Microsoft-Windows-Kernel-Acpi

EventTitleChannelSampleRule
1A memory range descriptor has been marked as reserved.DiagnosticNN
2Unexpected GPE event was fired on GPE bits that should be disabled.DiagnosticNN
3A temperature change notification (Notify(thermal_zone, 0x80)) for ACPI thermal …DiagnosticNN
4A trip point change notification (Notify(thermal_zone, 0x81)) for ACPI thermal …DiagnosticNN
5The active cooling device FanDeviceInstanceLength has been turned …DiagnosticNN
6The active cooling device FanDeviceInstanceLength has been turned …DiagnosticNN
7ACPI method AmlMethodName evaluation has AmlMethodState.DiagnosticYN
8The active cooling device DeviceInstance has been turned PowerState.DiagnosticNN
9The passive cooling device DeviceInstance throttle has changed to Throttle …DiagnosticNN
10The device Passive_cooling has the following cooling state.DiagnosticNN
11TemperatureChangeDiagnosticNN
12ThermalZoneRundown_V4DiagnosticNN
13FanRundownDiagnosticNN
14FanPowerStateChangeDiagnosticNN
15FanStatusChangeDiagnosticNN
16ActiveCoolingConstraintDiagnosticNN
17ActiveCoolingConstraintRundownDiagnosticNN
18PassiveCoolingConstraintDiagnosticNN
19PassiveCoolingConstraintRundownDiagnosticNN
20ACPI device DeviceBiosName is undergoing DeviceResetType.DiagnosticNN
21ACPI device OverRide - AcpiOverrideType.DiagnosticNN
22Error occured while interpreting AML code: scope Scope, object Object.DiagnosticNN
23ACPI method AmlMethodName has high frequency Frequency.DiagnosticYN
24A button notification for ACPI button ButtonDeviceInstance has been received.DiagnosticNN
25A button IRP for ACPI button ButtonDeviceInstance has been completed.DiagnosticNN
26PccSubspaceRundownDiagnosticNN
27PccEjectSubspaceDiagnosticNN
28PccAcquireSubspaceDiagnosticNN
29PccReleaseSubspaceDiagnosticNN
30PccExecuteCommandDiagnosticNN
31PccCommandCompleteDiagnosticNN
32PccCommandTimeoutDiagnosticNN
33PccPlatformInterruptDiagnosticNN
34The strict S4 enforcement _DSM failed evaluation.DiagnosticNN
35MsStateNotificationDiagnosticNN

Event ID 1: A memory range descriptor has been marked as reserved.

#
Channel
Diagnostic
Task
ResourceTranslation

Fields #

NameDescription
ResourceFlag UInt8
GeneralFlag UInt8
TypeSpecificFlag UInt8
Granularity UInt64
AddressMin UInt64
AddressMax UInt64
AddressTranslation UInt64
AddressLength UInt64

Event ID 2: Unexpected GPE event was fired on GPE bits that should be disabled.

#
Channel
Diagnostic
Task
GpeEventHandling

Fields #

NameDescription
GpeRegister UInt32
UnexpectedEventMap UInt8

Event ID 3: A temperature change notification (Notify(thermal_zone, 0x80)) for ACPI thermal zone ThermalZoneDeviceInstance has been received.

#
Channel
Diagnostic
Task
TemperatureNotification

Message #

A temperature change notification (Notify(thermal_zone, 0x80)) for ACPI thermal zone %2 has been received.             
_TMP = %3K             
_PSV = %4K             
_AC0 = %5K             
_AC1 = %6K             
_AC2 = %7K             
_AC3 = %8K             
_AC4 = %9K             
_AC5 = %10K             
_AC6 = %11K             
_AC7 = %12K             
_AC8 = %13K             
_AC9 = %14K             
_HOT = %15K             
_CRT = %16K

Fields #

NameDescription
ThermalZoneDeviceInstanceLength UInt16
ThermalZoneDeviceInstance UnicodeString
_TMP UInt32
_PSV UInt32
_AC0 UInt32
_AC1 UInt32
_AC2 UInt32
_AC3 UInt32
_AC4 UInt32
_AC5 UInt32
_AC6 UInt32
_AC7 UInt32
_AC8 UInt32
_AC9 UInt32
_HOT UInt32
_CRT UInt32

Event ID 4: A trip point change notification (Notify(thermal_zone, 0x81)) for ACPI thermal zone ThermalZoneDeviceInstance has been received.

#
Channel
Diagnostic
Task
TripPointNotification

Message #

A trip point change notification (Notify(thermal_zone, 0x81)) for ACPI thermal zone %2 has been received.             
_TMP = %3K             
_PSV = %4K             
_AC0 = %5K             
_AC1 = %6K             
_AC2 = %7K             
_AC3 = %8K             
_AC4 = %9K             
_AC5 = %10K             
_AC6 = %11K             
_AC7 = %12K             
_AC8 = %13K             
_AC9 = %14K             
_HOT = %15K             
_CRT = %16K

Fields #

NameDescription
ThermalZoneDeviceInstanceLength UInt16
ThermalZoneDeviceInstance UnicodeString
_TMP UInt32
_PSV UInt32
_AC0 UInt32
_AC1 UInt32
_AC2 UInt32
_AC3 UInt32
_AC4 UInt32
_AC5 UInt32
_AC6 UInt32
_AC7 UInt32
_AC8 UInt32
_AC9 UInt32
_HOT UInt32
_CRT UInt32

Event ID 5: The active cooling device FanDeviceInstanceLength has been turned PowerStateLength.

#
Channel
Diagnostic
Task
ActiveCoolingDevicePower

Message #

The active cooling device %6 has been turned %8.             
Thermal zone device instance: %2             
Active cooling package: _AC%3             
Namespace object: _AL%4

Fields #

NameDescription
ThermalZoneDeviceInstanceLength UInt16
ThermalZoneDeviceInstance UnicodeString
ActiveCoolingLevel UInt32
ActiveCoolingDeviceIndex UInt32
FanDeviceInstanceLength UInt16
FanDeviceInstance UnicodeString
PowerStateLength UInt16
PowerState UnicodeString

Event ID 6: The active cooling device FanDeviceInstanceLength has been turned FanDeviceInstance.

#
Channel
Diagnostic
Task
ActiveCoolingDevicePower

Message #

The active cooling device %6 has been turned %7.             
Thermal zone device instance: %2             
Active cooling package: _AC%3             
Namespace object: _AL%4

Fields #

NameDescription
ThermalZoneDeviceInstanceLength UInt16
ThermalZoneDeviceInstance UnicodeString
ActiveCoolingLevel UInt32
ActiveCoolingDeviceIndex UInt32
FanDeviceInstanceLength UInt16
FanDeviceInstance UnicodeString
PowerState UInt16

Event ID 7: ACPI method AmlMethodName evaluation has AmlMethodState.

#
Channel
Diagnostic
Level
Informational
Task
AmlMethodTrace

Message #

ACPI method %2 evaluation has %3.

Fields #

NameDescription
AmlMethodNameLength UInt16
AmlMethodName UnicodeString
AmlMethodState UInt16
AmlElapsedTime UInt64

Example Event #

{
  "system": {
    "channel": "Microsoft-Windows-Kernel-Acpi/Diagnostic",
    "computer": "10.2.10.21",
    "correlation": {},
    "event_id": 7,
    "event_record_id": 0,
    "event_source_name": "",
    "execution": {
      "process_id": 4,
      "thread_id": 9208
    },
    "guid": "",
    "keywords": 0,
    "level": 4,
    "opcode": 0,
    "provider": "Microsoft-Windows-Kernel-Acpi",
    "security": {
      "user_id": ""
    },
    "task": 0,
    "time_created": "2026-07-22 08:33:47.465Z",
    "version": 0
  },
  "event_data": {
    "AmlElapsedTime": 0,
    "AmlMethodName": "\\_SB.LNKA._STA",
    "AmlMethodNameLength": 14,
    "AmlMethodState": 1
  },
  "message": ""
}

Event ID 8: The active cooling device DeviceInstance has been turned PowerState.

#
Channel
Diagnostic
Task
DeviceActiveCooling

Message #

The active cooling device %2 has been turned %3.

Fields #

NameDescription
DeviceInstanceLength UInt16
DeviceInstance UnicodeString
PowerState UInt16

Event ID 9: The passive cooling device DeviceInstance throttle has changed to Throttle percent.

#
Channel
Diagnostic
Task
DevicePassiveCooling

Message #

The passive cooling device %2 throttle has changed to %3 percent.

Fields #

NameDescription
DeviceInstanceLength UInt16
DeviceInstance UnicodeString
Throttle UInt8

Event ID 10: The device Passive_cooling has the following cooling state.

#
Channel
Diagnostic
Task
DeviceCoolingRundown

Message #

The device %2 has the following cooling state.             
Active cooling: %3             
Passive cooling: %4 percent

Fields #

NameDescription
DeviceInstanceLength UInt16
DeviceInstance UnicodeString
PowerState UInt16
Throttle UInt8

Event ID 11: TemperatureChange

#
Channel
Diagnostic
Task
TemperatureChange

Fields #

NameDescription
ThermalZoneDeviceInstanceLength UInt16
ThermalZoneDeviceInstance UnicodeString
Temperature UInt32

Event ID 12: ThermalZoneRundown_V4

#
Channel
Diagnostic
Task
ThermalZoneRundown

Fields #

NameDescription
ThermalZoneBiosNameLength UInt16
ThermalZoneBiosName UnicodeString
_TMP UInt32
_PSV UInt32
_TC1 UInt32
_TC2 UInt32
_TSP UInt32
_AC0 UInt32
_AC1 UInt32
_AC2 UInt32
_AC3 UInt32
_AC4 UInt32
_AC5 UInt32
_AC6 UInt32
_AC7 UInt32
_AC8 UInt32
_AC9 UInt32
_HOT UInt32
_CRT UInt32
_NTT UInt32
_PSLCount UInt32
_PSLEntries AnsiString
_TZDCount UInt32
_TZDEntries AnsiString
_AL0Count UInt32
_AL0Entries AnsiString
_AL1Count UInt32
_AL1Entries AnsiString
_AL2Count UInt32
_AL2Entries AnsiString
_AL3Count UInt32
_AL3Entries AnsiString
_AL4Count UInt32
_AL4Entries AnsiString
_AL5Count UInt32
_AL5Entries AnsiString
_AL6Count UInt32
_AL6Entries AnsiString
_AL7Count UInt32
_AL7Entries AnsiString
_AL8Count UInt32
_AL8Entries AnsiString
_AL9Count UInt32
_AL9Entries AnsiString
MinimumThrottle UInt32
_CR3 UInt32
_TFP UInt32
OverThrottleThreshold UInt32
DescriptionLength UInt16
Description UnicodeString
_TZP UInt32

Event ID 13: FanRundown

#
Channel
Diagnostic
Task
FanRundown

Fields #

NameDescription
FanBiosNameLength UInt16
FanBiosName UnicodeString
FstSupported Boolean
PowerState UInt16
Control UInt32
Speed UInt32

Event ID 14: FanPowerStateChange

#
Channel
Diagnostic
Task
FanPowerStateChange

Fields #

NameDescription
FanBiosNameLength UInt16
FanBiosName UnicodeString
PowerState UInt16

Event ID 15: FanStatusChange

#
Channel
Diagnostic
Task
FanStatusChange

Fields #

NameDescription
FanBiosNameLength UInt16
FanBiosName UnicodeString
Control UInt32
Speed UInt32

Event ID 16: ActiveCoolingConstraint

#
Channel
Diagnostic
Task
ActiveCoolingConstraint

Fields #

NameDescription
ThermalZoneDeviceInstanceLength UInt16
ThermalZoneDeviceInstance UnicodeString
DeviceInstanceLength UInt16
DeviceInstance UnicodeString
PowerState UInt16

Event ID 17: ActiveCoolingConstraintRundown

#
Channel
Diagnostic
Task
ActiveCoolingConstraintRundown

Fields #

NameDescription
ThermalZoneDeviceInstanceLength UInt16
ThermalZoneDeviceInstance UnicodeString
DeviceInstanceLength UInt16
DeviceInstance UnicodeString
PowerState UInt16

Event ID 18: PassiveCoolingConstraint

#
Channel
Diagnostic
Task
PassiveCoolingConstraint

Fields #

NameDescription
ThermalZoneDeviceInstanceLength UInt16
ThermalZoneDeviceInstance UnicodeString
DeviceInstanceLength UInt16
DeviceInstance UnicodeString
ThrottleLimit UInt8

Event ID 19: PassiveCoolingConstraintRundown

#
Channel
Diagnostic
Task
PassiveCoolingConstraintRundown

Fields #

NameDescription
ThermalZoneDeviceInstanceLength UInt16
ThermalZoneDeviceInstance UnicodeString
DeviceInstanceLength UInt16
DeviceInstance UnicodeString
ThrottleLimit UInt8

Event ID 20: ACPI device DeviceBiosName is undergoing DeviceResetType.

#
Channel
Diagnostic
Task
DeviceReset

Description

ACPI device DeviceBiosName is undergoing DeviceResetType. Status Status.

Message #

ACPI device %2 is undergoing %3. Status %4.

Fields #

NameDescription
DeviceBiosNameLength UInt16
DeviceBiosName UnicodeString
DeviceResetType UInt16
Status UInt32NTSTATUS reference

Event ID 21: ACPI device OverRide - AcpiOverrideType.

#
Channel
Diagnostic
Task
AcpiOverride

Message #

ACPI device OverRide - %1

Fields #

NameDescription
AcpiOverrideType UInt16

Event ID 22: Error occured while interpreting AML code: scope Scope, object Object.

#
Channel
Diagnostic
Task
AMLIError

Description

Error occured while interpreting AML code: scope Scope, object Object. Status Status.

Message #

Error occured while interpreting AML code: scope %1, object %2. Status %3.

Fields #

NameDescription
Scope UnicodeString
Object UnicodeString
Status UInt32NTSTATUS reference

Event ID 23: ACPI method AmlMethodName has high frequency Frequency.

#
Channel
Diagnostic
Level
Warning
Task
FrequentAmlMethod

Message #

ACPI method %2 has high frequency %3.

Fields #

NameDescription
AmlMethodNameLength UInt16
AmlMethodName UnicodeString
Frequency UInt64

Example Event #

{
  "system": {
    "channel": "Microsoft-Windows-Kernel-Acpi/Diagnostic",
    "computer": "10.2.10.21",
    "correlation": {},
    "event_id": 23,
    "event_record_id": 0,
    "event_source_name": "",
    "execution": {
      "process_id": 4,
      "thread_id": 9208
    },
    "guid": "",
    "keywords": 0,
    "level": 4,
    "opcode": 0,
    "provider": "Microsoft-Windows-Kernel-Acpi",
    "security": {
      "user_id": ""
    },
    "task": 0,
    "time_created": "2026-07-22 08:33:47.658Z",
    "version": 0
  },
  "event_data": {
    "AmlMethodName": "\\_SB.PCI0.S28._ADR",
    "AmlMethodNameLength": 18,
    "Frequency": 60
  },
  "message": ""
}

Event ID 24: A button notification for ACPI button ButtonDeviceInstance has been received.

#
Channel
Diagnostic
Task
ButtonNotification

Description

A button notification for ACPI button ButtonDeviceInstance has been received. Capabilities = Capabilities, EventMask = EventMask.

Message #

A button notification for ACPI button %2 has been received. Capabilities = %3, EventMask = %4.

Fields #

NameDescription
ButtonDeviceInstanceLength UInt16
ButtonDeviceInstance UnicodeString
Capabilities HexInt32
EventMask HexInt32

Event ID 25: A button IRP for ACPI button ButtonDeviceInstance has been completed.

#
Channel
Diagnostic
Task
ButtonIrpCompletion

Description

A button IRP for ACPI button ButtonDeviceInstance has been completed. EventMask = EventMask, IRP = Irp.

Message #

A button IRP for ACPI button %2 has been completed. EventMask = %3, IRP = %4.

Fields #

NameDescription
ButtonDeviceInstanceLength UInt16
ButtonDeviceInstance UnicodeString
EventMask HexInt32
Irp UInt64

Event ID 26: PccSubspaceRundown

#
Channel
Diagnostic
Task
PccSubspaceRundown

Fields #

NameDescription
Type34SupportEnabled UInt32
SubspaceId UInt32
Type UInt8
State UInt8
InterruptSupported UInt8
InterruptFlags UInt8
GSIV UInt32
NominalLatency UInt32
AdvertisedNominalLatency UInt32
MaxPeriodicAccessRate UInt32
MinRequestTurnaroundTime UInt32
InitFailure UInt32
EjectFailure UInt32
WDTimeoutCount UInt32
WDTimerAttributes UInt32
SharedRegionPhysicalAddress UInt64
SharedRegionLength UInt32
RegisterCount UInt32
Registers SID

Event ID 27: PccEjectSubspace

#
Channel
Diagnostic
Task
PccEjectSubspace

Fields #

NameDescription
SubspaceId UInt32
Type UInt8
Result UInt32
EjectFailure UInt32
InitFailure UInt32

Event ID 28: PccAcquireSubspace

#
Channel
Diagnostic
Task
PccAcquireSubspace

Fields #

NameDescription
SubspaceId UInt32
PrevState UInt8
NewState UInt8
SyncAcquire UInt32
Result UInt32

Event ID 29: PccReleaseSubspace

#
Channel
Diagnostic
Task
PccReleaseSubspace

Fields #

NameDescription
SubspaceId UInt32
PrevState UInt8
NewState UInt8
Result UInt32

Event ID 30: PccExecuteCommand

#
Channel
Diagnostic
Task
PccExecuteCommand

Fields #

NameDescription
SubspaceId UInt32
Command UInt8
PrevState UInt8
NewState UInt8
DelayTimeInUs UInt64
Result UInt32

Event ID 31: PccCommandComplete

#
Channel
Diagnostic
Task
PccCommandComplete

Fields #

NameDescription
SubspaceId UInt32
Command UInt8
CommandInProgress UInt32
PrevState UInt8
NewState UInt8
Error UInt64
Result UInt32

Event ID 32: PccCommandTimeout

#
Channel
Diagnostic
Task
PccCommandTimeout

Fields #

NameDescription
SubspaceId UInt32
AccumulatedFailureCount UInt32

Event ID 33: PccPlatformInterrupt

#
Channel
Diagnostic
Task
PccPlatformInterrupt

Fields #

NameDescription
GSIV UInt32

Event ID 34: The strict S4 enforcement _DSM failed evaluation.

#
Channel
Diagnostic
Task
S4DsmEvaluationFailed

Description

The strict S4 enforcement _DSM failed evaluation. Status Status.

Message #

The strict S4 enforcement _DSM failed evaluation. Status %1.

Fields #

NameDescription
Status UInt32NTSTATUS reference

Event ID 35: MsStateNotification

#
Channel
Diagnostic
Task
MsStateNotification

Fields #

NameDescription
Promoted UInt32
NextState UInt32

Provenance

ETW provider GUID c514638f-7723-485b-bcfc-96565d735d4a

Defined in Microsoft-Windows-System-Events.dll, which carries the event manifest.

  • WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.3932, captured 2026-06-02 — Manifest XML pack, 1.9 MB
  • Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.5074, captured 2026-06-02 — Manifest XML pack, 2.0 MB