Microsoft-Windows-Kernel-PnP

EventTitleChannelSampleRule
200Begin boot start drivers phaseBoot DiagnosticNN
201End boot start drivers phaseBoot DiagnosticNN
202Begin system start drivers phaseBoot DiagnosticNN
203End system start drivers phaseBoot DiagnosticNN
204OS Loader Start: OS_Loader_Start.Boot DiagnosticNN
205EarlyLaunchAntiMalwareStartOperationalNN
206EarlyLaunchAntiMalwareStopOperationalNN
207EarlyLaunchAntiMalwareStart207OperationalNN
208EarlyLaunchAntiMalwareStop208OperationalNN
209EarlyLaunchAntiMalwareOperationalNN
210Begin initializing boot start driver DriverName.Driver DiagnosticNN
211End initializing boot start driver DriverName.Driver DiagnosticNN
212Begin loading driver DriverName.Driver DiagnosticNN
213End loading driver DriverName.Driver DiagnosticNN
214Begin unloading driver DriverName.Driver DiagnosticNN
215End unloading driver DriverName.Driver DiagnosticNN
216Begin starting device DriverName.Device Enumeration DiagnosticYN
217Pending start of device DriverName.Device Enumeration DiagnosticYN
218End starting device DriverName using driver FailureName.Device Enumeration DiagnosticYN
219The driver FailureName failed to load.SystemYN
220Begin querying bus relations for device DriverName.Device Enumeration DiagnosticYN
221Pending querying bus relations for device DriverName.Device Enumeration DiagnosticYN
222End querying bus relations for device DriverName.Device Enumeration DiagnosticYN
223Begin attempting to eject device DriverName.Device Enumeration DiagnosticNN
224End attempting to eject device DriverName.Device Enumeration DiagnosticNN
225The application ProcessName with process id ProcessId stopped the removal or …SystemNN
226Begin calling driver initialization routine for driver DriverName.Driver DiagnosticNN
227End calling driver initialization routine for driver DriverName.Driver DiagnosticNN
228task_0OperationalNN
229task_0229OperationalNN
230task_0230OperationalNN
231task_0StopOperationalNN
232task_0232OperationalNN
233task_0233OperationalNN
234task_0234OperationalNN
235task_0235OperationalNN
236task_0236OperationalNN
240A partition unit replace operation has been initiated.SystemNN
241A partition unit replace operation has failed.SystemNN
242A partition unit has been successfully replaced.SystemNN
250Begin configuration of device DeviceInstance.Configuration DiagnosticYN
251Pending configuration of device DeviceInstance.Configuration DiagnosticNN
252End configuration of device DeviceInstance.Configuration DiagnosticYN
260Begin starting system start drivers part 1Boot DiagnosticNN
261End starting system start drivers part 1Boot DiagnosticNN
262Begin starting system start drivers part 2Boot DiagnosticNN
263End starting system start drivers part 2Boot DiagnosticNN
264Begin processing reinitialization requests for boot start driversDriver DiagnosticNN
265End processing reinitialization requests for boot start driversDriver DiagnosticNN
266Begin processing reinitialization requests for system start driversDriver DiagnosticNN
267End processing reinitialization requests for system start driversDriver DiagnosticNN
270Begin loading driver database DriverName.Configuration DiagnosticYN
271Pending loading driver database DriverName.Configuration DiagnosticNN
272End loading driver database DriverName.Configuration DiagnosticYN
273Begin unloading driver database DriverName.Configuration DiagnosticYN
274Pending unloading driver database DriverName.Configuration DiagnosticYN
275End unloading driver database DriverName.Configuration DiagnosticYN
276DriverDatabaseLoadedStartOperationalYN
277DriverDatabaseLoadedStopOperationalYN
278task_0278OperationalNN
300Begin starting initialization of driversBoot DiagnosticNN
301End starting initialization of driversBoot DiagnosticNN
400Device DeviceInstanceId was configured.ConfigurationYN
401Device Driver_Name failed configuration.ConfigurationNN
402Device Driver_Name had its configuration blocked by policy.ConfigurationNN
403Device DeviceInstanceId requires a system reboot to complete configuration.ConfigurationYN
410Device DeviceInstanceId was started.ConfigurationYN
411Device DeviceInstanceId had a problem starting.ConfigurationYN
412Device Driver_Name requires a system reboot before it can be started.ConfigurationNN
420Device DeviceInstanceId was deleted.ConfigurationYN
421Device Class_Guid could not be deleted.ConfigurationNN
430Device DeviceInstanceId requires further installation.ConfigurationYN
440Device settings for Last_Device_Instance_Id were migrated from previous OS …ConfigurationNN
441Device settings for Last_Device_Instance_Id could not be migrated from previous …ConfigurationNN
442Device settings for Last_Device_Instance_Id were not migrated from previous OS …ConfigurationNN
500DevQuery_QueryProcessingOperationalYN
501DevQuery_QueryProcessingProcessingStartOperationalYN
502DevQuery_QueryProcessingProcessingStopOperationalYN
503DevQuery_QueryProcessingOperationalYN
600A start type override of StartType was set for driver Driver in hardware …Driver DiagnosticNN
700CfgMgr_DeviceListOperationalYN
701CfgMgr_DeviceListOperationalYN
702CfgMgr_DeviceInterfaceListOperationalYN
703CfgMgr_DeviceInterfaceListOperationalYN
704CfgMgr_QueryRemoveStartOperationalYN
705CfgMgr_QueryRemoveStopOperationalYN
800Begin processing new device (DeviceNode).Device Enumeration DiagnosticYN
801Processing device DeviceInstancePath (DeviceNode).Device Enumeration DiagnosticYN
802End processing new device (DeviceNode).Device Enumeration DiagnosticYN
803Begin processing phase Phase of starting device Device.OperationalYN
804End processing phase Phase of starting device Device.OperationalYN
805Begin processing phase Phase of restarting device Device.OperationalNN
806End processing phase Phase of restarting device Device.OperationalNN
807Begin device add operation for driver DriverName, device DeviceInstancePath.Device Enumeration DiagnosticYN
808End device add, status (Status).Device Enumeration DiagnosticYN
809Duplicate device instance reported by BusId and DeviceId.Device ManagementNN
810Reenumeration of device tree below Device has been queued.Device Enumeration DiagnosticYN
811Begin reenumeration of device tree below Device.Device Enumeration DiagnosticYN
812End reenumeration of device tree below Device.Device Enumeration DiagnosticYN
813Reenumeration of Device has been queued.Device Enumeration DiagnosticYN
814Begin reenumeration of Device.Device Enumeration DiagnosticYN
815End reenumeration of Device.Device Enumeration DiagnosticYN
816Configuration of device Device for configuration type RequestType has been …Configuration DiagnosticNN
817Begin configuration of device Device for configuration type RequestType.Configuration DiagnosticNN
818End configuration of device Device for configuration type RequestType.Configuration DiagnosticNN
819GenericDeviceActionOperationalYN
820GenericDeviceActionStartOperationalYN
821GenericDeviceActionStopOperationalYN
830Removal of Device has been queued.Device Enumeration DiagnosticYN
831Begin removal of Device.Device Enumeration DiagnosticYN
832End removal of Device.Device Enumeration DiagnosticYN
840Begin resetting device DeviceInstance.Device Enumeration DiagnosticNN
841End resetting device DeviceInstance with status Status, veto type VetoType, veto …Device Enumeration DiagnosticNN
850Begin assigning resources to device tree below Device.Device Enumeration DiagnosticYN
851End assigning resources to device tree below Device.Device Enumeration DiagnosticYN
852Begin rebalancing resources for device DeviceInstance.Device Enumeration DiagnosticNN
853End rebalancing resources for device DeviceInstance.Device Enumeration DiagnosticNN
860Updated problem code on device DeviceInstanceId.OperationalNN
900A long running thread for the device event queue was detected.Driver WatchdogYN
901A long running thread for the device event queue has been completed.Driver WatchdogYN
902A long running thread for device start processing was detected.Driver WatchdogYN
903A long running thread for device start processing has been completed.Driver WatchdogYN
904A long running thread for device removal was detected.Driver WatchdogNN
905A long running thread for device removal has been completed.Driver WatchdogNN
906A long running thread for device add routine was detected.Driver WatchdogNN
907A long running thread for device add routine has been completed.Driver WatchdogNN
908A long running thread for driver entry was detected.Driver WatchdogYN
909A long running thread for driver entry routine has been completed.Driver WatchdogYN
930Timed out waiting for response from user mode clients to synchronous …Driver WatchdogNN
931Responses from user mode clients to synchronous notification EventGuid took …Driver WatchdogNN
932Synchronous notification EventGuid to process ProcessId (ProcessImageName) was …Driver WatchdogNN
933Notification EventGuid to driver DriverName took ElapsedTimeMs milliseconds.Driver WatchdogNN
1000Device DeviceInstanceId could not be query removed as the removal was vetoed.Device ManagementYN
1010Device DeviceInstanceId has been surprise removed as it is reported as missing …Device ManagementYN
1011Device DeviceInstanceId has been surprise removed as it was reported to be …Device ManagementYN
1020A resource rebalance operation has succeeded.Device ManagementNN
1021A resource rebalance operation has failed.Device ManagementNN
1030Device Device has been assigned to a guest partition.Device ManagementNN
1031Device Device is no longer assigned to a guest partition.Device ManagementNN
1040Device Flags has requested a platform-level device reset.Device ManagementNN
1041Device Veto_type has completed a platform-level device reset.Device ManagementNN
1050Failed to create driver package defined child device of Child_Instance_ID.Device ManagementNN
1060Failed to create computer device derived from firmware information.Device ManagementNN
1065Device DeviceInstanceId with problem code ProblemCode and problem status …Device ManagementNN
1070Failed to open DeviceStackLocation driver service ServiceName for device …Device ManagementNN
1080The driver FailureName failed to unload.Device ManagementNN
1100SwDevice_IrpCreateStartOperationalNN
1101SwDevice_IrpCreateStopOperationalNN
1102SwDevice_KernelCreateStartOperationalNN
1103SwDevice_KernelCreateStopOperationalNN
1104task_01104OperationalNN
1105task_01105OperationalNN
1106task_01106OperationalNN
1107task_01107OperationalNN
1108SwDevice_InstanceTable_AddOperationalNN
1109SwDevice_InstanceTable_RemoveOperationalNN
1110SwDevice_DeviceEnumeratedStartOperationalNN
1111SwDevice_DeviceEnumeratedStopOperationalNN
1120SwDevice_RelationAddStartOperationalNN
1121SwDevice_RelationAddStopOperationalNN
1122SwDevice_RelationRemoveOperationalNN
1130SwDevice_LifetimeChangeStartOperationalNN
1131SwDevice_LifetimeChangeStopOperationalNN
1132SwDevice_LifetimeChangeOperationalNN
1140SwDevice_RegisterInterfaceStartOperationalNN
1141SwDevice_RegisterInterfaceStopOperationalNN
1142SwDevice_RegisterInterfaceOperationalNN
1143SwDevice_SetInterfaceStateOperationalNN
1144SwDevice_SetInterfaceStateStartOperationalNN
1145SwDevice_SetInterfaceStateStopOperationalNN
1150SwDevice_SetDevicePropertyStartOperationalNN
1151SwDevice_SetDevicePropertyStopOperationalNN
1160SwDevice_SetInterfacePropertyStartOperationalNN
1161SwDevice_SetInterfacePropertyStopOperationalNN
1170SwDevice_IrpCloseStartOperationalNN
1171SwDevice_IrpCloseStopOperationalNN
1172SwDevice_KernelCloseStartOperationalNN
1173SwDevice_KernelCloseStopOperationalNN
1174SwDevice_CloseDescendantsOperationalNN
1175SwDevice_CloseDeviceOperationalNN
1176SwDevice_ProcessRemoveOperationalNN
1177SwDevice_ProcessParentRemoveOperationalNN
1178SwDevice_UninstallDeviceOperationalNN
1190SwDevice_GetChildPdoStartOperationalYN
1191SwDevice_GetChildPdoStopOperationalYN
1192SwDevice_GetChildPdoOperationalNN
1200SwDevice_AttributesChangeStartOperationalNN
1201SwDevice_AttributesChangeStopOperationalNN
1202SwDevice_AttributesChangeOperationalNN
1300task_01300OperationalNN
1301task_01301OperationalNN
1302task_01302OperationalNN
1303task_01303OperationalNN
1304task_01304OperationalNN
1400Begin serializing boot with PnP device enumerationBoot DiagnosticNN
1401End serializing boot with PnP device enumerationBoot DiagnosticNN

Event ID 200: Begin boot start drivers phase

#
Channel
Boot Diagnostic
Task
BootStart
Opcode
Start

Event ID 201: End boot start drivers phase

#
Channel
Boot Diagnostic
Task
BootStart
Opcode
Stop

Event ID 202: Begin system start drivers phase

#
Channel
Boot Diagnostic
Task
SystemStart
Opcode
Start

Event ID 203: End system start drivers phase

#
Channel
Boot Diagnostic
Task
SystemStart
Opcode
Stop

Event ID 204: OS Loader Start: OS_Loader_Start.

#
Channel
Boot Diagnostic
Task
OsLoader

Message #

OS Loader Start: %1
OS Loader End: %2

Fields #

NameDescription
OSLoaderStart UInt64
OSLoaderEnd UInt64
PreloadEndTime UInt64
TcbLoaderStartTime UInt64
LoadHypervisorTime UInt64
LaunchHypervisorTime UInt64
LoadVsmTime UInt64
LaunchVsmTime UInt64
ExecuteTransitionStartTime UInt64
ExecuteTransitionEndTime UInt64
PerformanceDataFrequency UInt64

Event ID 205: EarlyLaunchAntiMalwareStart

#
Channel
Operational
Task
EarlyLaunchAntiMalware
Opcode
Start

Fields #

NameDescription
ElamDriverNameLength UInt16
ElamDriverName UnicodeString

Event ID 206: EarlyLaunchAntiMalwareStop

#
Channel
Operational
Task
EarlyLaunchAntiMalware
Opcode
Stop

Fields #

NameDescription
ElamDriverNameLength UInt16
ElamDriverName UnicodeString

Event ID 207: EarlyLaunchAntiMalwareStart207

#
Channel
Operational
Task
EarlyLaunchAntiMalware
Opcode
Start

Fields #

NameDescription
ElamStatus UInt32

Event ID 208: EarlyLaunchAntiMalwareStop208

#
Channel
Operational
Task
EarlyLaunchAntiMalware
Opcode
Stop

Fields #

NameDescription
ElamStatus UInt32

Event ID 209: EarlyLaunchAntiMalware

#
Channel
Operational
Task
EarlyLaunchAntiMalware

Fields #

NameDescription
Classification UInt32
Policy UInt32
Result UInt32

Event ID 210: Begin initializing boot start driver DriverName.

#
Channel
Driver Diagnostic
Task
BootInit
Opcode
Start

Message #

Begin initializing boot start driver %2

Fields #

NameDescription
DriverNameLength UInt16
DriverName UnicodeString

Event ID 211: End initializing boot start driver DriverName.

#
Channel
Driver Diagnostic
Task
BootInit
Opcode
Stop

Description

End initializing boot start driver DriverName. Status: Status.

Message #

End initializing boot start driver %2.  Status: %3

Fields #

NameDescription
DriverNameLength UInt16
DriverName UnicodeString
Status UInt32NTSTATUS reference

Event ID 212: Begin loading driver DriverName.

#
Channel
Driver Diagnostic
Task
DriverLoad
Opcode
Start

Message #

Begin loading driver %2

Fields #

NameDescription
DriverNameLength UInt16
DriverName UnicodeString

Event ID 213: End loading driver DriverName.

#
Channel
Driver Diagnostic
Task
DriverLoad
Opcode
Stop

Description

End loading driver DriverName. Status: Status.

Message #

End loading driver %5.  Status: %3

Fields #

NameDescription
ServiceNameLength UInt16
ServiceName UnicodeString
Status UInt32NTSTATUS reference
DriverNameLength UInt16
DriverName UnicodeString
Version UInt32

Event ID 214: Begin unloading driver DriverName.

#
Channel
Driver Diagnostic
Task
DriverUnload
Opcode
Start

Message #

Begin unloading driver %2

Fields #

NameDescription
DriverNameLength UInt16
DriverName UnicodeString

Event ID 215: End unloading driver DriverName.

#
Channel
Driver Diagnostic
Task
DriverUnload
Opcode
Stop

Description

End unloading driver DriverName. Status: Status.

Message #

End unloading driver %5.  Status: %3

Fields #

NameDescription
ServiceNameLength UInt16
ServiceName UnicodeString
Status UInt32NTSTATUS reference
DriverNameLength UInt16
DriverName UnicodeString
Version UInt32

Event ID 216: Begin starting device DriverName.

#
Channel
Device Enumeration Diagnostic
Level
Informational
Task
DeviceStart
Opcode
Start

Message #

Begin starting device %2

Fields #

NameDescription
DriverNameLength UInt16
DriverName UnicodeString

Example Event #

{
  "system": {
    "channel": "Microsoft-Windows-Kernel-PnP/Device Enumeration Diagnostic",
    "computer": "10.2.10.21",
    "correlation": {},
    "event_id": 216,
    "event_record_id": 0,
    "event_source_name": "",
    "execution": {
      "process_id": 4,
      "thread_id": 11848
    },
    "guid": "",
    "keywords": 0,
    "level": 4,
    "opcode": 1,
    "provider": "Microsoft-Windows-Kernel-PnP",
    "security": {
      "user_id": ""
    },
    "task": 0,
    "time_created": "2026-07-21 22:20:40.847Z",
    "version": 0
  },
  "event_data": {
    "DriverName": "ROOT\\VMS_VSMP\\0001",
    "DriverNameLength": 18
  },
  "message": ""
}

Event ID 217: Pending start of device DriverName.

#
Channel
Device Enumeration Diagnostic
Level
Informational
Task
DeviceStart
Opcode
Suspend

Message #

Pending start of device %2

Fields #

NameDescription
DriverNameLength UInt16
DriverName UnicodeString

Example Event #

{
  "system": {
    "channel": "Microsoft-Windows-Kernel-PnP/Device Enumeration Diagnostic",
    "computer": "10.2.10.21",
    "correlation": {},
    "event_id": 217,
    "event_record_id": 0,
    "event_source_name": "",
    "execution": {
      "process_id": 4,
      "thread_id": 11848
    },
    "guid": "",
    "keywords": 0,
    "level": 4,
    "opcode": 8,
    "provider": "Microsoft-Windows-Kernel-PnP",
    "security": {
      "user_id": ""
    },
    "task": 0,
    "time_created": "2026-07-21 22:20:40.847Z",
    "version": 0
  },
  "event_data": {
    "DriverName": "ROOT\\VMS_VSMP\\0001",
    "DriverNameLength": 18
  },
  "message": ""
}

Event ID 218: End starting device DriverName using driver FailureName.

#
Channel
Device Enumeration Diagnostic
Level
Informational
Task
DeviceStart
Opcode
Stop

Description

End starting device DriverName using driver FailureName. Status: Status.

Message #

End starting device %2 using driver %5.  Status: %3

Fields #

NameDescription
DriverNameLength UInt16
DriverName UnicodeString
Status UInt32NTSTATUS reference
FailureNameLength UInt16
FailureName UnicodeString
Version UInt32

Example Event #

{
  "system": {
    "channel": "Microsoft-Windows-Kernel-PnP/Device Enumeration Diagnostic",
    "computer": "10.2.10.21",
    "correlation": {},
    "event_id": 218,
    "event_record_id": 0,
    "event_source_name": "",
    "execution": {
      "process_id": 4,
      "thread_id": 4408
    },
    "guid": "",
    "keywords": 0,
    "level": 4,
    "opcode": 2,
    "provider": "Microsoft-Windows-Kernel-PnP",
    "security": {
      "user_id": ""
    },
    "task": 0,
    "time_created": "2026-07-21 22:20:40.848Z",
    "version": 0
  },
  "event_data": {
    "DriverName": "ROOT\\VMS_VSMP\\0001",
    "DriverNameLength": 18,
    "FailureName": "\\Driver\\VMSP",
    "FailureNameLength": 12,
    "Status": 3221225473,
    "Version": 655360
  },
  "message": ""
}

Event ID 219: The driver FailureName failed to load.

#
Channel
System
Level
Warning
Collection Priority
Recommended (NSA)
Task
DriverLoad

Message #

The driver %5 failed to load.
Device: %2
Status: %3

Fields #

NameDescription
DriverNameLength UInt16
DriverName UnicodeString
Status UInt32NTSTATUS reference
FailureNameLength UInt16
FailureName UnicodeString
Version UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Kernel-PnP",
    "guid": "9C205A39-1250-487D-ABD7-E831C6290539",
    "event_source_name": "",
    "event_id": 219,
    "version": 0,
    "level": 3,
    "task": 212,
    "opcode": 0,
    "keywords": 9223372036854775808,
    "time_created": "2023-11-06T06:25:19.591886+00:00",
    "event_record_id": 1645,
    "correlation": {},
    "execution": {
      "process_id": 4,
      "thread_id": 224
    },
    "channel": "System",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "DriverNameLength": 15,
    "DriverName": "ROOT\\VMBus\\0000",
    "Status": 3221226341,
    "FailureNameLength": 14,
    "FailureName": "\\Driver\\vmbusr",
    "Version": 0
  },
  "message": ""
}

References #

Event ID 220: Begin querying bus relations for device DriverName.

#
Channel
Device Enumeration Diagnostic
Level
Informational
Task
DeviceEnum
Opcode
Start

Message #

Begin querying bus relations for device %2

Fields #

NameDescription
DriverNameLength UInt16
DriverName UnicodeString

Example Event #

{
  "system": {
    "channel": "Microsoft-Windows-Kernel-PnP/Device Enumeration Diagnostic",
    "computer": "10.2.10.21",
    "correlation": {},
    "event_id": 220,
    "event_record_id": 0,
    "event_source_name": "",
    "execution": {
      "process_id": 4,
      "thread_id": 11360
    },
    "guid": "",
    "keywords": 0,
    "level": 4,
    "opcode": 1,
    "provider": "Microsoft-Windows-Kernel-PnP",
    "security": {
      "user_id": ""
    },
    "task": 0,
    "time_created": "2026-07-21 22:20:40.718Z",
    "version": 0
  },
  "event_data": {
    "DriverName": "HTREE\\ROOT\\0",
    "DriverNameLength": 12
  },
  "message": ""
}

Event ID 221: Pending querying bus relations for device DriverName.

#
Channel
Device Enumeration Diagnostic
Level
Informational
Task
DeviceEnum
Opcode
Suspend

Message #

Pending querying bus relations for device %2

Fields #

NameDescription
DriverNameLength UInt16
DriverName UnicodeString

Example Event #

{
  "system": {
    "channel": "Microsoft-Windows-Kernel-PnP/Device Enumeration Diagnostic",
    "computer": "10.2.10.21",
    "correlation": {},
    "event_id": 221,
    "event_record_id": 0,
    "event_source_name": "",
    "execution": {
      "process_id": 4,
      "thread_id": 2144
    },
    "guid": "",
    "keywords": 0,
    "level": 4,
    "opcode": 8,
    "provider": "Microsoft-Windows-Kernel-PnP",
    "security": {
      "user_id": ""
    },
    "task": 0,
    "time_created": "2026-07-22 05:46:25.914Z",
    "version": 0
  },
  "event_data": {
    "DriverName": "PCI\\VEN_8086&DEV_7010&SUBSYS_11001AF4&REV_00\\3&267a616a&0&09",
    "DriverNameLength": 60
  },
  "message": ""
}

Event ID 222: End querying bus relations for device DriverName.

#
Channel
Device Enumeration Diagnostic
Level
Informational
Task
DeviceEnum
Opcode
Stop

Message #

End querying bus relations for device %2

Fields #

NameDescription
DriverNameLength UInt16
DriverName UnicodeString

Example Event #

{
  "system": {
    "channel": "Microsoft-Windows-Kernel-PnP/Device Enumeration Diagnostic",
    "computer": "10.2.10.21",
    "correlation": {},
    "event_id": 222,
    "event_record_id": 0,
    "event_source_name": "",
    "execution": {
      "process_id": 4,
      "thread_id": 11360
    },
    "guid": "",
    "keywords": 0,
    "level": 4,
    "opcode": 2,
    "provider": "Microsoft-Windows-Kernel-PnP",
    "security": {
      "user_id": ""
    },
    "task": 0,
    "time_created": "2026-07-21 22:20:40.719Z",
    "version": 0
  },
  "event_data": {
    "DriverName": "HTREE\\ROOT\\0",
    "DriverNameLength": 12
  },
  "message": ""
}

Event ID 223: Begin attempting to eject device DriverName.

#
Channel
Device Enumeration Diagnostic
Task
DeviceEject
Opcode
Start

Message #

Begin attempting to eject device %2

Fields #

NameDescription
DriverNameLength UInt16
DriverName UnicodeString

Event ID 224: End attempting to eject device DriverName.

#
Channel
Device Enumeration Diagnostic
Task
DeviceEject
Opcode
Stop

Description

End attempting to eject device DriverName. Status: Status.

Message #

End attempting to eject device %2. Status: %3

Fields #

NameDescription
DriverNameLength UInt16
DriverName UnicodeString
Status UInt32NTSTATUS reference
FailureNameLength UInt16
FailureName UnicodeString
Version UInt32

Event ID 225: The application ProcessName with process id ProcessId stopped the removal or ejection for the device DeviceInstance.

#
Channel
System
Task
DeviceEject

Message #

The application %3 with process id %1 stopped the removal or ejection for the device %5.

Fields #

NameDescription
ProcessId UInt32
ProcessNameLength UInt16
ProcessName UnicodeString
DeviceInstanceLength UInt16
DeviceInstance UnicodeString
CommandLineLength UInt16
CommandLine UnicodeString
VetoingDevicesLength UInt16
VetoingDevices UnicodeString

Event ID 226: Begin calling driver initialization routine for driver DriverName.

#
Channel
Driver Diagnostic
Task
DriverInit
Opcode
Start

Message #

Begin calling driver initialization routine for driver %2

Fields #

NameDescription
DriverNameLength UInt16
DriverName UnicodeString

Event ID 227: End calling driver initialization routine for driver DriverName.

#
Channel
Driver Diagnostic
Task
DriverInit
Opcode
Stop

Description

End calling driver initialization routine for driver DriverName. Status: Status.

Message #

End calling driver initialization routine for driver %2. Status: %3

Fields #

NameDescription
DriverNameLength UInt16
DriverName UnicodeString
Status UInt32NTSTATUS reference

Event ID 228: task_0

#
Channel
Operational
Opcode
Info

Fields #

NameDescription
SqmType UInt32
SqmSessionGuid GUID
SqmSid SID
SqmWindowsSessionId UInt32
SqmSessionFlags UInt32

Event ID 229: task_0229

#
Channel
Operational
Opcode
Info

Fields #

NameDescription
SqmType UInt32
SqmSessionGuid GUID

Event ID 230: task_0230

#
Channel
Operational
Opcode
Info

Fields #

NameDescription
SqmType UInt32
SqmSessionGuid GUID
SqmID UInt32
SqmDWORDDatapointValue UInt32

Event ID 231: task_0Stop

#
Channel
Operational
Opcode
Stop

Fields #

NameDescription
SqmType UInt32
SqmSessionGuid GUID
SqmID UInt32
SqmDWORDDatapointValue UInt32

Event ID 232: task_0232

#
Channel
Operational
Opcode
Info

Fields #

NameDescription
SqmType UInt32
SqmSessionGuid GUID
SqmID UInt32
SqmDWORDDatapointValue UInt32

Event ID 233: task_0233

#
Channel
Operational
Opcode
Info

Fields #

NameDescription
SqmType UInt32
SqmSessionGuid GUID
SqmID UInt32
SqmDWORDDatapointValue UInt32

Event ID 234: task_0234

#
Channel
Operational
Opcode
Info

Fields #

NameDescription
SqmType UInt32
SqmSessionGuid GUID
SqmID UInt32
SqmDWORDDatapointValue UInt32

Event ID 235: task_0235

#
Channel
Operational
Opcode
Info

Fields #

NameDescription
SqmType UInt32
SqmSessionGuid GUID
SqmID UInt32
SqmStringDatapointValue UnicodeString

Event ID 236: task_0236

#
Channel
Operational
Opcode
Info

Fields #

NameDescription
SqmType UInt32
SqmSessionGuid GUID
SqmID UInt32
SqmStreamRowLength UInt32
SqmStreamRow Int16

Event ID 240: A partition unit replace operation has been initiated.

#
Channel
System
Opcode
Info

Fields #

NameDescription
TargetPath UnicodeString
SparePath UnicodeString

Event ID 241: A partition unit replace operation has failed.

#
Channel
System
Opcode
Info

Fields #

NameDescription
TargetPath UnicodeString
SparePath UnicodeString
Status HexInt32NTSTATUS reference
Location UInt32
ExtendedStatus UInt32

Event ID 242: A partition unit has been successfully replaced.

#
Channel
System
Opcode
Info

Fields #

NameDescription
TargetPath UnicodeString
TargetAffinity HexInt64
TargetProcessorCount UInt32
TargetMemoryCount UInt32
TargetMemorySize HexInt64
SparePath UnicodeString
SpareProcessorCount UInt32
SpareMemoryCount UInt32
SpareMemorySize HexInt64
TimeTotal UInt32
TimeToQuiesce UInt32
TimeQuiesced UInt32
TimeToWake UInt32
TargetProcessors FILETIME
TargetMemoryRanges SYSTEMTIME
SpareProcessors HexInt32
SpareMemoryRanges HexInt64

Event ID 250: Begin configuration of device DeviceInstance.

#
Channel
Configuration Diagnostic
Level
Informational
Task
DeviceConfig
Opcode
Start

Message #

Begin configuration of device %2

Fields #

NameDescription
DeviceInstanceLength UInt16
DeviceInstance UnicodeString

Example Event #

{
  "system": {
    "channel": "Microsoft-Windows-Kernel-PnP/Configuration Diagnostic",
    "computer": "10.2.10.21",
    "correlation": {},
    "event_id": 250,
    "event_record_id": 0,
    "event_source_name": "",
    "execution": {
      "process_id": 4,
      "thread_id": 11360
    },
    "guid": "",
    "keywords": 0,
    "level": 4,
    "opcode": 1,
    "provider": "Microsoft-Windows-Kernel-PnP",
    "security": {
      "user_id": ""
    },
    "task": 0,
    "time_created": "2026-07-21 22:20:40.703Z",
    "version": 0
  },
  "event_data": {
    "DeviceInstance": "ROOT\\VMS_VSMP\\0001",
    "DeviceInstanceLength": 18
  },
  "message": ""
}

Event ID 251: Pending configuration of device DeviceInstance.

#
Channel
Configuration Diagnostic
Task
DeviceConfig
Opcode
Suspend

Message #

Pending configuration of device %2

Fields #

NameDescription
DeviceInstanceLength UInt16
DeviceInstance UnicodeString

Event ID 252: End configuration of device DeviceInstance.

#
Channel
Configuration Diagnostic
Level
Informational
Task
DeviceConfig
Opcode
Stop

Description

End configuration of device DeviceInstance. Status: Status.

Message #

End configuration of device %2. Status: %3

Fields #

NameDescription
DeviceInstanceLength UInt16
DeviceInstance UnicodeString
Status UInt32NTSTATUS reference

Example Event #

{
  "system": {
    "channel": "Microsoft-Windows-Kernel-PnP/Configuration Diagnostic",
    "computer": "10.2.10.21",
    "correlation": {},
    "event_id": 252,
    "event_record_id": 0,
    "event_source_name": "",
    "execution": {
      "process_id": 4,
      "thread_id": 11360
    },
    "guid": "",
    "keywords": 0,
    "level": 4,
    "opcode": 2,
    "provider": "Microsoft-Windows-Kernel-PnP",
    "security": {
      "user_id": ""
    },
    "task": 0,
    "time_created": "2026-07-21 22:20:40.716Z",
    "version": 0
  },
  "event_data": {
    "DeviceInstance": "ROOT\\VMS_VSMP\\0001",
    "DeviceInstanceLength": 18,
    "Status": 0
  },
  "message": ""
}

Event ID 260: Begin starting system start drivers part 1

#
Channel
Boot Diagnostic
Task
SystemStartPnPEnum
Opcode
Start

Event ID 261: End starting system start drivers part 1

#
Channel
Boot Diagnostic
Task
SystemStartPnPEnum
Opcode
Stop

Event ID 262: Begin starting system start drivers part 2

#
Channel
Boot Diagnostic
Task
SystemStartLegacyEnum
Opcode
Start

Event ID 263: End starting system start drivers part 2

#
Channel
Boot Diagnostic
Task
SystemStartLegacyEnum
Opcode
Stop

Event ID 264: Begin processing reinitialization requests for boot start drivers

#
Channel
Driver Diagnostic
Task
BootDriverReinit
Opcode
Start

Event ID 265: End processing reinitialization requests for boot start drivers

#
Channel
Driver Diagnostic
Task
BootDriverReinit
Opcode
Stop

Event ID 266: Begin processing reinitialization requests for system start drivers

#
Channel
Driver Diagnostic
Task
SystemStartDriverReinit
Opcode
Start

Event ID 267: End processing reinitialization requests for system start drivers

#
Channel
Driver Diagnostic
Task
SystemStartDriverReinit
Opcode
Stop

Event ID 270: Begin loading driver database DriverName.

#
Channel
Configuration Diagnostic
Level
Informational
Task
DriverDatabaseLoad
Opcode
Start

Message #

Begin loading driver database %2

Fields #

NameDescription
DriverNameLength UInt16
DriverName UnicodeString

Example Event #

{
  "system": {
    "channel": "Microsoft-Windows-Kernel-PnP/Configuration Diagnostic",
    "computer": "10.2.10.21",
    "correlation": {},
    "event_id": 270,
    "event_record_id": 0,
    "event_source_name": "",
    "execution": {
      "process_id": 4,
      "thread_id": 3480
    },
    "guid": "",
    "keywords": 0,
    "level": 4,
    "opcode": 1,
    "provider": "Microsoft-Windows-Kernel-PnP",
    "security": {
      "user_id": ""
    },
    "task": 0,
    "time_created": "2026-07-22 05:45:21.826Z",
    "version": 0
  },
  "event_data": {
    "DriverName": "DRIVERS",
    "DriverNameLength": 7
  },
  "message": ""
}

Event ID 271: Pending loading driver database DriverName.

#
Channel
Configuration Diagnostic
Task
DriverDatabaseLoad
Opcode
Suspend

Message #

Pending loading driver database %2

Fields #

NameDescription
DriverNameLength UInt16
DriverName UnicodeString

Event ID 272: End loading driver database DriverName.

#
Channel
Configuration Diagnostic
Level
Informational
Task
DriverDatabaseLoad
Opcode
Stop

Message #

End loading driver database %2

Fields #

NameDescription
DriverNameLength UInt16
DriverName UnicodeString
Status UInt32NTSTATUS reference

Example Event #

{
  "system": {
    "channel": "Microsoft-Windows-Kernel-PnP/Configuration Diagnostic",
    "computer": "10.2.10.21",
    "correlation": {},
    "event_id": 272,
    "event_record_id": 0,
    "event_source_name": "",
    "execution": {
      "process_id": 4,
      "thread_id": 3480
    },
    "guid": "",
    "keywords": 0,
    "level": 4,
    "opcode": 2,
    "provider": "Microsoft-Windows-Kernel-PnP",
    "security": {
      "user_id": ""
    },
    "task": 0,
    "time_created": "2026-07-22 05:45:21.873Z",
    "version": 0
  },
  "event_data": {
    "DriverName": "DRIVERS",
    "DriverNameLength": 7,
    "Status": 0
  },
  "message": ""
}

Event ID 273: Begin unloading driver database DriverName.

#
Channel
Configuration Diagnostic
Level
Informational
Task
DriverDatabaseUnload
Opcode
Start

Message #

Begin unloading driver database %2

Fields #

NameDescription
DriverNameLength UInt16
DriverName UnicodeString

Example Event #

{
  "system": {
    "channel": "Microsoft-Windows-Kernel-PnP/Configuration Diagnostic",
    "computer": "10.2.10.21",
    "correlation": {},
    "event_id": 273,
    "event_record_id": 0,
    "event_source_name": "",
    "execution": {
      "process_id": 4,
      "thread_id": 12732
    },
    "guid": "",
    "keywords": 0,
    "level": 4,
    "opcode": 1,
    "provider": "Microsoft-Windows-Kernel-PnP",
    "security": {
      "user_id": ""
    },
    "task": 0,
    "time_created": "2026-07-22 05:45:15.030Z",
    "version": 0
  },
  "event_data": {
    "DriverName": "DRIVERS",
    "DriverNameLength": 7
  },
  "message": ""
}

Event ID 274: Pending unloading driver database DriverName.

#
Channel
Configuration Diagnostic
Level
Informational
Task
DriverDatabaseUnload
Opcode
Suspend

Message #

Pending unloading driver database %2

Fields #

NameDescription
DriverNameLength UInt16
DriverName UnicodeString

Example Event #

{
  "system": {
    "channel": "Microsoft-Windows-Kernel-PnP/Configuration Diagnostic",
    "computer": "10.2.10.21",
    "correlation": {},
    "event_id": 274,
    "event_record_id": 0,
    "event_source_name": "",
    "execution": {
      "process_id": 4,
      "thread_id": 12732
    },
    "guid": "",
    "keywords": 0,
    "level": 4,
    "opcode": 8,
    "provider": "Microsoft-Windows-Kernel-PnP",
    "security": {
      "user_id": ""
    },
    "task": 0,
    "time_created": "2026-07-22 05:45:15.033Z",
    "version": 0
  },
  "event_data": {
    "DriverName": "DRIVERS",
    "DriverNameLength": 7
  },
  "message": ""
}

Event ID 275: End unloading driver database DriverName.

#
Channel
Configuration Diagnostic
Level
Informational
Task
DriverDatabaseUnload
Opcode
Stop

Message #

End unloading driver database %2

Fields #

NameDescription
DriverNameLength UInt16
DriverName UnicodeString
Status UInt32NTSTATUS reference

Example Event #

{
  "system": {
    "channel": "Microsoft-Windows-Kernel-PnP/Configuration Diagnostic",
    "computer": "10.2.10.21",
    "correlation": {},
    "event_id": 275,
    "event_record_id": 0,
    "event_source_name": "",
    "execution": {
      "process_id": 4,
      "thread_id": 9184
    },
    "guid": "",
    "keywords": 0,
    "level": 4,
    "opcode": 2,
    "provider": "Microsoft-Windows-Kernel-PnP",
    "security": {
      "user_id": ""
    },
    "task": 0,
    "time_created": "2026-07-22 05:45:15.033Z",
    "version": 0
  },
  "event_data": {
    "DriverName": "DRIVERS",
    "DriverNameLength": 7,
    "Status": 0
  },
  "message": ""
}

Event ID 276: DriverDatabaseLoadedStart

#
Channel
Operational
Level
Informational
Task
DriverDatabaseLoaded
Opcode
Start

Fields #

NameDescription
DriverNameLength UInt16
DriverName UnicodeString

Example Event #

{
  "system": {
    "channel": "Microsoft-Windows-Kernel-PnP/Operational",
    "computer": "10.2.10.21",
    "correlation": {},
    "event_id": 276,
    "event_record_id": 0,
    "event_source_name": "",
    "execution": {
      "process_id": 4,
      "thread_id": 3480
    },
    "guid": "",
    "keywords": 0,
    "level": 4,
    "opcode": 1,
    "provider": "Microsoft-Windows-Kernel-PnP",
    "security": {
      "user_id": ""
    },
    "task": 0,
    "time_created": "2026-07-22 05:45:21.826Z",
    "version": 0
  },
  "event_data": {
    "DriverName": "DRIVERS",
    "DriverNameLength": 7
  },
  "message": ""
}

Event ID 277: DriverDatabaseLoadedStop

#
Channel
Operational
Level
Informational
Task
DriverDatabaseLoaded
Opcode
Stop

Fields #

NameDescription
DriverNameLength UInt16
DriverName UnicodeString
Status UInt32NTSTATUS reference

Example Event #

{
  "system": {
    "channel": "Microsoft-Windows-Kernel-PnP/Operational",
    "computer": "10.2.10.21",
    "correlation": {},
    "event_id": 277,
    "event_record_id": 0,
    "event_source_name": "",
    "execution": {
      "process_id": 4,
      "thread_id": 9184
    },
    "guid": "",
    "keywords": 0,
    "level": 4,
    "opcode": 2,
    "provider": "Microsoft-Windows-Kernel-PnP",
    "security": {
      "user_id": ""
    },
    "task": 0,
    "time_created": "2026-07-22 05:45:15.033Z",
    "version": 0
  },
  "event_data": {
    "DriverName": "DRIVERS",
    "DriverNameLength": 7,
    "Status": 0
  },
  "message": ""
}

Event ID 278: task_0278

#
Channel
Operational
Opcode
Info

Fields #

NameDescription
BlockedDriverEntry GUID

Event ID 300: Begin starting initialization of drivers

#
Channel
Boot Diagnostic
Opcode
Info

Event ID 301: End starting initialization of drivers

#
Channel
Boot Diagnostic
Opcode
Info

Event ID 400: Device DeviceInstanceId was configured.

#
Channel
Configuration
Level
Informational
Collection Priority
Recommended (NSA)
Opcode
Info

Message #

Device %1 was configured.

Driver Name: %2
Class GUID: %3
Driver Date: %4
Driver Version: %5
Driver Provider: %6
Driver Section: %8
Driver Rank: %9
Matching Device ID: %10
Outranked Drivers: %11
Device Updated: %12
Parent Device: %14

Fields #

NameDescription
DeviceInstanceId UnicodeString
DriverName UnicodeString
ClassGuid GUID
DriverDate UnicodeString
DriverVersion UnicodeString
DriverProvider UnicodeString
DriverInbox Boolean
DriverSection UnicodeString
DriverRank HexInt32
MatchingDeviceId UnicodeString
OutrankedDrivers UnicodeString
DeviceUpdated Boolean
Status HexInt32NTSTATUS reference
ParentDeviceInstanceId UnicodeStringParent Device.
DriverPackageId

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Kernel-PnP",
    "guid": "{9C205A39-1250-487D-ABD7-E831C6290539}",
    "event_source_name": "",
    "event_id": 400,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 4611686018427387904,
    "time_created": "2026-06-13T05:12:15.8137445+00:00",
    "event_record_id": 143,
    "correlation": {},
    "execution": {
      "process_id": 4,
      "thread_id": 8188
    },
    "channel": "Microsoft-Windows-Kernel-PnP/Configuration",
    "computer": "telemetry-DC-c.cell-c.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "DeviceInstanceId": "ROOT\\VBUS\\0000",
    "DriverName": "vbus.inf",
    "ClassGuid": "{4d36e97d-e325-11ce-bfc1-08002be10318}",
    "DriverDate": "06/21/2006",
    "DriverVersion": "10.0.20348.469",
    "DriverProvider": "Microsoft",
    "DriverInbox": "true",
    "DriverSection": "Vbus_Device.NT",
    "DriverRank": "0xff0000",
    "MatchingDeviceId": "ROOT\\vbus",
    "OutrankedDrivers": "",
    "DeviceUpdated": "false",
    "Status": "0x0",
    "ParentDeviceInstanceId": "HTREE\\ROOT\\0"
  },
  "message": "Device ROOT\\VBUS\\0000 was configured.\r\n\r\nDriver Name: vbus.inf\r\nClass Guid: {4d36e97d-e325-11ce-bfc1-08002be10318}\r\nDriver Date: 06/21/2006\r\nDriver Version: 10.0.20348.469\r\nDriver Provider: Microsoft\r\nDriver Section: Vbus_Device.NT\r\nDriver Rank: 0xFF0000\r\nMatching Device Id: ROOT\\vbus\r\nOutranked Drivers: \r\nDevice Updated: false\r\nParent Device: HTREE\\ROOT\\0"
}

Event ID 401: Device Driver_Name failed configuration.

#
Channel
Configuration
Opcode
Info

Message #

Device %1 failed configuration.

Driver Name: %2
Class GUID: %3
Driver Date: %4
Driver Version: %5
Driver Provider: %6
Driver Section: %8
Driver Rank: %9
Matching Device ID: %10
Outranked Drivers: %11
Device Updated: %12
Status: %13
Parent Device: %14

Fields #

NameDescription
DeviceInstanceId UnicodeString
DriverName UnicodeString
ClassGuid GUID
DriverDate UnicodeString
DriverVersion UnicodeString
DriverProvider UnicodeString
DriverInbox Boolean
DriverSection UnicodeString
DriverRank HexInt32
MatchingDeviceId UnicodeString
OutrankedDrivers UnicodeString
DeviceUpdated Boolean
Status HexInt32Outranked Drivers. NTSTATUS reference
ParentDeviceInstanceId UnicodeString
DriverPackageId UnicodeString

Event ID 402: Device Driver_Name had its configuration blocked by policy.

#
Channel
Configuration
Opcode
Info

Message #

Device %1 had its configuration blocked by policy.

Driver Name: %2
Class GUID: %3
Driver Date: %4
Driver Version: %5
Driver Provider: %6
Driver Section: %8
Driver Rank: %9
Matching Device ID: %10
Outranked Drivers: %11
Device Updated: %12
Status: %13
Parent Device: %14

Fields #

NameDescription
DeviceInstanceId UnicodeString
DriverName UnicodeString
ClassGuid GUID
DriverDate UnicodeString
DriverVersion UnicodeString
DriverProvider UnicodeString
DriverInbox Boolean
DriverSection UnicodeString
DriverRank HexInt32
MatchingDeviceId UnicodeString
OutrankedDrivers UnicodeString
DeviceUpdated Boolean
Status HexInt32Outranked Drivers. NTSTATUS reference
ParentDeviceInstanceId UnicodeString
DriverPackageId UnicodeString

Event ID 403: Device DeviceInstanceId requires a system reboot to complete configuration.

#
Channel
Configuration
Level
Warning
Opcode
Info

Message #

Device %1 requires a system reboot to complete configuration.

Driver Name: %2
Class GUID: %3
Driver Date: %4
Driver Version: %5
Driver Provider: %6
Driver Section: %8
Driver Rank: %9
Matching Device ID: %10
Outranked Drivers: %11
Device Updated: %12
Status: %13
Parent Device: %14

Fields #

NameDescription
DeviceInstanceId UnicodeString
DriverName UnicodeString
ClassGuid GUID
DriverDate UnicodeString
DriverVersion UnicodeString
DriverProvider UnicodeString
DriverInbox Boolean
DriverSection UnicodeString
DriverRank HexInt32
MatchingDeviceId UnicodeString
OutrankedDrivers UnicodeString
DeviceUpdated Boolean
Status HexInt32NTSTATUS reference
ParentDeviceInstanceId UnicodeStringParent Device.
DriverPackageId

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Kernel-PnP",
    "guid": "9C205A39-1250-487D-ABD7-E831C6290539",
    "event_source_name": "",
    "event_id": 403,
    "version": 0,
    "level": 3,
    "task": 0,
    "opcode": 0,
    "keywords": 4611686018427387904,
    "time_created": "2023-10-26T04:16:19.107877+00:00",
    "event_record_id": 112,
    "correlation": {},
    "execution": {
      "process_id": 4,
      "thread_id": 248
    },
    "channel": "Microsoft-Windows-Kernel-PnP/Configuration",
    "computer": "WIN-OQ6R0RVA4NF",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "DeviceInstanceId": "ROOT\\VOLMGR\\0000",
    "DriverName": "volmgr.inf",
    "ClassGuid": "4D36E97D-E325-11CE-BFC1-08002BE10318",
    "DriverDate": "06/21/2006",
    "DriverVersion": "10.0.22621.608",
    "DriverProvider": "Microsoft",
    "DriverInbox": true,
    "DriverSection": "Volmgr",
    "DriverRank": "0xff0000",
    "MatchingDeviceId": "ROOT\\VOLMGR",
    "OutrankedDrivers": "",
    "DeviceUpdated": false,
    "Status": "0x0",
    "ParentDeviceInstanceId": "HTREE\\ROOT\\0"
  },
  "message": ""
}

References #

Event ID 410: Device DeviceInstanceId was started.

#
Channel
Configuration
Level
Informational
Collection Priority
Recommended (NSA)
Opcode
Info

Message #

Device %1 was started.

Driver Name: %2
Class GUID: %3
Service: %4
Lower Filters: %5
Upper Filters: %6

Fields #

NameDescription
DeviceInstanceId UnicodeString
DriverName UnicodeString
ClassGuid GUID
ServiceName UnicodeStringService.
LowerFilters UnicodeString
UpperFilters UnicodeString
Problem HexInt32
Status HexInt32NTSTATUS reference

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Kernel-PnP",
    "guid": "{9C205A39-1250-487D-ABD7-E831C6290539}",
    "event_source_name": "",
    "event_id": 410,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 4611686018427387904,
    "time_created": "2026-06-13T05:12:16.5253427+00:00",
    "event_record_id": 145,
    "correlation": {},
    "execution": {
      "process_id": 4,
      "thread_id": 2340
    },
    "channel": "Microsoft-Windows-Kernel-PnP/Configuration",
    "computer": "telemetry-DC-c.cell-c.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "DeviceInstanceId": "ROOT\\NETFT\\0000",
    "DriverName": "netft.inf",
    "ClassGuid": "{4d36e972-e325-11ce-bfc1-08002be10318}",
    "ServiceName": "Netft",
    "LowerFilters": "",
    "UpperFilters": "",
    "Problem": "0x0",
    "Status": "0x0"
  },
  "message": "Device ROOT\\NETFT\\0000 was started.\r\n\r\nDriver Name: netft.inf\r\nClass Guid: {4d36e972-e325-11ce-bfc1-08002be10318}\r\nService: Netft\r\nLower Filters: \r\nUpper Filters: "
}

Event ID 411: Device DeviceInstanceId had a problem starting.

#
Channel
Configuration
Level
Error
Opcode
Info

Message #

Device %1 had a problem starting.

Driver Name: %2
Class GUID: %3
Service: %4
Lower Filters: %5
Upper Filters: %6
Problem: %7
Problem Status: %8

Fields #

NameDescription
DeviceInstanceId UnicodeString
DriverName UnicodeString
ClassGuid GUID
ServiceName UnicodeStringService.
LowerFilters UnicodeString
UpperFilters UnicodeString
Problem HexInt32
Status HexInt32Problem Status. NTSTATUS reference

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Kernel-PnP",
    "guid": "9C205A39-1250-487D-ABD7-E831C6290539",
    "event_source_name": "",
    "event_id": 411,
    "version": 0,
    "level": 2,
    "task": 0,
    "opcode": 0,
    "keywords": 4611686018427387904,
    "time_created": "2023-10-26T04:17:42.366175+00:00",
    "event_record_id": 168,
    "correlation": {},
    "execution": {
      "process_id": 4,
      "thread_id": 52
    },
    "channel": "Microsoft-Windows-Kernel-PnP/Configuration",
    "computer": "WIN-OQ6R0RVA4NF",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "DeviceInstanceId": "PCI\\VEN_8086&DEV_100F&SUBSYS_075015AD&REV_01\\4&bbf9765&0&0088",
    "DriverName": "nete1g3e.inf",
    "ClassGuid": "4D36E972-E325-11CE-BFC1-08002BE10318",
    "ServiceName": "E1G60",
    "LowerFilters": "",
    "UpperFilters": "",
    "Problem": "0x0",
    "Status": "0xc00000e5"
  },
  "message": ""
}

References #

Event ID 412: Device Driver_Name requires a system reboot before it can be started.

#
Channel
Configuration
Opcode
Info

Message #

Device %1 requires a system reboot before it can be started.

Driver Name: %2
Class GUID: %3
Service: %4
Lower Filters: %5
Upper Filters: %6
Problem: %7
Problem Status: %8

Fields #

NameDescription
DeviceInstanceId UnicodeString
DriverName UnicodeString
ClassGuid GUID
ServiceName UnicodeString
LowerFilters UnicodeString
UpperFilters UnicodeString
Problem HexInt32
Status HexInt32NTSTATUS reference

Event ID 420: Device DeviceInstanceId was deleted.

#
Channel
Configuration
Level
Informational
Opcode
Info

Message #

Device %1 was deleted.

Class GUID: %2

Fields #

NameDescription
DeviceInstanceId UnicodeString
ClassGuid GUID
Problem HexInt32
Status HexInt32NTSTATUS reference

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Kernel-PnP",
    "guid": "9C205A39-1250-487D-ABD7-E831C6290539",
    "event_source_name": "",
    "event_id": 420,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 4611686018427387904,
    "time_created": "2026-03-13T17:24:14.944455+00:00",
    "event_record_id": 226,
    "correlation": {},
    "execution": {
      "process_id": 3668,
      "thread_id": 7476
    },
    "channel": "Microsoft-Windows-Kernel-PnP/Configuration",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "DeviceInstanceId": "SWD\\PRINTENUM\\{01F312F1-DACA-4AA7-96B1-5CE1A11685FD}",
    "ClassGuid": "1ED2BBF9-11F0-4084-B21F-AD83A8E6DCDC",
    "Problem": "0x2d",
    "Status": "0x0"
  },
  "message": ""
}

Event ID 421: Device Class_Guid could not be deleted.

#
Channel
Configuration
Opcode
Info

Message #

Device %1 could not be deleted.

Class GUID: %2
Problem: %3
Status: %4

Fields #

NameDescription
DeviceInstanceId UnicodeString
ClassGuid GUID
Problem HexInt32
Status HexInt32NTSTATUS reference

Event ID 430: Device DeviceInstanceId requires further installation.

#
Channel
Configuration
Level
Informational
Opcode
Info

Message #

Device %1 requires further installation.

Fields #

NameDescription
DeviceInstanceId UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Kernel-PnP",
    "guid": "9C205A39-1250-487D-ABD7-E831C6290539",
    "event_source_name": "",
    "event_id": 430,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 4611686018427387904,
    "time_created": "2023-10-26T04:16:49.350000+00:00",
    "event_record_id": 160,
    "correlation": {},
    "execution": {
      "process_id": 4,
      "thread_id": 248
    },
    "channel": "Microsoft-Windows-Kernel-PnP/Configuration",
    "computer": "WIN-OQ6R0RVA4NF",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "DeviceInstanceId": "PCI\\VEN_8086&DEV_100F&SUBSYS_075015AD&REV_01\\4&bbf9765&0&0888"
  },
  "message": ""
}

References #

Event ID 440: Device settings for Last_Device_Instance_Id were migrated from previous OS installation.

#
Channel
Configuration
Opcode
Info

Message #

Device settings for %1 were migrated from previous OS installation.

Last Device Instance ID: %2
Class GUID: %3
Location Path: %4
Migration Rank: %5
Present: %6

Fields #

NameDescription
DeviceInstanceId UnicodeString
LastDeviceInstanceId UnicodeString
ClassGuid GUID
LocationPath UnicodeString
MigrationRank HexInt64
Present Boolean
Status HexInt32NTSTATUS reference

Event ID 441: Device settings for Last_Device_Instance_Id could not be migrated from previous OS installation.

#
Channel
Configuration
Opcode
Info

Message #

Device settings for %1 could not be migrated from previous OS installation.

Last Device Instance ID: %2
Class GUID: %3
Location Path: %4
Migration Rank: %5
Present: %6
Status: %7

Fields #

NameDescription
DeviceInstanceId UnicodeString
LastDeviceInstanceId UnicodeString
ClassGuid GUID
LocationPath UnicodeString
MigrationRank HexInt64
Present Boolean
Status HexInt32NTSTATUS reference

Event ID 442: Device settings for Last_Device_Instance_Id were not migrated from previous OS installation due to partial or ambiguous device match.

#
Channel
Configuration
Opcode
Info

Message #

Device settings for %1 were not migrated from previous OS installation due to partial or ambiguous device match.

Last Device Instance ID: %2
Class GUID: %3
Location Path: %4
Migration Rank: %5
Present: %6
Status: %7

Fields #

NameDescription
DeviceInstanceId UnicodeString
LastDeviceInstanceId UnicodeString
ClassGuid GUID
LocationPath UnicodeString
MigrationRank HexInt64
Present Boolean
Status HexInt32NTSTATUS reference

Event ID 500: DevQuery_QueryProcessing

#
Channel
Operational
Also via
realtime ETW trace
Level
Informational
Task
DevQuery_QueryProcessing
Opcode
QueryStart

Fields #

NameDescription
QueryAddress Pointer
ProcessId UInt32
ObjectType UnicodeString
QueryType UnicodeString
ObjectId UnicodeString
QueryFlags UnicodeString
PreferredLanguages UnicodeString
RequestedProperties UnicodeString
FilterExpression UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Kernel-PnP",
    "guid": "{9C205A39-1250-487D-ABD7-E831C6290539}",
    "event_source_name": "",
    "event_id": 500,
    "version": 0,
    "level": 4,
    "task": 500,
    "opcode": 10,
    "keywords": "0x0000000001200000",
    "time_created": "2026-06-02T05:27:16.405+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{877F78A1-F053-0002-0E59-828753F0DC01}"
    },
    "execution": {
      "process_id": 16540,
      "thread_id": 23192
    },
    "channel": "ETW Trace",
    "computer": "JD-DC01-2022",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "FilterExpression": "NULL",
    "ObjectId": "NULL",
    "ObjectType": "Device",
    "PreferredLanguages": "NULL",
    "ProcessId": 16540,
    "QueryAddress": "0xFFFF878DC7348210",
    "QueryFlags": "",
    "QueryType": "Type",
    "RequestedProperties": "NULL"
  },
  "message": "DevQuery_QueryProcessing"
}

Event ID 501: DevQuery_QueryProcessingProcessingStart

#
Channel
Operational
Level
Informational
Task
DevQuery_QueryProcessing
Opcode
ProcessingStart

Fields #

NameDescription
QueryAddress Pointer

Example Event #

{
  "system": {
    "channel": "Microsoft-Windows-Kernel-PnP/Operational",
    "computer": "10.2.10.21",
    "correlation": {},
    "event_id": 501,
    "event_record_id": 0,
    "event_source_name": "",
    "execution": {
      "process_id": 4,
      "thread_id": 11360
    },
    "guid": "",
    "keywords": 0,
    "level": 4,
    "opcode": 12,
    "provider": "Microsoft-Windows-Kernel-PnP",
    "security": {
      "user_id": ""
    },
    "task": 0,
    "time_created": "2026-07-21 22:20:40.690Z",
    "version": 0
  },
  "event_data": {
    "QueryAddress": "0xFFFFC807B7DC3910"
  },
  "message": ""
}

Event ID 502: DevQuery_QueryProcessingProcessingStop

#
Channel
Operational
Level
Informational
Task
DevQuery_QueryProcessing
Opcode
ProcessingStop

Fields #

NameDescription
QueryAddress Pointer

Example Event #

{
  "system": {
    "channel": "Microsoft-Windows-Kernel-PnP/Operational",
    "computer": "10.2.10.21",
    "correlation": {},
    "event_id": 502,
    "event_record_id": 0,
    "event_source_name": "",
    "execution": {
      "process_id": 4,
      "thread_id": 11360
    },
    "guid": "",
    "keywords": 0,
    "level": 4,
    "opcode": 13,
    "provider": "Microsoft-Windows-Kernel-PnP",
    "security": {
      "user_id": ""
    },
    "task": 0,
    "time_created": "2026-07-21 22:20:40.690Z",
    "version": 0
  },
  "event_data": {
    "QueryAddress": "0xFFFFC807B7DC3910"
  },
  "message": ""
}

Event ID 503: DevQuery_QueryProcessing

#
Channel
Operational
Also via
realtime ETW trace
Level
Informational
Task
DevQuery_QueryProcessing
Opcode
QueryStop

Fields #

NameDescription
QueryAddress Pointer

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Kernel-PnP",
    "guid": "{9C205A39-1250-487D-ABD7-E831C6290539}",
    "event_source_name": "",
    "event_id": 503,
    "version": 0,
    "level": 4,
    "task": 500,
    "opcode": 11,
    "keywords": "0x0000000001200000",
    "time_created": "2026-06-02T05:27:16.407+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{877F78A1-F053-0002-0E59-828753F0DC01}"
    },
    "execution": {
      "process_id": 16540,
      "thread_id": 17996
    },
    "channel": "ETW Trace",
    "computer": "JD-DC01-2022",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "QueryAddress": "0xFFFF878DC7348210"
  },
  "message": "DevQuery_QueryProcessing"
}

Event ID 600: A start type override of StartType was set for driver Driver in hardware configuration HardwareConfigurationId.

#
Channel
Driver Diagnostic
Task
DriverOverride

Message #

A start type override of %3 was set for driver %2 in hardware configuration %1

Fields #

NameDescription
HardwareConfigurationId HexInt32
Driver UnicodeString
StartType HexInt32
Known values
0
Boot
1
System
2
Automatic
3
Manual
4
Disabled

Event ID 700: CfgMgr_DeviceList

#
Channel
Operational
Also via
realtime ETW trace
Level
Informational
Task
CfgMgr_DeviceList
Opcode
Start

Fields #

NameDescription
Filter UnicodeString
FilterBy UnicodeString
OnlyPresent Boolean

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Kernel-PnP",
    "guid": "{9C205A39-1250-487D-ABD7-E831C6290539}",
    "event_source_name": "",
    "event_id": 700,
    "version": 0,
    "level": 4,
    "task": 700,
    "opcode": 1,
    "keywords": "0x0000000001400000",
    "time_created": "2026-06-02T05:27:15.299+00:00",
    "event_record_id": 0,
    "correlation": {},
    "execution": {
      "process_id": 4028,
      "thread_id": 17828
    },
    "channel": "ETW Trace",
    "computer": "JD-DC01-2022",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Filter": "{6bdd1fc5-810f-11d0-bec7-08002be2092f}",
    "FilterBy": "Class",
    "OnlyPresent": true
  },
  "message": "CfgMgr_DeviceList"
}

Event ID 701: CfgMgr_DeviceList

#
Channel
Operational
Also via
realtime ETW trace
Level
Informational
Task
CfgMgr_DeviceList
Opcode
Stop

Fields #

NameDescription
Result HexInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Kernel-PnP",
    "guid": "{9C205A39-1250-487D-ABD7-E831C6290539}",
    "event_source_name": "",
    "event_id": 701,
    "version": 0,
    "level": 4,
    "task": 700,
    "opcode": 2,
    "keywords": "0x0000000001400000",
    "time_created": "2026-06-02T05:27:15.299+00:00",
    "event_record_id": 0,
    "correlation": {},
    "execution": {
      "process_id": 4028,
      "thread_id": 17828
    },
    "channel": "ETW Trace",
    "computer": "JD-DC01-2022",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Result": "00000000"
  },
  "message": "CfgMgr_DeviceList"
}

Event ID 702: CfgMgr_DeviceInterfaceList

#
Channel
Operational
Also via
realtime ETW trace
Level
Informational
Task
CfgMgr_DeviceInterfaceList
Opcode
Start

Fields #

NameDescription
Class GUID
Device UnicodeString
OnlyPresent Boolean

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Kernel-PnP",
    "guid": "{9C205A39-1250-487D-ABD7-E831C6290539}",
    "event_source_name": "",
    "event_id": 702,
    "version": 0,
    "level": 4,
    "task": 702,
    "opcode": 1,
    "keywords": "0x0000000001400000",
    "time_created": "2026-06-02T05:27:15.469+00:00",
    "event_record_id": 0,
    "correlation": {},
    "execution": {
      "process_id": 11204,
      "thread_id": 17268
    },
    "channel": "ETW Trace",
    "computer": "JD-DC01-2022",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Class": "{53F5630D-B6BF-11D0-94F2-00A0C91EFB8B}",
    "Device": "NULL",
    "OnlyPresent": false
  },
  "message": "CfgMgr_DeviceInterfaceList"
}

Event ID 703: CfgMgr_DeviceInterfaceList

#
Channel
Operational
Also via
realtime ETW trace
Level
Informational
Task
CfgMgr_DeviceInterfaceList
Opcode
Stop

Fields #

NameDescription
Result HexInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Kernel-PnP",
    "guid": "{9C205A39-1250-487D-ABD7-E831C6290539}",
    "event_source_name": "",
    "event_id": 703,
    "version": 0,
    "level": 4,
    "task": 702,
    "opcode": 2,
    "keywords": "0x0000000001400000",
    "time_created": "2026-06-02T05:27:15.469+00:00",
    "event_record_id": 0,
    "correlation": {},
    "execution": {
      "process_id": 11204,
      "thread_id": 17268
    },
    "channel": "ETW Trace",
    "computer": "JD-DC01-2022",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Result": "00000000"
  },
  "message": "CfgMgr_DeviceInterfaceList"
}

Event ID 704: CfgMgr_QueryRemoveStart

#
Channel
Operational
Level
Informational
Task
CfgMgr_QueryRemove
Opcode
Start

Fields #

NameDescription
QueryRemoveType HexInt32
Device UnicodeString

Example Event #

{
  "system": {
    "channel": "Microsoft-Windows-Kernel-PnP/Operational",
    "computer": "10.2.10.21",
    "correlation": {},
    "event_id": 704,
    "event_record_id": 0,
    "event_source_name": "",
    "execution": {
      "process_id": 3908,
      "thread_id": 10692
    },
    "guid": "",
    "keywords": 0,
    "level": 4,
    "opcode": 1,
    "provider": "Microsoft-Windows-Kernel-PnP",
    "security": {
      "user_id": ""
    },
    "task": 0,
    "time_created": "2026-07-21 22:20:40.695Z",
    "version": 0
  },
  "event_data": {
    "Device": "ROOT\\VMS_VSMP\\0001",
    "QueryRemoveType": "01000000"
  },
  "message": ""
}

Event ID 705: CfgMgr_QueryRemoveStop

#
Channel
Operational
Level
Informational
Task
CfgMgr_QueryRemove
Opcode
Stop

Fields #

NameDescription
Device UnicodeString

Example Event #

{
  "system": {
    "channel": "Microsoft-Windows-Kernel-PnP/Operational",
    "computer": "10.2.10.21",
    "correlation": {},
    "event_id": 705,
    "event_record_id": 0,
    "event_source_name": "",
    "execution": {
      "process_id": 3908,
      "thread_id": 10692
    },
    "guid": "",
    "keywords": 0,
    "level": 4,
    "opcode": 2,
    "provider": "Microsoft-Windows-Kernel-PnP",
    "security": {
      "user_id": ""
    },
    "task": 0,
    "time_created": "2026-07-21 22:20:40.696Z",
    "version": 0
  },
  "event_data": {
    "Device": "ROOT\\VMS_VSMP\\0001"
  },
  "message": ""
}

Event ID 800: Begin processing new device (DeviceNode).

#
Channel
Device Enumeration Diagnostic
Level
Informational
Task
ProcessNewDevice
Opcode
Start

Message #

Begin processing new device (%1)

Fields #

NameDescription
DeviceNode Pointer

Example Event #

{
  "system": {
    "channel": "Microsoft-Windows-Kernel-PnP/Device Enumeration Diagnostic",
    "computer": "10.2.10.21",
    "correlation": {},
    "event_id": 800,
    "event_record_id": 0,
    "event_source_name": "",
    "execution": {
      "process_id": 4,
      "thread_id": 11360
    },
    "guid": "",
    "keywords": 0,
    "level": 4,
    "opcode": 1,
    "provider": "Microsoft-Windows-Kernel-PnP",
    "security": {
      "user_id": ""
    },
    "task": 0,
    "time_created": "2026-07-21 22:20:40.696Z",
    "version": 0
  },
  "event_data": {
    "DeviceNode": "0xFFFFC807B8F84320"
  },
  "message": ""
}

Event ID 801: Processing device DeviceInstancePath (DeviceNode).

#
Channel
Device Enumeration Diagnostic
Level
Informational
Task
ProcessNewDevice

Message #

Processing device %2 (%1)

Fields #

NameDescription
DeviceNode Pointer
DeviceInstancePath UnicodeString
ParentDeviceInstancePath UnicodeString

Example Event #

{
  "system": {
    "channel": "Microsoft-Windows-Kernel-PnP/Device Enumeration Diagnostic",
    "computer": "10.2.10.21",
    "correlation": {},
    "event_id": 801,
    "event_record_id": 0,
    "event_source_name": "",
    "execution": {
      "process_id": 4,
      "thread_id": 11360
    },
    "guid": "",
    "keywords": 0,
    "level": 4,
    "opcode": 0,
    "provider": "Microsoft-Windows-Kernel-PnP",
    "security": {
      "user_id": ""
    },
    "task": 0,
    "time_created": "2026-07-21 22:20:40.696Z",
    "version": 0
  },
  "event_data": {
    "DeviceInstancePath": "ROOT\\VMS_VSMP\\0001",
    "DeviceNode": "0xFFFFC807B8F84320"
  },
  "message": ""
}

Event ID 802: End processing new device (DeviceNode).

#
Channel
Device Enumeration Diagnostic
Level
Informational
Task
ProcessNewDevice
Opcode
Stop

Message #

End processing new device (%1)

Fields #

NameDescription
DeviceNode Pointer

Example Event #

{
  "system": {
    "channel": "Microsoft-Windows-Kernel-PnP/Device Enumeration Diagnostic",
    "computer": "10.2.10.21",
    "correlation": {},
    "event_id": 802,
    "event_record_id": 0,
    "event_source_name": "",
    "execution": {
      "process_id": 4,
      "thread_id": 11360
    },
    "guid": "",
    "keywords": 0,
    "level": 4,
    "opcode": 2,
    "provider": "Microsoft-Windows-Kernel-PnP",
    "security": {
      "user_id": ""
    },
    "task": 0,
    "time_created": "2026-07-21 22:20:40.717Z",
    "version": 0
  },
  "event_data": {
    "DeviceNode": "0xFFFFC807B8F84320"
  },
  "message": ""
}

Event ID 803: Begin processing phase Phase of starting device Device.

#
Channel
Operational
Level
Informational
Task
ProcessDeviceStart
Opcode
Start

Message #

Begin processing phase %1 of starting device %2

Fields #

NameDescription
Phase HexInt32
Device UnicodeString

Example Event #

{
  "system": {
    "channel": "Microsoft-Windows-Kernel-PnP/Operational",
    "computer": "10.2.10.21",
    "correlation": {},
    "event_id": 803,
    "event_record_id": 0,
    "event_source_name": "",
    "execution": {
      "process_id": 4,
      "thread_id": 11848
    },
    "guid": "",
    "keywords": 0,
    "level": 4,
    "opcode": 1,
    "provider": "Microsoft-Windows-Kernel-PnP",
    "security": {
      "user_id": ""
    },
    "task": 0,
    "time_created": "2026-07-21 22:20:40.847Z",
    "version": 0
  },
  "event_data": {
    "Device": "ROOT\\VMS_VSMP\\0001",
    "Phase": "01000000"
  },
  "message": ""
}

Event ID 804: End processing phase Phase of starting device Device.

#
Channel
Operational
Level
Informational
Task
ProcessDeviceStart
Opcode
Stop

Message #

End processing phase %1 of starting device %2

Fields #

NameDescription
Phase HexInt32
Device UnicodeString

Example Event #

{
  "system": {
    "channel": "Microsoft-Windows-Kernel-PnP/Operational",
    "computer": "10.2.10.21",
    "correlation": {},
    "event_id": 804,
    "event_record_id": 0,
    "event_source_name": "",
    "execution": {
      "process_id": 4,
      "thread_id": 11848
    },
    "guid": "",
    "keywords": 0,
    "level": 4,
    "opcode": 2,
    "provider": "Microsoft-Windows-Kernel-PnP",
    "security": {
      "user_id": ""
    },
    "task": 0,
    "time_created": "2026-07-21 22:20:40.847Z",
    "version": 0
  },
  "event_data": {
    "Device": "ROOT\\VMS_VSMP\\0001",
    "Phase": "01000000"
  },
  "message": ""
}

Event ID 805: Begin processing phase Phase of restarting device Device.

#
Channel
Operational
Task
ProcessDeviceRestart
Opcode
Start

Message #

Begin processing phase %1 of restarting device %2

Fields #

NameDescription
Phase HexInt32
Device UnicodeString

Event ID 806: End processing phase Phase of restarting device Device.

#
Channel
Operational
Task
ProcessDeviceRestart
Opcode
Stop

Message #

End processing phase %1 of restarting device %2

Fields #

NameDescription
Phase HexInt32
Device UnicodeString

Event ID 807: Begin device add operation for driver DriverName, device DeviceInstancePath.

#
Channel
Device Enumeration Diagnostic
Level
Informational
Task
DeviceAdd
Opcode
Start

Message #

Begin device add operation for driver %3, device %4

Fields #

NameDescription
ServiceType UInt32
Known values
1
Kernel Driver
2
File System Driver
4
Adapter
8
Recognizer Driver
16
Own Process
32
Share Process
256
Interactive
DriverNameLength UInt16
DriverName UnicodeString
DeviceInstancePath UnicodeString

Example Event #

{
  "system": {
    "channel": "Microsoft-Windows-Kernel-PnP/Device Enumeration Diagnostic",
    "computer": "10.2.10.21",
    "correlation": {},
    "event_id": 807,
    "event_record_id": 0,
    "event_source_name": "",
    "execution": {
      "process_id": 4,
      "thread_id": 11848
    },
    "guid": "",
    "keywords": 0,
    "level": 4,
    "opcode": 1,
    "provider": "Microsoft-Windows-Kernel-PnP",
    "security": {
      "user_id": ""
    },
    "task": 0,
    "time_created": "2026-07-21 22:20:40.840Z",
    "version": 0
  },
  "event_data": {
    "DeviceInstancePath": "ROOT\\VMS_VSMP\\0001",
    "DriverName": "\\Driver\\VMSP",
    "DriverNameLength": 12,
    "ServiceType": 3
  },
  "message": ""
}

Event ID 808: End device add, status (Status).

#
Channel
Device Enumeration Diagnostic
Level
Informational
Task
DeviceAdd
Opcode
Stop

Message #

End device add, status (%1)

Fields #

NameDescription
Status UInt32NTSTATUS reference

Example Event #

{
  "system": {
    "channel": "Microsoft-Windows-Kernel-PnP/Device Enumeration Diagnostic",
    "computer": "10.2.10.21",
    "correlation": {},
    "event_id": 808,
    "event_record_id": 0,
    "event_source_name": "",
    "execution": {
      "process_id": 4,
      "thread_id": 11848
    },
    "guid": "",
    "keywords": 0,
    "level": 4,
    "opcode": 2,
    "provider": "Microsoft-Windows-Kernel-PnP",
    "security": {
      "user_id": ""
    },
    "task": 0,
    "time_created": "2026-07-21 22:20:40.847Z",
    "version": 0
  },
  "event_data": {
    "Status": 0
  },
  "message": ""
}

Event ID 809: Duplicate device instance reported by BusId and DeviceId.

#
Channel
Device Management
Opcode
Info

Message #

Duplicate device instance reported by %4 and %5.
Bus ID: %1
Device ID: %2
Instance ID: %3

Fields #

NameDescription
BusId UnicodeString
DeviceId UnicodeString
InstanceId UnicodeString
PreviousParent UnicodeString
CurrentParent UnicodeString

Event ID 810: Reenumeration of device tree below Device has been queued.

#
Channel
Device Enumeration Diagnostic
Level
Informational
Task
ReenumerateDeviceTree

Message #

Reenumeration of device tree below %1 has been queued.

Fields #

NameDescription
Device UnicodeString
ReenumerateType HexInt32

Example Event #

{
  "system": {
    "channel": "Microsoft-Windows-Kernel-PnP/Device Enumeration Diagnostic",
    "computer": "10.2.10.21",
    "correlation": {},
    "event_id": 810,
    "event_record_id": 0,
    "event_source_name": "",
    "execution": {
      "process_id": 5792,
      "thread_id": 11556
    },
    "guid": "",
    "keywords": 0,
    "level": 4,
    "opcode": 0,
    "provider": "Microsoft-Windows-Kernel-PnP",
    "security": {
      "user_id": ""
    },
    "task": 0,
    "time_created": "2026-07-22 05:46:25.806Z",
    "version": 0
  },
  "event_data": {
    "Device": "HTREE\\ROOT\\0",
    "ReenumerateType": "09000000"
  },
  "message": ""
}

Event ID 811: Begin reenumeration of device tree below Device.

#
Channel
Device Enumeration Diagnostic
Level
Informational
Task
ReenumerateDeviceTree
Opcode
Start

Message #

Begin reenumeration of device tree below %1.

Fields #

NameDescription
Device UnicodeString
ReenumerateType HexInt32

Example Event #

{
  "system": {
    "channel": "Microsoft-Windows-Kernel-PnP/Device Enumeration Diagnostic",
    "computer": "10.2.10.21",
    "correlation": {},
    "event_id": 811,
    "event_record_id": 0,
    "event_source_name": "",
    "execution": {
      "process_id": 4,
      "thread_id": 2144
    },
    "guid": "",
    "keywords": 0,
    "level": 4,
    "opcode": 1,
    "provider": "Microsoft-Windows-Kernel-PnP",
    "security": {
      "user_id": ""
    },
    "task": 0,
    "time_created": "2026-07-22 05:46:25.807Z",
    "version": 0
  },
  "event_data": {
    "Device": "HTREE\\ROOT\\0",
    "ReenumerateType": "09000000"
  },
  "message": ""
}

Event ID 812: End reenumeration of device tree below Device.

#
Channel
Device Enumeration Diagnostic
Level
Informational
Task
ReenumerateDeviceTree
Opcode
Stop

Message #

End reenumeration of device tree below %1.

Fields #

NameDescription
Device UnicodeString
ReenumerateType HexInt32

Example Event #

{
  "system": {
    "channel": "Microsoft-Windows-Kernel-PnP/Device Enumeration Diagnostic",
    "computer": "10.2.10.21",
    "correlation": {},
    "event_id": 812,
    "event_record_id": 0,
    "event_source_name": "",
    "execution": {
      "process_id": 4,
      "thread_id": 2144
    },
    "guid": "",
    "keywords": 0,
    "level": 4,
    "opcode": 2,
    "provider": "Microsoft-Windows-Kernel-PnP",
    "security": {
      "user_id": ""
    },
    "task": 0,
    "time_created": "2026-07-22 05:46:26.304Z",
    "version": 0
  },
  "event_data": {
    "Device": "HTREE\\ROOT\\0",
    "ReenumerateType": "09000000"
  },
  "message": ""
}

Event ID 813: Reenumeration of Device has been queued.

#
Channel
Device Enumeration Diagnostic
Level
Informational
Task
ReenumerateDeviceOnly

Message #

Reenumeration of %1 has been queued.

Fields #

NameDescription
Device UnicodeString

Example Event #

{
  "system": {
    "channel": "Microsoft-Windows-Kernel-PnP/Device Enumeration Diagnostic",
    "computer": "10.2.10.21",
    "correlation": {},
    "event_id": 813,
    "event_record_id": 0,
    "event_source_name": "",
    "execution": {
      "process_id": 4,
      "thread_id": 9900
    },
    "guid": "",
    "keywords": 0,
    "level": 4,
    "opcode": 0,
    "provider": "Microsoft-Windows-Kernel-PnP",
    "security": {
      "user_id": ""
    },
    "task": 0,
    "time_created": "2026-07-21 22:20:40.718Z",
    "version": 0
  },
  "event_data": {
    "Device": "HTREE\\ROOT\\0"
  },
  "message": ""
}

Event ID 814: Begin reenumeration of Device.

#
Channel
Device Enumeration Diagnostic
Level
Informational
Task
ReenumerateDeviceOnly
Opcode
Start

Message #

Begin reenumeration of %1.

Fields #

NameDescription
Device UnicodeString

Example Event #

{
  "system": {
    "channel": "Microsoft-Windows-Kernel-PnP/Device Enumeration Diagnostic",
    "computer": "10.2.10.21",
    "correlation": {},
    "event_id": 814,
    "event_record_id": 0,
    "event_source_name": "",
    "execution": {
      "process_id": 4,
      "thread_id": 11360
    },
    "guid": "",
    "keywords": 0,
    "level": 4,
    "opcode": 1,
    "provider": "Microsoft-Windows-Kernel-PnP",
    "security": {
      "user_id": ""
    },
    "task": 0,
    "time_created": "2026-07-21 22:20:40.718Z",
    "version": 0
  },
  "event_data": {
    "Device": "HTREE\\ROOT\\0"
  },
  "message": ""
}

Event ID 815: End reenumeration of Device.

#
Channel
Device Enumeration Diagnostic
Level
Informational
Task
ReenumerateDeviceOnly
Opcode
Stop

Message #

End reenumeration of %1.

Fields #

NameDescription
Device UnicodeString

Example Event #

{
  "system": {
    "channel": "Microsoft-Windows-Kernel-PnP/Device Enumeration Diagnostic",
    "computer": "10.2.10.21",
    "correlation": {},
    "event_id": 815,
    "event_record_id": 0,
    "event_source_name": "",
    "execution": {
      "process_id": 4,
      "thread_id": 11360
    },
    "guid": "",
    "keywords": 0,
    "level": 4,
    "opcode": 2,
    "provider": "Microsoft-Windows-Kernel-PnP",
    "security": {
      "user_id": ""
    },
    "task": 0,
    "time_created": "2026-07-21 22:20:40.719Z",
    "version": 0
  },
  "event_data": {
    "Device": "HTREE\\ROOT\\0"
  },
  "message": ""
}

Event ID 816: Configuration of device Device for configuration type RequestType has been queued.

#
Channel
Configuration Diagnostic
Task
ConfigureDevice

Message #

Configuration of device %1 for configuration type %2 has been queued.

Fields #

NameDescription
Device UnicodeString
RequestType HexInt32

Event ID 817: Begin configuration of device Device for configuration type RequestType.

#
Channel
Configuration Diagnostic
Task
ConfigureDevice
Opcode
Start

Message #

Begin configuration of device %1 for configuration type %2.

Fields #

NameDescription
Device UnicodeString
RequestType HexInt32

Event ID 818: End configuration of device Device for configuration type RequestType.

#
Channel
Configuration Diagnostic
Task
ConfigureDevice
Opcode
Stop

Description

End configuration of device Device for configuration type RequestType. Result is Status.

Message #

End configuration of device %1 for configuration type %2. Result is %3

Fields #

NameDescription
Device UnicodeString
RequestType HexInt32
Status UInt32NTSTATUS reference

Event ID 819: GenericDeviceAction

#
Channel
Operational
Level
Informational
Task
GenericDeviceAction

Fields #

NameDescription
Device UnicodeString
RequestType HexInt32

Example Event #

{
  "system": {
    "channel": "Microsoft-Windows-Kernel-PnP/Operational",
    "computer": "10.2.10.21",
    "correlation": {},
    "event_id": 819,
    "event_record_id": 0,
    "event_source_name": "",
    "execution": {
      "process_id": 3908,
      "thread_id": 10692
    },
    "guid": "",
    "keywords": 0,
    "level": 4,
    "opcode": 0,
    "provider": "Microsoft-Windows-Kernel-PnP",
    "security": {
      "user_id": ""
    },
    "task": 0,
    "time_created": "2026-07-21 22:20:40.696Z",
    "version": 0
  },
  "event_data": {
    "Device": "ROOT\\VMS_VSMP\\0001",
    "RequestType": "10000000"
  },
  "message": ""
}

Event ID 820: GenericDeviceActionStart

#
Channel
Operational
Level
Informational
Task
GenericDeviceAction
Opcode
Start

Fields #

NameDescription
Device UnicodeString
RequestType HexInt32

Example Event #

{
  "system": {
    "channel": "Microsoft-Windows-Kernel-PnP/Operational",
    "computer": "10.2.10.21",
    "correlation": {},
    "event_id": 820,
    "event_record_id": 0,
    "event_source_name": "",
    "execution": {
      "process_id": 4,
      "thread_id": 11360
    },
    "guid": "",
    "keywords": 0,
    "level": 4,
    "opcode": 1,
    "provider": "Microsoft-Windows-Kernel-PnP",
    "security": {
      "user_id": ""
    },
    "task": 0,
    "time_created": "2026-07-21 22:20:40.696Z",
    "version": 0
  },
  "event_data": {
    "Device": "ROOT\\VMS_VSMP\\0001",
    "RequestType": "10000000"
  },
  "message": ""
}

Event ID 821: GenericDeviceActionStop

#
Channel
Operational
Level
Informational
Task
GenericDeviceAction
Opcode
Stop

Fields #

NameDescription
Device UnicodeString
RequestType HexInt32
Status UInt32NTSTATUS reference

Example Event #

{
  "system": {
    "channel": "Microsoft-Windows-Kernel-PnP/Operational",
    "computer": "10.2.10.21",
    "correlation": {},
    "event_id": 821,
    "event_record_id": 0,
    "event_source_name": "",
    "execution": {
      "process_id": 4,
      "thread_id": 11360
    },
    "guid": "",
    "keywords": 0,
    "level": 4,
    "opcode": 2,
    "provider": "Microsoft-Windows-Kernel-PnP",
    "security": {
      "user_id": ""
    },
    "task": 0,
    "time_created": "2026-07-21 22:20:40.718Z",
    "version": 0
  },
  "event_data": {
    "Device": "ROOT\\VMS_VSMP\\0001",
    "RequestType": "10000000",
    "Status": 0
  },
  "message": ""
}

Event ID 830: Removal of Device has been queued.

#
Channel
Device Enumeration Diagnostic
Level
Informational
Task
DeviceRemoval

Message #

Removal of %1 has been queued.

Fields #

NameDescription
Device UnicodeString
EventGuid GUID
ProblemCode UInt32
ProblemStatus HexInt32
Synchronous Boolean
Flags HexInt32

Example Event #

{
  "system": {
    "channel": "Microsoft-Windows-Kernel-PnP/Device Enumeration Diagnostic",
    "computer": "10.2.10.21",
    "correlation": {},
    "event_id": 830,
    "event_record_id": 0,
    "event_source_name": "",
    "execution": {
      "process_id": 3908,
      "thread_id": 10692
    },
    "guid": "",
    "keywords": 0,
    "level": 4,
    "opcode": 0,
    "provider": "Microsoft-Windows-Kernel-PnP",
    "security": {
      "user_id": ""
    },
    "task": 0,
    "time_created": "2026-07-21 22:20:40.695Z",
    "version": 0
  },
  "event_data": {
    "Device": "ROOT\\VMS_VSMP\\0001"
  },
  "message": ""
}

Event ID 831: Begin removal of Device.

#
Channel
Device Enumeration Diagnostic
Level
Informational
Task
DeviceRemoval
Opcode
Start

Message #

Begin removal of %1.

Fields #

NameDescription
Device UnicodeString

Example Event #

{
  "system": {
    "channel": "Microsoft-Windows-Kernel-PnP/Device Enumeration Diagnostic",
    "computer": "10.2.10.21",
    "correlation": {},
    "event_id": 831,
    "event_record_id": 0,
    "event_source_name": "",
    "execution": {
      "process_id": 4,
      "thread_id": 11848
    },
    "guid": "",
    "keywords": 0,
    "level": 4,
    "opcode": 1,
    "provider": "Microsoft-Windows-Kernel-PnP",
    "security": {
      "user_id": ""
    },
    "task": 0,
    "time_created": "2026-07-21 22:20:40.695Z",
    "version": 0
  },
  "event_data": {
    "Device": "ROOT\\VMS_VSMP\\0001"
  },
  "message": ""
}

Event ID 832: End removal of Device.

#
Channel
Device Enumeration Diagnostic
Level
Informational
Task
DeviceRemoval
Opcode
Stop

Message #

End removal of %1.

Fields #

NameDescription
Device UnicodeString

Example Event #

{
  "system": {
    "channel": "Microsoft-Windows-Kernel-PnP/Device Enumeration Diagnostic",
    "computer": "10.2.10.21",
    "correlation": {},
    "event_id": 832,
    "event_record_id": 0,
    "event_source_name": "",
    "execution": {
      "process_id": 4,
      "thread_id": 11848
    },
    "guid": "",
    "keywords": 0,
    "level": 4,
    "opcode": 2,
    "provider": "Microsoft-Windows-Kernel-PnP",
    "security": {
      "user_id": ""
    },
    "task": 0,
    "time_created": "2026-07-21 22:20:40.695Z",
    "version": 0
  },
  "event_data": {
    "Device": "ROOT\\VMS_VSMP\\0001"
  },
  "message": ""
}

Event ID 840: Begin resetting device DeviceInstance.

#
Channel
Device Enumeration Diagnostic
Opcode
Start

Message #

Begin resetting device %2.

Fields #

NameDescription
DeviceInstanceLength UInt16
DeviceInstance UnicodeString

Event ID 841: End resetting device DeviceInstance with status Status, veto type VetoType, veto name VetoName.

#
Channel
Device Enumeration Diagnostic
Opcode
Stop

Message #

End resetting device %2 with status %3, veto type %4, veto name %6.

Fields #

NameDescription
DeviceInstanceLength UInt16
DeviceInstance UnicodeString
Status UInt32NTSTATUS reference
VetoType UInt32
VetoNameLength UInt16
VetoName UnicodeString

Event ID 850: Begin assigning resources to device tree below Device.

#
Channel
Device Enumeration Diagnostic
Level
Informational
Task
AssignResources
Opcode
Start

Message #

Begin assigning resources to device tree below %1.

Fields #

NameDescription
Device UnicodeString

Example Event #

{
  "system": {
    "channel": "Microsoft-Windows-Kernel-PnP/Device Enumeration Diagnostic",
    "computer": "10.2.10.21",
    "correlation": {},
    "event_id": 850,
    "event_record_id": 0,
    "event_source_name": "",
    "execution": {
      "process_id": 4,
      "thread_id": 11360
    },
    "guid": "",
    "keywords": 0,
    "level": 4,
    "opcode": 1,
    "provider": "Microsoft-Windows-Kernel-PnP",
    "security": {
      "user_id": ""
    },
    "task": 0,
    "time_created": "2026-07-21 22:20:40.696Z",
    "version": 0
  },
  "event_data": {
    "Device": "ROOT\\VMS_VSMP\\0001"
  },
  "message": ""
}

Event ID 851: End assigning resources to device tree below Device.

#
Channel
Device Enumeration Diagnostic
Level
Informational
Task
AssignResources
Opcode
Stop

Message #

End assigning resources to device tree below %1.

Fields #

NameDescription
Device UnicodeString

Example Event #

{
  "system": {
    "channel": "Microsoft-Windows-Kernel-PnP/Device Enumeration Diagnostic",
    "computer": "10.2.10.21",
    "correlation": {},
    "event_id": 851,
    "event_record_id": 0,
    "event_source_name": "",
    "execution": {
      "process_id": 4,
      "thread_id": 11360
    },
    "guid": "",
    "keywords": 0,
    "level": 4,
    "opcode": 2,
    "provider": "Microsoft-Windows-Kernel-PnP",
    "security": {
      "user_id": ""
    },
    "task": 0,
    "time_created": "2026-07-21 22:20:40.696Z",
    "version": 0
  },
  "event_data": {
    "Device": "ROOT\\VMS_VSMP\\0001"
  },
  "message": ""
}

Event ID 852: Begin rebalancing resources for device DeviceInstance.

#
Channel
Device Enumeration Diagnostic
Task
Rebalance
Opcode
Start

Message #

Begin rebalancing resources for device %2.

Fields #

NameDescription
DeviceInstanceLength UInt16
DeviceInstance UnicodeString

Event ID 853: End rebalancing resources for device DeviceInstance.

#
Channel
Device Enumeration Diagnostic
Task
Rebalance
Opcode
Stop

Message #

End rebalancing resources for device %2.

Fields #

NameDescription
DeviceInstanceLength UInt16
DeviceInstance UnicodeString
Status UInt32NTSTATUS reference

Event ID 860: Updated problem code on device DeviceInstanceId.

#
Channel
Operational
Task
ProblemCode

Message #

Updated problem code on device %2.
Service name: %3
New problem code: %4
New problem status: %5
Old problem code: %6
Old problem status: %7

Fields #

NameDescription
DeviceNode Pointer
DeviceInstanceId UnicodeString
ServiceName UnicodeString
NewProblemCode UInt32
NewProblemStatus HexInt32
OldProblemCode UInt32
OldProblemStatus HexInt32

Event ID 900: A long running thread for the device event queue was detected.

#
Channel
Driver Watchdog
Level
Warning
Task
WatchdogTriggered
Opcode
Start

Description

A long running thread for the device event queue was detected. The thread has been running for ThreadId milliseconds.

Message #

A long running thread for the device event queue was detected. The thread has been running for %4 milliseconds.
Thread ID: %1
Device: %2
Service: %3

Fields #

NameDescription
ThreadId HexInt64
DeviceInstanceId UnicodeString
ServiceName UnicodeString
ElapsedTimeMs UInt64
EventCategory UInt32
EventGuid GUID
EventArgument HexInt32
EventArgumentStatus HexInt32
CategorySpecificData_Guid GUID
CategorySpecificData_String UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Kernel-PnP",
    "guid": "{9C205A39-1250-487D-ABD7-E831C6290539}",
    "event_source_name": "",
    "event_id": 900,
    "version": 1,
    "level": 3,
    "task": 900,
    "opcode": 1,
    "keywords": 144115188075855872,
    "time_created": "2026-05-30T02:07:59.6698259+00:00",
    "event_record_id": 3,
    "correlation": {},
    "execution": {
      "process_id": 4,
      "thread_id": 424
    },
    "channel": "Microsoft-Windows-Kernel-PnP/Driver Watchdog",
    "computer": "WIN11-25H2-X64",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "ThreadId": "0x108",
    "DeviceInstanceId": "",
    "ServiceName": "",
    "ElapsedTimeMs": "3003",
    "EventCategory": "2",
    "EventGuid": "{cb3a4004-46f0-11d0-b08f-00609713053f}",
    "EventArgument": "0x0",
    "EventArgumentStatus": "0x0",
    "CategorySpecificData_Guid": "{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}",
    "CategorySpecificData_String": "\\??\\STORAGE#Volume#{4769a76b-3ac5-11f1-a6b7-806e6f6e6963}#0000000021100000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}"
  },
  "message": "A long running thread for the device event queue was detected. The thread has been running for 3003 milliseconds.\r\nThread ID: 0x108\r\nDevice: \r\nService: \r\nEvent Category: 2\r\nEvent GUID: {cb3a4004-46f0-11d0-b08f-00609713053f}\r\nEvent Argument: 0x0\r\nArgument Status: 0x0\r\nCategory Specific Data:\r\n{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\r\n\\??\\STORAGE#Volume#{4769a76b-3ac5-11f1-a6b7-806e6f6e6963}#0000000021100000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}"
}

Event ID 901: A long running thread for the device event queue has been completed.

#
Channel
Driver Watchdog
Level
Informational
Task
WatchdogTriggered
Opcode
Stop

Message #

A long running thread for the device event queue has been completed.
Thread ID: %1
Device: %2
Service: %3
Total run time in milliseconds: %4

Fields #

NameDescription
ThreadId HexInt64
DeviceInstanceId UnicodeString
ServiceName UnicodeString
ElapsedTimeMs UInt64
EventCategory UInt32
EventGuid GUID
EventArgument HexInt32
EventArgumentStatus HexInt32
CategorySpecificData_Guid GUID
CategorySpecificData_String UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Kernel-PnP",
    "guid": "{9C205A39-1250-487D-ABD7-E831C6290539}",
    "event_source_name": "",
    "event_id": 901,
    "version": 1,
    "level": 4,
    "task": 900,
    "opcode": 2,
    "keywords": 144115188075855872,
    "time_created": "2026-05-30T02:07:59.7719600+00:00",
    "event_record_id": 4,
    "correlation": {},
    "execution": {
      "process_id": 4,
      "thread_id": 264
    },
    "channel": "Microsoft-Windows-Kernel-PnP/Driver Watchdog",
    "computer": "WIN11-25H2-X64",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "ThreadId": "0x108",
    "DeviceInstanceId": "",
    "ServiceName": "",
    "ElapsedTimeMs": "3105",
    "EventCategory": "2",
    "EventGuid": "{cb3a4004-46f0-11d0-b08f-00609713053f}",
    "EventArgument": "0x0",
    "EventArgumentStatus": "0x0",
    "CategorySpecificData_Guid": "{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}",
    "CategorySpecificData_String": "\\??\\STORAGE#Volume#{4769a76b-3ac5-11f1-a6b7-806e6f6e6963}#0000000021100000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}"
  },
  "message": "A long running thread for the device event queue has been completed.\r\nThread ID: 0x108\r\nDevice: \r\nService: \r\nEvent Category: 2\r\nEvent GUID: {cb3a4004-46f0-11d0-b08f-00609713053f}\r\nEvent Argument: 0x0\r\nArgument Status: 0x0\r\nCategory Specific Data:\r\n{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\r\n\\??\\STORAGE#Volume#{4769a76b-3ac5-11f1-a6b7-806e6f6e6963}#0000000021100000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\r\n\r\nTotal run time in milliseconds: 3105"
}

Event ID 902: A long running thread for device start processing was detected.

#
Channel
Driver Watchdog
Level
Warning
Task
WatchdogTriggered
Opcode
Start

Description

A long running thread for device start processing was detected. The thread has been running for ThreadId milliseconds.

Message #

A long running thread for device start processing was detected. The thread has been running for %4 milliseconds.
Thread ID: %1
Device: %2
Service: %3

Fields #

NameDescription
ThreadId HexInt64
DeviceInstanceId UnicodeString
ServiceName UnicodeString
ElapsedTimeMs UInt64

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Kernel-PnP",
    "event_id": 902,
    "level": 3,
    "task": 900,
    "opcode": 1,
    "time_created": "2026-04-18T00:24:03.8885756+00:00",
    "computer": "USERUSE-I0E7KUG",
    "channel": "Microsoft-Windows-Kernel-PnP"
  },
  "event_data": {
    "ThreadId": "0x8",
    "DeviceInstanceId": "PCIIDE\\IDEChannel\\4&403bef5&0&1",
    "ElapsedTimeMs": "3001",
    "ServiceName": "atapi"
  }
}

Event ID 903: A long running thread for device start processing has been completed.

#
Channel
Driver Watchdog
Level
Informational
Task
WatchdogTriggered
Opcode
Stop

Message #

A long running thread for device start processing has been completed.
Thread ID: %1
Device: %2
Service: %3
Total run time in milliseconds: %4

Fields #

NameDescription
ThreadId HexInt64
DeviceInstanceId UnicodeString
ServiceName UnicodeString
ElapsedTimeMs UInt64

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Kernel-PnP",
    "event_id": 903,
    "level": 4,
    "task": 900,
    "opcode": 2,
    "time_created": "2026-04-18T00:24:03.8892545+00:00",
    "computer": "USERUSE-I0E7KUG",
    "channel": "Microsoft-Windows-Kernel-PnP"
  },
  "event_data": {
    "ThreadId": "0x8",
    "DeviceInstanceId": "PCIIDE\\IDEChannel\\4&403bef5&0&1",
    "ElapsedTimeMs": "3001",
    "ServiceName": "atapi"
  }
}

Event ID 904: A long running thread for device removal was detected.

#
Channel
Driver Watchdog
Task
WatchdogTriggered
Opcode
Start

Description

A long running thread for device removal was detected. The thread has been running for ThreadId milliseconds.

Message #

A long running thread for device removal was detected. The thread has been running for %4 milliseconds.
Thread ID: %1
Device: %2
Service: %3

Fields #

NameDescription
ThreadId HexInt64
DeviceInstanceId UnicodeString
ServiceName UnicodeString
ElapsedTimeMs UInt64

Event ID 905: A long running thread for device removal has been completed.

#
Channel
Driver Watchdog
Task
WatchdogTriggered
Opcode
Stop

Message #

A long running thread for device removal has been completed.
Thread ID: %1
Device: %2
Service: %3
Total run time in milliseconds: %4

Fields #

NameDescription
ThreadId HexInt64
DeviceInstanceId UnicodeString
ServiceName UnicodeString
ElapsedTimeMs UInt64

Event ID 906: A long running thread for device add routine was detected.

#
Channel
Driver Watchdog
Task
WatchdogTriggered
Opcode
Start

Description

A long running thread for device add routine was detected. The thread has been running for ThreadId milliseconds.

Message #

A long running thread for device add routine was detected. The thread has been running for %4 milliseconds.
Thread ID: %1
Device: %2
Driver: %3

Fields #

NameDescription
ThreadId HexInt64
DeviceInstanceId UnicodeString
DriverName UnicodeString
ElapsedTimeMs UInt64

Event ID 907: A long running thread for device add routine has been completed.

#
Channel
Driver Watchdog
Task
WatchdogTriggered
Opcode
Stop

Message #

A long running thread for device add routine has been completed.
Thread ID: %1
Device: %2
Driver: %3
Total run time in milliseconds: %4

Fields #

NameDescription
ThreadId HexInt64
DeviceInstanceId UnicodeString
DriverName UnicodeString
ElapsedTimeMs UInt64

Event ID 908: A long running thread for driver entry was detected.

#
Channel
Driver Watchdog
Level
Warning
Task
WatchdogTriggered
Opcode
Start

Description

A long running thread for driver entry was detected. The thread has been running for ElapsedTimeMs milliseconds.

Message #

A long running thread for driver entry was detected. The thread has been running for %4 milliseconds.
Thread ID: %1
Driver: %3

Fields #

NameDescription
ThreadId HexInt64
DeviceInstanceId UnicodeString
DriverName UnicodeStringDriver.
ElapsedTimeMs UInt64

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Kernel-PnP",
    "guid": "9C205A39-1250-487D-ABD7-E831C6290539",
    "event_source_name": "",
    "event_id": 908,
    "version": 0,
    "level": 3,
    "task": 900,
    "opcode": 1,
    "keywords": 144115188075855872,
    "time_created": "2023-11-06T00:25:57.930157+00:00",
    "event_record_id": 1,
    "correlation": {},
    "execution": {
      "process_id": 4,
      "thread_id": 2352
    },
    "channel": "Microsoft-Windows-Kernel-PnP/Driver Watchdog",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "ThreadId": "0x2ba4",
    "DeviceInstanceId": "",
    "DriverName": "avgSP",
    "ElapsedTimeMs": 10005
  },
  "message": ""
}

References #

Event ID 909: A long running thread for driver entry routine has been completed.

#
Channel
Driver Watchdog
Level
Informational
Task
WatchdogTriggered
Opcode
Stop

Message #

A long running thread for driver entry routine has been completed.
Thread ID: %1
Driver: %3
Total run time in milliseconds: %4

Fields #

NameDescription
ThreadId HexInt64
DeviceInstanceId UnicodeString
DriverName UnicodeStringDriver.
ElapsedTimeMs UInt64Total run time in milliseconds.

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Kernel-PnP",
    "guid": "9C205A39-1250-487D-ABD7-E831C6290539",
    "event_source_name": "",
    "event_id": 909,
    "version": 0,
    "level": 4,
    "task": 900,
    "opcode": 2,
    "keywords": 144115188075855872,
    "time_created": "2023-11-06T00:26:29.468233+00:00",
    "event_record_id": 2,
    "correlation": {},
    "execution": {
      "process_id": 4,
      "thread_id": 11172
    },
    "channel": "Microsoft-Windows-Kernel-PnP/Driver Watchdog",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "ThreadId": "0x2ba4",
    "DeviceInstanceId": "",
    "DriverName": "avgSP",
    "ElapsedTimeMs": 41546
  },
  "message": ""
}

References #

Event ID 930: Timed out waiting for response from user mode clients to synchronous notification EventGuid.

#
Channel
Driver Watchdog

Message #

Timed out waiting for response from user mode clients to synchronous notification %1
Event Category: %2
Device Instance ID: %3
Category Specific Data:
%4
%5

Fields #

NameDescription
EventGuid GUID
EventCategory UInt32
DeviceInstanceId UnicodeString
CategorySpecificData_Guid GUID
CategorySpecificData_String UnicodeString
TimeMs UInt64

Event ID 931: Responses from user mode clients to synchronous notification EventGuid took TimeMs milliseconds.

#
Channel
Driver Watchdog

Message #

Responses from user mode clients to synchronous notification %1 took %6 milliseconds
Event Category: %2
Device Instance ID: %3
Category Specific Data:
%4
%5

Fields #

NameDescription
EventGuid GUID
EventCategory UInt32
DeviceInstanceId UnicodeString
CategorySpecificData_Guid GUID
CategorySpecificData_String UnicodeString
TimeMs UInt64

Event ID 932: Synchronous notification EventGuid to process ProcessId (ProcessImageName) was removed after ElapsedTimeMs milliseconds.

#
Channel
Driver Watchdog

Message #

Synchronous notification %7 to process %2 (%3) was removed after %14 milliseconds
Event Category: %8
Device Instance ID: %9
Category Specific Data:
%10
%11

Fields #

NameDescription
FilterType UInt32
ProcessId UInt32
ProcessImageName UnicodeString
QueueDepth UInt32
DropCount UInt32
RegistrationTeardown Boolean
EventGuid GUID
EventCategory UInt32
DeviceInstanceId UnicodeString
CategorySpecificData_Guid GUID
CategorySpecificData_String UnicodeString
Synchronous Boolean
NotificationReceivedByClient Boolean
ElapsedTimeMs UInt64

Event ID 933: Notification EventGuid to driver DriverName took ElapsedTimeMs milliseconds.

#
Channel
Driver Watchdog

Message #

Notification %4 to driver %3 took %5 milliseconds
Event Category: %1
Notification Specific Data:
%6
%8

Fields #

NameDescription
EventCategory UInt32
DriverNameLength UInt16
DriverName UnicodeString
EventGuid GUID
ElapsedTimeMs UInt64
NotificationSpecific_Guid GUID
UnicodeStringLength UInt16
NotificationSpecific_UnicodeString UnicodeString

Event ID 1000: Device DeviceInstanceId could not be query removed as the removal was vetoed.

#
Channel
Device Management
Level
Warning
Opcode
Info

Message #

Device %1 could not be query removed as the removal was vetoed.

Veto Type: %2
Vetoed By: %3

Fields #

NameDescription
DeviceInstanceId UnicodeString
VetoType UInt32
VetoName UnicodeStringVetoed By.

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Kernel-PnP",
    "guid": "9C205A39-1250-487D-ABD7-E831C6290539",
    "event_source_name": "",
    "event_id": 1000,
    "version": 0,
    "level": 3,
    "task": 0,
    "opcode": 0,
    "keywords": 72057594037927936,
    "time_created": "2023-10-25T22:50:39.854895+00:00",
    "event_record_id": 10,
    "correlation": {},
    "execution": {
      "process_id": 4,
      "thread_id": 384
    },
    "channel": "Microsoft-Windows-Kernel-PnP/Device Management",
    "computer": "WinDevEval",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "DeviceInstanceId": "ACPI\\PNP0303\\4&1bd7f811&0",
    "VetoType": 6,
    "VetoName": "ACPI\\PNP0303\\4&1bd7f811&0\\Driver\\i8042prt"
  },
  "message": ""
}

References #

Event ID 1010: Device DeviceInstanceId has been surprise removed as it is reported as missing on the bus.

#
Channel
Device Management
Level
Informational
Opcode
Info

Message #

Device %1 has been surprise removed as it is reported as missing on the bus.
Count of devices removed: %2

Fields #

NameDescription
DeviceInstanceId UnicodeString
DeviceCount UInt32Count of devices removed.

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Kernel-PnP",
    "guid": "{9C205A39-1250-487D-ABD7-E831C6290539}",
    "event_source_name": "",
    "event_id": 1010,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 72057594037927936,
    "time_created": "2026-06-13T05:22:34.5416180+00:00",
    "event_record_id": 5,
    "correlation": {},
    "execution": {
      "process_id": 4,
      "thread_id": 8144
    },
    "channel": "Microsoft-Windows-Kernel-PnP/Device Management",
    "computer": "telemetry-DC-c.cell-c.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "DeviceInstanceId": "UMB\\UMB\\1&841921d&0&TERMINPUT_BUS",
    "DeviceCount": "1"
  },
  "message": "Device UMB\\UMB\\1&841921d&0&TERMINPUT_BUS has been surprise removed as it is reported as missing on the bus.\r\nCount of devices removed: 1"
}

Event ID 1011: Device DeviceInstanceId has been surprise removed as it was reported to be failing.

#
Channel
Device Management
Level
Warning
Opcode
Info

Message #

Device %1 has been surprise removed as it was reported to be failing.
Count of devices removed: %2

Fields #

NameDescription
DeviceInstanceId UnicodeString
DeviceCount UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Kernel-PnP",
    "guid": "{9C205A39-1250-487D-ABD7-E831C6290539}",
    "event_source_name": "",
    "event_id": 1011,
    "version": 0,
    "level": 3,
    "task": 0,
    "opcode": 0,
    "keywords": 72057594037927936,
    "time_created": "2026-04-15T21:23:59.3712212+00:00",
    "event_record_id": 696,
    "correlation": {},
    "execution": {
      "process_id": 4,
      "thread_id": 6568
    },
    "channel": "Microsoft-Windows-Kernel-PnP/Device Management",
    "computer": "JD-WIN11-22H2-1.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "DeviceInstanceId": "SWD\\RemoteDisplayEnum\\RdpIdd_IndirectDisplay&SessionId_0001",
    "DeviceCount": "2"
  },
  "message": "Device SWD\\RemoteDisplayEnum\\RdpIdd_IndirectDisplay&SessionId_0001 has been surprise removed as it was reported to be failing.\r\nCount of devices removed: 2"
}

Event ID 1020: A resource rebalance operation has succeeded.

#
Channel
Device Management
Opcode
Info

Message #

A resource rebalance operation has succeeded.

Device Instance ID: %1
Service Name: %2
Device Count: %3
Rebalance Phase: %4
Subtree Root Instance ID: %5
Subtree Includes Root: %6
Rebalance Due to Dynamic Partitioning: %7
Rebalance Reason: %8
Conflicting Resource Type: %9
Duration in Milliseconds: %10
Device Reset: %11

Fields #

NameDescription
DeviceInstanceId UnicodeString
ServiceName UnicodeString
DeviceCount UInt32
Phase UInt32
SubtreeRootInstanceId UnicodeString
SubtreeIncludesRoot Boolean
RebalanceDueToDynamicPartitioning Boolean
RebalanceReason UInt32
ConflictResourceType UInt8
DurationInMs UInt64
ResetDeviceWhileStopped Boolean

Event ID 1021: A resource rebalance operation has failed.

#
Channel
Device Management
Opcode
Info

Message #

A resource rebalance operation has failed.

Device Instance ID: %1
Service Name: %2
Device Count: %3
Rebalance Phase: %4
Subtree Root Instance ID: %5
Subtree Includes Root: %6
Rebalance Due to Dynamic Partitioning: %7
Rebalance Reason: %8
Conflicting Resource Type: %9
Rebalance Failure: %10
Veto Reason: %11
Vetoing Device Node Instance ID: %12
Duration in Milliseconds: %13
Device Reset: %14

Fields #

NameDescription
DeviceInstanceId UnicodeString
ServiceName UnicodeString
DeviceCount UInt32
Phase UInt32
SubtreeRootInstanceId UnicodeString
SubtreeIncludesRoot Boolean
RebalanceDueToDynamicPartitioning Boolean
RebalanceReason UInt32
ConflictResourceType UInt8
RebalanceFailure UInt32
VetoReason UInt32
VetoNodeInstanceId UnicodeString
DurationInMs UInt64
ResetDeviceWhileStopped Boolean

Event ID 1030: Device Device has been assigned to a guest partition.

#
Channel
Device Management
Opcode
Info

Message #

Device %1 has been assigned to a guest partition.

Fields #

NameDescription
Device UnicodeString

Event ID 1031: Device Device is no longer assigned to a guest partition.

#
Channel
Device Management
Opcode
Info

Message #

Device %1 is no longer assigned to a guest partition.

Fields #

NameDescription
Device UnicodeString

Event ID 1040: Device Flags has requested a platform-level device reset.

#
Channel
Device Management
Opcode
Start

Message #

Device %1 has requested a platform-level device reset.

Flags: %2

Fields #

NameDescription
DeviceInstanceId UnicodeString
Flags UInt32

Event ID 1041: Device Veto_type has completed a platform-level device reset.

#
Channel
Device Management
Opcode
Stop

Message #

Device %2 has completed a platform-level device reset.

Status: %3
Veto type: %4
Vetoed By: %6

Fields #

NameDescription
DeviceInstanceLength UInt16
DeviceInstance UnicodeString
Status UInt32NTSTATUS reference
VetoType UInt32
VetoNameLength UInt16
VetoName UnicodeString

Event ID 1050: Failed to create driver package defined child device of Child_Instance_ID.

#
Channel
Device Management
Opcode
Info

Message #

Failed to create driver package defined child device of %1.

Child Instance ID: %2
Status: %3

Fields #

NameDescription
ParentDeviceInstancePath UnicodeString
InstanceId UnicodeString
Status HexInt32NTSTATUS reference

Event ID 1060: Failed to create computer device derived from firmware information.

#
Channel
Device Management
Opcode
Info

Description

Failed to create computer device derived from firmware information. Status: Status.

Message #

Failed to create computer device derived from firmware information. Status: %1

Fields #

NameDescription
Status HexInt32NTSTATUS reference

Event ID 1065: Device DeviceInstanceId with problem code ProblemCode and problem status ProblemStatus requires the system to be rebooted.

#
Channel
Device Management

Message #

Device %1 with problem code %2 and problem status %3 requires the system to be rebooted.
Additional information:
%4

Fields #

NameDescription
DeviceInstanceId UnicodeString
ProblemCode UInt32
ProblemStatus HexInt32
AdditionalInfo HexInt64

Event ID 1070: Failed to open DeviceStackLocation driver service ServiceName for device DeviceInstance.

#
Channel
Device Management
Opcode
Info

Description

Failed to open DeviceStackLocation driver service ServiceName for device DeviceInstance. Status: Status.

Message #

Failed to open %3 driver service %2 for device %1. Status: %4

Fields #

NameDescription
DeviceInstance UnicodeString
ServiceName UnicodeString
DeviceStackLocation UnicodeString
Status HexInt32NTSTATUS reference

Event ID 1080: The driver FailureName failed to unload.

#
Channel
Device Management
Task
DriverUnload

Message #

The driver %5 failed to unload.
Driver Version: %6
Status: %3

Fields #

NameDescription
DriverNameLength UInt16
DriverName UnicodeString
Status UInt32NTSTATUS reference
FailureNameLength UInt16
FailureName UnicodeString
Version UInt32

Event ID 1100: SwDevice_IrpCreateStart

#
Channel
Operational
Task
SwDevice_IrpCreate
Opcode
Start

References #

Event ID 1101: SwDevice_IrpCreateStop

#
Channel
Operational
Task
SwDevice_IrpCreate
Opcode
Stop

Fields #

NameDescription
Status HexInt32NTSTATUS reference

References #

Event ID 1102: SwDevice_KernelCreateStart

#
Channel
Operational
Task
SwDevice_KernelCreate
Opcode
Start

Fields #

NameDescription
EnumeratorName UnicodeString
InstanceId UnicodeString
ParentDeviceInstanceId UnicodeString

References #

Event ID 1103: SwDevice_KernelCreateStop

#
Channel
Operational
Task
SwDevice_KernelCreate
Opcode
Stop

Fields #

NameDescription
EnumeratorName UnicodeString
InstanceId UnicodeString
ParentDeviceInstanceId UnicodeString
Status HexInt32NTSTATUS reference

Event ID 1104: task_01104

#
Channel
Operational
Opcode
Info

Fields #

NameDescription
EnumeratorName UnicodeString
InstanceId UnicodeString
ParentDeviceInstanceId UnicodeString
CapabilityFlags HexInt32
DeviceDescription UnicodeString
DeviceLocation UnicodeString
NumProperties UInt32

References #

Event ID 1105: task_01105

#
Channel
Operational
Opcode
Info

Fields #

NameDescription
DeviceId UnicodeString
InstanceId UnicodeString

References #

Event ID 1106: task_01106

#
Channel
Operational
Opcode
Info

Fields #

NameDescription
DeviceId UnicodeString
InstanceId UnicodeString

Event ID 1107: task_01107

#
Channel
Operational
Opcode
Info

Fields #

NameDescription
DeviceId UnicodeString
InstanceId UnicodeString
RemovedFromBus Boolean
HasPrimaryDeviceObject Boolean

Event ID 1108: SwDevice_InstanceTable_Add

#
Channel
Operational
Task
SwDevice_InstanceTable_Add

Fields #

NameDescription
DeviceId UnicodeString
InstanceId UnicodeString
AlreadyExists Boolean

References #

Event ID 1109: SwDevice_InstanceTable_Remove

#
Channel
Operational
Task
SwDevice_InstanceTable_Remove

Fields #

NameDescription
DeviceId UnicodeString
InstanceId UnicodeString

Event ID 1110: SwDevice_DeviceEnumeratedStart

#
Channel
Operational
Task
SwDevice_DeviceEnumerated
Opcode
Start

Fields #

NameDescription
DeviceId UnicodeString
InstanceId UnicodeString
DeviceInstancePath UnicodeString

Event ID 1111: SwDevice_DeviceEnumeratedStop

#
Channel
Operational
Task
SwDevice_DeviceEnumerated
Opcode
Stop

Fields #

NameDescription
DeviceId UnicodeString
InstanceId UnicodeString
Status HexInt32NTSTATUS reference

Event ID 1120: SwDevice_RelationAddStart

#
Channel
Operational
Task
SwDevice_RelationAdd
Opcode
Start

Fields #

NameDescription
DeviceId UnicodeString
InstanceId UnicodeString
ParentDeviceInstanceId UnicodeString

References #

Event ID 1121: SwDevice_RelationAddStop

#
Channel
Operational
Task
SwDevice_RelationAdd
Opcode
Stop

Fields #

NameDescription
DeviceId UnicodeString
InstanceId UnicodeString
ParentDeviceInstanceId UnicodeString
Status HexInt32NTSTATUS reference

References #

Event ID 1122: SwDevice_RelationRemove

#
Channel
Operational
Task
SwDevice_RelationRemove

Fields #

NameDescription
DeviceId UnicodeString
InstanceId UnicodeString
ParentDeviceInstanceId UnicodeString

Event ID 1130: SwDevice_LifetimeChangeStart

#
Channel
Operational
Task
SwDevice_LifetimeChange
Opcode
Start

Fields #

NameDescription
DeviceId UnicodeString
InstanceId UnicodeString

Event ID 1131: SwDevice_LifetimeChangeStop

#
Channel
Operational
Task
SwDevice_LifetimeChange
Opcode
Stop

Fields #

NameDescription
DeviceId UnicodeString
InstanceId UnicodeString
Status HexInt32NTSTATUS reference

Event ID 1132: SwDevice_LifetimeChange

#
Channel
Operational
Task
SwDevice_LifetimeChange

Fields #

NameDescription
DeviceId UnicodeString
InstanceId UnicodeString
OldLifetime UInt32
NewLifetime UInt32

Event ID 1140: SwDevice_RegisterInterfaceStart

#
Channel
Operational
Task
SwDevice_RegisterInterface
Opcode
Start

Fields #

NameDescription
DeviceId UnicodeString
InstanceId UnicodeString

Event ID 1141: SwDevice_RegisterInterfaceStop

#
Channel
Operational
Task
SwDevice_RegisterInterface
Opcode
Stop

Fields #

NameDescription
DeviceId UnicodeString
InstanceId UnicodeString
Status HexInt32NTSTATUS reference

Event ID 1142: SwDevice_RegisterInterface

#
Channel
Operational
Task
SwDevice_RegisterInterface

Fields #

NameDescription
DeviceId UnicodeString
InstanceId UnicodeString
SymbolicLink UnicodeString

Event ID 1143: SwDevice_SetInterfaceState

#
Channel
Operational
Task
SwDevice_SetInterfaceState

Fields #

NameDescription
DeviceId UnicodeString
InstanceId UnicodeString
SymbolicLink UnicodeString
Enable Boolean

Event ID 1144: SwDevice_SetInterfaceStateStart

#
Channel
Operational
Task
SwDevice_SetInterfaceState
Opcode
Start

Fields #

NameDescription
DeviceId UnicodeString
InstanceId UnicodeString

Event ID 1145: SwDevice_SetInterfaceStateStop

#
Channel
Operational
Task
SwDevice_SetInterfaceState
Opcode
Stop

Fields #

NameDescription
DeviceId UnicodeString
InstanceId UnicodeString
Status HexInt32NTSTATUS reference

Event ID 1150: SwDevice_SetDevicePropertyStart

#
Channel
Operational
Task
SwDevice_SetDeviceProperty
Opcode
Start

Fields #

NameDescription
DeviceId UnicodeString
InstanceId UnicodeString

Event ID 1151: SwDevice_SetDevicePropertyStop

#
Channel
Operational
Task
SwDevice_SetDeviceProperty
Opcode
Stop

Fields #

NameDescription
DeviceId UnicodeString
InstanceId UnicodeString
Status HexInt32NTSTATUS reference

Event ID 1160: SwDevice_SetInterfacePropertyStart

#
Channel
Operational
Task
SwDevice_SetInterfaceProperty
Opcode
Start

Fields #

NameDescription
DeviceId UnicodeString
InstanceId UnicodeString

Event ID 1161: SwDevice_SetInterfacePropertyStop

#
Channel
Operational
Task
SwDevice_SetInterfaceProperty
Opcode
Stop

Fields #

NameDescription
DeviceId UnicodeString
InstanceId UnicodeString
Status HexInt32NTSTATUS reference

Event ID 1170: SwDevice_IrpCloseStart

#
Channel
Operational
Task
SwDevice_IrpClose
Opcode
Start

Fields #

NameDescription
DeviceId UnicodeString
InstanceId UnicodeString

Event ID 1171: SwDevice_IrpCloseStop

#
Channel
Operational
Task
SwDevice_IrpClose
Opcode
Stop

Fields #

NameDescription
DeviceId UnicodeString
InstanceId UnicodeString
DeviceClosed Boolean

Event ID 1172: SwDevice_KernelCloseStart

#
Channel
Operational
Task
SwDevice_KernelClose
Opcode
Start

Fields #

NameDescription
ParentDeviceInstanceId UnicodeString
EnumeratorName UnicodeString
InstanceId UnicodeString

Event ID 1173: SwDevice_KernelCloseStop

#
Channel
Operational
Task
SwDevice_KernelClose
Opcode
Stop

Fields #

NameDescription
ParentDeviceInstanceId UnicodeString
EnumeratorName UnicodeString
InstanceId UnicodeString
Status HexInt32NTSTATUS reference

Event ID 1174: SwDevice_CloseDescendants

#
Channel
Operational
Task
SwDevice_CloseDescendants

Fields #

NameDescription
ParentDeviceInstanceId UnicodeString

Event ID 1175: SwDevice_CloseDevice

#
Channel
Operational
Task
SwDevice_CloseDevice

Fields #

NameDescription
DeviceId UnicodeString
InstanceId UnicodeString

Event ID 1176: SwDevice_ProcessRemove

#
Channel
Operational
Task
SwDevice_ProcessRemove

Fields #

NameDescription
DeviceId UnicodeString
InstanceId UnicodeString
DeviceInstanceId UnicodeString
KeepActive Boolean
SwDeviceFlags HexInt32
DeviceExtensionFlags HexInt32

Event ID 1177: SwDevice_ProcessParentRemove

#
Channel
Operational
Task
SwDevice_ProcessParentRemove

Fields #

NameDescription
DeviceId UnicodeString
InstanceId UnicodeString
DeviceInstanceId UnicodeString
ParentDeviceInstanceId UnicodeString
SwDeviceFlags HexInt32
DeviceExtensionFlags HexInt32

Event ID 1178: SwDevice_UninstallDevice

#
Channel
Operational
Task
SwDevice_UninstallDevice

Fields #

NameDescription
DeviceId UnicodeString
InstanceId UnicodeString
DeviceInstanceId UnicodeString
Status HexInt32NTSTATUS reference

Event ID 1190: SwDevice_GetChildPdoStart

#
Channel
Operational
Level
Informational
Task
SwDevice_GetChildPdo
Opcode
Start

Fields #

NameDescription
DeviceId UnicodeString
InstanceId UnicodeString
ParentDeviceInstanceId UnicodeString
SwDeviceFlags HexInt32

Example Event #

{
  "system": {
    "channel": "Microsoft-Windows-Kernel-PnP/Operational",
    "computer": "10.2.10.21",
    "correlation": {},
    "event_id": 1190,
    "event_record_id": 0,
    "event_source_name": "",
    "execution": {
      "process_id": 4,
      "thread_id": 11360
    },
    "guid": "",
    "keywords": 0,
    "level": 4,
    "opcode": 1,
    "provider": "Microsoft-Windows-Kernel-PnP",
    "security": {
      "user_id": ""
    },
    "task": 0,
    "time_created": "2026-07-21 22:20:40.719Z",
    "version": 0
  },
  "event_data": {
    "DeviceId": "SWD\\COMPUTER",
    "InstanceId": "MFG_QEMU&PROD_Standard_PC_(i440FX_+_PIIX__1996)",
    "ParentDeviceInstanceId": "HTREE\\ROOT\\0",
    "SwDeviceFlags": "04000000"
  },
  "message": ""
}

Event ID 1191: SwDevice_GetChildPdoStop

#
Channel
Operational
Level
Informational
Task
SwDevice_GetChildPdo
Opcode
Stop

Fields #

NameDescription
DeviceId UnicodeString
InstanceId UnicodeString
PdoReported Boolean
NewPdo Boolean

Example Event #

{
  "system": {
    "channel": "Microsoft-Windows-Kernel-PnP/Operational",
    "computer": "10.2.10.21",
    "correlation": {},
    "event_id": 1191,
    "event_record_id": 0,
    "event_source_name": "",
    "execution": {
      "process_id": 4,
      "thread_id": 11360
    },
    "guid": "",
    "keywords": 0,
    "level": 4,
    "opcode": 2,
    "provider": "Microsoft-Windows-Kernel-PnP",
    "security": {
      "user_id": ""
    },
    "task": 0,
    "time_created": "2026-07-21 22:20:40.719Z",
    "version": 0
  },
  "event_data": {
    "DeviceId": "SWD\\COMPUTER",
    "InstanceId": "MFG_QEMU&PROD_Standard_PC_(i440FX_+_PIIX__1996)",
    "NewPdo": false,
    "PdoReported": true
  },
  "message": ""
}

Event ID 1192: SwDevice_GetChildPdo

#
Channel
Operational
Task
SwDevice_GetChildPdo

Fields #

NameDescription
DeviceId UnicodeString
InstanceId UnicodeString
SkipCount UInt32

Event ID 1200: SwDevice_AttributesChangeStart

#
Channel
Operational
Task
SwDevice_AttributesChange
Opcode
Start

Fields #

NameDescription
DeviceId UnicodeString
InstanceId UnicodeString

Event ID 1201: SwDevice_AttributesChangeStop

#
Channel
Operational
Task
SwDevice_AttributesChange
Opcode
Stop

Fields #

NameDescription
DeviceId UnicodeString
InstanceId UnicodeString
Status HexInt32NTSTATUS reference

Event ID 1202: SwDevice_AttributesChange

#
Channel
Operational
Task
SwDevice_AttributesChange

Fields #

NameDescription
DeviceId UnicodeString
InstanceId UnicodeString
OldAttributes UInt32
NewAttributes UInt32

Event ID 1300: task_01300

#
Channel
Operational

Fields #

NameDescription
FilterType UInt32
ProcessId UInt32
ProcessImageName UnicodeString
QueueDepth UInt32
DropCount UInt32
EventGuid GUID
EventCategory UInt32
DeviceInstanceId UnicodeString
CategorySpecificData_Guid GUID
CategorySpecificData_String UnicodeString
Synchronous Boolean
ElapsedTimeMs UInt64

Event ID 1301: task_01301

#
Channel
Operational

Fields #

NameDescription
FilterType UInt32
ProcessId UInt32
ProcessImageName UnicodeString
QueueDepth UInt32
DropCount UInt32
EventGuid GUID
EventCategory UInt32
DeviceInstanceId UnicodeString
CategorySpecificData_Guid GUID
CategorySpecificData_String UnicodeString
Synchronous Boolean
ElapsedTimeMs UInt64

Event ID 1302: task_01302

#
Channel
Operational

Fields #

NameDescription
FilterType UInt32
ProcessId UInt32
ProcessImageName UnicodeString
QueueDepth UInt32
DropCount UInt32
EventGuid GUID
EventCategory UInt32
DeviceInstanceId UnicodeString
CategorySpecificData_Guid GUID
CategorySpecificData_String UnicodeString
Synchronous Boolean
Status HexInt32NTSTATUS reference

Event ID 1303: task_01303

#
Channel
Operational

Fields #

NameDescription
FilterType UInt32
ProcessId UInt32
ProcessImageName UnicodeString
QueueDepth UInt32
DropCount UInt32
EventGuid GUID
EventCategory UInt32
DeviceInstanceId UnicodeString
CategorySpecificData_Guid GUID
CategorySpecificData_String UnicodeString
Synchronous Boolean
Status HexInt32NTSTATUS reference

Event ID 1304: task_01304

#
Channel
Operational

Fields #

NameDescription
FilterType UInt32
ProcessId UInt32
ProcessImageName UnicodeString
QueueDepth UInt32
DropCount UInt32
RegistrationTeardown Boolean
EventGuid GUID
EventCategory UInt32
DeviceInstanceId UnicodeString
CategorySpecificData_Guid GUID
CategorySpecificData_String UnicodeString
Synchronous Boolean
NotificationReceivedByClient Boolean
ElapsedTimeMs UInt64

Event ID 1400: Begin serializing boot with PnP device enumeration

#
Channel
Boot Diagnostic
Task
SerializeBoot
Opcode
Start

Event ID 1401: End serializing boot with PnP device enumeration

#
Channel
Boot Diagnostic
Task
SerializeBoot
Opcode
Stop

Provenance

ETW provider GUID {9C205A39-1250-487D-ABD7-E831C6290539}

Defined in microsoft-windows-kernel-pnp-events.dll, which carries the event manifest.

  • WS2022-20348.4893, sample captured from a live trace, binary version 10.0.20348.1, captured 2026-06-02 — Manifest XML pack, 1.9 MB
  • WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.1, captured 2026-06-02 — Manifest XML pack, 1.9 MB
  • Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.1, captured 2026-06-02 — Manifest XML pack, 2.0 MB