Microsoft-Windows-NDIS

EventTitleChannelSampleRule
10000Aborting Request Request on Filter LowerIf.DiagnosticNN
10001Aborting Request Request on Miniport LowerIf.DiagnosticNN
10002Add Device Miniport DeviceName.DiagnosticYN
10003Add Device Failed ErrorCode.DiagnosticNN
10004Add PnP Device: Add_PnP_Device.DiagnosticYN
10005Allocate Adapter Channel Failed ErrorCode.DiagnosticNN
10006Initialize Binding - Protocol: IfGuid, Adapter: Adapter, Result: IfIndex.DiagnosticYN
10007Miniport IfGuid, Calling miniport reset.DiagnosticNN
10008Filter IfGuid, Aborting Request Request.DiagnosticNN
10009Miniport IfGuid, Successfully canceled wake irp.DiagnosticNN
10010Miniport IfGuid, Aborting Request Request.DiagnosticNN
10011Miniport IfGuid, Failed to set the new information on the miniport.DiagnosticNN
10012Compartment change notification, compartment CompartmentId.DiagnosticNN
10013Interface change notification, interface IfType IfType, NetLuid index NetLuid.DiagnosticYN
10014Interface change notification, interface IfType IfType, NetLuid index NetLuid.DiagnosticYN
10015Network change notification, network NetworkId.DiagnosticNN
10016Request Clearing Processing Request Miniport IfGuid.DiagnosticYN
10017Protocol ProtocolName is closing Miniport IfGuid.DiagnosticNN
10018Completing Request Request to Filter IfGuid.DiagnosticNN
10019Miniport IfGuid, WaitWakeIrp ReferenceContext.DiagnosticNN
10020Miniport IfGuid, activating default port.DiagnosticNN
10021Miniport IfGuid, deactivating default port.DiagnosticNN
10022Failed to deregister interface IfBlock Context.DiagnosticNN
10023DevicePowerStateChange Miniport IfGuid, Going to device state State.DiagnosticNN
10024Dispatch PnP Irp Miniport IfGuid, MinorFunction: IrpMinorFunction.DiagnosticYN
10025Dispatch WMI Irp Miniport IfGuid, MinorFunction IrpMinorFunction.DiagnosticNN
10026Miniport IfGuid, Failed to execute WMI method (Context) on the miniport.DiagnosticNN
10027Failed to indicate filter arrivalDiagnosticNN
10028Miniport MiniportIfGuid, Filter FilterIfGuid changed media type from …DiagnosticNN
10029Filter Registration Failed FilterName - Reason.OperationalNN
10030Failed to indicate filter removalDiagnosticNN
10031Failed to indicate adapter removalDiagnosticNN
10032Miniport IfGuid, InitializeAdapter status - Reason (State).DiagnosticYN
10033Miniport IfGuid, InitializeAdapter error - Reason (State).OperationalNN
10034Could not read Bind/Export for DeviceName: ErrorCode.DiagnosticNN
10035Miniport State, Not a system state!DiagnosticNN
10037IoSetDeviceInterfaceState failed: Miniport IfGuid, Status Error.DiagnosticNN
10038IoWMIWriteEvent failed ErrorCode.DiagnosticNN
10039DeviceObject Context, IRP_MN_SET_POWER failed!DiagnosticNN
10040Keeping the fake handlers on Filter IfGuid, State flags StateFlags.DiagnosticNN
10041Keeping the fake handlers on Miniport IfGuid, State flags StateFlags.DiagnosticNN
10042Open Context is already getting unbind.DiagnosticNN
10043Miniport IfGuid is Action.DiagnosticNN
10044Miniport IfGuid - MiniportInitialize handler failed, Status Error.DiagnosticNN
10045Miniport IfGuid, Ethernet Address MacAddress.DiagnosticNN
10046Miniport IfGuid, DeviceState[State].DiagnosticNN
10047Miniport IfGuid, Powering up the Miniport.DiagnosticNN
10048Miniport IfGuid, SystemPowerState[SystemState] DevicePowerState[DeviceState].DiagnosticNN
10049Miniport IfGuid, SystemState[State].DiagnosticNN
10050Failed to restart miniport IfGuid.OperationalNN
10052Error querying Oid : Status.DiagnosticNN
10053Failing open because the miniport is not started, Miniport IfGuid, Open …DiagnosticNN
10054Port Activation Failed Miniport IfGuid Reason.DiagnosticNN
10055Miniport IfGuid, Disabling wake-up on the miniport.DiagnosticNN
10056Miniport IfGuid, Failed to power the device down.OperationalNN
10057Miniport IfGuid, failed to power down but we are not able to reinitialize it.DiagnosticNN
10058Miniport IfGuid, Halt the miniport.DiagnosticNN
10059Miniport IfGuid, System is either entering hibernate or shutting down.DiagnosticNN
10060DeviceObject Context, Going to system power state State.DiagnosticNN
10061Miniport IfGuid is not started yet.DiagnosticNN
10062Miniport IfGuid is being removed.DiagnosticNN
10063Miniport IfGuid, MagicPacket and pattern match are not enabled.DiagnosticNN
10064Miniport IfGuid, Place legacy or PM disabled device in D3.DiagnosticNN
10065Miniport IfGuid, SystemState SystemState, DeviceState DeviceState.DiagnosticNN
10066Miniport IfGuid, shutting down.OperationalNN
10067Miniport IfGuid, Device power wake is not enabled (ReferenceContext).DiagnosticNN
10068Miniport IfGuid, Waking up the device.OperationalNN
10069BIND (Layer) ProtocolName to DeviceName.OperationalNN
10070UNBIND(Layer) ProtocolName to DeviceName.OperationalNN
10071Miniport IfGuid, IRP_MN_QUERY_PNP_DEVICE_STATE device failed.DiagnosticNN
10072Miniport IfGuid, Bus Driver returned ReferenceContext for QueryPower.DiagnosticNN
10073Miniport IfGuid, Bus Driver returned ReferenceContext for QueryPower.DiagnosticNN
10074Miniport IfGuid, failed power Oid Oid, Set = Set with error Error.DiagnosticNN
10075ndisReferenceProtocolByName failed ErrorCode.DiagnosticNN
10076Miniport IfGuid failed to register for interrupts.DiagnosticNN
10077DriverObject Context, Miniport Driver should register both a DirectRequest and …DiagnosticNN
10078SendPacketCompleteToOpen Open OpenRef, Packet Packet.DiagnosticNN
10079ndisSetEnableWakeUp CompletedDiagnosticNN
10080SetMiniportEthMulticastList Failed Miniport IfGuid, Request Context.DiagnosticNN
10081SetMiniportRSSCaps Failed Miniport IfGuid, Request Context, Status Error.DiagnosticNN
10082SetOpenEthAddDeleteMulticast Failed, Miniport = IfGuid, Open = Context, Status = …DiagnosticNN
10083SetOpenEthMulticastList failed - Miniport IfGuid, Open Context.DiagnosticNN
10084SetOpenFunctional - Invalid media typeDiagnosticNN
10085SetOpenGroupAddress - Invalid media typeDiagnosticNN
10086SetOpenRSSCaps: Miniport IfGuid, Open Context, Status Error.DiagnosticNN
10087Miniport IfGuid, Going to system power state State.DiagnosticNN
10088Transport Transport failed the PnP event: PnPEvent for Miniport IfGuid with …OperationalNN
10089Miniport IfGuid, This version of NDIS does not support Arcnet, FDDI, IP1394, or …DiagnosticNN
10090ProtocolName, Reason.DiagnosticNN
10091Miniport IfGuid, Wake irp was complete due to wake event.DiagnosticNN
10092WaitWakeIrpFailed Miniport IfGuid, WAIT_WAKE irp failed or cancelled.DiagnosticNN
10093Miniport IfGuid woke up the system.OperationalNN
10094Error Log Entry : Miniport IfGuid (AdapterName) Error Error.DiagnosticNN
10095Aborting Request Request.DiagnosticNN
10096Port Deactivation Failed Miniport IfGuid Reason.DiagnosticNN
10097Miniport IfGuid, PoRequestPowerIrp for device state returned ReferenceContext.DiagnosticNN
10098Miniport IfGuid, failed query power.DiagnosticNN
10099DevicePowerOn failed Miniport IfGuid, status Error.DiagnosticNN
10100Power policy - Unable to enter requested stateDiagnosticNN
10101Miniport IfGuid: Oid Oid, Completed by NDIS on behalf of miniport with Status …DiagnosticYN
10102Completing Request Request to Miniport IfGuid.DiagnosticNN
10103Filter IfGuid entering state State.DiagnosticNN
10104Miniport IfGuid, NDIS_STATUS_MEDIA_CONNECT, Flags: Flags, PnpFlags PnPFlags, …DiagnosticNN
10105Miniport IfGuid, NDIS_STATUS_MEDIA_DISCONNECT, Flags: Flags, PnpFlags PnPFlags, …DiagnosticNN
10106Miniport OperationalStatusFlags, NDIS_STATUS_OPER_STATUS, OperationalStatus: …DiagnosticYN
10107Miniport OperationalStatusFlags, NDIS_STATUS_OPER_STATUS, OperationalStatus: …DiagnosticNN
10108Miniport IfGuid, NDIS_STATUS_NETWORK_CHANGE, Change Type: ChangeType.DiagnosticNN
10109Filter IfGuid, Aborting Request RequestType.DiagnosticNN
10110Miniport IfGuid, Aborting Request RequestType.DiagnosticNN
10111Completing Request RequestType to Filter IfGuid.DiagnosticYN
10112Completing Request RequestType to Miniport IfGuid.DiagnosticYN
10113Aborting Request RequestType.DiagnosticNN
10114Aborting Request RequestType on Filter LowerIf.DiagnosticNN
10115Aborting Request RequestType on Miniport LowerIf.DiagnosticNN
10200DPC/OtherDispatchRoutine StartDiagnosticNN
10201DPC/OtherDispatchRoutine EndDiagnosticNN
10202Queued Receive Indication StartDiagnosticNN
10203Queued Receive Indication EndDiagnosticNN
10204Miniport Duration on processor Individual has an RST limit change from …DiagnosticNN
10300The network adapter is idle and can be suspended now.DiagnosticNN
10301The network adapter declined to enter a suspended state.DiagnosticNN
10302The network adapter must be resumed.DiagnosticNN
10303NIC Active state is acquired.DiagnosticNN
10304NIC Active state is released.DiagnosticNN
10305The network adapter indicated a wake signal.DiagnosticNN
10306Working power state is requested for network adapter.DiagnosticNN
10307Working power request is completed for network adapter.DiagnosticNN
10308Low power state is requested for network adapter.DiagnosticNN
10309Low power request is completed for network adapter.DiagnosticNN
10310Wait/Wake IRP is completed for network adapter.DiagnosticNN
10311Miniport AdapterName, IfGuid, had event MiniportEventEnum.DiagnosticYN
10312Filter IfGuid entering state State (FriendlyName: FilterFriendlyName).DiagnosticYN
10313Entering Connected StandbyDiagnosticNN
10314Exiting Connected Standby.DiagnosticNN
10315Miniport IfLuid: CS active ActiveTime seconds, PowerTransitionCount power …DiagnosticNN
10316Component ComponentId: CS active ActiveTime seconds, Miniport InterfaceLuid.DiagnosticNN
10317Miniport AdapterName, IfGuid, had event MiniportEventEnum.SystemNN
10320Refcount rundown for miniport NetLuid will follow.DiagnosticNN
10321Refcount rundown for miniport NetLuid: component ComponentId has refcount …DiagnosticNN
10322Refcount rundown for miniport NetLuid: stop flags StopFlags Rundown complete.DiagnosticNN
10323Power transition for Miniport IfLuid in CS (PowerStateFrom to PowerStateTo).DiagnosticNN
10324Miniport PDO information for SleepstudyDiagnosticNN
10325Miniport IfGuid indicated a Wake Packet WakePacketPayload.DiagnosticNN
10400The network interface "AdapterName" has begun resetting.SystemYN
10401Timestamping change notification, interface NetLuid NetLuid.DiagnosticNN
10402Miniport IfGuid Capabilities: Flags Flags, SupportedWoLPatterns …DiagnosticNN
10500HAL's SupportFlags(value=SupportFlags) indicates DMA hybrid passthrough is not …SystemNN
10501A NDIS object (type=ObjectType, handle=ObjectHandle) registers hybrid …SystemNN
10502AzDmaV3 version NdisAllocateSharedMemory exceeds threshold: State State, …SystemNN
10503Enabling Hybrid DMA for miniport stack MiniportStack because of back compat …SystemNN
10504Enabled Hybrid DMA for NDIS Generic Object because of back compat configuration.SystemNN
10505Failed to enable Hybrid DMA for NDIS Generic Object required by back compat …SystemNN
10506NDIS requested Hybrid DMA, but the DMA_ADAPTER does not have Hybrid Passthrough …SystemNN
10507Unable to find parent stack PDO to enable CX-3 NDIS DMA Cache compatibility.SystemNN
10600task_010600OperationalYN
10601task_010601OperationalYN
10602task_010602OperationalYN
10603task_010603OperationalYN
60001Error: Error Location: Location Context: Context.DiagnosticNN
60002Warning: Warning Location: Location Context: Context.DiagnosticNN
60003Transitioned to State: NextState Context: Context.DiagnosticNN
60004Updated Context: Updated_Context Update Reason: Update_Reason.DiagnosticNN
60101SourceAddress: SourceAddress SourcePort: SourcePort DestinationAddress: …DiagnosticNN
60102SourceAddress: SourceAddress SourcePort: SourcePort DestinationAddress: …DiagnosticNN
60103Interface Guid: Interface_Guid IfIndex: IfIndex Interface Luid: Interface_Luid …DiagnosticNN

Event ID 10000: Aborting Request Request on Filter LowerIf.

#
Channel
Diagnostic
Task
Request

Message #

Aborting Request %4 on Filter %5

Fields #

NameDescription
IfGuid GUID
IfIndex UInt32
NetLuid UInt64
Request Pointer
LowerIf GUID

Event ID 10001: Aborting Request Request on Miniport LowerIf.

#
Channel
Diagnostic
Task
Request

Message #

Aborting Request %4 on Miniport %5

Fields #

NameDescription
IfGuid GUID
IfIndex UInt32
NetLuid UInt64
Request Pointer
LowerIf GUID

Event ID 10002: Add Device Miniport DeviceName.

#
Channel
Diagnostic
Level
Informational
Task
PnP

Message #

Add Device Miniport %1

Fields #

NameDescription
DeviceName UnicodeString

Example Event #

{
  "system": {
    "channel": "Microsoft-Windows-NDIS/Diagnostic",
    "computer": "10.2.10.21",
    "correlation": {},
    "event_id": 10002,
    "event_record_id": 0,
    "event_source_name": "",
    "execution": {
      "process_id": 4,
      "thread_id": 10892
    },
    "guid": "",
    "keywords": 0,
    "level": 4,
    "opcode": 0,
    "provider": "Microsoft-Windows-NDIS",
    "security": {
      "user_id": ""
    },
    "task": 0,
    "time_created": "2026-07-21 22:22:45.068Z",
    "version": 0
  },
  "event_data": {
    "DeviceName": "Hyper-V Virtual Switch Extension Adapter #2"
  },
  "message": ""
}

Event ID 10003: Add Device Failed ErrorCode.

#
Channel
Diagnostic
Task
PnP

Message #

Add Device Failed %1

Fields #

NameDescription
ErrorCode UInt32
Location UInt32
Context UInt32

Event ID 10004: Add PnP Device: Add_PnP_Device.

#
Channel
Diagnostic
Level
Informational
Task
PnP

Message #

Add PnP Device: %1

Fields #

NameDescription
DeviceName UnicodeString

Example Event #

{
  "system": {
    "channel": "Microsoft-Windows-NDIS/Diagnostic",
    "computer": "10.2.10.21",
    "correlation": {},
    "event_id": 10004,
    "event_record_id": 0,
    "event_source_name": "",
    "execution": {
      "process_id": 4,
      "thread_id": 10892
    },
    "guid": "",
    "keywords": 0,
    "level": 4,
    "opcode": 0,
    "provider": "Microsoft-Windows-NDIS",
    "security": {
      "user_id": ""
    },
    "task": 0,
    "time_created": "2026-07-21 22:22:45.064Z",
    "version": 0
  },
  "event_data": {
    "DeviceName": "\\Device\\{41ec8be7-277c-4bb3-82d0-481f30631895}"
  },
  "message": ""
}

Event ID 10005: Allocate Adapter Channel Failed ErrorCode.

#
Channel
Diagnostic
Task
Init

Message #

Allocate Adapter Channel Failed %1

Fields #

NameDescription
ErrorCode UInt32
Location UInt32
Context UInt32

Event ID 10006: Initialize Binding - Protocol: IfGuid, Adapter: Adapter, Result: IfIndex.

#
Channel
Diagnostic
Also via
realtime ETW trace
Level
Informational
Task
Bind
Opcode
win:Info

Message #

Initialize Binding - Protocol: %4, Adapter: %1, Result: %5

Fields #

NameDescription
IfGuid GUID
IfIndex UInt32
NetLuid UInt64
ProtocolName UnicodeString
Status HexInt32NTSTATUS reference

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-NDIS",
    "guid": "{CDEAD503-17F5-4A3E-B7AE-DF8CC2902EB9}",
    "event_source_name": "",
    "event_id": 10006,
    "version": 0,
    "level": 4,
    "task": 4,
    "opcode": 0,
    "keywords": "0x4000000000000008",
    "time_created": "2026-06-02T05:29:07.638+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{E47DFBE0-FE90-4385-8C84-1A825F85A4C2}"
    },
    "execution": {
      "process_id": 13372,
      "thread_id": 18092
    },
    "channel": "ETW Trace",
    "computer": "JD-DC01-2022",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "IfGuid": "{E47DFBE0-FE90-4385-8C84-1A825F85A4C2}",
    "IfIndex": 16,
    "NetLuid": 36873771788795904,
    "ProtocolName": "RDMANDK",
    "Status": "01000100"
  },
  "message": "Bind"
}

Event ID 10007: Miniport IfGuid, Calling miniport reset.

#
Channel
Diagnostic
Task
Init

Message #

Miniport %1, Calling miniport reset

Fields #

NameDescription
IfGuid GUID
IfIndex UInt32
IfLuid UInt64
ReferenceContext UInt32

Event ID 10008: Filter IfGuid, Aborting Request Request.

#
Channel
Diagnostic
Task
Request

Message #

Filter %1, Aborting Request %4

Fields #

NameDescription
IfGuid GUID
IfIndex UInt32
NetLuid UInt64
Request Pointer
Status HexInt32NTSTATUS reference
Location UInt32

Event ID 10009: Miniport IfGuid, Successfully canceled wake irp.

#
Channel
Diagnostic
Task
Power

Message #

Miniport %1, Successfully canceled wake irp

Fields #

NameDescription
IfGuid GUID
IfIndex UInt32
IfLuid UInt64
ReferenceContext UInt32

Event ID 10010: Miniport IfGuid, Aborting Request Request.

#
Channel
Diagnostic
Task
Request

Message #

Miniport %1, Aborting Request %4

Fields #

NameDescription
IfGuid GUID
IfIndex UInt32
NetLuid UInt64
Request Pointer
Status HexInt32NTSTATUS reference
Location UInt32

Event ID 10011: Miniport IfGuid, Failed to set the new information on the miniport.

#
Channel
Diagnostic
Task
WMI

Message #

Miniport %1, Failed to set the new information on the miniport

Fields #

NameDescription
IfGuid GUID
IfIndex UInt32
NetLuid UInt64
Error UInt32
Location UInt32
Context UInt32

Event ID 10012: Compartment change notification, compartment CompartmentId.

#
Channel
Diagnostic
Task
Interface

Message #

Compartment change notification, compartment %1

Fields #

NameDescription
CompartmentId UInt32

Event ID 10013: Interface change notification, interface IfType IfType, NetLuid index NetLuid.

#
Channel
Diagnostic
Level
Informational
Task
Interface

Message #

Interface change notification, interface IfType %1, NetLuid index %2

Fields #

NameDescription
IfType UInt32
NetLuid UInt64
StructType UInt32
ParameterLen UInt32
ParameterOffset UInt32

Example Event #

{
  "system": {
    "channel": "Microsoft-Windows-NDIS/Diagnostic",
    "computer": "10.2.10.21",
    "correlation": {},
    "event_id": 10013,
    "event_record_id": 0,
    "event_source_name": "",
    "execution": {
      "process_id": 4,
      "thread_id": 10892
    },
    "guid": "",
    "keywords": 0,
    "level": 4,
    "opcode": 0,
    "provider": "Microsoft-Windows-NDIS",
    "security": {
      "user_id": ""
    },
    "task": 0,
    "time_created": "2026-07-21 22:22:45.069Z",
    "version": 0
  },
  "event_data": {
    "IfType": 6,
    "NetLuid": 32774,
    "ParameterLen": 4,
    "ParameterOffset": 16,
    "StructType": 0
  },
  "message": ""
}

Event ID 10014: Interface change notification, interface IfType IfType, NetLuid index NetLuid.

#
Channel
Diagnostic
Also via
realtime ETW trace
Level
Informational
Task
Interface
Opcode
win:Info

Message #

Interface change notification, interface IfType %1, NetLuid index %2

Fields #

NameDescription
IfType UInt32
NetLuid UInt64

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-NDIS",
    "guid": "{CDEAD503-17F5-4A3E-B7AE-DF8CC2902EB9}",
    "event_source_name": "",
    "event_id": 10014,
    "version": 0,
    "level": 4,
    "task": 7,
    "opcode": 0,
    "keywords": "0x4000000000000040",
    "time_created": "2026-06-02T05:29:07.633+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{CDEAD503-17F5-4A3E-B7AE-DF8CC2902EB9}"
    },
    "execution": {
      "process_id": 13372,
      "thread_id": 18092
    },
    "channel": "ETW Trace",
    "computer": "JD-DC01-2022",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "IfType": 131,
    "NetLuid": 3
  },
  "message": "Interface"
}

Event ID 10015: Network change notification, network NetworkId.

#
Channel
Diagnostic
Task
Interface

Message #

Network change notification, network %1

Fields #

NameDescription
NetworkId GUID

Event ID 10016: Request Clearing Processing Request Miniport IfGuid.

#
Channel
Diagnostic
Also via
realtime ETW trace
Level
Verbose
Task
Request
Opcode
win:Info

Message #

Request Clearing Processing Request Miniport %1

Fields #

NameDescription
IfGuid GUID
IfIndex UInt32
IfLuid UInt64
ReferenceContext UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-NDIS",
    "guid": "{CDEAD503-17F5-4A3E-B7AE-DF8CC2902EB9}",
    "event_source_name": "",
    "event_id": 10016,
    "version": 0,
    "level": 5,
    "task": 1,
    "opcode": 0,
    "keywords": "0x4000000000000001",
    "time_created": "2026-06-02T05:29:07.634+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{2A7BD48E-DDC6-4641-9F41-682F29F1D76C}"
    },
    "execution": {
      "process_id": 4,
      "thread_id": 12056
    },
    "channel": "ETW Trace",
    "computer": "JD-DC01-2022",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "IfGuid": "{2A7BD48E-DDC6-4641-9F41-682F29F1D76C}",
    "IfIndex": 4,
    "IfLuid": 1689399632855040,
    "ReferenceContext": 65537
  },
  "message": "Request"
}

Event ID 10017: Protocol ProtocolName is closing Miniport IfGuid.

#
Channel
Diagnostic
Task
Bind

Message #

Protocol %4 is closing Miniport %1

Fields #

NameDescription
IfGuid GUID
IfIndex UInt32
NetLuid UInt64
ProtocolName UnicodeString

Event ID 10018: Completing Request Request to Filter IfGuid.

#
Channel
Diagnostic
Task
Request

Message #

Completing Request %4 to Filter %1

Fields #

NameDescription
IfGuid GUID
IfIndex UInt32
NetLuid UInt64
Request Pointer
Status HexInt32NTSTATUS reference
Location UInt32

Event ID 10019: Miniport IfGuid, WaitWakeIrp ReferenceContext.

#
Channel
Diagnostic
Task
Power

Message #

Miniport %1, WaitWakeIrp %4

Fields #

NameDescription
IfGuid GUID
IfIndex UInt32
IfLuid UInt64
ReferenceContext UInt32

Event ID 10020: Miniport IfGuid, activating default port.

#
Channel
Diagnostic
Task
Port

Message #

Miniport %1, activating default port

Fields #

NameDescription
IfGuid GUID
IfIndex UInt32
IfLuid UInt64
ReferenceContext UInt32

Event ID 10021: Miniport IfGuid, deactivating default port.

#
Channel
Diagnostic
Task
Port

Message #

Miniport %1, deactivating default port

Fields #

NameDescription
IfGuid GUID
IfIndex UInt32
IfLuid UInt64
ReferenceContext UInt32

Event ID 10022: Failed to deregister interface IfBlock Context.

#
Channel
Diagnostic
Task
Interface

Message #

Failed to deregister interface IfBlock %3

Fields #

NameDescription
ErrorCode UInt32
Location UInt32
Context UInt32

Event ID 10023: DevicePowerStateChange Miniport IfGuid, Going to device state State.

#
Channel
Diagnostic
Task
Power

Message #

DevicePowerStateChange Miniport %1, Going to device state %5

Fields #

NameDescription
IfGuid GUID
IfIndex UInt32
NetLuid UInt64
Type HexInt32
State HexInt32

Event ID 10024: Dispatch PnP Irp Miniport IfGuid, MinorFunction: IrpMinorFunction.

#
Channel
Diagnostic
Level
Informational
Task
PnP

Message #

Dispatch PnP Irp Miniport %1, MinorFunction: %4

Fields #

NameDescription
IfGuid GUID
IfIndex UInt32
NetLuid UInt64
IrpMinorFunction UInt32

Example Event #

{
  "system": {
    "channel": "Microsoft-Windows-NDIS/Diagnostic",
    "computer": "10.2.10.21",
    "correlation": {},
    "event_id": 10024,
    "event_record_id": 0,
    "event_source_name": "",
    "execution": {
      "process_id": 4,
      "thread_id": 10892
    },
    "guid": "",
    "keywords": 0,
    "level": 4,
    "opcode": 0,
    "provider": "Microsoft-Windows-NDIS",
    "security": {
      "user_id": ""
    },
    "task": 0,
    "time_created": "2026-07-21 22:22:45.070Z",
    "version": 0
  },
  "event_data": {
    "IfGuid": "{41EC8BE7-277C-4BB3-82D0-481F30631895}",
    "IfIndex": 20,
    "IrpMinorFunction": 24,
    "NetLuid": 1689399716741120
  },
  "message": ""
}

Event ID 10025: Dispatch WMI Irp Miniport IfGuid, MinorFunction IrpMinorFunction.

#
Channel
Diagnostic
Task
WMI

Message #

Dispatch WMI Irp Miniport %1, MinorFunction %4

Fields #

NameDescription
IfGuid GUID
IfIndex UInt32
NetLuid UInt64
IrpMinorFunction UInt32

Event ID 10026: Miniport IfGuid, Failed to execute WMI method (Context) on the miniport.

#
Channel
Diagnostic
Task
WMI

Message #

Miniport %1, Failed to execute WMI method (%6) on the miniport

Fields #

NameDescription
IfGuid GUID
IfIndex UInt32
NetLuid UInt64
Error UInt32
Location UInt32
Context UInt32

Event ID 10027: Failed to indicate filter arrival

#
Channel
Diagnostic
Task
Init

Fields #

NameDescription
ErrorCode UInt32
Location UInt32
Context UInt32

Event ID 10028: Miniport MiniportIfGuid, Filter FilterIfGuid changed media type from OriginalMediaType to NewMediaType.

#
Channel
Diagnostic
Task
PnP

Message #

Miniport %1, Filter %4 changed media type from %7 to %8

Fields #

NameDescription
MiniportIfGuid GUID
MiniportIfIndex UInt32
MiniportNetLuid UInt64
FilterIfGuid GUID
FilterIfIndex UInt32
FilterNetLuid UInt64
OriginalMediaType HexInt32
NewMediaType HexInt32

Event ID 10029: Filter Registration Failed FilterName - Reason.

#
Channel
Operational
Task
Init

Message #

Filter Registration Failed %1 - %2

Fields #

NameDescription
FilterName UnicodeString
Reason UInt32

Event ID 10030: Failed to indicate filter removal

#
Channel
Diagnostic
Task
Init

Fields #

NameDescription
ErrorCode UInt32
Location UInt32
Context UInt32

Event ID 10031: Failed to indicate adapter removal

#
Channel
Diagnostic
Task
WMI

Fields #

NameDescription
IfGuid GUID
IfIndex UInt32
IfLuid UInt64
ReferenceContext UInt32

Event ID 10032: Miniport IfGuid, InitializeAdapter status - Reason (State).

#
Channel
Diagnostic
Level
Informational
Task
Init

Message #

Miniport %1, InitializeAdapter status - %4 (%5)

Fields #

NameDescription
IfGuid GUID
IfIndex UInt32
NetLuid UInt64
Reason UInt32
State HexInt32

Example Event #

{
  "system": {
    "channel": "Microsoft-Windows-NDIS/Diagnostic",
    "computer": "10.2.10.21",
    "correlation": {},
    "event_id": 10032,
    "event_record_id": 0,
    "event_source_name": "",
    "execution": {
      "process_id": 4,
      "thread_id": 4408
    },
    "guid": "",
    "keywords": 0,
    "level": 4,
    "opcode": 0,
    "provider": "Microsoft-Windows-NDIS",
    "security": {
      "user_id": ""
    },
    "task": 0,
    "time_created": "2026-07-21 22:22:45.071Z",
    "version": 0
  },
  "event_data": {
    "IfGuid": "{41EC8BE7-277C-4BB3-82D0-481F30631895}",
    "IfIndex": 20,
    "NetLuid": 1689399716741120,
    "Reason": 1,
    "State": "110001C0"
  },
  "message": ""
}

Event ID 10033: Miniport IfGuid, InitializeAdapter error - Reason (State).

#
Channel
Operational
Task
Init

Message #

Miniport %1, InitializeAdapter error - %4 (%5)

Fields #

NameDescription
IfGuid GUID
IfIndex UInt32
NetLuid UInt64
Reason UInt32
State HexInt32

Event ID 10034: Could not read Bind/Export for DeviceName: ErrorCode.

#
Channel
Diagnostic
Task
PnP

Message #

Could not read Bind/Export for %4: %1

Fields #

NameDescription
ErrorCode UInt32
Location UInt32
Context UInt32
DeviceName UnicodeString

Event ID 10035: Miniport State, Not a system state!

#
Channel
Diagnostic
Task
Power

Description

Miniport State, Not a system state! Type: NetLuid. State: Type.

Message #

Miniport %1, Not a system state! Type: %4. State: %5.

Fields #

NameDescription
IfGuid GUID
IfIndex UInt32
NetLuid UInt64
Type HexInt32
State HexInt32

Event ID 10037: IoSetDeviceInterfaceState failed: Miniport IfGuid, Status Error.

#
Channel
Diagnostic
Task
Bind

Message #

IoSetDeviceInterfaceState failed: Miniport %1, Status %4

Fields #

NameDescription
IfGuid GUID
IfIndex UInt32
NetLuid UInt64
Error UInt32
Location UInt32
Context UInt32

Event ID 10038: IoWMIWriteEvent failed ErrorCode.

#
Channel
Diagnostic
Task
WMI

Message #

IoWMIWriteEvent failed %1

Fields #

NameDescription
ErrorCode UInt32
Location UInt32
Context UInt32

Event ID 10039: DeviceObject Context, IRP_MN_SET_POWER failed!

#
Channel
Diagnostic
Task
Power

Message #

DeviceObject %3, IRP_MN_SET_POWER failed!

Fields #

NameDescription
ErrorCode UInt32
Location UInt32
Context UInt32

Event ID 10040: Keeping the fake handlers on Filter IfGuid, State flags StateFlags.

#
Channel
Diagnostic
Task
PnP

Message #

Keeping the fake handlers on Filter %1, State flags %4

Fields #

NameDescription
IfGuid GUID
IfIndex UInt32
NetLuid UInt64
StateFlags HexInt32

Event ID 10041: Keeping the fake handlers on Miniport IfGuid, State flags StateFlags.

#
Channel
Diagnostic
Task
PnP

Message #

Keeping the fake handlers on Miniport %1, State flags %4

Fields #

NameDescription
IfGuid GUID
IfIndex UInt32
NetLuid UInt64
StateFlags HexInt32

Event ID 10042: Open Context is already getting unbind.

#
Channel
Diagnostic
Task
Bind

Message #

Open %3 is already getting unbind

Fields #

NameDescription
ErrorCode UInt32
Location UInt32
Context UInt32

Event ID 10043: Miniport IfGuid is Action.

#
Channel
Diagnostic
Task
WorkItem

Message #

Miniport %1 is %4

Fields #

NameDescription
IfGuid GUID
IfIndex UInt32
NetLuid UInt64
Action UInt32

Event ID 10044: Miniport IfGuid - MiniportInitialize handler failed, Status Error.

#
Channel
Diagnostic
Task
Power

Message #

Miniport %1 - MiniportInitialize handler failed, Status %4

Fields #

NameDescription
IfGuid GUID
IfIndex UInt32
NetLuid UInt64
Error UInt32
Location UInt32
Context UInt32

Event ID 10045: Miniport IfGuid, Ethernet Address MacAddress.

#
Channel
Diagnostic
Task
PnP

Message #

Miniport %1, Ethernet Address %4

Fields #

NameDescription
IfGuid GUID
IfIndex UInt32
NetLuid UInt64
MacAddress Binary

Event ID 10046: Miniport IfGuid, DeviceState[State].

#
Channel
Diagnostic
Task
Power

Message #

Miniport %1, DeviceState[%5]

Fields #

NameDescription
IfGuid GUID
IfIndex UInt32
NetLuid UInt64
Type HexInt32
State HexInt32

Event ID 10047: Miniport IfGuid, Powering up the Miniport.

#
Channel
Diagnostic
Task
Power

Message #

Miniport %1, Powering up the Miniport

Fields #

NameDescription
IfGuid GUID
IfIndex UInt32
IfLuid UInt64
ReferenceContext UInt32

Event ID 10048: Miniport IfGuid, SystemPowerState[SystemState] DevicePowerState[DeviceState].

#
Channel
Diagnostic
Task
Power

Message #

Miniport %1, SystemPowerState[%4] DevicePowerState[%5]

Fields #

NameDescription
IfGuid GUID
IfIndex UInt32
NetLuid UInt64
SystemState HexInt32
DeviceState HexInt32

Event ID 10049: Miniport IfGuid, SystemState[State].

#
Channel
Diagnostic
Task
Power

Message #

Miniport %1, SystemState[%5]

Fields #

NameDescription
IfGuid GUID
IfIndex UInt32
NetLuid UInt64
Type HexInt32
State HexInt32

Event ID 10050: Failed to restart miniport IfGuid.

#
Channel
Operational
Task
Init

Description

Failed to restart miniport IfGuid. Status Error.

Message #

Failed to restart miniport %1. Status %4

Fields #

NameDescription
IfGuid GUID
IfIndex UInt32
NetLuid UInt64
Error UInt32
Location UInt32
Context UInt32

Event ID 10052: Error querying Oid : Status.

#
Channel
Diagnostic
Task
PnP

Message #

Error querying %4 : %5

Fields #

NameDescription
IfGuid GUID
IfIndex UInt32
NetLuid UInt64
Oid UInt32
Status UInt32NTSTATUS reference
Location UInt32

Event ID 10053: Failing open because the miniport is not started, Miniport IfGuid, Open ReferenceContext.

#
Channel
Diagnostic
Task
Bind

Message #

Failing open because the miniport is not started, Miniport %1, Open %4

Fields #

NameDescription
IfGuid GUID
IfIndex UInt32
IfLuid UInt64
ReferenceContext UInt32

Event ID 10054: Port Activation Failed Miniport IfGuid Reason.

#
Channel
Diagnostic
Task
Port

Message #

Port Activation Failed Miniport %1 %4

Fields #

NameDescription
IfGuid GUID
IfIndex UInt32
NetLuid UInt64
Reason UInt32
Port UInt32

Event ID 10055: Miniport IfGuid, Disabling wake-up on the miniport.

#
Channel
Diagnostic
Task
Power

Message #

Miniport %1, Disabling wake-up on the miniport

Fields #

NameDescription
IfGuid GUID
IfIndex UInt32
IfLuid UInt64
ReferenceContext UInt32

Event ID 10056: Miniport IfGuid, Failed to power the device down.

#
Channel
Operational
Task
Power

Message #

Miniport %1, Failed to power the device down

Fields #

NameDescription
IfGuid GUID
IfIndex UInt32
NetLuid UInt64
Error UInt32
Location UInt32
Context UInt32

Event ID 10057: Miniport IfGuid, failed to power down but we are not able to reinitialize it.

#
Channel
Diagnostic
Task
Power

Message #

Miniport %1, failed to power down but we are not able to reinitialize it.

Fields #

NameDescription
IfGuid GUID
IfIndex UInt32
NetLuid UInt64
Error UInt32
Location UInt32
Context UInt32

Event ID 10058: Miniport IfGuid, Halt the miniport.

#
Channel
Diagnostic
Task
Power

Message #

Miniport %1, Halt the miniport

Fields #

NameDescription
IfGuid GUID
IfIndex UInt32
IfLuid UInt64
ReferenceContext UInt32

Event ID 10059: Miniport IfGuid, System is either entering hibernate or shutting down.

#
Channel
Diagnostic
Task
Power

Message #

Miniport %1, System is either entering hibernate or shutting down.

Fields #

NameDescription
IfGuid GUID
IfIndex UInt32
IfLuid UInt64
ReferenceContext UInt32

Event ID 10060: DeviceObject Context, Going to system power state State.

#
Channel
Diagnostic
Task
Power

Message #

DeviceObject %1, Going to system power state %2

Fields #

NameDescription
Context UInt32
State UInt32

Event ID 10061: Miniport IfGuid is not started yet.

#
Channel
Diagnostic
Task
Power

Message #

Miniport %1 is not started yet.

Fields #

NameDescription
IfGuid GUID
IfIndex UInt32
IfLuid UInt64
ReferenceContext UInt32

Event ID 10062: Miniport IfGuid is being removed.

#
Channel
Diagnostic
Task
Power

Message #

Miniport %1 is being removed

Fields #

NameDescription
IfGuid GUID
IfIndex UInt32
IfLuid UInt64
ReferenceContext UInt32

Event ID 10063: Miniport IfGuid, MagicPacket and pattern match are not enabled.

#
Channel
Diagnostic
Task
Power

Message #

Miniport %1, MagicPacket and pattern match are not enabled.

Fields #

NameDescription
IfGuid GUID
IfIndex UInt32
IfLuid UInt64
ReferenceContext UInt32

Event ID 10064: Miniport IfGuid, Place legacy or PM disabled device in D3.

#
Channel
Diagnostic
Task
Power

Message #

Miniport %1, Place legacy or PM disabled device in D3

Fields #

NameDescription
IfGuid GUID
IfIndex UInt32
IfLuid UInt64
ReferenceContext UInt32

Event ID 10065: Miniport IfGuid, SystemState SystemState, DeviceState DeviceState.

#
Channel
Diagnostic
Task
Power

Message #

Miniport %1, SystemState %4, DeviceState %5

Fields #

NameDescription
IfGuid GUID
IfIndex UInt32
NetLuid UInt64
SystemState HexInt32
DeviceState HexInt32

Event ID 10066: Miniport IfGuid, shutting down.

#
Channel
Operational
Task
Power

Message #

Miniport %1, shutting down

Fields #

NameDescription
IfGuid GUID
IfIndex UInt32
IfLuid UInt64
ReferenceContext UInt32

Event ID 10067: Miniport IfGuid, Device power wake is not enabled (ReferenceContext).

#
Channel
Diagnostic
Task
Power

Message #

Miniport %1, Device power wake is not enabled (%4)

Fields #

NameDescription
IfGuid GUID
IfIndex UInt32
IfLuid UInt64
ReferenceContext UInt32

Event ID 10068: Miniport IfGuid, Waking up the device.

#
Channel
Operational
Task
Power

Message #

Miniport %1, Waking up the device

Fields #

NameDescription
IfGuid GUID
IfIndex UInt32
IfLuid UInt64
ReferenceContext UInt32

Event ID 10069: BIND (Layer) ProtocolName to DeviceName.

#
Channel
Operational
Task
Bind

Message #

BIND (%1) %2 to %3

Fields #

NameDescription
Layer UInt32
ProtocolName UnicodeString
DeviceName UnicodeString

Event ID 10070: UNBIND(Layer) ProtocolName to DeviceName.

#
Channel
Operational
Task
Bind

Message #

UNBIND(%1) %2 to %3

Fields #

NameDescription
Layer UInt32
ProtocolName UnicodeString
DeviceName UnicodeString

Event ID 10071: Miniport IfGuid, IRP_MN_QUERY_PNP_DEVICE_STATE device failed.

#
Channel
Diagnostic
Task
PnP

Message #

Miniport %1, IRP_MN_QUERY_PNP_DEVICE_STATE device failed

Fields #

NameDescription
IfGuid GUID
IfIndex UInt32
IfLuid UInt64
ReferenceContext UInt32

Event ID 10072: Miniport IfGuid, Bus Driver returned ReferenceContext for QueryPower.

#
Channel
Diagnostic
Task
Power

Message #

Miniport %1, Bus Driver returned %4 for QueryPower.

Fields #

NameDescription
IfGuid GUID
IfIndex UInt32
IfLuid UInt64
ReferenceContext UInt32

Event ID 10073: Miniport IfGuid, Bus Driver returned ReferenceContext for QueryPower.

#
Channel
Diagnostic
Task
Power

Message #

Miniport %1, Bus Driver returned %4 for QueryPower.

Fields #

NameDescription
IfGuid GUID
IfIndex UInt32
IfLuid UInt64
ReferenceContext UInt32

Event ID 10074: Miniport IfGuid, failed power Oid Oid, Set = Set with error Error.

#
Channel
Diagnostic
Task
Power

Message #

Miniport %1, failed power Oid %5, Set = %6 with error %4

Fields #

NameDescription
IfGuid GUID
IfIndex UInt32
NetLuid UInt64
Error UInt32
Oid UInt32
Set Boolean

Event ID 10075: ndisReferenceProtocolByName failed ErrorCode.

#
Channel
Diagnostic
Task
Bind

Message #

ndisReferenceProtocolByName failed %1

Fields #

NameDescription
ErrorCode UInt32
Location UInt32
Context UInt32

Event ID 10076: Miniport IfGuid failed to register for interrupts.

#
Channel
Diagnostic
Task
Init

Message #

Miniport %1 failed to register for interrupts

Fields #

NameDescription
IfGuid GUID
IfIndex UInt32
NetLuid UInt64
Error UInt32
Location UInt32
Context UInt32

Event ID 10077: DriverObject Context, Miniport Driver should register both a DirectRequest and CancelDirectRequest handler or neither one.

#
Channel
Diagnostic
Task
Init

Message #

DriverObject %3, Miniport Driver should register both a DirectRequest and CancelDirectRequest handler or neither one

Fields #

NameDescription
ErrorCode UInt32
Location UInt32
Context UInt32

Event ID 10078: SendPacketCompleteToOpen Open OpenRef, Packet Packet.

#
Channel
Diagnostic
Task
SendM

Message #

SendPacketCompleteToOpen Open %1, Packet %2

Fields #

NameDescription
OpenRef Pointer
Packet Pointer

Event ID 10079: ndisSetEnableWakeUp Completed

#
Channel
Diagnostic
Task
Request

Fields #

NameDescription
IfGuid GUID
IfIndex UInt32
NetLuid UInt64
CompletedAtOpen Boolean
Open Pointer
Request Pointer

Event ID 10080: SetMiniportEthMulticastList Failed Miniport IfGuid, Request Context.

#
Channel
Diagnostic
Task
Request

Message #

SetMiniportEthMulticastList Failed Miniport %1, Request %6

Fields #

NameDescription
IfGuid GUID
IfIndex UInt32
NetLuid UInt64
Error UInt32
Location UInt32
Context UInt32

Event ID 10081: SetMiniportRSSCaps Failed Miniport IfGuid, Request Context, Status Error.

#
Channel
Diagnostic
Task
Request

Message #

SetMiniportRSSCaps Failed Miniport %1, Request %6, Status %4

Fields #

NameDescription
IfGuid GUID
IfIndex UInt32
NetLuid UInt64
Error UInt32
Location UInt32
Context UInt32

Event ID 10082: SetOpenEthAddDeleteMulticast Failed, Miniport = IfGuid, Open = Context, Status = Error.

#
Channel
Diagnostic
Task
Request

Message #

SetOpenEthAddDeleteMulticast Failed, Miniport = %1, Open = %6, Status = %4

Fields #

NameDescription
IfGuid GUID
IfIndex UInt32
NetLuid UInt64
Error UInt32
Location UInt32
Context UInt32

Event ID 10083: SetOpenEthMulticastList failed - Miniport IfGuid, Open Context.

#
Channel
Diagnostic
Task
Request

Message #

SetOpenEthMulticastList failed - Miniport %1, Open %6

Fields #

NameDescription
IfGuid GUID
IfIndex UInt32
NetLuid UInt64
Error UInt32
Location UInt32
Context UInt32

Event ID 10084: SetOpenFunctional - Invalid media type

#
Channel
Diagnostic
Task
Request

Fields #

NameDescription
IfGuid GUID
IfIndex UInt32
NetLuid UInt64
Open Pointer
OriginalMediaType HexInt32
ExpectedMediaType HexInt32

Event ID 10085: SetOpenGroupAddress - Invalid media type

#
Channel
Diagnostic
Task
Request

Fields #

NameDescription
IfGuid GUID
IfIndex UInt32
NetLuid UInt64
Open Pointer
OriginalMediaType HexInt32
ExpectedMediaType HexInt32

Event ID 10086: SetOpenRSSCaps: Miniport IfGuid, Open Context, Status Error.

#
Channel
Diagnostic
Task
Request

Message #

SetOpenRSSCaps: Miniport %1, Open %6, Status %4

Fields #

NameDescription
IfGuid GUID
IfIndex UInt32
NetLuid UInt64
Error UInt32
Location UInt32
Context UInt32

Event ID 10087: Miniport IfGuid, Going to system power state State.

#
Channel
Diagnostic
Task
Power

Message #

Miniport %1, Going to system power state %5

Fields #

NameDescription
IfGuid GUID
IfIndex UInt32
NetLuid UInt64
Type HexInt32
State HexInt32

Event ID 10088: Transport Transport failed the PnP event: PnPEvent for Miniport IfGuid with Status Status.

#
Channel
Operational
Task
PnP

Message #

Transport %4 failed the PnP event: %5 for Miniport %1 with Status %6

Fields #

NameDescription
IfGuid GUID
IfIndex UInt32
NetLuid UInt64
Transport UnicodeString
PnPEvent HexInt32
Status HexInt32NTSTATUS reference

Event ID 10089: Miniport IfGuid, This version of NDIS does not support Arcnet, FDDI, IP1394, or Token Ring.

#
Channel
Diagnostic
Task
PnP

Message #

Miniport %1, This version of NDIS does not support Arcnet, FDDI, IP1394, or Token Ring

Fields #

NameDescription
IfGuid GUID
IfIndex UInt32
IfLuid UInt64
ReferenceContext UInt32

Event ID 10090: ProtocolName, Reason.

#
Channel
Diagnostic
Task
Protocol

Message #

%1, %2

Fields #

NameDescription
ProtocolName UnicodeString
Reason UInt32

Event ID 10091: Miniport IfGuid, Wake irp was complete due to wake event.

#
Channel
Diagnostic
Task
Power

Message #

Miniport %1, Wake irp was complete due to wake event

Fields #

NameDescription
IfGuid GUID
IfIndex UInt32
IfLuid UInt64
ReferenceContext UInt32

Event ID 10092: WaitWakeIrpFailed Miniport IfGuid, WAIT_WAKE irp failed or cancelled.

#
Channel
Diagnostic
Task
Power

Description

WaitWakeIrpFailed Miniport IfGuid, WAIT_WAKE irp failed or cancelled. Status Error.

Message #

WaitWakeIrpFailed Miniport %1, WAIT_WAKE irp failed or cancelled. Status %4

Fields #

NameDescription
IfGuid GUID
IfIndex UInt32
NetLuid UInt64
Error UInt32
Location UInt32
Context UInt32

Event ID 10093: Miniport IfGuid woke up the system.

#
Channel
Operational
Task
Power

Message #

Miniport %1 woke up the system.

Fields #

NameDescription
IfGuid GUID
IfIndex UInt32
IfLuid UInt64
ReferenceContext UInt32

Event ID 10094: Error Log Entry : Miniport IfGuid (AdapterName) Error Error.

#
Channel
Diagnostic
Task
Log

Message #

Error Log Entry : Miniport %1 (%4) Error %5

Fields #

NameDescription
IfGuid GUID
IfIndex UInt32
NetLuid UInt64
AdapterName UnicodeString
Error UInt32
ErrorValueCount UInt32
ErrorValues UInt32

Event ID 10095: Aborting Request Request.

#
Channel
Diagnostic
Task
Request

Message #

Aborting Request %4

Fields #

NameDescription
IfGuid GUID
IfIndex UInt32
NetLuid UInt64
Request Pointer

Event ID 10096: Port Deactivation Failed Miniport IfGuid Reason.

#
Channel
Diagnostic
Task
Port

Message #

Port Deactivation Failed Miniport %1 %4

Fields #

NameDescription
IfGuid GUID
IfIndex UInt32
NetLuid UInt64
Reason UInt32
Port UInt32

Event ID 10097: Miniport IfGuid, PoRequestPowerIrp for device state returned ReferenceContext.

#
Channel
Diagnostic
Task
Power

Message #

Miniport %1, PoRequestPowerIrp for device state returned %4

Fields #

NameDescription
IfGuid GUID
IfIndex UInt32
IfLuid UInt64
ReferenceContext UInt32

Event ID 10098: Miniport IfGuid, failed query power.

#
Channel
Diagnostic
Task
Power

Message #

Miniport %1, failed query power

Fields #

NameDescription
IfGuid GUID
IfIndex UInt32
NetLuid UInt64
Error UInt32
Location UInt32
Context UInt32

Event ID 10099: DevicePowerOn failed Miniport IfGuid, status Error.

#
Channel
Diagnostic
Task
Power

Message #

DevicePowerOn failed Miniport %1, status %4

Fields #

NameDescription
IfGuid GUID
IfIndex UInt32
NetLuid UInt64
Error UInt32
Location UInt32
Context UInt32

Event ID 10100: Power policy - Unable to enter requested state

#
Channel
Diagnostic
Task
Power

Fields #

NameDescription
IfGuid GUID
IfIndex UInt32
IfLuid UInt64
ReferenceContext UInt32

Event ID 10101: Miniport IfGuid: Oid Oid, Completed by NDIS on behalf of miniport with Status Status: CompleteRequest.

#
Channel
Diagnostic
Also via
realtime ETW trace
Level
Verbose
Task
Request
Opcode
win:Info

Message #

Miniport %1: Oid %7, Completed by NDIS on behalf of miniport with Status %6: %5

Fields #

NameDescription
IfGuid GUID
IfIndex UInt32
NetLuid UInt64
Request Pointer
CompleteRequest Boolean
Status HexInt32NTSTATUS reference
Oid UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-NDIS",
    "guid": "{CDEAD503-17F5-4A3E-B7AE-DF8CC2902EB9}",
    "event_source_name": "",
    "event_id": 10101,
    "version": 0,
    "level": 5,
    "task": 1,
    "opcode": 0,
    "keywords": "0x4000000000000001",
    "time_created": "2026-06-02T05:29:07.634+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{2A7BD48E-DDC6-4641-9F41-682F29F1D76C}"
    },
    "execution": {
      "process_id": 4,
      "thread_id": 12056
    },
    "channel": "ETW Trace",
    "computer": "JD-DC01-2022",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "CompleteRequest": false,
    "IfGuid": "{2A7BD48E-DDC6-4641-9F41-682F29F1D76C}",
    "IfIndex": 4,
    "NetLuid": 1689399632855040,
    "Oid": 131334,
    "Request": "0xFFFF878DC8506280",
    "Status": "00000000"
  },
  "message": "Request"
}

Event ID 10102: Completing Request Request to Miniport IfGuid.

#
Channel
Diagnostic
Task
Request

Message #

Completing Request %4 to Miniport %1

Fields #

NameDescription
IfGuid GUID
IfIndex UInt32
NetLuid UInt64
Request Pointer
Status HexInt32NTSTATUS reference
Location UInt32

Event ID 10103: Filter IfGuid entering state State.

#
Channel
Diagnostic
Task
WorkItem

Message #

Filter %1 entering state %2

Fields #

NameDescription
IfGuid GUID
State UInt8
Location UInt32

Event ID 10104: Miniport IfGuid, NDIS_STATUS_MEDIA_CONNECT, Flags: Flags, PnpFlags PnPFlags, DevicePowerState DevicePowerState.

#
Channel
Diagnostic
Task
Indication

Message #

Miniport %1, NDIS_STATUS_MEDIA_CONNECT, Flags: %4, PnpFlags %5, DevicePowerState %6

Fields #

NameDescription
IfGuid GUID
IfIndex UInt32
NetLuid UInt64
Flags HexInt32
PnPFlags HexInt32
DevicePowerState UInt32

Event ID 10105: Miniport IfGuid, NDIS_STATUS_MEDIA_DISCONNECT, Flags: Flags, PnpFlags PnPFlags, DevicePowerState DevicePowerState.

#
Channel
Diagnostic
Task
Indication

Message #

Miniport %1, NDIS_STATUS_MEDIA_DISCONNECT, Flags: %4, PnpFlags %5, DevicePowerState %6

Fields #

NameDescription
IfGuid GUID
IfIndex UInt32
NetLuid UInt64
Flags HexInt32
PnPFlags HexInt32
DevicePowerState UInt32

Event ID 10106: Miniport OperationalStatusFlags, NDIS_STATUS_OPER_STATUS, OperationalStatus: NetLuid, OperationalStatusFlags: OperationalStatus.

#
Channel
Diagnostic
Also via
realtime ETW trace
Level
Informational
Task
Indication
Opcode
win:Info

Message #

Miniport %1, NDIS_STATUS_OPER_STATUS, OperationalStatus: %4, OperationalStatusFlags: %5

Fields #

NameDescription
IfGuid GUID
IfIndex UInt32
NetLuid UInt64
OperationalStatus UInt32
OperationalStatusFlags UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-NDIS",
    "guid": "{CDEAD503-17F5-4A3E-B7AE-DF8CC2902EB9}",
    "event_source_name": "",
    "event_id": 10106,
    "version": 0,
    "level": 4,
    "task": 10,
    "opcode": 0,
    "keywords": "0x4000000000000200",
    "time_created": "2026-06-02T05:29:07.646+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{2A7BD48E-DDC6-4641-9F41-682F29F1D76C}"
    },
    "execution": {
      "process_id": 13372,
      "thread_id": 18092
    },
    "channel": "ETW Trace",
    "computer": "JD-DC01-2022",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "IfGuid": "{2A7BD48E-DDC6-4641-9F41-682F29F1D76C}",
    "IfIndex": 4,
    "NetLuid": 1689399632855040,
    "OperationalStatus": 1,
    "OperationalStatusFlags": 0
  },
  "message": "Indication"
}

Event ID 10107: Miniport OperationalStatusFlags, NDIS_STATUS_OPER_STATUS, OperationalStatus: NetLuid, OperationalStatusFlags: OperationalStatus.

#
Channel
Diagnostic
Task
Indication

Message #

Miniport %1, NDIS_STATUS_OPER_STATUS, OperationalStatus: %4, OperationalStatusFlags: %5

Fields #

NameDescription
IfGuid GUID
IfIndex UInt32
NetLuid UInt64
OperationalStatus UInt32
OperationalStatusFlags UInt32

Event ID 10108: Miniport IfGuid, NDIS_STATUS_NETWORK_CHANGE, Change Type: ChangeType.

#
Channel
Diagnostic
Task
Indication

Message #

Miniport %1, NDIS_STATUS_NETWORK_CHANGE, Change Type: %4

Fields #

NameDescription
IfGuid GUID
IfIndex UInt32
NetLuid UInt64
ChangeType UInt32

Event ID 10109: Filter IfGuid, Aborting Request RequestType.

#
Channel
Diagnostic
Task
Request

Message #

Filter %1, Aborting Request %4

Fields #

NameDescription
IfGuid GUID
IfIndex UInt32
NetLuid UInt64
RequestType UInt32
Status HexInt32NTSTATUS reference
Location UInt32

Event ID 10110: Miniport IfGuid, Aborting Request RequestType.

#
Channel
Diagnostic
Task
Request

Message #

Miniport %1, Aborting Request %4

Fields #

NameDescription
IfGuid GUID
IfIndex UInt32
NetLuid UInt64
RequestType UInt32
Status HexInt32NTSTATUS reference
Location UInt32

Event ID 10111: Completing Request RequestType to Filter IfGuid.

#
Channel
Diagnostic
Also via
realtime ETW trace
Level
Verbose
Task
Request
Opcode
win:Info

Message #

Completing Request %4 to Filter %1

Fields #

NameDescription
IfGuid GUID
IfIndex UInt32
NetLuid UInt64
RequestType UInt32
Status HexInt32NTSTATUS reference
Location UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-NDIS",
    "guid": "{CDEAD503-17F5-4A3E-B7AE-DF8CC2902EB9}",
    "event_source_name": "",
    "event_id": 10111,
    "version": 0,
    "level": 5,
    "task": 1,
    "opcode": 0,
    "keywords": "0x4000000000000001",
    "time_created": "2026-06-02T05:29:07.634+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{C5883B93-5C46-11F1-9665-806E6F6E6963}"
    },
    "execution": {
      "process_id": 4,
      "thread_id": 12056
    },
    "channel": "ETW Trace",
    "computer": "JD-DC01-2022",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "IfGuid": "{C5883B93-5C46-11F1-9665-806E6F6E6963}",
    "IfIndex": 17,
    "Location": 65537,
    "NetLuid": 1688849860263936,
    "RequestType": 131334,
    "Status": "00000000"
  },
  "message": "Request"
}

Event ID 10112: Completing Request RequestType to Miniport IfGuid.

#
Channel
Diagnostic
Also via
realtime ETW trace
Level
Verbose
Task
Request
Opcode
win:Info

Message #

Completing Request %4 to Miniport %1

Fields #

NameDescription
IfGuid GUID
IfIndex UInt32
NetLuid UInt64
RequestType UInt32
Status HexInt32NTSTATUS reference
Location UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-NDIS",
    "guid": "{CDEAD503-17F5-4A3E-B7AE-DF8CC2902EB9}",
    "event_source_name": "",
    "event_id": 10112,
    "version": 0,
    "level": 5,
    "task": 1,
    "opcode": 0,
    "keywords": "0x4000000000000001",
    "time_created": "2026-06-02T05:29:07.634+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{2A7BD48E-DDC6-4641-9F41-682F29F1D76C}"
    },
    "execution": {
      "process_id": 4,
      "thread_id": 12056
    },
    "channel": "ETW Trace",
    "computer": "JD-DC01-2022",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "IfGuid": "{2A7BD48E-DDC6-4641-9F41-682F29F1D76C}",
    "IfIndex": 4,
    "Location": 65537,
    "NetLuid": 1689399632855040,
    "RequestType": 131334,
    "Status": "00000000"
  },
  "message": "Request"
}

Event ID 10113: Aborting Request RequestType.

#
Channel
Diagnostic
Task
Request

Message #

Aborting Request %4

Fields #

NameDescription
IfGuid GUID
IfIndex UInt32
NetLuid UInt64
RequestType UInt32

Event ID 10114: Aborting Request RequestType on Filter LowerIf.

#
Channel
Diagnostic
Task
Request

Message #

Aborting Request %4 on Filter %5

Fields #

NameDescription
IfGuid GUID
IfIndex UInt32
NetLuid UInt64
RequestType UInt32
LowerIf GUID

Event ID 10115: Aborting Request RequestType on Miniport LowerIf.

#
Channel
Diagnostic
Task
Request

Message #

Aborting Request %4 on Miniport %5

Fields #

NameDescription
IfGuid GUID
IfIndex UInt32
NetLuid UInt64
RequestType UInt32
LowerIf GUID

Event ID 10200: DPC/OtherDispatchRoutine Start

#
Channel
Diagnostic
Task
ReceiveThrottling

Fields #

NameDescription
NetLuidIndex UInt32
FunctionType UInt32

Event ID 10201: DPC/OtherDispatchRoutine End

#
Channel
Diagnostic
Task
ReceiveThrottling

Fields #

NameDescription
NetLuidIndex UInt32
FunctionType UInt32
Duration UInt64

Event ID 10202: Queued Receive Indication Start

#
Channel
Diagnostic
Task
ReceiveThrottling

Fields #

NameDescription
NetLuidIndex UInt32

Event ID 10203: Queued Receive Indication End

#
Channel
Diagnostic
Task
ReceiveThrottling

Fields #

NameDescription
NetLuidIndex UInt32
Duration UInt64
NumberOfNbls UInt32

Event ID 10204: Miniport Duration on processor Individual has an RST limit change from CurrentProcessorIndex to NumberOfNetBufferLists NBLs per indication (NumNbls: Cummulative, Duration: NetLuidIndex, Individual:...

#
Channel
Diagnostic
Task
ReceiveThrottling

Description

Miniport Duration on processor Individual has an RST limit change from CurrentProcessorIndex to NumberOfNetBufferLists NBLs per indication (NumNbls: Cummulative, Duration: NetLuidIndex, Individual: ProcessingDurationMilliseconds, Cummulative: PreviousLimit).

Message #

Miniport %1 on processor %2 has an RST limit change from %5 to %6 NBLs per indication (NumNbls: %3, Duration: %4, Individual: %7, Cummulative: %8)

Fields #

NameDescription
NetLuidIndex UInt32
CurrentProcessorIndex UInt32
NumberOfNetBufferLists UInt32
ProcessingDurationMilliseconds UInt32
PreviousLimit UInt32
NewLimit UInt32
IndividualMeasurement UInt32
CummulativeMeasurement UInt32

Event ID 10300: The network adapter is idle and can be suspended now.

#
Channel
Diagnostic
Task
Power

Description

The network adapter is idle and can be suspended now. Interface Luid: NetLuidIndex.

Message #

The network adapter is idle and can be suspended now. Interface Luid: %1

Fields #

NameDescription
NetLuidIndex UInt32

Event ID 10301: The network adapter declined to enter a suspended state.

#
Channel
Diagnostic
Task
Power

Description

The network adapter declined to enter a suspended state. Interface Luid: NetLuidIndex Status code: NdisStatusCode.

Message #

The network adapter declined to enter a suspended state. Interface Luid: %1 Status code: %2

Fields #

NameDescription
NetLuidIndex UInt32
NdisStatusCode UInt32

Event ID 10302: The network adapter must be resumed.

#
Channel
Diagnostic
Task
Power

Description

The network adapter must be resumed. Interface Luid: NetLuidIndex Resume reason: ResumeReason.

Message #

The network adapter must be resumed. Interface Luid: %1 Resume reason: %2

Fields #

NameDescription
NetLuidIndex UInt32
ResumeReason UInt32

Event ID 10303: NIC Active state is acquired.

#
Channel
Diagnostic
Task
Power

Description

NIC Active state is acquired. Interface Luid: InterfaceLuid Component ID: ComponentId Component Ref Count: ComponentRefCount Interface Ref Count: InterfaceRefCount.

Message #

NIC Active state is acquired. Interface Luid: %1 Component ID: %2 Component Ref Count: %3 Interface Ref Count: %4

Fields #

NameDescription
InterfaceLuid UInt64
ComponentId UInt32
ComponentRefCount UInt32
InterfaceRefCount UInt32

Event ID 10304: NIC Active state is released.

#
Channel
Diagnostic
Task
Power

Description

NIC Active state is released. Interface Luid: InterfaceLuid Component ID: ComponentId Component Ref Count: ComponentRefCount Interface Ref Count: InterfaceRefCount.

Message #

NIC Active state is released. Interface Luid: %1 Component ID: %2 Component Ref Count: %3 Interface Ref Count: %4

Fields #

NameDescription
InterfaceLuid UInt64
ComponentId UInt32
ComponentRefCount UInt32
InterfaceRefCount UInt32

Event ID 10305: The network adapter indicated a wake signal.

#
Channel
Diagnostic
Task
Power

Description

The network adapter indicated a wake signal. Interface Luid: IfLuid Wake reason: WakeReason.

Message #

The network adapter indicated a wake signal. Interface Luid: %1 Wake reason: %2

Fields #

NameDescription
IfLuid UInt64
WakeReason UInt32

Event ID 10306: Working power state is requested for network adapter.

#
Channel
Diagnostic
Task
Power

Description

Working power state is requested for network adapter. Interface Luid: IfLuid.

Message #

Working power state is requested for network adapter. Interface Luid: %3

Fields #

NameDescription
IfGuid GUID
IfIndex UInt32
IfLuid UInt64

Event ID 10307: Working power request is completed for network adapter.

#
Channel
Diagnostic
Task
Power

Description

Working power request is completed for network adapter. Interface Luid: IfLuid Status: Status.

Message #

Working power request is completed for network adapter. Interface Luid: %3 Status: %4

Fields #

NameDescription
IfGuid GUID
IfIndex UInt32
IfLuid UInt64
Status UInt32NTSTATUS reference

Event ID 10308: Low power state is requested for network adapter.

#
Channel
Diagnostic
Task
Power

Description

Low power state is requested for network adapter. Interface Luid: IfLuid.

Message #

Low power state is requested for network adapter. Interface Luid: %3

Fields #

NameDescription
IfGuid GUID
IfIndex UInt32
IfLuid UInt64

Event ID 10309: Low power request is completed for network adapter.

#
Channel
Diagnostic
Task
Power

Description

Low power request is completed for network adapter. Interface Luid: IfLuid Status: Status.

Message #

Low power request is completed for network adapter. Interface Luid: %3 Status: %4

Fields #

NameDescription
IfGuid GUID
IfIndex UInt32
IfLuid UInt64
Status UInt32NTSTATUS reference

Event ID 10310: Wait/Wake IRP is completed for network adapter.

#
Channel
Diagnostic
Task
Power

Description

Wait/Wake IRP is completed for network adapter. Interface Luid: IfLuid.

Message #

Wait/Wake IRP is completed for network adapter. Interface Luid: %3

Fields #

NameDescription
IfGuid GUID
IfIndex UInt32
IfLuid UInt64

Event ID 10311: Miniport AdapterName, IfGuid, had event MiniportEventEnum.

#
Channel
Diagnostic
Also via
realtime ETW trace
Level
Informational
Task
PnP
Opcode
win:Info

Message #

Miniport %4, %1, had event %5

Fields #

NameDescription
IfGuid GUID
IfIndex UInt32
IfLuid UInt64
AdapterName UnicodeString
MiniportEventEnum UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-NDIS",
    "guid": "{CDEAD503-17F5-4A3E-B7AE-DF8CC2902EB9}",
    "event_source_name": "",
    "event_id": 10311,
    "version": 0,
    "level": 4,
    "task": 2,
    "opcode": 0,
    "keywords": "0x4000000000004016",
    "time_created": "2026-06-02T05:29:07.631+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{E47DFBE0-FE90-4385-8C84-1A825F85A4C2}"
    },
    "execution": {
      "process_id": 13372,
      "thread_id": 18092
    },
    "channel": "ETW Trace",
    "computer": "JD-DC01-2022",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "AdapterName": "Microsoft Failover Cluster Virtual Adapter",
    "IfGuid": "{E47DFBE0-FE90-4385-8C84-1A825F85A4C2}",
    "IfIndex": 16,
    "IfLuid": 36873771788795904,
    "MiniportEventEnum": 53
  },
  "message": "PnP"
}

Event ID 10312: Filter IfGuid entering state State (FriendlyName: FilterFriendlyName).

#
Channel
Diagnostic
Also via
realtime ETW trace
Level
Informational
Task
WorkItem
Opcode
win:Info

Message #

Filter %1 entering state %2 (FriendlyName: %7)

Fields #

NameDescription
IfGuid GUID
State UInt8
Location UInt32
MiniportIfGuid GUID
MiniportAdapterName UnicodeString
FilterInstanceName UnicodeString
FilterFriendlyName UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-NDIS",
    "guid": "{CDEAD503-17F5-4A3E-B7AE-DF8CC2902EB9}",
    "event_source_name": "",
    "event_id": 10312,
    "version": 0,
    "level": 4,
    "task": 9,
    "opcode": 0,
    "keywords": "0x4000000000000100",
    "time_created": "2026-06-02T05:29:07.631+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{C5883B98-5C46-11F1-9665-806E6F6E6963}"
    },
    "execution": {
      "process_id": 13372,
      "thread_id": 18092
    },
    "channel": "ETW Trace",
    "computer": "JD-DC01-2022",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "FilterFriendlyName": "Microsoft Failover Cluster Virtual Adapter-WFP 802.3 MAC Layer LightWeight Filter-0000",
    "FilterInstanceName": "{E47DFBE0-FE90-4385-8C84-1A825F85A4C2}-{B70D6460-3635-4D42-B866-B8AB1A24454C}-0000",
    "IfGuid": "{C5883B98-5C46-11F1-9665-806E6F6E6963}",
    "Location": 1,
    "MiniportAdapterName": "Microsoft Failover Cluster Virtual Adapter",
    "MiniportIfGuid": "{E47DFBE0-FE90-4385-8C84-1A825F85A4C2}",
    "State": 5
  },
  "message": "WorkItem"
}

Event ID 10313: Entering Connected Standby

#
Channel
Diagnostic
Task
Power

Event ID 10314: Exiting Connected Standby.

#
Channel
Diagnostic
Task
Power

Description

Exiting Connected Standby. Duration Duration sec.

Message #

Exiting Connected Standby. Duration %1 sec.

Fields #

NameDescription
Duration UInt64

Event ID 10315: Miniport IfLuid: CS active ActiveTime seconds, PowerTransitionCount power transitions.

#
Channel
Diagnostic
Task
Power

Message #

Miniport %2: CS active %3 seconds, %4 power transitions.

Fields #

NameDescription
IfIndex UInt32
IfLuid UInt64
ActiveTime UInt64
PowerTransitionCount UInt32

Event ID 10316: Component ComponentId: CS active ActiveTime seconds, Miniport InterfaceLuid.

#
Channel
Diagnostic
Task
Power

Message #

Component %2: CS active %3 seconds, Miniport %1.

Fields #

NameDescription
InterfaceLuid UInt64
ComponentId UInt32
ActiveTime UInt64

Event ID 10317: Miniport AdapterName, IfGuid, had event MiniportEventEnum.

#
Channel
System
Task
PnP

Message #

Miniport %4, %1, had event %5

Fields #

NameDescription
IfGuid GUID
IfIndex UInt32
IfLuid UInt64
AdapterName UnicodeString
MiniportEventEnum UInt32

Event ID 10320: Refcount rundown for miniport NetLuid will follow.

#
Channel
Diagnostic
Task
Refcountrundown
Opcode
Start

Message #

Refcount rundown for miniport %3 will follow

Fields #

NameDescription
IfGuid GUID
IfIndex UInt32
NetLuid UInt64

Event ID 10321: Refcount rundown for miniport NetLuid: component ComponentId has refcount RefcountValue.

#
Channel
Diagnostic
Task
Refcountrundown

Message #

Refcount rundown for miniport %1: component %2 has refcount %3

Fields #

NameDescription
NetLuid UInt64
ComponentId UInt32
RefcountValue UInt32

Event ID 10322: Refcount rundown for miniport NetLuid: stop flags StopFlags Rundown complete.

#
Channel
Diagnostic
Task
Refcountrundown
Opcode
Stop

Message #

Refcount rundown for miniport %1: stop flags %2 Rundown complete

Fields #

NameDescription
NetLuid UInt64
StopFlags UInt32

Event ID 10323: Power transition for Miniport IfLuid in CS (PowerStateFrom to PowerStateTo).

#
Channel
Diagnostic
Task
Power

Description

Power transition for Miniport IfLuid in CS (PowerStateFrom to PowerStateTo). PowerStateFrom traffic (In-Out): Unicast Packets (IfInUnicastPackets-IfOutUnicastPackets), Multicast Packets (IfInMulticastPackets-IfOutMulticastPackets), Broadcast Packets (IfInBroadcastPackets-IfOutBroadcastPackets).

Message #

Power transition for Miniport %2 in CS (%3 to %4). %3 traffic (In-Out): Unicast Packets (%5-%6), Multicast Packets (%7-%8), Broadcast Packets (%9-%10).

Fields #

NameDescription
IfIndex UInt32
IfLuid UInt64
PowerStateFrom UnicodeString
PowerStateTo UnicodeString
IfInUnicastPackets UInt64
IfOutUnicastPackets UInt64
IfInMulticastPackets UInt64
IfOutMulticastPackets UInt64
IfInBroadcastPackets UInt64
IfOutBroadcastPackets UInt64

Event ID 10324: Miniport PDO information for Sleepstudy

#
Channel
Diagnostic
Task
Power

Fields #

NameDescription
ScenarioInstanceId UInt8
ParentGuid GUID
BlockerGuid GUID
PhysicalDeviceNode Pointer
ScenarioInstanceIdV2 UInt64

Event ID 10325: Miniport IfGuid indicated a Wake Packet WakePacketPayload.

#
Channel
Diagnostic
Task
Power

Message #

Miniport %1 indicated a Wake Packet %3

Fields #

NameDescription
IfGuid GUID
WakePacketSize UInt32
WakePacketPayload Binary

Event ID 10400: The network interface "AdapterName" has begun resetting.

#
Channel
System
Level
Warning
Opcode
Info

Description

The network interface "AdapterName" has begun resetting. There will be a momentary disruption in network connectivity while the hardware resets. Reason: ResetReason. This network interface has reset ResetCount time(s) since it was last initialized.

Message #

The network interface "%4" has begun resetting.  There will be a momentary disruption in network connectivity while the hardware resets. Reason: %5. This network interface has reset %6 time(s) since it was last initialized.

Fields #

NameDescription
IfGuid GUID
IfIndex UInt32
IfLuid UInt64
AdapterName UnicodeString
ResetReason UInt324" has begun resetting. There will be a momentary disruption in network connectivity while the hardware resets. Reason.
ResetCount UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-NDIS",
    "guid": "CDEAD503-17F5-4A3E-B7AE-DF8CC2902EB9",
    "event_source_name": "",
    "event_id": 10400,
    "version": 0,
    "level": 3,
    "task": 0,
    "opcode": 0,
    "keywords": 2305843009213693952,
    "time_created": "2023-11-06T00:53:47.295624+00:00",
    "event_record_id": 2138,
    "correlation": {
      "ActivityID": "3D03B11E-98A0-4304-84E2-CD3AAE8EFE1D"
    },
    "execution": {
      "process_id": 4,
      "thread_id": 20768
    },
    "channel": "System",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "IfGuid": "3D03B11E-98A0-4304-84E2-CD3AAE8EFE1D",
    "IfIndex": 4,
    "IfLuid": 1689399649632256,
    "AdapterName": "Intel(R) PRO/1000 MT Network Connection #2",
    "ResetReason": 1,
    "ResetCount": 2
  },
  "message": ""
}

References #

Event ID 10401: Timestamping change notification, interface NetLuid NetLuid.

#
Channel
Diagnostic
Task
Interface

Message #

Timestamping change notification, interface NetLuid %1

Fields #

NameDescription
NetLuid UInt64

Event ID 10402: Miniport IfGuid Capabilities: Flags Flags, SupportedWoLPatterns SupportedWolPatterns, SupportedProtocolOffloads SupportedProtocolOffloads, SupportedWakeUpEvents SupportedWakeUpFlags, SupportedMedia...

#
Channel
Diagnostic
Task
Power

Description

Miniport IfGuid Capabilities: Flags % 2, SupportedWoLPatterns SupportedWolPatterns, SupportedProtocolOffloads SupportedProtocolOffloads, SupportedWakeUpEvents SupportedWakeUpFlags, SupportedMediaWakeUpEvents SupportedMediaWakeUpEvents; PmParameter: IdleCondition Flags, WolPatterns SupportedWolPatterns, ProtocolOffloads SupportedProtocolOffloads, WakeUpFlags SupportedWakeUpFlags, MediaWakeUpEvents SupportedMediaWakeUpEvents

Message #

Miniport %1 Capabilities: Flags %2, SupportedWoLPatterns %3, SupportedProtocolOffloads %4, SupportedWakeUpEvents %5, SupportedMediaWakeUpEvents %6; PmParameter: IdleCondition %7, WolPatterns %8, ProtocolOffloads %9, WakeUpFlags %10, MediaWakeUpEvents %11

Fields #

NameDescription
IfGuid GUID
Flags UInt32
SupportedWolPatterns UInt32
SupportedProtocolOffloads UInt32
SupportedWakeUpFlags UInt32
SupportedMediaWakeUpEvents UInt32
IdleCondition UInt32
WolPatterns UInt32
ProtocolOffloads UInt32
WakeUpFlags UInt32
MediaWakeUpEvents UInt32

Event ID 10500: HAL's SupportFlags(value=SupportFlags) indicates DMA hybrid passthrough is not supported on system.

#
Channel
System
Task
Init

Message #

HAL's SupportFlags(value=%1) indicates DMA hybrid passthrough is not supported on system

Fields #

NameDescription
SupportFlags UInt32

Event ID 10501: A NDIS object (type=ObjectType, handle=ObjectHandle) registers hybrid SG_DMA_BLOCK on system that doesn't support hybrid DMA (SupportFlags=SupportFlags).

#
Channel
System
Task
Init

Message #

A NDIS object (type=%1, handle=%2) registers hybrid SG_DMA_BLOCK on system that doesn't support hybrid DMA (SupportFlags=%3)

Fields #

NameDescription
ObjectType UInt8
ObjectHandle Pointer
SupportFlags UInt32

Event ID 10502: AzDmaV3 version NdisAllocateSharedMemory exceeds threshold: State State, NetworkInterfaceGuid NetworkInterfaceGuid, QueueId QueueId, VPortId VPortId, NumaNode NumaNode, AllocationSize ...

#
Channel
System
Task
Alloc

Description

AzDmaV3 version NdisAllocateSharedMemory exceeds threshold: State , NetworkInterfaceGuid , QueueId , VPortId , NumaNode , AllocationSize , AllocationTimeUs , AllocationTimeThresholdUs.

Message #

AzDmaV3 version NdisAllocateSharedMemory exceeds threshold: State %1, NetworkInterfaceGuid %2, QueueId %3, VPortId %4, NumaNode %5, AllocationSize %6, AllocationTimeUs %7, AllocationTimeThresholdUs %8

Fields #

NameDescription
State UInt32
NetworkInterfaceGuid GUID
QueueId UInt32
VPortId UInt32
NumaNode UInt32
AllocationSize UInt32
AllocationTime UInt64
AllocationTimeThreshold UInt64

Event ID 10503: Enabling Hybrid DMA for miniport stack MiniportStack because of back compat configuration.

#
Channel
System
Task
Init

Description

Enabling Hybrid DMA for miniport stack MiniportStack because of back compat configuration. Driver service name DriverServiceName, driver requested OriginalFlags flags, effective flags will be EffectiveFlags.

Message #

Enabling Hybrid DMA for miniport stack %1 because of back compat configuration. Driver service name %2, driver requested %3 flags, effective flags will be %4

Fields #

NameDescription
MiniportStack GUID
DriverServiceName CountedUtf16String
OriginalFlags UInt32
EffectiveFlags UInt32

Event ID 10504: Enabled Hybrid DMA for NDIS Generic Object because of back compat configuration.

#
Channel
System
Task
Init

Description

Enabled Hybrid DMA for NDIS Generic Object because of back compat configuration. Driver name DriverName.

Message #

Enabled Hybrid DMA for NDIS Generic Object because of back compat configuration. Driver name %1

Fields #

NameDescription
DriverName CountedUtf16String

Event ID 10505: Failed to enable Hybrid DMA for NDIS Generic Object required by back compat configuration.

#
Channel
System
Task
Init

Description

Failed to enable Hybrid DMA for NDIS Generic Object required by back compat configuration. Driver name DriverName, ntStatus Status.

Message #

Failed to enable Hybrid DMA for NDIS Generic Object required by back compat configuration. Driver name %1, ntStatus %2

Fields #

NameDescription
DriverName CountedUtf16String
Status HexInt32NTSTATUS reference

Event ID 10506: NDIS requested Hybrid DMA, but the DMA_ADAPTER does not have Hybrid Passthrough enabled.

#
Channel
System
Task
Init

Description

NDIS requested Hybrid DMA, but the DMA_ADAPTER does not have Hybrid Passthrough enabled. Driver name DriverName, Network interface GUID NetworkInterfaceGuid.

Message #

NDIS requested Hybrid DMA, but the DMA_ADAPTER does not have Hybrid Passthrough enabled. Driver name %1, Network interface GUID %2

Fields #

NameDescription
DriverName CountedUtf16String
NetworkInterfaceGuid GUID

Event ID 10507: Unable to find parent stack PDO to enable CX-3 NDIS DMA Cache compatibility.

#
Channel
System
Task
Init

Description

Unable to find parent stack PDO to enable CX-3 NDIS DMA Cache compatibility. Miniport parent instance ID ParentInstanceId.

Message #

Unable to find parent stack PDO to enable CX-3 NDIS DMA Cache compatibility. Miniport parent instance ID %1

Fields #

NameDescription
ParentInstanceId CountedUtf16String
NetworkInterfaceGuid GUID

Event ID 10600: task_010600

#
Channel
Operational
Also via
realtime ETW trace
Level
Informational
Opcode
win:Info

Fields #

NameDescription
Name CountedUtf16String
MatchingHardwareId UnicodeString
CaptureErrors UInt32
DriverService CountedUtf16String
DriverDate CountedUtf16String
DriverVersion CountedUtf16String
InfPath CountedUtf16String
InstallTimestamp SYSTEMTIME
IfGuid GUID
IfIndex UInt32
IfLuid UInt64
Flags UInt32
PnPFlags UInt32
FilterPnPFlags UInt32
AdminStatus UInt32
OperStatus UInt32
OperStatusFlags UInt32
SyncFlags UInt32
WSyncFlags UInt32
InterlockedFlags UInt32
EventLogCount UInt32
EventLog 27
LastEventTimestamp FILETIME
FilterListCount UInt32
FilterList 29
ProtocolListCount UInt32
ProtocolList 37

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-NDIS",
    "guid": "{CDEAD503-17F5-4A3E-B7AE-DF8CC2902EB9}",
    "event_source_name": "",
    "event_id": 10600,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": "0x0000000000020000",
    "time_created": "2026-06-02T05:58:43.440+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{73315E02-1FED-46EB-BADF-BDE47D827AD3}"
    },
    "execution": {
      "process_id": 12516,
      "thread_id": 716
    },
    "channel": "ETW Trace",
    "computer": "DESKTOP-FF3N5XK",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "AdminStatus": 1,
    "CaptureErrors": 0,
    "DriverDate": "120036002D00320031002D003200300030003600",
    "DriverService": "0E004E00640069007300570061006E00",
    "DriverVersion": "1800310030002E0030002E00320036003100300030002E003100",
    "EventLog": "03001F0000002000020033000B003600",
    "EventLogCount": 4,
    "FilterList": "2078FD3B5CD61B4C9FEA983A019639EA0000000000000000010000000100000000000000000000000000000059D6F4B5AA7D65458E41BE220ED6054200000000000000000100000001000000000000000000000000000000",
    "FilterListCount": 2,
    "FilterPnPFlags": 0,
    "Flags": 608632832,
    "IfGuid": "{73315E02-1FED-46EB-BADF-BDE47D827AD3}",
    "IfIndex": 8,
    "IfLuid": 1689399683186688,
    "InfPath": "16006E006500740072006100730061002E0069006E006600",
    "InstallTimestamp": "2026-04-17 22:10:11.682Z",
    "InterlockedFlags": 0,
    "LastEventTimestamp": "2026-05-27 20:12:49.444Z",
    "MatchingHardwareId": "ms_ndiswanbh",
    "Name": "3C00570041004E0020004D0069006E00690070006F0072007400200028004E006500740077006F0072006B0020004D006F006E00690074006F0072002900",
    "OperStatus": 1,
    "OperStatusFlags": 0,
    "PnPFlags": 102435,
    "ProtocolList": "",
    "ProtocolListCount": 0,
    "SyncFlags": 0,
    "WSyncFlags": 0
  },
  "message": ""
}

Event ID 10601: task_010601

#
Channel
Operational
Also via
realtime ETW trace
Level
Informational
Opcode
win:Info

Fields #

NameDescription
ServiceName CountedUtf16String
ImageName CountedUtf16String
RegistryPath CountedUtf16String
MajorNdisVersion UInt8
MinorNdisVersion UInt8
DriverVersion UInt32
Flags UInt32
CharacteristicsFlags UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-NDIS",
    "guid": "{CDEAD503-17F5-4A3E-B7AE-DF8CC2902EB9}",
    "event_source_name": "",
    "event_id": 10601,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": "0x0000000000020000",
    "time_created": "2026-06-02T05:58:43.441+00:00",
    "event_record_id": 0,
    "correlation": {},
    "execution": {
      "process_id": 12516,
      "thread_id": 716
    },
    "channel": "ETW Trace",
    "computer": "DESKTOP-FF3N5XK",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "CharacteristicsFlags": 0,
    "DriverVersion": 65537,
    "Flags": 0,
    "ImageName": "16006E00640069007300770061006E002E00730079007300",
    "MajorNdisVersion": 6,
    "MinorNdisVersion": 30,
    "RegistryPath": "6E005C00520045004700490053005400520059005C004D0041004300480049004E0045005C00530059005300540045004D005C0043006F006E00740072006F006C005300650074003000300031005C00530065007200760069006300650073005C004E00640069007300570061006E00",
    "ServiceName": "0E004E00640069007300570061006E00"
  },
  "message": ""
}

Event ID 10602: task_010602

#
Channel
Operational
Also via
realtime ETW trace
Level
Informational
Opcode
win:Info

Fields #

NameDescription
ServiceName CountedUtf16String
UniqueName CountedUtf16String
FriendlyName CountedUtf16String
ImageName CountedUtf16String
MajorNdisVersion UInt8
MinorNdisVersion UInt8
MajorDriverVersion UInt8
MinorDriverVersion UInt8
Flags UInt32
CharacteristicsFlags UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-NDIS",
    "guid": "{CDEAD503-17F5-4A3E-B7AE-DF8CC2902EB9}",
    "event_source_name": "",
    "event_id": 10602,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": "0x0000000000020000",
    "time_created": "2026-06-02T05:58:43.441+00:00",
    "event_record_id": 0,
    "correlation": {},
    "execution": {
      "process_id": 12516,
      "thread_id": 716
    },
    "channel": "ETW Trace",
    "computer": "DESKTOP-FF3N5XK",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "CharacteristicsFlags": 0,
    "Flags": 0,
    "FriendlyName": "4E00480079007000650072002D00560020005600690072007400750061006C002000530077006900740063006800200045007800740065006E00730069006F006E002000460069006C00740065007200",
    "ImageName": "180076006D007300770069007400630068002E00730079007300",
    "MajorDriverVersion": 19,
    "MajorNdisVersion": 6,
    "MinorDriverVersion": 0,
    "MinorNdisVersion": 83,
    "ServiceName": "0C0056004D005300560053004600",
    "UniqueName": "4C007B00350032003900420038003900380033002D0039003600320035002D0034003900410035002D0038003200380034002D004300450039003400340046004400380045003200340032007D00"
  },
  "message": ""
}

Event ID 10603: task_010603

#
Channel
Operational
Also via
realtime ETW trace
Level
Informational
Opcode
win:Info

Fields #

NameDescription
ServiceName CountedUtf16String
ImageName CountedUtf16String
MajorNdisVersion UInt8
MinorNdisVersion UInt8
MajorDriverVersion UInt8
MinorDriverVersion UInt8
BindFlags UInt32
Guid GUID

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-NDIS",
    "guid": "{CDEAD503-17F5-4A3E-B7AE-DF8CC2902EB9}",
    "event_source_name": "",
    "event_id": 10603,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": "0x0000000000020000",
    "time_created": "2026-06-02T05:58:43.442+00:00",
    "event_record_id": 0,
    "correlation": {},
    "execution": {
      "process_id": 12516,
      "thread_id": 716
    },
    "channel": "ETW Trace",
    "computer": "DESKTOP-FF3N5XK",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "BindFlags": 1,
    "Guid": "{00000000-0000-0000-0000-000000000000}",
    "ImageName": "16006E00640069007300770061006E002E00730079007300",
    "MajorDriverVersion": 0,
    "MajorNdisVersion": 5,
    "MinorDriverVersion": 0,
    "MinorNdisVersion": 0,
    "ServiceName": "1A004E00440049005300570041004E004C0045004700410043005900"
  },
  "message": ""
}

Event ID 60001: Error: Error Location: Location Context: Context.

#
Channel
Diagnostic
Opcode
Info

Message #

Error: %1 Location: %2 Context: %3

Fields #

NameDescription
ErrorCode UInt32
Location UInt32
Context UInt32

Event ID 60002: Warning: Warning Location: Location Context: Context.

#
Channel
Diagnostic
Opcode
Info

Message #

Warning: %1 Location: %2 Context: %3

Fields #

NameDescription
WarningCode UInt32
Location UInt32
Context UInt32

Event ID 60003: Transitioned to State: NextState Context: Context.

#
Channel
Diagnostic
Opcode
Info

Message #

Transitioned to State: %1 Context: %2

Fields #

NameDescription
NextState UInt8
Context UInt32

Event ID 60004: Updated Context: Updated_Context Update Reason: Update_Reason.

#
Channel
Diagnostic
Opcode
Info

Message #

Updated Context: %1 Update Reason: %2

Fields #

NameDescription
Context UInt32
UpdateReasonCode UInt32

Event ID 60101: SourceAddress: SourceAddress SourcePort: SourcePort DestinationAddress: DestinationAddress DestinationPort: DestinationPort Protocol: Protocol ReferenceContext: ReferenceContext.

#
Channel
Diagnostic
Opcode
Info

Message #

SourceAddress: %1 SourcePort: %2 DestinationAddress: %3 DestinationPort: %4 Protocol: %5 ReferenceContext: %6

Fields #

NameDescription
SourceAddress UInt32
SourcePort UInt32
DestinationAddress UInt32
DestinationPort UInt32
Protocol UInt32
Known values
0
HOPOPT
1
ICMP
2
IGMP
6
TCP
17
UDP
41
IPv6
43
IPv6-Route
44
IPv6-Frag
47
GRE
50
ESP
51
AH
58
ICMPv6
89
OSPF
103
PIM
132
SCTP
ReferenceContext UInt32

Event ID 60102: SourceAddress: SourceAddress SourcePort: SourcePort DestinationAddress: DestinationAddress DestinationPort: DestinationPort Protocol: Protocol ReferenceContext: ReferenceContext.

#
Channel
Diagnostic
Opcode
Info

Message #

SourceAddress: %1 SourcePort: %2 DestinationAddress: %3 DestinationPort: %4 Protocol: %5 ReferenceContext: %6

Fields #

NameDescription
SourceAddress Binary
SourcePort UInt32
DestinationAddress Binary
DestinationPort UInt32
Protocol UInt32
Known values
0
HOPOPT
1
ICMP
2
IGMP
6
TCP
17
UDP
41
IPv6
43
IPv6-Route
44
IPv6-Frag
47
GRE
50
ESP
51
AH
58
ICMPv6
89
OSPF
103
PIM
132
SCTP
ReferenceContext UInt32

Event ID 60103: Interface Guid: Interface_Guid IfIndex: IfIndex Interface Luid: Interface_Luid ReferenceContext: ReferenceContext.

#
Channel
Diagnostic
Opcode
Info

Message #

Interface Guid: %1 IfIndex: %2 Interface Luid: %3 ReferenceContext: %4

Fields #

NameDescription
IfGuid GUID
IfIndex UInt32
IfLuid UInt64
ReferenceContext UInt32

Provenance

ETW provider GUID {CDEAD503-17F5-4A3E-B7AE-DF8CC2902EB9}

Defined in ndis.sys, the binary that emits these events.

  • WS2022-20348.4893, sample captured from a live trace, binary version 10.0.20348.1, captured 2026-06-02 — Manifest XML pack, 1.9 MB
  • Win11-26200.6584, sample captured from a live trace, binary version 10.0.26100.3323, captured 2026-06-02 — Manifest XML pack, 2.0 MB
  • WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.1, captured 2026-06-02 — Manifest XML pack, 1.9 MB
  • Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.3323, captured 2026-06-02 — Manifest XML pack, 2.0 MB