Microsoft-Windows-Storage-Tiering

Event ID 1: Volume {VolumeGuid} (ID {VolumeIdHash}) is measuring I/O heat.

#
Channel
Tiering Heat Measurement Channel

Fields #

NameDescription
VolumeGuid
VolumeIdHash

Event ID 2: READ - Volume: {VolumeIdHash} File: {FileIDLower}{FileIDUpper} Offset: {Offset} Length {Length}.

#
Channel
Tiering Heat Measurement Channel

Fields #

NameDescription
VolumeIdHash
FileIDLower
FileIDUpper
Offset
Length

Event ID 3: WRITE - Volume: {VolumeIdHash} File: {FileIDLower}{FileIDUpper} Offset: {Offset} Length {Length}.

#
Channel
Tiering Heat Measurement Channel

Fields #

NameDescription
VolumeIdHash
FileIDLower
FileIDUpper
Offset
Length

Event ID 4: DELETE - Volume: {VolumeIdHash} File: {FileIDLower}{FileIDUpper}.

#
Channel
Tiering Heat Measurement Channel

Fields #

NameDescription
VolumeIdHash
FileIDLower
FileIDUpper

Event ID 5: TIERMOVE - Volume: {VolumeIdHash} File: {FileIDLower}{FileIDUpper} Offset: {Offset} Length {Length} Source: {Source} Destination: {Destination}.

#
Channel
Tiering Heat Measurement Channel

Fields #

NameDescription
VolumeIdHash
FileIDLower
FileIDUpper
Offset
Length
Source
Destination

Event ID 11: The Storage Tiers Management service started monitoring a volume on a tiered storage space.

#
Channel
Admin
Opcode
Info

Description

The Storage Tiers Management service started monitoring a volume on a tiered storage space. No action is required. Volume name: VolumeName.

Message #

The Storage Tiers Management service started monitoring a volume on a tiered storage space. No action is required.  Volume name: %2.

Fields #

NameDescription
VolumeNameLength UInt16
VolumeName UnicodeString

Event ID 12: The Storage Tiers Management service encountered an error with the database of manually assigned files and re-created the database.

#
Channel
Admin
Opcode
Info

Description

The Storage Tiers Management service encountered an error with the database of manually assigned files and re-created the database. Confirm that files that were manually assigned to a particular storage tier are still assigned to the correct tier, as appropriate. Volume name: VolumeName.

Message #

The Storage Tiers Management service encountered an error with the database of manually assigned files and re-created the database. Confirm that files that were manually assigned to a particular storage tier are still assigned to the correct tier, as appropriate. Volume name: %2.

Fields #

NameDescription
VolumeNameLength UInt16
VolumeName UnicodeString

Event ID 13: The Storage Tiers Management service is monitoring a volume on a tiered storage space.

#
Channel
Admin
Opcode
Info

Description

The Storage Tiers Management service is monitoring a volume on a tiered storage space. No action is required.

Message #

The Storage Tiers Management service is monitoring a volume on a tiered storage space. No action is required.

           Local volume name: %2
           CSV name: %4

Fields #

NameDescription
VolumeNameLength UInt16
VolumeName UnicodeString
CsvNameLength UInt16
CsvName UnicodeString

Event ID 21: The Storage Tiers Management service completed optimization of the tiered storage space.

#
Channel
Admin
Opcode
Info

Description

The Storage Tiers Management service completed optimization of the tiered storage space. No action is required. Volume name: VolumeName Result: HResult. Processing time (in minutes): ProcessTimeInMinutes Optimization time (in minutes): DefragTimeInMinutes Number of clusters requested to move to Performance tier: AskedToMoveToFlash; to Capacity tier: AskedToMoveToDisk Actual number of clusters moved to Performance tier: MovedToFlash; to Capacity tier: MovedToDisk

Message #

The Storage Tiers Management service completed optimization of the tiered storage space. No action is required. Volume name: %2 Result: %7.  Processing time (in minutes): %8 Optimization time (in minutes): %9  Number of clusters requested to move to Performance tier: %3; to Capacity tier: %4  Actual number of clusters moved to Performance tier: %5; to Capacity tier: %6

Fields #

NameDescription
VolumeNameLength UInt16
VolumeName UnicodeString
AskedToMoveToFlash UInt64
AskedToMoveToDisk UInt64
MovedToFlash UInt64
MovedToDisk UInt64
HResult Int32
ProcessTimeInMinutes Int32
DefragTimeInMinutes Int32

Event ID 22: Storage Tier Optimization Report for volume VolumeName.

#
Channel
Admin
Opcode
Info

Message #

Storage Tier Optimization Report for volume %2

	% I/Os serviced from Perf tier		Performance tier size required
%3
Current size of the Performance tier: %4
Percent of total I/Os serviced from the Performance tier: %5% 

Size of files pinned to the Performance tier: %6
Percent of total I/Os: %7% 

Size of files pinned to the Capacity tier: %8
Percent of total I/Os: %9%

Fields #

NameDescription
VolumeNameLength UInt16
VolumeName UnicodeString
Report UnicodeString
FasterTierSize UnicodeString
TotalIOPercentFromPerfTier UInt16
SizeOfPerfTierPinnedFiles UnicodeString
PercentOfPerfTierPinnedFilesIO UInt16
SizeOfCapacityTierPinnedFiles UnicodeString
PercentOfCapacityTierPinnedFilesIO UInt16

Event ID 31: The Storage Tiers Management service reached the limit of in-memory records of reads and writes to a tiered storage space.

#
Channel
Admin
Opcode
Info

Description

The Storage Tiers Management service reached the limit of in-memory records of reads and writes to a tiered storage space. Additional read and write activity will not be recorded or considered during optimization of storage tiers on this storage space for the rest of the hour. Consider increasing the MaxInMemoryTreeSize registry value. Memory entries limit: NumberEntries Volume name: VolumeName

Message #

The Storage Tiers Management service reached the limit of in-memory records of reads and writes to a tiered storage space. Additional read and write activity will not be recorded or considered during optimization of storage tiers on this storage space for the rest of the hour.  Consider increasing the MaxInMemoryTreeSize registry value. Memory entries limit: %3 Volume name: %2

Fields #

NameDescription
VolumeNameLength UInt16
VolumeName UnicodeString
NumberEntries UInt32

Provenance

ETW provider GUID 4a104570-ec6d-4560-a40f-858fa955e84f

Defined in TieringEngineService.exe, which carries the event manifest.

  • WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.1, captured 2026-06-02 — Manifest XML pack, 1.9 MB
  • Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.1, captured 2026-06-02 — Manifest XML pack, 2.0 MB