Microsoft-Windows-Kernel-Dump

12 events across 1 channel

Event ID 1: AllowCrashDump policy: AllowCrashDump_policy.

#
Provider
Microsoft-Windows-Kernel-Dump
Channel
Operational
Task
CrashDumpPolicy
Opcode
PolicyOperationFailed

Description

AllowCrashDump policy: AllowCrashDump_policy.

Message #

AllowCrashDump policy: %1.

Fields #

NameDescription
OperationType AnsiString
Known values
%%1904
New registry value created
%%1905
Existing registry value modified
%%1906
Registry value deleted
%%14674
Value Added
%%14675
Value Deleted
%%14680
Value Added With Expiration Time
%%14681
Value Deleted With Expiration Time
%%14688
Value Auto Deleted With Expiration Time

Event ID 2: AllowCrashDump policy value changed (AllowCrashDump = PolicyValue).

#
Provider
Microsoft-Windows-Kernel-Dump
Channel
Operational
Task
CrashDumpPolicy
Opcode
PolicyValueChanged

Description

AllowCrashDump policy value changed (AllowCrashDump = PolicyValue). Configure crash dump. NT status: NTStatus.

Message #

AllowCrashDump policy value changed (AllowCrashDump = %1). Configure crash dump. NT status: %2

Fields #

NameDescription
PolicyValue UInt32
NTStatus UInt32NTSTATUS reference

Event ID 3: CrashDump disabled on boot by policy (AllowCrashDump = PolicyValue).

#
Provider
Microsoft-Windows-Kernel-Dump
Channel
Operational
Task
CrashDumpPolicy
Opcode
CrashDumpDisabledOnBoot

Description

CrashDump disabled on boot by policy (AllowCrashDump = PolicyValue).

Message #

CrashDump disabled on boot by policy (AllowCrashDump = %1).

Fields #

NameDescription
PolicyValue UInt32

Event ID 4: Crash dump disable failed.

#
Provider
Microsoft-Windows-Kernel-Dump
Channel
Operational
Task
CrashDumpConfig
Opcode
DumpDisableFailed

Description

Crash dump disable failed. NT status: Crash_dump_disable_failed_NT_status.

Message #

Crash dump disable failed. NT status: %1.

Fields #

NameDescription
NTStatus UInt32NTSTATUS reference

Event ID 5: Crash dump initialization failed.

#
Provider
Microsoft-Windows-Kernel-Dump
Channel
Operational
Level
Warning
Task
CrashDumpConfig
Opcode
DumpInitializationFailed.

Description

Crash dump initialization failed. NT status: NTStatus.

Message #

Crash dump initialization failed. NT status: %1.

Fields #

NameDescription
NTStatus UInt32Crash dump initialization failed. NT status. NTSTATUS reference

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Kernel-Dump",
    "guid": "17D2A329-4539-5F4D-3435-F510634CE3B9",
    "event_source_name": "",
    "event_id": 5,
    "version": 0,
    "level": 3,
    "task": 2,
    "opcode": 15,
    "keywords": 9223372036854775808,
    "time_created": "2023-10-26T04:16:27.309101+00:00",
    "event_record_id": 1,
    "correlation": {},
    "execution": {
      "process_id": 4,
      "thread_id": 8
    },
    "channel": "Microsoft-Windows-Kernel-Dump/Operational",
    "computer": "WIN-OQ6R0RVA4NF",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "NTStatus": 3221225487
  },
  "message": ""
}

References #

Event ID 6: Crash dump load driver failed.

#
Provider
Microsoft-Windows-Kernel-Dump
Channel
Operational
Task
CrashDumpConfig
Opcode
DumpLoadDriverFailed.

Description

Crash dump load driver failed. NT status: Crash_dump_load_driver_failed_NT_status.

Message #

Crash dump load driver failed. NT status: %1.

Fields #

NameDescription
NTStatus UInt32NTSTATUS reference

Event ID 7: Crash dump dump stack initialization failed.

#
Provider
Microsoft-Windows-Kernel-Dump
Channel
Operational
Task
CrashDumpConfig
Opcode
DumpStackInitializationFailed

Description

Crash dump dump stack initialization failed. NT status: NTStatus.

Message #

Crash dump dump stack initialization failed. NT status: %1.

Fields #

NameDescription
NTStatus UInt32NTSTATUS reference

Event ID 8: Crash dump free dump stack failed.

#
Provider
Microsoft-Windows-Kernel-Dump
Channel
Operational
Task
CrashDumpConfig
Opcode
FreeDumpStackFailed

Description

Crash dump free dump stack failed. NT status: NTStatus.

Message #

Crash dump free dump stack failed. NT status: %1.

Fields #

NameDescription
NTStatus UInt32NTSTATUS reference

Event ID 9: Crash dump load dump stack failed.

#
Provider
Microsoft-Windows-Kernel-Dump
Channel
Operational
Task
CrashDumpConfig
Opcode
LoadDumpStackFailed

Description

Crash dump load dump stack failed. NT status: NTStatus.

Message #

Crash dump load dump stack failed. NT status: %1.

Fields #

NameDescription
NTStatus UInt32NTSTATUS reference

Event ID 10: Crash dump disabled.

#
Provider
Microsoft-Windows-Kernel-Dump
Channel
Operational
Level
Informational
Task
CrashDumpConfig
Opcode
DumpDisabled

Description

Crash dump disabled.

Message #

Crash dump disabled.

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Kernel-Dump",
    "guid": "17D2A329-4539-5F4D-3435-F510634CE3B9",
    "event_source_name": "",
    "event_id": 10,
    "version": 0,
    "level": 4,
    "task": 2,
    "opcode": 20,
    "keywords": 9223372036854775808,
    "time_created": "2023-11-06T06:25:25.603988+00:00",
    "event_record_id": 11,
    "correlation": {},
    "execution": {
      "process_id": 396,
      "thread_id": 408
    },
    "channel": "Microsoft-Windows-Kernel-Dump/Operational",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {},
  "message": ""
}

References #

Event ID 11: Crash dump reconfigured.

#
Provider
Microsoft-Windows-Kernel-Dump
Channel
Operational
Task
CrashDumpConfig
Opcode
DumpReconfigured

Description

Crash dump reconfigured. NT status: Crash_dump_reconfigured_NT_status.

Message #

Crash dump reconfigured. NT status: %1.

Fields #

NameDescription
NTStatus UInt32NTSTATUS reference

Event ID 12: Dump disabled forcefully (ForceDumpDisabled: Dump_disabled_forcefully_ForceDumpDisabled).

#
Provider
Microsoft-Windows-Kernel-Dump
Channel
Operational
Task
DumpConfig
Opcode
Dumpdisabledforcefully

Description

Dump disabled forcefully (ForceDumpDisabled: Dump_disabled_forcefully_ForceDumpDisabled).

Message #

Dump disabled forcefully (ForceDumpDisabled: %1).

Fields #

NameDescription
ForceDumpDisabled UInt32

Provenance

Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.

ETW provider GUID 17d2a329-4539-5f4d-3435-f510634ce3b9

Defined in Microsoft-Windows-System-Events.dll, which carries the event manifest.

Observed on:

  • WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.3932, captured 2026-06-02
  • Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.5074, captured 2026-06-02

Downloads