Microsoft-Windows-Hyper-V-VSmb
45 events across 3 channels
Event ID 1: [VMID VmId]
#Fields #
| Name | Description |
|---|---|
TraceData UnicodeString | |
VmName UnicodeString | |
VmId UnicodeString | |
StackFrameCount UInt32 | |
StackFrame Pointer | |
ModuleCount UInt32 | |
Module Int32 |
Event ID 1: [VMID VmId] TraceData.
#Event ID 2: [VMID VmId]
#Fields #
| Name | Description |
|---|---|
TraceData UnicodeString | |
VmName UnicodeString | |
VmId UnicodeString | |
StackFrameCount UInt32 | |
StackFrame Pointer | |
ModuleCount UInt32 | |
Module Int32 |
Event ID 2: [VMID VmId] TraceData.
#Event ID 3: [VMID VmId]
#Fields #
| Name | Description |
|---|---|
TraceData UnicodeString | |
VmName UnicodeString | |
VmId UnicodeString | |
StackFrameCount UInt32 | |
StackFrame Pointer | |
ModuleCount UInt32 | |
Module Int32 |
Event ID 3: [VMID VmId] TraceData.
#Event ID 4: [VMID VmId]
#Fields #
| Name | Description |
|---|---|
TraceData UnicodeString | |
VmName UnicodeString | |
VmId UnicodeString | |
StackFrameCount UInt32 | |
StackFrame Pointer | |
ModuleCount UInt32 | |
Module Int32 |
Event ID 4: [VMID VmId] TraceData.
#Event ID 101: SMB2 Response Negotiate
#Description
SMB2 Response Negotiate.
Message #
Fields #
| Name | Description |
|---|---|
SessionId UInt64 | |
ProcessId UInt32 | |
TreeId UInt32 | |
MessageId UInt64 | |
MasterMessageId UInt64 | |
Command UInt16 | |
CreditsGranted UInt16 | |
Flags UInt32 | |
Status UInt32 | NTSTATUS reference |
ResponseTime_QPC UInt64 |
Event ID 102: SMB2 Response Session Setup
#Description
SMB2 Response Session Setup.
Message #
Fields #
| Name | Description |
|---|---|
SessionId UInt64 | |
ProcessId UInt32 | |
TreeId UInt32 | |
MessageId UInt64 | |
MasterMessageId UInt64 | |
Command UInt16 | |
CreditsGranted UInt16 | |
Flags UInt32 | |
Status UInt32 | NTSTATUS reference |
ResponseTime_QPC UInt64 |
Event ID 103: SMB2 Response Logoff
#Description
SMB2 Response Logoff.
Message #
Fields #
| Name | Description |
|---|---|
SessionId UInt64 | |
ProcessId UInt32 | |
TreeId UInt32 | |
MessageId UInt64 | |
MasterMessageId UInt64 | |
Command UInt16 | |
CreditsGranted UInt16 | |
Flags UInt32 | |
Status UInt32 | NTSTATUS reference |
ResponseTime_QPC UInt64 |
Event ID 104: SMB2 Response Tree Connect
#Description
SMB2 Response Tree Connect.
Message #
Fields #
| Name | Description |
|---|---|
SessionId UInt64 | |
ProcessId UInt32 | |
TreeId UInt32 | |
MessageId UInt64 | |
MasterMessageId UInt64 | |
Command UInt16 | |
CreditsGranted UInt16 | |
Flags UInt32 | |
Status UInt32 | NTSTATUS reference |
ResponseTime_QPC UInt64 | |
ShareType UInt8 | |
ShareFlags UInt32 | |
Capabilities UInt32 | |
MaximalAccess UInt32 |
Event ID 105: SMB2 Response Tree Disconnect
#Description
SMB2 Response Tree Disconnect.
Message #
Fields #
| Name | Description |
|---|---|
SessionId UInt64 | |
ProcessId UInt32 | |
TreeId UInt32 | |
MessageId UInt64 | |
MasterMessageId UInt64 | |
Command UInt16 | |
CreditsGranted UInt16 | |
Flags UInt32 | |
Status UInt32 | NTSTATUS reference |
ResponseTime_QPC UInt64 |
Event ID 106: SMB2 Response Echo
#Description
SMB2 Response Echo.
Message #
Fields #
| Name | Description |
|---|---|
SessionId UInt64 | |
ProcessId UInt32 | |
TreeId UInt32 | |
MessageId UInt64 | |
MasterMessageId UInt64 | |
Command UInt16 | |
CreditsGranted UInt16 | |
Flags UInt32 | |
Status UInt32 | NTSTATUS reference |
ResponseTime_QPC UInt64 |
Event ID 108: SMB2 Response Create
#Description
SMB2 Response Create.
Message #
Fields #
| Name | Description |
|---|---|
SessionId UInt64 | |
ProcessId UInt32 | |
TreeId UInt32 | |
MessageId UInt64 | |
MasterMessageId UInt64 | |
Command UInt16 | |
CreditsGranted UInt16 | |
Flags UInt32 | |
Status UInt32 | NTSTATUS reference |
ResponseTime_QPC UInt64 | |
AllocationSize UInt64 | |
FileNameLength UInt16 | |
FileName UnicodeString |
Event ID 109: SMB2 Response Close
#Description
SMB2 Response Close.
Message #
Fields #
| Name | Description |
|---|---|
SessionId UInt64 | |
ProcessId UInt32 | |
TreeId UInt32 | |
MessageId UInt64 | |
MasterMessageId UInt64 | |
Command UInt16 | |
CreditsGranted UInt16 | |
Flags UInt32 | |
Status UInt32 | NTSTATUS reference |
ResponseTime_QPC UInt64 | |
AllocationSize UInt64 | |
FileNameLength UInt16 | |
FileName UnicodeString |
Event ID 110: SMB2 Response Flush
#Description
SMB2 Response Flush.
Message #
Fields #
| Name | Description |
|---|---|
SessionId UInt64 | |
ProcessId UInt32 | |
TreeId UInt32 | |
MessageId UInt64 | |
MasterMessageId UInt64 | |
Command UInt16 | |
CreditsGranted UInt16 | |
Flags UInt32 | |
Status UInt32 | NTSTATUS reference |
ResponseTime_QPC UInt64 | |
AllocationSize UInt64 | |
FileNameLength UInt16 | |
FileName UnicodeString |
Event ID 111: SMB2 Response Read
#Description
SMB2 Response Read.
Message #
Fields #
| Name | Description |
|---|---|
SessionId UInt64 | |
ProcessId UInt32 | |
TreeId UInt32 | |
MessageId UInt64 | |
MasterMessageId UInt64 | |
Command UInt16 | |
CreditsGranted UInt16 | |
Flags UInt32 | |
Status UInt32 | NTSTATUS reference |
ResponseTime_QPC UInt64 | |
LengthRead UInt32 |
Event ID 112: SMB2 Response Write
#Description
SMB2 Response Write.
Message #
Fields #
| Name | Description |
|---|---|
SessionId UInt64 | |
ProcessId UInt32 | |
TreeId UInt32 | |
MessageId UInt64 | |
MasterMessageId UInt64 | |
Command UInt16 | |
CreditsGranted UInt16 | |
Flags UInt32 | |
Status UInt32 | NTSTATUS reference |
ResponseTime_QPC UInt64 | |
LengthWritten UInt32 | |
Remaining UInt32 | |
WriteChannelInfoOffset UInt16 | |
WriteChannelInfoLength UInt16 |
Event ID 113: SMB2 Response Break Oplock
#Description
SMB2 Response Break Oplock.
Message #
Fields #
| Name | Description |
|---|---|
SessionId UInt64 | |
ProcessId UInt32 | |
TreeId UInt32 | |
MessageId UInt64 | |
MasterMessageId UInt64 | |
Command UInt16 | |
CreditsGranted UInt16 | |
Flags UInt32 | |
Status UInt32 | NTSTATUS reference |
ResponseTime_QPC UInt64 | |
OplockLevel UInt8 | |
FileId UInt64 |
Event ID 115: SMB2 Response Acknowledge Break Lease
#Description
SMB2 Response Acknowledge Break Lease.
Message #
Fields #
| Name | Description |
|---|---|
SessionId UInt64 | |
ProcessId UInt32 | |
TreeId UInt32 | |
MessageId UInt64 | |
MasterMessageId UInt64 | |
Command UInt16 | |
CreditsGranted UInt16 | |
Flags UInt32 | |
Status UInt32 | NTSTATUS reference |
ResponseTime_QPC UInt64 | |
LeaseFlags UInt32 | |
LeaseState UInt32 | |
LeaseDuration Int64 | |
LeaseKey GUID |
Event ID 116: SMB2 Response Lock
#Description
SMB2 Response Lock.
Message #
Fields #
| Name | Description |
|---|---|
SessionId UInt64 | |
ProcessId UInt32 | |
TreeId UInt32 | |
MessageId UInt64 | |
MasterMessageId UInt64 | |
Command UInt16 | |
CreditsGranted UInt16 | |
Flags UInt32 | |
Status UInt32 | NTSTATUS reference |
ResponseTime_QPC UInt64 |
Event ID 117: SMB2 Response Ioctl
#Description
SMB2 Response Ioctl.
Message #
Fields #
| Name | Description |
|---|---|
SessionId UInt64 | |
ProcessId UInt32 | |
TreeId UInt32 | |
MessageId UInt64 | |
MasterMessageId UInt64 | |
Command UInt16 | |
CreditsGranted UInt16 | |
Flags UInt32 | |
Status UInt32 | NTSTATUS reference |
ResponseTime_QPC UInt64 | |
ControlCode UInt32 | |
IoctlFlags UInt32 | |
FileId UInt64 |
Event ID 118: SMB2 Response Query Directory
#Description
SMB2 Response Query Directory.
Message #
Fields #
| Name | Description |
|---|---|
SessionId UInt64 | |
ProcessId UInt32 | |
TreeId UInt32 | |
MessageId UInt64 | |
MasterMessageId UInt64 | |
Command UInt16 | |
CreditsGranted UInt16 | |
Flags UInt32 | |
Status UInt32 | NTSTATUS reference |
ResponseTime_QPC UInt64 | |
Infoclass UInt64 |
Event ID 119: SMB2 Response Change Notify
#Description
SMB2 Response Change Notify.
Message #
Fields #
| Name | Description |
|---|---|
SessionId UInt64 | |
ProcessId UInt32 | |
TreeId UInt32 | |
MessageId UInt64 | |
MasterMessageId UInt64 | |
Command UInt16 | |
CreditsGranted UInt16 | |
Flags UInt32 | |
Status UInt32 | NTSTATUS reference |
ResponseTime_QPC UInt64 |
Event ID 120: SMB2 Response Query Info
#Description
SMB2 Response Query Info.
Message #
Fields #
| Name | Description |
|---|---|
SessionId UInt64 | |
ProcessId UInt32 | |
TreeId UInt32 | |
MessageId UInt64 | |
MasterMessageId UInt64 | |
Command UInt16 | |
CreditsGranted UInt16 | |
Flags UInt32 | |
Status UInt32 | NTSTATUS reference |
ResponseTime_QPC UInt64 | |
InfoType UInt32 | |
InfoClass UInt32 | |
AllocationSize UInt64 | |
FileNameLength UInt16 | |
FileName UnicodeString |
Event ID 121: SMB2 Response Set Info
#Description
SMB2 Response Set Info.
Message #
Fields #
| Name | Description |
|---|---|
SessionId UInt64 | |
ProcessId UInt32 | |
TreeId UInt32 | |
MessageId UInt64 | |
MasterMessageId UInt64 | |
Command UInt16 | |
CreditsGranted UInt16 | |
Flags UInt32 | |
Status UInt32 | NTSTATUS reference |
ResponseTime_QPC UInt64 | |
InfoType UInt32 | |
InfoClass UInt32 | |
AllocationSize UInt64 | |
FileNameLength UInt16 | |
FileName UnicodeString |
Event ID 122: SMB2 Response Error
#Description
SMB2 Response Error.
Message #
Fields #
| Name | Description |
|---|---|
SessionId UInt64 | |
ProcessId UInt32 | |
TreeId UInt32 | |
MessageId UInt64 | |
MasterMessageId UInt64 | |
Command UInt16 | |
CreditsGranted UInt16 | |
Flags UInt32 | |
Status UInt32 | NTSTATUS reference |
ResponseTime_QPC UInt64 |
Event ID 201: VSMBNET Read segment length
#Event ID 202: VSMBNET Read segment
#Event ID 203: VSMBNET write segment
#Event ID 204: VMId: VSMB Direct Map Section Created GPA Index GpaPageIndex PageCount
#Description
: VSMB Direct Map Section Created GPA Index PageCount.
Fields #
| Name | Description |
|---|---|
VMId UnicodeString | |
GpaPageIndex UInt64 | |
PageCount UInt64 |
Event ID 204: VMId: VSMB Direct Map Section Created GPA Index GpaPageIndex PageCount PageCount.
#Event ID 205: VMId: VSMB Direct Map Section destroyed GPA Index
#Description
: VSMB Direct Map Section destroyed GPA Index.
Fields #
| Name | Description |
|---|---|
VMId UnicodeString | |
GpaPageIndex UInt64 | |
PageCount UInt64 |
Event ID 205: VMId: VSMB Direct Map Section destroyed GPA Index GpaPageIndex.
#Event ID 206: VMId: VSMB Dataless CIMFs Direct Map Request failed in share VMName for file SharePath due to size mismatch
#Description
: VSMB Dataless CIMFs Direct Map Request failed in share for file due to size mismatch. Expected: . Actual . The CIM file may need to be recreated.
Fields #
| Name | Description |
|---|---|
VMId UnicodeString | |
VMName UnicodeString | |
SharePath UnicodeString | |
FileRelativePath UnicodeString | |
ExpectedSize UInt64 | |
ActualSize UInt64 |
Event ID 206: VMId: VSMB Dataless CIMFs Direct Map Request failed in share VMName for file SharePath due to size mismatch.
#Description
VMId: VSMB Dataless CIMFs Direct Map Request failed in share VMName for file SharePath due to size mismatch. Expected: FileRelativePath. Actual ExpectedSize. The CIM file may need to be recreated.
Message #
Fields #
| Name | Description |
|---|---|
VMId UnicodeString | |
VMName UnicodeString | |
SharePath UnicodeString | |
FileRelativePath UnicodeString | |
ExpectedSize UInt64 | |
ActualSize UInt64 |
Event ID 301: 'VMName': VSMB Share is creating ShareName: 'ShareName' SharePath: 'SharePath' ShareFlags:
#Description
'VMName': VSMB Share is creating ShareName: 'ShareName' SharePath: 'SharePath' ShareFlags: ShareFlags. (Virtual machine ID VMId).
Fields #
| Name | Description |
|---|---|
VMId UnicodeString | |
VMName UnicodeString | |
ShareName UnicodeString | |
SharePath UnicodeString | |
ShareFlags UInt64 | |
ShareJson UnicodeString |
Event ID 301: 'VMName': VSMB Share is creating ShareName: 'ShareName' SharePath: 'SharePath' ShareFlags: ShareFlags.
#Description
'VMName': VSMB Share is creating ShareName: 'ShareName' SharePath: 'SharePath' ShareFlags: ShareFlags. (Virtual machine ID VMId).
Message #
Fields #
| Name | Description |
|---|---|
VMId UnicodeString | |
VMName UnicodeString | |
ShareName UnicodeString | |
SharePath UnicodeString | |
ShareFlags UInt64 | |
ShareJson UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Hyper-V-VSmb",
"guid": "7B0EA079-E3BC-424A-B2F0-E3D8478D204B",
"event_source_name": "",
"event_id": 301,
"version": 1,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 2305843009213693968,
"time_created": "2026-03-13T20:08:13.013130+00:00",
"event_record_id": 1,
"correlation": {
"ActivityID": "A5B814C5-B324-0005-441D-B8A524B3DC01"
},
"execution": {
"process_id": 9752,
"thread_id": 8468
},
"channel": "Microsoft-Windows-Hyper-V-Worker-Operational",
"computer": "LAB-WIN11.ludus.domain",
"security": {
"user_id": "S-1-5-83-1-754131803-1256623942-3691508397-1420384594"
}
},
"event_data": {
"VMId": "2CF3235B-8F46-4AE6-ADF2-07DC5259A954",
"VMName": "2cf3235b-8f46-4ae6-adf2-07dc5259a954",
"ShareName": "os",
"SharePath": "C:\\ProgramData\\Microsoft\\Windows\\Containers\\BaseImages\\a132399d-901b-4af5-af28-9bf0fed54acd\\BaseLayer\\Files",
"ShareFlags": 16867473,
"ShareJson": "{\"Name\":\"os\",\"Path\":\"C:\\\\ProgramData\\\\Microsoft\\\\Windows\\\\Containers\\\\BaseImages\\\\a132399d-901b-4af5-af28-9bf0fed54acd\\\\BaseLayer\\\\Files\",\"Options\":{\"ReadOnly\":true,\"TakeBackupPrivilege\":true,\"NoLocks\":true,\"ReparseBaseLayer\":true,\"PseudoOplocks\":true,\"PseudoDirnotify\":true,\"SupportCloudFiles\":true}}"
},
"message": ""
}
Provenance
Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.
ETW provider GUID 7b0ea079-e3bc-424a-b2f0-e3d8478d204b
Defined in vmsmb.dll, which carries the event manifest.
Observed on:
- Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.1, captured 2026-06-02