Microsoft-Windows-Kernel-LiveDump
60 events across 2 channels
Event ID 1: Live Dump Capture Dump Data API started.
#Event ID 2: Live Dump Capture Dump Data API ended.
#Description
Live Dump Capture Dump Data API ended. NT Status: NTStatus. BugcheckCode: BugcheckCode. BugcheckParameter1: BugCheckParameter1. BugcheckParameter2: BugCheckParameter2. BugcheckParameter3: BugCheckParameter3. BugcheckParameter4: BugCheckParameter4. AbortIfMemoryPressure: AbortIfMemoryPressure. DumpCaptureDuration: DumpCaptureDuration_msms. SelectiveDump: SelectiveDump. DynamicLowMemoryThreshold: DynamicLowMemoryThresholdBytes bytes. AvailablePhysicalMemory: AvailablePhysicalMemoryInBytes bytes. TotalPhysicalMemory: TotalPhysicalMemoryInBytes bytes. IOSpaceEnabled: IOSpaceEnabled.
Message #
Fields #
| Name | Description |
|---|---|
NTStatus UInt32 | NTSTATUS reference |
BugcheckCode UInt32 | |
BugCheckParameter1 Pointer | |
BugCheckParameter2 Pointer | |
BugCheckParameter3 Pointer | |
BugCheckParameter4 Pointer | |
AbortIfMemoryPressure UInt32 | |
DumpCaptureDuration_ms UInt64 | |
SelectiveDump UInt32 | |
DynamicLowMemoryThresholdBytes UInt64 | |
AvailablePhysicalMemoryInBytes UInt64 | |
TotalPhysicalMemoryInBytes UInt64 | |
IOSpaceEnabled Boolean |
Event ID 4: Writing dump file ended.
#Description
Writing dump file ended. NT Status: Writing_dump_file_ended_NT_Status. Total NTStatus bytes (Header|Primary|Secondary: TotalBytes|HeaderBytes|PrimaryDataBytes bytes). DumpWriteDuration: SecondaryDataBytesms.
Message #
Fields #
| Name | Description |
|---|---|
NTStatus UInt32 | NTSTATUS reference |
TotalBytes UInt64 | |
HeaderBytes UInt64 | |
PrimaryDataBytes UInt64 | |
SecondaryDataBytes UInt64 | |
DumpWriteDuration_ms UInt64 |
Event ID 5: Live Dump request aborted due to memory pressure on system
#Description
Live Dump request aborted due to memory pressure on system.
Message #
Event ID 6: LiveDump Event Generic
#Description
LiveDump Event Generic.
Message #
Fields #
| Name | Description |
|---|---|
LiveDumpEventDescription UnicodeString | |
Parameter1Name UnicodeString | |
Parameter1Value UInt64 | |
Parameter2Name UnicodeString | |
Parameter2Value UInt64 | |
Parameter3Name UnicodeString | |
Parameter3Value UInt64 | |
Parameter4Name UnicodeString | |
Parameter4Value UInt64 | |
Parameter5Name UnicodeString | |
Parameter5Value UInt64 | |
Parameter6Name UnicodeString | |
Parameter6Value UInt64 | |
Parameter7Name UnicodeString | |
Parameter7Value UInt64 | |
Parameter8Name UnicodeString | |
Parameter8Value UInt64 |
Event ID 101: Sizing Workflow: Mirroring started.
#Description
Sizing Workflow: Mirroring started.
Message #
Event ID 102: Sizing Workflow: Mirroring Phase 0 ended.
#Description
Sizing Workflow: Mirroring Phase 0 ended.
Message #
Event ID 103: Sizing Workflow: Mirroring Phase 1 ended.
#Description
Sizing Workflow: Mirroring Phase 1 ended.
Message #
Event ID 104: Sizing Workflow: System Quiesce started.
#Description
Sizing Workflow: System Quiesce started.
Message #
Event ID 105: Sizing Workflow: System Quiesce ended.
#Description
Sizing Workflow: System Quiesce ended.
Message #
Event ID 106: Sizing Workflow: Estimation.
#Description
Sizing Workflow: Estimation. NT: NtEstimatedRequiredPrimaryDataBytes bytes (Minimum Sizing_Workflow_Estimation_NT bytes). Hypervisor: Primary NtEstimatedPrimaryDataBytes bytes. Secondary HvEstimatedPrimaryDataBytes bytes.
Message #
Fields #
| Name | Description |
|---|---|
NtEstimatedRequiredPrimaryDataBytes UInt64 | |
NtEstimatedPrimaryDataBytes UInt64 | |
HvEstimatedPrimaryDataBytes UInt64 | |
HvEstimatedSecondaryDataBytes UInt64 | |
SkEstimatedPrimaryDataBytes UInt64 | |
MemoryEstimationDuration_ms UInt64 | |
SystemQuiescedDuration_ms UInt64 | |
EndMirroringPhasesDuration_ms UInt64 | |
MirrorPhysicalMemoryDuration_ms UInt64 | |
MirrorPhysicalMemorySizeInBytes UInt64 | |
HvlCalculateLiveDumpSizeDuration_ms UInt64 |
Event ID 107: Sizing Workflow: Allocation.
#Description
Sizing Workflow: Allocation. NT: Sizing_Workflow_Allocation_NT bytes. Hypervisor: Primary NtPrimaryDataBytes bytes. Secondary HvPrimaryDataBytes bytes.
Message #
Fields #
| Name | Description |
|---|---|
NtPrimaryDataBytes UInt64 | |
HvPrimaryDataBytes UInt64 | |
HvSecondaryDataBytes UInt64 | |
SkPrimaryDataBytes UInt64 | |
AllocateDumpBuffersDuration_ms UInt64 | |
AllocateExtraBuffersDuration_ms UInt64 | |
HvlPrepareLivedumpDescriptorDuration_ms UInt64 |
Event ID 108: Sizing Workflow: RemovePages Callbacks started.
#Description
Sizing Workflow: RemovePages Callbacks started.
Message #
Event ID 109: Sizing Workflow: RemovePages Callbacks ended.
#Description
Sizing Workflow: RemovePages Callbacks ended.
Message #
Event ID 110: Sizing Workflow: RemovePages Callback CallbackIdentifier started.
#Event ID 111: Sizing Workflow: RemovePages Callback CallbackIdentifier ended.
#Event ID 112: Sizing Workflow: RemovePages Callback CallbackIdentifier failed.
#Description
Sizing Workflow: RemovePages Callback CallbackIdentifier failed. NT Status: NTStatus.
Message #
Fields #
| Name | Description |
|---|---|
CallbackIdentifier AnsiString | |
NTStatus UInt32 | NTSTATUS reference |
Event ID 113: Sizing workflow: Sizing_workflow pages estimated to be allocated and Dump_file_size_limit pages allocated.
#Description
Sizing workflow: EstimatedPageCount pages estimated to be allocated and AllocatedPageCount pages allocated (VM memory partition's IOSpace|VM memory partition|System partition's IOSpace|System partition: VMMemoryPartitionIOSpaceAllocatedPages|VMMemoryPartitionAllocatedPages|SystemPartitionIOSpaceAllocatedPages|SystemPartitionAllocatedPages pages). Limit dump file size: LimitDumpFileSize. Dump file size limit: DumpFileSizeLimitInBytes bytes. Dump file size limit reached: DumpFileSizeLimitReached. Aborted while buffer allocation: AbortWhileBufferAllocation.
Message #
Fields #
| Name | Description |
|---|---|
EstimatedPageCount UInt64 | |
AllocatedPageCount UInt64 | |
VMMemoryPartitionIOSpaceAllocatedPages UInt64 | |
VMMemoryPartitionAllocatedPages UInt64 | |
SystemPartitionIOSpaceAllocatedPages UInt64 | |
SystemPartitionAllocatedPages UInt64 | |
LimitDumpFileSize UInt32 | |
DumpFileSizeLimitInBytes UInt64 | |
DumpFileSizeLimitReached UInt32 | |
AbortWhileBufferAllocation UInt32 |
Event ID 114: Sizing Workflow: Query Hvl for dump size failed.
#Description
Sizing Workflow: Query Hvl for dump size failed. NT Status: NTStatus.
Message #
Fields #
| Name | Description |
|---|---|
NTStatus UInt32 | NTSTATUS reference |
Event ID 115: Sizing Workflow: Open VM memory partition failed.
#Description
Sizing Workflow: Open VM memory partition failed. NT Status: NTStatus.
Message #
Fields #
| Name | Description |
|---|---|
NTStatus UInt32 | NTSTATUS reference |
Event ID 116: Sizing Workflow: Buffer allocation from the VM memory partition failed.
#Description
Sizing Workflow: Buffer allocation from the VM memory partition failed. NT Status: NTStatus.
Message #
Fields #
| Name | Description |
|---|---|
NTStatus UInt32 | NTSTATUS reference |
Event ID 117: Sizing Workflow: Capture processor context when the system is quiesced.
#Event ID 118: Sizing Workflow: Mark required dump data when system is quiesced.
#Event ID 119: Sizing Workflow: Mark important dump data when system is quiesced.
#Event ID 120: Sizing Workflow: Populate bitmap for dump when system is quiesced.
#Description
Sizing Workflow: Populate bitmap for dump when system is quiesced. PopulateBitmapForDumpDuration: PopulateBitmapForDumpDuration_msms. RemoveSystemCacheFromDumpDuration RemoveSystemCacheFromDumpDuration_msms.
Message #
Fields #
| Name | Description |
|---|---|
PopulateBitmapForDumpDuration_ms UInt64 | |
RemoveSystemCacheFromDumpDuration_ms UInt64 |
Event ID 121: Sizing Workflow: Corral processors to quiesce the system.
#Description
Sizing Workflow: Corral processors to quiesce the system. CorralDuration: CorralDuration_msms. DisableInterruptsDuration: DisableInterruptsDuration_msms. SaveSupervisorStateDuration: SaveSupervisorStateDuration_msms. SuspendClockTimerDuration: SuspendClockTimerDuration_msms.
Message #
Fields #
| Name | Description |
|---|---|
CorralDuration_ms UInt64 | |
DisableInterruptsDuration_ms UInt64 | |
SaveSupervisorStateDuration_ms UInt64 | |
SuspendClockTimerDuration_ms UInt64 |
Event ID 122: Sizing Workflow: Uncorral processors to quiesce the system.
#Description
Sizing Workflow: Uncorral processors to quiesce the system. UncorralDuration: UncorralDuration_msms. EnableInterruptsDuration: EnableInterruptsDuration_msms. RestoreSupervisorStateDuration: RestoreSupervisorStateDuration_msms. ResumeClockTimerDuration: ResumeClockTimerDuration_msms.
Message #
Fields #
| Name | Description |
|---|---|
UncorralDuration_ms UInt64 | |
EnableInterruptsDuration_ms UInt64 | |
RestoreSupervisorStateDuration_ms UInt64 | |
ResumeClockTimerDuration_ms UInt64 |
Event ID 123: Sizing Workflow: MmDuplicateMemory failed.
#Description
Sizing Workflow: MmDuplicateMemory failed. NT Status: NTStatus. MirrorInProgress: MirrorInProgress.
Message #
Fields #
| Name | Description |
|---|---|
NTStatus UInt32 | NTSTATUS reference |
MirrorInProgress UInt64 |
Event ID 124: IO space utilization disabled when HV/SK pages requested, NoSecrets mode disabled, and SK running.
#Description
IO space utilization disabled when HV/SK pages requested, NoSecrets mode disabled, and SK running.
Message #
Event ID 125: Callout for Callout (included Included).
#Event ID 126: Sizing Workflow: Call to Hvl for preparing livedump descriptor failed.
#Description
Sizing Workflow: Call to Hvl for preparing livedump descriptor failed. NT Status: NTStatus.
Message #
Fields #
| Name | Description |
|---|---|
NTStatus UInt32 | NTSTATUS reference |
Event ID 151: Capture Pages Workflow: Mirroring started.
#Description
Capture Pages Workflow: Mirroring started.
Message #
Event ID 152: Capture Pages Workflow: Mirroring Phase 0 ended.
#Description
Capture Pages Workflow: Mirroring Phase 0 ended.
Message #
Event ID 153: Capture Pages Workflow: Mirroring Phase 1 ended.
#Description
Capture Pages Workflow: Mirroring Phase 1 ended.
Message #
Event ID 154: Capture Pages Workflow: System Quiesce started.
#Description
Capture Pages Workflow: System Quiesce started.
Message #
Event ID 155: Capture Pages Workflow: System Quiesce ended.
#Description
Capture Pages Workflow: System Quiesce ended.
Message #
Event ID 156: Capture Pages Workflow: Copy memory pages started.
#Description
Capture Pages Workflow: Copy memory pages started.
Message #
Event ID 157: Capture Pages Workflow: Copy memory pages ended.
#Description
Capture Pages Workflow: Copy memory pages ended.
Message #
Event ID 158: Capture Pages Workflow: Capture processor context when the system is quiesced.
#Event ID 159: Capture Pages Workflow: Mark required dump data when system is quiesced.
#Event ID 160: Capture Pages Workflow: Mark important dump data when system is quiesced.
#Event ID 161: Capture Pages Workflow: Populate bitmap for dump when system is quiesced.
#Description
Capture Pages Workflow: Populate bitmap for dump when system is quiesced. PopulateBitmapForDumpDuration: PopulateBitmapForDumpDuration_msms. RemoveSystemCacheFromDumpDuration RemoveSystemCacheFromDumpDuration_msms.
Message #
Fields #
| Name | Description |
|---|---|
PopulateBitmapForDumpDuration_ms UInt64 | |
RemoveSystemCacheFromDumpDuration_ms UInt64 |
Event ID 162: Capture Pages Workflow: Collect Hvl dump when system is quiesced.
#Event ID 163: Capture Pages Workflow: Generate Ipt secondary data when system is quiesced.
#Event ID 164: Capture Pages Workflow: Initiate state change to copy contents of marked pages when system is quiesced.
#Event ID 165: Capture Pages Workflow: Corral processors to quiesce the system.
#Description
Capture Pages Workflow: Corral processors to quiesce the system. CorralDuration: CorralDuration_msms. DisableInterruptsDuration: DisableInterruptsDuration_msms. SaveSupervisorStateDuration: SaveSupervisorStateDuration_msms. SuspendClockTimerDuration: SuspendClockTimerDuration_msms.
Message #
Fields #
| Name | Description |
|---|---|
CorralDuration_ms UInt64 | |
DisableInterruptsDuration_ms UInt64 | |
SaveSupervisorStateDuration_ms UInt64 | |
SuspendClockTimerDuration_ms UInt64 |
Event ID 166: Capture Pages Workflow: Uncorral processors to quiesce the system.
#Description
Capture Pages Workflow: Uncorral processors to quiesce the system. UncorralDuration: UncorralDuration_msms. EnableInterruptsDuration: EnableInterruptsDuration_msms. RestoreSupervisorStateDuration: RestoreSupervisorStateDuration_msms. ResumeClockTimerDuration: ResumeClockTimerDuration_msms.
Message #
Fields #
| Name | Description |
|---|---|
UncorralDuration_ms UInt64 | |
EnableInterruptsDuration_ms UInt64 | |
RestoreSupervisorStateDuration_ms UInt64 | |
ResumeClockTimerDuration_ms UInt64 |
Event ID 167: Capture Pages Workflow: Capture memory pages.
#Description
Capture Pages Workflow: Capture memory pages. MemoryCaptureDuration: MemoryCaptureDuration_msms. SystemQuiescedDuration: SystemQuiescedDuration_msms. EndMirroringPhasesDuration: EndMirroringPhasesDuration_msms. MirrorPhysicalMemoryDuration: MirrorPhysicalMemoryDuration_msms. MirrorPhysicalMemorySizeInBytes: MirrorPhysicalMemorySizeInBytes bytes. HvlCollectLivedumpDuration: HvlCollectLivedumpDuration_msms. DumpDataBufferingDuration: DumpDataBufferingDuration_msms.
Message #
Fields #
| Name | Description |
|---|---|
MemoryCaptureDuration_ms UInt64 | |
SystemQuiescedDuration_ms UInt64 | |
EndMirroringPhasesDuration_ms UInt64 | |
MirrorPhysicalMemoryDuration_ms UInt64 | |
MirrorPhysicalMemorySizeInBytes UInt64 | |
HvlCollectLivedumpDuration_ms UInt64 | |
DumpDataBufferingDuration_ms UInt64 |
Event ID 168: Capture Pages Workflow: MmDuplicateMemory failed.
#Description
Capture Pages Workflow: MmDuplicateMemory failed. NT Status: NTStatus. MirrorInProgress: MirrorInProgress.
Message #
Fields #
| Name | Description |
|---|---|
NTStatus UInt32 | NTSTATUS reference |
MirrorInProgress UInt64 |
Event ID 169: Callout for Callout (included Included).
#Event ID 201: Live Dump Write Deferred Dump Data API started.
#Description
Live Dump Write Deferred Dump Data API started.
Message #
Event ID 202: Live Dump Write Deferred Dump Data API ended.
#Description
Live Dump Write Deferred Dump Data API ended. NT Status: NTStatus. BugcheckCode: BugcheckCode. BugcheckParameter1: BugCheckParameter1. BugcheckParameter2: BugCheckParameter2. BugcheckParameter3: BugCheckParameter3. BugcheckParameter4: BugCheckParameter4. DumpWriteDuration: DumpCaptureDuration_msms. SelectiveDump: SelectiveDump. DynamicLowMemoryThreshold: DynamicLowMemoryThresholdBytes bytes. AvailablePhysicalMemory: AvailablePhysicalMemoryInBytes bytes. TotalPhysicalMemory: TotalPhysicalMemoryInBytes bytes. IOSpaceEnabled: IOSpaceEnabled.
Message #
Fields #
| Name | Description |
|---|---|
NTStatus UInt32 | NTSTATUS reference |
BugcheckCode UInt32 | |
BugCheckParameter1 Pointer | |
BugCheckParameter2 Pointer | |
BugCheckParameter3 Pointer | |
BugCheckParameter4 Pointer | |
AbortIfMemoryPressure UInt32 | |
DumpCaptureDuration_ms UInt64 | |
SelectiveDump UInt32 | |
DynamicLowMemoryThresholdBytes UInt64 | |
AvailablePhysicalMemoryInBytes UInt64 | |
TotalPhysicalMemoryInBytes UInt64 | |
IOSpaceEnabled Boolean |
Event ID 203: Write deferred dump data to file started.
#Description
Write deferred dump data to file started.
Message #
Event ID 204: Write deferred dump data to file ended.
#Description
Write deferred dump data to file ended. NT Status: NTStatus. Total TotalBytes bytes (Header|Primary|Secondary: HeaderBytes|PrimaryDataBytes|SecondaryDataBytes bytes). DumpWriteDuration: DumpWriteDuration_msms.
Message #
Fields #
| Name | Description |
|---|---|
NTStatus UInt32 | NTSTATUS reference |
TotalBytes UInt64 | |
HeaderBytes UInt64 | |
PrimaryDataBytes UInt64 | |
SecondaryDataBytes UInt64 | |
DumpWriteDuration_ms UInt64 |
Event ID 251: Live Dump Discard Deferred Dump Data API started.
#Description
Live Dump Discard Deferred Dump Data API started.
Message #
Event ID 252: Live Dump Discard Deferred Dump Data API ended.
#Description
Live Dump Discard Deferred Dump Data API ended. NT Status: NTStatus. BugcheckCode: BugcheckCode. BugcheckParameter1: BugCheckParameter1. BugcheckParameter2: BugCheckParameter2. BugcheckParameter3: BugCheckParameter3. BugcheckParameter4: BugCheckParameter4.
Message #
Fields #
| Name | Description |
|---|---|
NTStatus UInt32 | NTSTATUS reference |
BugcheckCode UInt32 | |
BugCheckParameter1 Pointer | |
BugCheckParameter2 Pointer | |
BugCheckParameter3 Pointer | |
BugCheckParameter4 Pointer | |
AbortIfMemoryPressure UInt32 | |
DumpCaptureDuration_ms UInt64 | |
SelectiveDump UInt32 | |
DynamicLowMemoryThresholdBytes UInt64 | |
AvailablePhysicalMemoryInBytes UInt64 | |
TotalPhysicalMemoryInBytes UInt64 | |
IOSpaceEnabled Boolean |
Event ID 271: AllowLiveDump policy: AllowLiveDump_policy.
#Description
AllowLiveDump policy: AllowLiveDump_policy.
Message #
Fields #
| Name | Description |
|---|---|
OperationType AnsiString | Known values
|
Event ID 272: AllowLiveDump policy value changed (AllowLiveDump = PolicyValue).
#Description
AllowLiveDump policy value changed (AllowLiveDump = PolicyValue). Configure live dump. NT status: NTStatus.
Message #
Fields #
| Name | Description |
|---|---|
PolicyValue UInt32 | |
NTStatus UInt32 | NTSTATUS reference |
Event ID 273: LiveDump disabled on boot by policy (AllowLiveDump = PolicyValue).
#Provenance
Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.
ETW provider GUID bef2aa8e-81cd-11e2-a7bb-5eac6188709b
Defined in Microsoft-Windows-System-Events.dll, which carries the event manifest.
Observed on:
- WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.3932, captured 2026-06-02
- Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.5074, captured 2026-06-02