Microsoft-Windows-NtfsLog_0b829c43cfd535d90d24f72b908ea742
505 events across 1 channel
Event ID 11: NtfsAllocateAttribute MaxAlloc for Mft's AttrList IC:.
#Fields #
| Name | Description |
|---|---|
NtfsAllocateAttribute_MaxAlloc_for_Mfts_AttrList_IC | NtfsAllocateAttribute MaxAlloc for Mft's AttrList IC. |
p_Scb |
Event ID 12: FileObject: .
#Fields #
| Name | Description |
|---|---|
FileObject | |
p_Scb | |
p_StaringVcn | |
I64x_ClusterCount | |
I64x_Flags | !I64x!, Flags. |
Event ID 13: NtfsAddAllocation IC:.
#Fields #
| Name | Description |
|---|---|
NtfsAddAllocation_IC | |
p_FileObject | |
p_Scb | |
p_StaringVcn | |
I64x_ClusterCount | |
I64x_Flags | !I64x!, Flags. |
Event ID 16: NtfsGetLastVcnForNewMappingPairSize IC:.
#Fields #
| Name | Description |
|---|---|
NtfsGetLastVcnForNewMappingPairSize_IC | |
p_Using_LastVcn |
Event ID 19: NtfsCreateNonresidentWithValue Create Mft's NonResident Attribute List IC:.
#Fields #
| Name | Description |
|---|---|
NtfsCreateNonresidentWithValue_Create_Mfts_NonResident_Attribute_List_IC | NtfsCreateNonresidentWithValue Create Mft's NonResident Attribute List IC. |
pValueLength |
Event ID 20: NtfsAddAttributeAllocation(.
#Fields #
| Name | Description |
|---|---|
param1 | |
param2 | |
param3 | |
param4 | |
param5 | |
param6 | |
param7 |
Event ID 21: NtfsAddAttributeAllocation(.
#Fields #
| Name | Description |
|---|---|
param1 | |
param2 | |
param3 | |
param4 | |
param5 | |
param6 | |
param7 |
Event ID 22: NtfsAddAttributeAllocation(.
#Fields #
| Name | Description |
|---|---|
param1 | |
param2 | |
param3 | |
param4 | |
param5 | |
param6 | |
param7 |
Event ID 23: NtfsAddAttributeAllocation(.
#Fields #
| Name | Description |
|---|---|
param1 | |
param2 | |
param3 | |
param4 | |
param5 | |
param6 | |
param7 | |
param8 |
Event ID 24: NtfsAddAttributeAllocation(.
#Fields #
| Name | Description |
|---|---|
param1 | |
param2 | |
param3 | |
param4 | |
param5 | |
param6 | |
param7 |
Event ID 30: MakeRoomForAttribute Moving Mft's attribute IC:.
#Fields #
| Name | Description |
|---|---|
MakeRoomForAttribute_Moving_Mfts_attribute_IC | MakeRoomForAttribute Moving Mft's attribute IC. |
Event ID 31: MoveAttributeToOwnRecord Moving Mft's $BITMAP IC:.
#Fields #
| Name | Description |
|---|---|
MoveAttributeToOwnRecord_Moving_Mfts_BITMAP_IC | MoveAttributeToOwnRecord Moving Mft's $BITMAP IC. |
p_SizeNeeded | |
x_TypeCode | |
x_RecLen | |
x_Form | |
x_Instance |
Event ID 32: MoveAttributeToOwnRecord IC:.
#Fields #
| Name | Description |
|---|---|
MoveAttributeToOwnRecord_IC | |
p_SizeNeeded | |
x_Bytes2Free | |
x_OldMappingSize | |
x_NewMappingSize |
Event ID 33: NtfsRestartZeroEndOfFileRecord FileRef:0x.
#Fields #
| Name | Description |
|---|---|
param1 | |
param2 | |
param3 | |
param4 | |
param5 |
Event ID 34: MergeFRS2(.
#Fields #
| Name | Description |
|---|---|
param1 | |
param2 | |
param3 | |
param4 | |
param5 | |
param6 | |
param7 | |
param8 | |
param9 | |
param10 | |
param11 |
Event ID 35: MergeFRS2(.
#Fields #
| Name | Description |
|---|---|
param1 | |
param2 | |
param3 | |
param4 | |
param5 | |
param6 | |
param7 | |
param8 | |
param9 | |
param10 | |
param11 |
Event ID 36: MergeFRS2(.
#Fields #
| Name | Description |
|---|---|
param1 | |
param2 | |
param3 | |
param4 | |
param5 | |
param6 | |
param7 | |
param8 | |
param9 | |
param10 | |
param11 |
Event ID 45: MergeFRS2(.
#Fields #
| Name | Description |
|---|---|
param1 | |
param2 | |
param3 | |
param4 | |
param5 | |
param6 | |
param7 | |
param8 | |
param9 | |
param10 | |
param11 | |
param12 | |
param13 | |
param14 | |
param15 |
Event ID 48: RedoAttribute(.
#Fields #
| Name | Description |
|---|---|
param1 | |
param2 | |
param3 | |
param4 | |
param5 | |
param6 | |
param7 | |
param8 | |
param9 | |
param10 |
Event ID 49: RedoAttribute(.
#Fields #
| Name | Description |
|---|---|
param1 | |
param2 | |
param3 | |
param4 | |
param5 | |
param6 | |
param7 | |
param8 | |
param9 | |
param10 | |
param11 | |
param12 |
Event ID 50: NtfsConsolidateAllFileRecords: Invalid Vcb.
#Fields #
| Name | Description |
|---|---|
NtfsConsolidateAllFileRecords_Invalid_Vcb_Thread | NtfsConsolidateAllFileRecords: Invalid Vcb. Thread. |
Event ID 51: NtfsConsolidateAllFileRecords: Volume is locked.
#Fields #
| Name | Description |
|---|---|
NtfsConsolidateAllFileRecords_Volume_is_locked_Thread | NtfsConsolidateAllFileRecords: Volume is locked. Thread. |
p_Vcb | |
p_VolumeName | |
S_VolumeLabel | |
S_Volume_Id |
Event ID 55: NtfsConsolidateAllFileRecords(.
#Fields #
| Name | Description |
|---|---|
param1 | |
param2 | |
param3 | |
param4 | |
param5 | |
param6 | |
param7 | |
param8 | |
param9 | |
param10 | |
param11 | |
param12 |
Event ID 56: NtfsConsolidateAllFileRecords(.
#Fields #
| Name | Description |
|---|---|
param1 | |
param2 | |
param3 | |
param4 | |
param5 | |
param6 | |
param7 | |
param8 | |
param9 | |
param10 |
Event ID 57: NtfsConsolidateAllFileRecords(.
#Fields #
| Name | Description |
|---|---|
param1 | |
param2 | |
param3 | |
param4 | |
param5 | |
param6 | |
param7 | |
param8 | |
param9 | |
param10 |
Event ID 64: NtfsConsolidateAllFileRecords(.
#Fields #
| Name | Description |
|---|---|
param1 | |
param2 | |
param3 | |
param4 | |
param5 | |
param6 | |
param7 |
Event ID 67: NtfsAllocateClustersPriv IC: .
#Fields #
| Name | Description |
|---|---|
NtfsAllocateClustersPriv_IC | |
p_Vcb | |
p_Scb | |
p_Mcb | |
S_DelayedAllocation | 6!I64x!, AllocateAll. |
Event ID 68: NtfsAllocateClustersPriv IC: .
#Fields #
| Name | Description |
|---|---|
NtfsAllocateClustersPriv_IC | |
p_Vcb | |
p_Scb | |
p_Mcb | |
S_DelayedAllocation | 6!I64x!, AllocateAll. |
Event ID 69: NtfsAllocateClustersPriv: Incremented TotalAllocated by 0x.
#Event ID 70: NtfsAllocateClustersPriv: Skipped incrementing TotalAllocated by 0x.
#Fields #
| Name | Description |
|---|---|
3I64xScbState | 1!I64x! clusters, Scb. |
Event ID 71: NtfsAllocateClustersPriv IC: .
#Fields #
| Name | Description |
|---|---|
NtfsAllocateClustersPriv_IC | |
p_ClustersAllocated |
Event ID 72: NtfsAllocateClustersPriv IC: .
#Fields #
| Name | Description |
|---|---|
NtfsAllocateClustersPriv_IC | |
p_ClustersAllocated |
Event ID 73: NtfsDeallocateClusters IC: .
#Fields #
| Name | Description |
|---|---|
NtfsDeallocateClusters_IC | |
p_Vcb | |
p_Scb | |
p_Mcb |
Event ID 75: NtfsDeallocateClusters IC: .
#Fields #
| Name | Description |
|---|---|
NtfsDeallocateClusters_IC | |
p_Vcb | |
p_Scb | |
p_Mcb |
Event ID 78: NtfsDeallocateClusters: Vcb .
#Fields #
| Name | Description |
|---|---|
p__Lsn | |
I64x_ClusterCount | |
I64x_Flags | |
I64x_new | !08x!; Vcb's DeallocatedClustersCount old. |
Event ID 79: NtfsDeallocateClusters: Decremented TotalAllocated by 0x.
#Fields #
| Name | Description |
|---|---|
3I64xAddrTotalAllocated | 1!I64x! clusters, Scb. |
Event ID 80: NtfsDeallocateClusters: Skipped decrementing TotalAllocated by 0x.
#Fields #
| Name | Description |
|---|---|
pAddrTotalAllocated | 1!I64x! clusters, Scb. |
p_ScbState |
Event ID 82: NtfsDeallocateClusters IC: .
#Fields #
| Name | Description |
|---|---|
NtfsDeallocateClusters_IC | |
p_ClustersDeallocated |
Event ID 83: NtfsDeallocateClusters IC: .
#Fields #
| Name | Description |
|---|---|
NtfsDeallocateClusters_IC | |
p_ClustersDeallocated |
Event ID 88: NtfsRestartSetBitsInBitMap IC: .
#Fields #
| Name | Description |
|---|---|
NtfsRestartSetBitsInBitMap_IC | |
p_Bitmap |
Event ID 91: NtfsRestartClearBitsInBitMap IC: .
#Fields #
| Name | Description |
|---|---|
NtfsRestartClearBitsInBitMap_IC | |
p_Bitmap |
Event ID 92: NtfsSetOrClearBitsUsingBaseMcb IC: .
#Fields #
| Name | Description |
|---|---|
NtfsSetOrClearBitsUsingBaseMcb_IC | |
p_Vcb | |
p_Bitmap |
Event ID 93: NtfsSetOrClearBitsUsingBaseMcb IC: .
#Fields #
| Name | Description |
|---|---|
NtfsSetOrClearBitsUsingBaseMcb_IC | |
p_Bitmap |
Event ID 94: NtfsSetOrClearBitsUsingBaseMcb IC: .
#Fields #
| Name | Description |
|---|---|
NtfsSetOrClearBitsUsingBaseMcb_IC | |
p_Result |
Event ID 95: System files not marked as in use in the MFT bitmap.
#Fields #
| Name | Description |
|---|---|
param1 | |
param2 |
Event ID 96: Length: 0 --> BinIndex : 0 - Unexpected length
#Event ID 103: Searched committed allocations but didnt find enough free space.
#Fields #
| Name | Description |
|---|---|
param1 | |
param2 | |
param3 | |
param4 | |
param5 |
Event ID 109: NtfsValidateTotalClustersCommitted(.
#Fields #
| Name | Description |
|---|---|
param1 | |
param2 | |
param3 | |
param4 | |
param5 |
Event ID 111: Entering: Scb: .
#Fields #
| Name | Description |
|---|---|
Entering_Scb | Entering: Scb. |
p_ExtentsDescriptorIndex |
Event ID 113: Offset is beyond this extent skipping the extent.
#Event ID 116: Exiting: ExtentsDescriptorIndex: .
#Fields #
| Name | Description |
|---|---|
Exiting_ExtentsDescriptorIndex | Exiting: ExtentsDescriptorIndex. |
Event ID 119: RemainingClusterCount: 0x.
#Event ID 120: Dsm: TotalNumberOfRanges: .
#Fields #
| Name | Description |
|---|---|
Dsm_TotalNumberOfRanges | Dsm: TotalNumberOfRanges. |
d_NumberOfRangesReturned |
Event ID 123: Updating ExtentsDescriptor Index and StartOffset from Locals: ExtentsDescriptorIndex: .
#Fields #
| Name | Description |
|---|---|
Updating_ExtentsDescriptor_Index_and_StartOffset_from_Locals_ExtentsDescriptorIndex | Updating ExtentsDescriptor Index and StartOffset from Locals: ExtentsDescriptorIndex. |
Event ID 124: Entering: Scb: .
#Fields #
| Name | Description |
|---|---|
Entering_Scb | Entering: Scb. |
p_ExtentsDescriptorIndex |
Event ID 125: Updating ExtentsDescriptor Index and StartOffset from Locals: ExtentsDescriptorIndex: .
#Fields #
| Name | Description |
|---|---|
Updating_ExtentsDescriptor_Index_and_StartOffset_from_Locals_ExtentsDescriptorIndex | Updating ExtentsDescriptor Index and StartOffset from Locals: ExtentsDescriptorIndex. |
Event ID 129: Raising STATUS_SUCCESS from NtfsCommonCleanup: .
#Fields #
| Name | Description |
|---|---|
Raising_STATUSSUCCESS_from_NtfsCommonCleanup | Raising STATUS_SUCCESS from NtfsCommonCleanup. |
Event ID 132: Irp: .
#Fields #
| Name | Description |
|---|---|
Irp | |
p_IC | |
p_Vcb | |
p_FileObject | |
p_RelatedFileObject | |
p_FileIdBuffer |
Event ID 134: NtfsCommonCreate: Volume is locked.
#Fields #
| Name | Description |
|---|---|
NtfsCommonCreate_Volume_is_locked_Thread | NtfsCommonCreate: Volume is locked. Thread. |
p_Vcb | |
p_VolumeName | |
S_VolumeLabel | |
S_Vcb_State |
Event ID 135: NtfsCommonVolumeOpen: Invalid create disposition for volume open.
#Fields #
| Name | Description |
|---|---|
NtfsCommonVolumeOpen_Invalid_create_disposition_for_volume_open_Thread | NtfsCommonVolumeOpen: Invalid create disposition for volume open. Thread. |
Event ID 136: NtfsCommonVolumeOpen: Volume is locked or we have performed a dismount.
#Fields #
| Name | Description |
|---|---|
NtfsCommonVolumeOpen_Volume_is_locked_or_we_have_performed_a_dismount_Thread | NtfsCommonVolumeOpen: Volume is locked or we have performed a dismount. Thread. |
p_Vcb | |
p_VolumeName | |
S_VolumeLabel |
Event ID 137: NtfsCommonVolumeOpen: Thread: .
#Fields #
| Name | Description |
|---|---|
NtfsCommonVolumeOpen_Thread | NtfsCommonVolumeOpen: Thread. |
p_Vcb | |
p_VolumeName | |
S_VolumeLabel | |
d_BiasedCleanupCount |
Event ID 138: NtfsCommonVolumeOpen: Volume is locked or we have performed a dismount.
#Fields #
| Name | Description |
|---|---|
NtfsCommonVolumeOpen_Volume_is_locked_or_we_have_performed_a_dismountThread | NtfsCommonVolumeOpen: Volume is locked or we have performed a dismount.Thread. |
p_Vcb | |
p_VolumeName | |
S_VolumeLabel |
Event ID 139: NtfsCommonVolumeOpen: Conlicting file objects.
#Fields #
| Name | Description |
|---|---|
NtfsCommonVolumeOpen_Conlicting_file_objects_Thread | NtfsCommonVolumeOpen: Conlicting file objects. Thread. |
p_Vcb | |
p_VolumeName | |
S_VolumeLabel | |
d_VcbCloseCount | |
d_VcbSystemFileCloseCount |
Event ID 140: NtfsHandlePagingFile: Paging file already open, paging files can only be opened once.
#Fields #
| Name | Description |
|---|---|
NtfsHandlePagingFile_Paging_file_already_open_paging_files_can_only_be_opened_once_Thread | NtfsHandlePagingFile: Paging file already open, paging files can only be opened once. Thread. |
p_Vcb | |
p_VolumeName | |
S_VolumeLabel | |
S_Fcb |
Event ID 141: NtfsHandlePagingFile: Cannot open system file as paging file.
#Fields #
| Name | Description |
|---|---|
NtfsHandlePagingFile_Cannot_open_system_file_as_paging_file_Thread | NtfsHandlePagingFile: Cannot open system file as paging file. Thread. |
p_Vcb | |
p_VolumeName | |
S_VolumeLabel | |
S_Fcb |
Event ID 142: NtfsHandlePagingFile: Persisted paging file already exists.
#Fields #
| Name | Description |
|---|---|
NtfsHandlePagingFile_Persisted_paging_file_already_exists_Thread | NtfsHandlePagingFile: Persisted paging file already exists. Thread. |
p_Vcb | |
p_VolumeName | |
S_VolumeLabel | |
S_Fcb |
Event ID 143: NtfsOpenFcbById: Invalid system file access.
#Fields #
| Name | Description |
|---|---|
NtfsOpenFcbById_Invalid_system_file_access_Thread | NtfsOpenFcbById: Invalid system file access. Thread. |
p_Vcb | |
p_VolumeName | |
S_VolumeLabel | |
S_Fcb |
Event ID 144: NtfsOpenExistingPrefixFcb: Can not directly open txf directory.
#Fields #
| Name | Description |
|---|---|
NtfsOpenExistingPrefixFcb_Can_not_directly_open_txf_directory_Thread | NtfsOpenExistingPrefixFcb: Can not directly open txf directory. Thread. |
p_Vcb | |
p_VolumeName | |
S_VolumeLabel | |
S_Fcb |
Event ID 145: NtfsOpenExistingPrefixFcb: Invalid system file access.
#Fields #
| Name | Description |
|---|---|
NtfsOpenExistingPrefixFcb_Invalid_system_file_access_Thread | NtfsOpenExistingPrefixFcb: Invalid system file access. Thread. |
p_Vcb | |
p_VolumeName | |
S_VolumeLabel | |
S_Fcb |
Event ID 146: NtfsOpenFile: Unsafe to acquire parent directory after acquiring a txf-system file.
#Fields #
| Name | Description |
|---|---|
NtfsOpenFile_Unsafe_to_acquire_parent_directory_after_acquiring_a_txfsystem_file_Thread | NtfsOpenFile: Unsafe to acquire parent directory after acquiring a txf-system file. Thread. |
p_Vcb | |
p_VolumeName | |
S_VolumeLabel | |
S_Fcb |
Event ID 147: NtfsOpenFile: Invalid system file access.
#Fields #
| Name | Description |
|---|---|
NtfsOpenFile_Invalid_system_file_access_Thread | NtfsOpenFile: Invalid system file access. Thread. |
p_Vcb | |
p_VolumeName | |
S_VolumeLabel | |
S_Fcb |
Event ID 148: NtfsOpenFile: Deny open when txf rm is active.
#Fields #
| Name | Description |
|---|---|
NtfsOpenFile_Deny_open_when_txf_rm_is_active_Thread | NtfsOpenFile: Deny open when txf rm is active. Thread. |
p_Vcb | |
p_VolumeName | |
S_VolumeLabel | |
S_Fcb |
Event ID 149: NtfsCreateNewFile: Deny creation in system directory (except root).
#Fields #
| Name | Description |
|---|---|
NtfsCreateNewFile_Deny_creation_in_system_directory_except_root_Thread | NtfsCreateNewFile: Deny creation in system directory (except root). Thread. |
p_Vcb | |
p_VolumeName | |
S_VolumeLabel | |
S_Parent_Fcb_Fcb |
Event ID 150: NtfsCreateNewFile: Unable to create Ea for the file.
#Fields #
| Name | Description |
|---|---|
NtfsCreateNewFile_Unable_to_create_Ea_for_the_file_Thread | NtfsCreateNewFile: Unable to create Ea for the file. Thread. |
p_Vcb | |
p_VolumeName | |
S_VolumeLabel | |
S_Fcb |
Event ID 151: NtfsCreateNewFile: Unable to create in the $txf directory.
#Fields #
| Name | Description |
|---|---|
NtfsCreateNewFile_Unable_to_create_in_the_txf_directory_Thread | NtfsCreateNewFile: Unable to create in the $txf directory. Thread. |
p_Vcb | |
p_VolumeName | |
S_VolumeLabel | |
S_Parent_Fcb_Fcb |
Event ID 152: NtfsOpenSubdirectory: Denying access to $Txf file when the RM is active.
#Fields #
| Name | Description |
|---|---|
NtfsOpenSubdirectory_Denying_access_to_Txf_file_when_the_RM_is_active_Thread | NtfsOpenSubdirectory: Denying access to $Txf file when the RM is active. Thread. |
p_Vcb | |
p_VolumeName | |
S_VolumeLabel | |
S_Fcb |
Event ID 153: NtfsOpenAttributeInExistingFile: Denying access due to caller being Ea blind.
#Fields #
| Name | Description |
|---|---|
NtfsOpenAttributeInExistingFile_Denying_access_due_to_caller_being_Ea_blind_Thread | NtfsOpenAttributeInExistingFile: Denying access due to caller being Ea blind. Thread. |
p_Vcb | |
p_VolumeName | |
S_VolumeLabel | |
S_Fcb |
Event ID 154: NtfsOpenAttributeInExistingFile: Fail to find $INDEX_ROOT attribute.
#Fields #
| Name | Description |
|---|---|
NtfsOpenAttributeInExistingFile_Fail_to_find_INDEXROOT_attribute_Thread | NtfsOpenAttributeInExistingFile: Fail to find $INDEX_ROOT attribute. Thread. |
p_Vcb | |
p_VolumeName | |
S_VolumeLabel | |
S_Fcb |
Event ID 155: NtfsOpenAttributeInExistingFile: Denying access for volume root directory.
#Fields #
| Name | Description |
|---|---|
NtfsOpenAttributeInExistingFile_Denying_access_for_volume_root_directory_Thread | NtfsOpenAttributeInExistingFile: Denying access for volume root directory. Thread. |
p_Vcb | |
p_VolumeName | |
S_VolumeLabel | |
S_Fcb |
Event ID 156: NtfsCreateNewFile: Not allowed to create streams on system files.
#Fields #
| Name | Description |
|---|---|
NtfsCreateNewFile_Not_allowed_to_create_streams_on_system_files_Thread | NtfsCreateNewFile: Not allowed to create streams on system files. Thread. |
p_Vcb | |
p_VolumeName | |
S_VolumeLabel | |
S_Fcb |
Event ID 157: NtfsOverwriteAttr: Cannot overwrite hidden or system attribute for a non-paging file.
#Fields #
| Name | Description |
|---|---|
p_Vcb | |
p_VolumeName | |
S_VolumeLabel | |
S_Fcb |
Event ID 158: NtfsOverwriteAttr: Denying access due to user being Ea blind.
#Fields #
| Name | Description |
|---|---|
NtfsOverwriteAttr_Denying_access_due_to_user_being_Ea_blind_Thread | NtfsOverwriteAttr: Denying access due to user being Ea blind. Thread. |
p_Vcb | |
p_VolumeName | |
S_VolumeLabel | |
S_Fcb | |
p_FileRef |
Event ID 159: NtfsOverwriteAttr: Deny access due to encryption happening on the stream.
#Fields #
| Name | Description |
|---|---|
NtfsOverwriteAttr_Deny_access_due_to_encryption_happening_on_the_stream_Thread | NtfsOverwriteAttr: Deny access due to encryption happening on the stream. Thread. |
p_Vcb | |
p_VolumeName | |
S_VolumeLabel | |
S_Fcb |
Event ID 160: NtfsCheckValidAttributeAccess: Supersede or overwrite is not allowed on this type of named attribute.
#Fields #
| Name | Description |
|---|---|
NtfsCheckValidAttributeAccess_Supersede_or_overwrite_is_not_allowed_on_this_type_of_named_attribute_Thread | NtfsCheckValidAttributeAccess: Supersede or overwrite is not allowed on this type of named attribute. Thread. |
p_Vcb | |
p_VolumeName | |
S_VolumeLabel |
Event ID 161: NtfsCheckValidAttributeAccess: Only read attributes access is supported on this attribute.
#Fields #
| Name | Description |
|---|---|
NtfsCheckValidAttributeAccess_Only_read_attributes_access_is_supported_on_this_attribute_Thread | NtfsCheckValidAttributeAccess: Only read attributes access is supported on this attribute. Thread. |
p_Vcb | |
p_VolumeName | |
S_VolumeLabel |
Event ID 162: NtfsCheckValidAttributeAccess: Deny access for protected system attributes.
#Fields #
| Name | Description |
|---|---|
NtfsCheckValidAttributeAccess_Deny_access_for_protected_system_attributes_Thread | NtfsCheckValidAttributeAccess: Deny access for protected system attributes. Thread. |
p_AttributeTypeCode |
Event ID 163: NtfsOpenAttributeCheck: File already has user writable references.
#Fields #
| Name | Description |
|---|---|
NtfsOpenAttributeCheck_File_already_has_user_writable_references_Thread | NtfsOpenAttributeCheck: File already has user writable references. Thread. |
p_Vcb | |
p_VolumeName | |
S_VolumeLabel | |
S_Fcb |
Event ID 164: NtfsOpenAttributeCheck: Deny access for online encryption backup data stream.
#Fields #
| Name | Description |
|---|---|
NtfsOpenAttributeCheck_Deny_access_for_online_encryption_backup_data_stream_Thread | NtfsOpenAttributeCheck: Deny access for online encryption backup data stream. Thread. |
p_Vcb | |
p_VolumeName | |
S_VolumeLabel | |
S_Fcb |
Event ID 165: NtfsOpenAttributeCheck: File was granted write access but has image section.
#Fields #
| Name | Description |
|---|---|
NtfsOpenAttributeCheck_File_was_granted_write_access_but_has_image_section_Thread | NtfsOpenAttributeCheck: File was granted write access but has image section. Thread. |
p_Vcb | |
p_VolumeName | |
S_VolumeLabel | |
S_Fcb |
Event ID 166: NtfsOpenAttribute: Denying write access on disallowed writes.
#Fields #
| Name | Description |
|---|---|
NtfsOpenAttribute_Denying_write_access_on_disallowed_writes_Thread | NtfsOpenAttribute: Denying write access on disallowed writes. Thread. |
p_Vcb | |
p_VolumeName | |
S_VolumeLabel | |
S_Fcb | |
p_Disallow_write_count | 6!I64x!, Scb. |
Event ID 167: NtfsOpenAttribute: File already has user writable references.
#Fields #
| Name | Description |
|---|---|
NtfsOpenAttribute_File_already_has_user_writable_references_Thread | NtfsOpenAttribute: File already has user writable references. Thread. |
p_Vcb | |
p_VolumeName | |
S_VolumeLabel | |
S_Fcb |
Event ID 168: NtfsOpenAttribute: Open for exclusive read access is not allowed.
#Fields #
| Name | Description |
|---|---|
NtfsOpenAttribute_Open_for_exclusive_read_access_is_not_allowed_Thread | NtfsOpenAttribute: Open for exclusive read access is not allowed. Thread. |
p_Vcb | |
p_VolumeName | |
S_VolumeLabel | |
S_Fcb |
Event ID 169: NtfsOpenAttribute: File already has user writable references.
#Fields #
| Name | Description |
|---|---|
NtfsOpenAttribute_File_already_has_user_writable_references_Thread | NtfsOpenAttribute: File already has user writable references. Thread. |
p_Vcb | |
p_VolumeName | |
S_VolumeLabel | |
S_Fcb |
Event ID 170: NtfsOpenAttribute: Open for exclusive read access is not allowed.
#Fields #
| Name | Description |
|---|---|
NtfsOpenAttribute_Open_for_exclusive_read_access_is_not_allowed_Thread | NtfsOpenAttribute: Open for exclusive read access is not allowed. Thread. |
p_Vcb | |
p_VolumeName | |
S_VolumeLabel | |
S_Fcb |
Event ID 171: NtfsCheckExistingFile: Desired access conflicts with read-only state.
#Fields #
| Name | Description |
|---|---|
NtfsCheckExistingFile_Desired_access_conflicts_with_readonly_state_Thread | NtfsCheckExistingFile: Desired access conflicts with read-only state. Thread. |
p_Vcb | |
p_VolumeName | |
S_VolumeLabel | |
S_Fcb |
Event ID 172: NtfsOpenExistingEncryptedStream: No encryption driver found.
#Fields #
| Name | Description |
|---|---|
NtfsOpenExistingEncryptedStream_No_encryption_driver_found_Thread | NtfsOpenExistingEncryptedStream: No encryption driver found. Thread. |
p_Vcb | |
p_VolumeName | |
S_VolumeLabel | |
S_Fcb |
Event ID 173: NtfsOpenExistingEncryptedStream: Opening for read/write access not allowed on compressed file.
#Fields #
| Name | Description |
|---|---|
NtfsOpenExistingEncryptedStream_Opening_for_readwrite_access_not_allowed_on_compressed_file_Thread | NtfsOpenExistingEncryptedStream: Opening for read/write access not allowed on compressed file. Thread. |
p_Vcb | |
p_VolumeName | |
S_VolumeLabel | |
S_Fcb |
Event ID 174: NtfsEncryptionCreateCallback: Encrytion engine fail to encrypt all streams for file with open handle.
#Fields #
| Name | Description |
|---|---|
NtfsEncryptionCreateCallback_Encrytion_engine_fail_to_encrypt_all_streams_for_file_with_open_handle_Thread | NtfsEncryptionCreateCallback: Encrytion engine fail to encrypt all streams for file with open handle. Thread. |
p_Vcb | |
p_VolumeName | |
S_VolumeLabel | |
S_Fcb |
Event ID 175: NtfsFindStartingNode: Opening not allowed for txf name when RM is active.
#Fields #
| Name | Description |
|---|---|
NtfsFindStartingNode_Opening_not_allowed_for_txf_name_when_RM_is_active_Thread | NtfsFindStartingNode: Opening not allowed for txf name when RM is active. Thread. |
p_Fcb |
Event ID 176: NtfsCheckShareAccess: IoCheckLinkShareAccess failed with sharing violation.
#Fields #
| Name | Description |
|---|---|
NtfsCheckShareAccess_IoCheckLinkShareAccess_failed_with_sharing_violation_Thread | NtfsCheckShareAccess: IoCheckLinkShareAccess failed with sharing violation. Thread. |
p_Vcb | |
p_VolumeName | |
S_VolumeLabel | |
S_Fcb | |
d_LinkShareAccessDeleters | |
d_LinkShareAccessSharedDelete |
Event ID 177: NtfsCheckShareAccess: IoCheckLinkShareAccess failed with sharing violation.
#Fields #
| Name | Description |
|---|---|
NtfsCheckShareAccess_IoCheckLinkShareAccess_failed_with_sharing_violation_Thread | NtfsCheckShareAccess: IoCheckLinkShareAccess failed with sharing violation. Thread. |
p_Vcb | |
p_VolumeName | |
S_VolumeLabel | |
S_Fcb | |
d_ShareAccessReaders | |
d_ShareAccessWriters | |
d_ShareAccessDeleters | |
d_ShareAccessSharedRead | |
d_ShareAccessSharedWrite | |
d_ShareAccessSharedDelete |
Event ID 178: NtfsCheckShareAccess: IoCheckLinkShareAccess failed with sharing violation.
#Fields #
| Name | Description |
|---|---|
NtfsCheckShareAccess_IoCheckLinkShareAccess_failed_with_sharing_violation_Thread | NtfsCheckShareAccess: IoCheckLinkShareAccess failed with sharing violation. Thread. |
p_Vcb | |
p_VolumeName | |
S_VolumeLabel | |
S_Fcb | |
S_Link_Name | |
d_ShareAccessReaders | |
d_ShareAccessWriters | |
d_ShareAccessDeleters | |
d_ShareAccessSharedRead | |
d_ShareAccessSharedWrite | |
d_ShareAccessSharedDelete | |
d_LinkShareAccessOpenCount | |
d_LinkShareAccessDeleters | |
d_LinkShareAccessSharedDelete |
Event ID 179: NtfsReCheckShareAccess: Does not meet allow open requirement.
#Fields #
| Name | Description |
|---|---|
NtfsReCheckShareAccess_Does_not_meet_allow_open_requirement_Thread | NtfsReCheckShareAccess: Does not meet allow open requirement. Thread. |
p_Vcb | |
p_VolumeName | |
S_VolumeLabel | |
S_Fcb | |
S_Link_Name | |
d_Readers | |
d_Writers | |
d_Deleters | |
d_SharedRead | |
d_Lcb_Deleters |
Event ID 180: ...:...!d! Status: ...!S! ProcessName: ...!S!
#Fields #
| Name | Description |
|---|---|
1 | |
d_Status | |
S_ProcessName |
Event ID 181: ...:...!d! Status: ...!S! ProcessName: ...!S!
#Fields #
| Name | Description |
|---|---|
1 | |
d_Status | |
S_ProcessName |
Event ID 182: ...:...!d! Status: ...!S! ProcessName: ...!S!
#Fields #
| Name | Description |
|---|---|
1 | |
d_Status | |
S_ProcessName |
Event ID 183: ...:...!d! Status: ...!S! ProcessName: ...!S!
#Fields #
| Name | Description |
|---|---|
1 | |
d_Status | |
S_ProcessName |
Event ID 191: NtfsTransferMaxDataSetRanges: Src .
#Fields #
| Name | Description |
|---|---|
param1 | |
param2 | |
param3 | |
param4 | |
param5 |
Event ID 192: NtfsTransferMaxDataSetRanges: Src .
#Fields #
| Name | Description |
|---|---|
param1 | |
param2 | |
param3 | |
param4 | |
param5 | |
param6 | |
param7 |
Event ID 193: NtfsMarkUnusedContextPostTrimProcessing: Entering
#Event ID 194: NtfsMarkUnusedContextPostTrimProcessing: Vcb .
#Fields #
| Name | Description |
|---|---|
param1 | |
param2 | |
param3 | |
param4 | |
param5 | |
param6 | |
param7 |
Event ID 195: NtfsMarkUnusedContextPostTrimProcessing: Vcb .
#Fields #
| Name | Description |
|---|---|
param1 | |
param2 | |
param3 | |
param4 | |
param5 | |
param6 | |
param7 | |
param8 |
Event ID 198: NtfsMarkUnusedContextPostTrimProcessing: Leaving
#Event ID 203: NtfsMarkUnusedContextPreTrimWorkItemProcessing: Entering Vcb .
#Fields #
| Name | Description |
|---|---|
param1 |
Event ID 204: NtfsMarkUnusedContextPreTrimWorkItemProcessing: Vcb .
#Fields #
| Name | Description |
|---|---|
param1 | |
param2 | |
param3 |
Event ID 205: NtfsMarkUnusedContextPreTrimWorkItemProcessing: Vcb .
#Fields #
| Name | Description |
|---|---|
param1 | |
param2 |
Event ID 206: NtfsMarkUnusedContextPreTrimWorkItemProcessing: Vcb .
#Fields #
| Name | Description |
|---|---|
param1 | |
param2 |
Event ID 207: NtfsMarkUnusedContextPreTrimWorkItemProcessing: Vcb .
#Fields #
| Name | Description |
|---|---|
param1 | |
param2 | |
param3 | |
param4 | |
param5 |
Event ID 208: NtfsMarkUnusedContextPreTrimWorkItemProcessing: Vcb .
#Fields #
| Name | Description |
|---|---|
param1 | |
param2 | |
param3 |
Event ID 209: NtfsMarkUnusedContextPreTrimWorkItemProcessing: Vcb .
#Fields #
| Name | Description |
|---|---|
param1 | |
param2 | |
param3 |
Event ID 210: NtfsMarkUnusedContextPreTrimWorkItemProcessing: Vcb .
#Fields #
| Name | Description |
|---|---|
param1 | |
param2 |
Event ID 211: NtfsMarkUnusedContextPreTrimWorkItemProcessing: Vcb .
#Fields #
| Name | Description |
|---|---|
param1 | |
param2 |
Event ID 212: NtfsMarkUnusedContextPreTrimWorkItemProcessing: Vcb .
#Fields #
| Name | Description |
|---|---|
param1 | |
param2 | |
param3 | |
param4 |
Event ID 213: NtfsMarkUnusedContextPreTrimWorkItemProcessing: Leaving
#Event ID 222: NtfsPrepareToWaitForDeallocatedClustersToDrain: Vcb .
#Fields #
| Name | Description |
|---|---|
param1 | |
param2 |
Event ID 224: NtfsWaitForDeallocatedClustersToDrainAfterPrepare: Vcb .
#Fields #
| Name | Description |
|---|---|
param1 | |
param2 |
Event ID 225: NtfsWaitForDeallocatedClustersToDrainAfterPrepare: Waited for .
#Fields #
| Name | Description |
|---|---|
param1 | |
param2 | |
param3 | |
param4 | |
param5 |
Event ID 226: NtfsWaitForDeallocatedClustersToDrainAfterPrepare: Waited for .
#Fields #
| Name | Description |
|---|---|
param1 | |
param2 | |
param3 | |
param4 | |
param5 |
Event ID 246: NtfsCommonDeviceControl: IOCTL_DISK_COPY_DATA is not allowed on unlocked volume.
#Fields #
| Name | Description |
|---|---|
NtfsCommonDeviceControl_IOCTLDISKCOPYDATA_is_not_allowed_on_unlocked_volume_Thread | NtfsCommonDeviceControl: IOCTL_DISK_COPY_DATA is not allowed on unlocked volume. Thread. |
p_Vcb | |
p_VolumeName | |
S_VolumeLabel |
Event ID 247: NtfsVolumeDasdIo: Data section blocking flush.
#Fields #
| Name | Description |
|---|---|
NtfsVolumeDasdIo_Data_section_blocking_flush_Thread | NtfsVolumeDasdIo: Data section blocking flush. Thread. |
p_Vcb | |
p_VolumeName | |
S_VolumeLabel | |
S_Flush_status |
Event ID 248: Could not find paging file run.
#Event ID 249: Could not find paging file MCB entry.
#Event ID 250: Could not find paging file run.
#Event ID 251: Writing to $Bitmap.
#Fields #
| Name | Description |
|---|---|
Writing_to_Bitmap_Vcb | Writing to $Bitmap. Vcb. |
Event ID 252: NTFS: Posting hotfix on file object: .
#Fields #
| Name | Description |
|---|---|
NTFS_Posting_hotfix_on_file_object | NTFS: Posting hotfix on file object. |
Event ID 253: NTFS: Freeing Bad Vcn: .
#Fields #
| Name | Description |
|---|---|
NTFS_____Freeing_Bad_Vcn | NTFS: Freeing Bad Vcn. |
Event ID 254: NTFS: Retiring Bad Lcn: .
#Fields #
| Name | Description |
|---|---|
NTFS_____Retiring_Bad_Lcn | NTFS: Retiring Bad Lcn. |
Event ID 255: NTFS: Reallocating Bad Vcn
#Event ID 256: NTFS: Bad Cluster replaced
#Event ID 263: NtfsDefragFileInternal: Defrag is denied.
#Fields #
| Name | Description |
|---|---|
NtfsDefragFileInternal_Defrag_is_denied_Thread | NtfsDefragFileInternal: Defrag is denied. Thread. |
p_Vcb | |
p_VolumeName | |
S_VolumeLabel | |
S_Fcb |
Event ID 266: NtfsDefragFileInternal: Defrag is denied.
#Fields #
| Name | Description |
|---|---|
NtfsDefragFileInternal_Defrag_is_denied_Thread | NtfsDefragFileInternal: Defrag is denied. Thread. |
p_Vcb | |
p_VolumeName | |
S_VolumeLabel | |
S_Fcb |
Event ID 267: NtfsDefragFileInternal(.
#Fields #
| Name | Description |
|---|---|
param1 | |
param2 | |
param3 | |
param4 | |
param5 | |
param6 | |
param7 | |
param8 | |
param9 | |
param10 | |
param11 |
Event ID 268: NtfsDefragFileInternal(.
#Fields #
| Name | Description |
|---|---|
param1 | |
param2 | |
param3 | |
param4 | |
param5 | |
param6 | |
param7 | |
param8 | |
param9 | |
param10 | |
param11 |
Event ID 269: NtfsDefragFileInternal(.
#Fields #
| Name | Description |
|---|---|
param1 | |
param2 | |
param3 | |
param4 | |
param5 | |
param6 | |
param7 |
Event ID 270: NtfsDefragFileInternal(.
#Fields #
| Name | Description |
|---|---|
param1 | |
param2 | |
param3 | |
param4 | |
param5 | |
param6 | |
param7 |
Event ID 271: NtfsDefragFileInternal(.
#Fields #
| Name | Description |
|---|---|
param1 | |
param2 | |
param3 | |
param4 | |
param5 | |
param6 | |
param7 | |
param8 | |
param9 | |
param10 |
Event ID 273: NtfsDefragFile: Defrag is denied without manage volume access.
#Fields #
| Name | Description |
|---|---|
NtfsDefragFile_Defrag_is_denied_without_manage_volume_access_Thread | NtfsDefragFile: Defrag is denied without manage volume access. Thread. |
p_Vcb | |
p_VolumeName | |
S_VolumeLabel | |
S_Fcb |
Event ID 274: NtfsEncryptDecryptOnline: Defrag is denied.
#Fields #
| Name | Description |
|---|---|
NtfsEncryptDecryptOnline_Defrag_is_denied_Thread | NtfsEncryptDecryptOnline: Defrag is denied. Thread. |
p_Vcb | |
p_VolumeName | |
S_VolumeLabel | |
S_Fcb |
Event ID 277: NtfsEncryptDecryptOnline: Defrag is denied.
#Fields #
| Name | Description |
|---|---|
NtfsEncryptDecryptOnline_Defrag_is_denied_Thread | NtfsEncryptDecryptOnline: Defrag is denied. Thread. |
p_Vcb | |
p_VolumeName | |
S_VolumeLabel | |
S_Fcb |
Event ID 280: NumberOfValidRuns: 0
#Event ID 281: RemainingClusterCount: 0x.
#Event ID 289: NtfsCommonQueryInformation: File information query not allowed as file was opened by ID without traversal privilege.
#Fields #
| Name | Description |
|---|---|
NtfsCommonQueryInformation_File_information_query_not_allowed_as_file_was_opened_by_ID_without_traversal_privilege_Thread | NtfsCommonQueryInformation: File information query not allowed as file was opened by ID without traversal privilege. Thread. |
p_Vcb | |
p_VolumeName | |
S_VolumeLabel | |
S_Fcb |
Event ID 290: NtfsQueryCaseSensitiveInfo: Case sensitive info query not allowed without read attributes access.
#Fields #
| Name | Description |
|---|---|
NtfsQueryCaseSensitiveInfo_Case_sensitive_info_query_not_allowed_without_read_attributes_access_Thread | NtfsQueryCaseSensitiveInfo: Case sensitive info query not allowed without read attributes access. Thread. |
p_Vcb | |
p_VolumeName | |
S_VolumeLabel | |
S_Fcb |
Event ID 291: NtfsQueryNameInfo: Name info query not allowed as file was opened without traverse privilege.
#Fields #
| Name | Description |
|---|---|
NtfsQueryNameInfo_Name_info_query_not_allowed_as_file_was_opened_without_traverse_privilege_Thread | NtfsQueryNameInfo: Name info query not allowed as file was opened without traverse privilege. Thread. |
p_Vcb | |
p_VolumeName | |
S_VolumeLabel | |
S_Fcb |
Event ID 292: NtfsQueryLinksInfo: Link info query not allowed as file was opened without traverse privilege.
#Fields #
| Name | Description |
|---|---|
NtfsQueryLinksInfo_Link_info_query_not_allowed_as_file_was_opened_without_traverse_privilege_Thread | NtfsQueryLinksInfo: Link info query not allowed as file was opened without traverse privilege. Thread. |
p_Vcb | |
p_VolumeName | |
S_VolumeLabel | |
S_Fcb |
Event ID 293: NtfsSetCaseSensitiveInfo: Cannot mark root directory of a volume case-sensitive.
#Fields #
| Name | Description |
|---|---|
NtfsSetCaseSensitiveInfo_Cannot_mark_root_directory_of_a_volume_casesensitive_Thread | NtfsSetCaseSensitiveInfo: Cannot mark root directory of a volume case-sensitive. Thread. |
p_Vcb | |
p_VolumeName | |
S_VolumeLabel | |
S_Fcb |
Event ID 294: NtfsRemoveSupersededTarget: Can not do a superseding rename over a system file.
#Fields #
| Name | Description |
|---|---|
NtfsRemoveSupersededTarget_Can_not_do_a_superseding_rename_over_a_system_file_Thread | NtfsRemoveSupersededTarget: Can not do a superseding rename over a system file. Thread. |
p_Vcb | |
p_VolumeName | |
S_VolumeLabel | |
S_Fcb |
Event ID 295: NtfsRemoveSupersededTarget: Can not do a superseding rename over a file with open handles.
#Fields #
| Name | Description |
|---|---|
NtfsRemoveSupersededTarget_Can_not_do_a_superseding_rename_over_a_file_with_open_handles_Thread | NtfsRemoveSupersededTarget: Can not do a superseding rename over a file with open handles. Thread. |
p_Vcb | |
p_VolumeName | |
S_VolumeLabel | |
S_Fcb |
Event ID 296: NtfsRemoveSupersededTarget: Can not do a superseding rename over a file with open handles.
#Fields #
| Name | Description |
|---|---|
NtfsRemoveSupersededTarget_Can_not_do_a_superseding_rename_over_a_file_with_open_handles_Thread | NtfsRemoveSupersededTarget: Can not do a superseding rename over a file with open handles. Thread. |
p_Vcb | |
p_VolumeName | |
S_VolumeLabel | |
S_Fcb | |
p_Link_name | 6!I64x!, Lcb. |
S_TxfNumWriters_count |
Event ID 297: NtfsRemoveSupersededTarget: Can not do a superseding rename over a file opened by ID.
#Fields #
| Name | Description |
|---|---|
NtfsRemoveSupersededTarget_Can_not_do_a_superseding_rename_over_a_file_opened_by_ID_Thread | NtfsRemoveSupersededTarget: Can not do a superseding rename over a file opened by ID. Thread. |
p_Vcb | |
p_VolumeName | |
S_VolumeLabel | |
S_Fcb |
Event ID 298: NtfsRemoveSupersededTarget: Can not do a superseding rename over a file with open handles via either part of the long/short pair.
#Fields #
| Name | Description |
|---|---|
NtfsRemoveSupersededTarget_Can_not_do_a_superseding_rename_over_a_file_with_open_handles_via_either_part_of_the_longshort_pair_Thread | NtfsRemoveSupersededTarget: Can not do a superseding rename over a file with open handles via either part of the long/short pair. Thread. |
p_Vcb | |
p_VolumeName | |
S_VolumeLabel | |
S_Fcb | |
p_Link_name | 6!I64x!, Lcb. |
S_Link_cleanup_count | |
d_SplitPrimaryLcb | |
p_Split_link_name | |
S_Split_link_cleanup_count |
Event ID 299: NtfsSetRenameInfo: Can not rename a file marked for deletion.
#Fields #
| Name | Description |
|---|---|
NtfsSetRenameInfo_Can_not_rename_a_file_marked_for_deletion_Thread | NtfsSetRenameInfo: Can not rename a file marked for deletion. Thread. |
p_Vcb | |
p_VolumeName | |
S_VolumeLabel | |
S_Fcb | |
p_link_name |
Event ID 300: NtfsSetRenameInfo: Can not rename a txf directory.
#Fields #
| Name | Description |
|---|---|
NtfsSetRenameInfo_Can_not_rename_a_txf_directory_Thread | NtfsSetRenameInfo: Can not rename a txf directory. Thread. |
p_Vcb | |
p_VolumeName | |
S_VolumeLabel | |
S_Fcb |
Event ID 301: NtfsSetRenameInfo: Can not rename into a system directory.
#Fields #
| Name | Description |
|---|---|
NtfsSetRenameInfo_Can_not_rename_into_a_system_directory_Thread | NtfsSetRenameInfo: Can not rename into a system directory. Thread. |
p_Vcb | |
p_VolumeName | |
S_VolumeLabel | |
S_Fcb |
Event ID 302: NtfsSetRenameInfo: Can not rename a file that is part of a TxF transaction.
#Fields #
| Name | Description |
|---|---|
NtfsSetRenameInfo_Can_not_rename_a_file_that_is_part_of_a_TxF_transaction_Thread | NtfsSetRenameInfo: Can not rename a file that is part of a TxF transaction. Thread. |
p_Vcb | |
p_VolumeName | |
S_VolumeLabel | |
S_Fcb |
Event ID 303: NtfsSetRenameInfo: The file should not have in-memory directory descendents.
#Fields #
| Name | Description |
|---|---|
NtfsSetRenameInfo_The_file_should_not_have_inmemory_directory_descendents_Thread | NtfsSetRenameInfo: The file should not have in-memory directory descendents. Thread. |
p_Vcb | |
p_VolumeName | |
S_VolumeLabel | |
S_Fcb |
Event ID 304: NtfsSetRenameInfo: Child Scb mismatch.
#Fields #
| Name | Description |
|---|---|
NtfsSetRenameInfo_Child_Scb_mismatch_Thread | NtfsSetRenameInfo: Child Scb mismatch. Thread. |
p_Vcb | |
p_VolumeName | |
S_VolumeLabel | |
S_Fcb |
Event ID 305: NtfsSetLinkInfo: Set link info is not allowed on txf directory.
#Fields #
| Name | Description |
|---|---|
NtfsSetLinkInfo_Set_link_info_is_not_allowed_on_txf_directory_Thread | NtfsSetLinkInfo: Set link info is not allowed on txf directory. Thread. |
p_Vcb | |
p_VolumeName | |
S_VolumeLabel | |
S_Fcb |
Event ID 306: NtfsSetLinkInfo: Set link info is not allowed on a file in a TxF transaction.
#Fields #
| Name | Description |
|---|---|
NtfsSetLinkInfo_Set_link_info_is_not_allowed_on_a_file_in_a_TxF_transaction_Thread | NtfsSetLinkInfo: Set link info is not allowed on a file in a TxF transaction. Thread. |
p_Vcb | |
p_VolumeName | |
S_VolumeLabel | |
S_Fcb | |
S_TxfVisibleLinks | 6!I64x!, FileName. |
Event ID 307: NtfsSetLinkInfo: Set link info failed due to caller not having FILE_WRITE_ATTRIBUTES access.
#Fields #
| Name | Description |
|---|---|
NtfsSetLinkInfo_Set_link_info_failed_due_to_caller_not_having_FILEWRITEATTRIBUTES_access_Thread | NtfsSetLinkInfo: Set link info failed due to caller not having FILE_WRITE_ATTRIBUTES access. Thread. |
p_Vcb | |
p_VolumeName | |
S_VolumeLabel | |
S_Fcb | |
S_SeAccessCheck_status | 6!I64x!, FileName. |
Event ID 308: NtfsSetLinkInfo: Creating a link in system directory is not allowed.
#Fields #
| Name | Description |
|---|---|
NtfsSetLinkInfo_Creating_a_link_in_system_directory_is_not_allowed_Thread | NtfsSetLinkInfo: Creating a link in system directory is not allowed. Thread. |
p_Vcb | |
p_VolumeName | |
S_VolumeLabel | |
S_Fcb |
Event ID 309: NtfsSetLinkInfo: Creating a link in $txf is not allowed if the RM is running.
#Fields #
| Name | Description |
|---|---|
NtfsSetLinkInfo_Creating_a_link_in_txf_is_not_allowed_if_the_RM_is_running_Thread | NtfsSetLinkInfo: Creating a link in $txf is not allowed if the RM is running. Thread. |
p_Vcb | |
p_VolumeName | |
S_VolumeLabel | |
S_Fcb | |
S_Target_RM_state | 6!I64x!, NewLinkName. |
Event ID 310: NtfsSetShortNameInfo: Can not set a short name on a deleted file.
#Fields #
| Name | Description |
|---|---|
NtfsSetShortNameInfo_Can_not_set_a_short_name_on_a_deleted_file_Thread | NtfsSetShortNameInfo: Can not set a short name on a deleted file. Thread. |
p_Vcb | |
p_VolumeName | |
S_VolumeLabel | |
S_Fcb | |
p_Link_Name | 6!I64x!, Lcb. |
Event ID 311: NtfsSetShortNameInfo: Can not set a short name on a file under the $TxF directory.
#Fields #
| Name | Description |
|---|---|
NtfsSetShortNameInfo_Can_not_set_a_short_name_on_a_file_under_the_TxF_directory_Thread | NtfsSetShortNameInfo: Can not set a short name on a file under the $TxF directory. Thread. |
p_Vcb | |
p_VolumeName | |
S_VolumeLabel | |
S_Fcb | |
p_Link_Name | 6!I64x!, Lcb. |
S_Parent_FileRef |
Event ID 312: NtfsCheckScbForLinkRemoval: Existing handles are not allowed if Txf transaction is doing the rename.
#Fields #
| Name | Description |
|---|---|
NtfsCheckScbForLinkRemoval_Existing_handles_are_not_allowed_if_Txf_transaction_is_doing_the_rename_Thread | NtfsCheckScbForLinkRemoval: Existing handles are not allowed if Txf transaction is doing the rename. Thread. |
p_Vcb | |
p_VolumeName | |
S_VolumeLabel | |
S_Fcb |
Event ID 313: NtfsCheckScbForLinkRemoval: Not all open handles for the stream are by-id opens.
#Fields #
| Name | Description |
|---|---|
NtfsCheckScbForLinkRemoval_Not_all_open_handles_for_the_stream_are_byid_opens_Thread | NtfsCheckScbForLinkRemoval: Not all open handles for the stream are by-id opens. Thread. |
p_Vcb | |
p_VolumeName | |
S_VolumeLabel | |
S_Fcb | |
d_Stream_cleanup_count | 6!I64x!, ByID opens. |
Event ID 314: NtfsStreamRename: Deny access due to encryption happening on source stream.
#Fields #
| Name | Description |
|---|---|
NtfsStreamRename_Deny_access_due_to_encryption_happening_on_source_stream_Thread | NtfsStreamRename: Deny access due to encryption happening on source stream. Thread. |
p_Vcb | |
p_VolumeName | |
S_VolumeLabel | |
S_Fcb |
Event ID 315: NtfsProcessTreeForRename: Deny access due to number of batch oplocks has grown.
#Fields #
| Name | Description |
|---|---|
NtfsProcessTreeForRename_Deny_access_due_to_number_of_batch_oplocks_has_grown_Thread | NtfsProcessTreeForRename: Deny access due to number of batch oplocks has grown. Thread. |
p_Vcb | |
p_VolumeName | |
S_VolumeLabel | |
S_Fcb | |
d_current_batch_oplock_count | 6!I64x!, Previous batch oplock count. |
Event ID 316: NtfsFlushVolumeFlushSingleFcb: Thread: .
#Fields #
| Name | Description |
|---|---|
NtfsFlushVolumeFlushSingleFcb_Thread | NtfsFlushVolumeFlushSingleFcb: Thread. |
p_Vcb | |
p_Fcb | |
p_LocalFlags |
Event ID 317: NtfsFlushVolumeFlushSingleFcb: Thread: .
#Fields #
| Name | Description |
|---|---|
NtfsFlushVolumeFlushSingleFcb_Thread | NtfsFlushVolumeFlushSingleFcb: Thread. |
p_Scb |
Event ID 318: NtfsFlushVolume: Thread: .
#Fields #
| Name | Description |
|---|---|
NtfsFlushVolume_Thread | NtfsFlushVolume: Thread. |
p_Vcb | |
p_LocalFlags |
Event ID 319: NtfsFlushVolume setting SCB_PERSIST_VOLUME_DISMOUNTED on BitmapScb Scb: .
#Fields #
| Name | Description |
|---|---|
NtfsFlushVolume_setting_SCBPERSISTVOLUMEDISMOUNTED_on_BitmapScb_Scb | NtfsFlushVolume setting SCB_PERSIST_VOLUME_DISMOUNTED on BitmapScb Scb. |
p_Vcb |
Event ID 320: NtfsFlushVolume setting SCB_PERSIST_VOLUME_DISMOUNTED on MftScb Scb: .
#Fields #
| Name | Description |
|---|---|
NtfsFlushVolume_setting_SCBPERSISTVOLUMEDISMOUNTED_on_MftScb_Scb | NtfsFlushVolume setting SCB_PERSIST_VOLUME_DISMOUNTED on MftScb Scb. |
p_Vcb |
Event ID 323: NtfsDiskFlushContextWorkItemProcessing: Process work item
#Event ID 324: NtfsDiskFlushContextWorkItemProcessing: Nothing to work on
#Event ID 326: NtfsLockVolumeInternal: Cannot lock the volume.
#Fields #
| Name | Description |
|---|---|
NtfsLockVolumeInternal_Cannot_lock_the_volume_Thread | NtfsLockVolumeInternal: Cannot lock the volume. Thread. |
p_Vcb | |
p_VolumeName | |
S_VolumeLabel | |
d_ExplicitLock | |
d_Volume_CleanupCount | |
d_Handle_count |
Event ID 327: NtfsLockVolumeInternal: Volume is already locked.
#Fields #
| Name | Description |
|---|---|
NtfsLockVolumeInternal_Volume_is_already_lockedThread | NtfsLockVolumeInternal: Volume is already locked.Thread. |
p_Vcb | |
p_VolumeName | |
S_VolumeLabel |
Event ID 328: NtfsLockVolumeInternal: Failed to flush system files on the volume.
#Fields #
| Name | Description |
|---|---|
NtfsLockVolumeInternal_Failed_to_flush_system_files_on_the_volume_Thread | NtfsLockVolumeInternal: Failed to flush system files on the volume. Thread. |
p_Vcb | |
p_VolumeName | |
S_VolumeLabel | |
S_Flush_Status |
Event ID 329: NtfsLockVolumeInternal: Failed to flush system files on the volume.
#Fields #
| Name | Description |
|---|---|
NtfsLockVolumeInternal_Failed_to_flush_system_files_on_the_volumeThread | NtfsLockVolumeInternal: Failed to flush system files on the volume.Thread. |
p_Vcb | |
p_VolumeName | |
S_VolumeLabel | |
S_Flush_Status |
Event ID 330: NtfsLockVolumeInternal: Outstanding user files open after flush and retry.
#Fields #
| Name | Description |
|---|---|
NtfsLockVolumeInternal_Outstanding_user_files_open_after_flush_and_retry_Thread | NtfsLockVolumeInternal: Outstanding user files open after flush and retry. Thread. |
p_Vcb | |
p_VolumeName | |
S_VolumeLabel | |
S_Volume_close_count | |
d_System_file_close_count | |
d_User_handle_count |
Event ID 331: NtfsLockVolume: Cannot lock volume due to caller does not have manage volume privilege.
#Fields #
| Name | Description |
|---|---|
NtfsLockVolume_Cannot_lock_volume_due_to_caller_does_not_have_manage_volume_privilege_Thread | NtfsLockVolume: Cannot lock volume due to caller does not have manage volume privilege. Thread. |
p_Vcb | |
p_VolumeName | |
S_VolumeLabel |
Event ID 332: NtfsLockVolume: Cannot lock volume due to active secondary RMs on the volume.
#Fields #
| Name | Description |
|---|---|
NtfsLockVolume_Cannot_lock_volume_due_to_active_secondary_RMs_on_the_volume_Thread | NtfsLockVolume: Cannot lock volume due to active secondary RMs on the volume. Thread. |
p_Vcb | |
p_VolumeName | |
S_VolumeLabel | |
S_Active_RM_count | |
d_Default_RM_Active |
Event ID 333: ...: Setting RM at 0x...!p! ({...!S!}) up for auto-restart.
#Fields #
| Name | Description |
|---|---|
param1 | |
param2 | |
param3 |
Event ID 334: NtfsUnlockVolume: Cannot unlock volume due to caller does not have manage volume privilege.
#Fields #
| Name | Description |
|---|---|
NtfsUnlockVolume_Cannot_unlock_volume_due_to_caller_does_not_have_manage_volume_privilege_Thread | NtfsUnlockVolume: Cannot unlock volume due to caller does not have manage volume privilege. Thread. |
p_Vcb | |
p_VolumeName | |
S_VolumeLabel |
Event ID 335: NtfsDismountVolume: IC: .
#Fields #
| Name | Description |
|---|---|
NtfsDismountVolume_IC | NtfsDismountVolume: IC. |
p_Vcb | |
p_Label | |
S_DeviceName |
Event ID 336: NtfsDismountVolume: Cannot dismount volume due to system/pagefiles being open for write access.
#Fields #
| Name | Description |
|---|---|
NtfsDismountVolume_Cannot_dismount_volume_due_to_systempagefiles_being_open_for_write_access_Thread | NtfsDismountVolume: Cannot dismount volume due to system/pagefiles being open for write access. Thread. |
p_Vcb | |
p_VolumeName | |
S_VolumeLabel |
Event ID 337: NtfsDismountVolume: Cannot dismount volume due to volume being locked.
#Fields #
| Name | Description |
|---|---|
NtfsDismountVolume_Cannot_dismount_volume_due_to_volume_being_locked_Thread | NtfsDismountVolume: Cannot dismount volume due to volume being locked. Thread. |
p_Vcb | |
p_VolumeName | |
S_VolumeLabel |
Event ID 338: NtfsDismountVolume: Cannot dismount volume due to system/pagefiles being open for write access.
#Fields #
| Name | Description |
|---|---|
NtfsDismountVolume_Cannot_dismount_volume_due_to_systempagefiles_being_open_for_write_access_Thread | NtfsDismountVolume: Cannot dismount volume due to system/pagefiles being open for write access. Thread. |
p_Vcb | |
p_VolumeName | |
S_VolumeLabel | |
d_CloseCount | |
d_SystemFileCloseCount |
Event ID 339: NtfsMarkVolumeDirty: Cannot mark volume dirty due to caller not having manage volume privilege.
#Fields #
| Name | Description |
|---|---|
NtfsMarkVolumeDirty_Cannot_mark_volume_dirty_due_to_caller_not_having_manage_volume_privilege_Thread | NtfsMarkVolumeDirty: Cannot mark volume dirty due to caller not having manage volume privilege. Thread. |
p_Vcb | |
p_VolumeName | |
S_VolumeLabel |
Event ID 340: NtfsGetVolumeBitmap: Cannot get volume bitmap due to caller not having manage volume privilege.
#Fields #
| Name | Description |
|---|---|
NtfsGetVolumeBitmap_Cannot_get_volume_bitmap_due_to_caller_not_having_manage_volume_privilege_Thread | NtfsGetVolumeBitmap: Cannot get volume bitmap due to caller not having manage volume privilege. Thread. |
p_Vcb | |
p_VolumeName | |
S_VolumeLabel |
Event ID 341: NtfsGetBootAreaInfo: Cannot get boot area info due to caller not having manage volume privilege.
#Fields #
| Name | Description |
|---|---|
NtfsGetBootAreaInfo_Cannot_get_boot_area_info_due_to_caller_not_having_manage_volume_privilege_Thread | NtfsGetBootAreaInfo: Cannot get boot area info due to caller not having manage volume privilege. Thread. |
p_Vcb | |
p_VolumeName | |
S_VolumeLabel |
Event ID 342: NtfsGetRetrievalPointers: Cannot get retrieval pointers due to caller not having manage volume privilege.
#Fields #
| Name | Description |
|---|---|
NtfsGetRetrievalPointers_Cannot_get_retrieval_pointers_due_to_caller_not_having_manage_volume_privilege_Thread | NtfsGetRetrievalPointers: Cannot get retrieval pointers due to caller not having manage volume privilege. Thread. |
p_Vcb | |
p_VolumeName | |
S_VolumeLabel |
Event ID 343: NtfsGetRetrievalPointerBase: Cannot get revrieval pointer base info due to caller not having manage volume privilege.
#Fields #
| Name | Description |
|---|---|
NtfsGetRetrievalPointerBase_Cannot_get_revrieval_pointer_base_info_due_to_caller_not_having_manage_volume_privilege_Thread | NtfsGetRetrievalPointerBase: Cannot get revrieval pointer base info due to caller not having manage volume privilege. Thread. |
p_Vcb | |
p_VolumeName | |
S_VolumeLabel |
Event ID 344: NtfsGetRetrievalPointerBase: Cannot get revrieval pointer base info due to caller not having manage volume privilege or this is not a volume open.
#Fields #
| Name | Description |
|---|---|
NtfsGetRetrievalPointerBase_Cannot_get_revrieval_pointer_base_info_due_to_caller_not_having_manage_volume_privilege_or_this_is_not_a_volume_open_Thread | NtfsGetRetrievalPointerBase: Cannot get revrieval pointer base info due to caller not having manage volume privilege or this is not a volume open. Thread. |
p_Vcb | |
p_VolumeName | |
S_VolumeLabel |
Event ID 345: NtfsCreateUsnJournal: Cannot create Usn journal due to caller not having manage volume privilege.
#Fields #
| Name | Description |
|---|---|
NtfsCreateUsnJournal_Cannot_create_Usn_journal_due_to_caller_not_having_manage_volume_privilege_Thread | NtfsCreateUsnJournal: Cannot create Usn journal due to caller not having manage volume privilege. Thread. |
p_Vcb | |
p_VolumeName | |
S_VolumeLabel |
Event ID 346: NtfsUsnTrackModifiedRanges: Cannot enable range tracking due to caller not having manage volume privilege.
#Fields #
| Name | Description |
|---|---|
NtfsUsnTrackModifiedRanges_Cannot_enable_range_tracking_due_to_caller_not_having_manage_volume_privilege_Thread | NtfsUsnTrackModifiedRanges: Cannot enable range tracking due to caller not having manage volume privilege. Thread. |
p_Vcb | |
p_VolumeName | |
S_VolumeLabel |
Event ID 347: NtfsEnumerateUsnData: Cannot enumerate Usn data due to caller not having manage volume privilege.
#Fields #
| Name | Description |
|---|---|
NtfsEnumerateUsnData_Cannot_enumerate_Usn_data_due_to_caller_not_having_manage_volume_privilege_Thread | NtfsEnumerateUsnData: Cannot enumerate Usn data due to caller not having manage volume privilege. Thread. |
p_Vcb | |
p_VolumeName | |
S_VolumeLabel |
Event ID 348: NtfsFindFilesOwnedBySid: Caller not having manage volume privilege, backup access or can bypass traverse checks.
#Fields #
| Name | Description |
|---|---|
NtfsFindFilesOwnedBySid_Caller_not_having_manage_volume_privilege_backup_access_or_can_bypass_traverse_checks_Thread | NtfsFindFilesOwnedBySid: Caller not having manage volume privilege, backup access or can bypass traverse checks. Thread. |
p_Vcb | |
p_VolumeName | |
S_VolumeLabel |
Event ID 349: NtfsFindFilesOwnedBySid: Caller not having manage volume privilege or backup access and is not admin.
#Fields #
| Name | Description |
|---|---|
NtfsFindFilesOwnedBySid_Caller_not_having_manage_volume_privilege_or_backup_access_and_is_not_admin_Thread | NtfsFindFilesOwnedBySid: Caller not having manage volume privilege or backup access and is not admin. Thread. |
p_Vcb | |
p_VolumeName | |
S_VolumeLabel | |
d_Context_owner_ID |
Event ID 350: NtfsSetSparse: Caller does not have appropriate write access to the stream.
#Fields #
| Name | Description |
|---|---|
NtfsSetSparse_Caller_does_not_have_appropriate_write_access_to_the_stream_Thread | NtfsSetSparse: Caller does not have appropriate write access to the stream. Thread. |
p_Vcb | |
p_VolumeName | |
S_VolumeLabel | |
S_Fcb |
Event ID 351: NtfsSetSparse: Cannot desparse encrypted file without write data access.
#Fields #
| Name | Description |
|---|---|
NtfsSetSparse_Cannot_desparse_encrypted_file_without_write_data_access_Thread | NtfsSetSparse: Cannot desparse encrypted file without write data access. Thread. |
p_Vcb | |
p_VolumeName | |
S_VolumeLabel | |
S_Fcb |
Event ID 352: NtfsZeroRange: User mode caller not allowed.
#Fields #
| Name | Description |
|---|---|
NtfsZeroRange_User_mode_caller_not_allowed_Thread | NtfsZeroRange: User mode caller not allowed. Thread. |
Event ID 355: NtfsReadRawEncrypted: Caller does not have backup access or read data access.
#Fields #
| Name | Description |
|---|---|
NtfsReadRawEncrypted_Caller_does_not_have_backup_access_or_read_data_access_Thread | NtfsReadRawEncrypted: Caller does not have backup access or read data access. Thread. |
p_Vcb | |
p_VolumeName | |
S_VolumeLabel | |
S_Fcb |
Event ID 356: NtfsWriteRawEncrypted: Caller does not have write data access or restore access.
#Fields #
| Name | Description |
|---|---|
NtfsWriteRawEncrypted_Caller_does_not_have_write_data_access_or_restore_access_Thread | NtfsWriteRawEncrypted: Caller does not have write data access or restore access. Thread. |
p_Vcb | |
p_VolumeName | |
S_VolumeLabel | |
S_Fcb |
Event ID 357: NtfsWriteRawEncrypted: Caller not having manage volume privilege.
#Fields #
| Name | Description |
|---|---|
NtfsWriteRawEncrypted_Caller_not_having_manage_volume_privilege_Thread | NtfsWriteRawEncrypted: Caller not having manage volume privilege. Thread. |
p_Vcb | |
p_VolumeName | |
S_VolumeLabel |
Event ID 358: NtfsLookupStreamFromCluster: Caller not having manage volume privilege.
#Fields #
| Name | Description |
|---|---|
NtfsLookupStreamFromCluster_Caller_not_having_manage_volume_privilege_Thread | NtfsLookupStreamFromCluster: Caller not having manage volume privilege. Thread. |
p_Vcb | |
p_VolumeName | |
S_VolumeLabel |
Event ID 359: NtfsChangeVolumeSize: Caller not having manage volume privilege.
#Fields #
| Name | Description |
|---|---|
NtfsChangeVolumeSize_Caller_not_having_manage_volume_privilege_Thread | NtfsChangeVolumeSize: Caller not having manage volume privilege. Thread. |
p_Vcb | |
p_VolumeName | |
S_VolumeLabel |
Event ID 362: NtfsMarkHandle: Caller does not have a valid volume handle or manage volume access or is not kernel model caller.
#Fields #
| Name | Description |
|---|---|
NtfsMarkHandle_Caller_does_not_have_a_valid_volume_handle_or_manage_volume_access_or_is_not_kernel_model_caller_Thread | NtfsMarkHandle: Caller does not have a valid volume handle or manage volume access or is not kernel model caller. Thread. |
p_Vcb | |
p_VolumeName | |
S_VolumeLabel | |
S_Fcb |
Event ID 363: NtfsMarkHandle: Caller not having manage volume privilege.
#Fields #
| Name | Description |
|---|---|
NtfsMarkHandle_Caller_not_having_manage_volume_privilege_Thread | NtfsMarkHandle: Caller not having manage volume privilege. Thread. |
p_Vcb | |
p_VolumeName | |
S_VolumeLabel |
Event ID 364: NtfsMarkHandle: Cannot deny defrag.
#Fields #
| Name | Description |
|---|---|
NtfsMarkHandle_Cannot_deny_defrag_Thread | NtfsMarkHandle: Cannot deny defrag. Thread. |
p_Vcb | |
p_VolumeName | |
S_VolumeLabel | |
S_Fcb |
Event ID 365: NtfsMarkHandle: Cannot deny Frs consolidation.
#Fields #
| Name | Description |
|---|---|
NtfsMarkHandle_Cannot_deny_Frs_consolidation_Thread | NtfsMarkHandle: Cannot deny Frs consolidation. Thread. |
p_Vcb | |
p_VolumeName | |
S_VolumeLabel | |
S_Fcb |
Event ID 366: NtfsMarkHandle: Cannot filter metadata.
#Fields #
| Name | Description |
|---|---|
NtfsMarkHandle_Cannot_filter_metadata_Thread | NtfsMarkHandle: Cannot filter metadata. Thread. |
p_Vcb | |
p_VolumeName | |
S_VolumeLabel | |
S_Fcb |
Event ID 367: NtfsMarkHandle: Mark handle is not allowed on system files.
#Fields #
| Name | Description |
|---|---|
NtfsMarkHandle_Mark_handle_is_not_allowed_on_system_files_Thread | NtfsMarkHandle: Mark handle is not allowed on system files. Thread. |
p_Vcb | |
p_VolumeName | |
S_VolumeLabel | |
S_Fcb |
Event ID 368: NtfsMarkHandle: File already has user writable references.
#Fields #
| Name | Description |
|---|---|
NtfsMarkHandle_File_already_has_user_writable_references_Thread | NtfsMarkHandle: File already has user writable references. Thread. |
p_Vcb | |
p_VolumeName | |
S_VolumeLabel | |
S_Fcb |
Event ID 369: NtfsMarkHandle: File was granted write access previously but no oplocks were broken.
#Fields #
| Name | Description |
|---|---|
NtfsMarkHandle_File_was_granted_write_access_previously_but_no_oplocks_were_broken_Thread | NtfsMarkHandle: File was granted write access previously but no oplocks were broken. Thread. |
p_Vcb | |
p_VolumeName | |
S_VolumeLabel | |
S_Fcb | |
S_Writers |
Event ID 370: NtfsPrefetchFile: Caller not having manage volume privilege.
#Fields #
| Name | Description |
|---|---|
NtfsPrefetchFile_Caller_not_having_manage_volume_privilege_Thread | NtfsPrefetchFile: Caller not having manage volume privilege. Thread. |
p_TypeOfOpen | |
d_Vcb | |
p_VolumeName | |
S_VolumeLabel | |
S_Fcb |
Event ID 371: NtfsSetZeroOnDeallocate: Only allowed on regular user files opened for write.
#Fields #
| Name | Description |
|---|---|
NtfsSetZeroOnDeallocate_Only_allowed_on_regular_user_files_opened_for_write_Thread | NtfsSetZeroOnDeallocate: Only allowed on regular user files opened for write. Thread. |
p_Vcb | |
p_VolumeName | |
S_VolumeLabel | |
S_TypeOfOpen | |
d_WriteAccess | |
d_Fcb |
Event ID 372: NtfsSetShortNameBehavior: Caller not having manage volume privilege.
#Fields #
| Name | Description |
|---|---|
NtfsSetShortNameBehavior_Caller_not_having_manage_volume_privilege_Thread | NtfsSetShortNameBehavior: Caller not having manage volume privilege. Thread. |
p_Vcb | |
p_VolumeName | |
S_VolumeLabel |
Event ID 373: Setting VCB_EXT_CHAR_STATE_ALLOW_EXT_CHAR for volume 0x.
#Fields #
| Name | Description |
|---|---|
param1 | |
param2 |
Event ID 374: NtfsQueryPagefileEncryption: Caller not having manage volume privilege.
#Fields #
| Name | Description |
|---|---|
NtfsQueryPagefileEncryption_Caller_not_having_manage_volume_privilege_Thread | NtfsQueryPagefileEncryption: Caller not having manage volume privilege. Thread. |
p_Vcb | |
p_VolumeName | |
S_VolumeLabel |
Event ID 375: NtfsQueryPagefileEncryption: Caller not having manage volume privilege.
#Fields #
| Name | Description |
|---|---|
NtfsQueryPagefileEncryption_Caller_not_having_manage_volume_privilege_Thread | NtfsQueryPagefileEncryption: Caller not having manage volume privilege. Thread. |
p_Vcb | |
p_VolumeName | |
S_VolumeLabel |
Event ID 376: NtfsResetVolsnapBehaviorForVolume: Volsnap hints are disabled by registry.
#Fields #
| Name | Description |
|---|---|
NtfsResetVolsnapBehaviorForVolume_Volsnap_hints_are_disabled_by_registry_Thread | NtfsResetVolsnapBehaviorForVolume: Volsnap hints are disabled by registry. Thread. |
p_Vcb | |
p_VolumeName | |
S_VolumeLabel | |
S_NtfsData_Flags |
Event ID 377: NtfsResetVolsnapBehaviorForVolume: Caller not having manage volume privilege.
#Fields #
| Name | Description |
|---|---|
NtfsResetVolsnapBehaviorForVolume_Caller_not_having_manage_volume_privilege_Thread | NtfsResetVolsnapBehaviorForVolume: Caller not having manage volume privilege. Thread. |
p_Vcb | |
p_VolumeName | |
S_VolumeLabel |
Event ID 379: NtfsResetVolsnapBehaviorForVolume: Caller not having manage volume privilege.
#Fields #
| Name | Description |
|---|---|
NtfsResetVolsnapBehaviorForVolume_Caller_not_having_manage_volume_privilege_Thread | NtfsResetVolsnapBehaviorForVolume: Caller not having manage volume privilege. Thread. |
p_Vcb | |
p_VolumeName | |
S_VolumeLabel |
Event ID 380: NtfsCorruptionHandling: Caller not having manage volume privilege.
#Fields #
| Name | Description |
|---|---|
NtfsCorruptionHandling_Caller_not_having_manage_volume_privilege_Thread | NtfsCorruptionHandling: Caller not having manage volume privilege. Thread. |
p_Vcb | |
p_VolumeName | |
S_VolumeLabel |
Event ID 381: NtfsGlobalCorruptionHandling: Caller does not have manage volume privilege.
#Fields #
| Name | Description |
|---|---|
NtfsGlobalCorruptionHandling_Caller_does_not_have_manage_volume_privilege_Thread | NtfsGlobalCorruptionHandling: Caller does not have manage volume privilege. Thread. |
p_Vcb | |
p_VolumeName | |
S_VolumeLabel |
Event ID 382: Scrub resume from SystemScbIndex: .
#Fields #
| Name | Description |
|---|---|
Scrub_resume_from_SystemScbIndex | |
u_Vcn |
Event ID 385: NtfsScrubData: Caller not having manage volume privilege.
#Fields #
| Name | Description |
|---|---|
NtfsScrubData_Caller_not_having_manage_volume_privilege_Thread | NtfsScrubData: Caller not having manage volume privilege. Thread. |
p_Vcb | |
p_VolumeName | |
S_VolumeLabel | |
S_TypeOfOpen | |
d_Fcb |
Event ID 386: Scrub not supported for Txf file, Scb: .
#Fields #
| Name | Description |
|---|---|
Scrub_not_supported_for_Txf_file_Scb | Scrub not supported for Txf file, Scb. |
p_TxfScb |
Event ID 387: Scrub SCRUB_DATA_INPUT_FLAG_SKIP_NON_INTEGRITY_DATA is request.
#Event ID 388: Scb:.
#Fields #
| Name | Description |
|---|---|
Scb | |
p_ScrubInternal_OperationStatus | |
S_Repaired | |
I64x_Failed | !#I64x! Failed. |
I64x_FileOffset | !#I64x! FileOffset. |
I64x_Length | |
I64x_ParityExtentCount |
Event ID 389: Scb:.
#Fields #
| Name | Description |
|---|---|
Scb | |
p_ScrubInternal_Status | |
S_Repaired | |
I64x_Failed | !#I64x! Failed. |
I64x_ParityExtentCount |
Event ID 396: Scb:.
#Fields #
| Name | Description |
|---|---|
Scb | |
p_Scrub_starting_vcn_is_beyond_VDL_FileOffset | |
I64x_SectorAlignedVdl | !#I64x!, SectorAlignedVdl. |
Event ID 401: Scrub found problems Scb: .
#Fields #
| Name | Description |
|---|---|
Scrub_found_problems_Scb | |
I64x_Length | 2!#I64x! FileOffset. |
I64x_Status | |
S_BytesFailed | !#I64x! Status. |
I64x_BytesRepaired | |
I64x_NewParityExtents | !#I64x! BytesRepaired. |
Event ID 404: FSCTL_REPAIR_COPIES not supported for Txf file, Scb: .
#Fields #
| Name | Description |
|---|---|
FSCTLREPAIRCOPIES_not_supported_for_Txf_file_Scb | FSCTL_REPAIR_COPIES not supported for Txf file, Scb. |
p_TxfScb |
Event ID 407: FSCTL_REPAIR_COPIES interrupted by thread termination.
#Event ID 408: FSCTL_REPAIR_COPIES canceled
#Event ID 409: Scb:.
#Fields #
| Name | Description |
|---|---|
Scb | |
p_FSCTLREPAIRCOPIES_no_more_Mcb_entries_from_StartingVcn |
Event ID 410: Scb:.
#Fields #
| Name | Description |
|---|---|
Scb | |
p_FSCTLREPAIRCOPIES_No_more_Mcb_entries_unallocated_from_StartingVcn |
Event ID 411: Scb:.
#Fields #
| Name | Description |
|---|---|
Scb | |
p_FSCTLREPAIRCOPIES_skipping_UNUSEDLCN_Vcn | |
I64x_ClusterCount |
Event ID 416: NtfsQueryCachedRuns: Caller not having manage volume privilege.
#Fields #
| Name | Description |
|---|---|
NtfsQueryCachedRuns_Caller_not_having_manage_volume_privilege_Thread | NtfsQueryCachedRuns: Caller not having manage volume privilege. Thread. |
p_Vcb | |
p_VolumeName | |
S_VolumeLabel | |
S_TypeOfOpen | |
d_Fcb |
Event ID 417: NtfsQueryStorageClasses: Caller not having manage volume privilege.
#Fields #
| Name | Description |
|---|---|
NtfsQueryStorageClasses_Caller_not_having_manage_volume_privilege_Thread | NtfsQueryStorageClasses: Caller not having manage volume privilege. Thread. |
p_Vcb | |
p_VolumeName | |
S_VolumeLabel | |
S_TypeOfOpen | |
d_Fcb |
Event ID 418: NtfsQueryRegionInfo: Caller not having manage volume privilege.
#Fields #
| Name | Description |
|---|---|
NtfsQueryRegionInfo_Caller_not_having_manage_volume_privilege_Thread | NtfsQueryRegionInfo: Caller not having manage volume privilege. Thread. |
p_Vcb | |
p_VolumeName | |
S_VolumeLabel | |
S_TypeOfOpen | |
d_Fcb |
Event ID 419: NtfsUnloadFile: Caller not having manage volume privilege.
#Fields #
| Name | Description |
|---|---|
NtfsUnloadFile_Caller_not_having_manage_volume_privilege_Thread | NtfsUnloadFile: Caller not having manage volume privilege. Thread. |
p_Vcb | |
p_VolumeName | |
S_VolumeLabel | |
S_TypeOfOpen | |
d_Fcb |
Event ID 420: NtfsCheckForSection: File already has image section.
#Fields #
| Name | Description |
|---|---|
NtfsCheckForSection_File_already_has_image_section_Thread | NtfsCheckForSection: File already has image section. Thread. |
p_Vcb | |
p_VolumeName | |
S_VolumeLabel | |
S_Fcb |
Event ID 421: NtfsShuffleFile: User mode caller is not allowed.
#Fields #
| Name | Description |
|---|---|
NtfsShuffleFile_User_mode_caller_is_not_allowed_Thread | NtfsShuffleFile: User mode caller is not allowed. Thread. |
p_Vcb | |
p_VolumeName | |
S_VolumeLabel | |
S_TypeOfOpen | |
d_Fcb | |
S_Irp_RequestorMode | 7!I64x!, Ccb FullFileName. |
Event ID 422: NtfsShuffleFile: Denying access due to volume is locked.
#Fields #
| Name | Description |
|---|---|
NtfsShuffleFile_Denying_access_due_to_volume_is_locked_Thread | NtfsShuffleFile: Denying access due to volume is locked. Thread. |
p_TypeOfOpen | |
d_Vcb | |
p_VolumeName | |
S_VolumeLabel | |
S_Fcb | |
p_FileRef | |
I64x_Ccb_FullFileName | !I64x!, Ccb FullFileName. |
Event ID 423: NtfsShuffleFile: Defrag is denied.
#Fields #
| Name | Description |
|---|---|
NtfsShuffleFile_Defrag_is_denied_Thread | NtfsShuffleFile: Defrag is denied. Thread. |
p_Vcb | |
p_VolumeName | |
S_VolumeLabel | |
S_Fcb |
Event ID 424: NtfsShuffleFile: Denying access due to conflicting with read-only state.
#Fields #
| Name | Description |
|---|---|
NtfsShuffleFile_Denying_access_due_to_conflicting_with_readonly_state_Thread | NtfsShuffleFile: Denying access due to conflicting with read-only state. Thread. |
p_Vcb | |
p_VolumeName | |
S_VolumeLabel | |
S_Fcb |
Event ID 425: NtfsRearrangeFile: User mode caller is not allowed.
#Fields #
| Name | Description |
|---|---|
NtfsRearrangeFile_User_mode_caller_is_not_allowed_Thread | NtfsRearrangeFile: User mode caller is not allowed. Thread. |
p_Vcb | |
p_VolumeName | |
S_VolumeLabel | |
S_Fcb | |
S_Irp_RequestorMode | 6!I64x!, Ccb FullFileName. |
Event ID 426: NtfsRearrangeFile: Denying access due to volume is locked.
#Fields #
| Name | Description |
|---|---|
NtfsRearrangeFile_Denying_access_due_to_volume_is_locked_Thread | NtfsRearrangeFile: Denying access due to volume is locked. Thread. |
p_Vcb | |
p_VolumeName | |
S_VolumeLabel | |
S_Fcb |
Event ID 427: NtfsRearrangeFile: Defrag is denied.
#Fields #
| Name | Description |
|---|---|
NtfsRearrangeFile_Defrag_is_denied_Thread | NtfsRearrangeFile: Defrag is denied. Thread. |
p_Vcb | |
p_VolumeName | |
S_VolumeLabel | |
S_Fcb |
Event ID 428: NtfsShuffleFile: Denying access due to conflicting with read-only state.
#Fields #
| Name | Description |
|---|---|
NtfsShuffleFile_Denying_access_due_to_conflicting_with_readonly_state_Thread | NtfsShuffleFile: Denying access due to conflicting with read-only state. Thread. |
p_Vcb | |
p_VolumeName | |
S_VolumeLabel | |
S_Fcb |
Event ID 429: NtfsSparseOverAllocate: Caller does not have appropriate write access.
#Fields #
| Name | Description |
|---|---|
NtfsSparseOverAllocate_Caller_does_not_have_appropriate_write_access_Thread | NtfsSparseOverAllocate: Caller does not have appropriate write access. Thread. |
p_Vcb | |
p_VolumeName | |
S_VolumeLabel | |
S_FileRef | |
I64x_FullFileName | !I64x!, FullFileName. |
S_Ccb_access_flags |
Event ID 430: NtfsInitiateFileMetadataOptimization: Only allowed on regular user files/directories opened for write.
#Fields #
| Name | Description |
|---|---|
NtfsInitiateFileMetadataOptimization_Only_allowed_on_regular_user_filesdirectories_opened_for_write_Thread | NtfsInitiateFileMetadataOptimization: Only allowed on regular user files/directories opened for write. Thread. |
p_TypeOfOpen | |
d_Vcb | |
p_VolumeName | |
S_VolumeLabel | |
S_Fcb | |
p_FileRef | |
I64x_Scb_AttributeTypeCode | !I64x!, Scb AttributeTypeCode. |
x_FcbState2 | |
x_Ccb_FullFileName | |
S_Ccb_Access_flags | |
x_Ccb_Flags2 |
Event ID 431: NtfsQueryFileMetadataOptimization: Only allowed on regular user files/directories opened for read.
#Fields #
| Name | Description |
|---|---|
NtfsQueryFileMetadataOptimization_Only_allowed_on_regular_user_filesdirectories_opened_for_read_Thread | NtfsQueryFileMetadataOptimization: Only allowed on regular user files/directories opened for read. Thread. |
p_TypeOfOpen | |
d_Vcb | |
p_VolumeName | |
S_VolumeLabel | |
S_Fcb |
Event ID 432: NtfsCleanVolumeMetadata: Caller not having manage volume privilege.
#Fields #
| Name | Description |
|---|---|
NtfsCleanVolumeMetadata_Caller_not_having_manage_volume_privilege_Thread | NtfsCleanVolumeMetadata: Caller not having manage volume privilege. Thread. |
p_Vcb | |
p_VolumeName | |
S_VolumeLabel | |
S_Fcb |
Event ID 438: NtfsCleanVolumeMetadata: Caller not having manage volume privilege.
#Fields #
| Name | Description |
|---|---|
NtfsCleanVolumeMetadata_Caller_not_having_manage_volume_privilege_Thread | NtfsCleanVolumeMetadata: Caller not having manage volume privilege. Thread. |
p_TypeOfOpen | |
d_Vcb | |
p_VolumeName | |
S_VolumeLabel | |
S_Fcb |
Event ID 440: FsLibGetBadAddressRanges returned Status: .
#Fields #
| Name | Description |
|---|---|
FsLibGetBadAddressRanges_returned_Status |
Event ID 444: NtfsEncryptionKeyCtl: Caller does not have SE_TCB_PRIVILEGE.
#Fields #
| Name | Description |
|---|---|
NtfsEncryptionKeyCtl_Caller_does_not_have_SETCBPRIVILEGE_Thread | NtfsEncryptionKeyCtl: Caller does not have SE_TCB_PRIVILEGE. Thread. |
p_Vcb | |
p_VolumeName | |
S_VolumeLabel |
Event ID 445: Logic error of posting close to work queue.
#Event ID 446: NtfsFindPrefixHashEntry: {Hash table: .
#Fields #
| Name | Description |
|---|---|
NtfsFindPrefixHashEntry_Hash_table | NtfsFindPrefixHashEntry: {Hash table. |
p_ParentScb |
Event ID 447: NtfsFindPrefixHashEntry: {Lcb: NULL}
#Event ID 448: NtfsFindPrefixHashEntry: {Lcb: .
#Fields #
| Name | Description |
|---|---|
NtfsFindPrefixHashEntry_Lcb | NtfsFindPrefixHashEntry: {Lcb. |
Event ID 449: NtfsFindPrefixHashEntry: {Lcb not found}
#Event ID 450: NtfsInsertHashEntry: {Hash table: .
#Fields #
| Name | Description |
|---|---|
NtfsInsertHashEntry_Hash_table | NtfsInsertHashEntry: {Hash table. |
p_HashValue | |
d_Lcb |
Event ID 451: NtfsRemoveHashEntry: {Hash table: .
#Fields #
| Name | Description |
|---|---|
NtfsRemoveHashEntry_Hash_table | NtfsRemoveHashEntry: {Hash table. |
p_HashValue |
Event ID 465: NtfsCommitCurrentTransaction IC: .
#Fields #
| Name | Description |
|---|---|
NtfsCommitCurrentTransaction_IC |
Event ID 466: NtfsCommitCurrentTransaction IC: .
#Fields #
| Name | Description |
|---|---|
NtfsCommitCurrentTransaction_IC |
Event ID 472: NtfsCommitCurrentTransaction IC: .
#Fields #
| Name | Description |
|---|---|
NtfsCommitCurrentTransaction_IC |
Event ID 473: NtfsCommitCurrentTransaction IC: .
#Fields #
| Name | Description |
|---|---|
NtfsCommitCurrentTransaction_IC |
Event ID 481: Vcb: .
#Fields #
| Name | Description |
|---|---|
Vcb | |
p_Processing_range_DeallocatedClusters | |
p_RunIndex | |
d_StartingLcn | |
I64x_ClusterCount |
Event ID 482: Looking for dangling MDLs
#Event ID 483: FsLibGroupSubExtentsByDanglingMdl failed: .
#Fields #
| Name | Description |
|---|---|
FsLibGroupSubExtentsByDanglingMdl_failed |
Event ID 485: NtfsAddToMatchingDeallocatedClusters( ExtentsWithoutDanglingMdl ) failed: .
#Fields #
| Name | Description |
|---|---|
NtfsAddToMatchingDeallocatedClusters_ExtentsWithoutDanglingMdl__failed | NtfsAddToMatchingDeallocatedClusters( ExtentsWithoutDanglingMdl ) failed. |
Event ID 486: NtfsAddToMatchingDeallocatedClusters( ExtentsWithDanglingMdl ) failed: .
#Fields #
| Name | Description |
|---|---|
NtfsAddToMatchingDeallocatedClusters_ExtentsWithDanglingMdl__failed | NtfsAddToMatchingDeallocatedClusters( ExtentsWithDanglingMdl ) failed. |
Event ID 487: No sub extents has dangling MDL
#Event ID 499: Valid NTFS boot sector.
#Fields #
| Name | Description |
|---|---|
Valid_NTFS_boot_sector_Vcb | Valid NTFS boot sector. Vcb. |
p_BootSector |
Event ID 500: Not an NTFS boot sector.
#Fields #
| Name | Description |
|---|---|
Not_an_NTFS_boot_sector_Vcb | Not an NTFS boot sector. Vcb. |
p_BootSector | |
p_CheckNumber |
Event ID 501: NtfsMountVolume: Vcb:.
#Fields #
| Name | Description |
|---|---|
NtfsMountVolume_Vcb | NtfsMountVolume: Vcb. |
p_IC |
Event ID 502: NtfsMountVolume: IC: .
#Fields #
| Name | Description |
|---|---|
NtfsMountVolume_IC | NtfsMountVolume: IC. |
p_Vcb | |
p_Label | |
S_DeviceName |
Event ID 503: Mounting DAX partition.
#Fields #
| Name | Description |
|---|---|
Mounting_DAX_partition_Vcb | Mounting DAX partition. Vcb. |
Event ID 504: DAX volume mounted without DAX support because storage is not DAX capable.
#Fields #
| Name | Description |
|---|---|
DAX_volume_mounted_without_DAX_support_because_storage_is_not_DAX_capable_Vcb | DAX volume mounted without DAX support because storage is not DAX capable. Vcb. |
Event ID 505: NtfsGrowMftsAttributeListAllocation Vcb:.
#Fields #
| Name | Description |
|---|---|
NtfsGrowMftsAttributeListAllocation_Vcb | |
p_IC |
Event ID 506: NtfsGrowMftsAttributeListAllocation Vcb:.
#Fields #
| Name | Description |
|---|---|
NtfsGrowMftsAttributeListAllocation_Vcb | |
p_IC |
Event ID 507: NtfsGrowMftsAttributeListAllocation Vcb:.
#Fields #
| Name | Description |
|---|---|
NtfsGrowMftsAttributeListAllocation_Vcb | |
p_IC | |
p_AttrListScb |