Microsoft-Windows-OverlayFilter
19 events across 1 channel
Event ID 24832: The filter failed to open the integrity file for FileNameBuffer (data source DataSourceId) with status Status.
#Description
The filter failed to open the integrity file for FileNameBuffer (data source DataSourceId) with status Status.
Message #
Fields #
| Name | Description |
|---|---|
FileNameLength UInt16 | |
FileNameBuffer UnicodeString | |
DataSourceId Int64 | |
Status HexInt32 | NTSTATUS reference |
Event ID 24833: The filter failed to validate block BlockNumber of length BlockLength from FileNameBuffer.
#Event ID 24834: The filter failed to validate a read from FileNameBuffer at file offset FileOffset of length ReadSize.
#Event ID 24835: The task is enumerating Volume volume.
#Event ID 24836: The task has failed to report integrity file generation completion to BitLocker.
#Event ID 24837: The task has created integrity file wimHashFile for file wimFile.
#Event ID 24838: The task has completed generation of integrity file wimHashFile for file wimFile.
#Event ID 24839: The task has deleted integrity file wimHashFile for file wimFile.
#Event ID 24840: The task is resuming generation of integrity file filename at file offset offset.
#Event ID 24841: The task has paused generation of integrity file filename at file offset offset.
#Event ID 24842: The task has failed to identify encryption/decryption state.
#Event ID 24843: The task has failed to generate integrity file wimHashFile for file wimFile.
#Event ID 24844: The task has failed to delete integrity file wimHashFile for file wimFile.
#Event ID 24845: The task has failed to read file at wimHashFile.
#Event ID 24846: The task has failed to write file at wimHashFile.
#Event ID 24847: The filter opened the integrity file for FileNameBuffer (data source DataSourceId).
#Event ID 24848: The filter did not open the integrity file for FileNameBuffer (data source DataSourceId) because it is not ready.
#Event ID 24849: The task is generating integrity files
#Description
The task is generating integrity files.
Message #
Event ID 24850: The task is deleting integrity files
#Description
The task is deleting integrity files.
Message #
Provenance
Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.
ETW provider GUID 46c78e5c-a213-46a8-8a6b-622f6916201d
Defined in wof.sys, the binary that emits these events.
Observed on:
- WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.1, captured 2026-06-02
- Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.1, captured 2026-06-02