Microsoft-Windows-ResumeKeyFilter
96 events across 3 channels
Event ID 1000: The filter loaded successfully.
#Description
The filter loaded successfully.
Message #
Fields #
| Name | Description |
|---|---|
Status UInt32 | NTSTATUS reference |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-ResumeKeyFilter",
"guid": "{38EEA17B-DB1E-46FE-84D3-07034BEAAFD0}",
"event_source_name": "",
"event_id": 1000,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": -9223372036854775807,
"time_created": "2026-05-30T02:30:35.6593862+00:00",
"event_record_id": 1,
"correlation": {},
"execution": {
"process_id": 4,
"thread_id": 720
},
"channel": "Microsoft-Windows-ResumeKeyFilter/Operational",
"computer": "JD-DC01-2022.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"Status": "0"
},
"message": "The filter loaded successfully."
}
Event ID 1001: The filter was successfully attached to String.
#Description
The filter was successfully attached to String.
Message #
Fields #
| Name | Description |
|---|---|
StringLength UInt16 | |
String UnicodeString | |
Status UInt32 | NTSTATUS reference |
Event ID 1002: The resume database for String was loaded successfully.
#Description
The resume database for String was loaded successfully. The load operation took Valuems to complete.
Message #
Fields #
| Name | Description |
|---|---|
StringLength UInt16 | |
String UnicodeString | |
Value UInt32 | |
Status UInt32 | NTSTATUS reference |
Event ID 1003: The filter received a dismount request for String.
#Description
The filter received a dismount request for String.
Message #
Fields #
| Name | Description |
|---|---|
StringLength UInt16 | |
String UnicodeString | |
Status UInt32 | NTSTATUS reference |
Event ID 1004: The re-mount request for String completed successfully.
#Description
The re-mount request for String completed successfully.
Message #
Fields #
| Name | Description |
|---|---|
StringLength UInt16 | |
String UnicodeString | |
Status UInt32 | NTSTATUS reference |
Event ID 1005: The filter was detached from String.
#Description
The filter was detached from String.
Message #
Fields #
| Name | Description |
|---|---|
StringLength UInt16 | |
String UnicodeString | |
Status UInt32 | NTSTATUS reference |
Event ID 1006: The filter unloaded.
#Event ID 1007: The filter detected an incomplete failover recovery and purged the resume database for String.
#Description
The filter detected an incomplete failover recovery and purged the resume database for String.
Message #
Fields #
| Name | Description |
|---|---|
StringLength UInt16 | |
String UnicodeString | |
Status UInt32 | NTSTATUS reference |
Event ID 1008: The filter failed to attach to a volume because the volume supports short names but the filter does not support short names.
#Description
The filter failed to attach to a volume because the volume supports short names but the filter does not support short names.
Message #
Fields #
| Name | Description |
|---|---|
Status UInt32 | NTSTATUS reference |
Event ID 1010: The filter detected that chkdsk has been run on volume String and has purged the resume database.
#Description
The filter detected that chkdsk has been run on volume String and has purged the resume database.
Message #
Fields #
| Name | Description |
|---|---|
StringLength UInt16 | |
String UnicodeString | |
Status UInt32 | NTSTATUS reference |
Event ID 1011: The filter detected that a volume snap shot may have been restored on volume String and has purged the resume database.
#Description
The filter detected that a volume snap shot may have been restored on volume String and has purged the resume database.
Message #
Fields #
| Name | Description |
|---|---|
StringLength UInt16 | |
String UnicodeString | |
Status UInt32 | NTSTATUS reference |
Event ID 1100: The creation of a bypass handle on file String completed successfully.
#Description
The creation of a bypass handle on file String completed successfully.
Message #
Fields #
| Name | Description |
|---|---|
Guid GUID | |
StringLength UInt16 | |
String UnicodeString | |
Value UInt32 | |
Status UInt32 | NTSTATUS reference |
Event ID 1100
#Description
The creation of a bypass handle on file completed successfully.
Fields #
| Name | Description |
|---|---|
Guid GUID | |
StringLength UInt16 | |
String UnicodeString | |
Value UInt32 | |
Status UInt32 | NTSTATUS reference |
Event ID 1101: The creation of a new resume handle Guid on file String completed successfully.
#Description
The creation of a new resume handle Guid on file String completed successfully.
Message #
Fields #
| Name | Description |
|---|---|
Guid GUID | |
StringLength UInt16 | |
String UnicodeString | |
Value UInt32 | |
Status UInt32 | NTSTATUS reference |
Event ID 1101
#Description
The creation of a new resume handle on file completed successfully.
Fields #
| Name | Description |
|---|---|
Guid GUID | |
StringLength UInt16 | |
String UnicodeString | |
Value UInt32 | |
Status UInt32 | NTSTATUS reference |
Event ID 1102: The replay creation of resume handle Guid on file String completed successfully.
#Description
The replay creation of resume handle Guid on file String completed successfully.
Message #
Fields #
| Name | Description |
|---|---|
Guid GUID | |
StringLength UInt16 | |
String UnicodeString | |
Value UInt32 | |
Status UInt32 | NTSTATUS reference |
Event ID 1102
#Description
The replay creation of resume handle on file completed successfully.
Fields #
| Name | Description |
|---|---|
Guid GUID | |
StringLength UInt16 | |
String UnicodeString | |
Value UInt32 | |
Status UInt32 | NTSTATUS reference |
Event ID 1103: The resume of handle Guid on file String started successfully.
#Description
The resume of handle Guid on file String started successfully.
Message #
Fields #
| Name | Description |
|---|---|
Guid GUID | |
StringLength UInt16 | |
String UnicodeString | |
Value UInt32 | |
Status UInt32 | NTSTATUS reference |
Event ID 1103
#Description
The resume of handle on file started successfully.
Fields #
| Name | Description |
|---|---|
Guid GUID | |
StringLength UInt16 | |
String UnicodeString | |
Value UInt32 | |
Status UInt32 | NTSTATUS reference |
Event ID 1104: The resume of a handle on file name String1 was successfully reparsed to file name String2.
#Description
The resume of a handle on file name String1 was successfully reparsed to file name String2.
Message #
Fields #
| Name | Description |
|---|---|
String1Length UInt16 | |
String1 UnicodeString | |
String2Length UInt16 | |
String2 UnicodeString | |
Status UInt32 | NTSTATUS reference |
Event ID 1104
#Description
The resume of a handle on file name was successfully reparsed to file name .
Fields #
| Name | Description |
|---|---|
String1Length UInt16 | |
String1 UnicodeString | |
String2Length UInt16 | |
String2 UnicodeString | |
Status UInt32 | NTSTATUS reference |
Event ID 1105: The resume of handle Guid on file String completed successfully.
#Description
The resume of handle Guid on file String completed successfully.
Message #
Fields #
| Name | Description |
|---|---|
Guid GUID | |
StringLength UInt16 | |
String UnicodeString | |
Value UInt32 | |
Status UInt32 | NTSTATUS reference |
Event ID 1105
#Description
The resume of handle on file completed successfully.
Fields #
| Name | Description |
|---|---|
Guid GUID | |
StringLength UInt16 | |
String UnicodeString | |
Value UInt32 | |
Status UInt32 | NTSTATUS reference |
Event ID 1110: The resume handle Guid on file String was suspended.
#Description
The resume handle Guid on file String was suspended.
Message #
Fields #
| Name | Description |
|---|---|
Guid GUID | |
StringLength UInt16 | |
String UnicodeString | |
Value UInt32 | |
Status UInt32 | NTSTATUS reference |
Event ID 1110
#Description
The resume handle on file was suspended.
Fields #
| Name | Description |
|---|---|
Guid GUID | |
StringLength UInt16 | |
String UnicodeString | |
Value UInt32 | |
Status UInt32 | NTSTATUS reference |
Event ID 1111: The resume handle ResumeKey on file String was timed out and cancelled.
#Description
The resume handle ResumeKey on file String was timed out and cancelled.
Message #
Fields #
| Name | Description |
|---|---|
ResumeKey GUID | |
StringLength UInt16 | |
String UnicodeString | |
Value UInt32 | |
Status UInt32 | NTSTATUS reference |
RfsKey GUID | |
NodeId GUID | |
AppId GUID | |
DesiredAccess UInt32 | Process access rights reference |
ShareMode UInt32 | |
CreateOptions UInt32 | |
FileAttribs UInt32 | |
CreateDisp UInt32 |
Event ID 1112: The resume handle Guid on file String was cancelled successfully.
#Description
The resume handle Guid on file String was cancelled successfully.
Message #
Fields #
| Name | Description |
|---|---|
Guid GUID | |
StringLength UInt16 | |
String UnicodeString | |
Value UInt32 | |
Status UInt32 | NTSTATUS reference |
Event ID 1112
#Description
The resume handle on file was cancelled successfully.
Fields #
| Name | Description |
|---|---|
Guid GUID | |
StringLength UInt16 | |
String UnicodeString | |
Value UInt32 | |
Status UInt32 | NTSTATUS reference |
Event ID 1113: The resume handle Guid on file String was closed.
#Description
The resume handle Guid on file String was closed.
Message #
Fields #
| Name | Description |
|---|---|
Guid GUID | |
StringLength UInt16 | |
String UnicodeString | |
Value UInt32 | |
Status UInt32 | NTSTATUS reference |
Event ID 1113
#Description
The resume handle on file was closed.
Fields #
| Name | Description |
|---|---|
Guid GUID | |
StringLength UInt16 | |
String UnicodeString | |
Value UInt32 | |
Status UInt32 | NTSTATUS reference |
Event ID 1114: The deferred delete of file String completed successfully.
#Description
The deferred delete of file String completed successfully.
Message #
Fields #
| Name | Description |
|---|---|
StringLength UInt16 | |
String UnicodeString | |
Status UInt32 | NTSTATUS reference |
Event ID 1114
#Description
The deferred delete of file completed successfully.
Fields #
| Name | Description |
|---|---|
StringLength UInt16 | |
String UnicodeString | |
Status UInt32 | NTSTATUS reference |
Event ID 1120: The filter delayed the creation of a handle on file String1 because the resume database for the volume was still loading.
#Description
The filter delayed the creation of a handle on file String1 because the resume database for the volume was still loading.
Message #
Fields #
| Name | Description |
|---|---|
String1Length UInt16 | |
String1 UnicodeString | |
String2Length UInt16 | |
String2 UnicodeString | |
Status UInt32 | NTSTATUS reference |
Event ID 1121: The filter failed the creation of a handle on file String because the file has pending resume handles.
#Description
The filter failed the creation of a handle on file String because the file has pending resume handles.
Message #
Fields #
| Name | Description |
|---|---|
StringLength UInt16 | |
String UnicodeString | |
Status UInt32 | NTSTATUS reference |
Event ID 1122: The filter failed the creation of a handle on file String because the file is delete pending.
#Description
The filter failed the creation of a handle on file String because the file is delete pending.
Message #
Fields #
| Name | Description |
|---|---|
StringLength UInt16 | |
String UnicodeString | |
Status UInt32 | NTSTATUS reference |
Event ID 1123: The filter failed the creation of a handle on file String because the parent directory has pending resume handles.
#Description
The filter failed the creation of a handle on file String because the parent directory has pending resume handles.
Message #
Fields #
| Name | Description |
|---|---|
StringLength UInt16 | |
String UnicodeString | |
Status UInt32 | NTSTATUS reference |
Event ID 1124: The filter failed the creation of a handle on file String because the parent directory is delete pending.
#Description
The filter failed the creation of a handle on file String because the parent directory is delete pending.
Message #
Fields #
| Name | Description |
|---|---|
StringLength UInt16 | |
String UnicodeString | |
Status UInt32 | NTSTATUS reference |
Event ID 1130: The filter failed an oplock request on file String because the file has conflicting pending resume handles.
#Description
The filter failed an oplock request on file String because the file has conflicting pending resume handles.
Message #
Fields #
| Name | Description |
|---|---|
StringLength UInt16 | |
String UnicodeString | |
Status UInt32 | NTSTATUS reference |
Event ID 1130
#Description
The filter failed an oplock request on file because the file has conflicting pending resume handles.
Fields #
| Name | Description |
|---|---|
StringLength UInt16 | |
String UnicodeString | |
Status UInt32 | NTSTATUS reference |
Event ID 1131: The filter failed a write operation on file String because the file has conflicting pending resume handles.
#Description
The filter failed a write operation on file String because the file has conflicting pending resume handles.
Message #
Fields #
| Name | Description |
|---|---|
StringLength UInt16 | |
String UnicodeString | |
Status UInt32 | NTSTATUS reference |
Event ID 1131
#Description
The filter failed a write operation on file because the file has conflicting pending resume handles.
Fields #
| Name | Description |
|---|---|
StringLength UInt16 | |
String UnicodeString | |
Status UInt32 | NTSTATUS reference |
Event ID 1132: The filter failed a read operation on file String because the file has conflicting pending resume handles.
#Description
The filter failed a read operation on file String because the file has conflicting pending resume handles.
Message #
Fields #
| Name | Description |
|---|---|
StringLength UInt16 | |
String UnicodeString | |
Status UInt32 | NTSTATUS reference |
Event ID 1132
#Description
The filter failed a read operation on file because the file has conflicting pending resume handles.
Fields #
| Name | Description |
|---|---|
StringLength UInt16 | |
String UnicodeString | |
Status UInt32 | NTSTATUS reference |
Event ID 1133: The filter failed an exclusive byte range lock request on file String because the file has conflicting pending resume handles.
#Description
The filter failed an exclusive byte range lock request on file String because the file has conflicting pending resume handles.
Message #
Fields #
| Name | Description |
|---|---|
StringLength UInt16 | |
String UnicodeString | |
Status UInt32 | NTSTATUS reference |
Event ID 1133
#Description
The filter failed an exclusive byte range lock request on file because the file has conflicting pending resume handles.
Fields #
| Name | Description |
|---|---|
StringLength UInt16 | |
String UnicodeString | |
Status UInt32 | NTSTATUS reference |
Event ID 1134: The filter failed a shared byte range lock request on file String because the file has conflicting pending resume handles.
#Description
The filter failed a shared byte range lock request on file String because the file has conflicting pending resume handles.
Message #
Fields #
| Name | Description |
|---|---|
StringLength UInt16 | |
String UnicodeString | |
Status UInt32 | NTSTATUS reference |
Event ID 1134
#Description
The filter failed a shared byte range lock request on file because the file has conflicting pending resume handles.
Fields #
| Name | Description |
|---|---|
StringLength UInt16 | |
String UnicodeString | |
Status UInt32 | NTSTATUS reference |
Event ID 1135: The filter failed the create of a hard link on file String because hard links are not supported.
#Description
The filter failed the create of a hard link on file String because hard links are not supported.
Message #
Fields #
| Name | Description |
|---|---|
StringLength UInt16 | |
String UnicodeString | |
Status UInt32 | NTSTATUS reference |
Event ID 1136: The filter failed the rename of an alternate data stream on file String because rename of alternate data streams is not supported.
#Description
The filter failed the rename of an alternate data stream on file String because rename of alternate data streams is not supported.
Message #
Fields #
| Name | Description |
|---|---|
StringLength UInt16 | |
String UnicodeString | |
Status UInt32 | NTSTATUS reference |
Event ID 1137: The filter failed a rename replace to file String because this target file has conflicting pending resume handles.
#Description
The filter failed a rename replace to file String because this target file has conflicting pending resume handles.
Message #
Fields #
| Name | Description |
|---|---|
StringLength UInt16 | |
String UnicodeString | |
Status UInt32 | NTSTATUS reference |
Event ID 1137
#Description
The filter failed a rename replace to file because this target file has conflicting pending resume handles.
Fields #
| Name | Description |
|---|---|
StringLength UInt16 | |
String UnicodeString | |
Status UInt32 | NTSTATUS reference |
Event ID 1138: The filter failed a set end-of-file request on file String because the file has conflicting pending resume handles.
#Description
The filter failed a set end-of-file request on file String because the file has conflicting pending resume handles.
Message #
Fields #
| Name | Description |
|---|---|
StringLength UInt16 | |
String UnicodeString | |
Status UInt32 | NTSTATUS reference |
Event ID 1138
#Description
The filter failed a set end-of-file request on file because the file has conflicting pending resume handles.
Fields #
| Name | Description |
|---|---|
StringLength UInt16 | |
String UnicodeString | |
Status UInt32 | NTSTATUS reference |
Event ID 1139: The filter failed a set zero data request on file String because the file has conflicting pending resume handles.
#Description
The filter failed a set zero data request on file String because the file has conflicting pending resume handles.
Message #
Fields #
| Name | Description |
|---|---|
StringLength UInt16 | |
String UnicodeString | |
Status UInt32 | NTSTATUS reference |
Event ID 1139
#Description
The filter failed a set zero data request on file because the file has conflicting pending resume handles.
Fields #
| Name | Description |
|---|---|
StringLength UInt16 | |
String UnicodeString | |
Status UInt32 | NTSTATUS reference |
Event ID 1140: The filter failed a rename request on file String because the resume database was still being processed.
#Description
The filter failed a rename request on file String because the resume database was still being processed.
Message #
Fields #
| Name | Description |
|---|---|
StringLength UInt16 | |
String UnicodeString | |
Status UInt32 | NTSTATUS reference |
Event ID 1140
#Description
The filter failed a rename request on file because the resume database was still being processed.
Fields #
| Name | Description |
|---|---|
StringLength UInt16 | |
String UnicodeString | |
Status UInt32 | NTSTATUS reference |
Event ID 1141: The filter failed a rename request on file String because the file has conflicting pending resume handles.
#Description
The filter failed a rename request on file String because the file has conflicting pending resume handles.
Message #
Fields #
| Name | Description |
|---|---|
StringLength UInt16 | |
String UnicodeString | |
Status UInt32 | NTSTATUS reference |
Event ID 1141
#Description
The filter failed a rename request on file because the file has conflicting pending resume handles.
Fields #
| Name | Description |
|---|---|
StringLength UInt16 | |
String UnicodeString | |
Status UInt32 | NTSTATUS reference |
Event ID 1142: The filter failed a copy offload read operation on file String because the file has conflicting pending resume handles.
#Description
The filter failed a copy offload read operation on file String because the file has conflicting pending resume handles.
Message #
Fields #
| Name | Description |
|---|---|
StringLength UInt16 | |
String UnicodeString | |
Status UInt32 | NTSTATUS reference |
Event ID 1142
#Description
The filter failed a copy offload read operation on file because the file has conflicting pending resume handles.
Fields #
| Name | Description |
|---|---|
StringLength UInt16 | |
String UnicodeString | |
Status UInt32 | NTSTATUS reference |
Event ID 1143: The filter failed a copy offload write operation on file String because the file has conflicting pending resume handles.
#Description
The filter failed a copy offload write operation on file String because the file has conflicting pending resume handles.
Message #
Fields #
| Name | Description |
|---|---|
StringLength UInt16 | |
String UnicodeString | |
Status UInt32 | NTSTATUS reference |
Event ID 1143
#Description
The filter failed a copy offload write operation on file because the file has conflicting pending resume handles.
Fields #
| Name | Description |
|---|---|
StringLength UInt16 | |
String UnicodeString | |
Status UInt32 | NTSTATUS reference |
Event ID 1144: The filter failed a file trim operation on file String because the file has conflicting pending resume handles.
#Description
The filter failed a file trim operation on file String because the file has conflicting pending resume handles.
Message #
Fields #
| Name | Description |
|---|---|
StringLength UInt16 | |
String UnicodeString | |
Status UInt32 | NTSTATUS reference |
Event ID 1144
#Description
The filter failed a file trim operation on file because the file has conflicting pending resume handles.
Fields #
| Name | Description |
|---|---|
StringLength UInt16 | |
String UnicodeString | |
Status UInt32 | NTSTATUS reference |
Event ID 1145: The filter failed a file set read only attribute operation on file String because the file has conflicting pending resume handles.
#Description
The filter failed a file set read only attribute operation on file String because the file has conflicting pending resume handles.
Message #
Fields #
| Name | Description |
|---|---|
StringLength UInt16 | |
String UnicodeString | |
Status UInt32 | NTSTATUS reference |
Event ID 1145
#Description
The filter failed a file set read only attribute operation on file because the file has conflicting pending resume handles.
Fields #
| Name | Description |
|---|---|
StringLength UInt16 | |
String UnicodeString | |
Status UInt32 | NTSTATUS reference |
Event ID 1150: The creation of a new resume handle on file String failed because the file has hard links.
#Description
The creation of a new resume handle on file String failed because the file has hard links.
Message #
Fields #
| Name | Description |
|---|---|
StringLength UInt16 | |
String UnicodeString | |
Status UInt32 | NTSTATUS reference |
Event ID 1151: The creation of a new handle on file String failed because the supersede of a file that has open resume handles on Alternate Data Streams is not suppor...
#Description
The creation of a new handle on file String failed because the supersede of a file that has open resume handles on Alternate Data Streams is not supported.
Message #
Fields #
| Name | Description |
|---|---|
StringLength UInt16 | |
String UnicodeString | |
Status UInt32 | NTSTATUS reference |
Event ID 2000: The filter failed to load with error status Status.
#Description
The filter failed to load with error status Status.
Message #
Fields #
| Name | Description |
|---|---|
Status UInt32 | NTSTATUS reference |
Event ID 2001: The filter failed to attach to String with error status Status.
#Description
The filter failed to attach to String with error status Status.
Message #
Fields #
| Name | Description |
|---|---|
StringLength UInt16 | |
String UnicodeString | |
Status UInt32 | NTSTATUS reference |
Event ID 2002: The resume database for String failed to load with error status Status.
#Description
The resume database for String failed to load with error status Status. The load operation took Valuems to complete.
Message #
Fields #
| Name | Description |
|---|---|
StringLength UInt16 | |
String UnicodeString | |
Value UInt32 | |
Status UInt32 | NTSTATUS reference |
Event ID 2004: The re-mount request for String failed with error status Status.
#Description
The re-mount request for String failed with error status Status.
Message #
Fields #
| Name | Description |
|---|---|
StringLength UInt16 | |
String UnicodeString | |
Status UInt32 | NTSTATUS reference |
Event ID 2100: The creation of a bypass handle on file String failed with error status Status.
#Description
The creation of a bypass handle on file String failed with error status Status.
Message #
Fields #
| Name | Description |
|---|---|
Guid GUID | |
StringLength UInt16 | |
String UnicodeString | |
Value UInt32 | |
Status UInt32 | NTSTATUS reference |
Event ID 2100
#Description
The creation of a bypass handle on file failed with error status .
Fields #
| Name | Description |
|---|---|
Guid GUID | |
StringLength UInt16 | |
String UnicodeString | |
Value UInt32 | |
Status UInt32 | NTSTATUS reference |
Event ID 2101: The creation of a new resume handle Guid on file String failed with error status Status.
#Description
The creation of a new resume handle Guid on file String failed with error status Status.
Message #
Fields #
| Name | Description |
|---|---|
Guid GUID | |
StringLength UInt16 | |
String UnicodeString | |
Value UInt32 | |
Status UInt32 | NTSTATUS reference |
Event ID 2101
#Description
The creation of a new resume handle on file failed with error status .
Fields #
| Name | Description |
|---|---|
Guid GUID | |
StringLength UInt16 | |
String UnicodeString | |
Value UInt32 | |
Status UInt32 | NTSTATUS reference |
Event ID 2102: The replay creation of resume handle Guid on file String failed with error status Status.
#Description
The replay creation of resume handle Guid on file String failed with error status Status.
Message #
Fields #
| Name | Description |
|---|---|
Guid GUID | |
StringLength UInt16 | |
String UnicodeString | |
Value UInt32 | |
Status UInt32 | NTSTATUS reference |
Event ID 2102
#Description
The replay creation of resume handle on file failed with error status .
Fields #
| Name | Description |
|---|---|
Guid GUID | |
StringLength UInt16 | |
String UnicodeString | |
Value UInt32 | |
Status UInt32 | NTSTATUS reference |
Event ID 2103: The resume of handle Guid on file String failed with error status Status.
#Description
The resume of handle Guid on file String failed with error status Status.
Message #
Fields #
| Name | Description |
|---|---|
Guid GUID | |
StringLength UInt16 | |
String UnicodeString | |
Value UInt32 | |
Status UInt32 | NTSTATUS reference |
Event ID 2104: The resume of a handle on file name String1 failed to reparse to a valid file name with error status Status.
#Description
The resume of a handle on file name String1 failed to reparse to a valid file name with error status Status.
Message #
Fields #
| Name | Description |
|---|---|
String1Length UInt16 | |
String1 UnicodeString | |
String2Length UInt16 | |
String2 UnicodeString | |
Status UInt32 | NTSTATUS reference |
Event ID 2112: The resume handle Guid on file String failed to cancel with error status Status.
#Description
The resume handle Guid on file String failed to cancel with error status Status.
Message #
Fields #
| Name | Description |
|---|---|
Guid GUID | |
StringLength UInt16 | |
String UnicodeString | |
Value UInt32 | |
Status UInt32 | NTSTATUS reference |
Event ID 2112
#Description
The resume handle on file failed to cancel with error status .
Fields #
| Name | Description |
|---|---|
Guid GUID | |
StringLength UInt16 | |
String UnicodeString | |
Value UInt32 | |
Status UInt32 | NTSTATUS reference |
Event ID 2114: The deferred delete of file String failed with error status Status.
#Description
The deferred delete of file String failed with error status Status.
Message #
Fields #
| Name | Description |
|---|---|
StringLength UInt16 | |
String UnicodeString | |
Status UInt32 | NTSTATUS reference |
Event ID 4000
#Description
Driver entry pre enter: FileObject (), MajorFunction (), MinorFunction , ControlCode.
Fields #
| Name | Description |
|---|---|
FileObject UInt64 | |
FileObjectNameLength UInt16 | |
FileObjectName UnicodeString | |
MajorFunction UInt8 | |
MajorFunctionName AnsiString | |
MinorFunction UInt8 | |
ControlCode UInt32 |
Event ID 4000: Driver entry pre enter: FileObject FileObject (FileObjectName), MajorFunction MajorFunction (MajorFunctionName), MinorFunction MinorFunction, ControlCode ControlCode.
#Description
Driver entry pre enter: FileObject FileObject (FileObjectName), MajorFunction MajorFunction (MajorFunctionName), MinorFunction MinorFunction, ControlCode ControlCode.
Message #
Fields #
| Name | Description |
|---|---|
FileObject UInt64 | |
FileObjectNameLength UInt16 | |
FileObjectName UnicodeString | |
MajorFunction UInt8 | |
MajorFunctionName AnsiString | |
MinorFunction UInt8 | |
ControlCode UInt32 |
Event ID 4001
#Description
Driver entry pre exit: FileObject , MajorFunction (), MinorFunction , ControlCode , Status , IoStatus , IoInformation , FltStatus.
Fields #
| Name | Description |
|---|---|
FileObject UInt64 | |
MajorFunction UInt8 | |
MajorFunctionName AnsiString | |
MinorFunction UInt8 | |
ControlCode UInt32 | |
Status UInt32 | NTSTATUS reference |
IoStatus UInt32 | |
IoInformation UInt64 | |
FltStatus UInt32 |
Event ID 4001: Driver entry pre exit: FileObject FileObject, MajorFunction MajorFunction (MajorFunctionName), MinorFunction MinorFunction, ControlCode ControlCode, Status Status, IoStatus IoStatus, IoInformation ...
#Description
Driver entry pre exit: FileObject FileObject, MajorFunction MajorFunction (MajorFunctionName), MinorFunction MinorFunction, ControlCode ControlCode, Status Status, IoStatus IoStatus, IoInformation IoInformation, FltStatus FltStatus.
Message #
Fields #
| Name | Description |
|---|---|
FileObject UInt64 | |
MajorFunction UInt8 | |
MajorFunctionName AnsiString | |
MinorFunction UInt8 | |
ControlCode UInt32 | |
Status UInt32 | NTSTATUS reference |
IoStatus UInt32 | |
IoInformation UInt64 | |
FltStatus UInt32 |
Event ID 4002
#Description
Driver entry post enter: FileObject , MajorFunction (), MinorFunction , ControlCode , IoStatus , IoInformation.
Fields #
| Name | Description |
|---|---|
FileObject UInt64 | |
MajorFunction UInt8 | |
MajorFunctionName AnsiString | |
MinorFunction UInt8 | |
ControlCode UInt32 | |
IoStatus UInt32 | |
IoInformation UInt64 |
Event ID 4002: Driver entry post enter: FileObject FileObject, MajorFunction MajorFunction (MajorFunctionName), MinorFunction MinorFunction, ControlCode ControlCode, IoStatus IoStatus, IoInformation IoInformation.
#Description
Driver entry post enter: FileObject FileObject, MajorFunction MajorFunction (MajorFunctionName), MinorFunction MinorFunction, ControlCode ControlCode, IoStatus IoStatus, IoInformation IoInformation.
Message #
Fields #
| Name | Description |
|---|---|
FileObject UInt64 | |
MajorFunction UInt8 | |
MajorFunctionName AnsiString | |
MinorFunction UInt8 | |
ControlCode UInt32 | |
IoStatus UInt32 | |
IoInformation UInt64 |
Event ID 4003
#Description
Driver entry post exit: FileObject , MajorFunction (), MinorFunction , ControlCode , Status.
Fields #
| Name | Description |
|---|---|
FileObject UInt64 | |
MajorFunction UInt8 | |
MajorFunctionName AnsiString | |
MinorFunction UInt8 | |
ControlCode UInt32 | |
Status UInt32 | NTSTATUS reference |
Event ID 4003: Driver entry post exit: FileObject FileObject, MajorFunction MajorFunction (MajorFunctionName), MinorFunction MinorFunction, ControlCode ControlCode, Status Status.
#Description
Driver entry post exit: FileObject FileObject, MajorFunction MajorFunction (MajorFunctionName), MinorFunction MinorFunction, ControlCode ControlCode, Status Status.
Message #
Fields #
| Name | Description |
|---|---|
FileObject UInt64 | |
MajorFunction UInt8 | |
MajorFunctionName AnsiString | |
MinorFunction UInt8 | |
ControlCode UInt32 | |
Status UInt32 | NTSTATUS reference |
Event ID 4010
#Description
Log file enter: FileObject , MajorFunction (), ControlCode , ByteOffset , Length.
Fields #
| Name | Description |
|---|---|
FileObject UInt64 | |
MajorFunction UInt8 | |
MajorFunctionName AnsiString | |
ControlCode UInt32 | |
ByteOffset UInt64 | |
Length UInt32 |
Event ID 4010: Log file enter: FileObject FileObject, MajorFunction MajorFunction (MajorFunctionName), ControlCode ControlCode, ByteOffset ByteOffset, Length Length.
#Description
Log file enter: FileObject FileObject, MajorFunction MajorFunction (MajorFunctionName), ControlCode ControlCode, ByteOffset ByteOffset, Length Length.
Message #
Fields #
| Name | Description |
|---|---|
FileObject UInt64 | |
MajorFunction UInt8 | |
MajorFunctionName AnsiString | |
ControlCode UInt32 | |
ByteOffset UInt64 | |
Length UInt32 |
Event ID 4011
#Description
Log file exit: FileObject , MajorFunction (), ControlCode , Status.
Fields #
| Name | Description |
|---|---|
FileObject UInt64 | |
MajorFunction UInt8 | |
MajorFunctionName AnsiString | |
ControlCode UInt32 | |
Status UInt32 | NTSTATUS reference |
Event ID 4011: Log file exit: FileObject FileObject, MajorFunction MajorFunction (MajorFunctionName), ControlCode ControlCode, Status Status.
#Description
Log file exit: FileObject FileObject, MajorFunction MajorFunction (MajorFunctionName), ControlCode ControlCode, Status Status.
Message #
Fields #
| Name | Description |
|---|---|
FileObject UInt64 | |
MajorFunction UInt8 | |
MajorFunctionName AnsiString | |
ControlCode UInt32 | |
Status UInt32 | NTSTATUS reference |
Provenance
Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.
ETW provider GUID 38eea17b-db1e-46fe-84d3-07034beaafd0
Defined in ResumeKeyFilter.sys, the binary that emits these events.
Observed on:
- WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.1, captured 2026-06-02