Microsoft-Windows-Ntfs

72 events across 4 channels

EventTitleChannelSample
1RundownStartPerformanceY
2RundownCompletePerformanceY
3RundownVolumeInformation VolumeId: RundownVolumeInformation_VolumeId, …PerformanceY
4The NTFS volume has been successfully mounted.OperationalY
5NTFS KSR data retrieved successfully.OperationalN
6NTFS KSR data retrieval failed.OperationalN
7Ntfs has detected torn write on a volume.SystemN
8File's duplicate info has been updated during flush.OperationalN
9NTFS scanned entire volume bitmap.OperationalY
10NTFS cached runs statistics.OperationalY
11NTFS KSR data prepared successfully.OperationalN
12NTFS KSR data prepare failed.OperationalN
13NTFS KSR data filled successfully.OperationalN
14NTFS KSR data fill failed.OperationalN
98Volume DriveName (DeviceName) CorruptionActionState.SystemY
100NTFS global corruption action state is now hc_stateid.WHCY
139The file system structure that maintains security information on volume …OperationalN
140The system failed to flush data to the transaction log.SystemN
141An operation failed because the disk was full.OperationalN
142Summary of disk space usage, since last event.OperationalY
143Surprise removal of a persistent memory device with active DAX mappings.SystemN
144A volume that already has DAX mappings is being mounted.SystemN
145IO latency summary common data for volume.OperationalN
146IO latency summary.OperationalN
147An IO took more than MaxLatencyMs ms to complete.OperationalY
148A FileIdHigh failed with StartingLcn.OperationalN
149In the past SecondsElapsed seconds we had high latency IOs and/or IO failures.OperationalY
150An IO failed with FailureStatus and NTFS has relocated the clusters.SystemN
151In the past SecondsElapsed seconds TotalCountDeleteFile files were deleted from …OperationalY
152A process has not acknowledged an NTFS oplock break in a long time.OperationalN
154System file pages are now locked into memory.OperationalN
155System file pages are no longer locked into memory.OperationalN
156VCB exclusive resource acquires.OperationalY
157An exclusive resource duration exceeded MaxDurationMs ms.OperationalY
158NTFS metadata statistics for volume.OperationalY
159NTFS has successfully completed the VolumeSizeChangeRequestType request in …OperationalY
160NTFS has failed to complete the VolumeSizeChangeOperation request after …OperationalN
161An operation has failed due to a file system limitation.OperationalN
162The data read from the storage does not match what was previously written or …SystemN
163MftBitmap is not big enough for MftData or does not have required allocations.SystemN
170IO latency summary.OperationalY
171File-Level Trim Summary.OperationalY
201NtfsLogFileFull VolumeId: NtfsLogFileFull_VolumeId, Reason: Reason.PerformanceN
202PeriodicCheckpointStart VolumeId: PeriodicCheckpointStart_VolumeId, Reason: …PerformanceY
203PeriodicCheckpointComplete VolumeId: PeriodicCheckpointComplete_VolumeId, …PerformanceY
204CleanCheckpointStart VolumeId: CleanCheckpointStart_VolumeId, Reason: Reason, …PerformanceN
205CleanCheckpointComplete VolumeId: CleanCheckpointComplete_VolumeId, …PerformanceN
206MftRecordRead VolumeId: MftRecordRead_VolumeId, BaseFileId: BaseFileId, FileId: …PerformanceY
208MftRecordRead VolumeId: MftRecordRead_VolumeId, BaseFileId: BaseFileId, FileId: …PerformanceN
210Thinly provisioned volume VolumeId (DeviceName).SystemN
211Thinly provisioned volume VolumeId (DeviceName).SystemN
230WorkItem queued, WorkItem: WorkItem_queued_WorkItem, Reason: Reason.PerformanceY
231WorkItem queue failed, WorkItem: WorkItem_queue_failed_WorkItem, Reason: Reason, …PerformanceN
232WorkItem started, WorkItem: WorkItem_started_WorkItem, Reason: Reason.PerformanceY
233WorkItem completed, WorkItem: WorkItem_completed_WorkItem, Reason: Reason.PerformanceY
240File metadata optimization started.PerformanceN
241File metadata optimization completed.PerformanceN
300NTFS volume dismount has started.OperationalY
301NTFS has sent volume dismount event notification and is waiting for the …OperationalY
302The volume dismount event notification on the NTFS volume has completed.OperationalY
303The NTFS volume has successfully dismounted.OperationalY
304The NTFS volume dismount failed.OperationalN
305NTFS failed to mount the volume.OperationalN
401Efs offloading initiated.PerformanceN
402Efs offloading read regular file.PerformanceN
403Efs offloading write regular file.PerformanceN
404Efs legacy initiated.PerformanceY
405Efs legacy read regular file.PerformanceN
406Efs legacy write regular file.PerformanceN
500A process has created a USN journal on a volume.OperationalY
501A process has deleted a USN journal on a volume.OperationalY
502File has been opened by an isolated reader.PerformanceN

Event ID 1: RundownStart

#
Provider
Microsoft-Windows-Ntfs
Channel
Performance
Level
Informational
Task
Rundown
Opcode
Start

Description

RundownStart.

Message #

RundownStart

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Ntfs",
    "guid": "{3FF37A1C-A68D-4D6E-8C9B-F79E8B16C482}",
    "event_source_name": "",
    "event_id": 1,
    "version": 0,
    "level": 4,
    "task": 5,
    "opcode": 1,
    "keywords": "0x1000000000000010",
    "time_created": "2026-06-02T05:29:46.295+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{877F78A1-F053-0001-D39A-828753F0DC01}"
    },
    "execution": {
      "process_id": 13444,
      "thread_id": 12168
    },
    "channel": "ETW Trace",
    "computer": "JD-DC01-2022",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": "Rundown"
}

Event ID 2: RundownComplete

#
Provider
Microsoft-Windows-Ntfs
Channel
Performance
Level
Informational
Task
Rundown
Opcode
Stop

Description

RundownComplete.

Message #

RundownComplete

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Ntfs",
    "guid": "{3FF37A1C-A68D-4D6E-8C9B-F79E8B16C482}",
    "event_source_name": "",
    "event_id": 2,
    "version": 0,
    "level": 4,
    "task": 5,
    "opcode": 2,
    "keywords": "0x1000000000000010",
    "time_created": "2026-06-02T05:29:46.295+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{877F78A1-F053-0001-D39A-828753F0DC01}"
    },
    "execution": {
      "process_id": 13444,
      "thread_id": 12168
    },
    "channel": "ETW Trace",
    "computer": "JD-DC01-2022",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": "Rundown"
}

Event ID 3: RundownVolumeInformation VolumeId: RundownVolumeInformation_VolumeId, DeviceName: Vcb.

#
Provider
Microsoft-Windows-Ntfs
Channel
Performance
Also via
realtime ETW trace
Level
Informational
Task
Rundown
Opcode
win:Info

Description

RundownVolumeInformation VolumeId: RundownVolumeInformation_VolumeId, DeviceName: Vcb.

Message #

RundownVolumeInformation VolumeId: %1, DeviceName: %3

Fields #

NameDescription
Vcb Pointer
DeviceNameLength UInt16
DeviceName UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Ntfs",
    "guid": "{3FF37A1C-A68D-4D6E-8C9B-F79E8B16C482}",
    "event_source_name": "",
    "event_id": 3,
    "version": 0,
    "level": 4,
    "task": 5,
    "opcode": 0,
    "keywords": "0x1000000000000010",
    "time_created": "2026-06-02T05:29:46.295+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{877F78A1-F053-0001-D39A-828753F0DC01}"
    },
    "execution": {
      "process_id": 13444,
      "thread_id": 12168
    },
    "channel": "ETW Trace",
    "computer": "JD-DC01-2022",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "DeviceName": "\\Device\\HarddiskVolume1",
    "DeviceNameLength": 23,
    "Vcb": "0x0"
  },
  "message": "Rundown"
}

Event ID 4: The NTFS volume has been successfully mounted.

#
Provider
Microsoft-Windows-Ntfs
Channel
Operational
Level
Informational
Task
Volumemount

Description

The NTFS volume has been successfully mounted.

Message #

The NTFS volume has been successfully mounted.

           Volume GUID: %4
           Volume Name: %6
           Volume Label: %8
           Device Name: %3

Fields #

NameDescription
VolumeCorrelationId GUID
VolumeIdLength UInt16
VolumeId UnicodeStringVolume name.
VolumeLabelLength UInt16
VolumeLabel UnicodeString
DeviceNameLength UInt16
DeviceName UnicodeString
DeviceGuid GUID
VendorIdLength UInt32
VendorId UnicodeStringDevice manufacturer.
ProductIdLength UInt32
ProductId UnicodeStringDevice model.
ProductRevisionLength UInt32
ProductRevision UnicodeStringDevice revision.
DeviceSerialNumberLength UInt32
DeviceSerialNumber UnicodeString
BusType UInt32
AdapterSerialNumberLength UInt32
AdapterSerialNumber UnicodeString
Vcb Pointer
MountDurationUs UInt64
MountDuration UnicodeStringTotal mount duration.
LongestStage UInt64
LongestStageDuration UnicodeString
LongestStagePercentage UInt64
SecondLongestStage UInt64
SecondLongestStageDuration UnicodeString
SecondLongestStagePercentage UInt64
RestartApplied BooleanVolume restart applied.
IsBootVolume Boolean
Stage1DurationUs UInt64
Stage2DurationUs UInt64
Stage3DurationUs UInt64
Stage4DurationUs UInt64
Stage5DurationUs UInt64
Stage6DurationUs UInt64
Stage7DurationUs UInt64
Stage8DurationUs UInt64
Stage9DurationUs UInt64
Stage10DurationUs UInt64
DeviceNumber
NativeNVMe

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Ntfs",
    "guid": "{3FF37A1C-A68D-4D6E-8C9B-F79E8B16C482}",
    "event_source_name": "",
    "event_id": 4,
    "version": 1,
    "level": 4,
    "task": 6,
    "opcode": 0,
    "keywords": 4611967493404098592,
    "time_created": "2026-05-29T16:32:44.9878791+00:00",
    "event_record_id": 457,
    "correlation": {},
    "execution": {
      "process_id": 4,
      "thread_id": 200
    },
    "channel": "Microsoft-Windows-Ntfs/Operational",
    "computer": "telemetry-DC-a.cell-a.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "VolumeCorrelationId": "{77ac4d73-0000-0000-0000-100000000000}",
    "VolumeIdLength": "2",
    "VolumeId": "C:",
    "VolumeLabelLength": "12",
    "VolumeLabel": "Windows 2022",
    "DeviceNameLength": "23",
    "DeviceName": "\\Device\\HarddiskVolume1",
    "DeviceGuid": "{5a7d9ced-a852-a1ac-e3da-7b3e59928b2a}",
    "VendorIdLength": "8",
    "VendorId": "Red Hat ",
    "ProductIdLength": "6",
    "ProductId": "VirtIO",
    "ProductRevisionLength": "4",
    "ProductRevision": "0001",
    "DeviceSerialNumberLength": "0",
    "DeviceSerialNumber": "",
    "BusType": "1",
    "AdapterSerialNumberLength": "0",
    "AdapterSerialNumber": "",
    "Vcb": "0xffffd3853a0b61b0",
    "MountDurationUs": "61931",
    "MountDuration": "61 ms",
    "LongestStage": "7",
    "LongestStageDuration": "46 ms",
    "LongestStagePercentage": "76",
    "SecondLongestStage": "4",
    "SecondLongestStageDuration": "15 ms",
    "SecondLongestStagePercentage": "24",
    "RestartApplied": "false",
    "IsBootVolume": "true",
    "Stage1DurationUs": "0",
    "Stage2DurationUs": "0",
    "Stage3DurationUs": "0",
    "Stage4DurationUs": "15056",
    "Stage5DurationUs": "0",
    "Stage6DurationUs": "0",
    "Stage7DurationUs": "46875",
    "Stage8DurationUs": "0",
    "Stage9DurationUs": "0",
    "Stage10DurationUs": "0"
  },
  "message": "The NTFS volume has been successfully mounted.\r\n\r\n           Volume correlation Id: {77ac4d73-0000-0000-0000-100000000000}\r\n           Volume name: C:\r\n           Volume label: Windows 2022\r\n\r\n           Device name: \\Device\\HarddiskVolume1\r\n           Device GUID: {5a7d9ced-a852-a1ac-e3da-7b3e59928b2a}\r\n           Device manufacturer: Red Hat \r\n           Device model: VirtIO\r\n           Device revision: 0001\r\n           Device serial number: \r\n           Bus type: SCSI\r\n\r\n           Adapter serial number: \r\n           \r\n           Total mount duration: 61 ms\r\n           Longest stage: 7. Duration 46 ms (76% of the total)\r\n           Second longest stage: 4. Duration 15 ms (24% of the total)\r\n           Volume restart applied: false\r\n"
}

Event ID 5: NTFS KSR data retrieved successfully.

#
Provider
Microsoft-Windows-Ntfs
Channel
Operational
Task
KSR

Description

NTFS KSR data retrieved successfully.

Message #

NTFS KSR data retrieved successfully.

           Volume GUID: %4
           Device Name: %3

           NTFS KSR version: %5
           Number of runs restored: %6
           Time to restore (ms): %7

Fields #

NameDescription
Vcb Pointer
DeviceNameLength UInt16
DeviceName UnicodeString
VolumeGuid GUID
Version UInt16
CachedRunsRestoredRunCount UInt32
CachedRunsRestoredTimeMs UInt32

Event ID 6: NTFS KSR data retrieval failed.

#
Provider
Microsoft-Windows-Ntfs
Channel
Operational
Task
KSR

Description

NTFS KSR data retrieval failed.

Message #

NTFS KSR data retrieval failed.

           Volume GUID: %4
           Device Name: %3
           Error: %6

Fields #

NameDescription
Vcb Pointer
DeviceNameLength UInt16
DeviceName UnicodeString
VolumeGuid GUID
MessageLength UInt16
Message UnicodeString
FailureStatus HexInt32
SourceTag UInt32

Event ID 7: Ntfs has detected torn write on a volume.

#
Provider
Microsoft-Windows-Ntfs
Channel
System
Opcode
Info

Description

Ntfs has detected torn write on a volume.

Message #

Ntfs has detected torn write on a volume.

           Volume correlation Id: %1
           Volume name: %3
           Volume label: %5
           File reference: %6
           File name: %8
           Byte offset of the buffer within the file: %9
           Byte offset of the torn structure within the buffer: %10
           Block index: %11
           Expected sequence number: %12
           Actual sequence number: %13

Fields #

NameDescription
VolumeCorrelationId GUID
VolumeNameLength UInt32
VolumeName UnicodeString
VolumeLabelLength UInt16
VolumeLabel UnicodeString
FileReference UInt64
FileNameLength UInt32
FileName UnicodeString
BufferOffset UInt64
TornStructureOffset UInt32
BlockIndex UInt16
ExpectedSequenceNumber UInt16
ActualSequenceNumber UInt16
FrsFileReference UInt64
FrsFileNameLength UInt32
FrsFileName UnicodeString
IsChildFRS Boolean

Event ID 8: File's duplicate info has been updated during flush.

#
Provider
Microsoft-Windows-Ntfs
Channel
Operational
Opcode
Info

Description

File's duplicate info has been updated during flush.

Message #

File's duplicate info has been updated during flush.

           Volume correlation Id: %1
           Volume name: %3
           File Reference: %4
           File Name: %6
           File Link name: %8
           Parent file reference: %9
           Parent file name: %11
           Update Reason: [%12] %13

Fields #

NameDescription
VolumeCorrelationId GUID
VolumeNameLength UInt32
VolumeName UnicodeString
FileReference UInt64
FileNameLength UInt32
FileName UnicodeString
FileLinkNameLength UInt32
FileLinkName UnicodeString
ParentFileReference UInt64
ParentFileNameLength UInt32
ParentFileName UnicodeString
Reason HexInt32
ReasonText UInt16

Event ID 9: NTFS scanned entire volume bitmap.

#
Provider
Microsoft-Windows-Ntfs
Channel
Operational
Level
Informational
Opcode
Info

Description

NTFS scanned entire volume bitmap.

Message #

NTFS scanned entire volume bitmap.

           Volume correlation Id: %1
           Volume name: %3
           Volume label: %5

           Device name: %7
           Device GUID: %8
           Device manufacturer: %10
           Device model: %12
           Device revision: %14
           Device serial number: %16
           Bus type: %17

           Adapter serial number: %19

           Duration (micro seconds): %20
           InputFlags: %21
           Reason: %22
           Flags: %23

Fields #

NameDescription
VolumeCorrelationId GUID
VolumeIdLength UInt16
VolumeId UnicodeStringVolume name.
VolumeLabelLength UInt16
VolumeLabel UnicodeString
DeviceNameLength UInt16
DeviceName UnicodeString
DeviceGuid GUID
VendorIdLength UInt32
VendorId UnicodeStringDevice manufacturer.
ProductIdLength UInt32
ProductId UnicodeStringDevice model.
ProductRevisionLength UInt32
ProductRevision UnicodeStringDevice revision.
DeviceSerialNumberLength UInt32
DeviceSerialNumber UnicodeString
BusType UInt32
AdapterSerialNumberLength UInt32
AdapterSerialNumber UnicodeString
DurationUs UInt32Duration (micro seconds).
InputFlags HexInt32
Reason UInt32
Flags HexInt32
NativeNVMe

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Ntfs",
    "guid": "{3FF37A1C-A68D-4D6E-8C9B-F79E8B16C482}",
    "event_source_name": "",
    "event_id": 9,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 4611686018429485056,
    "time_created": "2026-05-29T16:32:44.9878759+00:00",
    "event_record_id": 456,
    "correlation": {},
    "execution": {
      "process_id": 4,
      "thread_id": 196
    },
    "channel": "Microsoft-Windows-Ntfs/Operational",
    "computer": "telemetry-DC-a.cell-a.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "VolumeCorrelationId": "{77ac4d73-0000-0000-0000-100000000000}",
    "VolumeIdLength": "2",
    "VolumeId": "C:",
    "VolumeLabelLength": "12",
    "VolumeLabel": "Windows 2022",
    "DeviceNameLength": "23",
    "DeviceName": "\\Device\\HarddiskVolume1",
    "DeviceGuid": "{5a7d9ced-a852-a1ac-e3da-7b3e59928b2a}",
    "VendorIdLength": "8",
    "VendorId": "Red Hat ",
    "ProductIdLength": "6",
    "ProductId": "VirtIO",
    "ProductRevisionLength": "4",
    "ProductRevision": "0001",
    "DeviceSerialNumberLength": "0",
    "DeviceSerialNumber": "",
    "BusType": "1",
    "AdapterSerialNumberLength": "0",
    "AdapterSerialNumber": "",
    "DurationUs": "42083",
    "InputFlags": "0xe",
    "Reason": "1",
    "Flags": "0x10"
  },
  "message": "NTFS scanned entire volume bitmap.\r\n\r\n           Volume correlation Id: {77ac4d73-0000-0000-0000-100000000000}\r\n           Volume name: C:\r\n           Volume label: Windows 2022\r\n\r\n           Device name: \\Device\\HarddiskVolume1\r\n           Device GUID: {5a7d9ced-a852-a1ac-e3da-7b3e59928b2a}\r\n           Device manufacturer: Red Hat \r\n           Device model: VirtIO\r\n           Device revision: 0001\r\n           Device serial number: \r\n           Bus type: SCSI\r\n\r\n           Adapter serial number: \r\n\r\n           Duration (micro seconds): 42083\r\n           InputFlags: 0xE\r\n           Reason: Mount\r\n           Flags: 0x10\r\n"
}

Event ID 10: NTFS cached runs statistics.

#
Provider
Microsoft-Windows-Ntfs
Channel
Operational
Level
Informational
Opcode
Info

Description

NTFS cached runs statistics.

Message #

NTFS cached runs statistics.

           Volume correlation Id: %1
           Volume name: %2
           Volume label: %3

           Device name: %4
           Device GUID: %5
           Device manufacturer: %6
           Device model: %7
           Device revision: %8
           Device serial number: %9
           Bus type: %10

           Adapter serial number: %11

           Media type: %12
           Runs cached: %13
           Longest run cached: %15
           Most populated bin Count: %16
           Most populated bin's minimum length: %18
           Most populated bin's maximum length: %20

Fields #

NameDescription
VolumeCorrelationId GUID
VolumeId UnicodeStringVolume name.
VolumeLabel UnicodeString
DeviceName UnicodeString
DeviceGuid GUID
VendorId UnicodeStringDevice manufacturer.
ProductId UnicodeStringDevice model.
ProductRevision UnicodeStringDevice revision.
DeviceSerialNumber UnicodeString
BusType UInt32
AdapterSerialNumber UnicodeString
MediaType
RunsCached
LongestRunCached
LongestRunCachedStr
MostPopulatedBinCount
MostPopulatedBinMinLength
MostPopulatedBinMinLengthStr
MostPopulatedBinMaxLength
MostPopulatedBinMaxLengthStr
TotalCachedRuns
CachedRunsLogged
CachedRunsAlignment
RunsInCachedRuns
LongestRunInCachedRuns
MostPopulatedBinCountInCachedRuns
MostPopulatedBinMinLengthInCachedRuns
MostPopulatedBinMaxLengthInCachedRuns
CapacityTierName
CapacityMediaType
CapacityRunsCached
CapacityLongestRunCached
CapacityLongestRunCachedStr
CapacityMostPopulatedBinCount
CapacityMostPopulatedBinMinLength
CapacityMostPopulatedBinMinLengthStr
CapacityMostPopulatedBinMaxLength
CapacityMostPopulatedBinMaxLengthStr
CapacityTotalCachedRuns
CapacityCachedRunsLogged
CapacityCachedRunsAlignment
CapacityRunsInCachedRuns
CapacityLongestRunInCachedRuns
CapacityMostPopulatedBinCountInCachedRuns
CapacityMostPopulatedBinMinLengthInCachedRuns
CapacityMostPopulatedBinMaxLengthInCachedRuns
PerfTierName
PerfMediaType
PerfRunsCached
PerfLongestRunCached
PerfLongestRunCachedStr
PerfMostPopulatedBinCount
PerfMostPopulatedBinMinLength
PerfMostPopulatedBinMinLengthStr
PerfMostPopulatedBinMaxLength
PerfMostPopulatedBinMaxLengthStr
PerfTotalCachedRuns
PerfCachedRunsLogged
PerfCachedRunsAlignment
PerfRunsInCachedRuns
PerfLongestRunInCachedRuns
PerfMostPopulatedBinCountInCachedRuns
PerfMostPopulatedBinMinLengthInCachedRuns
PerfMostPopulatedBinMaxLengthInCachedRuns

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Ntfs",
    "guid": "{3FF37A1C-A68D-4D6E-8C9B-F79E8B16C482}",
    "event_source_name": "",
    "event_id": 10,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 4611686018429485056,
    "time_created": "2026-05-29T16:32:44.9878958+00:00",
    "event_record_id": 458,
    "correlation": {},
    "execution": {
      "process_id": 4,
      "thread_id": 196
    },
    "channel": "Microsoft-Windows-Ntfs/Operational",
    "computer": "telemetry-DC-a.cell-a.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "VolumeCorrelationId": "{77ac4d73-0000-0000-0000-100000000000}",
    "VolumeId": "C:",
    "VolumeLabel": "Windows 2022",
    "DeviceName": "\\Device\\HarddiskVolume1",
    "DeviceGuid": "{5a7d9ced-a852-a1ac-e3da-7b3e59928b2a}",
    "VendorId": "Red Hat ",
    "ProductId": "VirtIO",
    "ProductRevision": "0001",
    "DeviceSerialNumber": "",
    "BusType": "1",
    "AdapterSerialNumber": "",
    "MediaType": "1",
    "RunsCached": "818",
    "LongestRunCached": "33034878976",
    "LongestRunCachedStr": "30.77 GB",
    "MostPopulatedBinCount": "278",
    "MostPopulatedBinMinLength": "0",
    "MostPopulatedBinMinLengthStr": "0 Bytes",
    "MostPopulatedBinMaxLength": "4096",
    "MostPopulatedBinMaxLengthStr": "4 KB",
    "TotalCachedRuns": "1",
    "CachedRunsLogged": "1",
    "CachedRunsAlignment": "1",
    "RunsInCachedRuns": "818",
    "LongestRunInCachedRuns": "33034878976",
    "MostPopulatedBinCountInCachedRuns": "278",
    "MostPopulatedBinMinLengthInCachedRuns": "0",
    "MostPopulatedBinMaxLengthInCachedRuns": "4096"
  },
  "message": "NTFS cached runs statistics.\r\n\r\n           Volume correlation Id: {77ac4d73-0000-0000-0000-100000000000}\r\n           Volume name: C:\r\n           Volume label: Windows 2022\r\n\r\n           Device name: \\Device\\HarddiskVolume1\r\n           Device GUID: {5a7d9ced-a852-a1ac-e3da-7b3e59928b2a}\r\n           Device manufacturer: Red Hat \r\n           Device model: VirtIO\r\n           Device revision: 0001\r\n           Device serial number: \r\n           Bus type: SCSI\r\n\r\n           Adapter serial number: \r\n\r\n           Media type: Hard disk\r\n           Runs cached: 818\r\n           Longest run cached: 30.77 GB\r\n           Most populated bin Count: 278\r\n           Most populated bin's minimum length: 0 Bytes\r\n           Most populated bin's maximum length: 4 KB\r\n"
}

Event ID 11: NTFS KSR data prepared successfully.

#
Provider
Microsoft-Windows-Ntfs
Channel
Operational
Task
KSR

Description

NTFS KSR data prepared successfully.

Message #

NTFS KSR data prepared successfully.

           Volume GUID: %4
           Device Name: %3

           NTFS KSR version: %5
           Number of runs prepared: %6
           Time to prepare (ms): %7

Fields #

NameDescription
Vcb Pointer
DeviceNameLength UInt16
DeviceName UnicodeString
VolumeGuid GUID
Version UInt16
CachedRunsPreparedRunCount UInt32
CachedRunsPreparedTimeMs UInt32

Event ID 12: NTFS KSR data prepare failed.

#
Provider
Microsoft-Windows-Ntfs
Channel
Operational
Task
KSR

Description

NTFS KSR data prepare failed.

Message #

NTFS KSR data prepare failed.

           Volume GUID: %4
           Device Name: %3
           Error: %6
           Failure Status: %7           Source Tag: %8

Fields #

NameDescription
Vcb Pointer
DeviceNameLength UInt16
DeviceName UnicodeString
VolumeGuid GUID
MessageLength UInt16
Message UnicodeString
FailureStatus HexInt32
SourceTag UInt32

Event ID 13: NTFS KSR data filled successfully.

#
Provider
Microsoft-Windows-Ntfs
Channel
Operational
Task
KSR

Description

NTFS KSR data filled successfully.

Message #

NTFS KSR data filled successfully.

           Volume GUID: %4
           Device Name: %3

           NTFS KSR version: %5
           Number of runs filled: %6
           Time to fill (ms): %7

Fields #

NameDescription
Vcb Pointer
DeviceNameLength UInt16
DeviceName UnicodeString
VolumeGuid GUID
Version UInt16
CachedRunsFilledRunCount UInt32
CachedRunsFilledTimeMs UInt32

Event ID 14: NTFS KSR data fill failed.

#
Provider
Microsoft-Windows-Ntfs
Channel
Operational
Task
KSR

Description

NTFS KSR data fill failed.

Message #

NTFS KSR data fill failed.

           Volume GUID: %4
           Device Name: %3
           Error: %6
           Failure Status: %7           Source Tag: %8

Fields #

NameDescription
Vcb Pointer
DeviceNameLength UInt16
DeviceName UnicodeString
VolumeGuid GUID
MessageLength UInt16
Message UnicodeString
FailureStatus HexInt32
SourceTag UInt32

Event ID 98: Volume DriveName (DeviceName) CorruptionActionState.

#
Provider
Microsoft-Windows-Ntfs
Channel
System
Level
Informational
Opcode
Info

Description

Volume DriveName (DeviceName) CorruptionActionState.

Message #

Volume %1 (%2) %3

Fields #

NameDescriptionRules
DriveName UnicodeString
DeviceName UnicodeString1 detection rule
CorruptionActionState UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Ntfs",
    "guid": "{3FF37A1C-A68D-4D6E-8C9B-F79E8B16C482}",
    "event_source_name": "",
    "event_id": 98,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": -9223372036854775806,
    "time_created": "2026-05-29T16:32:44.9878875+00:00",
    "event_record_id": 6677,
    "correlation": {},
    "execution": {
      "process_id": 4,
      "thread_id": 200
    },
    "channel": "System",
    "computer": "telemetry-DC-a.cell-a.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "DriveName": "C:",
    "DeviceName": "\\Device\\HarddiskVolume1",
    "CorruptionActionState": "0"
  },
  "message": "Volume C: (\\Device\\HarddiskVolume1) is healthy.  No action is needed."
}

Detection Rules #

View all rules referencing this event →

Sigma # view in coverage

Event ID 100: NTFS global corruption action state is now hc_stateid.

#
Provider
Microsoft-Windows-Ntfs
Channel
WHC
Level
Informational
Opcode
Info

Description

NTFS global corruption action state is now hc_stateid.

Message #

NTFS global corruption action state is now %1.

Fields #

NameDescription
hc_stateid UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Ntfs",
    "guid": "{3FF37A1C-A68D-4D6E-8C9B-F79E8B16C482}",
    "event_source_name": "",
    "event_id": 100,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 2305843009213693953,
    "time_created": "2026-05-29T16:32:44.7906763+00:00",
    "event_record_id": 16,
    "correlation": {},
    "execution": {
      "process_id": 4,
      "thread_id": 8
    },
    "channel": "Microsoft-Windows-Ntfs/WHC",
    "computer": "telemetry-DC-a.cell-a.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "hc_stateid": "0"
  },
  "message": "NTFS global corruption action state is now 0."
}

Event ID 139: The file system structure that maintains security information on volume DriveName (DeviceName) has grown excessively large and fragmented.

#
Provider
Microsoft-Windows-Ntfs
Channel
Operational
Opcode
Info

Description

The file system structure that maintains security information on volume DriveName (DeviceName) has grown excessively large and fragmented. The structure has reached FragmentationLevel% of its maximum fragmentation limit. If the structure continues to grow and reaches this limit, it may not be possible to create new files on this volume. It is strongly recommended that the volume be taken offline for preventative maintenance.

Message #

The file system structure that maintains security information on volume %1 (%2) has grown excessively large and fragmented.  The structure has reached %3%% of its maximum fragmentation limit.  If the structure continues to grow and reaches this limit, it may not be possible to create new files on this volume.  It is strongly recommended that the volume be taken offline for preventative maintenance.

Fields #

NameDescription
DriveName UnicodeString
DeviceName UnicodeString
FragmentationLevel UInt16

Event ID 140: The system failed to flush data to the transaction log.

#
Provider
Microsoft-Windows-Ntfs
Channel
System
Opcode
Info

Description

The system failed to flush data to the transaction log. Corruption may occur in VolumeId: VolumeId, DeviceName: DeviceName.

Message #

The system failed to flush data to the transaction log. Corruption may occur in VolumeId: %2, DeviceName: %4.

           Failure status: %5

           Device GUID: %6
           Device manufacturer: %8
           Device model: %10
           Device revision: %12
           Device serial number: %14
           Bus type: %15

           Adapter serial number: %17

Fields #

NameDescription
VolumeIdLength UInt32
VolumeId UnicodeString
DeviceNameLength UInt32
DeviceName UnicodeStringThe system failed to flush data to the transaction log. Corruption may occur in VolumeId.
Error HexInt32
DeviceGuid GUID
VendorIdLength UInt32
VendorId UnicodeString
ProductIdLength UInt32
ProductId UnicodeString
ProductRevisionLength UInt32
ProductRevision UnicodeString
DeviceSerialNumberLength UInt32
DeviceSerialNumber UnicodeString
BusType UInt32
AdapterSerialNumberLength UInt32
AdapterSerialNumber UnicodeString

Event ID 141: An operation failed because the disk was full.

#
Provider
Microsoft-Windows-Ntfs
Channel
Operational
Opcode
Info

Description

An operation failed because the disk was full.

Message #

An operation failed because the disk was full.

           Process: %5
           Free space in bytes: %7
           Total reserved space in bytes: %8
           Txf TotalAbortReservation space in bytes: %9
           Requested space in bytes: %10
           Page file size in bytes: %11
           Volume guid: %1
           Volume name: %3
           Is boot volume: %6
           Source Tag: %12

Your disk '%3' is full. Use disk cleanup to free up disk space by deleting unnecessary files. If this is a thinly provisioned volume the physical storage backing this volume may have been exhausted.

Fields #

NameDescription
VolumeGuid GUID
VolumeNameLength UInt32
VolumeName UnicodeString
ProcessNameLength UInt32
ProcessName UnicodeString
IsBootVolume Boolean
FreeSpaceInBytes UInt64
TotalReservedSpaceInBytes UInt64
TotalAbortReservationSpaceInBytes UInt64
RequestedSpaceInBytes UInt64
PageFileSize UInt64
SourceTag HexInt64

Event ID 142: Summary of disk space usage, since last event.

#
Provider
Microsoft-Windows-Ntfs
Channel
Operational
Level
Informational
Opcode
Info

Description

Summary of disk space usage, since last event.

Message #

Summary of disk space usage, since last event:

           Lowest free space in bytes: %4
           Highest free space in bytes: %5
           Page file size in bytes: 0
           Volume guid: %1
           Volume name: %3
           Is boot volume: %6

Fields #

NameDescription
VolumeGuid GUID[Summary of disk space usage, since last event] Volume guid.
VolumeNameLength UInt32
VolumeName UnicodeString[Summary of disk space usage, since last event] Volume name.
IsBootVolume Boolean[Summary of disk space usage, since last event] Is boot volume.
ElapsedSeconds UInt64[Summary of disk space usage, since last event] Elapsed seconds.
AvailabeSpaceMinStr UnicodeString
AvailabeSpaceMaxStr UnicodeString
AvailabeSpaceDeltaStr UnicodeString[Summary of disk space usage, since last event] Change in available space.
AvailableClustersMin UInt64[Summary of disk space usage, since last event] Available clusters were between.
AvailableClustersMax UInt64
UnallocatedClustersMin UInt64
UnallocatedClustersMax UInt64
ReservedClustersMin UInt64[Summary of disk space usage, since last event] Reserved clusters were between.
ReservedClustersMax UInt64
TxfAbortReservedClustersMin UInt64[Summary of disk space usage, since last event] Txf abort reserved clusters were between.
TxfAbortReservedClustersMax UInt64
PageFileSizeInBytes UInt64
PageFileSizeStr UnicodeString[Summary of disk space usage, since last event] Pagefile size.
VolumeSizeInBytes UInt64
VolumeSizeStr UnicodeString[Summary of disk space usage, since last event] Volume size.
ClusterSize UInt64[Summary of disk space usage, since last event] Bytes per cluster.
CachedRunsMissCountForMft UInt32
CachedRunsMissCountForMftZone UInt32[Summary of disk space usage, since last event] Slab size.
CachedRunsMissCount UInt32[Summary of disk space usage, since last event] Slabs in use.
SlabSizeInClusters
SlabSizeStr
SlabsInUse
TotalSlabsCount
MapFailureCount

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Ntfs",
    "guid": "{3FF37A1C-A68D-4D6E-8C9B-F79E8B16C482}",
    "event_source_name": "",
    "event_id": 142,
    "version": 3,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 4611686018429485056,
    "time_created": "2026-06-13T13:39:59.5439065+00:00",
    "event_record_id": 591,
    "correlation": {},
    "execution": {
      "process_id": 4,
      "thread_id": 4356
    },
    "channel": "Microsoft-Windows-Ntfs/Operational",
    "computer": "telemetry-DC-a.cell-a.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "VolumeGuid": "{77ac4d73-0000-0000-0000-100000000000}",
    "VolumeNameLength": "2",
    "VolumeName": "C:",
    "IsBootVolume": "true",
    "ElapsedSeconds": "3603",
    "AvailabeSpaceMinStr": "228.07 GB",
    "AvailabeSpaceMaxStr": "228.11 GB",
    "AvailabeSpaceDeltaStr": "38.99 MB",
    "AvailableClustersMin": "59785775",
    "AvailableClustersMax": "59795755",
    "UnallocatedClustersMin": "59911572",
    "UnallocatedClustersMax": "59921552",
    "ReservedClustersMin": "124288",
    "ReservedClustersMax": "124288",
    "TxfAbortReservedClustersMin": "1024",
    "TxfAbortReservedClustersMax": "1024",
    "PageFileSizeInBytes": "2550136832",
    "PageFileSizeStr": "2.38 GB",
    "VolumeSizeInBytes": "268433354752",
    "VolumeSizeStr": "250 GB",
    "ClusterSize": "4096",
    "CachedRunsMissCountForMft": "0",
    "CachedRunsMissCountForMftZone": "0",
    "CachedRunsMissCount": "0"
  },
  "message": "Summary of disk space usage, since last event:\r\n\r\n           Available space was between 228.07 GB and 228.11 GB\r\n           Change in available space: 38.99 MB\r\n           \r\n           Available clusters were between: 59785775 and 59795755\r\n           Reserved clusters were between: 124288 and 124288\r\n           Txf abort reserved clusters were between: 1024 and 1024\r\n           \r\n           Elapsed seconds: 3603\r\n           \r\n           Pagefile size: 2.38 GB\r\n           Volume size: 250 GB\r\n           Bytes per cluster: 4096\r\n           \r\n           Volume guid: {77ac4d73-0000-0000-0000-100000000000}\r\n           Volume name: C:\r\n           Is boot volume: true\r\n           \r\n           Cached runs miss counts:\r\n               For MFT: 0\r\n               For MFT zone: 0\r\n               Everything else: 0\r\n"
}

Event ID 143: Surprise removal of a persistent memory device with active DAX mappings.

#
Provider
Microsoft-Windows-Ntfs
Channel
System
Opcode
Info

Description

Surprise removal of a persistent memory device with active DAX mappings. This might lead to data corruption.

Message #

Surprise removal of a persistent memory device with active DAX mappings. This might lead to data corruption.

           Volume GUID: %4
           Volume Name: %6
           Volume Label: %8

Guidance:
A reboot is required to clean up the DAX mappings.

Fields #

NameDescription
Vcb Pointer
DeviceNameLength UInt16
DeviceName UnicodeString
VolumeGuid GUID
VolumeNameLength UInt16
VolumeName UnicodeString
VolumeLabelLength UInt16
VolumeLabel UnicodeString

Event ID 144: A volume that already has DAX mappings is being mounted.

#
Provider
Microsoft-Windows-Ntfs
Channel
System
Opcode
Info

Description

A volume that already has DAX mappings is being mounted. This generally occurs after surprise removal. This might lead to data corruption.

Message #

A volume that already has DAX mappings is being mounted. This generally occurs after surprise removal. This might lead to data corruption.

           Volume GUID: %4
           Volume Name: %6

Guidance:
A reboot is required to clean up the DAX mappings.

Fields #

NameDescription
Vcb Pointer
DeviceNameLength UInt16
DeviceName UnicodeString
VolumeGuid GUID
VolumeNameLength UInt16
VolumeName UnicodeString

Event ID 145: IO latency summary common data for volume.

#
Provider
Microsoft-Windows-Ntfs
Channel
Operational
Opcode
Info

Description

IO latency summary common data for volume.

Message #

IO latency summary common data for volume:

           Volume Id: %2
           Volume name: %4
           Is boot volume: %5

           Device GUID: %7
           Device manufacturer: %9
           Device model: %11
           Device revision: %13
           Device serial number: %15
           Bus type: %16

           Adapter serial number: %18

           Max Acceptable IO Latency: %19 ms

           Read/Write latency buckets (ns): [%20, %21, %22, %23, %24, %25, %26]
           Trim latency buckets (ns): [%27, %28, %29, %30, %31, %32, %33]
           Flush latency buckets (ns): [%34, %35, %36, %37, %38, %39, %40]

Fields #

NameDescription
Version UInt32
VolumeCorrelationId GUID
VolumeNameLength UInt32
VolumeName UnicodeString
IsBootVolume Boolean
TierIndex UInt32
DeviceGuid GUID
VendorIdLength UInt32
VendorId UnicodeString
ProductIdLength UInt32
ProductId UnicodeString
ProductRevisionLength UInt32
ProductRevision UnicodeString
DeviceSerialNumberLength UInt32
DeviceSerialNumber UnicodeString
BusType UInt32
AdapterSerialNumberLength UInt32
AdapterSerialNumber UnicodeString
MaxLatencyMs UInt64
ReadWriteLatencyBucket1 Int64
ReadWriteLatencyBucket2 Int64
ReadWriteLatencyBucket3 Int64
ReadWriteLatencyBucket4 Int64
ReadWriteLatencyBucket5 Int64
ReadWriteLatencyBucket6 Int64
ReadWriteLatencyBucket7 Int64
TrimLatencyBucket1 Int64
TrimLatencyBucket2 Int64
TrimLatencyBucket3 Int64
TrimLatencyBucket4 Int64
TrimLatencyBucket5 Int64
TrimLatencyBucket6 Int64
TrimLatencyBucket7 Int64
FlushLatencyBucket1 Int64
FlushLatencyBucket2 Int64
FlushLatencyBucket3 Int64
FlushLatencyBucket4 Int64
FlushLatencyBucket5 Int64
FlushLatencyBucket6 Int64
FlushLatencyBucket7 Int64

Event ID 146: IO latency summary.

#
Provider
Microsoft-Windows-Ntfs
Channel
Operational
Opcode
Info

Description

IO latency summary.

Message #

IO latency summary:

           Volume Id: %2
           Volume name: %4
           Is boot volume: %5

           Device GUID: %7
           Device manufacturer: %9
           Device model: %11
           Device revision: %13
           Device serial number: %15
           Bus type: %16

           Adapter serial number: %18

           Max Acceptable IO Latency: %19 ms

           Read/Write latency buckets (ns): [%20, %21, %22, %23, %24, %25, %26]
           Trim latency buckets (ns): [%27, %28, %29, %30, %31, %32, %33]
           Flush latency buckets (ns): [%34, %35, %36, %37, %38, %39, %40]

           Interval duration: %42 us

           Non-cached reads:
                     IO count: %43
                     Total bytes: %44
                     Avg latency: %45 ns

           Non-cached writes:
                     IO count: %46
                     Total bytes: %47
                     Avg latency: %48 ns

           File flushes:
                     IO count: %49
                     Avg latency: %50 ns

           Directory flushes:
                     IO count: %51
                     Avg latency: %52 ns

           Volume flushes:
                     IO count: %53
                     Avg latency: %54 ns

           File level trims:
                     IO count: %55
                     Total bytes: %56
                     Extents count: %57
                     Avg latency: %58 ns

           Volume trims:
                     IO count: %59
                     Total bytes: %60
                     Extents count: %61
                     Avg latency: %62 ns

           VCB exclusive resource acquires:
                     Acquire count: %71
                     Max wait duration: %72 ms
                     Avg wait duration: %73 ms
                     Max hold duration: %74 ms
                     Avg hold duration: %75 ms
                     Max combined duration: %76 ms
                     Avg combined duration: %77 ms

           For more details see the details tab.

Fields #

NameDescription
Version UInt32
VolumeCorrelationId GUID
VolumeNameLength UInt32
VolumeName UnicodeString
IsBootVolume Boolean
TierIndex UInt32
DeviceGuid GUID
VendorIdLength UInt32
VendorId UnicodeString
ProductIdLength UInt32
ProductId UnicodeString
ProductRevisionLength UInt32
ProductRevision UnicodeString
DeviceSerialNumberLength UInt32
DeviceSerialNumber UnicodeString
BusType UInt32
AdapterSerialNumberLength UInt32
AdapterSerialNumber UnicodeString
MaxLatencyMs UInt64
ReadWriteLatencyBucket1 Int64
ReadWriteLatencyBucket2 Int64
ReadWriteLatencyBucket3 Int64
ReadWriteLatencyBucket4 Int64
ReadWriteLatencyBucket5 Int64
ReadWriteLatencyBucket6 Int64
ReadWriteLatencyBucket7 Int64
TrimLatencyBucket1 Int64
TrimLatencyBucket2 Int64
TrimLatencyBucket3 Int64
TrimLatencyBucket4 Int64
TrimLatencyBucket5 Int64
TrimLatencyBucket6 Int64
TrimLatencyBucket7 Int64
FlushLatencyBucket1 Int64
FlushLatencyBucket2 Int64
FlushLatencyBucket3 Int64
FlushLatencyBucket4 Int64
FlushLatencyBucket5 Int64
FlushLatencyBucket6 Int64
FlushLatencyBucket7 Int64
HighIoLatencyCount UInt32
IntervalDurationUs Int64
NCReadIOCount UInt64
NCReadTotalBytes UInt64
NCReadAvgLatencyNs UInt64
NCWriteIOCount UInt64
NCWriteTotalBytes UInt64
NCWriteAvgLatencyNs UInt64
FileFlushCount UInt64
FileFlushAvgLatencyNs UInt64
DirectoryFlushCount UInt64
DirectoryFlushAvgLatencyNs UInt64
VolumeFlushCount UInt64
VolumeFlushAvgLatencyNs UInt64
FileLevelTrimCount UInt64
FileLevelTrimTotalBytes UInt64
FileLevelTrimExtentsCount UInt64
FileLevelTrimAvgLatencyNs UInt64
VolumeTrimCount UInt64
VolumeTrimTotalBytes UInt64
VolumeTrimExtentsCount UInt64
VolumeTrimAvgLatencyNs UInt64
IoBucketsCount UInt8
TotalBytesBucketsCount UInt8
ExtentsBucketsCount UInt8
IoCount UInt64
TotalLatencyUs UInt64
TotalBytes UInt64
TrimExtentsCount UInt64
IoTypeIndex UInt16
VcbExAcquireCount UInt32
VcbExMaxWaitDurationMs UInt64
VcbExAvgWaitDurationMs UInt64
VcbExMaxHoldDurationMs UInt64
VcbExAvgHoldDurationMs UInt64
VcbExMaxCombinedDurationMs UInt64
VcbExAvgCombinedDurationMs UInt64

Event ID 147: An IO took more than MaxLatencyMs ms to complete.

#
Provider
Microsoft-Windows-Ntfs
Channel
Operational
Level
Warning
Opcode
Info

Description

An IO took more than MaxLatencyMs ms to complete.

Message #

An IO took more than %5 ms to complete:

           Process Id: %6
           Process name: %7
           File name: %9
           File offset: %12
           IO Type: %10
           IO Size: %11 bytes
           %15 cluster(s) starting at cluster %14
           Latency: %13 ms

           Volume Id: %1
           Volume name: %3
           Is boot volume: %4

           Device GUID: %16
           Device manufacturer: %18
           Device model: %20
           Device revision: %22
           Device serial number: %24
           Bus type: %25

           Adapter serial number: %27

Fields #

NameDescription
VolumeCorrelationId GUIDVolume Id.
VolumeNameLength UInt32
VolumeName UnicodeString
IsBootVolume Boolean
MaxLatencyMs UInt64
ProcessId UInt32
ProcessName AnsiString
FileNameLength UInt32
FileName UnicodeString
FileIdHigh HexInt64
FileIdLow HexInt64
IoType UInt16
IoTypeStr UnicodeStringIO Type.
LatencyMs UInt64
DeviceGuid GUIDDevice model.
VendorIdLength UInt32
VendorId UnicodeStringDevice revision.
ProductIdLength UInt32
ProductId UnicodeStringDevice serial number.
ProductRevisionLength UInt32Bus type.
ProductRevision UnicodeString
DeviceSerialNumberLength UInt32Adapter serial number.
DeviceSerialNumber UnicodeString
BusType UInt32
AdapterSerialNumberLength UInt32
AdapterSerialNumber UnicodeString
NativeNVMe

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Ntfs",
    "guid": "{3FF37A1C-A68D-4D6E-8C9B-F79E8B16C482}",
    "event_source_name": "",
    "event_id": 147,
    "version": 5,
    "level": 3,
    "task": 0,
    "opcode": 0,
    "keywords": 4611967493406195712,
    "time_created": "2026-06-13T04:35:04.3813224+00:00",
    "event_record_id": 287,
    "correlation": {},
    "execution": {
      "process_id": 4,
      "thread_id": 5044
    },
    "channel": "Microsoft-Windows-Ntfs/Operational",
    "computer": "telemetry-DC-d.cell-d.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "VolumeCorrelationId": "{77ac4d73-0000-0000-0000-100000000000}",
    "VolumeNameLength": "2",
    "VolumeName": "C:",
    "IsBootVolume": "true",
    "MaxLatencyMs": "30000",
    "ProcessId": "1544",
    "ProcessName": "svchost.exe",
    "FileNameLength": "50",
    "FileName": "\\Windows\\ServiceState\\EventLog\\Data\\lastalive0.dat",
    "FileIdHigh": "0x0",
    "FileIdLow": "0xa000000010f88",
    "IoType": "25",
    "IoTypeStr": "Open file",
    "LatencyMs": "30047",
    "DeviceGuid": "{5a7d9ced-a852-a1ac-e3da-7b3e59928b2a}",
    "VendorIdLength": "8",
    "VendorId": "Red Hat ",
    "ProductIdLength": "6",
    "ProductId": "VirtIO",
    "ProductRevisionLength": "4",
    "ProductRevision": "0001",
    "DeviceSerialNumberLength": "0",
    "DeviceSerialNumber": "",
    "BusType": "1",
    "AdapterSerialNumberLength": "0",
    "AdapterSerialNumber": ""
  },
  "message": "An IO took more than 30000 ms to complete:\r\n\r\n           Process Id: 1544\r\n           Process name: svchost.exe\r\n           File name: \\Windows\\ServiceState\\EventLog\\Data\\lastalive0.dat\r\n           IO Type: Open file\r\n           Latency: 30047 ms\r\n\r\n           Volume Id: {77ac4d73-0000-0000-0000-100000000000}\r\n           Volume name: C:\r\n           Is boot volume: true\r\n\r\n           Device GUID: {5a7d9ced-a852-a1ac-e3da-7b3e59928b2a}\r\n           Device manufacturer: Red Hat \r\n           Device model: VirtIO\r\n           Device revision: 0001\r\n           Device serial number: \r\n           Bus type: SCSI\r\n\r\n           Adapter serial number: \r\n"
}

Event ID 148: A FileIdHigh failed with StartingLcn.

#
Provider
Microsoft-Windows-Ntfs
Channel
Operational
Opcode
Info

Description

A FileIdHigh failed with StartingLcn.

Message #

A %9 failed with %14.
This may indicate a failing disk.

           Process Id: %5
           Process name: %6
           File name: %8
           IO Size: %10 bytes
           File offset: %11
           %13 cluster(s) starting at cluster %12
           Latency: %15 ms

           Volume Id: %1
           Volume name: %3
           Is boot volume: %4

           Device GUID: %16
           Device manufacturer: %18
           Device model: %20
           Device revision: %22
           Device serial number: %24
           Bus type: %25

           Adapter serial number: %27

Fields #

NameDescription
VolumeCorrelationId GUID
VolumeNameLength UInt32
VolumeName UnicodeString
IsBootVolume Boolean
ProcessId UInt32
ProcessName AnsiString
FileNameLength UInt32
FileName UnicodeString
FileIdHigh HexInt64
FileIdLow HexInt64
IoType UInt32
IoSize UInt32
FileOffset UInt64
StartingLcn UInt64
ClustersCount UInt32
FailureStatus HexInt32
DeviceGuid GUID
VendorIdLength UInt32
VendorId UnicodeString
ProductIdLength UInt32
ProductId UnicodeString
ProductRevisionLength UInt32
ProductRevision UnicodeString
DeviceSerialNumberLength UInt32
DeviceSerialNumber UnicodeString
BusType UInt32
NativeNVMe Boolean
AdapterSerialNumberLength UInt32
AdapterSerialNumber UnicodeString

Event ID 149: In the past SecondsElapsed seconds we had high latency IOs and/or IO failures.

#
Provider
Microsoft-Windows-Ntfs
Channel
Operational
Level
Warning
Opcode
Info

Description

In the past SecondsElapsed seconds we had high latency IOs and/or IO failures.

Message #

In the past %17 seconds we had high latency IOs and/or IO failures.

           High latency IO count: %18
           Failed writes: %19
           Failed reads: %20
           Bad clusters relocated: %21

           Volume Id: %1
           Volume name: %3
           Is boot volume: %4

           Device GUID: %5
           Device manufacturer: %7
           Device model: %9
           Device revision: %11
           Device serial number: %13
           Bus type: %14

           Adapter serial number: %16

Fields #

NameDescription
VolumeCorrelationId GUIDVolume Id.
VolumeNameLength UInt32
VolumeName UnicodeString
IsBootVolume Boolean
DeviceGuid GUID
VendorIdLength UInt32
VendorId UnicodeStringDevice manufacturer.
ProductIdLength UInt32
ProductId UnicodeStringDevice model.
ProductRevisionLength UInt32
ProductRevision UnicodeStringDevice revision.
DeviceSerialNumberLength UInt32
DeviceSerialNumber UnicodeString
BusType UInt32
NativeNVMe
AdapterSerialNumberLength UInt32
AdapterSerialNumber UnicodeString
SecondsElapsed UInt32
HighLatencyCount UInt32High latency IO count.
FailedWriteCount UInt32Failed writes.
FailedReadCount UInt32Failed reads.
BadClusterHotfixCount UInt32Bad clusters relocated.
ValuesCount UInt32
HighLatencyArray UInt32
FailedWriteArray UInt32
FailedReadArray UInt32
BadClusterHotfixArray UInt32
StatusArray HexInt32
TableIndexArray UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Ntfs",
    "guid": "3FF37A1C-A68D-4D6E-8C9B-F79E8B16C482",
    "event_source_name": "",
    "event_id": 149,
    "version": 2,
    "level": 3,
    "task": 0,
    "opcode": 0,
    "keywords": 4611967493406195712,
    "time_created": "2023-11-06T01:32:12.814212+00:00",
    "event_record_id": 249,
    "correlation": {},
    "execution": {
      "process_id": 4,
      "thread_id": 18088
    },
    "channel": "Microsoft-Windows-Ntfs/Operational",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "VolumeCorrelationId": "7597D2A3-4404-4F99-B979-6233378A81BF",
    "VolumeNameLength": 2,
    "VolumeName": "C:",
    "IsBootVolume": true,
    "DeviceGuid": "22A04354-7C2B-11EE-936C-806E6F6E6963",
    "VendorIdLength": 8,
    "VendorId": "VMware, ",
    "ProductIdLength": 16,
    "ProductId": "VMware Virtual S",
    "ProductRevisionLength": 4,
    "ProductRevision": "1.0 ",
    "DeviceSerialNumberLength": 0,
    "DeviceSerialNumber": "",
    "BusType": 10,
    "AdapterSerialNumberLength": 0,
    "AdapterSerialNumber": "",
    "SecondsElapsed": 3602,
    "HighLatencyCount": 4,
    "FailedWriteCount": 0,
    "FailedReadCount": 0,
    "BadClusterHotfixCount": 0,
    "ValuesCount": 3,
    "HighLatencyArray": 1,
    "FailedWriteArray": 0,
    "FailedReadArray": 0,
    "BadClusterHotfixArray": 0,
    "StatusArray": "0x0",
    "TableIndexArray": 3
  },
  "message": ""
}

References #

Event ID 150: An IO failed with FailureStatus and NTFS has relocated the clusters.

#
Provider
Microsoft-Windows-Ntfs
Channel
System
Opcode
Info

Description

An IO failed with FailureStatus and NTFS has relocated the clusters. The original clusters are now marked as bad and they will not be reused.

Message #

An IO failed with %12 and NTFS has relocated the clusters. The original clusters are now marked as bad and they will not be reused.
This may indicate a failing disk.

           Process Id: %5
           Process name: %6
           File name: %8
           File offset: %9
           %11 cluster(s) were marked as bad starting at cluster %10

           Volume guid: %1
           Volume name: %3
           Is boot volume: %4

Fields #

NameDescription
VolumeGuid GUID
VolumeNameLength UInt32
VolumeName UnicodeString
IsBootVolume Boolean
ProcessId UInt32
ProcessName AnsiString
FileNameLength UInt32
FileName UnicodeString
BadFileOffset UInt64
BadLcn UInt64
ClustersCount UInt32
FailureStatus HexInt32

Event ID 151: In the past SecondsElapsed seconds TotalCountDeleteFile files were deleted from the user's popular known folders.

#
Provider
Microsoft-Windows-Ntfs
Channel
Operational
Level
Informational
Opcode
Info

Description

In the past SecondsElapsed seconds TotalCountDeleteFile files were deleted from the user's popular known folders (i.e. Desktop, Documents, Downloads, Music, Pictures, Videos, etc.).

Message #

In the past %5 seconds %6 files were deleted from the user's popular known folders (i.e. Desktop, Documents, Downloads, Music, Pictures, Videos, etc.).
%7 of the deletions recorded their process names.

           Volume Id: %1
           Volume name: %3
           Is boot volume: %4

           Process names: [%8]
           Delete counts: 
             Desktop: [%9]
             Documents: [%10]
             Downloads: [%11]
             Music: [%12]
             Pictures: [%13]
             Videos: [%14]
             Other: [%15]

Fields #

NameDescription
VolumeCorrelationId GUID
VolumeNameLength UInt32
VolumeName UnicodeString
IsBootVolume Boolean
SecondsElapsed UInt32
TotalCountDeleteFile UInt32
TotalCountDeleteFileLogged UInt32
ProcessNamesArray AnsiString
CountDeletesInDesktopArray AnsiString
CountDeletesInDocumentsArray AnsiString
CountDeletesInDownloadsArray AnsiString
CountDeletesInMusicArray AnsiString
CountDeletesInPicturesArray AnsiString
CountDeletesInVideosArray AnsiString
CountDeletesInOtherArray AnsiString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Ntfs",
    "guid": "3FF37A1C-A68D-4D6E-8C9B-F79E8B16C482",
    "event_source_name": "",
    "event_id": 151,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 4611686018429485056,
    "time_created": "2026-03-13T17:16:12.046261+00:00",
    "event_record_id": 5903,
    "correlation": {},
    "execution": {
      "process_id": 4,
      "thread_id": 8128
    },
    "channel": "Microsoft-Windows-Ntfs/Operational",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "VolumeCorrelationId": "77AC4D73-0000-0000-0000-100000000000",
    "VolumeNameLength": 2,
    "VolumeName": "C:",
    "IsBootVolume": true,
    "SecondsElapsed": 3601,
    "TotalCountDeleteFile": 2,
    "TotalCountDeleteFileLogged": 2,
    "ProcessNamesArray": "powershell_ise",
    "CountDeletesInDesktopArray": "0",
    "CountDeletesInDocumentsArray": "2",
    "CountDeletesInDownloadsArray": "0",
    "CountDeletesInMusicArray": "0",
    "CountDeletesInPicturesArray": "0",
    "CountDeletesInVideosArray": "0",
    "CountDeletesInOtherArray": "0"
  },
  "message": ""
}

Event ID 152: A process has not acknowledged an NTFS oplock break in a long time.

#
Provider
Microsoft-Windows-Ntfs
Channel
Operational
Opcode
Info

Description

A process has not acknowledged an NTFS oplock break in a long time.

Message #

A process has not acknowledged an NTFS oplock break in a long time.

           Time (seconds): %1
           Owner Process: %2
           Breaking Process: %3

Fields #

NameDescription
TimeoutSeconds UInt32
OwnerProcessNameLength UInt32
OwnerProcessName UnicodeString
BreakingProcessNameLength UInt32
BreakingProcessName UnicodeString

Event ID 154: System file pages are now locked into memory.

#
Provider
Microsoft-Windows-Ntfs
Channel
Operational
Opcode
Info

Description

System file pages are now locked into memory.

Message #

System file pages are now locked into memory.

                    Volume Id: %1
                    Volume name: %3

                    File reference: %4
                    File name: %6

Fields #

NameDescription
VolumeCorrelationId GUID
VolumeNameLength UInt32
VolumeName UnicodeString
FileReference UInt64
FileNameLength UInt32
FileName UnicodeString

Event ID 155: System file pages are no longer locked into memory.

#
Provider
Microsoft-Windows-Ntfs
Channel
Operational
Opcode
Info

Description

System file pages are no longer locked into memory.

Message #

System file pages are no longer locked into memory.

                    Volume Id: %1
                    Volume name: %3

                    File reference: %4
                    File name: %6

                    Reason: %7

Fields #

NameDescription
VolumeCorrelationId GUID
VolumeNameLength UInt32
VolumeName UnicodeString
FileReference UInt64
FileNameLength UInt32
FileName UnicodeString
UnlockReason UInt32

Event ID 156: VCB exclusive resource acquires.

#
Provider
Microsoft-Windows-Ntfs
Channel
Operational
Level
Informational
Opcode
Info

Description

VCB exclusive resource acquires.

Message #

VCB exclusive resource acquires:

           Volume Id: %1
           Volume name: %3
           Is boot volume: %4

           Interval duration: %18

           Acquire count: %19
           Max wait duration: %20 ms
           Avg wait duration: %21 ms
           Max hold duration: %22 ms
           Avg hold duration: %23 ms
           Max combined duration: %24 ms
           Avg combined duration: %25 ms

           Device GUID: %5
           Device manufacturer: %7
           Device model: %9
           Device revision: %11
           Device serial number: %13
           Bus type: %14
           
           Adapter serial number: %16
           
           For more details see the details tab.

Fields #

NameDescription
VolumeCorrelationId GUID[VCB exclusive resource acquires] Volume Id.
VolumeNameLength UInt16
VolumeName UnicodeString[VCB exclusive resource acquires] Volume name.
IsBootVolume Boolean[VCB exclusive resource acquires] Is boot volume.
DeviceGuid GUID[VCB exclusive resource acquires] Device GUID.
VendorIdLength UInt16
VendorId UnicodeString[VCB exclusive resource acquires] Device manufacturer.
ProductIdLength UInt16
ProductId UnicodeString[VCB exclusive resource acquires] Device model.
ProductRevisionLength UInt16
ProductRevision UnicodeString[VCB exclusive resource acquires] Device revision.
DeviceSerialNumberLength UInt16
DeviceSerialNumber UnicodeString[VCB exclusive resource acquires] Device serial number.
BusType UInt32[VCB exclusive resource acquires] Bus type.
NativeNVMe
AdapterSerialNumberLength UInt16
AdapterSerialNumber UnicodeString[VCB exclusive resource acquires] Adapter serial number.
IntervalDurationMs UInt64
IntervalDurationStr UnicodeString[VCB exclusive resource acquires] Interval duration.
VcbExAcquireCount UInt32[VCB exclusive resource acquires] Acquire count.
VcbExMaxWaitDurationMs UInt64[VCB exclusive resource acquires] Max wait duration.
VcbExAvgWaitDurationMs UInt64[VCB exclusive resource acquires] Avg wait duration.
VcbExMaxHoldDurationMs UInt64[VCB exclusive resource acquires] Max hold duration.
VcbExAvgHoldDurationMs UInt64[VCB exclusive resource acquires] Avg hold duration.
VcbExMaxCombinedDurationMs UInt64[VCB exclusive resource acquires] Max combined duration.
VcbExAvgCombinedDurationMs UInt64[VCB exclusive resource acquires] Avg combined duration.

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Ntfs",
    "guid": "3FF37A1C-A68D-4D6E-8C9B-F79E8B16C482",
    "event_source_name": "",
    "event_id": 156,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 4611686018429485056,
    "time_created": "2023-11-06T01:32:12.811781+00:00",
    "event_record_id": 230,
    "correlation": {},
    "execution": {
      "process_id": 4,
      "thread_id": 18088
    },
    "channel": "Microsoft-Windows-Ntfs/Operational",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "VolumeCorrelationId": "7597D2A3-4404-4F99-B979-6233378A81BF",
    "VolumeNameLength": 2,
    "VolumeName": "C:",
    "IsBootVolume": true,
    "DeviceGuid": "22A04354-7C2B-11EE-936C-806E6F6E6963",
    "VendorIdLength": 8,
    "VendorId": "VMware, ",
    "ProductIdLength": 16,
    "ProductId": "VMware Virtual S",
    "ProductRevisionLength": 4,
    "ProductRevision": "1.0 ",
    "DeviceSerialNumberLength": 0,
    "DeviceSerialNumber": "",
    "BusType": 10,
    "AdapterSerialNumberLength": 0,
    "AdapterSerialNumber": "",
    "IntervalDurationMs": 3602451,
    "IntervalDurationStr": "3602 s",
    "VcbExAcquireCount": 171,
    "VcbExMaxWaitDurationMs": 15210,
    "VcbExAvgWaitDurationMs": 90,
    "VcbExMaxHoldDurationMs": 18627,
    "VcbExAvgHoldDurationMs": 237,
    "VcbExMaxCombinedDurationMs": 18627,
    "VcbExAvgCombinedDurationMs": 327
  },
  "message": ""
}

References #

Event ID 157: An exclusive resource duration exceeded MaxDurationMs ms.

#
Provider
Microsoft-Windows-Ntfs
Channel
Operational
Level
Warning
Opcode
Info

Description

An exclusive resource duration exceeded MaxDurationMs ms.

Message #

An exclusive resource duration exceeded %5 ms:

           Process Id: %6
           Process name: %7
           Major function: %8
           Minor function: %9
           Control code: %10
           Resource name: %11
           Wait duration: %12 ms
           Hold duration: %13 ms
           Combined duration: %14 ms

           Volume Id: %1
           Volume name: %3
           Is boot volume: %4

           Device GUID: %15
           Device manufacturer: %17
           Device model: %19
           Device revision: %21
           Device serial number: %23
           Bus type: %24

           Adapter serial number: %26

Fields #

NameDescription
VolumeCorrelationId GUID
VolumeNameLength UInt32
VolumeName UnicodeString
IsBootVolume Boolean
MaxDurationMs UInt64
ProcessId UInt32
ProcessName AnsiString
MajorFunction UInt8
MinorFunction UInt8
ControlCode UInt32
ResourceName UInt32
WaitDurationMs UInt64
HoldDurationMs UInt64
CombinedDurationMs UInt64
DeviceGuid GUID
VendorIdLength UInt32
VendorId UnicodeString
ProductIdLength UInt32
ProductId UnicodeString
ProductRevisionLength UInt32
ProductRevision UnicodeString
DeviceSerialNumberLength UInt32
DeviceSerialNumber UnicodeString
BusType UInt32
AdapterSerialNumberLength UInt32
AdapterSerialNumber UnicodeString
NativeNVMe Boolean

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Ntfs",
    "guid": "{3FF37A1C-A68D-4D6E-8C9B-F79E8B16C482}",
    "event_source_name": "",
    "event_id": 157,
    "version": 0,
    "level": 3,
    "task": 0,
    "opcode": 0,
    "keywords": 4611686018429485056,
    "time_created": "2026-04-17T04:05:09.8163657+00:00",
    "event_record_id": 1110,
    "correlation": {},
    "execution": {
      "process_id": 4468,
      "thread_id": 15840
    },
    "channel": "Microsoft-Windows-Ntfs/Operational",
    "computer": "JD-WIN11-22H2-1.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "VolumeCorrelationId": "{ce657ebb-70c7-4b8b-a13f-ff11b9725249}",
    "VolumeNameLength": "2",
    "VolumeName": "C:",
    "IsBootVolume": "true",
    "MaxDurationMs": "30000",
    "ProcessId": "4468",
    "ProcessName": "SenseIR.exe",
    "MajorFunction": "3",
    "MinorFunction": "0",
    "ControlCode": "0",
    "ResourceName": "32",
    "WaitDurationMs": "0",
    "HoldDurationMs": "88671",
    "CombinedDurationMs": "88671",
    "DeviceGuid": "{5a7d9ced-a852-a1ac-e3da-7b3e59928b2a}",
    "VendorIdLength": "8",
    "VendorId": "Red Hat ",
    "ProductIdLength": "6",
    "ProductId": "VirtIO",
    "ProductRevisionLength": "4",
    "ProductRevision": "0001",
    "DeviceSerialNumberLength": "0",
    "DeviceSerialNumber": "",
    "BusType": "1",
    "AdapterSerialNumberLength": "0",
    "AdapterSerialNumber": ""
  },
  "message": "An exclusive resource duration exceeded 30000 ms:\r\n\r\n           Process Id: 4468\r\n           Process name: SenseIR.exe\r\n           Major function: 0x3\r\n           Minor function: 0x0\r\n           Control code: 0\r\n           Resource name: VCB\r\n           Wait duration: 0 ms\r\n           Hold duration: 88671 ms\r\n           Combined duration: 88671 ms\r\n\r\n           Volume Id: {ce657ebb-70c7-4b8b-a13f-ff11b9725249}\r\n           Volume name: C:\r\n           Is boot volume: true\r\n\r\n           Device GUID: {5a7d9ced-a852-a1ac-e3da-7b3e59928b2a}\r\n           Device manufacturer: Red Hat \r\n           Device model: VirtIO\r\n           Device revision: 0001\r\n           Device serial number: \r\n           Bus type: SCSI\r\n\r\n           Adapter serial number: \r\n"
}

Event ID 158: NTFS metadata statistics for volume.

#
Provider
Microsoft-Windows-Ntfs
Channel
Operational
Level
Informational
Opcode
Info

Description

NTFS metadata statistics for volume.

Message #

NTFS metadata statistics for volume:

           Volume Id: %1
           Volume name: %3

           UserFileReads: %4
           UserFileReadBytes: %5
           UserDiskReads: %6
           UserFileWrites: %7
           UserFileWriteBytes: %8
           UserDiskWrites: %9

           MetaDataReads: %10
           MetaDataReadBytes: %11
           MetaDataDiskReads: %12
           MetaDataWrites: %13
           MetaDataWriteBytes: %14
           MetaDataDiskWrites: %15

           MftReads: %16
           MftReadBytes: %17
           MftWrites: %18
           MftWriteBytes: %19
           Mft2Writes: %20
           Mft2WriteBytes: %21
           RootIndexReads: %22
           RootIndexReadBytes: %23
           RootIndexWrites: %24
           RootIndexWriteBytes: %25
           BitmapReads: %26
           BitmapReadBytes: %27
           BitmapWrites: %28
           BitmapWriteBytes: %29
           MftBitmapReads: %30
           MftBitmapReadBytes: %31
           MftBitmapWrites: %32
           MftBitmapWriteBytes: %33
           UserIndexReads: %34
           UserIndexReadBytes: %35
           UserIndexWrites: %36
           UserIndexWriteBytes: %37
           LogFileReads: %38
           LogFileReadBytes: %39
           LogFileWrites: %40
           LogFileWriteBytes: %41
           LogFileFull: %42
           LogFileFullReasons:
                     LF_LOG_SPACE: %43
                     LF_DIRTY_PAGES: %44
                     LF_OPEN_ATTRIBUTES: %45
                     LF_TRANSACTION_DRAIN: %46
                     LF_FASTIO_CALLBACK: %47
                     LF_DEALLOCATED_CLUSTERS: %48
                     LF_DEALLOCATED_CLUSTERS_MEM: %49
                     LF_RECORD_STACK_CHECK: %50
                     LF_DISMOUNT: %51
                     LF_COMPRESSION: %52
                     LF_SNAPSHOT: %53
                     LF_MOUNT: %54
                     LF_SHUTDOWN: %55
                     LF_RECURSIVE_COMPRESSION: %56
                     LF_TESTING: %57

           DiskResourceFailure: %58
           VolumeTrimCount: %59
                     VolumeTrimTime (ms): %60
                     VolumeTrimSize (KB): %61
                     AvgVolumeTrimTime (ms): %62
                     AvgVolumeTrimSize (KB): %63
           VolumeTrimSkippedCount: %64
                     VolumeTrimSkippedSize (KB): %65
           FileLevelTrimCount: %66
                     FileLevelTrimTime (ms): %67
                     FileLevelTrimSize (KB): %68
                     AvgFileLevelTrimTime (ms): %69
                     AvgFileLevelTrimSize (KB): %70
           NtfsFillStatInfoFromMftRecordCalledCount: %71
           NtfsFillStatInfoFromMftRecordBailedBecauseOfAttributeListCount: %72
           NtfsFillStatInfoFromMftRecordBailedBecauseOfNonResReparsePointCount: %73

Fields #

NameDescription
VolumeCorrelationId GUID[NTFS metadata statistics for volume] Volume Id.
VolumeNameLength UInt32
VolumeName UnicodeString[NTFS metadata statistics for volume] Volume name.
UserFileReads UInt64[NTFS metadata statistics for volume] UserFileReads.
UserFileReadBytes UInt64[NTFS metadata statistics for volume] UserFileReadBytes.
UserDiskReads UInt64[NTFS metadata statistics for volume] UserDiskReads.
UserFileWrites UInt64[NTFS metadata statistics for volume] UserFileWrites.
UserFileWriteBytes UInt64[NTFS metadata statistics for volume] UserFileWriteBytes.
UserDiskWrites UInt64[NTFS metadata statistics for volume] UserDiskWrites.
MetaDataReads UInt64[NTFS metadata statistics for volume] MetaDataReads.
MetaDataReadBytes UInt64[NTFS metadata statistics for volume] MetaDataReadBytes.
MetaDataDiskReads UInt64[NTFS metadata statistics for volume] MetaDataDiskReads.
MetaDataWrites UInt64[NTFS metadata statistics for volume] MetaDataWrites.
MetaDataWriteBytes UInt64[NTFS metadata statistics for volume] MetaDataWriteBytes.
MetaDataDiskWrites UInt64[NTFS metadata statistics for volume] MetaDataDiskWrites.
MftReads UInt64[NTFS metadata statistics for volume] MftReads.
MftReadBytes UInt64[NTFS metadata statistics for volume] MftReadBytes.
MftWrites UInt64[NTFS metadata statistics for volume] MftWrites.
MftWriteBytes UInt64[NTFS metadata statistics for volume] MftWriteBytes.
Mft2Writes UInt64[NTFS metadata statistics for volume] Mft2Writes.
Mft2WriteBytes UInt64[NTFS metadata statistics for volume] Mft2WriteBytes.
RootIndexReads UInt64[NTFS metadata statistics for volume] RootIndexReads.
RootIndexReadBytes UInt64[NTFS metadata statistics for volume] RootIndexReadBytes.
RootIndexWrites UInt64[NTFS metadata statistics for volume] RootIndexWrites.
RootIndexWriteBytes UInt64[NTFS metadata statistics for volume] RootIndexWriteBytes.
BitmapReads UInt64[NTFS metadata statistics for volume] BitmapReads.
BitmapReadBytes UInt64[NTFS metadata statistics for volume] BitmapReadBytes.
BitmapWrites UInt64[NTFS metadata statistics for volume] BitmapWrites.
BitmapWriteBytes UInt64[NTFS metadata statistics for volume] BitmapWriteBytes.
MftBitmapReads UInt64[NTFS metadata statistics for volume] MftBitmapReads.
MftBitmapReadBytes UInt64[NTFS metadata statistics for volume] MftBitmapReadBytes.
MftBitmapWrites UInt64[NTFS metadata statistics for volume] MftBitmapWrites.
MftBitmapWriteBytes UInt64[NTFS metadata statistics for volume] MftBitmapWriteBytes.
UserIndexReads UInt64[NTFS metadata statistics for volume] UserIndexReads.
UserIndexReadBytes UInt64[NTFS metadata statistics for volume] UserIndexReadBytes.
UserIndexWrites UInt64[NTFS metadata statistics for volume] UserIndexWrites.
UserIndexWriteBytes UInt64[NTFS metadata statistics for volume] UserIndexWriteBytes.
LogFileReads UInt64[NTFS metadata statistics for volume] LogFileReads.
LogFileReadBytes UInt64[NTFS metadata statistics for volume] LogFileReadBytes.
LogFileWrites UInt64[NTFS metadata statistics for volume] LogFileWrites.
LogFileWriteBytes UInt64[NTFS metadata statistics for volume] LogFileWriteBytes.
LogFileFull UInt64[NTFS metadata statistics for volume] LogFileFull.
LogFileFullReasonBucket1 UInt64[LogFileFullReasons] LF_LOG_SPACE.
LogFileFullReasonBucket2 UInt64[LogFileFullReasons] LF_DIRTY_PAGES.
LogFileFullReasonBucket3 UInt64[LogFileFullReasons] LF_OPEN_ATTRIBUTES.
LogFileFullReasonBucket4 UInt64[LogFileFullReasons] LF_TRANSACTION_DRAIN.
LogFileFullReasonBucket5 UInt64[LogFileFullReasons] LF_FASTIO_CALLBACK.
LogFileFullReasonBucket6 UInt64[LogFileFullReasons] LF_DEALLOCATED_CLUSTERS.
LogFileFullReasonBucket7 UInt64[LogFileFullReasons] LF_DEALLOCATED_CLUSTERS_MEM.
LogFileFullReasonBucket8 UInt64[LogFileFullReasons] LF_RECORD_STACK_CHECK.
LogFileFullReasonBucket9 UInt64[LogFileFullReasons] LF_DISMOUNT.
LogFileFullReasonBucket10 UInt64[LogFileFullReasons] LF_COMPRESSION.
LogFileFullReasonBucket11 UInt64[LogFileFullReasons] LF_SNAPSHOT.
LogFileFullReasonBucket12 UInt64[LogFileFullReasons] LF_MOUNT.
LogFileFullReasonBucket13 UInt64[LogFileFullReasons] LF_SHUTDOWN.
LogFileFullReasonBucket14 UInt64[LogFileFullReasons] LF_RECURSIVE_COMPRESSION.
LogFileFullReasonBucket15 UInt64[LogFileFullReasons] LF_TESTING.
DiskResourceFailure UInt64[LogFileFullReasons] DiskResourceFailure.
VolumeTrimCount UInt64
VolumeTrimTime UInt64[LogFileFullReasons] VolumeTrimTime (ms).
VolumeTrimSize UInt64[LogFileFullReasons] VolumeTrimSize (KB).
AvgVolumeTrimTime UInt64[LogFileFullReasons] AvgVolumeTrimTime (ms).
AvgVolumeTrimSize UInt64[LogFileFullReasons] AvgVolumeTrimSize (KB).
VolumeTrimSkippedCount UInt64[LogFileFullReasons] VolumeTrimSkippedCount.
VolumeTrimSkippedSize UInt64[LogFileFullReasons] VolumeTrimSkippedSize (KB).
FileLevelTrimCount UInt64[LogFileFullReasons] FileLevelTrimCount.
FileLevelTrimTime UInt64[LogFileFullReasons] FileLevelTrimTime (ms).
FileLevelTrimSize UInt64[LogFileFullReasons] FileLevelTrimSize (KB).
AvgFileLevelTrimTime UInt64[LogFileFullReasons] AvgFileLevelTrimTime (ms).
AvgFileLevelTrimSize UInt64[LogFileFullReasons] AvgFileLevelTrimSize (KB).
NtfsFillStatInfoFromMftRecordCalledCount UInt64[LogFileFullReasons] NtfsFillStatInfoFromMftRecordCalledCount.
NtfsFillStatInfoFromMftRecordBailedBecauseOfAttributeListCount UInt64[LogFileFullReasons] NtfsFillStatInfoFromMftRecordBailedBecauseOfAttributeListCount.
NtfsFillStatInfoFromMftRecordBailedBecauseOfNonResReparsePointCount UInt64[LogFileFullReasons] NtfsFillStatInfoFromMftRecordBailedBecauseOfNonResReparsePointCount.

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Ntfs",
    "guid": "{3FF37A1C-A68D-4D6E-8C9B-F79E8B16C482}",
    "event_source_name": "",
    "event_id": 158,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 4611686018429485056,
    "time_created": "2026-06-13T05:39:34.3289115+00:00",
    "event_record_id": 491,
    "correlation": {},
    "execution": {
      "process_id": 4,
      "thread_id": 4312
    },
    "channel": "Microsoft-Windows-Ntfs/Operational",
    "computer": "telemetry-DC-a.cell-a.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "VolumeCorrelationId": "{77ac4d73-0000-0000-0000-100000000000}",
    "VolumeNameLength": "2",
    "VolumeName": "C:",
    "UserFileReads": "62240",
    "UserFileReadBytes": "1887262720",
    "UserDiskReads": "62333",
    "UserFileWrites": "14033",
    "UserFileWriteBytes": "2973306880",
    "UserDiskWrites": "15109",
    "MetaDataReads": "1887",
    "MetaDataReadBytes": "7729152",
    "MetaDataDiskReads": "2728",
    "MetaDataWrites": "8027",
    "MetaDataWriteBytes": "38236160",
    "MetaDataDiskWrites": "9384",
    "MftReads": "1587",
    "MftReadBytes": "6500352",
    "MftWrites": "5609",
    "MftWriteBytes": "26447872",
    "Mft2Writes": "1",
    "Mft2WriteBytes": "4096",
    "RootIndexReads": "0",
    "RootIndexReadBytes": "0",
    "RootIndexWrites": "0",
    "RootIndexWriteBytes": "0",
    "BitmapReads": "0",
    "BitmapReadBytes": "0",
    "BitmapWrites": "1696",
    "BitmapWriteBytes": "8228864",
    "MftBitmapReads": "0",
    "MftBitmapReadBytes": "0",
    "MftBitmapWrites": "273",
    "MftBitmapWriteBytes": "1183744",
    "UserIndexReads": "1130",
    "UserIndexReadBytes": "4628480",
    "UserIndexWrites": "1263",
    "UserIndexWriteBytes": "5763072",
    "LogFileReads": "0",
    "LogFileReadBytes": "0",
    "LogFileWrites": "5918",
    "LogFileWriteBytes": "61857792",
    "LogFileFull": "0",
    "LogFileFullReasonBucket1": "0",
    "LogFileFullReasonBucket2": "0",
    "LogFileFullReasonBucket3": "0",
    "LogFileFullReasonBucket4": "0",
    "LogFileFullReasonBucket5": "0",
    "LogFileFullReasonBucket6": "0",
    "LogFileFullReasonBucket7": "0",
    "LogFileFullReasonBucket8": "0",
    "LogFileFullReasonBucket9": "0",
    "LogFileFullReasonBucket10": "0",
    "LogFileFullReasonBucket11": "0",
    "LogFileFullReasonBucket12": "0",
    "LogFileFullReasonBucket13": "0",
    "LogFileFullReasonBucket14": "0",
    "LogFileFullReasonBucket15": "0",
    "DiskResourceFailure": "0",
    "VolumeTrimCount": "1969",
    "VolumeTrimTime": "15764",
    "VolumeTrimSize": "3106796",
    "AvgVolumeTrimTime": "8",
    "AvgVolumeTrimSize": "1577",
    "VolumeTrimSkippedCount": "0",
    "VolumeTrimSkippedSize": "0",
    "FileLevelTrimCount": "0",
    "FileLevelTrimTime": "0",
    "FileLevelTrimSize": "0",
    "AvgFileLevelTrimTime": "0",
    "AvgFileLevelTrimSize": "0",
    "NtfsFillStatInfoFromMftRecordCalledCount": "0",
    "NtfsFillStatInfoFromMftRecordBailedBecauseOfAttributeListCount": "0",
    "NtfsFillStatInfoFromMftRecordBailedBecauseOfNonResReparsePointCount": "0"
  },
  "message": "NTFS metadata statistics for volume:\r\n\r\n           Volume Id: {77ac4d73-0000-0000-0000-100000000000}\r\n           Volume name: C:\r\n\r\n           UserFileReads: 62240\r\n           UserFileReadBytes: 1887262720\r\n           UserDiskReads: 62333\r\n           UserFileWrites: 14033\r\n           UserFileWriteBytes: 2973306880\r\n           UserDiskWrites: 15109\r\n\r\n           MetaDataReads: 1887\r\n           MetaDataReadBytes: 7729152\r\n           MetaDataDiskReads: 2728\r\n           MetaDataWrites: 8027\r\n           MetaDataWriteBytes: 38236160\r\n           MetaDataDiskWrites: 9384\r\n\r\n           MftReads: 1587\r\n           MftReadBytes: 6500352\r\n           MftWrites: 5609\r\n           MftWriteBytes: 26447872\r\n           Mft2Writes: 1\r\n           Mft2WriteBytes: 4096\r\n           RootIndexReads: 0\r\n           RootIndexReadBytes: 0\r\n           RootIndexWrites: 0\r\n           RootIndexWriteBytes: 0\r\n           BitmapReads: 0\r\n           BitmapReadBytes: 0\r\n           BitmapWrites: 1696\r\n           BitmapWriteBytes: 8228864\r\n           MftBitmapReads: 0\r\n           MftBitmapReadBytes: 0\r\n           MftBitmapWrites: 273\r\n           MftBitmapWriteBytes: 1183744\r\n           UserIndexReads: 1130\r\n           UserIndexReadBytes: 4628480\r\n           UserIndexWrites: 1263\r\n           UserIndexWriteBytes: 5763072\r\n           LogFileReads: 0\r\n           LogFileReadBytes: 0\r\n           LogFileWrites: 5918\r\n           LogFileWriteBytes: 61857792\r\n           LogFileFull: 0\r\n           LogFileFullReasons:\r\n                     LF_LOG_SPACE: 0\r\n                     LF_DIRTY_PAGES: 0\r\n                     LF_OPEN_ATTRIBUTES: 0\r\n                     LF_TRANSACTION_DRAIN: 0\r\n                     LF_FASTIO_CALLBACK: 0\r\n                     LF_DEALLOCATED_CLUSTERS: 0\r\n                     LF_DEALLOCATED_CLUSTERS_MEM: 0\r\n                     LF_RECORD_STACK_CHECK: 0\r\n                     LF_DISMOUNT: 0\r\n                     LF_COMPRESSION: 0\r\n                     LF_SNAPSHOT: 0\r\n                     LF_MOUNT: 0\r\n                     LF_SHUTDOWN: 0\r\n                     LF_RECURSIVE_COMPRESSION: 0\r\n                     LF_TESTING: 0\r\n\r\n           DiskResourceFailure: 0\r\n           VolumeTrimCount: 1969\r\n                     VolumeTrimTime (ms): 15764\r\n                     VolumeTrimSize (KB): 3106796\r\n                     AvgVolumeTrimTime (ms): 8\r\n                     AvgVolumeTrimSize (KB): 1577\r\n           VolumeTrimSkippedCount: 0\r\n                     VolumeTrimSkippedSize (KB): 0\r\n           FileLevelTrimCount: 0\r\n                     FileLevelTrimTime (ms): 0\r\n                     FileLevelTrimSize (KB): 0\r\n                     AvgFileLevelTrimTime (ms): 0\r\n                     AvgFileLevelTrimSize (KB): 0\r\n           NtfsFillStatInfoFromMftRecordCalledCount: 0\r\n           NtfsFillStatInfoFromMftRecordBailedBecauseOfAttributeListCount: 0\r\n           NtfsFillStatInfoFromMftRecordBailedBecauseOfNonResReparsePointCount: 0\r\n"
}

Event ID 159: NTFS has successfully completed the VolumeSizeChangeRequestType request in CombinedDurationMs ms when trying to VolumeSizeChangeOperation the volume size from FromSize (MB) to ToSize (MB).

#
Provider
Microsoft-Windows-Ntfs
Channel
Operational
Level
Informational
Task
VolumeSizeChange

Description

NTFS has successfully completed the VolumeSizeChangeRequestType request in CombinedDurationMs ms when trying to VolumeSizeChangeOperation the volume size from FromSize (MB) to ToSize (MB).

Message #

NTFS has successfully completed the %19 request in %20 ms when trying to %18 the volume size from %4 (MB) to %5 (MB).

           Volume Id: %1
           Volume name: %3

           Device GUID: %6
           Device manufacturer: %8
           Device model: %10
           Device revision: %12
           Device serial number: %14
           Bus type: %15

           Adapter serial number: %17

           Operation: %18
                     Request Type: %19

           Stage Durations:
                     Stage 1. Verify input and calculate new volume size (ms): %21
                     Stage 2. Set boundary and allocate/deallocate cluster (ms): %22
                     Stage 3. Update bitmap (ms): %23

Fields #

NameDescription
VolumeCorrelationId GUIDVolume Id.
VolumeNameLength UInt32
VolumeName UnicodeString
FromSize UInt64
ToSize UInt64
DeviceGuid GUID
VendorIdLength UInt32
VendorId UnicodeStringDevice manufacturer.
ProductIdLength UInt32
ProductId UnicodeStringDevice model.
ProductRevisionLength UInt32
ProductRevision UnicodeStringDevice revision.
DeviceSerialNumberLength UInt32
DeviceSerialNumber UnicodeString
BusType UInt32
NativeNVMe
AdapterSerialNumberLength UInt32
AdapterSerialNumber UnicodeString
VolumeSizeChangeOperation UInt16Operation.
VolumeSizeChangeRequestType UInt16Request Type.
CombinedDurationMs UInt64
Stage1DurationMs UInt64[Stage Durations] Stage 1. Verify input and calculate new volume size (ms).
Stage2DurationMs UInt64[Stage Durations] Stage 2. Set boundary and allocate/deallocate cluster (ms).
Stage3DurationMs UInt64[Stage Durations] Stage 3. Update bitmap (ms).

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Ntfs",
    "guid": "3FF37A1C-A68D-4D6E-8C9B-F79E8B16C482",
    "event_source_name": "",
    "event_id": 159,
    "version": 0,
    "level": 4,
    "task": 13,
    "opcode": 0,
    "keywords": 4611686018429485056,
    "time_created": "2022-04-07T16:45:03.658483+00:00",
    "event_record_id": 8,
    "correlation": {},
    "execution": {
      "process_id": 4476,
      "thread_id": 4512
    },
    "channel": "Microsoft-Windows-Ntfs/Operational",
    "computer": "WIN-FPV0DSIC9O6",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "VolumeCorrelationId": "ADDC92DC-EB36-4896-AAEB-9547FEEB7B8C",
    "VolumeNameLength": 2,
    "VolumeName": "C:",
    "FromSize": 102281,
    "ToSize": 101756,
    "DeviceGuid": "7B6F1752-BD95-6E22-E3A5-6EE8419ECAD7",
    "VendorIdLength": 0,
    "VendorId": "",
    "ProductIdLength": 24,
    "ProductId": "VMware Virtual NVMe Disk",
    "ProductRevisionLength": 3,
    "ProductRevision": "1.0",
    "DeviceSerialNumberLength": 16,
    "DeviceSerialNumber": "VMWare NVME_0000",
    "BusType": 17,
    "AdapterSerialNumberLength": 16,
    "AdapterSerialNumber": "VMWare NVME_0000",
    "VolumeSizeChangeOperation": 1,
    "VolumeSizeChangeRequestType": 2,
    "CombinedDurationMs": 62,
    "Stage1DurationMs": 0,
    "Stage2DurationMs": 0,
    "Stage3DurationMs": 62
  },
  "message": ""
}

References #

Event ID 160: NTFS has failed to complete the VolumeSizeChangeOperation request after VolumeSizeChangeRequestType ms when trying to AdapterSerialNumber the volume size from FromSize (MB) to ToSize (MB).

#
Provider
Microsoft-Windows-Ntfs
Channel
Operational
Task
VolumeSizeChange
Opcode
Stop

Description

NTFS has failed to complete the VolumeSizeChangeOperation request after VolumeSizeChangeRequestType ms when trying to AdapterSerialNumber the volume size from FromSize (MB) to ToSize (MB).

Message #

NTFS has failed to complete the %19 request after %20 ms when trying to %18 the volume size from %4 (MB) to %5 (MB).

           Volume Id: %1
           Volume name: %3

           Device GUID: %6
           Device manufacturer: %8
           Device model: %10
           Device revision: %12
           Device serial number: %14
           Bus type: %15

           Adapter serial number: %17

           Operation: %18
                     Request Type: %19

           Stage Durations:
                     Stage 1. Verify input and calculate new volume size (ms): %21
                     Stage 2. Set boundary and allocate/deallocate cluster (ms): %22
                     Stage 3. Update bitmap (ms): %23

           Failure Stage: %24
           Status Code: %25
           Failure Reason: %26

Fields #

NameDescription
VolumeCorrelationId GUID
VolumeNameLength UInt32
VolumeName UnicodeString
FromSize UInt64
ToSize UInt64
DeviceGuid GUID
VendorIdLength UInt32
VendorId UnicodeString
ProductIdLength UInt32
ProductId UnicodeString
ProductRevisionLength UInt32
ProductRevision UnicodeString
DeviceSerialNumberLength UInt32
DeviceSerialNumber UnicodeString
BusType UInt32
NativeNVMe Boolean
AdapterSerialNumberLength UInt32
AdapterSerialNumber UnicodeString
VolumeSizeChangeOperation UInt16
VolumeSizeChangeRequestType UInt16
CombinedDurationMs UInt64
Stage1DurationMs UInt64
Stage2DurationMs UInt64
Stage3DurationMs UInt64
FailureStage UInt16
FailureStatusCode UInt32
FailureReason HexInt32
Known values
%%2304
An Error occured during Logon.
%%2305
The specified user account has expired.
%%2306
The NetLogon component is not active.
%%2307
Account locked out.
%%2308
The user has not been granted the requested logon type at this machine.
%%2309
The specified account's password has expired.
%%2310
Account currently disabled.
%%2311
Account logon time restriction violation.
%%2312
User not allowed to logon at this computer.
%%2313
Unknown user name or bad password.
%%2314
Domain sid inconsistent.
%%2315
Smartcard logon is required and was not used.

Event ID 161: An operation has failed due to a file system limitation.

#
Provider
Microsoft-Windows-Ntfs
Channel
Operational
Opcode
Info

Description

An operation has failed due to a file system limitation.

Message #

An operation has failed due to a file system limitation.

           Reason: %1
           Volume Id: %3
           Volume Name: %4
           File Path: %5

Fields #

NameDescription
Reason UInt16
ReasonOrigin UInt16
VolumeCorrelationId GUID
VolumeName UnicodeString
FilePath UnicodeString
AdditionalInfo UnicodeString

Event ID 162: The data read from the storage does not match what was previously written or read.

#
Provider
Microsoft-Windows-Ntfs
Channel
System
Opcode
Info

Description

The data read from the storage does not match what was previously written or read.

Message #

The data read from the storage does not match what was previously written or read.

           Volume correlation Id: %1
           Volume name: %3
           Volume label: %5
           Device name: %7
           File reference: %8
           File name: %10
           Attribute type code: %11
           Attribute name: %13
           File offset: %14
           Volume offset: %15
           Length: %16
           Called from worker: %17
           Livedump worker status: %18

Fields #

NameDescription
VolumeCorrelationId GUID
VolumeIdLength UInt16
VolumeId UnicodeString
VolumeLabelLength UInt16
VolumeLabel UnicodeString
DeviceNameLength UInt16
DeviceName UnicodeString
FileReference UInt64
FileNameLength UInt16
FileName UnicodeString
AttributeTypeCode HexInt32
AttributeNameLength UInt16
AttributeName UnicodeString
FileOffset HexInt64
VolumeOffset HexInt64
Length HexInt32
CalledFromWorker Boolean
WorkerStatus HexInt32
DeviceGuid GUID
VendorIdLength UInt32
VendorId UnicodeString
ProductIdLength UInt32
ProductId UnicodeString
ProductRevisionLength UInt32
ProductRevision UnicodeString
DeviceSerialNumberLength UInt32
DeviceSerialNumber UnicodeString
BusType UInt32
NativeNVMe Boolean
AdapterSerialNumberLength UInt32
AdapterSerialNumber UnicodeString
ReadDataValidOffset UInt16
ReadDataValidLength UInt16
ReadData Binary
PrevDataValidOffset UInt16
PrevDataValidLength UInt16
PrevData Binary

Event ID 163: MftBitmap is not big enough for MftData or does not have required allocations.

#
Provider
Microsoft-Windows-Ntfs
Channel
System
Opcode
Info

Description

MftBitmap is not big enough for MftData or does not have required allocations.

Message #

MftBitmap is not big enough for MftData or does not have required allocations.

           Volume correlation Id: %1
           Volume name: %3
           Volume label: %5
           Device name: %7
           Mft data allocation size: %20
           Mft data file size: %21
           Mft bitmap allocation size: %22
           Mft bitmap file size: %23
           Bytes per FRS: %24
           Mft data attribute allocation size: %25
           Mft data attribute file size: %26
           Mft bitmap attribute highest Vcn: %27
           Mft bitmap attribute allocation size: %28
           Mft bitmap attribute file size: %29
           Last data and bitmap attribute record in Mft are in same FRS: %30
           Called from worker: %31
           Livedump worker status: %32
           Major function: %33
           Minor function: %34
           Source tag: %35

Fields #

NameDescription
VolumeCorrelationId GUID
VolumeIdLength UInt16
VolumeId UnicodeString
VolumeLabelLength UInt16
VolumeLabel UnicodeString
DeviceNameLength UInt16
DeviceName UnicodeString
DeviceGuid GUID
VendorIdLength UInt32
VendorId UnicodeString
ProductIdLength UInt32
ProductId UnicodeString
ProductRevisionLength UInt32
ProductRevision UnicodeString
DeviceSerialNumberLength UInt32
DeviceSerialNumber UnicodeString
BusType UInt32
NativeNVMe Boolean
AdapterSerialNumberLength UInt32
AdapterSerialNumber UnicodeString
MftDataAllocationSize HexInt64
MftDataFileSize HexInt64
MftBitmapAllocationSize HexInt64
MftBitmapFileSize HexInt64
BytesPerFRS HexInt32
MftDataAttrAllocatedLength HexInt64
MftDataAttrFileSize HexInt64
MftBitmapAttrHighestVcn HexInt64
MftBitmapAttrAllocatedLength HexInt64
MftBitmapAttrFileSize HexInt64
MftLastDataAndBitmapInSameFrs UInt8
CalledFromWorker Boolean
WorkerStatus HexInt32
MajorFunction UInt8
MinorFunction UInt8
SourceTag HexInt64

Event ID 170: IO latency summary.

#
Provider
Microsoft-Windows-Ntfs
Channel
Operational
Level
Informational
Opcode
Info

Description

IO latency summary.

Message #

IO latency summary:

           Volume Id: %1
           Volume name: %3
           Is boot volume: %4
           
           IO type: %20
           
           Interval duration: %18
           
           Max Acceptable IO Latency: %22
           High Latency IOs: %23
           
           IO count: %24
           Avg IOPS: %25
           Avg latency: %27
           
           Latency buckets: [%28]
           IO count buckets: [%29, %30, %31, %32, %33, %34, %35, %36, %37, %38, %39, %40]
           Total time buckets (ns): [%41, %42, %43, %44, %45, %46, %47, %48, %49, %50, %51, %52]
           
           Device GUID: %5
           Device manufacturer: %7
           Device model: %9
           Device revision: %11
           Device serial number: %13
           Bus type: %14
           
           Adapter serial number: %16
           
           For more details see the details tab.

Fields #

NameDescription
VolumeCorrelationId GUID[IO latency summary] Volume Id.
VolumeNameLength UInt16
VolumeName UnicodeString[IO latency summary] Volume name.
IsBootVolume Boolean[IO latency summary] Is boot volume.
DeviceGuid GUID[IO latency summary] Device GUID.
VendorIdLength UInt16
VendorId UnicodeString[IO latency summary] Device manufacturer.
ProductIdLength UInt16
ProductId UnicodeString[IO latency summary] Device model.
ProductRevisionLength UInt16
ProductRevision UnicodeString[IO latency summary] Device revision.
DeviceSerialNumberLength UInt16
DeviceSerialNumber UnicodeString[IO latency summary] Device serial number.
BusType UInt32[IO latency summary] Bus type.
AdapterSerialNumberLength UInt16
AdapterSerialNumber UnicodeString[IO latency summary] Adapter serial number.
IntervalDurationMs UInt64
IntervalDurationStr UnicodeString[IO latency summary] Interval duration.
IoType UInt16
IoTypeStr UnicodeString[IO latency summary] IO type.
MaxLatencyMs
MaxLatencyStr UnicodeString[IO latency summary] Max latency.
HighLatencyIoCount UInt32[IO latency summary] High Latency IOs.
TotalIoCount UInt64[IO latency summary] IO count.
AverageIops UInt64[IO latency summary] Avg IOPS.
AverageLatencyNs UInt64
AverageLatencyStr UnicodeString[IO latency summary] Avg latency.
LatencyBuckets UnicodeString
IoCount0 UInt64
IoCount1 UInt64
IoCount2 UInt64
IoCount3 UInt64
IoCount4 UInt64
IoCount5 UInt64
IoCount6 UInt64
IoCount7 UInt64
IoCount8 UInt64
IoCount9 UInt64
IoCount10 UInt64
IoCount11 UInt64
TotalTimeNs0 UInt64
TotalTimeNs1 UInt64
TotalTimeNs2 UInt64
TotalTimeNs3 UInt64
TotalTimeNs4 UInt64
TotalTimeNs5 UInt64
TotalTimeNs6 UInt64
TotalTimeNs7 UInt64
TotalTimeNs8 UInt64
TotalTimeNs9 UInt64
TotalTimeNs10 UInt64
TotalTimeNs11 UInt64
SummaryId UInt64
HighLatencyMs
HighLatencyStr[IO latency summary] Max Acceptable IO Latency.
TotalIoTimeNs
MaxLatencyNs UInt64
IoCount12 UInt64
IoCount13 UInt64
IoCount14 UInt64
IoCount15 UInt64
TotalTimeNs12 UInt64
TotalTimeNs13 UInt64
TotalTimeNs14 UInt64
TotalTimeNs15 UInt64
TotalBytes
AverageBps
TotalBytes0
TotalBytes1
TotalBytes2
TotalBytes3
TotalBytes4
TotalBytes5
TotalBytes6
TotalBytes7
TotalBytes8
TotalBytes9
TotalBytes10
TotalBytes11
TotalBytes12
TotalBytes13
TotalBytes14
TotalBytes15
TotalExtents
TotalExtents0
TotalExtents1
TotalExtents2
TotalExtents3
TotalExtents4
TotalExtents5
TotalExtents6
TotalExtents7
TotalExtents8
TotalExtents9
TotalExtents10
TotalExtents11
TotalExtents12
TotalExtents13
TotalExtents14
TotalExtents15

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Ntfs",
    "guid": "{3FF37A1C-A68D-4D6E-8C9B-F79E8B16C482}",
    "event_source_name": "",
    "event_id": 170,
    "version": 1,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 4611967493406195712,
    "time_created": "2026-06-13T13:22:17.4336943+00:00",
    "event_record_id": 590,
    "correlation": {},
    "execution": {
      "process_id": 4,
      "thread_id": 5376
    },
    "channel": "Microsoft-Windows-Ntfs/Operational",
    "computer": "telemetry-DC-a.cell-a.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "VolumeCorrelationId": "{77ac4d73-0000-0000-0000-100000000000}",
    "VolumeNameLength": "2",
    "VolumeName": "C:",
    "IsBootVolume": "true",
    "DeviceGuid": "{5a7d9ced-a852-a1ac-e3da-7b3e59928b2a}",
    "VendorIdLength": "8",
    "VendorId": "Red Hat ",
    "ProductIdLength": "6",
    "ProductId": "VirtIO",
    "ProductRevisionLength": "4",
    "ProductRevision": "0001",
    "DeviceSerialNumberLength": "0",
    "DeviceSerialNumber": "",
    "BusType": "1",
    "AdapterSerialNumberLength": "0",
    "AdapterSerialNumber": "",
    "IntervalDurationMs": "3603390",
    "IntervalDurationStr": "3603 s",
    "IoType": "25",
    "IoTypeStr": "Open file",
    "MaxLatencyMs": "30000",
    "MaxLatencyStr": "30 s",
    "HighLatencyIoCount": "0",
    "TotalIoCount": "127270",
    "AverageIops": "80820",
    "AverageLatencyNs": "12373",
    "AverageLatencyStr": "12 us",
    "LatencyBuckets": "256 us, 1 ms, 4 ms, 16 ms, 64 ms, 128 ms, 256 ms, 2 s, 6 s, 10 s, 20 s, > 20 s",
    "IoCount0": "127146",
    "IoCount1": "123",
    "IoCount2": "1",
    "IoCount3": "0",
    "IoCount4": "0",
    "IoCount5": "0",
    "IoCount6": "0",
    "IoCount7": "0",
    "IoCount8": "0",
    "IoCount9": "0",
    "IoCount10": "0",
    "IoCount11": "0",
    "TotalTimeNs0": "1505343400",
    "TotalTimeNs1": "68184200",
    "TotalTimeNs2": "1195600",
    "TotalTimeNs3": "0",
    "TotalTimeNs4": "0",
    "TotalTimeNs5": "0",
    "TotalTimeNs6": "0",
    "TotalTimeNs7": "0",
    "TotalTimeNs8": "0",
    "TotalTimeNs9": "0",
    "TotalTimeNs10": "0",
    "TotalTimeNs11": "0"
  },
  "message": "IO latency summary:\r\n\r\n           Volume Id: {77ac4d73-0000-0000-0000-100000000000}\r\n           Volume name: C:\r\n           Is boot volume: true\r\n           \r\n           IO type: Open file\r\n           \r\n           Interval duration: 3603 s\r\n           \r\n           Max Acceptable IO Latency: 30 s\r\n           High Latency IOs: 0\r\n           \r\n           IO count: 127270\r\n           Avg IOPS: 80820\r\n           Avg latency: 12 us\r\n           \r\n           Latency buckets: [256 us, 1 ms, 4 ms, 16 ms, 64 ms, 128 ms, 256 ms, 2 s, 6 s, 10 s, 20 s, > 20 s]\r\n           IO count buckets: [127146, 123, 1, 0, 0, 0, 0, 0, 0, 0, 0, 0]\r\n           Total time buckets (ns): [1505343400, 68184200, 1195600, 0, 0, 0, 0, 0, 0, 0, 0, 0]\r\n           \r\n           Device GUID: {5a7d9ced-a852-a1ac-e3da-7b3e59928b2a}\r\n           Device manufacturer: Red Hat \r\n           Device model: VirtIO\r\n           Device revision: 0001\r\n           Device serial number: \r\n           Bus type: SCSI\r\n           \r\n           Adapter serial number: \r\n           \r\n           For more details see the details tab.\r\n"
}

Event ID 171: File-Level Trim Summary.

#
Provider
Microsoft-Windows-Ntfs
Channel
Operational
Level
Informational
Opcode
Info

Description

File-Level Trim Summary.

Message #

File-Level Trim Summary:

           Volume Id: %1
           Volume name: %3
           Is boot volume: %4
           
           Period duration (us): %5
           
           Operation count: %6
           Reposted operation count: %7
           Failed operation count: %8
           Operation range count: %9
           Operation byte count: %10
           Operation long range byte count %11
           Unaligned range count: %12
           Bytes in unaligned ranges: %13
           Operation trim extent count: %14
           Non-blocking aligned trim byte count: %15
           Reclaimed byte count: %16
           
           Byte count bucket values: [%18]
           
           Operation counts: [%19, %20, %21, %22, %23, %24, %25, %26, %27, %28, %29, %30]
           Operation byte counts: [%31, %32, %33, %34, %35, %36, %37, %38, %39, %40, %41, %42]
           Operation bytes reclaimed: [%43, %44, %45, %46, %47, %48, %49, %50, %51, %52, %53, %54]
           Operation latency (us): [%55, %56, %57, %58, %59, %60, %61, %62, %63, %64, %65, %67]
           
           Latency bucket values: [%68]
           
           Operation latency count: [%69, %70, %71, %72, %73, %74, %75, %76, %77, %78, %79, %80, %81, %82, %83]
           
           Top failure status codes and instance counts:
               %84      %85
               %86      %87
               %88      %89
               %90      %91
               %92      %93

Fields #

NameDescription
VolumeCorrelationId GUID[File-Level Trim Summary] Volume Id.
VolumeNameLength UInt16
VolumeName UnicodeString[File-Level Trim Summary] Volume name.
IsBootVolume Boolean[File-Level Trim Summary] Is boot volume.
PeriodDurationMicrosSec Int64[File-Level Trim Summary] Period duration (us).
OperationCount UInt64[File-Level Trim Summary] Operation count.
RepostedOperationCount UInt64[File-Level Trim Summary] Reposted operation count.
FailedOperationCount UInt64[File-Level Trim Summary] Failed operation count.
OperationRangeCount UInt64[File-Level Trim Summary] Operation range count.
OperationByteCount UInt64[File-Level Trim Summary] Operation byte count.
OperationLongRangeByteCount UInt64
UnalignedRangeCount UInt64[File-Level Trim Summary] Unaligned range count.
BytesInUnalignedRanges UInt64[File-Level Trim Summary] Bytes in unaligned ranges.
OperationTrimExtentCount UInt64[File-Level Trim Summary] Operation trim extent count.
NonBlockAlignedTrimByteCount UInt64[File-Level Trim Summary] Non-blocking aligned trim byte count.
ReclaimedByteCount UInt64[File-Level Trim Summary] Reclaimed byte count.
ByteCountLabelsLength UInt16
ByteCountLabels UnicodeString
OperationCountBuckets1 UInt64
OperationCountBuckets2 UInt64
OperationCountBuckets3 UInt64
OperationCountBuckets4 UInt64
OperationCountBuckets5 UInt64
OperationCountBuckets6 UInt64
OperationCountBuckets7 UInt64
OperationCountBuckets8 UInt64
OperationCountBuckets9 UInt64
OperationCountBuckets10 UInt64
OperationCountBuckets11 UInt64
OperationCountBuckets12 UInt64
OperationByteCountBuckets1 UInt64
OperationByteCountBuckets2 UInt64
OperationByteCountBuckets3 UInt64
OperationByteCountBuckets4 UInt64
OperationByteCountBuckets5 UInt64
OperationByteCountBuckets6 UInt64
OperationByteCountBuckets7 UInt64
OperationByteCountBuckets8 UInt64
OperationByteCountBuckets9 UInt64
OperationByteCountBuckets10 UInt64
OperationByteCountBuckets11 UInt64
OperationByteCountBuckets12 UInt64
OperationBytesReclaimedBuckets1 UInt64
OperationBytesReclaimedBuckets2 UInt64
OperationBytesReclaimedBuckets3 UInt64
OperationBytesReclaimedBuckets4 UInt64
OperationBytesReclaimedBuckets5 UInt64
OperationBytesReclaimedBuckets6 UInt64
OperationBytesReclaimedBuckets7 UInt64
OperationBytesReclaimedBuckets8 UInt64
OperationBytesReclaimedBuckets9 UInt64
OperationBytesReclaimedBuckets10 UInt64
OperationBytesReclaimedBuckets11 UInt64
OperationBytesReclaimedBuckets12 UInt64
OperationLatencyBuckets1 UInt64
OperationLatencyBuckets2 UInt64
OperationLatencyBuckets3 UInt64
OperationLatencyBuckets4 UInt64
OperationLatencyBuckets5 UInt64
OperationLatencyBuckets6 UInt64
OperationLatencyBuckets7 UInt64
OperationLatencyBuckets8 UInt64
OperationLatencyBuckets9 UInt64
OperationLatencyBuckets10 UInt64
OperationLatencyBuckets11 UInt64
OperationLatencyBuckets12 UInt64
LatencyBucketLabelsLength UInt16
LatencyBucketLabelsLabels UnicodeString
OperationCountLatencyBuckets1 UInt64
OperationCountLatencyBuckets2 UInt64
OperationCountLatencyBuckets3 UInt64
OperationCountLatencyBuckets4 UInt64
OperationCountLatencyBuckets5 UInt64
OperationCountLatencyBuckets6 UInt64
OperationCountLatencyBuckets7 UInt64
OperationCountLatencyBuckets8 UInt64
OperationCountLatencyBuckets9 UInt64
OperationCountLatencyBuckets10 UInt64
OperationCountLatencyBuckets11 UInt64
OperationCountLatencyBuckets12 UInt64
OperationCountLatencyBuckets13 UInt64
OperationCountLatencyBuckets14 UInt64
OperationCountLatencyBuckets15 UInt64
OperationFailureStatusCode1 HexInt32Top failure status codes and instance counts
OperationFailureCount1 UInt64
OperationFailureStatusCode2 HexInt32
OperationFailureCount2 UInt64
OperationFailureStatusCode3 HexInt32
OperationFailureCount3 UInt64
OperationFailureStatusCode4 HexInt32
OperationFailureCount4 UInt64
OperationFailureStatusCode5 HexInt32
OperationFailureCount5 UInt64

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Ntfs",
    "guid": "3FF37A1C-A68D-4D6E-8C9B-F79E8B16C482",
    "event_source_name": "",
    "event_id": 171,
    "version": 3,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 4611967493406195712,
    "time_created": "2023-11-05T22:47:04.962167+00:00",
    "event_record_id": 182,
    "correlation": {},
    "execution": {
      "process_id": 4,
      "thread_id": 52
    },
    "channel": "Microsoft-Windows-Ntfs/Operational",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "VolumeCorrelationId": "7597D2A3-4404-4F99-B979-6233378A81BF",
    "VolumeNameLength": 2,
    "VolumeName": "C:",
    "IsBootVolume": true,
    "PeriodDurationMicrosSec": 899757629,
    "OperationCount": 2,
    "RepostedOperationCount": 0,
    "FailedOperationCount": 0,
    "OperationRangeCount": 2,
    "OperationByteCount": 0,
    "OperationLongRangeByteCount": 18446744073709551614,
    "UnalignedRangeCount": 0,
    "BytesInUnalignedRanges": 0,
    "OperationTrimExtentCount": 2,
    "NonBlockAlignedTrimByteCount": 0,
    "ReclaimedByteCount": 2030043136,
    "ByteCountLabelsLength": 80,
    "ByteCountLabels": "4 KB, 64 KB, 1 MB, 16 MB, 128 MB, 1 GB, 16 GB, 128 GB, 1 TB, 16 TB, 1 EB, 1+ EB",
    "OperationCountBuckets1": 0,
    "OperationCountBuckets2": 0,
    "OperationCountBuckets3": 0,
    "OperationCountBuckets4": 0,
    "OperationCountBuckets5": 0,
    "OperationCountBuckets6": 0,
    "OperationCountBuckets7": 0,
    "OperationCountBuckets8": 0,
    "OperationCountBuckets9": 0,
    "OperationCountBuckets10": 0,
    "OperationCountBuckets11": 0,
    "OperationCountBuckets12": 2,
    "OperationByteCountBuckets1": 0,
    "OperationByteCountBuckets2": 0,
    "OperationByteCountBuckets3": 0,
    "OperationByteCountBuckets4": 0,
    "OperationByteCountBuckets5": 0,
    "OperationByteCountBuckets6": 0,
    "OperationByteCountBuckets7": 0,
    "OperationByteCountBuckets8": 0,
    "OperationByteCountBuckets9": 0,
    "OperationByteCountBuckets10": 0,
    "OperationByteCountBuckets11": 0,
    "OperationByteCountBuckets12": 0,
    "OperationBytesReclaimedBuckets1": 0,
    "OperationBytesReclaimedBuckets2": 0,
    "OperationBytesReclaimedBuckets3": 0,
    "OperationBytesReclaimedBuckets4": 0,
    "OperationBytesReclaimedBuckets5": 54,
    "OperationBytesReclaimedBuckets6": 0,
    "OperationBytesReclaimedBuckets7": 70,
    "OperationBytesReclaimedBuckets8": 0,
    "OperationBytesReclaimedBuckets9": 0,
    "OperationBytesReclaimedBuckets10": 0,
    "OperationBytesReclaimedBuckets11": 0,
    "OperationBytesReclaimedBuckets12": 0,
    "OperationLatencyBuckets1": 0,
    "OperationLatencyBuckets2": 0,
    "OperationLatencyBuckets3": 0,
    "OperationLatencyBuckets4": 0,
    "OperationLatencyBuckets5": 0,
    "OperationLatencyBuckets6": 0,
    "OperationLatencyBuckets7": 0,
    "OperationLatencyBuckets8": 0,
    "OperationLatencyBuckets9": 0,
    "OperationLatencyBuckets10": 0,
    "OperationLatencyBuckets11": 0,
    "OperationLatencyBuckets12": 248,
    "LatencyBucketLabelsLength": 79,
    "LatencyBucketLabelsLabels": "256us, 1ms, 4ms, 16ms, 64ms, 128ms, 256ms, 2s, 6s, 10s, 20s, 1m, 5m, 15m, 15m+",
    "OperationCountLatencyBuckets1": 2,
    "OperationCountLatencyBuckets2": 0,
    "OperationCountLatencyBuckets3": 0,
    "OperationCountLatencyBuckets4": 0,
    "OperationCountLatencyBuckets5": 0,
    "OperationCountLatencyBuckets6": 0,
    "OperationCountLatencyBuckets7": 0,
    "OperationCountLatencyBuckets8": 0,
    "OperationCountLatencyBuckets9": 0,
    "OperationCountLatencyBuckets10": 0,
    "OperationCountLatencyBuckets11": 0,
    "OperationCountLatencyBuckets12": 0,
    "OperationCountLatencyBuckets13": 0,
    "OperationCountLatencyBuckets14": 0,
    "OperationCountLatencyBuckets15": 0,
    "OperationFailureStatusCode1": "0x0",
    "OperationFailureCount1": 0,
    "OperationFailureStatusCode2": "0x0",
    "OperationFailureCount2": 0,
    "OperationFailureStatusCode3": "0x0",
    "OperationFailureCount3": 0,
    "OperationFailureStatusCode4": "0x0",
    "OperationFailureCount4": 0,
    "OperationFailureStatusCode5": "0x0",
    "OperationFailureCount5": 0
  },
  "message": ""
}

References #

Event ID 201: NtfsLogFileFull VolumeId: NtfsLogFileFull_VolumeId, Reason: Reason.

#
Provider
Microsoft-Windows-Ntfs
Channel
Performance
Task
LogFileFull

Description

NtfsLogFileFull VolumeId: NtfsLogFileFull_VolumeId, Reason: Reason.

Message #

NtfsLogFileFull VolumeId: %1, Reason: %2

Fields #

NameDescription
Vcb Pointer
LogFileFullReason UInt16

Event ID 202: PeriodicCheckpointStart VolumeId: PeriodicCheckpointStart_VolumeId, Reason: Reason, Usage: Usage%.

#
Provider
Microsoft-Windows-Ntfs
Channel
Performance
Also via
realtime ETW trace
Level
Informational
Task
Checkpoint
Opcode
Start

Description

PeriodicCheckpointStart VolumeId: PeriodicCheckpointStart_VolumeId, Reason: Reason, Usage: Usage%.

Message #

PeriodicCheckpointStart VolumeId: %1, Reason: %2, Usage: %3%

Fields #

NameDescription
Vcb Pointer
LogFileFullReason UInt16
LogFileUsePercentage UInt16

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Ntfs",
    "guid": "{3FF37A1C-A68D-4D6E-8C9B-F79E8B16C482}",
    "event_source_name": "",
    "event_id": 202,
    "version": 0,
    "level": 4,
    "task": 1,
    "opcode": 1,
    "keywords": "0x1000000000000A00",
    "time_created": "2026-06-02T06:00:05.123+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{405E6FE6-7C77-466B-8D93-5F354CA37E8C}"
    },
    "execution": {
      "process_id": 4,
      "thread_id": 6140
    },
    "channel": "ETW Trace",
    "computer": "DESKTOP-FF3N5XK",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "LogFileFullReason": 0,
    "LogFileUsePercentage": 9,
    "Vcb": "0x0"
  },
  "message": "Checkpoint"
}

Event ID 203: PeriodicCheckpointComplete VolumeId: PeriodicCheckpointComplete_VolumeId, DirtyMetaDataPages: DirtyMetaDataPages.

#
Provider
Microsoft-Windows-Ntfs
Channel
Performance
Also via
realtime ETW trace
Level
Informational
Task
Checkpoint
Opcode
Stop

Description

PeriodicCheckpointComplete VolumeId: PeriodicCheckpointComplete_VolumeId, DirtyMetaDataPages: DirtyMetaDataPages.

Message #

PeriodicCheckpointComplete VolumeId: %1, DirtyMetaDataPages: %2

Fields #

NameDescription
Vcb Pointer
DirtyMetaDataPages UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Ntfs",
    "guid": "{3FF37A1C-A68D-4D6E-8C9B-F79E8B16C482}",
    "event_source_name": "",
    "event_id": 203,
    "version": 0,
    "level": 4,
    "task": 1,
    "opcode": 2,
    "keywords": "0x1000000000000A00",
    "time_created": "2026-06-02T06:00:05.124+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{405E6FE6-7C77-466B-8D93-5F354CA37E8C}"
    },
    "execution": {
      "process_id": 4,
      "thread_id": 6140
    },
    "channel": "ETW Trace",
    "computer": "DESKTOP-FF3N5XK",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "DirtyMetaDataPages": 144,
    "Vcb": "0x0"
  },
  "message": "Checkpoint"
}

Event ID 204: CleanCheckpointStart VolumeId: CleanCheckpointStart_VolumeId, Reason: Reason, Usage: Usage%.

#
Provider
Microsoft-Windows-Ntfs
Channel
Performance
Task
Checkpoint
Opcode
Start

Description

CleanCheckpointStart VolumeId: CleanCheckpointStart_VolumeId, Reason: Reason, Usage: Usage%.

Message #

CleanCheckpointStart VolumeId: %1, Reason: %2, Usage: %3%

Fields #

NameDescription
Vcb Pointer
LogFileFullReason UInt16
LogFileUsePercentage UInt16

Event ID 205: CleanCheckpointComplete VolumeId: CleanCheckpointComplete_VolumeId, DirtyMetaDataPages: DirtyMetaDataPages.

#
Provider
Microsoft-Windows-Ntfs
Channel
Performance
Task
Checkpoint
Opcode
Stop

Description

CleanCheckpointComplete VolumeId: CleanCheckpointComplete_VolumeId, DirtyMetaDataPages: DirtyMetaDataPages.

Message #

CleanCheckpointComplete VolumeId: %1, DirtyMetaDataPages: %2

Fields #

NameDescription
Vcb Pointer
DirtyMetaDataPages UInt32

Event ID 206: MftRecordRead VolumeId: MftRecordRead_VolumeId, BaseFileId: BaseFileId, FileId: FileId, CacheHit: CacheHit.

#
Provider
Microsoft-Windows-Ntfs
Channel
Performance
Also via
realtime ETW trace
Level
Informational
Task
MftRecordRead
Opcode
win:Info

Description

MftRecordRead VolumeId: MftRecordRead_VolumeId, BaseFileId: BaseFileId, FileId: FileId, CacheHit: CacheHit.

Message #

MftRecordRead VolumeId: %1, BaseFileId: %2, FileId: %3, CacheHit: %4

Fields #

NameDescription
Vcb Pointer
BaseFileId HexInt32
FileId HexInt32
CacheHit Boolean

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Ntfs",
    "guid": "{3FF37A1C-A68D-4D6E-8C9B-F79E8B16C482}",
    "event_source_name": "",
    "event_id": 206,
    "version": 0,
    "level": 4,
    "task": 2,
    "opcode": 0,
    "keywords": "0x1000000000001000",
    "time_created": "2026-06-02T05:29:46.301+00:00",
    "event_record_id": 0,
    "correlation": {},
    "execution": {
      "process_id": 4,
      "thread_id": 22516
    },
    "channel": "ETW Trace",
    "computer": "JD-DC01-2022",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "BaseFileId": "0A100000",
    "CacheHit": false,
    "FileId": "0A100000",
    "Vcb": "0x0"
  },
  "message": "MftRecordRead"
}

Event ID 208: MftRecordRead VolumeId: MftRecordRead_VolumeId, BaseFileId: BaseFileId, FileId: FileId.

#
Provider
Microsoft-Windows-Ntfs
Channel
Performance
Task
MftRecordWrite

Description

MftRecordRead VolumeId: MftRecordRead_VolumeId, BaseFileId: BaseFileId, FileId: FileId.

Message #

MftRecordRead VolumeId: %1, BaseFileId: %2, FileId: %3

Fields #

NameDescription
Vcb Pointer
BaseFileId HexInt32
FileId HexInt32

Event ID 210: Thinly provisioned volume VolumeId (DeviceName).

#
Provider
Microsoft-Windows-Ntfs
Channel
System
Task
TPMapBitNotSet

Description

Thinly provisioned volume VolumeId (DeviceName).

Message #

Thinly provisioned volume %1 (%2)
were not being mapped between clusters %3 and %4.
It is now fixed.

Fields #

NameDescription
VolumeId UnicodeString
DeviceName UnicodeString
StartingLCN HexInt64
EndingLCN HexInt64

Event ID 211: Thinly provisioned volume VolumeId (DeviceName).

#
Provider
Microsoft-Windows-Ntfs
Channel
System
Task
TPMapBitNotSet

Description

Thinly provisioned volume VolumeId (DeviceName).

Message #

Thinly provisioned volume %1 (%2)
were not being mapped between clusters %3 and %4.
Repair was unsucccessful.
Possibly out of available slabs.

Fields #

NameDescription
VolumeId UnicodeString
DeviceName UnicodeString
StartingLCN HexInt64
EndingLCN HexInt64

Event ID 230: WorkItem queued, WorkItem: WorkItem_queued_WorkItem, Reason: Reason.

#
Provider
Microsoft-Windows-Ntfs
Channel
Performance
Also via
realtime ETW trace
Level
Informational
Task
WorkItem
Opcode
win:Info

Description

WorkItem queued, WorkItem: WorkItem_queued_WorkItem, Reason: Reason.

Message #

WorkItem queued, WorkItem: %1, Reason: %2

Fields #

NameDescription
WorkItem Pointer
Reason UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Ntfs",
    "guid": "{3FF37A1C-A68D-4D6E-8C9B-F79E8B16C482}",
    "event_source_name": "",
    "event_id": 230,
    "version": 0,
    "level": 4,
    "task": 7,
    "opcode": 0,
    "keywords": "0x1000000000010000",
    "time_created": "2026-06-02T06:00:02.768+00:00",
    "event_record_id": 0,
    "correlation": {},
    "execution": {
      "process_id": 3756,
      "thread_id": 4588
    },
    "channel": "ETW Trace",
    "computer": "DESKTOP-FF3N5XK",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Reason": 2,
    "WorkItem": "0x0"
  },
  "message": "WorkItem"
}

Event ID 231: WorkItem queue failed, WorkItem: WorkItem_queue_failed_WorkItem, Reason: Reason, Error: Error.

#
Provider
Microsoft-Windows-Ntfs
Channel
Performance
Task
WorkItem

Description

WorkItem queue failed, WorkItem: WorkItem_queue_failed_WorkItem, Reason: Reason, Error: Error.

Message #

WorkItem queue failed, WorkItem: %1, Reason: %2, Error: %3

Fields #

NameDescription
WorkItem Pointer
Reason UInt32
Error HexInt32

Event ID 232: WorkItem started, WorkItem: WorkItem_started_WorkItem, Reason: Reason.

#
Provider
Microsoft-Windows-Ntfs
Channel
Performance
Also via
realtime ETW trace
Level
Informational
Task
WorkItem
Opcode
Start

Description

WorkItem started, WorkItem: WorkItem_started_WorkItem, Reason: Reason.

Message #

WorkItem started, WorkItem: %1, Reason: %2

Fields #

NameDescription
WorkItem Pointer
Reason UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Ntfs",
    "guid": "{3FF37A1C-A68D-4D6E-8C9B-F79E8B16C482}",
    "event_source_name": "",
    "event_id": 232,
    "version": 0,
    "level": 4,
    "task": 7,
    "opcode": 1,
    "keywords": "0x1000000000010000",
    "time_created": "2026-06-02T06:00:05.123+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{405E6FE6-7C77-466B-8D93-5F354CA37E8C}"
    },
    "execution": {
      "process_id": 4,
      "thread_id": 6140
    },
    "channel": "ETW Trace",
    "computer": "DESKTOP-FF3N5XK",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Reason": 1,
    "WorkItem": "0x0"
  },
  "message": "WorkItem"
}

Event ID 233: WorkItem completed, WorkItem: WorkItem_completed_WorkItem, Reason: Reason.

#
Provider
Microsoft-Windows-Ntfs
Channel
Performance
Also via
realtime ETW trace
Level
Informational
Task
WorkItem
Opcode
Stop

Description

WorkItem completed, WorkItem: WorkItem_completed_WorkItem, Reason: Reason.

Message #

WorkItem completed, WorkItem: %1, Reason: %2

Fields #

NameDescription
WorkItem Pointer
Reason UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Ntfs",
    "guid": "{3FF37A1C-A68D-4D6E-8C9B-F79E8B16C482}",
    "event_source_name": "",
    "event_id": 233,
    "version": 0,
    "level": 4,
    "task": 7,
    "opcode": 2,
    "keywords": "0x1000000000010000",
    "time_created": "2026-06-02T06:00:05.124+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{405E6FE6-7C77-466B-8D93-5F354CA37E8C}"
    },
    "execution": {
      "process_id": 4,
      "thread_id": 6140
    },
    "channel": "ETW Trace",
    "computer": "DESKTOP-FF3N5XK",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Reason": 1,
    "WorkItem": "0x0"
  },
  "message": "WorkItem"
}

Event ID 240: File metadata optimization started.

#
Provider
Microsoft-Windows-Ntfs
Channel
Performance
Task
FileMetadataOptimization
Opcode
Start

Description

File metadata optimization started.

Message #

File metadata optimization started.

                    Volume guid: %1
                    Volume name: %3
                    File reference: %4

Fields #

NameDescription
VolumeGuid GUID
VolumeNameLength UInt32
VolumeName UnicodeString
FileReference UInt64

Event ID 241: File metadata optimization completed.

#
Provider
Microsoft-Windows-Ntfs
Channel
Performance
Task
FileMetadataOptimization
Opcode
Stop

Description

File metadata optimization completed.

Message #

File metadata optimization completed.

                    Volume guid: %1
                    Volume name: %3
                    File reference: %4

Fields #

NameDescription
VolumeGuid GUID
VolumeNameLength UInt32
VolumeName UnicodeString
FileReference UInt64

Event ID 300: NTFS volume dismount has started.

#
Provider
Microsoft-Windows-Ntfs
Channel
Operational
Level
Informational
Task
Volumedismount
Opcode
Start

Description

NTFS volume dismount has started.

Message #

NTFS volume dismount has started.

           Volume GUID: %4
           Volume Name: %6
           Volume Label: %8

Fields #

NameDescription
VolumeCorrelationId GUID
VolumeIdLength UInt16
VolumeId UnicodeStringVolume name.
VolumeLabelLength UInt16
VolumeLabel UnicodeString
DeviceNameLength UInt16
DeviceName UnicodeString
DeviceGuid GUID
VendorIdLength UInt32
VendorId UnicodeStringDevice manufacturer.
ProductIdLength UInt32
ProductId UnicodeStringDevice model.
ProductRevisionLength UInt32
ProductRevision UnicodeStringDevice revision.
DeviceSerialNumberLength UInt32
DeviceSerialNumber UnicodeString
BusType UInt32
AdapterSerialNumberLength UInt32
AdapterSerialNumber UnicodeString
Vcb Pointer
ProcessId UInt32
ProcessName AnsiString
DismountReason AnsiStringReason.
NativeNVMe

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Ntfs",
    "guid": "{3FF37A1C-A68D-4D6E-8C9B-F79E8B16C482}",
    "event_source_name": "",
    "event_id": 300,
    "version": 1,
    "level": 4,
    "task": 8,
    "opcode": 1,
    "keywords": 4611686018427387936,
    "time_created": "2026-05-28T11:11:54.0183900+00:00",
    "event_record_id": 113,
    "correlation": {},
    "execution": {
      "process_id": 4844,
      "thread_id": 4912
    },
    "channel": "Microsoft-Windows-Ntfs/Operational",
    "computer": "telemetry-DC-d.cell-d.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "VolumeCorrelationId": "{ee0f27ce-5a85-11f1-9650-d85cd7107d86}",
    "VolumeIdLength": "0",
    "VolumeId": "",
    "VolumeLabelLength": "12",
    "VolumeLabel": "Windows 2022",
    "DeviceNameLength": "33",
    "DeviceName": "\\Device\\HarddiskVolumeShadowCopy3",
    "DeviceGuid": "{00000000-0000-0000-0000-000000000000}",
    "VendorIdLength": "0",
    "VendorId": "",
    "ProductIdLength": "0",
    "ProductId": "",
    "ProductRevisionLength": "0",
    "ProductRevision": "",
    "DeviceSerialNumberLength": "0",
    "DeviceSerialNumber": "",
    "BusType": "0",
    "AdapterSerialNumberLength": "0",
    "AdapterSerialNumber": "",
    "Vcb": "0xffffd70d7e8761b0",
    "ProcessId": "4844",
    "ProcessName": "svchost.exe",
    "DismountReason": "User request"
  },
  "message": "NTFS volume dismount has started.\r\n\r\n           Volume correlation Id: {ee0f27ce-5a85-11f1-9650-d85cd7107d86}\r\n           Volume name: \r\n           Volume label: Windows 2022\r\n\r\n           Device name: \\Device\\HarddiskVolumeShadowCopy3\r\n           Device GUID: {00000000-0000-0000-0000-000000000000}\r\n           Device manufacturer: \r\n           Device model: \r\n           Device revision: \r\n           Device serial number: \r\n           Bus type: <unknown>\r\n           \r\n           Adapter serial number: \r\n           \r\n           Process Id: 4844\r\n           Process name: svchost.exe\r\n           \r\n           Reason: User request\r\n"
}

Event ID 301: NTFS has sent volume dismount event notification and is waiting for the notifications to complete.

#
Provider
Microsoft-Windows-Ntfs
Channel
Operational
Level
Informational
Task
Volumedismount
Opcode
Suspend

Description

NTFS has sent volume dismount event notification and is waiting for the notifications to complete.

Message #

NTFS has sent volume dismount event notification and is waiting for the notifications to complete.

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Ntfs",
    "guid": "{3FF37A1C-A68D-4D6E-8C9B-F79E8B16C482}",
    "event_source_name": "",
    "event_id": 301,
    "version": 0,
    "level": 4,
    "task": 8,
    "opcode": 8,
    "keywords": 4611686018427387936,
    "time_created": "2026-05-28T11:11:54.0183925+00:00",
    "event_record_id": 114,
    "correlation": {},
    "execution": {
      "process_id": 4844,
      "thread_id": 4912
    },
    "channel": "Microsoft-Windows-Ntfs/Operational",
    "computer": "telemetry-DC-d.cell-d.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {},
  "message": "NTFS has sent volume dismount event notification and is waiting for the notifications to complete."
}

Event ID 302: The volume dismount event notification on the NTFS volume has completed.

#
Provider
Microsoft-Windows-Ntfs
Channel
Operational
Level
Informational
Task
Volumedismount
Opcode
Resume

Description

The volume dismount event notification on the NTFS volume has completed.

Message #

The volume dismount event notification on the NTFS volume has completed.

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Ntfs",
    "guid": "{3FF37A1C-A68D-4D6E-8C9B-F79E8B16C482}",
    "event_source_name": "",
    "event_id": 302,
    "version": 0,
    "level": 4,
    "task": 8,
    "opcode": 7,
    "keywords": 4611686018427387936,
    "time_created": "2026-05-28T11:11:54.0184862+00:00",
    "event_record_id": 115,
    "correlation": {},
    "execution": {
      "process_id": 4844,
      "thread_id": 4912
    },
    "channel": "Microsoft-Windows-Ntfs/Operational",
    "computer": "telemetry-DC-d.cell-d.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {},
  "message": "The volume dismount event notification on the NTFS volume has completed."
}

Event ID 303: The NTFS volume has successfully dismounted.

#
Provider
Microsoft-Windows-Ntfs
Channel
Operational
Level
Informational
Task
Volumedismount
Opcode
Stop

Description

The NTFS volume has successfully dismounted.

Message #

The NTFS volume has successfully dismounted.

           Volume GUID: %4
           Volume Name: %6
           Volume Label: %8

Fields #

NameDescription
VolumeCorrelationId GUID
VolumeIdLength UInt16
VolumeId UnicodeStringVolume name.
VolumeLabelLength UInt16
VolumeLabel UnicodeString
DeviceNameLength UInt16
DeviceName UnicodeString
DeviceGuid GUID
VendorIdLength UInt32
VendorId UnicodeStringDevice manufacturer.
ProductIdLength UInt32
ProductId UnicodeStringDevice model.
ProductRevisionLength UInt32
ProductRevision UnicodeStringDevice revision.
DeviceSerialNumberLength UInt32
DeviceSerialNumber UnicodeString
BusType UInt32
AdapterSerialNumberLength UInt32
AdapterSerialNumber UnicodeString
Vcb Pointer
ProcessId UInt32
ProcessName AnsiString
DismountReason AnsiStringReason.
NativeNVMe

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Ntfs",
    "guid": "{3FF37A1C-A68D-4D6E-8C9B-F79E8B16C482}",
    "event_source_name": "",
    "event_id": 303,
    "version": 1,
    "level": 4,
    "task": 8,
    "opcode": 2,
    "keywords": 4611686018427387936,
    "time_created": "2026-05-28T11:11:54.0200205+00:00",
    "event_record_id": 116,
    "correlation": {},
    "execution": {
      "process_id": 4844,
      "thread_id": 4912
    },
    "channel": "Microsoft-Windows-Ntfs/Operational",
    "computer": "telemetry-DC-d.cell-d.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "VolumeCorrelationId": "{ee0f27ce-5a85-11f1-9650-d85cd7107d86}",
    "VolumeIdLength": "12",
    "VolumeId": "Windows 2022",
    "VolumeLabelLength": "12",
    "VolumeLabel": "Windows 2022",
    "DeviceNameLength": "33",
    "DeviceName": "\\Device\\HarddiskVolumeShadowCopy3",
    "DeviceGuid": "{00000000-0000-0000-0000-000000000000}",
    "VendorIdLength": "0",
    "VendorId": "",
    "ProductIdLength": "0",
    "ProductId": "",
    "ProductRevisionLength": "0",
    "ProductRevision": "",
    "DeviceSerialNumberLength": "0",
    "DeviceSerialNumber": "",
    "BusType": "0",
    "AdapterSerialNumberLength": "0",
    "AdapterSerialNumber": "",
    "Vcb": "0xffffd70d7e8761b0",
    "ProcessId": "4844",
    "ProcessName": "svchost.exe",
    "DismountReason": "User request"
  },
  "message": "The NTFS volume has successfully dismounted.\r\n\r\n           Volume correlation Id: {ee0f27ce-5a85-11f1-9650-d85cd7107d86}\r\n           Volume name: Windows 2022\r\n           Volume label: Windows 2022\r\n\r\n           Device name: \\Device\\HarddiskVolumeShadowCopy3\r\n           Device GUID: {00000000-0000-0000-0000-000000000000}\r\n           Device manufacturer: \r\n           Device model: \r\n           Device revision: \r\n           Device serial number: \r\n           Bus type: <unknown>\r\n\r\n           Adapter serial number: \r\n           \r\n           Process Id: 4844\r\n           Process name: svchost.exe\r\n           \r\n           Reason: User request\r\n"
}

Event ID 304: The NTFS volume dismount failed.

#
Provider
Microsoft-Windows-Ntfs
Channel
Operational
Task
Volumedismount
Opcode
Stop

Description

The NTFS volume dismount failed.

Message #

The NTFS volume dismount failed.

           Error:%1

Fields #

NameDescription
VolumeCorrelationId GUID
VolumeIdLength UInt16
VolumeId UnicodeString
VolumeLabelLength UInt16
VolumeLabel UnicodeString
DeviceNameLength UInt16
DeviceName UnicodeString
DeviceGuid GUID
VendorIdLength UInt32
VendorId UnicodeString
ProductIdLength UInt32
ProductId UnicodeString
ProductRevisionLength UInt32
ProductRevision UnicodeString
DeviceSerialNumberLength UInt32
DeviceSerialNumber UnicodeString
BusType UInt32
NativeNVMe Boolean
AdapterSerialNumberLength UInt32
AdapterSerialNumber UnicodeString
Vcb Pointer
Error HexInt32Volume correlation Id.

Event ID 305: NTFS failed to mount the volume.

#
Provider
Microsoft-Windows-Ntfs
Channel
Operational
Task
Volumemount
Opcode
Stop

Description

NTFS failed to mount the volume.

Message #

NTFS failed to mount the volume.

           Error: %1
           Volume GUID: %2
           Volume Name: %4

Fields #

NameDescription
VolumeCorrelationId GUID
VolumeIdLength UInt16
VolumeId UnicodeString
VolumeLabelLength UInt16
VolumeLabel UnicodeString
DeviceNameLength UInt16
DeviceName UnicodeString
DeviceGuid GUID
VendorIdLength UInt32
VendorId UnicodeString
ProductIdLength UInt32
ProductId UnicodeString
ProductRevisionLength UInt32
ProductRevision UnicodeString
DeviceSerialNumberLength UInt32
DeviceSerialNumber UnicodeString
BusType UInt32
DeviceNumber UInt32
IsBootVolume Boolean
NativeNVMe Boolean
AdapterSerialNumberLength UInt32
AdapterSerialNumber UnicodeString
Error HexInt32Volume correlation Id.
RestartApplied Boolean
MountStageSourceTag HexInt64

Event ID 401: Efs offloading initiated.

#
Provider
Microsoft-Windows-Ntfs
Channel
Performance
Task
EfsTest

Description

Efs offloading initiated.

Message #

Efs offloading initiated.

                    Volume serial: %1
                    File reference: %2
                    File name: %4

Fields #

NameDescription
VolumeSerialNumber Int64
FileReference UInt64
FileNameLength UInt32
FileName UnicodeString

Event ID 402: Efs offloading read regular file.

#
Provider
Microsoft-Windows-Ntfs
Channel
Performance
Task
EfsTest

Description

Efs offloading read regular file.

Message #

Efs offloading read regular file.

                    Volume serial: %1
                    File reference: %2
                    File name: %4

Fields #

NameDescription
VolumeSerialNumber Int64
FileReference UInt64
FileNameLength UInt32
FileName UnicodeString

Event ID 403: Efs offloading write regular file.

#
Provider
Microsoft-Windows-Ntfs
Channel
Performance
Task
EfsTest

Description

Efs offloading write regular file.

Message #

Efs offloading write regular file.

                    Volume serial: %1
                    File reference: %2
                    File name: %4

Fields #

NameDescription
VolumeSerialNumber Int64
FileReference UInt64
FileNameLength UInt32
FileName UnicodeString

Event ID 404: Efs legacy initiated.

#
Provider
Microsoft-Windows-Ntfs
Channel
Performance
Also via
realtime ETW trace
Level
Informational
Task
EfsTest
Opcode
win:Info

Description

Efs legacy initiated.

Message #

Efs legacy initiated.

                    Volume serial: %1
                    File reference: %2
                    File name: %4

Fields #

NameDescription
VolumeSerialNumber Int64
FileReference UInt64
FileNameLength UInt32
FileName UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Ntfs",
    "guid": "{3FF37A1C-A68D-4D6E-8C9B-F79E8B16C482}",
    "event_source_name": "",
    "event_id": 404,
    "version": 0,
    "level": 4,
    "task": 10,
    "opcode": 0,
    "keywords": "0x1000000000800000",
    "time_created": "2026-06-02T05:29:47.644+00:00",
    "event_record_id": 0,
    "correlation": {},
    "execution": {
      "process_id": 952,
      "thread_id": 4780
    },
    "channel": "ETW Trace",
    "computer": "JD-DC01-2022",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "FileName": "",
    "FileNameLength": 0,
    "FileReference": 3096224743917653,
    "VolumeSerialNumber": -8062353066713383766
  },
  "message": "EfsTest"
}

Event ID 405: Efs legacy read regular file.

#
Provider
Microsoft-Windows-Ntfs
Channel
Performance
Task
EfsTest

Description

Efs legacy read regular file.

Message #

Efs legacy read regular file.

                    Volume serial: %1
                    File reference: %2
                    File name: %4

Fields #

NameDescription
VolumeSerialNumber Int64
FileReference UInt64
FileNameLength UInt32
FileName UnicodeString

Event ID 406: Efs legacy write regular file.

#
Provider
Microsoft-Windows-Ntfs
Channel
Performance
Task
EfsTest

Description

Efs legacy write regular file.

Message #

Efs legacy write regular file.

                    Volume serial: %1
                    File reference: %2
                    File name: %4

Fields #

NameDescription
VolumeSerialNumber Int64
FileReference UInt64
FileNameLength UInt32
FileName UnicodeString

Event ID 500: A process has created a USN journal on a volume.

#
Provider
Microsoft-Windows-Ntfs
Channel
Operational
Level
Informational
Opcode
Info

Description

A process has created a USN journal on a volume.

Message #

A process has created a USN journal on a volume.

           Process: %1
           Volume Id: %2
           Volume Name: %4
           Journal Id: %5
           Maximum Size: %6
           Allocation Delta: %7

Fields #

NameDescription
ProcessName AnsiStringProcess.
VolumeCorrelationId GUIDVolume Id.
VolumeNameLength UInt32
VolumeName UnicodeString
JournalId HexInt64
MaximumSize HexInt64
AllocationDelta HexInt64

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Ntfs",
    "guid": "3FF37A1C-A68D-4D6E-8C9B-F79E8B16C482",
    "event_source_name": "",
    "event_id": 500,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 4611686018429485056,
    "time_created": "2023-10-26T04:16:37.820075+00:00",
    "event_record_id": 7,
    "correlation": {},
    "execution": {
      "process_id": 428,
      "thread_id": 432
    },
    "channel": "Microsoft-Windows-Ntfs/Operational",
    "computer": "WIN-OQ6R0RVA4NF",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "ProcessName": "System",
    "VolumeCorrelationId": "7597D2A3-4404-4F99-B979-6233378A81BF",
    "VolumeNameLength": 2,
    "VolumeName": "C:",
    "JournalId": "0x1da07c336abde45",
    "MaximumSize": "0x2000000",
    "AllocationDelta": "0x800000"
  },
  "message": ""
}

References #

Event ID 501: A process has deleted a USN journal on a volume.

#
Provider
Microsoft-Windows-Ntfs
Channel
Operational
Level
Informational
Opcode
Info

Description

A process has deleted a USN journal on a volume.

Message #

A process has deleted a USN journal on a volume.

           Process: %1
           Volume Id: %2
           Volume Name: %4
           Journal Id: %5
           Current USN: %6

Fields #

NameDescription
ProcessName AnsiStringProcess.
VolumeCorrelationId GUIDVolume Id.
VolumeNameLength UInt32
VolumeName UnicodeString
JournalId HexInt64
CurrentUsn HexInt64

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Ntfs",
    "guid": "3FF37A1C-A68D-4D6E-8C9B-F79E8B16C482",
    "event_source_name": "",
    "event_id": 501,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 4611686018429485056,
    "time_created": "2023-11-06T06:25:51.720407+00:00",
    "event_record_id": 151,
    "correlation": {},
    "execution": {
      "process_id": 5004,
      "thread_id": 5064
    },
    "channel": "Microsoft-Windows-Ntfs/Operational",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "ProcessName": "SearchIndexer.",
    "VolumeCorrelationId": "7597D2A3-4404-4F99-B979-6233378A81BF",
    "VolumeNameLength": 2,
    "VolumeName": "C:",
    "JournalId": "0x1da07c336abde45",
    "CurrentUsn": "0x0"
  },
  "message": ""
}

References #

Event ID 502: File has been opened by an isolated reader.

#
Provider
Microsoft-Windows-Ntfs
Channel
Performance
Task
TxF

Description

File has been opened by an isolated reader.

Message #

File has been opened by an isolated reader.

Fields #

NameDescription
VolumeCorrelationId GUID
VolumeNameLength UInt32
VolumeName UnicodeString
FileReference UInt64
FileNameLength UInt32
FileName UnicodeString
KtmTransaction Pointer

Provenance

Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.

ETW provider GUID {3FF37A1C-A68D-4D6E-8C9B-F79E8B16C482}

Defined in ntfs.sys, the binary that emits these events.

Observed on:

  • WS2022-20348.4893, sample captured from a live trace, binary version 10.0.20348.3328, captured 2026-06-02
  • Win11-26200.6584, sample captured from a live trace, binary version 10.0.26100.1, captured 2026-06-02
  • WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.3328, captured 2026-06-02
  • Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.1, captured 2026-06-02

Downloads