Microsoft-Windows-NLB-Diagnostic

14 events across 1 channel

EventTitleChannelSample
1FilteringReceiveAcceptDiagnosticN
2FilteringReceiveDropDiagnosticN
3FilteringReceiveAccept3DiagnosticN
4FilteringReceiveDrop4DiagnosticN
5FilteringSendAcceptDiagnosticN
6FilteringSendDropDiagnosticN
7FilteringSendAccept7DiagnosticN
8FilteringSendDrop8DiagnosticN
9AffinityCreateDiagnosticN
10AffinityDestroyDiagnosticN
11GhostingGhostDiagnosticN
12GhostingUnGhostDiagnosticN
13ConnectionUpDiagnosticN
14ConnectionDownDiagnosticN

Event ID 1: FilteringReceiveAccept

#
Provider
Microsoft-Windows-NLB-Diagnostic
Channel
Diagnostic
Task
Task.Filtering.ReceiveAccept

Message #

NLB cluster on interface %1 received traffic from %4 destined to %6 [protocol: %7 (%9), flags: %8]. This cluster node will accept this traffic (reason: %2). Source port %10, destination port %11, and protocol %12 have been used for the accept/drop decision.

Fields #

NameDescription
InterfaceGUID GUID
Reason UInt32
SourceIPLength UInt32
SourceIP Binary
DestinationIPLength UInt32
DestinationIP Binary
Protocol UInt8
Flags HexInt32
Data HexInt32
HashSourcePort UInt16
HashDestinationPort UInt16
HashProtocol UInt16
Bucket UInt8
CurrentBucketMap HexInt64

Event ID 2: FilteringReceiveDrop

#
Provider
Microsoft-Windows-NLB-Diagnostic
Channel
Diagnostic
Task
Task.Filtering.ReceiveDrop

Message #

NLB cluster on interface %1 received traffic from %4 destined to %6 [protocol: %7 (%9), flags: %8]. This cluster node will drop this traffic (reason: %2). Source port %10, destination port %11, and protocol %12 have been used for the accept/drop decision.

Fields #

NameDescription
InterfaceGUID GUID
Reason UInt32
SourceIPLength UInt32
SourceIP Binary
DestinationIPLength UInt32
DestinationIP Binary
Protocol UInt8
Flags HexInt32
Data HexInt32
HashSourcePort UInt16
HashDestinationPort UInt16
HashProtocol UInt16
Bucket UInt8
CurrentBucketMap HexInt64

Event ID 3: FilteringReceiveAccept3

#
Provider
Microsoft-Windows-NLB-Diagnostic
Channel
Diagnostic
Task
Task.Filtering.ReceiveAccept

Message #

NLB cluster on interface %1 received traffic from %4 destined to %6. This cluster node will accept this traffic (reason: %2). An application registered hook requested that source %8, destination %10, and protocol %11 be used for the accept/drop decision.

Fields #

NameDescription
InterfaceGUID GUID
Reason UInt32
SourceIPLength UInt32
SourceIP Binary
DestinationIPLength UInt32
DestinationIP Binary
HookSourceIPLength UInt32
HookSourceIP Binary
HookDestinationIPLength UInt32
HookDestinationIP Binary
Protocol UInt8
Flags HexInt32
Bucket UInt8
CurrentBucketMap HexInt64

Event ID 4: FilteringReceiveDrop4

#
Provider
Microsoft-Windows-NLB-Diagnostic
Channel
Diagnostic
Task
Task.Filtering.ReceiveDrop

Message #

NLB cluster on interface %1 received traffic from %4 destined to %6. This cluster node will drop this traffic (reason: %2). An application registered hook requested that source %8, destination %10, and protocol %11 be used for the accept/drop decision.

Fields #

NameDescription
InterfaceGUID GUID
Reason UInt32
SourceIPLength UInt32
SourceIP Binary
DestinationIPLength UInt32
DestinationIP Binary
HookSourceIPLength UInt32
HookSourceIP Binary
HookDestinationIPLength UInt32
HookDestinationIP Binary
Protocol UInt8
Flags HexInt32
Bucket UInt8
CurrentBucketMap HexInt64

Event ID 5: FilteringSendAccept

#
Provider
Microsoft-Windows-NLB-Diagnostic
Channel
Diagnostic
Task
Task.Filtering.SendAccept

Message #

NLB cluster on interface %1 intercepted outgoing traffic from %4 destined to %6 [protocol: %7 (%9), flags: %8]. This cluster node will send this traffic (reason: %2).

Fields #

NameDescription
InterfaceGUID GUID
Reason UInt32
SourceIPLength UInt32
SourceIP Binary
DestinationIPLength UInt32
DestinationIP Binary
Protocol UInt8
Flags HexInt32
Data HexInt32

Event ID 6: FilteringSendDrop

#
Provider
Microsoft-Windows-NLB-Diagnostic
Channel
Diagnostic
Task
Task.Filtering.SendDrop

Message #

NLB cluster on interface %1 intercepted outgoing traffic from %4 destined to %6 [protocol: %7 (%9), flags: %8]. This cluster node will drop this traffic (reason: %2).

Fields #

NameDescription
InterfaceGUID GUID
Reason UInt32
SourceIPLength UInt32
SourceIP Binary
DestinationIPLength UInt32
DestinationIP Binary
Protocol UInt8
Flags HexInt32
Data HexInt32

Event ID 7: FilteringSendAccept7

#
Provider
Microsoft-Windows-NLB-Diagnostic
Channel
Diagnostic
Task
Task.Filtering.SendAccept

Message #

NLB cluster on interface %1 intercepted outgoing traffic from %4 destined to %6. This cluster node will send this traffic (reason: %2). An application registered hook requested that source %8, destination %10, and protocol %11 be used for the accept/drop decision.

Fields #

NameDescription
InterfaceGUID GUID
Reason UInt32
SourceIPLength UInt32
SourceIP Binary
DestinationIPLength UInt32
DestinationIP Binary
HookSourceIPLength UInt32
HookSourceIP Binary
HookDestinationIPLength UInt32
HookDestinationIP Binary
Protocol UInt8
Flags HexInt32

Event ID 8: FilteringSendDrop8

#
Provider
Microsoft-Windows-NLB-Diagnostic
Channel
Diagnostic
Task
Task.Filtering.SendDrop

Message #

NLB cluster on interface %1 intercepted outgoing traffic from %4 destined to %6. This cluster node will drop this traffic (reason: %2). An application registered hook requested that source %8, destination %10, and protocol %11 be used for the accept/drop decision.

Fields #

NameDescription
InterfaceGUID GUID
Reason UInt32
SourceIPLength UInt32
SourceIP Binary
DestinationIPLength UInt32
DestinationIP Binary
HookSourceIPLength UInt32
HookSourceIP Binary
HookDestinationIPLength UInt32
HookDestinationIP Binary
Protocol UInt8
Flags HexInt32

Event ID 9: AffinityCreate

#
Provider
Microsoft-Windows-NLB-Diagnostic
Channel
Diagnostic
Task
Task.Affinity.Create

Message #

NLB cluster on interface %1 port %2 bucket %3 created client affinity for address %5.

Fields #

NameDescription
InterfaceGUID UnicodeString
PortId UInt16
BucketId UInt16
SourceIPLength UInt32
SourceIP Binary

Event ID 10: AffinityDestroy

#
Provider
Microsoft-Windows-NLB-Diagnostic
Channel
Diagnostic
Task
Task.Affinity.Destroy

Message #

NLB cluster on interface %1 port %2 bucket %3 destroyed client affinity for address %5.

Fields #

NameDescription
InterfaceGUID UnicodeString
PortId UInt16
BucketId UInt16
SourceIPLength UInt32
SourceIP Binary

Event ID 11: GhostingGhost

#
Provider
Microsoft-Windows-NLB-Diagnostic
Channel
Diagnostic
Task
Task.Ghosting.Ghost

Message #

NLB cluster ghosted client %6. interface=%1;port=%2;bucket=%3;otherhost=%4.

Fields #

NameDescription
InterfaceGUID UnicodeString
PortId UInt16
BucketId UInt16
HostId UInt16
SourceIPLength UInt32
SourceIP Binary

Event ID 12: GhostingUnGhost

#
Provider
Microsoft-Windows-NLB-Diagnostic
Channel
Diagnostic
Task
Task.Ghosting.UnGhost

Message #

NLB cluster unghosted client %6. interface=%1;port=%2;bucket=%3;otherhost=%4.

Fields #

NameDescription
InterfaceGUID UnicodeString
PortId UInt16
BucketId UInt16
HostId UInt16
SourceIPLength UInt32
SourceIP Binary

Event ID 13: ConnectionUp

#
Provider
Microsoft-Windows-NLB-Diagnostic
Channel
Diagnostic
Task
Task.Connection.Up

Message #

NLB cluster Connection Up %2 -> %4 references=%5, flags=%6.

Fields #

NameDescription
SourceIPLength UInt32
SourceIP Binary
DestinationIPLength UInt32
DestinationIP Binary
References UInt32
Flags HexInt32

Event ID 14: ConnectionDown

#
Provider
Microsoft-Windows-NLB-Diagnostic
Channel
Diagnostic
Task
Task.Connection.Down

Message #

NLB cluster Connection Down %2 -> %4 references=%5, flags=%6.

Fields #

NameDescription
SourceIPLength UInt32
SourceIP Binary
DestinationIPLength UInt32
DestinationIP Binary
References UInt32
Flags HexInt32

Provenance

Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.

ETW provider GUID def02e30-3290-4b2d-bc28-d2b0edadf411

Defined in nlb.sys, the binary that emits these events.

Observed on:

  • WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.1, captured 2026-06-02

Downloads