Microsoft-Windows-Ras-NdisWanPacketCapture

3 events across 1 channel

EventTitleChannelSample
5001Sending NDIS Wan Packet (FragmentSize bytes).DiagnosticN
5002Reciving NDIS Wan Packet (FragmentSize bytes).DiagnosticN
5003Event.DiagnosticN

Event ID 5001: Sending NDIS Wan Packet (FragmentSize bytes).

#
Provider
Microsoft-Windows-Ras-NdisWanPacketCapture
Channel
Diagnostic
Opcode
Info

Description

Sending NDIS Wan Packet (FragmentSize bytes).

Message #

Sending NDIS Wan Packet (%3 bytes)

Fields #

NameDescription
RoutingDomainID UnicodeString
RRASUserName UnicodeString
FragmentSize UInt32
Fragment Binary

Event ID 5002: Reciving NDIS Wan Packet (FragmentSize bytes).

#
Provider
Microsoft-Windows-Ras-NdisWanPacketCapture
Channel
Diagnostic
Opcode
Info

Description

Reciving NDIS Wan Packet (FragmentSize bytes).

Message #

Reciving NDIS Wan Packet (%3 bytes)

Fields #

NameDescription
RoutingDomainID UnicodeString
RRASUserName UnicodeString
FragmentSize UInt32
Fragment Binary

Event ID 5003: Event.

#
Provider
Microsoft-Windows-Ras-NdisWanPacketCapture
Channel
Diagnostic
Opcode
Info

Description

Event: param1

Message #

Event: %1

Fields #

NameDescription
param1 UnicodeString

Provenance

Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.

ETW provider GUID d84521f7-2235-4237-a7c0-14e3a9676286

Defined in ndiswan.sys, the binary that emits these events.

Observed on:

  • WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.2849, captured 2026-06-02
  • Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.5074, captured 2026-06-02

Downloads