Microsoft-Windows-StorageManagement

11 events across 2 channels

Event ID 1: Message FileName(LineNumber).

#
Provider
Microsoft-Windows-StorageManagement
Channel
Debug

Description

Message FileName(LineNumber)

Message #

%1
%2(%3)

Fields #

NameDescription
Message UnicodeString
FileName AnsiString
LineNumber UInt32

Event ID 2: Message ErrorCode FileName(LineNumber).

#
Provider
Microsoft-Windows-StorageManagement
Channel
Debug

Description

Message ErrorCode FileName(LineNumber)

Message #

%1 %2
%3(%4)

Fields #

NameDescription
Message UnicodeString
ErrorCode HexInt32
FileName AnsiString
LineNumber UInt32

Event ID 3: Message FileName(LineNumber).

#
Provider
Microsoft-Windows-StorageManagement
Channel
Debug

Description

Message FileName(LineNumber)

Message #

%1
%2(%3)

Fields #

NameDescription
Message UnicodeString
FileName AnsiString
LineNumber UInt32

Event ID 4: An error has occurred during method execution.

#
Provider
Microsoft-Windows-StorageManagement
Channel
Operational

Description

An error has occurred during method execution.

Message #

An error has occurred during method execution.                    
Class: %1                    
Method: %2                    
Error Code: %3                    
Error Message: %4

Fields #

NameDescription
ClassName UnicodeString
MethodName UnicodeString
ErrorCode UInt32
MessageString UnicodeString

Event ID 5: An error has occurred during method execution.

#
Provider
Microsoft-Windows-StorageManagement
Channel
Operational

Description

An error has occurred during method execution.

Message #

An error has occurred during method execution.                   
Class: %1                   
Method: %2                   
Error Code: %3

Fields #

NameDescription
ClassName UnicodeString
MethodName UnicodeString
ErrorCode UInt32

Event ID 6: The Windows Storage Provider host service failed to start.

#
Provider
Microsoft-Windows-StorageManagement
Channel
Operational

Description

The Windows Storage Provider host service failed to start.

Message #

The Windows Storage Provider host service failed to start.                    
Error Code: %1                    
Operation: %2

Fields #

NameDescription
ErrorCode UInt32
Operation UnicodeString
Known values
%%2456
Open key file.
%%2457
Delete key file.
%%2458
Read persisted key from file.
%%2459
Write persisted key to file.
%%2464
Export of persistent cryptographic key.
%%2465
Import of persistent cryptographic key.
%%2480
Open Key.
%%2481
Create Key.
%%2482
Delete Key.
%%2483
Encrypt.
%%2484
Decrypt.
%%2485
Sign hash.
%%2486
Secret agreement.
%%2487
Domain settings.
%%2488
Local settings.
%%2489
Add provider.
%%2490
Remove provider.
%%2491
Add context.
%%2492
Remove context.
%%2493
Add function.
%%2494
Remove function.
%%2495
Add function provider.
%%2496
Remove function provider.
%%2497
Add function property.
%%2498
Remove function property.
%%2499
Machine key.
%%2500
User key.
%%2501
Key Derivation.
%%2502
Claim Creation.
%%2503
Claim Verification.

Event ID 7: The Windows Storage Provider host service was started successfully.

#
Provider
Microsoft-Windows-StorageManagement
Channel
Operational
Level
Informational

Description

The Windows Storage Provider host service was started successfully.

Message #

The Windows Storage Provider host service was started successfully.                    
Start time (milliseconds): %1

Fields #

NameDescription
StartTime_msecs UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-StorageManagement",
    "guid": "{7E58E69A-E361-4F06-B880-AD2F4B64C944}",
    "event_source_name": "",
    "event_id": 7,
    "version": 1,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": -9223372036854775808,
    "time_created": "2026-06-13T04:29:32.9075766+00:00",
    "event_record_id": 37,
    "correlation": {
      "ActivityID": "{48CED4C6-793C-4347-AB40-5015BCC32186}"
    },
    "execution": {
      "process_id": 4692,
      "thread_id": 3704
    },
    "channel": "Microsoft-Windows-StorageManagement/Operational",
    "computer": "telemetry-DC-d.cell-d.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "StartTime_msecs": "734"
  },
  "message": "The Windows Storage Provider host service was started successfully.                    \r\nStart time (milliseconds): 734"
}

Event ID 8: The Windows Storage Management WMI Provider was loaded.

#
Provider
Microsoft-Windows-StorageManagement
Channel
Operational
Level
Informational

Description

The Windows Storage Management WMI Provider was loaded.

Message #

The Windows Storage Management WMI Provider was loaded.                    
Load time (milliseconds): %1

Fields #

NameDescription
LoadTime_msecs UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-StorageManagement",
    "guid": "{7E58E69A-E361-4F06-B880-AD2F4B64C944}",
    "event_source_name": "",
    "event_id": 8,
    "version": 1,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": -9223372036854775808,
    "time_created": "2026-06-13T04:29:32.1555209+00:00",
    "event_record_id": 31,
    "correlation": {},
    "execution": {
      "process_id": 4692,
      "thread_id": 3704
    },
    "channel": "Microsoft-Windows-StorageManagement/Operational",
    "computer": "telemetry-DC-d.cell-d.ludus.domain",
    "security": {
      "user_id": "S-1-5-20"
    }
  },
  "event_data": {
    "LoadTime_msecs": "0"
  },
  "message": "The Windows Storage Management WMI Provider was loaded.                    \r\nLoad time (milliseconds): 0"
}

Event ID 9: A Windows Storage Management WMI enumeration operation was performed.

#
Provider
Microsoft-Windows-StorageManagement
Channel
Operational
Level
Informational

Description

A Windows Storage Management WMI enumeration operation was performed.

Message #

A Windows Storage Management WMI enumeration operation was performed.                   
Class: %1                   
ResultCount: %2                   
Operation time (milliseconds): %3

Fields #

NameDescription
ClassName UnicodeString
ResultCount UInt32
OperationTime_msecs UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-StorageManagement",
    "guid": "{7E58E69A-E361-4F06-B880-AD2F4B64C944}",
    "event_source_name": "",
    "event_id": 9,
    "version": 1,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": -9223372036854775808,
    "time_created": "2026-06-13T04:29:32.9374574+00:00",
    "event_record_id": 38,
    "correlation": {
      "ActivityID": "{48CED4C6-793C-4347-AB40-5015BCC32186}"
    },
    "execution": {
      "process_id": 4692,
      "thread_id": 3704
    },
    "channel": "Microsoft-Windows-StorageManagement/Operational",
    "computer": "telemetry-DC-d.cell-d.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "ClassName": "MSFT_PhysicalDisk",
    "ResultCount": "1",
    "OperationTime_msecs": "32"
  },
  "message": "A Windows Storage Management WMI enumeration operation was performed.                   \r\nClass: MSFT_PhysicalDisk                   \r\nResultCount: 1                   \r\nOperation time (milliseconds): 32"
}

Event ID 10: A Windows Storage Management WMI get instance operation was performed.

#
Provider
Microsoft-Windows-StorageManagement
Channel
Operational
Level
Informational

Description

A Windows Storage Management WMI get instance operation was performed.

Message #

A Windows Storage Management WMI get instance operation was performed.                   
Class: %1                   
Operation time (milliseconds): %2

Fields #

NameDescription
ClassName UnicodeString
OperationTime_msecs UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-StorageManagement",
    "guid": "7E58E69A-E361-4F06-B880-AD2F4B64C944",
    "event_source_name": "",
    "event_id": 10,
    "version": 1,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775808,
    "time_created": "2022-04-07T17:21:56.538886+00:00",
    "event_record_id": 34,
    "correlation": {
      "ActivityID": "81FAF879-7D33-43C8-9320-DFCB4C248FFD"
    },
    "execution": {
      "process_id": 892,
      "thread_id": 2328
    },
    "channel": "Microsoft-Windows-StorageManagement/Operational",
    "computer": "WIN-FPV0DSIC9O6.lab.local",
    "security": {
      "user_id": "S-1-5-21-2121334350-1110938707-2888912545-500"
    }
  },
  "event_data": {
    "ClassName": "SPACES_PhysicalDisk",
    "OperationTime_msecs": 16
  },
  "message": ""
}

References #

Event ID 11: A Windows Storage Management WMI method operation was performed.

#
Provider
Microsoft-Windows-StorageManagement
Channel
Operational
Level
Informational

Description

A Windows Storage Management WMI method operation was performed.

Message #

A Windows Storage Management WMI method operation was performed.                   
Class: %1                   
Method: %2                   
Operation time (milliseconds): %3

Fields #

NameDescription
ClassName UnicodeString
MethodName UnicodeString
OperationTime_msecs UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-StorageManagement",
    "guid": "{7E58E69A-E361-4F06-B880-AD2F4B64C944}",
    "event_source_name": "",
    "event_id": 11,
    "version": 1,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": -9223372036854775808,
    "time_created": "2026-05-30T04:00:13.2767357+00:00",
    "event_record_id": 137,
    "correlation": {
      "ActivityID": "{62771D43-8704-4A7A-AD68-269A9C6F6CD6}"
    },
    "execution": {
      "process_id": 4544,
      "thread_id": 12792
    },
    "channel": "Microsoft-Windows-StorageManagement/Operational",
    "computer": "JD-WIN11-22H2-1.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1105"
    }
  },
  "event_data": {
    "ClassName": "MSFT_FileIntegrity",
    "MethodName": "Set",
    "OperationTime_msecs": "0"
  },
  "message": "A Windows Storage Management WMI method operation was performed.                   \r\nClass: MSFT_FileIntegrity                   \r\nMethod: Set                   \r\nOperation time (milliseconds): 0"
}

Provenance

Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.

ETW provider GUID 7e58e69a-e361-4f06-b880-ad2f4b64c944

Defined in storagewmi.dll, which carries the event manifest.

Observed on:

  • WS2022-20348.4893, schema read from the registered manifest, captured 2026-06-02
  • Win11-26200.6584, schema read from the registered manifest, captured 2026-06-02

Downloads