Microsoft-Windows-OverlayFilter

19 events across 1 channel

Event ID 24832: The filter failed to open the integrity file for FileNameBuffer (data source DataSourceId) with status Status.

#
Provider
Microsoft-Windows-OverlayFilter
Channel
System
Task
WIMintegrityverification
Opcode
IntegrityFileOpen

Description

The filter failed to open the integrity file for FileNameBuffer (data source DataSourceId) with status Status.

Message #

The filter failed to open the integrity file for %2 (data source %3) with status %4.

Fields #

NameDescription
FileNameLength UInt16
FileNameBuffer UnicodeString
DataSourceId Int64
Status HexInt32NTSTATUS reference

Event ID 24833: The filter failed to validate block BlockNumber of length BlockLength from FileNameBuffer.

#
Provider
Microsoft-Windows-OverlayFilter
Channel
System
Task
WIMintegrityverification
Opcode
IntegrityBlockVerificationFailure

Description

The filter failed to validate block BlockNumber of length BlockLength from FileNameBuffer.

Message #

The filter failed to validate block %3 of length %4 from %2.

Fields #

NameDescription
FileNameLength UInt16
FileNameBuffer UnicodeString
BlockNumber UInt32
BlockLength UInt32

Event ID 24834: The filter failed to validate a read from FileNameBuffer at file offset FileOffset of length ReadSize.

#
Provider
Microsoft-Windows-OverlayFilter
Channel
System
Task
WIMintegrityverification
Opcode
IntegrityInvalidBlock

Description

The filter failed to validate a read from FileNameBuffer at file offset FileOffset of length ReadSize.

Message #

The filter failed to validate a read from %2 at file offset %3 of length %4.

Fields #

NameDescription
FileNameLength UInt16
FileNameBuffer UnicodeString
FileOffset Int64
ReadSize UInt32

Event ID 24835: The task is enumerating Volume volume.

#
Provider
Microsoft-Windows-OverlayFilter
Channel
System
Task
TheWindowsOverlayTask
Opcode
EnumVolume

Description

The task is enumerating Volume volume.

Message #

The task is enumerating Volume %1

Fields #

NameDescription
volume UnicodeString

Event ID 24836: The task has failed to report integrity file generation completion to BitLocker.

#
Provider
Microsoft-Windows-OverlayFilter
Channel
System
Task
TheWindowsOverlayTask
Opcode
ReportHashGenerationToBitlockerError

Description

The task has failed to report integrity file generation completion to BitLocker. HRESULT = hr.

Message #

The task has failed to report integrity file generation completion to BitLocker. HRESULT = %1

Fields #

NameDescription
hr UInt32

Event ID 24837: The task has created integrity file wimHashFile for file wimFile.

#
Provider
Microsoft-Windows-OverlayFilter
Channel
System
Task
TheWindowsOverlayTask
Opcode
CreateHashFile

Description

The task has created integrity file wimHashFile for file wimFile.

Message #

The task has created integrity file %1 for file %2

Fields #

NameDescription
wimHashFile UnicodeString
wimFile UnicodeString

Event ID 24838: The task has completed generation of integrity file wimHashFile for file wimFile.

#
Provider
Microsoft-Windows-OverlayFilter
Channel
System
Task
TheWindowsOverlayTask
Opcode
CompleteHashFile

Description

The task has completed generation of integrity file wimHashFile for file wimFile.

Message #

The task has completed generation of integrity file %1 for file %2

Fields #

NameDescription
wimHashFile UnicodeString
wimFile UnicodeString

Event ID 24839: The task has deleted integrity file wimHashFile for file wimFile.

#
Provider
Microsoft-Windows-OverlayFilter
Channel
System
Task
TheWindowsOverlayTask
Opcode
DeleteHashFile

Description

The task has deleted integrity file wimHashFile for file wimFile.

Message #

The task has deleted integrity file %1 for file %2

Fields #

NameDescription
wimHashFile UnicodeString
wimFile UnicodeString

Event ID 24840: The task is resuming generation of integrity file filename at file offset offset.

#
Provider
Microsoft-Windows-OverlayFilter
Channel
System
Task
TheWindowsOverlayTask
Opcode
ResumeHashFile

Description

The task is resuming generation of integrity file filename at file offset offset.

Message #

The task is resuming generation of integrity file %1 at file offset %2

Fields #

NameDescription
filename UnicodeString
offset UInt64

Event ID 24841: The task has paused generation of integrity file filename at file offset offset.

#
Provider
Microsoft-Windows-OverlayFilter
Channel
System
Task
TheWindowsOverlayTask
Opcode
PauseHashFile

Description

The task has paused generation of integrity file filename at file offset offset.

Message #

The task has paused generation of integrity file %1 at file offset %2

Fields #

NameDescription
filename UnicodeString
offset UInt64

Event ID 24842: The task has failed to identify encryption/decryption state.

#
Provider
Microsoft-Windows-OverlayFilter
Channel
System
Task
TheWindowsOverlayTask
Opcode
ActionError

Description

The task has failed to identify encryption/decryption state. HRESULT = hr.

Message #

The task has failed to identify encryption/decryption state. HRESULT = %1

Fields #

NameDescription
hr UInt32

Event ID 24843: The task has failed to generate integrity file wimHashFile for file wimFile.

#
Provider
Microsoft-Windows-OverlayFilter
Channel
System
Task
TheWindowsOverlayTask
Opcode
GenerateHashFileError

Description

The task has failed to generate integrity file wimHashFile for file wimFile. HRESULT = hr.

Message #

The task has failed to generate integrity file %1 for file %2. HRESULT = %3

Fields #

NameDescription
wimHashFile UnicodeString
wimFile UnicodeString
hr Int32

Event ID 24844: The task has failed to delete integrity file wimHashFile for file wimFile.

#
Provider
Microsoft-Windows-OverlayFilter
Channel
System
Task
TheWindowsOverlayTask
Opcode
DeleteHashFileError

Description

The task has failed to delete integrity file wimHashFile for file wimFile. HRESULT = hr.

Message #

The task has failed to delete integrity file %1 for file %2. HRESULT = %3

Fields #

NameDescription
wimHashFile UnicodeString
wimFile UnicodeString
hr Int32

Event ID 24845: The task has failed to read file at wimHashFile.

#
Provider
Microsoft-Windows-OverlayFilter
Channel
System
Task
TheWindowsOverlayTask
Opcode
FileReadError

Description

The task has failed to read file at wimHashFile. HRESULT = hr.

Message #

The task has failed to read file at %1. HRESULT = %3

Fields #

NameDescription
wimHashFile UnicodeString
wimFile UnicodeString
hr Int32

Event ID 24846: The task has failed to write file at wimHashFile.

#
Provider
Microsoft-Windows-OverlayFilter
Channel
System
Task
TheWindowsOverlayTask
Opcode
FileWriteError

Description

The task has failed to write file at wimHashFile. HRESULT = hr.

Message #

The task has failed to write file at %1. HRESULT = %3

Fields #

NameDescription
wimHashFile UnicodeString
wimFile UnicodeString
hr Int32

Event ID 24847: The filter opened the integrity file for FileNameBuffer (data source DataSourceId).

#
Provider
Microsoft-Windows-OverlayFilter
Channel
System
Task
WIMintegrityverification
Opcode
IntegrityFileOpen

Description

The filter opened the integrity file for FileNameBuffer (data source DataSourceId).

Message #

The filter opened the integrity file for %2 (data source %3).

Fields #

NameDescription
FileNameLength UInt16
FileNameBuffer UnicodeString
DataSourceId Int64

Event ID 24848: The filter did not open the integrity file for FileNameBuffer (data source DataSourceId) because it is not ready.

#
Provider
Microsoft-Windows-OverlayFilter
Channel
System
Task
WIMintegrityverification
Opcode
IntegrityFileOpen

Description

The filter did not open the integrity file for FileNameBuffer (data source DataSourceId) because it is not ready.

Message #

The filter did not open the integrity file for %2 (data source %3) because it is not ready.

Fields #

NameDescription
FileNameLength UInt16
FileNameBuffer UnicodeString
DataSourceId Int64

Event ID 24849: The task is generating integrity files

#
Provider
Microsoft-Windows-OverlayFilter
Channel
System
Task
TheWindowsOverlayTask
Opcode
ActionGenerateHashes

Description

The task is generating integrity files.

Message #

The task is generating integrity files

Event ID 24850: The task is deleting integrity files

#
Provider
Microsoft-Windows-OverlayFilter
Channel
System
Task
TheWindowsOverlayTask
Opcode
ActionDeleteHashes

Description

The task is deleting integrity files.

Message #

The task is deleting integrity files

Provenance

Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.

ETW provider GUID 46c78e5c-a213-46a8-8a6b-622f6916201d

Defined in wof.sys, the binary that emits these events.

Observed on:

  • WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.1, captured 2026-06-02
  • Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.1, captured 2026-06-02

Downloads