Microsoft-Windows-Kernel-Acpi
Event ID 1: A memory range descriptor has been marked as reserved.
#Fields #
| Name | Description |
|---|---|
ResourceFlag UInt8 | |
GeneralFlag UInt8 | |
TypeSpecificFlag UInt8 | |
Granularity UInt64 | |
AddressMin UInt64 | |
AddressMax UInt64 | |
AddressTranslation UInt64 | |
AddressLength UInt64 |
Event ID 2: Unexpected GPE event was fired on GPE bits that should be disabled.
#Fields #
| Name | Description |
|---|---|
GpeRegister UInt32 | |
UnexpectedEventMap UInt8 |
Event ID 3: A temperature change notification (Notify(thermal_zone, 0x80)) for ACPI thermal zone ThermalZoneDeviceInstance has been received.
#Event ID 4: A trip point change notification (Notify(thermal_zone, 0x81)) for ACPI thermal zone ThermalZoneDeviceInstance has been received.
#Event ID 5: The active cooling device FanDeviceInstanceLength has been turned PowerStateLength.
#Event ID 6: The active cooling device FanDeviceInstanceLength has been turned FanDeviceInstance.
#Event ID 7: ACPI method AmlMethodName evaluation has AmlMethodState.
#Message #
Fields #
| Name | Description |
|---|---|
AmlMethodNameLength UInt16 | |
AmlMethodName UnicodeString | |
AmlMethodState UInt16 | |
AmlElapsedTime UInt64 |
Example Event #
{
"system": {
"channel": "Microsoft-Windows-Kernel-Acpi/Diagnostic",
"computer": "10.2.10.21",
"correlation": {},
"event_id": 7,
"event_record_id": 0,
"event_source_name": "",
"execution": {
"process_id": 4,
"thread_id": 9208
},
"guid": "",
"keywords": 0,
"level": 4,
"opcode": 0,
"provider": "Microsoft-Windows-Kernel-Acpi",
"security": {
"user_id": ""
},
"task": 0,
"time_created": "2026-07-22 08:33:47.465Z",
"version": 0
},
"event_data": {
"AmlElapsedTime": 0,
"AmlMethodName": "\\_SB.LNKA._STA",
"AmlMethodNameLength": 14,
"AmlMethodState": 1
},
"message": ""
}
Event ID 8: The active cooling device DeviceInstance has been turned PowerState.
#Event ID 9: The passive cooling device DeviceInstance throttle has changed to Throttle percent.
#Event ID 10: The device Passive_cooling has the following cooling state.
#Event ID 11: TemperatureChange
#Fields #
| Name | Description |
|---|---|
ThermalZoneDeviceInstanceLength UInt16 | |
ThermalZoneDeviceInstance UnicodeString | |
Temperature UInt32 |
Event ID 12: ThermalZoneRundown_V4
#Fields #
| Name | Description |
|---|---|
ThermalZoneBiosNameLength UInt16 | |
ThermalZoneBiosName UnicodeString | |
_TMP UInt32 | |
_PSV UInt32 | |
_TC1 UInt32 | |
_TC2 UInt32 | |
_TSP UInt32 | |
_AC0 UInt32 | |
_AC1 UInt32 | |
_AC2 UInt32 | |
_AC3 UInt32 | |
_AC4 UInt32 | |
_AC5 UInt32 | |
_AC6 UInt32 | |
_AC7 UInt32 | |
_AC8 UInt32 | |
_AC9 UInt32 | |
_HOT UInt32 | |
_CRT UInt32 | |
_NTT UInt32 | |
_PSLCount UInt32 | |
_PSLEntries AnsiString | |
_TZDCount UInt32 | |
_TZDEntries AnsiString | |
_AL0Count UInt32 | |
_AL0Entries AnsiString | |
_AL1Count UInt32 | |
_AL1Entries AnsiString | |
_AL2Count UInt32 | |
_AL2Entries AnsiString | |
_AL3Count UInt32 | |
_AL3Entries AnsiString | |
_AL4Count UInt32 | |
_AL4Entries AnsiString | |
_AL5Count UInt32 | |
_AL5Entries AnsiString | |
_AL6Count UInt32 | |
_AL6Entries AnsiString | |
_AL7Count UInt32 | |
_AL7Entries AnsiString | |
_AL8Count UInt32 | |
_AL8Entries AnsiString | |
_AL9Count UInt32 | |
_AL9Entries AnsiString | |
MinimumThrottle UInt32 | |
_CR3 UInt32 | |
_TFP UInt32 | |
OverThrottleThreshold UInt32 | |
DescriptionLength UInt16 | |
Description UnicodeString | |
_TZP UInt32 |
Event ID 13: FanRundown
#Fields #
| Name | Description |
|---|---|
FanBiosNameLength UInt16 | |
FanBiosName UnicodeString | |
FstSupported Boolean | |
PowerState UInt16 | |
Control UInt32 | |
Speed UInt32 |
Event ID 14: FanPowerStateChange
#Fields #
| Name | Description |
|---|---|
FanBiosNameLength UInt16 | |
FanBiosName UnicodeString | |
PowerState UInt16 |
Event ID 15: FanStatusChange
#Fields #
| Name | Description |
|---|---|
FanBiosNameLength UInt16 | |
FanBiosName UnicodeString | |
Control UInt32 | |
Speed UInt32 |
Event ID 16: ActiveCoolingConstraint
#Fields #
| Name | Description |
|---|---|
ThermalZoneDeviceInstanceLength UInt16 | |
ThermalZoneDeviceInstance UnicodeString | |
DeviceInstanceLength UInt16 | |
DeviceInstance UnicodeString | |
PowerState UInt16 |
Event ID 17: ActiveCoolingConstraintRundown
#Fields #
| Name | Description |
|---|---|
ThermalZoneDeviceInstanceLength UInt16 | |
ThermalZoneDeviceInstance UnicodeString | |
DeviceInstanceLength UInt16 | |
DeviceInstance UnicodeString | |
PowerState UInt16 |
Event ID 18: PassiveCoolingConstraint
#Fields #
| Name | Description |
|---|---|
ThermalZoneDeviceInstanceLength UInt16 | |
ThermalZoneDeviceInstance UnicodeString | |
DeviceInstanceLength UInt16 | |
DeviceInstance UnicodeString | |
ThrottleLimit UInt8 |
Event ID 19: PassiveCoolingConstraintRundown
#Fields #
| Name | Description |
|---|---|
ThermalZoneDeviceInstanceLength UInt16 | |
ThermalZoneDeviceInstance UnicodeString | |
DeviceInstanceLength UInt16 | |
DeviceInstance UnicodeString | |
ThrottleLimit UInt8 |
Event ID 20: ACPI device DeviceBiosName is undergoing DeviceResetType.
#Description
ACPI device DeviceBiosName is undergoing DeviceResetType. Status Status.
Message #
Fields #
| Name | Description |
|---|---|
DeviceBiosNameLength UInt16 | |
DeviceBiosName UnicodeString | |
DeviceResetType UInt16 | |
Status UInt32 | NTSTATUS reference |
Event ID 21: ACPI device OverRide - AcpiOverrideType.
#Event ID 22: Error occured while interpreting AML code: scope Scope, object Object.
#Description
Error occured while interpreting AML code: scope Scope, object Object. Status Status.
Message #
Fields #
| Name | Description |
|---|---|
Scope UnicodeString | |
Object UnicodeString | |
Status UInt32 | NTSTATUS reference |
Event ID 23: ACPI method AmlMethodName has high frequency Frequency.
#Message #
Fields #
| Name | Description |
|---|---|
AmlMethodNameLength UInt16 | |
AmlMethodName UnicodeString | |
Frequency UInt64 |
Example Event #
{
"system": {
"channel": "Microsoft-Windows-Kernel-Acpi/Diagnostic",
"computer": "10.2.10.21",
"correlation": {},
"event_id": 23,
"event_record_id": 0,
"event_source_name": "",
"execution": {
"process_id": 4,
"thread_id": 9208
},
"guid": "",
"keywords": 0,
"level": 4,
"opcode": 0,
"provider": "Microsoft-Windows-Kernel-Acpi",
"security": {
"user_id": ""
},
"task": 0,
"time_created": "2026-07-22 08:33:47.658Z",
"version": 0
},
"event_data": {
"AmlMethodName": "\\_SB.PCI0.S28._ADR",
"AmlMethodNameLength": 18,
"Frequency": 60
},
"message": ""
}
Event ID 24: A button notification for ACPI button ButtonDeviceInstance has been received.
#Event ID 25: A button IRP for ACPI button ButtonDeviceInstance has been completed.
#Event ID 26: PccSubspaceRundown
#Fields #
| Name | Description |
|---|---|
Type34SupportEnabled UInt32 | |
SubspaceId UInt32 | |
Type UInt8 | |
State UInt8 | |
InterruptSupported UInt8 | |
InterruptFlags UInt8 | |
GSIV UInt32 | |
NominalLatency UInt32 | |
AdvertisedNominalLatency UInt32 | |
MaxPeriodicAccessRate UInt32 | |
MinRequestTurnaroundTime UInt32 | |
InitFailure UInt32 | |
EjectFailure UInt32 | |
WDTimeoutCount UInt32 | |
WDTimerAttributes UInt32 | |
SharedRegionPhysicalAddress UInt64 | |
SharedRegionLength UInt32 | |
RegisterCount UInt32 | |
Registers SID |
Event ID 27: PccEjectSubspace
#Fields #
| Name | Description |
|---|---|
SubspaceId UInt32 | |
Type UInt8 | |
Result UInt32 | |
EjectFailure UInt32 | |
InitFailure UInt32 |
Event ID 28: PccAcquireSubspace
#Fields #
| Name | Description |
|---|---|
SubspaceId UInt32 | |
PrevState UInt8 | |
NewState UInt8 | |
SyncAcquire UInt32 | |
Result UInt32 |
Event ID 29: PccReleaseSubspace
#Fields #
| Name | Description |
|---|---|
SubspaceId UInt32 | |
PrevState UInt8 | |
NewState UInt8 | |
Result UInt32 |
Event ID 30: PccExecuteCommand
#Fields #
| Name | Description |
|---|---|
SubspaceId UInt32 | |
Command UInt8 | |
PrevState UInt8 | |
NewState UInt8 | |
DelayTimeInUs UInt64 | |
Result UInt32 |
Event ID 31: PccCommandComplete
#Fields #
| Name | Description |
|---|---|
SubspaceId UInt32 | |
Command UInt8 | |
CommandInProgress UInt32 | |
PrevState UInt8 | |
NewState UInt8 | |
Error UInt64 | |
Result UInt32 |
Event ID 32: PccCommandTimeout
#Fields #
| Name | Description |
|---|---|
SubspaceId UInt32 | |
AccumulatedFailureCount UInt32 |
Event ID 34: The strict S4 enforcement _DSM failed evaluation.
#Description
The strict S4 enforcement _DSM failed evaluation. Status Status.
Message #
Fields #
| Name | Description |
|---|---|
Status UInt32 | NTSTATUS reference |
Provenance
ETW provider GUID c514638f-7723-485b-bcfc-96565d735d4a
Defined in Microsoft-Windows-System-Events.dll, which carries the event manifest.
- WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.3932, captured 2026-06-02 — Manifest XML pack, 1.9 MB
- Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.5074, captured 2026-06-02 — Manifest XML pack, 2.0 MB