L4LoadBalanced Boolean
L3LoadBalanced Boolean
PortName UnicodeString
PortFriendlyName UnicodeString

Event ID 977: VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) Negative caching into space SpaceId the following mapping: {mapping type = MappingType, ca = CustomerIpv4Addr, pa = Provider...

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Message #

VfpExt on port %1 (Name = %19, FriendlyName = %20) Negative caching into space %2 the following mapping: {mapping type = %3, ca = %4, pa = %9, mac addr = %10, customer mac addr = %11, isolation id = %12, flags = {all = %13, permanent = %14, non unique PA = %15, mac mapping = %16, L4-load-balanced mapping = %17, L3-load-balanced mapping = %18}}

Fields #

NameDescription
PortId UInt32
SpaceId UnicodeString
MappingType UInt8
CustomerIpv4Addr UInt32
CustomerIpv6AddrLength UInt32
CustomerIpv6Addr Binary
ProviderIpv4Addr UInt32
ProviderIpv6AddrLength UInt32
ProviderIpv6Addr Binary
MacAddr UnicodeString
CustomerMacAddr UnicodeString
IsolationId UInt32
Flags UInt32
PermanentFlag Boolean
NonUniquePAFlag Boolean
MacMappingFlag Boolean
L4LoadBalanced Boolean
L3LoadBalanced Boolean
PortName UnicodeString
PortFriendlyName UnicodeString

Event ID 977

#
Channel
Operational

Fields #

NameDescription
PortId UInt32
SpaceId UnicodeString
MappingType UInt8
CustomerIpv4Addr UInt32
CustomerIpv6AddrLength UInt32
CustomerIpv6Addr Binary
ProviderIpv4Addr UInt32
ProviderIpv6AddrLength UInt32
ProviderIpv6Addr Binary
MacAddr UnicodeString
CustomerMacAddr UnicodeString
IsolationId UInt32
Flags UInt32
PermanentFlag Boolean
NonUniquePAFlag Boolean
MacMappingFlag Boolean
L4LoadBalanced Boolean
L3LoadBalanced Boolean
PortName UnicodeString
PortFriendlyName UnicodeString

Event ID 978: VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) Negative caching into space SpaceId the following mapping: {mapping type = MappingType, ca = CustomerIpv6Addr, pa = Provider...

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Message #

VfpExt on port %1 (Name = %19, FriendlyName = %20) Negative caching into space %2 the following mapping: {mapping type = %3, ca = %6, pa = %9, mac addr = %10, customer mac addr = %11, isolation id = %12, flags = {all = %13, permanent = %14, non unique PA = %15, mac mapping = %16, L4-load-balanced mapping = %17, L3-load-balanced mapping = %18}}

Fields #

NameDescription
PortId UInt32
SpaceId UnicodeString
MappingType UInt8
CustomerIpv4Addr UInt32
CustomerIpv6AddrLength UInt32
CustomerIpv6Addr Binary
ProviderIpv4Addr UInt32
ProviderIpv6AddrLength UInt32
ProviderIpv6Addr Binary
MacAddr UnicodeString
CustomerMacAddr UnicodeString
IsolationId UInt32
Flags UInt32
PermanentFlag Boolean
NonUniquePAFlag Boolean
MacMappingFlag Boolean
L4LoadBalanced Boolean
L3LoadBalanced Boolean
PortName UnicodeString
PortFriendlyName UnicodeString

Event ID 978

#
Channel
Operational

Fields #

NameDescription
PortId UInt32
SpaceId UnicodeString
MappingType UInt8
CustomerIpv4Addr UInt32
CustomerIpv6AddrLength UInt32
CustomerIpv6Addr Binary
ProviderIpv4Addr UInt32
ProviderIpv6AddrLength UInt32
ProviderIpv6Addr Binary
MacAddr UnicodeString
CustomerMacAddr UnicodeString
IsolationId UInt32
Flags UInt32
PermanentFlag Boolean
NonUniquePAFlag Boolean
MacMappingFlag Boolean
L4LoadBalanced Boolean
L3LoadBalanced Boolean
PortName UnicodeString
PortFriendlyName UnicodeString

Event ID 979: VfpExt on port PortId received mappingdesc for following mapping: {mapping index type = MappingIndexType, address = Ipv4Addr}}.

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Message #

VfpExt on port %1 received mappingdesc for following mapping: {mapping index type = %2, address = %3}}

Fields #

NameDescription
PortId UInt32
MappingIndexType UInt8
Ipv4Addr UInt32
Ipv6AddrLength UInt32
Ipv6Addr Binary

Event ID 979

#
Channel
Operational

Description

VfpExt on port received mappingdesc for following mapping: {mapping index type = , address = }}.

Fields #

NameDescription
PortId UInt32
MappingIndexType UInt8
Ipv4Addr UInt32
Ipv6AddrLength UInt32
Ipv6Addr Binary

Event ID 980: VfpExt on port PortId received mappingdesc for following mapping: {mapping index type = MappingIndexType, address = Ipv6Addr}}.

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Message #

VfpExt on port %1 received mappingdesc for following mapping: {mapping index type = %2, address = %5}}

Fields #

NameDescription
PortId UInt32
MappingIndexType UInt8
Ipv4Addr UInt32
Ipv6AddrLength UInt32
Ipv6Addr Binary

Event ID 980

#
Channel
Operational

Description

VfpExt on port received mappingdesc for following mapping: {mapping index type = , address = }}.

Fields #

NameDescription
PortId UInt32
MappingIndexType UInt8
Ipv4Addr UInt32
Ipv6AddrLength UInt32
Ipv6Addr Binary

Event ID 981: Applying GFT Multi-Tenant Settings status Status - port VPortId (Name = PortName), Enable: Enable, UseVlanMask: UseVlanMask, UseVlanMaxRange: UseMaxVlanRange, UseVlanMinRange: UseMinVlanRange, Vlan...

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Description

Applying GFT Multi-Tenant Settings status Status - port VPortId (Name = PortName), Enable: Enable, UseVlanMask: UseVlanMask, UseVlanMaxRange: UseMaxVlanRange, UseVlanMinRange: UseMinVlanRange, VlanMask: VlanMask, MaxVlanRange: MaxVlanRange, MinVlanRange: MinVlanRange.

Message #

Applying GFT Multi-Tenant Settings status %1 - port %2 (Name = %3), Enable: %4, UseVlanMask: %5, UseVlanMaxRange: %6, UseVlanMinRange: %7, VlanMask: %8, MaxVlanRange: %9, MinVlanRange: %10

Fields #

NameDescription
Status UInt32NTSTATUS reference
VPortId UInt32
PortName UnicodeString
Enable Boolean
UseVlanMask Boolean
UseMaxVlanRange Boolean
UseMinVlanRange Boolean
VlanMask HexInt32
MaxVlanRange UInt32
MinVlanRange UInt32

Event ID 981

#
Channel
Operational

Description

Applying GFT Multi-Tenant Settings status - port (Name = ), Enable: , UseVlanMask: , UseVlanMaxRange: , UseVlanMinRange: , VlanMask: , MaxVlanRange: , MinVlanRange.

Fields #

NameDescription
Status UInt32NTSTATUS reference
VPortId UInt32
PortName UnicodeString
Enable Boolean
UseVlanMask Boolean
UseMaxVlanRange Boolean
UseMinVlanRange Boolean
VlanMask HexInt32
MaxVlanRange UInt32
MinVlanRange UInt32

Event ID 982: Reason, status = Status.

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Message #

%1, status = %2

Fields #

NameDescription
Reason UnicodeString
Status UInt32NTSTATUS reference

Event ID 982

#
Channel
Operational

Description

, status =.

Fields #

NameDescription
Reason UnicodeString
Status UInt32NTSTATUS reference

Event ID 983: GFT direct configuration dispatch table for switch SwitchName returned status Status.

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Description

GFT direct configuration dispatch table for switch returned status . ClientHandle , ProviderHandle , ClientRequestCompletionHandler , ProviderRequestHandler .

Message #

GFT direct configuration dispatch table for switch %1 returned status %2. ClientHandle %3, ProviderHandle %4, ClientRequestCompletionHandler %5, ProviderRequestHandler %6.

Fields #

NameDescription
SwitchName UnicodeString
Status UInt32NTSTATUS reference
GftClientHandle UInt64
GftProviderHandle UInt64
GftClientDirectConfigurationRequestCompleteHandler UInt64
GftProviderDirectConfigurationRequestHandler UInt64

Event ID 983

#
Channel
Operational

Description

GFT direct configuration dispatch table for switch returned status . ClientHandle , ProviderHandle , ClientRequestCompletionHandler , ProviderRequestHandler .

Fields #

NameDescription
SwitchName UnicodeString
Status UInt32NTSTATUS reference
GftClientHandle UInt64
GftProviderHandle UInt64
GftClientDirectConfigurationRequestCompleteHandler UInt64
GftProviderDirectConfigurationRequestHandler UInt64

Event ID 984: VfpExt on port PortId layer LayerName matched a redirect rule, using reconcilation path {Path}.

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Message #

VfpExt on port %1 layer %2 matched a redirect rule, using reconcilation path {%3}

Fields #

NameDescription
PortId UInt32
LayerName UnicodeString
Known values
%%14596
IP Packet
%%14597
Transport
%%14598
Forward
%%14599
Stream
%%14600
Datagram Data
%%14601
ICMP Error
%%14602
MAC 802.3
%%14603
MAC Native
%%14604
vSwitch
%%14608
Resource Assignment
%%14609
Listen
%%14610
Receive/Accept
%%14611
Connect
%%14612
Flow Established
%%14614
Resource Release
%%14615
Endpoint Closure
%%14616
Connect Redirect
%%14617
Bind Redirect
%%14624
Stream Packet
%%14625
Accept Redirect
%%14626
Accept Redirect
%%14640
ICMP Echo-Request
%%14641
vSwitch Ingress
%%14642
vSwitch Egress
%%14643
Unknown
Path UInt8

Event ID 984

#
Channel
Operational

Description

VfpExt on port layer matched a redirect rule, using reconcilation path {}.

Fields #

NameDescription
PortId UInt32
LayerName UnicodeString
Known values
%%14596
IP Packet
%%14597
Transport
%%14598
Forward
%%14599
Stream
%%14600
Datagram Data
%%14601
ICMP Error
%%14602
MAC 802.3
%%14603
MAC Native
%%14604
vSwitch
%%14608
Resource Assignment
%%14609
Listen
%%14610
Receive/Accept
%%14611
Connect
%%14612
Flow Established
%%14614
Resource Release
%%14615
Endpoint Closure
%%14616
Connect Redirect
%%14617
Bind Redirect
%%14624
Stream Packet
%%14625
Accept Redirect
%%14626
Accept Redirect
%%14640
ICMP Echo-Request
%%14641
vSwitch Ingress
%%14642
vSwitch Egress
%%14643
Unknown
Path UInt8

Event ID 990: VfpExt hairpin processing dropped packet because destination port after hairpin processing is same as original source part.

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Message #

VfpExt hairpin processing dropped packet because destination port after hairpin processing is same as original source part. Source port %1 (Name = %2, FriendlyName = %3) Target port %4 (Name = %5, FriendlyName = %6) IsMirror = %7, Packet = %8, Original Packet = %9

Fields #

NameDescription
SrcPortId UInt32
SrcPortName UnicodeString
SrcPortFriendlyName UnicodeString
TargetPortId UInt32
TargetPortName UnicodeString
TargetPortFriendlyName UnicodeString
IsMirror Boolean
Packet Pointer
OriginalPacket Pointer

Event ID 990

#
Channel
Operational

Fields #

NameDescription
SrcPortId UInt32
SrcPortName UnicodeString
SrcPortFriendlyName UnicodeString
TargetPortId UInt32
TargetPortName UnicodeString
TargetPortFriendlyName UnicodeString
IsMirror Boolean
Packet Pointer
OriginalPacket Pointer

Event ID 1000: VFP PktMon Registration failed for switch SwitchName with status Status and statusLocation StatusLocation.

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Message #

VFP PktMon Registration failed for switch %1 with status %2 and statusLocation %3

Fields #

NameDescription
SwitchName UnicodeString
Status UInt32NTSTATUS reference
StatusLocation UInt32

Event ID 1000

#
Channel
Operational

Description

VFP PktMon Registration failed for switch with status and statusLocation.

Fields #

NameDescription
SwitchName UnicodeString
Status UInt32NTSTATUS reference
StatusLocation UInt32

Event ID 1010: VfpExt QoS config with EnableHardwareCaps=EnableHardwareCaps, EnableHardwareReservations=EnableHardwareReservations, EnableSoftwareReservations=EnableSoftwareReservations, Flags=Flags, failed with ...

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Description

VfpExt QoS config with EnableHardwareCaps=EnableHardwareCaps, EnableHardwareReservations=EnableHardwareReservations, EnableSoftwareReservations=EnableSoftwareReservations, Flags=Flags, failed with status:(Status), reason:(FailReason).

Message #

VfpExt QoS config with EnableHardwareCaps=%1, EnableHardwareReservations=%2, EnableSoftwareReservations=%3, Flags=%4, failed with status:(%5), reason:(%6)

Fields #

NameDescription
EnableHardwareCaps Boolean
EnableHardwareReservations Boolean
EnableSoftwareReservations Boolean
Flags UInt8
Status UInt32NTSTATUS reference
FailReason UInt8

Event ID 1010

#
Channel
Operational

Description

VfpExt QoS config with EnableHardwareCaps=, EnableHardwareReservations=, EnableSoftwareReservations=, Flags=, failed with status:(), reason:().

Fields #

NameDescription
EnableHardwareCaps Boolean
EnableHardwareReservations Boolean
EnableSoftwareReservations Boolean
Flags UInt8
Status UInt32NTSTATUS reference
FailReason UInt8

Event ID 1011: VPort OID failed for VportName=PortName, AttachedFunctionId=AttachedFunctionId, status=(Status), reason=(Reason).

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Message #

VPort OID failed for VportName=%1, AttachedFunctionId=%2, status=(%4), reason=(%3)

Fields #

NameDescription
PortName UnicodeString
AttachedFunctionId UInt16
Reason UInt32
Status UInt32NTSTATUS reference

Event ID 1011

#
Channel
Operational

Description

VPort OID failed for VportName=, AttachedFunctionId=, status=(), reason=().

Fields #

NameDescription
PortName UnicodeString
AttachedFunctionId UInt16
Reason UInt32
Status UInt32NTSTATUS reference

Event ID 1012: RuleTyperule with ID RuleId processed Directionpackets on port PortId (Name = PortName, FriendlyName = PortFriendlyName) with status = Status and statusLocation = StatusLocation: flow ID {src ip = ...

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Message #

%6rule with ID %5 processed %2packets on port %1 (Name = %14, FriendlyName = %15) with status = %13 and statusLocation = %17: flow ID {src ip = %7, dst ip = %8, src port = %9, dst port = %10, protocol = %11, isTcpSyn = %12}, rule {layer = %3, group = %4, rule id = %5, gftFlags = %16}

Fields #

NameDescription
PortId UInt32
Direction UInt8
Known values
%%14592
Inbound
%%14593
Outbound
%%14594
Forward
%%14595
Bidirectional
LayerId UnicodeString
GroupId UnicodeString
RuleId UnicodeString
RuleType UInt8
SrcIpv4Addr UInt32
DstIpv4Addr UInt32
SrcPort UInt16
DstPort UInt16
IpProtocol UInt8
IsTcpSyn Boolean
Status UInt32NTSTATUS reference
PortName UnicodeString
PortFriendlyName UnicodeString
GftFlags UInt32
StatusLocation UInt32

Event ID 1012

#
Channel
Operational

Fields #

NameDescription
PortId UInt32
Direction UInt8
Known values
%%14592
Inbound
%%14593
Outbound
%%14594
Forward
%%14595
Bidirectional
LayerId UnicodeString
GroupId UnicodeString
RuleId UnicodeString
RuleType UInt8
SrcIpv4Addr UInt32
DstIpv4Addr UInt32
SrcPort UInt16
DstPort UInt16
IpProtocol UInt8
IsTcpSyn Boolean
Status UInt32NTSTATUS reference
PortName UnicodeString
PortFriendlyName UnicodeString
GftFlags UInt32
StatusLocation UInt32

Event ID 1013: RuleTyperule with ID RuleId processed Directionpackets on port PortId (Name = PortName, FriendlyName = PortFriendlyName) with status = Status and statusLocation = StatusLocation: flow ID {src ip = ...

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Message #

%6rule with ID %5 processed %2packets on port %1 (Name = %14, FriendlyName = %15) with status = %13 and statusLocation = %17: flow ID {src ip = %7, dst ip = %8, src port = %9, dst port = %10, protocol = %11, isTcpSyn = %12}, rule {layer = %3, group = %4, rule id = %5, gftFlags = %16}

Fields #

NameDescription
PortId UInt32
Direction UInt8
Known values
%%14592
Inbound
%%14593
Outbound
%%14594
Forward
%%14595
Bidirectional
LayerId UnicodeString
GroupId UnicodeString
RuleId UnicodeString
RuleType UInt8
SrcIpv6Addr Binary
DstIpv6Addr Binary
SrcPort UInt16
DstPort UInt16
IpProtocol UInt8
IsTcpSyn Boolean
Status UInt32NTSTATUS reference
PortName UnicodeString
PortFriendlyName UnicodeString
GftFlags UInt32
StatusLocation UInt32

Event ID 1013

#
Channel
Operational

Fields #

NameDescription
PortId UInt32
Direction UInt8
Known values
%%14592
Inbound
%%14593
Outbound
%%14594
Forward
%%14595
Bidirectional
LayerId UnicodeString
GroupId UnicodeString
RuleId UnicodeString
RuleType UInt8
SrcIpv6Addr Binary
DstIpv6Addr Binary
SrcPort UInt16
DstPort UInt16
IpProtocol UInt8
IsTcpSyn Boolean
Status UInt32NTSTATUS reference
PortName UnicodeString
PortFriendlyName UnicodeString
GftFlags UInt32
StatusLocation UInt32

Event ID 1014: VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) found no match in layer LayerId for Directionpackets with flow id {src ip = SrcIpv4Addr, dst ip = DstIpv4Addr, src port = Sr...

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Description

VfpExt on port (Name = , FriendlyName = ) found no match in layer for packets with flow id {src ip = , dst ip = , src port = , dst port = , protocol = , isTcpSyn = }, gftFlags =.

Message #

VfpExt on port %1 (Name = %10, FriendlyName = %11) found no match in layer %3 for %2packets with flow id {src ip = %4, dst ip = %5, src port = %6, dst port = %7, protocol = %8, isTcpSyn = %9}, gftFlags = %12

Fields #

NameDescription
PortId UInt32
Direction UInt8
Known values
%%14592
Inbound
%%14593
Outbound
%%14594
Forward
%%14595
Bidirectional
LayerId UnicodeString
SrcIpv4Addr UInt32
DstIpv4Addr UInt32
SrcPort UInt16
DstPort UInt16
IpProtocol UInt8
IsTcpSyn Boolean
PortName UnicodeString
PortFriendlyName UnicodeString
GftFlags UInt32

Event ID 1014

#
Channel
Operational

Description

VfpExt on port (Name = , FriendlyName = ) found no match in layer for packets with flow id {src ip = , dst ip = , src port = , dst port = , protocol = , isTcpSyn = }, gftFlags =.

Fields #

NameDescription
PortId UInt32
Direction UInt8
Known values
%%14592
Inbound
%%14593
Outbound
%%14594
Forward
%%14595
Bidirectional
LayerId UnicodeString
SrcIpv4Addr UInt32
DstIpv4Addr UInt32
SrcPort UInt16
DstPort UInt16
IpProtocol UInt8
IsTcpSyn Boolean
PortName UnicodeString
PortFriendlyName UnicodeString
GftFlags UInt32

Event ID 1015: VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) found no match in layer LayerId for Directionpackets with flow id {src ip = SrcIpv6Addr, dst ip = DstIpv6Addr, src port = Sr...

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Description

VfpExt on port (Name = , FriendlyName = ) found no match in layer for packets with flow id {src ip = , dst ip = , src port = , dst port = , protocol = , isTcpSyn = }, gftFlags =.

Message #

VfpExt on port %1 (Name = %10, FriendlyName = %11) found no match in layer %3 for %2packets with flow id {src ip = %4, dst ip = %5, src port = %6, dst port = %7, protocol = %8, isTcpSyn = %9}, gftFlags = %12

Fields #

NameDescription
PortId UInt32
Direction UInt8
Known values
%%14592
Inbound
%%14593
Outbound
%%14594
Forward
%%14595
Bidirectional
LayerId UnicodeString
SrcIpv6Addr Binary
DstIpv6Addr Binary
SrcPort UInt16
DstPort UInt16
IpProtocol UInt8
IsTcpSyn Boolean
PortName UnicodeString
PortFriendlyName UnicodeString
GftFlags UInt32

Event ID 1015

#
Channel
Operational

Description

VfpExt on port (Name = , FriendlyName = ) found no match in layer for packets with flow id {src ip = , dst ip = , src port = , dst port = , protocol = , isTcpSyn = }, gftFlags =.

Fields #

NameDescription
PortId UInt32
Direction UInt8
Known values
%%14592
Inbound
%%14593
Outbound
%%14594
Forward
%%14595
Bidirectional
LayerId UnicodeString
SrcIpv6Addr Binary
DstIpv6Addr Binary
SrcPort UInt16
DstPort UInt16
IpProtocol UInt8
IsTcpSyn Boolean
PortName UnicodeString
PortFriendlyName UnicodeString
GftFlags UInt32

Event ID 1016: VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) found no match in layer LayerId for Directionpackets with flow id {src ip = SrcIpv4Addr, dst ip = DstIpv4Addr, gre key = Gre...

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Description

VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) found no match in layer LayerId for Directionpackets with flow id {src ip = SrcIpv4Addr, dst ip = DstIpv4Addr, gre key = GreKey}. GftFlags = GftFlags.

Message #

VfpExt on port %1 (Name = %7, FriendlyName = %8) found no match in layer %3 for %2packets with flow id {src ip = %4, dst ip = %5, gre key = %6}. GftFlags = %9

Fields #

NameDescription
PortId UInt32
Direction UInt8
Known values
%%14592
Inbound
%%14593
Outbound
%%14594
Forward
%%14595
Bidirectional
LayerId UnicodeString
SrcIpv4Addr UInt32
DstIpv4Addr UInt32
GreKey UInt32
PortName UnicodeString
PortFriendlyName UnicodeString
GftFlags UInt32

Event ID 1016

#
Channel
Operational

Description

VfpExt on port (Name = , FriendlyName = ) found no match in layer for packets with flow id {src ip = , dst ip = , gre key = }. GftFlags =.

Fields #

NameDescription
PortId UInt32
Direction UInt8
Known values
%%14592
Inbound
%%14593
Outbound
%%14594
Forward
%%14595
Bidirectional
LayerId UnicodeString
SrcIpv4Addr UInt32
DstIpv4Addr UInt32
GreKey UInt32
PortName UnicodeString
PortFriendlyName UnicodeString
GftFlags UInt32

Event ID 1017: VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) found no match in layer LayerId for Directionpackets with flow id {src ip = SrcIpv6Addr, dst ip = DstIpv6Addr, gre key = Gre...

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Description

VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) found no match in layer LayerId for Directionpackets with flow id {src ip = SrcIpv6Addr, dst ip = DstIpv6Addr, gre key = GreKey}. GftFlags = GftFlags.

Message #

VfpExt on port %1 (Name = %7, FriendlyName = %8) found no match in layer %3 for %2packets with flow id {src ip = %4, dst ip = %5, gre key = %6}. GftFlags = %9

Fields #

NameDescription
PortId UInt32
Direction UInt8
Known values
%%14592
Inbound
%%14593
Outbound
%%14594
Forward
%%14595
Bidirectional
LayerId UnicodeString
SrcIpv6Addr Binary
DstIpv6Addr Binary
GreKey UInt32
PortName UnicodeString
PortFriendlyName UnicodeString
GftFlags UInt32

Event ID 1017

#
Channel
Operational

Description

VfpExt on port (Name = , FriendlyName = ) found no match in layer for packets with flow id {src ip = , dst ip = , gre key = }. GftFlags =.

Fields #

NameDescription
PortId UInt32
Direction UInt8
Known values
%%14592
Inbound
%%14593
Outbound
%%14594
Forward
%%14595
Bidirectional
LayerId UnicodeString
SrcIpv6Addr Binary
DstIpv6Addr Binary
GreKey UInt32
PortName UnicodeString
PortFriendlyName UnicodeString
GftFlags UInt32

Event ID 1018: RuleTyperule with ID RuleId processed Directionpackets on port PortId (Name = PortName, FriendlyName = PortFriendlyName) with status = Status and statusLocation = StatusLocation: flow id {src ip = ...

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Description

rule with ID processed packets on port (Name = , FriendlyName = ) with status = and statusLocation = : flow id {src ip = , dst ip = , gre key = }, rule {layer = , group = , rule id = , gftFlags = }.

Message #

%6rule with ID %5 processed %2packets on port %1 (Name = %11, FriendlyName = %12) with status = %10 and statusLocation = %14: flow id {src ip = %7, dst ip = %8, gre key = %9}, rule {layer = %3, group = %4, rule id = %5, gftFlags = %13}

Fields #

NameDescription
PortId UInt32
Direction UInt8
Known values
%%14592
Inbound
%%14593
Outbound
%%14594
Forward
%%14595
Bidirectional
LayerId UnicodeString
GroupId UnicodeString
RuleId UnicodeString
RuleType UInt8
SrcIpv4Addr UInt32
DstIpv4Addr UInt32
GreKey UInt32
Status UInt32NTSTATUS reference
PortName UnicodeString
PortFriendlyName UnicodeString
GftFlags UInt32
StatusLocation UInt32

Event ID 1018

#
Channel
Operational

Description

rule with ID processed packets on port (Name = , FriendlyName = ) with status = and statusLocation = : flow id {src ip = , dst ip = , gre key = }, rule {layer = , group = , rule id = , gftFlags = }.

Fields #

NameDescription
PortId UInt32
Direction UInt8
Known values
%%14592
Inbound
%%14593
Outbound
%%14594
Forward
%%14595
Bidirectional
LayerId UnicodeString
GroupId UnicodeString
RuleId UnicodeString
RuleType UInt8
SrcIpv4Addr UInt32
DstIpv4Addr UInt32
GreKey UInt32
Status UInt32NTSTATUS reference
PortName UnicodeString
PortFriendlyName UnicodeString
GftFlags UInt32
StatusLocation UInt32

Event ID 1019: RuleTyperule with ID RuleId processed Directionpackets on port PortId (Name = PortName, FriendlyName = PortFriendlyName) with status = Status and statusLocation = StatusLocation: flow id {src ip = ...

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Description

rule with ID processed packets on port (Name = , FriendlyName = ) with status = and statusLocation = : flow id {src ip = , dst ip = , gre key = }, rule {layer = , group = , rule id = , gftFlags = }.

Message #

%6rule with ID %5 processed %2packets on port %1 (Name = %11, FriendlyName = %12) with status = %10 and statusLocation = %14: flow id {src ip = %7, dst ip = %8, gre key = %9}, rule {layer = %3, group = %4, rule id = %5, gftFlags = %13}

Fields #

NameDescription
PortId UInt32
Direction UInt8
Known values
%%14592
Inbound
%%14593
Outbound
%%14594
Forward
%%14595
Bidirectional
LayerId UnicodeString
GroupId UnicodeString
RuleId UnicodeString
RuleType UInt8
SrcIpv6Addr Binary
DstIpv6Addr Binary
GreKey UInt32
Status UInt32NTSTATUS reference
PortName UnicodeString
PortFriendlyName UnicodeString
GftFlags UInt32
StatusLocation UInt32

Event ID 1019

#
Channel
Operational

Description

rule with ID processed packets on port (Name = , FriendlyName = ) with status = and statusLocation = : flow id {src ip = , dst ip = , gre key = }, rule {layer = , group = , rule id = , gftFlags = }.

Fields #

NameDescription
PortId UInt32
Direction UInt8
Known values
%%14592
Inbound
%%14593
Outbound
%%14594
Forward
%%14595
Bidirectional
LayerId UnicodeString
GroupId UnicodeString
RuleId UnicodeString
RuleType UInt8
SrcIpv6Addr Binary
DstIpv6Addr Binary
GreKey UInt32
Status UInt32NTSTATUS reference
PortName UnicodeString
PortFriendlyName UnicodeString
GftFlags UInt32
StatusLocation UInt32

Event ID 1020: VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) matched Directionpackets with flow id {src ip = SrcIpv4Addr, dst ip = DstIpv4Addr, src port = SrcPort, dst port = DstPort, p...

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Description

VfpExt on port (Name = , FriendlyName = ) matched packets with flow id {src ip = , dst ip = , src port = , dst port = , protocol = , isTcpSyn = } to flow {layer = , flow type = }. GftFlags = .

Message #

VfpExt on port %1 (Name = %11, FriendlyName = %12) matched %2packets with flow id {src ip = %5, dst ip = %6, src port = %7, dst port = %8, protocol = %9, isTcpSyn = %10} to flow {layer = %3, flow type = %4}. GftFlags = %13.

Fields #

NameDescription
PortId UInt32
Direction UInt8
Known values
%%14592
Inbound
%%14593
Outbound
%%14594
Forward
%%14595
Bidirectional
LayerId UnicodeString
FlowType UInt8
SrcIpv4Addr UInt32
DstIpv4Addr UInt32
SrcPort UInt16
DstPort UInt16
IpProtocol UInt8
IsTcpSyn Boolean
PortName UnicodeString
PortFriendlyName UnicodeString
GftFlags UInt32

Event ID 1020

#
Channel
Operational

Description

VfpExt on port (Name = , FriendlyName = ) matched packets with flow id {src ip = , dst ip = , src port = , dst port = , protocol = , isTcpSyn = } to flow {layer = , flow type = }. GftFlags = .

Fields #

NameDescription
PortId UInt32
Direction UInt8
Known values
%%14592
Inbound
%%14593
Outbound
%%14594
Forward
%%14595
Bidirectional
LayerId UnicodeString
FlowType UInt8
SrcIpv4Addr UInt32
DstIpv4Addr UInt32
SrcPort UInt16
DstPort UInt16
IpProtocol UInt8
IsTcpSyn Boolean
PortName UnicodeString
PortFriendlyName UnicodeString
GftFlags UInt32

Event ID 1021: VfpExt on port PortId (Name = PortName, FriendlyName = PortFriendlyName) matched Directionpackets with flow id {src ip = SrcIpv6Addr, dst ip = DstIpv6Addr, src port = SrcPort, dst port = DstPort, p...

#
Channel
Microsoft-Windows-Hyper-V-VfpExt-Analytic

Description

VfpExt on port (Name = , FriendlyName = ) matched packets with flow id {src ip = , dst ip = , src port = , dst port = , protocol = , isTcpSyn = } to flow {layer = , flow type = }. GftFlags = .

Message #

VfpExt on port %1 (Name = %11, FriendlyName = %12) matched %2packets with flow id {src ip = %5, dst ip = %6, src port = %7, dst port = %8, protocol = %9, isTcpSyn = %10} to flow {layer = %3, flow type = %4}. GftFlags = %13.

Fields #

NameDescription
PortId UInt32
Direction UInt8
Known values
%%14592
Inbound
%%14593
Outbound
%%14594
Forward
%%14595
Bidirectional
LayerId UnicodeString
FlowType UInt8
SrcIpv6Addr Binary
DstIpv6Addr Binary
SrcPort UInt16
DstPort UInt16
IpProtocol UInt8
IsTcpSyn Boolean
PortName UnicodeString
PortFriendlyName UnicodeString
GftFlags UInt32

Event ID 1021

#
Channel
Operational

Description

VfpExt on port (Name = , FriendlyName = ) matched packets with flow id {src ip = , dst ip = , src port = , dst port = , protocol = , isTcpSyn = } to flow {layer = , flow type = }. GftFlags = .

Fields #

NameDescription
PortId UInt32
Direction UInt8
Known values
%%14592
Inbound
%%14593
Outbound
%%14594
Forward
%%14595
Bidirectional
LayerId UnicodeString
FlowType UInt8
SrcIpv6Addr Binary
DstIpv6Addr Binary
SrcPort UInt16
DstPort UInt16
IpProtocol UInt8
IsTcpSyn Boolean
PortName UnicodeString
PortFriendlyName UnicodeString
GftFlags UInt32