Microsoft-Windows-ResumeKeyFilter

EventTitleChannelSampleRule
1000The filter loaded successfully.OperationalYN
1001The filter was successfully attached to String.OperationalNN
1002The resume database for String was loaded successfully.OperationalNN
1003The filter received a dismount request for String.OperationalNN
1004The re-mount request for String completed successfully.OperationalNN
1005The filter was detached from String.OperationalNN
1006The filter unloaded.OperationalNN
1007The filter detected an incomplete failover recovery and purged the resume …OperationalNN
1008The filter failed to attach to a volume because the volume supports short names …OperationalNN
1010The filter detected that chkdsk has been run on volume String and has purged the …OperationalNN
1011The filter detected that a volume snap shot may have been restored on volume …OperationalNN
1100The creation of a bypass handle on file String completed successfully.AnalyticNN
1100Event ID 1100OperationalNN
1101The creation of a new resume handle Guid on file String completed successfully.AnalyticNN
1101Event ID 1101OperationalNN
1102The replay creation of resume handle Guid on file String completed successfully.AnalyticNN
1102Event ID 1102OperationalNN
1103The resume of handle Guid on file String started successfully.AnalyticNN
1103Event ID 1103OperationalNN
1104The resume of a handle on file name String1 was successfully reparsed to file …AnalyticNN
1104Event ID 1104OperationalNN
1105The resume of handle Guid on file String completed successfully.AnalyticNN
1105Event ID 1105OperationalNN
1110The resume handle Guid on file String was suspended.AnalyticNN
1110Event ID 1110OperationalNN
1111The resume handle ResumeKey on file String was timed out and cancelled.OperationalNN
1112The resume handle Guid on file String was cancelled successfully.AnalyticNN
1112Event ID 1112OperationalNN
1113The resume handle Guid on file String was closed.AnalyticNN
1113Event ID 1113OperationalNN
1114The deferred delete of file String completed successfully.AnalyticNN
1114Event ID 1114OperationalNN
1120The filter delayed the creation of a handle on file String1 because the resume …OperationalNN
1121The filter failed the creation of a handle on file String because the file has …OperationalNN
1122The filter failed the creation of a handle on file String because the file is …OperationalNN
1123The filter failed the creation of a handle on file String because the parent …OperationalNN
1124The filter failed the creation of a handle on file String because the parent …OperationalNN
1130The filter failed an oplock request on file String because the file has …AnalyticNN
1130Event ID 1130OperationalNN
1131The filter failed a write operation on file String because the file has …AnalyticNN
1131Event ID 1131OperationalNN
1132The filter failed a read operation on file String because the file has …AnalyticNN
1132Event ID 1132OperationalNN
1133The filter failed an exclusive byte range lock request on file String because …AnalyticNN
1133Event ID 1133OperationalNN
1134The filter failed a shared byte range lock request on file String because the …AnalyticNN
1134Event ID 1134OperationalNN
1135The filter failed the create of a hard link on file String because hard links …OperationalNN
1136The filter failed the rename of an alternate data stream on file String because …OperationalNN
1137The filter failed a rename replace to file String because this target file has …AnalyticNN
1137Event ID 1137OperationalNN
1138The filter failed a set end-of-file request on file String because the file has …AnalyticNN
1138Event ID 1138OperationalNN
1139The filter failed a set zero data request on file String because the file has …AnalyticNN
1139Event ID 1139OperationalNN
1140The filter failed a rename request on file String because the resume database …AnalyticNN
1140Event ID 1140OperationalNN
1141The filter failed a rename request on file String because the file has …AnalyticNN
1141Event ID 1141OperationalNN
1142The filter failed a copy offload read operation on file String because the file …AnalyticNN
1142Event ID 1142OperationalNN
1143The filter failed a copy offload write operation on file String because the file …AnalyticNN
1143Event ID 1143OperationalNN
1144The filter failed a file trim operation on file String because the file has …AnalyticNN
1144Event ID 1144OperationalNN
1145The filter failed a file set read only attribute operation on file String …AnalyticNN
1145Event ID 1145OperationalNN
1150The creation of a new resume handle on file String failed because the file has …OperationalNN
1151The creation of a new handle on file String failed because the supersede of a …OperationalNN
2000The filter failed to load with error status Status.OperationalNN
2001The filter failed to attach to String with error status Status.OperationalNN
2002The resume database for String failed to load with error status Status.OperationalNN
2004The re-mount request for String failed with error status Status.OperationalNN
2100The creation of a bypass handle on file String failed with error status Status.AnalyticNN
2100Event ID 2100OperationalNN
2101The creation of a new resume handle Guid on file String failed with error status …AnalyticNN
2101Event ID 2101OperationalNN
2102The replay creation of resume handle Guid on file String failed with error …AnalyticNN
2102Event ID 2102OperationalNN
2103The resume of handle Guid on file String failed with error status Status.OperationalNN
2104The resume of a handle on file name String1 failed to reparse to a valid file …OperationalNN
2112The resume handle Guid on file String failed to cancel with error status Status.AnalyticNN
2112Event ID 2112OperationalNN
2114The deferred delete of file String failed with error status Status.OperationalNN
4000Event ID 4000OperationalNN
4000Driver entry pre enter: FileObject FileObject (FileObjectName), MajorFunction …PerformanceNN
4001Event ID 4001OperationalNN
4001Driver entry pre exit: FileObject FileObject, MajorFunction MajorFunction …PerformanceNN
4002Event ID 4002OperationalNN
4002Driver entry post enter: FileObject FileObject, MajorFunction MajorFunction …PerformanceNN
4003Event ID 4003OperationalNN
4003Driver entry post exit: FileObject FileObject, MajorFunction MajorFunction …PerformanceNN
4010Event ID 4010OperationalNN
4010Log file enter: FileObject FileObject, MajorFunction MajorFunction …PerformanceNN
4011Event ID 4011OperationalNN
4011Log file exit: FileObject FileObject, MajorFunction MajorFunction …PerformanceNN

Event ID 1000: The filter loaded successfully.

#
Channel
Operational
Level
Informational

Fields #

NameDescription
Status UInt32NTSTATUS reference

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-ResumeKeyFilter",
    "guid": "{38EEA17B-DB1E-46FE-84D3-07034BEAAFD0}",
    "event_source_name": "",
    "event_id": 1000,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": -9223372036854775807,
    "time_created": "2026-05-30T02:30:35.6593862+00:00",
    "event_record_id": 1,
    "correlation": {},
    "execution": {
      "process_id": 4,
      "thread_id": 720
    },
    "channel": "Microsoft-Windows-ResumeKeyFilter/Operational",
    "computer": "JD-DC01-2022.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "Status": "0"
  },
  "message": "The filter loaded successfully."
}

Event ID 1001: The filter was successfully attached to String.

#
Channel
Operational

Message #

The filter was successfully attached to %2.

Fields #

NameDescription
StringLength UInt16
String UnicodeString
Status UInt32NTSTATUS reference

Event ID 1002: The resume database for String was loaded successfully.

#
Channel
Operational

Description

The resume database for String was loaded successfully. The load operation took Valuems to complete.

Message #

The resume database for %2 was loaded successfully. The load operation took %3ms to complete.

Fields #

NameDescription
StringLength UInt16
String UnicodeString
Value UInt32
Status UInt32NTSTATUS reference

Event ID 1003: The filter received a dismount request for String.

#
Channel
Operational

Message #

The filter received a dismount request for %2.

Fields #

NameDescription
StringLength UInt16
String UnicodeString
Status UInt32NTSTATUS reference

Event ID 1004: The re-mount request for String completed successfully.

#
Channel
Operational

Message #

The re-mount request for %2 completed successfully.

Fields #

NameDescription
StringLength UInt16
String UnicodeString
Status UInt32NTSTATUS reference

Event ID 1005: The filter was detached from String.

#
Channel
Operational

Message #

The filter was detached from %2.

Fields #

NameDescription
StringLength UInt16
String UnicodeString
Status UInt32NTSTATUS reference

Event ID 1006: The filter unloaded.

#
Channel
Operational

Fields #

NameDescription
Status UInt32NTSTATUS reference

Event ID 1007: The filter detected an incomplete failover recovery and purged the resume database for String.

#
Channel
Operational

Message #

The filter detected an incomplete failover recovery and purged the resume database for %2.

Fields #

NameDescription
StringLength UInt16
String UnicodeString
Status UInt32NTSTATUS reference

Event ID 1008: The filter failed to attach to a volume because the volume supports short names but the filter does not support short names.

#
Channel
Operational

Fields #

NameDescription
Status UInt32NTSTATUS reference

Event ID 1010: The filter detected that chkdsk has been run on volume String and has purged the resume database.

#
Channel
Operational

Message #

The filter detected that chkdsk has been run on volume %2 and has purged the resume database.

Fields #

NameDescription
StringLength UInt16
String UnicodeString
Status UInt32NTSTATUS reference

Event ID 1011: The filter detected that a volume snap shot may have been restored on volume String and has purged the resume database.

#
Channel
Operational

Message #

The filter detected that a volume snap shot may have been restored on volume %2 and has purged the resume database.

Fields #

NameDescription
StringLength UInt16
String UnicodeString
Status UInt32NTSTATUS reference

Event ID 1100: The creation of a bypass handle on file String completed successfully.

#
Channel
Analytic

Message #

The creation of a bypass handle on file %3 completed successfully.

Fields #

NameDescription
Guid GUID
StringLength UInt16
String UnicodeString
Value UInt32
Status UInt32NTSTATUS reference

Event ID 1100

#
Channel
Operational

Description

The creation of a bypass handle on file completed successfully.

Fields #

NameDescription
Guid GUID
StringLength UInt16
String UnicodeString
Value UInt32
Status UInt32NTSTATUS reference

Event ID 1101: The creation of a new resume handle Guid on file String completed successfully.

#
Channel
Analytic

Message #

The creation of a new resume handle %1 on file %3 completed successfully.

Fields #

NameDescription
Guid GUID
StringLength UInt16
String UnicodeString
Value UInt32
Status UInt32NTSTATUS reference

Event ID 1101

#
Channel
Operational

Description

The creation of a new resume handle on file completed successfully.

Fields #

NameDescription
Guid GUID
StringLength UInt16
String UnicodeString
Value UInt32
Status UInt32NTSTATUS reference

Event ID 1102: The replay creation of resume handle Guid on file String completed successfully.

#
Channel
Analytic

Message #

The replay creation of resume handle %1 on file %3 completed successfully.

Fields #

NameDescription
Guid GUID
StringLength UInt16
String UnicodeString
Value UInt32
Status UInt32NTSTATUS reference

Event ID 1102

#
Channel
Operational

Description

The replay creation of resume handle on file completed successfully.

Fields #

NameDescription
Guid GUID
StringLength UInt16
String UnicodeString
Value UInt32
Status UInt32NTSTATUS reference

Event ID 1103: The resume of handle Guid on file String started successfully.

#
Channel
Analytic

Message #

The resume of handle %1 on file %3 started successfully.

Fields #

NameDescription
Guid GUID
StringLength UInt16
String UnicodeString
Value UInt32
Status UInt32NTSTATUS reference

Event ID 1103

#
Channel
Operational

Description

The resume of handle on file started successfully.

Fields #

NameDescription
Guid GUID
StringLength UInt16
String UnicodeString
Value UInt32
Status UInt32NTSTATUS reference

Event ID 1104: The resume of a handle on file name String1 was successfully reparsed to file name String2.

#
Channel
Analytic

Message #

The resume of a handle on file name %2 was successfully reparsed to file name %4.

Fields #

NameDescription
String1Length UInt16
String1 UnicodeString
String2Length UInt16
String2 UnicodeString
Status UInt32NTSTATUS reference

Event ID 1104

#
Channel
Operational

Description

The resume of a handle on file name was successfully reparsed to file name .

Fields #

NameDescription
String1Length UInt16
String1 UnicodeString
String2Length UInt16
String2 UnicodeString
Status UInt32NTSTATUS reference

Event ID 1105: The resume of handle Guid on file String completed successfully.

#
Channel
Analytic

Message #

The resume of handle %1 on file %3 completed successfully.

Fields #

NameDescription
Guid GUID
StringLength UInt16
String UnicodeString
Value UInt32
Status UInt32NTSTATUS reference

Event ID 1105

#
Channel
Operational

Description

The resume of handle on file completed successfully.

Fields #

NameDescription
Guid GUID
StringLength UInt16
String UnicodeString
Value UInt32
Status UInt32NTSTATUS reference

Event ID 1110: The resume handle Guid on file String was suspended.

#
Channel
Analytic

Message #

The resume handle %1 on file %3 was suspended.

Fields #

NameDescription
Guid GUID
StringLength UInt16
String UnicodeString
Value UInt32
Status UInt32NTSTATUS reference

Event ID 1110

#
Channel
Operational

Description

The resume handle on file was suspended.

Fields #

NameDescription
Guid GUID
StringLength UInt16
String UnicodeString
Value UInt32
Status UInt32NTSTATUS reference

Event ID 1111: The resume handle ResumeKey on file String was timed out and cancelled.

#
Channel
Operational

Message #

The resume handle %1 on file %3 was timed out and cancelled.

Fields #

NameDescription
ResumeKey GUID
StringLength UInt16
String UnicodeString
Value UInt32
Status UInt32NTSTATUS reference
RfsKey GUID
NodeId GUID
AppId GUID
DesiredAccess UInt32Process access rights reference
ShareMode UInt32
CreateOptions UInt32
FileAttribs UInt32
CreateDisp UInt32

Event ID 1112: The resume handle Guid on file String was cancelled successfully.

#
Channel
Analytic

Message #

The resume handle %1 on file %3 was cancelled successfully.

Fields #

NameDescription
Guid GUID
StringLength UInt16
String UnicodeString
Value UInt32
Status UInt32NTSTATUS reference

Event ID 1112

#
Channel
Operational

Description

The resume handle on file was cancelled successfully.

Fields #

NameDescription
Guid GUID
StringLength UInt16
String UnicodeString
Value UInt32
Status UInt32NTSTATUS reference

Event ID 1113: The resume handle Guid on file String was closed.

#
Channel
Analytic

Message #

The resume handle %1 on file %3 was closed.

Fields #

NameDescription
Guid GUID
StringLength UInt16
String UnicodeString
Value UInt32
Status UInt32NTSTATUS reference

Event ID 1113

#
Channel
Operational

Description

The resume handle on file was closed.

Fields #

NameDescription
Guid GUID
StringLength UInt16
String UnicodeString
Value UInt32
Status UInt32NTSTATUS reference

Event ID 1114: The deferred delete of file String completed successfully.

#
Channel
Analytic

Message #

The deferred delete of file %2 completed successfully.

Fields #

NameDescription
StringLength UInt16
String UnicodeString
Status UInt32NTSTATUS reference

Event ID 1114

#
Channel
Operational

Description

The deferred delete of file completed successfully.

Fields #

NameDescription
StringLength UInt16
String UnicodeString
Status UInt32NTSTATUS reference

Event ID 1120: The filter delayed the creation of a handle on file String1 because the resume database for the volume was still loading.

#
Channel
Operational

Message #

The filter delayed the creation of a handle on file %2 because the resume database for the volume was still loading.

Fields #

NameDescription
String1Length UInt16
String1 UnicodeString
String2Length UInt16
String2 UnicodeString
Status UInt32NTSTATUS reference

Event ID 1121: The filter failed the creation of a handle on file String because the file has pending resume handles.

#
Channel
Operational

Message #

The filter failed the creation of a handle on file %2 because the file has pending resume handles.

Fields #

NameDescription
StringLength UInt16
String UnicodeString
Status UInt32NTSTATUS reference

Event ID 1122: The filter failed the creation of a handle on file String because the file is delete pending.

#
Channel
Operational

Message #

The filter failed the creation of a handle on file %2 because the file is delete pending.

Fields #

NameDescription
StringLength UInt16
String UnicodeString
Status UInt32NTSTATUS reference

Event ID 1123: The filter failed the creation of a handle on file String because the parent directory has pending resume handles.

#
Channel
Operational

Message #

The filter failed the creation of a handle on file %2 because the parent directory has pending resume handles.

Fields #

NameDescription
StringLength UInt16
String UnicodeString
Status UInt32NTSTATUS reference

Event ID 1124: The filter failed the creation of a handle on file String because the parent directory is delete pending.

#
Channel
Operational

Message #

The filter failed the creation of a handle on file %2 because the parent directory is delete pending.

Fields #

NameDescription
StringLength UInt16
String UnicodeString
Status UInt32NTSTATUS reference

Event ID 1130: The filter failed an oplock request on file String because the file has conflicting pending resume handles.

#
Channel
Analytic

Message #

The filter failed an oplock request on file %2 because the file has conflicting pending resume handles.

Fields #

NameDescription
StringLength UInt16
String UnicodeString
Status UInt32NTSTATUS reference

Event ID 1130

#
Channel
Operational

Description

The filter failed an oplock request on file because the file has conflicting pending resume handles.

Fields #

NameDescription
StringLength UInt16
String UnicodeString
Status UInt32NTSTATUS reference

Event ID 1131: The filter failed a write operation on file String because the file has conflicting pending resume handles.

#
Channel
Analytic

Message #

The filter failed a write operation on file %2 because the file has conflicting pending resume handles.

Fields #

NameDescription
StringLength UInt16
String UnicodeString
Status UInt32NTSTATUS reference

Event ID 1131

#
Channel
Operational

Description

The filter failed a write operation on file because the file has conflicting pending resume handles.

Fields #

NameDescription
StringLength UInt16
String UnicodeString
Status UInt32NTSTATUS reference

Event ID 1132: The filter failed a read operation on file String because the file has conflicting pending resume handles.

#
Channel
Analytic

Message #

The filter failed a read operation on file %2 because the file has conflicting pending resume handles.

Fields #

NameDescription
StringLength UInt16
String UnicodeString
Status UInt32NTSTATUS reference

Event ID 1132

#
Channel
Operational

Description

The filter failed a read operation on file because the file has conflicting pending resume handles.

Fields #

NameDescription
StringLength UInt16
String UnicodeString
Status UInt32NTSTATUS reference

Event ID 1133: The filter failed an exclusive byte range lock request on file String because the file has conflicting pending resume handles.

#
Channel
Analytic

Message #

The filter failed an exclusive byte range lock request on file %2 because the file has conflicting pending resume handles.

Fields #

NameDescription
StringLength UInt16
String UnicodeString
Status UInt32NTSTATUS reference

Event ID 1133

#
Channel
Operational

Description

The filter failed an exclusive byte range lock request on file because the file has conflicting pending resume handles.

Fields #

NameDescription
StringLength UInt16
String UnicodeString
Status UInt32NTSTATUS reference

Event ID 1134: The filter failed a shared byte range lock request on file String because the file has conflicting pending resume handles.

#
Channel
Analytic

Message #

The filter failed a shared byte range lock request on file %2 because the file has conflicting pending resume handles.

Fields #

NameDescription
StringLength UInt16
String UnicodeString
Status UInt32NTSTATUS reference

Event ID 1134

#
Channel
Operational

Description

The filter failed a shared byte range lock request on file because the file has conflicting pending resume handles.

Fields #

NameDescription
StringLength UInt16
String UnicodeString
Status UInt32NTSTATUS reference

Event ID 1135: The filter failed the create of a hard link on file String because hard links are not supported.

#
Channel
Operational

Message #

The filter failed the create of a hard link on file %2 because hard links are not supported.

Fields #

NameDescription
StringLength UInt16
String UnicodeString
Status UInt32NTSTATUS reference

Event ID 1136: The filter failed the rename of an alternate data stream on file String because rename of alternate data streams is not supported.

#
Channel
Operational

Message #

The filter failed the rename of an alternate data stream on file %2 because rename of alternate data streams is not supported.

Fields #

NameDescription
StringLength UInt16
String UnicodeString
Status UInt32NTSTATUS reference

Event ID 1137: The filter failed a rename replace to file String because this target file has conflicting pending resume handles.

#
Channel
Analytic

Message #

The filter failed a rename replace to file %2 because this target file has conflicting pending resume handles.

Fields #

NameDescription
StringLength UInt16
String UnicodeString
Status UInt32NTSTATUS reference

Event ID 1137

#
Channel
Operational

Description

The filter failed a rename replace to file because this target file has conflicting pending resume handles.

Fields #

NameDescription
StringLength UInt16
String UnicodeString
Status UInt32NTSTATUS reference

Event ID 1138: The filter failed a set end-of-file request on file String because the file has conflicting pending resume handles.

#
Channel
Analytic

Message #

The filter failed a set end-of-file request on file %2 because the file has conflicting pending resume handles.

Fields #

NameDescription
StringLength UInt16
String UnicodeString
Status UInt32NTSTATUS reference

Event ID 1138

#
Channel
Operational

Description

The filter failed a set end-of-file request on file because the file has conflicting pending resume handles.

Fields #

NameDescription
StringLength UInt16
String UnicodeString
Status UInt32NTSTATUS reference

Event ID 1139: The filter failed a set zero data request on file String because the file has conflicting pending resume handles.

#
Channel
Analytic

Message #

The filter failed a set zero data request on file %2 because the file has conflicting pending resume handles.

Fields #

NameDescription
StringLength UInt16
String UnicodeString
Status UInt32NTSTATUS reference

Event ID 1139

#
Channel
Operational

Description

The filter failed a set zero data request on file because the file has conflicting pending resume handles.

Fields #

NameDescription
StringLength UInt16
String UnicodeString
Status UInt32NTSTATUS reference

Event ID 1140: The filter failed a rename request on file String because the resume database was still being processed.

#
Channel
Analytic

Message #

The filter failed a rename request on file %2 because the resume database was still being processed.

Fields #

NameDescription
StringLength UInt16
String UnicodeString
Status UInt32NTSTATUS reference

Event ID 1140

#
Channel
Operational

Description

The filter failed a rename request on file because the resume database was still being processed.

Fields #

NameDescription
StringLength UInt16
String UnicodeString
Status UInt32NTSTATUS reference

Event ID 1141: The filter failed a rename request on file String because the file has conflicting pending resume handles.

#
Channel
Analytic

Message #

The filter failed a rename request on file %2 because the file has conflicting pending resume handles.

Fields #

NameDescription
StringLength UInt16
String UnicodeString
Status UInt32NTSTATUS reference

Event ID 1141

#
Channel
Operational

Description

The filter failed a rename request on file because the file has conflicting pending resume handles.

Fields #

NameDescription
StringLength UInt16
String UnicodeString
Status UInt32NTSTATUS reference

Event ID 1142: The filter failed a copy offload read operation on file String because the file has conflicting pending resume handles.

#
Channel
Analytic

Message #

The filter failed a copy offload read operation on file %2 because the file has conflicting pending resume handles.

Fields #

NameDescription
StringLength UInt16
String UnicodeString
Status UInt32NTSTATUS reference

Event ID 1142

#
Channel
Operational

Description

The filter failed a copy offload read operation on file because the file has conflicting pending resume handles.

Fields #

NameDescription
StringLength UInt16
String UnicodeString
Status UInt32NTSTATUS reference

Event ID 1143: The filter failed a copy offload write operation on file String because the file has conflicting pending resume handles.

#
Channel
Analytic

Message #

The filter failed a copy offload write operation on file %2 because the file has conflicting pending resume handles.

Fields #

NameDescription
StringLength UInt16
String UnicodeString
Status UInt32NTSTATUS reference

Event ID 1143

#
Channel
Operational

Description

The filter failed a copy offload write operation on file because the file has conflicting pending resume handles.

Fields #

NameDescription
StringLength UInt16
String UnicodeString
Status UInt32NTSTATUS reference

Event ID 1144: The filter failed a file trim operation on file String because the file has conflicting pending resume handles.

#
Channel
Analytic

Message #

The filter failed a file trim operation on file %2 because the file has conflicting pending resume handles.

Fields #

NameDescription
StringLength UInt16
String UnicodeString
Status UInt32NTSTATUS reference

Event ID 1144

#
Channel
Operational

Description

The filter failed a file trim operation on file because the file has conflicting pending resume handles.

Fields #

NameDescription
StringLength UInt16
String UnicodeString
Status UInt32NTSTATUS reference

Event ID 1145: The filter failed a file set read only attribute operation on file String because the file has conflicting pending resume handles.

#
Channel
Analytic

Message #

The filter failed a file set read only attribute operation on file %2 because the file has conflicting pending resume handles.

Fields #

NameDescription
StringLength UInt16
String UnicodeString
Status UInt32NTSTATUS reference

Event ID 1145

#
Channel
Operational

Description

The filter failed a file set read only attribute operation on file because the file has conflicting pending resume handles.

Fields #

NameDescription
StringLength UInt16
String UnicodeString
Status UInt32NTSTATUS reference

Event ID 1150: The creation of a new resume handle on file String failed because the file has hard links.

#
Channel
Operational

Message #

The creation of a new resume handle on file %2 failed because the file has hard links.

Fields #

NameDescription
StringLength UInt16
String UnicodeString
Status UInt32NTSTATUS reference

Event ID 1151: The creation of a new handle on file String failed because the supersede of a file that has open resume handles on Alternate Data Streams is not suppor...

#
Channel
Operational

Description

The creation of a new handle on file String failed because the supersede of a file that has open resume handles on Alternate Data Streams is not supported.

Message #

The creation of a new handle on file %2 failed because the supersede of a file that has open resume handles on Alternate Data Streams is not supported.

Fields #

NameDescription
StringLength UInt16
String UnicodeString
Status UInt32NTSTATUS reference

Event ID 2000: The filter failed to load with error status Status.

#
Channel
Operational

Message #

The filter failed to load with error status %1.

Fields #

NameDescription
Status UInt32NTSTATUS reference

Event ID 2001: The filter failed to attach to String with error status Status.

#
Channel
Operational

Message #

The filter failed to attach to %2 with error status %3.

Fields #

NameDescription
StringLength UInt16
String UnicodeString
Status UInt32NTSTATUS reference

Event ID 2002: The resume database for String failed to load with error status Status.

#
Channel
Operational

Description

The resume database for String failed to load with error status Status. The load operation took Valuems to complete.

Message #

The resume database for %2 failed to load with error status %4. The load operation took %3ms to complete.

Fields #

NameDescription
StringLength UInt16
String UnicodeString
Value UInt32
Status UInt32NTSTATUS reference

Event ID 2004: The re-mount request for String failed with error status Status.

#
Channel
Operational

Message #

The re-mount request for %2 failed with error status %3.

Fields #

NameDescription
StringLength UInt16
String UnicodeString
Status UInt32NTSTATUS reference

Event ID 2100: The creation of a bypass handle on file String failed with error status Status.

#
Channel
Analytic

Message #

The creation of a bypass handle on file %3 failed with error status %5.

Fields #

NameDescription
Guid GUID
StringLength UInt16
String UnicodeString
Value UInt32
Status UInt32NTSTATUS reference

Event ID 2100

#
Channel
Operational

Description

The creation of a bypass handle on file failed with error status .

Fields #

NameDescription
Guid GUID
StringLength UInt16
String UnicodeString
Value UInt32
Status UInt32NTSTATUS reference

Event ID 2101: The creation of a new resume handle Guid on file String failed with error status Status.

#
Channel
Analytic

Message #

The creation of a new resume handle %1 on file %3 failed with error status %5.

Fields #

NameDescription
Guid GUID
StringLength UInt16
String UnicodeString
Value UInt32
Status UInt32NTSTATUS reference

Event ID 2101

#
Channel
Operational

Description

The creation of a new resume handle on file failed with error status .

Fields #

NameDescription
Guid GUID
StringLength UInt16
String UnicodeString
Value UInt32
Status UInt32NTSTATUS reference

Event ID 2102: The replay creation of resume handle Guid on file String failed with error status Status.

#
Channel
Analytic

Message #

The replay creation of resume handle %1 on file %3 failed with error status %5.

Fields #

NameDescription
Guid GUID
StringLength UInt16
String UnicodeString
Value UInt32
Status UInt32NTSTATUS reference

Event ID 2102

#
Channel
Operational

Description

The replay creation of resume handle on file failed with error status .

Fields #

NameDescription
Guid GUID
StringLength UInt16
String UnicodeString
Value UInt32
Status UInt32NTSTATUS reference

Event ID 2103: The resume of handle Guid on file String failed with error status Status.

#
Channel
Operational

Message #

The resume of handle %1 on file %3 failed with error status %5.

Fields #

NameDescription
Guid GUID
StringLength UInt16
String UnicodeString
Value UInt32
Status UInt32NTSTATUS reference

Event ID 2104: The resume of a handle on file name String1 failed to reparse to a valid file name with error status Status.

#
Channel
Operational

Message #

The resume of a handle on file name %2 failed to reparse to a valid file name with error status %5.

Fields #

NameDescription
String1Length UInt16
String1 UnicodeString
String2Length UInt16
String2 UnicodeString
Status UInt32NTSTATUS reference

Event ID 2112: The resume handle Guid on file String failed to cancel with error status Status.

#
Channel
Analytic

Message #

The resume handle %1 on file %3 failed to cancel with error status %5.

Fields #

NameDescription
Guid GUID
StringLength UInt16
String UnicodeString
Value UInt32
Status UInt32NTSTATUS reference

Event ID 2112

#
Channel
Operational

Description

The resume handle on file failed to cancel with error status .

Fields #

NameDescription
Guid GUID
StringLength UInt16
String UnicodeString
Value UInt32
Status UInt32NTSTATUS reference

Event ID 2114: The deferred delete of file String failed with error status Status.

#
Channel
Operational

Message #

The deferred delete of file %2 failed with error status %3.

Fields #

NameDescription
StringLength UInt16
String UnicodeString
Status UInt32NTSTATUS reference

Event ID 4000

#
Channel
Operational

Description

Driver entry pre enter: FileObject (), MajorFunction (), MinorFunction , ControlCode.

Fields #

NameDescription
FileObject UInt64
FileObjectNameLength UInt16
FileObjectName UnicodeString
MajorFunction UInt8
MajorFunctionName AnsiString
MinorFunction UInt8
ControlCode UInt32

Event ID 4000: Driver entry pre enter: FileObject FileObject (FileObjectName), MajorFunction MajorFunction (MajorFunctionName), MinorFunction MinorFunction, ControlCode ControlCode.

#
Channel
Performance

Message #

Driver entry pre enter: FileObject %1 (%3), MajorFunction %4 (%5), MinorFunction %6, ControlCode %7

Fields #

NameDescription
FileObject UInt64
FileObjectNameLength UInt16
FileObjectName UnicodeString
MajorFunction UInt8
MajorFunctionName AnsiString
MinorFunction UInt8
ControlCode UInt32

Event ID 4001

#
Channel
Operational

Description

Driver entry pre exit: FileObject , MajorFunction (), MinorFunction , ControlCode , Status , IoStatus , IoInformation , FltStatus.

Fields #

NameDescription
FileObject UInt64
MajorFunction UInt8
MajorFunctionName AnsiString
MinorFunction UInt8
ControlCode UInt32
Status UInt32NTSTATUS reference
IoStatus UInt32
IoInformation UInt64
FltStatus UInt32

Event ID 4001: Driver entry pre exit: FileObject FileObject, MajorFunction MajorFunction (MajorFunctionName), MinorFunction MinorFunction, ControlCode ControlCode, Status Status, IoStatus IoStatus, IoInformation ...

#
Channel
Performance

Description

Driver entry pre exit: FileObject FileObject, MajorFunction MajorFunction (MajorFunctionName), MinorFunction MinorFunction, ControlCode ControlCode, Status Status, IoStatus IoStatus, IoInformation IoInformation, FltStatus FltStatus.

Message #

Driver entry pre exit: FileObject %1, MajorFunction %2 (%3), MinorFunction %4, ControlCode %5, Status %6, IoStatus %7, IoInformation %8, FltStatus %9

Fields #

NameDescription
FileObject UInt64
MajorFunction UInt8
MajorFunctionName AnsiString
MinorFunction UInt8
ControlCode UInt32
Status UInt32NTSTATUS reference
IoStatus UInt32
IoInformation UInt64
FltStatus UInt32

Event ID 4002

#
Channel
Operational

Description

Driver entry post enter: FileObject , MajorFunction (), MinorFunction , ControlCode , IoStatus , IoInformation.

Fields #

NameDescription
FileObject UInt64
MajorFunction UInt8
MajorFunctionName AnsiString
MinorFunction UInt8
ControlCode UInt32
IoStatus UInt32
IoInformation UInt64

Event ID 4002: Driver entry post enter: FileObject FileObject, MajorFunction MajorFunction (MajorFunctionName), MinorFunction MinorFunction, ControlCode ControlCode, IoStatus IoStatus, IoInformation IoInformation.

#
Channel
Performance

Message #

Driver entry post enter: FileObject %1, MajorFunction %2 (%3), MinorFunction %4, ControlCode %5, IoStatus %6, IoInformation %7

Fields #

NameDescription
FileObject UInt64
MajorFunction UInt8
MajorFunctionName AnsiString
MinorFunction UInt8
ControlCode UInt32
IoStatus UInt32
IoInformation UInt64

Event ID 4003

#
Channel
Operational

Description

Driver entry post exit: FileObject , MajorFunction (), MinorFunction , ControlCode , Status.

Fields #

NameDescription
FileObject UInt64
MajorFunction UInt8
MajorFunctionName AnsiString
MinorFunction UInt8
ControlCode UInt32
Status UInt32NTSTATUS reference

Event ID 4003: Driver entry post exit: FileObject FileObject, MajorFunction MajorFunction (MajorFunctionName), MinorFunction MinorFunction, ControlCode ControlCode, Status Status.

#
Channel
Performance

Message #

Driver entry post exit: FileObject %1, MajorFunction %2 (%3), MinorFunction %4, ControlCode %5, Status %6

Fields #

NameDescription
FileObject UInt64
MajorFunction UInt8
MajorFunctionName AnsiString
MinorFunction UInt8
ControlCode UInt32
Status UInt32NTSTATUS reference

Event ID 4010

#
Channel
Operational

Description

Log file enter: FileObject , MajorFunction (), ControlCode , ByteOffset , Length.

Fields #

NameDescription
FileObject UInt64
MajorFunction UInt8
MajorFunctionName AnsiString
ControlCode UInt32
ByteOffset UInt64
Length UInt32

Event ID 4010: Log file enter: FileObject FileObject, MajorFunction MajorFunction (MajorFunctionName), ControlCode ControlCode, ByteOffset ByteOffset, Length Length.

#
Channel
Performance

Message #

Log file enter: FileObject %1, MajorFunction %2 (%3), ControlCode %4, ByteOffset %5, Length %6

Fields #

NameDescription
FileObject UInt64
MajorFunction UInt8
MajorFunctionName AnsiString
ControlCode UInt32
ByteOffset UInt64
Length UInt32

Event ID 4011

#
Channel
Operational

Description

Log file exit: FileObject , MajorFunction (), ControlCode , Status.

Fields #

NameDescription
FileObject UInt64
MajorFunction UInt8
MajorFunctionName AnsiString
ControlCode UInt32
Status UInt32NTSTATUS reference

Event ID 4011: Log file exit: FileObject FileObject, MajorFunction MajorFunction (MajorFunctionName), ControlCode ControlCode, Status Status.

#
Channel
Performance

Message #

Log file exit: FileObject %1, MajorFunction %2 (%3), ControlCode %4, Status %5

Fields #

NameDescription
FileObject UInt64
MajorFunction UInt8
MajorFunctionName AnsiString
ControlCode UInt32
Status UInt32NTSTATUS reference

Provenance

ETW provider GUID 38eea17b-db1e-46fe-84d3-07034beaafd0

Defined in ResumeKeyFilter.sys, the binary that emits these events.

  • WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.1, captured 2026-06-02 — Manifest XML pack, 1.9 MB