Microsoft-Windows-Remotefs-Rdbss
24 events across 2 channels
Event ID 100: RDBSS Name Canonicalize Error: RDBSS_Name_Canonicalize_Error Location: Location Context: Context.
#Event ID 401: Create VNetRoot Error: Create_VNetRoot_Error Location: Location Context: Context.
#Event ID 30001: Irp request: Irp Irp RxContext RxContext Fcb Fcb Fobx Fobx FileObject FileObject FileName FileName MajorFunction MajorFunction.
#Description
Irp request: Irp Irp RxContext RxContext Fcb Fcb Fobx Fobx FileObject FileObject FileName FileName MajorFunction MajorFunction.
Message #
Fields #
| Name | Description |
|---|---|
Irp Pointer | |
RxContext Pointer | |
Fcb Pointer | |
Fobx Pointer | |
FileObject Pointer | |
FileNameLength UInt16 | |
FileName UnicodeString | |
MajorFunction UInt16 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Remotefs-Rdbss",
"guid": "{1A870028-F191-4699-8473-6FCD299EAB77}",
"event_source_name": "",
"event_id": 30001,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": "0x4000000000000003",
"time_created": "2026-06-02T06:01:00.012+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{72529F65-EE0F-0003-6DCB-7B720FEEDC01}"
},
"execution": {
"process_id": 3824,
"thread_id": 14624
},
"channel": "ETW Trace",
"computer": "DESKTOP-FF3N5XK",
"security": {
"user_id": ""
}
},
"event_data": {
"Fcb": "0xFFFFF80065CCA7C0",
"FileName": "",
"FileNameLength": 0,
"FileObject": "0xFFFFBD09EC3CA780",
"Fobx": "0x0",
"Irp": "0xFFFFBD09F35DFAE0",
"MajorFunction": 14,
"RxContext": "0xFFFFBD09DF692010"
},
"message": ""
}
Event ID 30002: Irp request completion: Irp Irp RxContext RxContext Fcb Fcb Fobx Fobx FileObject FileObject FileName FileName MajorFunction MajorFunction Status Status.
#Description
Irp request completion: Irp Irp RxContext RxContext Fcb Fcb Fobx Fobx FileObject FileObject FileName FileName MajorFunction MajorFunction Status Status.
Message #
Fields #
| Name | Description |
|---|---|
Irp Pointer | |
RxContext Pointer | |
Fcb Pointer | |
Fobx Pointer | |
FileObject Pointer | |
FileNameLength UInt16 | |
FileName UnicodeString | |
MajorFunction UInt16 | |
Status UInt32 | NTSTATUS reference |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Remotefs-Rdbss",
"guid": "{1A870028-F191-4699-8473-6FCD299EAB77}",
"event_source_name": "",
"event_id": 30002,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": "0x4000000000000003",
"time_created": "2026-06-02T06:01:00.012+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{72529F65-EE0F-0003-6DCB-7B720FEEDC01}"
},
"execution": {
"process_id": 3824,
"thread_id": 14624
},
"channel": "ETW Trace",
"computer": "DESKTOP-FF3N5XK",
"security": {
"user_id": ""
}
},
"event_data": {
"Fcb": "0xFFFFF80065CCA7C0",
"FileName": "",
"FileNameLength": 0,
"FileObject": "0xFFFFBD09EC3CA780",
"Fobx": "0x0",
"Irp": "0xFFFFBD09F35DFAE0",
"MajorFunction": 14,
"RxContext": "0xFFFFBD09DF692010",
"Status": 3221226099
},
"message": ""
}
Event ID 30003: FastIo request: FileObject FileObject FileName FileName MajorFunction MajorFunction.
#Event ID 30004: FastIo completion: FileObject FileObject FileName FileName MajorFunction MajorFunction Status Status.
#Description
FastIo completion: FileObject FileObject FileName FileName MajorFunction MajorFunction Status Status.
Message #
Fields #
| Name | Description |
|---|---|
FileObject Pointer | |
FileNameLength UInt16 | |
FileName UnicodeString | |
MajorFunction UInt16 | |
Status UInt32 | NTSTATUS reference |
Event ID 30005: Csc request: RxContext RxContext.
#Event ID 30006: Csc completion: RxContext RxContext Status Status.
#Description
Csc completion: RxContext RxContext Status Status.
Message #
Fields #
| Name | Description |
|---|---|
RxContext Pointer | |
Status UInt32 | NTSTATUS reference |
Event ID 30007: Acquire Fcb: RxContext RxContext Fcb Fcb Mode Mode.
#Event ID 30008: Acquire Fcb completion: RxContext RxContext Fcb Fcb.
#Event ID 30009: Cc read request: RxContext RxContext FileObject FileObject.
#Event ID 30010: Cc read completion: RxContext RxContext FileObject FileObject Status Status.
#Description
Cc read completion: RxContext RxContext FileObject FileObject Status Status.
Message #
Fields #
| Name | Description |
|---|---|
RxContext Pointer | |
FileObject Pointer | |
Status UInt32 | NTSTATUS reference |
Event ID 30011: Cc write request: RxContext RxContext FileObject FileObject.
#Event ID 30012: Cc write completion: RxContext RxContext FileObject FileObject Status Status.
#Description
Cc write completion: RxContext RxContext FileObject FileObject Status Status.
Message #
Fields #
| Name | Description |
|---|---|
RxContext Pointer | |
FileObject Pointer | |
Status UInt32 | NTSTATUS reference |
Event ID 30013: Cc uninitialize cache map request: RxContext RxContext FileObject FileObject.
#Event ID 30014: Cc uninitialize cache map completion: RxContext RxContext FileObject FileObject Status Status.
#Description
Cc uninitialize cache map completion: RxContext RxContext FileObject FileObject Status Status.
Message #
Fields #
| Name | Description |
|---|---|
RxContext Pointer | |
FileObject Pointer | |
Status UInt32 | NTSTATUS reference |
Event ID 30015: Cc flush request: Fcb Fcb.
#Event ID 30016: Cc flush completion: Fcb Fcb.
#Event ID 30017: Cc purge request: Fcb Fcb.
#Event ID 30018: Cc purge completion: Fcb Fcb.
#Event ID 30019: Perform logical view migration: RxContext RxContext from (logical path LogicalPathFrom physical path PhysicalPathFrom) to (logical path LogicalPathTo physical path PhysicalPathTo).
#Description
Perform logical view migration: RxContext RxContext from (logical path LogicalPathFrom physical path PhysicalPathFrom) to (logical path LogicalPathTo physical path PhysicalPathTo).
Message #
Fields #
| Name | Description |
|---|---|
RxContext Pointer | |
LogicalPathFromLength UInt16 | |
LogicalPathFrom UnicodeString | |
PhysicalPathFromLength UInt16 | |
PhysicalPathFrom UnicodeString | |
LogicalPathToLength UInt16 | |
LogicalPathTo UnicodeString | |
PhysicalPathToLength UInt16 | |
PhysicalPathTo UnicodeString |
Event ID 30020: Logical view migration completion: RxContext RxContext from (logical path LogicalPathFrom physical path PhysicalPathFrom) to (logical path LogicalPathTo physical path PhysicalPathTo).
#Description
Logical view migration completion: RxContext RxContext from (logical path LogicalPathFrom physical path PhysicalPathFrom) to (logical path LogicalPathTo physical path PhysicalPathTo).
Message #
Fields #
| Name | Description |
|---|---|
RxContext Pointer | |
LogicalPathFromLength UInt16 | |
LogicalPathFrom UnicodeString | |
PhysicalPathFromLength UInt16 | |
PhysicalPathFrom UnicodeString | |
LogicalPathToLength UInt16 | |
LogicalPathTo UnicodeString | |
PhysicalPathToLength UInt16 | |
PhysicalPathTo UnicodeString |
Event ID 30301: Orphaning: Fcb Fcb SrvOpen SrvOpen Fobx Fobx.
#Event ID 30302: Delay close: Fcb Fcb SrvOpen SrvOpen Fobx Fobx.
#Provenance
Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.
ETW provider GUID {1A870028-F191-4699-8473-6FCD299EAB77}
Defined in rdbss.sys, the binary that emits these events.
Observed on:
- Win11-26200.6584, sample captured from a live trace, binary version 10.0.26100.1, captured 2026-06-02
- WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.3804, captured 2026-06-02
- Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.1, captured 2026-06-02