Microsoft-Windows-KernelStreaming

30 events across 3 channels

EventTitleChannelSample
200KS_PnpAddDevice Start.OperationalN
200KS_PnpAddDevice Start.WINDOWS_KS_CHANNELN
201KS_PnpAddDevice Stop.OperationalN
201KS_PnpAddDevice Stop.WINDOWS_KS_CHANNELN
202KS_StreamingRequest Start, pIrp: pIrp.AnalyticN
202KS_StreamingRequest Start, pIrp: pIrp.WINDOWS_KS_CHANNELN
203KS_StreamingRequest Stop, pIrp: pIrp.AnalyticN
203KS_StreamingRequest Stop, pIrp: pIrp.WINDOWS_KS_CHANNELN
204KS_CameraGrab Start, ProcessId: ProcessId, PinId: PinId, FilterAddress: …OperationalN
204KS_CameraGrab Start, ProcessId: ProcessId, PinId: PinId, FilterAddress: …WINDOWS_KS_CHANNELN
205KS_CameraGrab Stop, Status: Status.OperationalN
205KS_CameraGrab Stop, Status: Status.WINDOWS_KS_CHANNELN
206KS_WNF Register.OperationalN
206KS_WNF Register.WINDOWS_KS_CHANNELN
207KS_WNF Unregister.OperationalN
207KS_WNF Unregister.WINDOWS_KS_CHANNELN
208KS_WNFPinState Update, FilterExt: FilterExt, PinState: PinState.OperationalN
208KS_WNFPinState Update, FilterExt: FilterExt, PinState: PinState.WINDOWS_KS_CHANNELN
209KS_WNFNotification Fire, EntryCount: EntryCount.OperationalN
209KS_WNFNotification Fire, EntryCount: EntryCount.WINDOWS_KS_CHANNELN
210KS_DisplayOff StopStreams.OperationalN
210KS_DisplayOff StopStreams.WINDOWS_KS_CHANNELN
211KS_IoProbeandLock Start, PinId: PinId, BufSize: BufSize.AnalyticN
211KS_IoProbeandLock Start, PinId: PinId, BufSize: BufSize.WINDOWS_KS_CHANNELN
212KS_IoProbeandLock End, PinId: PinId, BufSize: BufSize.AnalyticN
212KS_IoProbeandLock End, PinId: PinId, BufSize: BufSize.WINDOWS_KS_CHANNELN
213KS_QueryInterface Start, pKsDevice: pKsDevice, pIrp: pIrp, InterfaceGuid: …OperationalN
213KS_QueryInterface Start, pKsDevice: pKsDevice, pIrp: pIrp, InterfaceGuid: …WINDOWS_KS_CHANNELN
214KS_QueryInterface Stop, pKsDevice: pKsDevice, pIrp: pIrp, InterfaceGuid: …OperationalN
214KS_QueryInterface Stop, pKsDevice: pKsDevice, pIrp: pIrp, InterfaceGuid: …WINDOWS_KS_CHANNELN

Event ID 200: KS_PnpAddDevice Start.

#
Provider
Microsoft-Windows-KernelStreaming
Channel
Operational
Task
KS_PnpAddDevice
Opcode
Start

Description

KS_PnpAddDevice Start.

Message #

KS_PnpAddDevice Start.

Event ID 200: KS_PnpAddDevice Start.

#
Provider
Microsoft-Windows-KernelStreaming
Channel
WINDOWS_KS_CHANNEL
Task
KS_PnpAddDevice
Opcode
Start

Description

KS_PnpAddDevice Start.

Message #

KS_PnpAddDevice Start.

Event ID 201: KS_PnpAddDevice Stop.

#
Provider
Microsoft-Windows-KernelStreaming
Channel
Operational
Task
KS_PnpAddDevice
Opcode
Stop

Description

KS_PnpAddDevice Stop.

Message #

KS_PnpAddDevice Stop.

Event ID 201: KS_PnpAddDevice Stop.

#
Provider
Microsoft-Windows-KernelStreaming
Channel
WINDOWS_KS_CHANNEL
Task
KS_PnpAddDevice
Opcode
Stop

Description

KS_PnpAddDevice Stop.

Message #

KS_PnpAddDevice Stop.

Event ID 202: KS_StreamingRequest Start, pIrp: pIrp.

#
Provider
Microsoft-Windows-KernelStreaming
Channel
Analytic
Task
KS_StreamingRequest
Opcode
Start

Description

KS_StreamingRequest Start, pIrp: pIrp.

Message #

KS_StreamingRequest Start, pIrp: %1.

Fields #

NameDescription
pIrp Pointer

Event ID 202: KS_StreamingRequest Start, pIrp: pIrp.

#
Provider
Microsoft-Windows-KernelStreaming
Channel
WINDOWS_KS_CHANNEL
Task
KS_StreamingRequest
Opcode
Start

Description

KS_StreamingRequest Start, pIrp: pIrp.

Message #

KS_StreamingRequest Start, pIrp: %1.

Fields #

NameDescription
pIrp Pointer

Event ID 203: KS_StreamingRequest Stop, pIrp: pIrp.

#
Provider
Microsoft-Windows-KernelStreaming
Channel
Analytic
Task
KS_StreamingRequest
Opcode
Stop

Description

KS_StreamingRequest Stop, pIrp: pIrp.

Message #

KS_StreamingRequest Stop, pIrp: %1.

Fields #

NameDescription
pIrp Pointer

Event ID 203: KS_StreamingRequest Stop, pIrp: pIrp.

#
Provider
Microsoft-Windows-KernelStreaming
Channel
WINDOWS_KS_CHANNEL
Task
KS_StreamingRequest
Opcode
Stop

Description

KS_StreamingRequest Stop, pIrp: pIrp.

Message #

KS_StreamingRequest Stop, pIrp: %1.

Fields #

NameDescription
pIrp Pointer

Event ID 204: KS_CameraGrab Start, ProcessId: ProcessId, PinId: PinId, FilterAddress: FilterAddress.

#
Provider
Microsoft-Windows-KernelStreaming
Channel
Operational
Task
KS_CameraGrab
Opcode
Start

Description

KS_CameraGrab Start, ProcessId: ProcessId, PinId: PinId, FilterAddress: FilterAddress.

Message #

KS_CameraGrab Start, ProcessId: %1, PinId: %2, FilterAddress: %3.

Fields #

NameDescription
ProcessId Pointer
PinId UInt32
FilterAddress Pointer

Event ID 204: KS_CameraGrab Start, ProcessId: ProcessId, PinId: PinId, FilterAddress: FilterAddress.

#
Provider
Microsoft-Windows-KernelStreaming
Channel
WINDOWS_KS_CHANNEL
Task
KS_CameraGrab
Opcode
Start

Description

KS_CameraGrab Start, ProcessId: ProcessId, PinId: PinId, FilterAddress: FilterAddress.

Message #

KS_CameraGrab Start, ProcessId: %1, PinId: %2, FilterAddress: %3.

Fields #

NameDescription
ProcessId Pointer
PinId UInt32
FilterAddress Pointer

Event ID 205: KS_CameraGrab Stop, Status: Status.

#
Provider
Microsoft-Windows-KernelStreaming
Channel
Operational
Task
KS_CameraGrab
Opcode
Stop

Description

KS_CameraGrab Stop, Status: Status.

Message #

KS_CameraGrab Stop, Status: %1.

Fields #

NameDescription
Status HexInt32NTSTATUS reference

Event ID 205: KS_CameraGrab Stop, Status: Status.

#
Provider
Microsoft-Windows-KernelStreaming
Channel
WINDOWS_KS_CHANNEL
Task
KS_CameraGrab
Opcode
Stop

Description

KS_CameraGrab Stop, Status: Status.

Message #

KS_CameraGrab Stop, Status: %1.

Fields #

NameDescription
Status HexInt32NTSTATUS reference

Event ID 206: KS_WNF Register.

#
Provider
Microsoft-Windows-KernelStreaming
Channel
Operational
Task
KS_WNF

Description

KS_WNF Register.

Message #

KS_WNF Register.

Event ID 206: KS_WNF Register.

#
Provider
Microsoft-Windows-KernelStreaming
Channel
WINDOWS_KS_CHANNEL
Task
KS_WNF

Description

KS_WNF Register.

Message #

KS_WNF Register.

Event ID 207: KS_WNF Unregister.

#
Provider
Microsoft-Windows-KernelStreaming
Channel
Operational
Task
KS_WNF

Description

KS_WNF Unregister.

Message #

KS_WNF Unregister.

Event ID 207: KS_WNF Unregister.

#
Provider
Microsoft-Windows-KernelStreaming
Channel
WINDOWS_KS_CHANNEL
Task
KS_WNF

Description

KS_WNF Unregister.

Message #

KS_WNF Unregister.

Event ID 208: KS_WNFPinState Update, FilterExt: FilterExt, PinState: PinState.

#
Provider
Microsoft-Windows-KernelStreaming
Channel
Operational
Task
KS_WNFPinState

Description

KS_WNFPinState Update, FilterExt: FilterExt, PinState: PinState.

Message #

KS_WNFPinState Update, FilterExt: %1, PinState: %2.

Fields #

NameDescription
FilterExt Pointer
PinState UInt32

Event ID 208: KS_WNFPinState Update, FilterExt: FilterExt, PinState: PinState.

#
Provider
Microsoft-Windows-KernelStreaming
Channel
WINDOWS_KS_CHANNEL
Task
KS_WNFPinState

Description

KS_WNFPinState Update, FilterExt: FilterExt, PinState: PinState.

Message #

KS_WNFPinState Update, FilterExt: %1, PinState: %2.

Fields #

NameDescription
FilterExt Pointer
PinState UInt32

Event ID 209: KS_WNFNotification Fire, EntryCount: EntryCount.

#
Provider
Microsoft-Windows-KernelStreaming
Channel
Operational
Task
KS_WNFNotification

Description

KS_WNFNotification Fire, EntryCount: EntryCount.

Message #

KS_WNFNotification Fire, EntryCount: %1.

Fields #

NameDescription
EntryCount UInt32

Event ID 209: KS_WNFNotification Fire, EntryCount: EntryCount.

#
Provider
Microsoft-Windows-KernelStreaming
Channel
WINDOWS_KS_CHANNEL
Task
KS_WNFNotification

Description

KS_WNFNotification Fire, EntryCount: EntryCount.

Message #

KS_WNFNotification Fire, EntryCount: %1.

Fields #

NameDescription
EntryCount UInt32

Event ID 210: KS_DisplayOff StopStreams.

#
Provider
Microsoft-Windows-KernelStreaming
Channel
Operational
Task
KS_DisplayOff

Description

KS_DisplayOff StopStreams.

Message #

KS_DisplayOff StopStreams.

Event ID 210: KS_DisplayOff StopStreams.

#
Provider
Microsoft-Windows-KernelStreaming
Channel
WINDOWS_KS_CHANNEL
Task
KS_DisplayOff

Description

KS_DisplayOff StopStreams.

Message #

KS_DisplayOff StopStreams.

Event ID 211: KS_IoProbeandLock Start, PinId: PinId, BufSize: BufSize.

#
Provider
Microsoft-Windows-KernelStreaming
Channel
Analytic
Task
KS_IoProbeandLock
Opcode
Start

Description

KS_IoProbeandLock Start, PinId: PinId, BufSize: BufSize.

Message #

KS_IoProbeandLock Start, PinId: %1, BufSize: %2.

Fields #

NameDescription
PinId HexInt32
BufSize UInt32

Event ID 211: KS_IoProbeandLock Start, PinId: PinId, BufSize: BufSize.

#
Provider
Microsoft-Windows-KernelStreaming
Channel
WINDOWS_KS_CHANNEL
Task
KS_IoProbeandLock
Opcode
Start

Description

KS_IoProbeandLock Start, PinId: PinId, BufSize: BufSize.

Message #

KS_IoProbeandLock Start, PinId: %1, BufSize: %2.

Fields #

NameDescription
PinId HexInt32
BufSize UInt32

Event ID 212: KS_IoProbeandLock End, PinId: PinId, BufSize: BufSize.

#
Provider
Microsoft-Windows-KernelStreaming
Channel
Analytic
Task
KS_IoProbeandLock
Opcode
Stop

Description

KS_IoProbeandLock End, PinId: PinId, BufSize: BufSize.

Message #

KS_IoProbeandLock End, PinId: %1, BufSize: %2.

Fields #

NameDescription
PinId HexInt32
BufSize UInt32

Event ID 212: KS_IoProbeandLock End, PinId: PinId, BufSize: BufSize.

#
Provider
Microsoft-Windows-KernelStreaming
Channel
WINDOWS_KS_CHANNEL
Task
KS_IoProbeandLock
Opcode
Stop

Description

KS_IoProbeandLock End, PinId: PinId, BufSize: BufSize.

Message #

KS_IoProbeandLock End, PinId: %1, BufSize: %2.

Fields #

NameDescription
PinId HexInt32
BufSize UInt32

Event ID 213: KS_QueryInterface Start, pKsDevice: pKsDevice, pIrp: pIrp, InterfaceGuid: InterfaceGuid, Status: Status.

#
Provider
Microsoft-Windows-KernelStreaming
Channel
Operational
Task
KS_QueryInterface
Opcode
Start

Description

KS_QueryInterface Start, pKsDevice: pKsDevice, pIrp: pIrp, InterfaceGuid: InterfaceGuid, Status: Status.

Message #

KS_QueryInterface Start, pKsDevice: %1, pIrp: %2, InterfaceGuid: %3, Status: %4.

Fields #

NameDescription
pKsDevice Pointer
pIrp Pointer
InterfaceGuid GUID
Status UInt32NTSTATUS reference

Event ID 213: KS_QueryInterface Start, pKsDevice: pKsDevice, pIrp: pIrp, InterfaceGuid: InterfaceGuid, Status: Status.

#
Provider
Microsoft-Windows-KernelStreaming
Channel
WINDOWS_KS_CHANNEL
Task
KS_QueryInterface
Opcode
Start

Description

KS_QueryInterface Start, pKsDevice: pKsDevice, pIrp: pIrp, InterfaceGuid: InterfaceGuid, Status: Status.

Message #

KS_QueryInterface Start, pKsDevice: %1, pIrp: %2, InterfaceGuid: %3, Status: %4.

Fields #

NameDescription
pKsDevice Pointer
pIrp Pointer
InterfaceGuid GUID
Status UInt32NTSTATUS reference

Event ID 214: KS_QueryInterface Stop, pKsDevice: pKsDevice, pIrp: pIrp, InterfaceGuid: InterfaceGuid, Status: Status.

#
Provider
Microsoft-Windows-KernelStreaming
Channel
Operational
Task
KS_QueryInterface
Opcode
Stop

Description

KS_QueryInterface Stop, pKsDevice: pKsDevice, pIrp: pIrp, InterfaceGuid: InterfaceGuid, Status: Status.

Message #

KS_QueryInterface Stop, pKsDevice: %1, pIrp: %2, InterfaceGuid: %3, Status: %4.

Fields #

NameDescription
pKsDevice Pointer
pIrp Pointer
InterfaceGuid GUID
Status UInt32NTSTATUS reference

Event ID 214: KS_QueryInterface Stop, pKsDevice: pKsDevice, pIrp: pIrp, InterfaceGuid: InterfaceGuid, Status: Status.

#
Provider
Microsoft-Windows-KernelStreaming
Channel
WINDOWS_KS_CHANNEL
Task
KS_QueryInterface
Opcode
Stop

Description

KS_QueryInterface Stop, pKsDevice: pKsDevice, pIrp: pIrp, InterfaceGuid: InterfaceGuid, Status: Status.

Message #

KS_QueryInterface Stop, pKsDevice: %1, pIrp: %2, InterfaceGuid: %3, Status: %4.

Fields #

NameDescription
pKsDevice Pointer
pIrp Pointer
InterfaceGuid GUID
Status UInt32NTSTATUS reference

Provenance

Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.

ETW provider GUID 548c4417-ce45-41ff-99dd-528f01ce0fe1

Defined in ks.sys, the binary that emits these events.

Observed on:

  • WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.4767, captured 2026-06-02
  • Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.6584, captured 2026-06-02

Downloads