Microsoft-Windows-SmbWmiProvider

3 events across 1 channel

EventTitleChannelSample
0Function FunctionName returned MI error MiError Win32 Error Win32Error.SmbWmiAnalyticN
1Message.SmbWmiAnalyticN
2Message.SmbWmiAnalyticN

Event ID 0: Function FunctionName returned MI error MiError Win32 Error Win32Error.

#
Provider
Microsoft-Windows-SmbWmiProvider
Channel
SmbWmiAnalytic

Description

Function FunctionName returned MI error MiError Win32 Error Win32Error.

Message #

Function %1 returned MI error %2 Win32 Error %3

Fields #

NameDescription
FunctionName UnicodeString
MiError UInt32
Win32Error UInt32

Event ID 1: Message.

#
Provider
Microsoft-Windows-SmbWmiProvider
Channel
SmbWmiAnalytic

Description

Message

Message #

%1

Fields #

NameDescription
Message UnicodeString

Event ID 2: Message.

#
Provider
Microsoft-Windows-SmbWmiProvider
Channel
SmbWmiAnalytic

Description

Message

Message #

%1

Fields #

NameDescription
Message UnicodeString

Provenance

Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.

ETW provider GUID 50b9e206-9d55-4092-92e8-f157a8235799

Defined in SmbWmiv2.dll, which carries the event manifest.

Observed on:

  • WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.3207, captured 2026-06-02
  • Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.2161, captured 2026-06-02

Downloads