Microsoft-Windows-MediaFoundation-Platform

EventTitleChannelSampleRule
1Attempt to use MFT clsid clsid marked as do not use.MediaFoundationPlatformNN
2Attempt to use Media Source clsid clsid marked as do not use.MediaFoundationPlatformNN
3Mark MFT clsid clsid do not use = Disabled.MediaFoundationPlatformNN
4Mark Media Source clsid clsid do not use = Disabled.MediaFoundationPlatformNN
5Choosing preferred MFT clsid clsid for subtype Selector.MediaFoundationPlatformNN
6Registering preferred MFT clsid clsid for subtype Selector.MediaFoundationPlatformNN
7Choosing preferred Media Source clsid clsid for Selector.MediaFoundationPlatformNN
8Registering preferred Media Soure clsid clsid for Selector.MediaFoundationPlatformNN
9Found preferred MFT clsid clsid for media subtype Selector.MediaFoundationPlatformNN
10Did not find preferred MFT for media subtype Selector.MediaFoundationPlatformNN
11Query MFT clsid clsid do not use: Disabled.MediaFoundationPlatformNN
12Found preferred Media Source clsid clsid for Selector.MediaFoundationPlatformNN
13Did not find preferred Media Source for Selector.MediaFoundationPlatformNN
14Query Media Source clsid clsid do not use: Disabled.MediaFoundationPlatformNN
15Registering local MFT(MFTName).MediaFoundationPlatformNN
16Unregistering local MFT(MFTName).MediaFoundationPlatformNN
17Enumerating local MFT(MFTName).MediaFoundationPlatformNN
18MF_MFT_Hardware_EnumerationStartMediaFoundationDeviceProxyNN
19MF_MFT_Hardware_EnumerationMediaFoundationDeviceProxyNN
20MF_MFT_Hardware_EnumerationStopMediaFoundationDeviceProxyNN
21Configuration: dwType = dwType dwConfig=dwConfig.MediaFoundationPlatformNN
100MFStartup returned hr.MediaFoundationPlatformYN
101MFShutdown StartMediaFoundationPlatformNN
102MFShutdown Stop - return code hr.MediaFoundationPlatformNN
103MFGetConfigurationKey Type Type Key KeyName Result lResult.MediaFoundationPlatformYN
104MFGetConfigurationValueDWORD Type Type Key KeyName ValueName ValueName Result …MediaFoundationPlatformYN
105MFGetConfigurationValueString Type Type Key KeyName ValueName ValueName Result …MediaFoundationPlatformNN
200Source Resolver Context(Context) Resolve url flags hr.MediaFoundationPlatformNN
201Source Resolver Context(Context) Trying Scheme Handler clsid.MediaFoundationPlatformNN
202Source Resolver Context(Context) Trying Byte Scheme Handler CLSID(clsid).MediaFoundationPlatformNN
203Source Resolver Context(Context) SchemeHandler Result hr.MediaFoundationPlatformNN
204Source Resolver Context(Context) Byte stream Handler Result hr.MediaFoundationPlatformNN
205Source Resolver Context(Context) Resolving url returned hr.MediaFoundationPlatformNN
206TraceFailure logger (Context) line Line result hr function function.MediaFoundationPlatformNN
207ByteStreamOnInputStream_Read_Start stream (stream) ptr offset length length.MediaFoundationPlatformNN
208ByteStreamOnInputStream_Read_Stop stream (stream) ptr length length buffer hr …MediaFoundationPlatformNN
300MFTEnumEx flags flags, category Category for input type …MediaFoundationPlatformNN
301Found matching software MFT clsid.MediaFoundationPlatformNN
302Found Local MFT string.MediaFoundationPlatformNN
303Found Hardware MFT string.MediaFoundationPlatformNN
304MFTEnumEx returned code hr, found localMFTs local MFTs, softwareMFTs software …MediaFoundationPlatformNN
305MFTEnum2 flags flags, category Category for input type (inputType,inputSubtype), …MediaFoundationPlatformNN
306MFTEnum2 returned code hr, found numMFTs MFTs matching adapter with vendor ID …MediaFoundationPlatformNN
2500MFGetMFTMerit EnterMediaFoundationPlatformNN
2501MFGetMFTMerit Leave Merit(Merit) Return Code(hr).MediaFoundationPlatformNN
2502MFGetMFTMerit: StartInitialization returned hr.MediaFoundationPlatformNN
2503MFGetMFTMerit: Validate Certificate returned hr.MediaFoundationPlatformNN
2504MFGetMFTMerit: EndInitialization returned hr.MediaFoundationPlatformNN
2505MFGetMFTMerit: GetInformation returned hr.MediaFoundationPlatformNN

Event ID 1: Attempt to use MFT clsid clsid marked as do not use.

#
Channel
MediaFoundationPlatform
Task
PluginManager

Message #

Attempt to use MFT clsid %1 marked as do not use.

Fields #

NameDescription
clsid GUID

Event ID 2: Attempt to use Media Source clsid clsid marked as do not use.

#
Channel
MediaFoundationPlatform
Task
PluginManager

Message #

Attempt to use Media Source clsid %1 marked as do not use.

Fields #

NameDescription
clsid GUID

Event ID 3: Mark MFT clsid clsid do not use = Disabled.

#
Channel
MediaFoundationPlatform
Task
PluginManager

Message #

Mark MFT clsid %1 do not use = %2.

Fields #

NameDescription
clsid GUID
Disabled Boolean

Event ID 4: Mark Media Source clsid clsid do not use = Disabled.

#
Channel
MediaFoundationPlatform
Task
PluginManager

Message #

Mark Media Source clsid %1 do not use = %2.

Fields #

NameDescription
clsid GUID
Disabled Boolean

Event ID 5: Choosing preferred MFT clsid clsid for subtype Selector.

#
Channel
MediaFoundationPlatform
Task
PluginManager

Message #

Choosing preferred MFT clsid %1 for subtype %2.

Fields #

NameDescription
clsid GUID
Selector UnicodeString

Event ID 6: Registering preferred MFT clsid clsid for subtype Selector.

#
Channel
MediaFoundationPlatform
Task
PluginManager

Message #

Registering preferred MFT clsid %1 for subtype %2.

Fields #

NameDescription
clsid GUID
Selector UnicodeString

Event ID 7: Choosing preferred Media Source clsid clsid for Selector.

#
Channel
MediaFoundationPlatform
Task
PluginManager

Message #

Choosing preferred Media Source clsid %1 for %2.

Fields #

NameDescription
clsid GUID
Selector UnicodeString

Event ID 8: Registering preferred Media Soure clsid clsid for Selector.

#
Channel
MediaFoundationPlatform
Task
PluginManager

Message #

Registering preferred Media Soure clsid %1 for %2.

Fields #

NameDescription
clsid GUID
Selector UnicodeString

Event ID 9: Found preferred MFT clsid clsid for media subtype Selector.

#
Channel
MediaFoundationPlatform
Task
PluginManager

Message #

Found preferred MFT clsid %1 for media subtype %2.

Fields #

NameDescription
clsid GUID
Selector UnicodeString

Event ID 10: Did not find preferred MFT for media subtype Selector.

#
Channel
MediaFoundationPlatform
Task
PluginManager

Message #

Did not find preferred MFT for media subtype %1.

Fields #

NameDescription
Selector UnicodeString

Event ID 11: Query MFT clsid clsid do not use: Disabled.

#
Channel
MediaFoundationPlatform
Task
PluginManager

Message #

Query MFT clsid %1 do not use: %2.

Fields #

NameDescription
clsid GUID
Disabled Boolean

Event ID 12: Found preferred Media Source clsid clsid for Selector.

#
Channel
MediaFoundationPlatform
Task
PluginManager

Message #

Found preferred Media Source clsid %1 for %2.

Fields #

NameDescription
clsid GUID
Selector UnicodeString

Event ID 13: Did not find preferred Media Source for Selector.

#
Channel
MediaFoundationPlatform
Task
PluginManager

Message #

Did not find preferred Media Source for %1.

Fields #

NameDescription
Selector UnicodeString

Event ID 14: Query Media Source clsid clsid do not use: Disabled.

#
Channel
MediaFoundationPlatform
Task
PluginManager

Message #

Query Media Source clsid %1 do not use: %2.

Fields #

NameDescription
clsid GUID
Disabled Boolean

Event ID 15: Registering local MFT(MFTName).

#
Channel
MediaFoundationPlatform
Task
PluginManager

Message #

Registering local MFT(%1).

Fields #

NameDescription
MFTName UnicodeString

Event ID 16: Unregistering local MFT(MFTName).

#
Channel
MediaFoundationPlatform
Task
PluginManager

Message #

Unregistering local MFT(%1).

Fields #

NameDescription
MFTName UnicodeString

Event ID 17: Enumerating local MFT(MFTName).

#
Channel
MediaFoundationPlatform
Task
PluginManager

Message #

Enumerating local MFT(%1).

Fields #

NameDescription
MFTName UnicodeString

Event ID 18: MF_MFT_Hardware_EnumerationStart

#
Channel
MediaFoundationDeviceProxy
Task
MF_MFT_Hardware_Enumeration
Opcode
Start

Fields #

NameDescription
Category GUID

Event ID 19: MF_MFT_Hardware_Enumeration

#
Channel
MediaFoundationDeviceProxy
Task
MF_MFT_Hardware_Enumeration

Fields #

NameDescription
LinkName UnicodeString
FriendlyName UnicodeString

Event ID 20: MF_MFT_Hardware_EnumerationStop

#
Channel
MediaFoundationDeviceProxy
Task
MF_MFT_Hardware_Enumeration
Opcode
Stop

Fields #

NameDescription
Category GUID

Event ID 21: Configuration: dwType = dwType dwConfig=dwConfig.

#
Channel
MediaFoundationPlatform
Task
OptimizationFlags
Opcode
Start

Message #

Configuration: dwType = %1 dwConfig=%2

Fields #

NameDescription
dwType UInt32
dwConfig UInt32

Event ID 100: MFStartup returned hr.

#
Channel
MediaFoundationPlatform
Level
Informational
Task
MediaFoundationPlatform
Opcode
Start

Message #

MFStartup returned %1

Fields #

NameDescription
hr HexInt32

Example Event #

{
  "system": {
    "channel": "MediaFoundationPlatform",
    "computer": "10.2.10.21",
    "correlation": {},
    "event_id": 100,
    "event_record_id": 0,
    "event_source_name": "",
    "execution": {
      "process_id": 10776,
      "thread_id": 5912
    },
    "guid": "",
    "keywords": 0,
    "level": 4,
    "opcode": 1,
    "provider": "Microsoft-Windows-MediaFoundation-Platform",
    "security": {
      "user_id": ""
    },
    "task": 0,
    "time_created": "2026-07-22 02:10:39.401Z",
    "version": 0
  },
  "event_data": {
    "hr": "00000000"
  },
  "message": ""
}

Event ID 101: MFShutdown Start

#
Channel
MediaFoundationPlatform
Task
MediaFoundationPlatformShutdown
Opcode
Start

Event ID 102: MFShutdown Stop - return code hr.

#
Channel
MediaFoundationPlatform
Task
MediaFoundationPlatformShutdown
Opcode
Stop

Message #

MFShutdown Stop - return code %1

Fields #

NameDescription
hr HexInt32

Event ID 103: MFGetConfigurationKey Type Type Key KeyName Result lResult.

#
Channel
MediaFoundationPlatform
Level
Informational
Task
MediaFoundationGetConfigurationKey

Message #

MFGetConfigurationKey Type %1 Key %2 Result %3

Fields #

NameDescription
Type Int32
KeyName UnicodeString
lResult Int32

Example Event #

{
  "system": {
    "channel": "MediaFoundationPlatform",
    "computer": "10.2.10.21",
    "correlation": {},
    "event_id": 103,
    "event_record_id": 0,
    "event_source_name": "",
    "execution": {
      "process_id": 10776,
      "thread_id": 5912
    },
    "guid": "",
    "keywords": 0,
    "level": 4,
    "opcode": 0,
    "provider": "Microsoft-Windows-MediaFoundation-Platform",
    "security": {
      "user_id": ""
    },
    "task": 0,
    "time_created": "2026-07-22 02:10:39.400Z",
    "version": 0
  },
  "event_data": {
    "KeyName": "SOFTWARE\\Microsoft\\Windows Media Foundation\\Platform",
    "Type": 0,
    "lResult": 0
  },
  "message": ""
}

Event ID 104: MFGetConfigurationValueDWORD Type Type Key KeyName ValueName ValueName Result lResult QuerySize QuerySize ValueResult ValueDWORD.

#
Channel
MediaFoundationPlatform
Level
Informational
Task
MediaFoundationGetConfigurationValueDWORD

Message #

MFGetConfigurationValueDWORD Type %1 Key %2 ValueName %3 Result %4 QuerySize %5 ValueResult %6

Fields #

NameDescription
Type Int32
KeyName UnicodeString
ValueName UnicodeString
lResult Int32
QuerySize Boolean
ValueDWORD UInt32

Example Event #

{
  "system": {
    "channel": "MediaFoundationPlatform",
    "computer": "10.2.10.21",
    "correlation": {},
    "event_id": 104,
    "event_record_id": 0,
    "event_source_name": "",
    "execution": {
      "process_id": 10776,
      "thread_id": 5912
    },
    "guid": "",
    "keywords": 0,
    "level": 4,
    "opcode": 0,
    "provider": "Microsoft-Windows-MediaFoundation-Platform",
    "security": {
      "user_id": ""
    },
    "task": 0,
    "time_created": "2026-07-22 02:10:39.401Z",
    "version": 0
  },
  "event_data": {
    "KeyName": "Platform\\CallStackTracingEnabled",
    "QuerySize": false,
    "Type": 0,
    "ValueDWORD": 0,
    "ValueName": "CallStackTracingEnabled",
    "lResult": 2
  },
  "message": ""
}

Event ID 105: MFGetConfigurationValueString Type Type Key KeyName ValueName ValueName Result lResult QuerySize QuerySize ValueResult ValueString.

#
Channel
MediaFoundationPlatform
Task
MediaFoundationGetConfigurationValueString

Message #

MFGetConfigurationValueString Type %1 Key %2 ValueName %3 Result %4 QuerySize %5 ValueResult %6

Fields #

NameDescription
Type Int32
KeyName UnicodeString
ValueName UnicodeString
lResult Int32
QuerySize Boolean
ValueString UnicodeString

Event ID 200: Source Resolver Context(Context) Resolve url flags hr.

#
Channel
MediaFoundationPlatform
Task
MediaFoundationSourceResolver
Opcode
Start

Message #

Source Resolver Context(%1) Resolve %2 flags %3

Fields #

NameDescription
Context Pointer
url UnicodeString
hr HexInt32

Event ID 201: Source Resolver Context(Context) Trying Scheme Handler clsid.

#
Channel
MediaFoundationPlatform
Task
MediaFoundationSourceResolver
Opcode
Start

Message #

Source Resolver Context(%1) Trying Scheme Handler %2

Fields #

NameDescription
Context Pointer
clsid UnicodeString

Event ID 202: Source Resolver Context(Context) Trying Byte Scheme Handler CLSID(clsid).

#
Channel
MediaFoundationPlatform
Task
MediaFoundationSourceResolver

Message #

Source Resolver Context(%1) Trying Byte Scheme Handler CLSID(%2)

Fields #

NameDescription
Context Pointer
clsid UnicodeString

Event ID 203: Source Resolver Context(Context) SchemeHandler Result hr.

#
Channel
MediaFoundationPlatform
Task
MediaFoundationSourceResolver

Message #

Source Resolver Context(%1) SchemeHandler Result %2

Fields #

NameDescription
Context Pointer
hr HexInt32

Event ID 204: Source Resolver Context(Context) Byte stream Handler Result hr.

#
Channel
MediaFoundationPlatform
Task
MediaFoundationSourceResolver

Message #

Source Resolver Context(%1) Byte stream Handler Result %2

Fields #

NameDescription
Context Pointer
hr HexInt32

Event ID 205: Source Resolver Context(Context) Resolving url returned hr.

#
Channel
MediaFoundationPlatform
Task
MediaFoundationSourceResolver
Opcode
Stop

Message #

Source Resolver Context(%1) Resolving %2 returned %3

Fields #

NameDescription
Context Pointer
url UnicodeString
hr HexInt32

Event ID 206: TraceFailure logger (Context) line Line result hr function function.

#
Channel
MediaFoundationPlatform
Task
MediaFoundationTraceFailure

Message #

TraceFailure logger (%1) line %2 result %3 function %4

Fields #

NameDescription
Context Pointer
Line Int32
hr HexInt32
function AnsiString

Event ID 207: ByteStreamOnInputStream_Read_Start stream (stream) ptr offset length length.

#
Channel
MediaFoundationPlatform
Task
MediaFoundationByteStreamOnInputStream_Read
Opcode
Start

Message #

ByteStreamOnInputStream_Read_Start stream (%1) ptr %2 length %3

Fields #

NameDescription
stream Pointer
offset Int64
length Int32
buffer Pointer

Event ID 208: ByteStreamOnInputStream_Read_Stop stream (stream) ptr length length buffer hr hr.

#
Channel
MediaFoundationPlatform
Task
MediaFoundationByteStreamOnInputStream_Read
Opcode
Stop

Message #

ByteStreamOnInputStream_Read_Stop stream (%1) ptr %2 length %3 hr %4

Fields #

NameDescription
stream Pointer
length Int32
buffer Pointer
hr HexInt32

Event ID 300: MFTEnumEx flags flags, category Category for input type (inputType,inputSubtype), output type (outputType,outputSubtype).

#
Channel
MediaFoundationPlatform
Task
MediaFoundationMFTEnum
Opcode
Start

Message #

MFTEnumEx flags %1, category %2 for input type (%3,%4), output type (%5,%6)

Fields #

NameDescription
flags HexInt32
Category GUID
inputType GUID
inputSubtype GUID
outputType GUID
outputSubtype GUID

Event ID 301: Found matching software MFT clsid.

#
Channel
MediaFoundationPlatform
Task
MediaFoundationMFTEnum

Message #

Found matching software MFT %1

Fields #

NameDescription
clsid UnicodeString

Event ID 302: Found Local MFT string.

#
Channel
MediaFoundationPlatform
Task
MediaFoundationMFTEnum

Message #

Found Local MFT %1

Fields #

NameDescription
string UnicodeString

Event ID 303: Found Hardware MFT string.

#
Channel
MediaFoundationPlatform
Task
MediaFoundationMFTEnum

Message #

Found Hardware MFT %1

Fields #

NameDescription
string UnicodeString

Event ID 304: MFTEnumEx returned code hr, found localMFTs local MFTs, softwareMFTs software MFTs, hardwareMFTs hardware MFTs, deviceRegHardwareMFTs device reg hardware MFTs, and packagedMFTs packaged MFTs.

#
Channel
MediaFoundationPlatform
Task
MediaFoundationMFTEnum
Opcode
Stop

Message #

MFTEnumEx returned code %1, found %2 local MFTs, %3 software MFTs, %4 hardware MFTs, %5 device reg hardware MFTs, and %6 packaged MFTs

Fields #

NameDescription
hr HexInt32
localMFTs UInt32
softwareMFTs UInt32
hardwareMFTs UInt32
deviceRegHardwareMFTs UInt32
packagedMFTs UInt32

Event ID 305: MFTEnum2 flags flags, category Category for input type (inputType,inputSubtype), output type (outputType,outputSubtype), LUID set: luidSet.

#
Channel
MediaFoundationPlatform
Task
MediaFoundationMFTEnum
Opcode
Start

Message #

MFTEnum2 flags %1, category %2 for input type (%3,%4), output type (%5,%6), LUID set: %7

Fields #

NameDescription
flags HexInt32
Category GUID
inputType GUID
inputSubtype GUID
outputType GUID
outputSubtype GUID
luidSet Boolean

Event ID 306: MFTEnum2 returned code hr, found numMFTs MFTs matching adapter with vendor ID adapterVendorId, device ID adapterDeviceId, SubSys ID adapterSubSysId, Revision adapterRevision.

#
Channel
MediaFoundationPlatform
Task
MediaFoundationMFTEnum
Opcode
Stop

Message #

MFTEnum2 returned code %1, found %2 MFTs matching adapter with vendor ID %3, device ID %4, SubSys ID %5, Revision %6

Fields #

NameDescription
hr HexInt32
numMFTs UInt32
adapterVendorId HexInt32
adapterDeviceId HexInt32
adapterSubSysId HexInt32
adapterRevision HexInt32

Event ID 2500: MFGetMFTMerit Enter

#
Channel
MediaFoundationPlatform
Task
MediaFoundationMFTEnum
Opcode
Start

Event ID 2501: MFGetMFTMerit Leave Merit(Merit) Return Code(hr).

#
Channel
MediaFoundationPlatform
Task
MediaFoundationMFTEnum
Opcode
Stop

Message #

MFGetMFTMerit Leave Merit(%1) Return Code(%2)

Fields #

NameDescription
Merit HexInt32
hr HexInt32

Event ID 2502: MFGetMFTMerit: StartInitialization returned hr.

#
Channel
MediaFoundationPlatform
Task
MediaFoundationMFTEnum

Message #

MFGetMFTMerit:  StartInitialization returned %1

Fields #

NameDescription
hr HexInt32

Event ID 2503: MFGetMFTMerit: Validate Certificate returned hr.

#
Channel
MediaFoundationPlatform
Task
MediaFoundationMFTEnum

Message #

MFGetMFTMerit:  Validate Certificate returned %1

Fields #

NameDescription
hr HexInt32

Event ID 2504: MFGetMFTMerit: EndInitialization returned hr.

#
Channel
MediaFoundationPlatform
Task
MediaFoundationMFTEnum

Message #

MFGetMFTMerit:  EndInitialization returned %1

Fields #

NameDescription
hr HexInt32

Event ID 2505: MFGetMFTMerit: GetInformation returned hr.

#
Channel
MediaFoundationPlatform
Task
MediaFoundationMFTEnum

Message #

MFGetMFTMerit:  GetInformation returned %1

Fields #

NameDescription
hr HexInt32

Provenance

ETW provider GUID bc97b970-d001-482f-8745-b8d7d5759f99

Defined in mfplat.dll, which carries the event manifest.

  • WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.1, captured 2026-06-02 — Manifest XML pack, 1.9 MB
  • Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.4768, captured 2026-06-02 — Manifest XML pack, 2.0 MB