Microsoft-Windows-NLB-Diagnostic
14 events across 1 channel
| Event | Title | Channel | Sample |
|---|---|---|---|
| 1 | FilteringReceiveAccept | Diagnostic | N |
| 2 | FilteringReceiveDrop | Diagnostic | N |
| 3 | FilteringReceiveAccept3 | Diagnostic | N |
| 4 | FilteringReceiveDrop4 | Diagnostic | N |
| 5 | FilteringSendAccept | Diagnostic | N |
| 6 | FilteringSendDrop | Diagnostic | N |
| 7 | FilteringSendAccept7 | Diagnostic | N |
| 8 | FilteringSendDrop8 | Diagnostic | N |
| 9 | AffinityCreate | Diagnostic | N |
| 10 | AffinityDestroy | Diagnostic | N |
| 11 | GhostingGhost | Diagnostic | N |
| 12 | GhostingUnGhost | Diagnostic | N |
| 13 | ConnectionUp | Diagnostic | N |
| 14 | ConnectionDown | Diagnostic | N |
Event ID 1: FilteringReceiveAccept
#Event ID 2: FilteringReceiveDrop
#Event ID 3: FilteringReceiveAccept3
#Message #
Fields #
| Name | Description |
|---|---|
InterfaceGUID GUID | |
Reason UInt32 | |
SourceIPLength UInt32 | |
SourceIP Binary | |
DestinationIPLength UInt32 | |
DestinationIP Binary | |
HookSourceIPLength UInt32 | |
HookSourceIP Binary | |
HookDestinationIPLength UInt32 | |
HookDestinationIP Binary | |
Protocol UInt8 | |
Flags HexInt32 | |
Bucket UInt8 | |
CurrentBucketMap HexInt64 |
Event ID 4: FilteringReceiveDrop4
#Message #
Fields #
| Name | Description |
|---|---|
InterfaceGUID GUID | |
Reason UInt32 | |
SourceIPLength UInt32 | |
SourceIP Binary | |
DestinationIPLength UInt32 | |
DestinationIP Binary | |
HookSourceIPLength UInt32 | |
HookSourceIP Binary | |
HookDestinationIPLength UInt32 | |
HookDestinationIP Binary | |
Protocol UInt8 | |
Flags HexInt32 | |
Bucket UInt8 | |
CurrentBucketMap HexInt64 |
Event ID 5: FilteringSendAccept
#Event ID 6: FilteringSendDrop
#Event ID 7: FilteringSendAccept7
#Event ID 8: FilteringSendDrop8
#Event ID 9: AffinityCreate
#Event ID 10: AffinityDestroy
#Event ID 11: GhostingGhost
#Event ID 12: GhostingUnGhost
#Event ID 13: ConnectionUp
#Event ID 14: ConnectionDown
#Provenance
Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.
ETW provider GUID def02e30-3290-4b2d-bc28-d2b0edadf411
Defined in nlb.sys, the binary that emits these events.
Observed on:
- WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.1, captured 2026-06-02