Microsoft-Windows-StorageManagement
11 events across 2 channels
| Event | Title | Channel | Sample |
|---|---|---|---|
| 1 | Message FileName(LineNumber). | Debug | N |
| 2 | Message ErrorCode FileName(LineNumber). | Debug | N |
| 3 | Message FileName(LineNumber). | Debug | N |
| 4 | An error has occurred during method execution. | Operational | N |
| 5 | An error has occurred during method execution. | Operational | N |
| 6 | The Windows Storage Provider host service failed to start. | Operational | N |
| 7 | The Windows Storage Provider host service was started successfully. | Operational | Y |
| 8 | The Windows Storage Management WMI Provider was loaded. | Operational | Y |
| 9 | A Windows Storage Management WMI enumeration operation was performed. | Operational | Y |
| 10 | A Windows Storage Management WMI get instance operation was performed. | Operational | Y |
| 11 | A Windows Storage Management WMI method operation was performed. | Operational | Y |
Event ID 1: Message FileName(LineNumber).
#Event ID 2: Message ErrorCode FileName(LineNumber).
#Event ID 3: Message FileName(LineNumber).
#Event ID 4: An error has occurred during method execution.
#Event ID 5: An error has occurred during method execution.
#Event ID 6: The Windows Storage Provider host service failed to start.
#Description
The Windows Storage Provider host service failed to start.
Message #
Fields #
| Name | Description |
|---|---|
ErrorCode UInt32 | |
Operation UnicodeString | Known values
|
Event ID 7: The Windows Storage Provider host service was started successfully.
#Description
The Windows Storage Provider host service was started successfully.
Message #
Fields #
| Name | Description |
|---|---|
StartTime_msecs UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-StorageManagement",
"guid": "{7E58E69A-E361-4F06-B880-AD2F4B64C944}",
"event_source_name": "",
"event_id": 7,
"version": 1,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": -9223372036854775808,
"time_created": "2026-06-13T04:29:32.9075766+00:00",
"event_record_id": 37,
"correlation": {
"ActivityID": "{48CED4C6-793C-4347-AB40-5015BCC32186}"
},
"execution": {
"process_id": 4692,
"thread_id": 3704
},
"channel": "Microsoft-Windows-StorageManagement/Operational",
"computer": "telemetry-DC-d.cell-d.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"StartTime_msecs": "734"
},
"message": "The Windows Storage Provider host service was started successfully. \r\nStart time (milliseconds): 734"
}
Event ID 8: The Windows Storage Management WMI Provider was loaded.
#Description
The Windows Storage Management WMI Provider was loaded.
Message #
Fields #
| Name | Description |
|---|---|
LoadTime_msecs UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-StorageManagement",
"guid": "{7E58E69A-E361-4F06-B880-AD2F4B64C944}",
"event_source_name": "",
"event_id": 8,
"version": 1,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": -9223372036854775808,
"time_created": "2026-06-13T04:29:32.1555209+00:00",
"event_record_id": 31,
"correlation": {},
"execution": {
"process_id": 4692,
"thread_id": 3704
},
"channel": "Microsoft-Windows-StorageManagement/Operational",
"computer": "telemetry-DC-d.cell-d.ludus.domain",
"security": {
"user_id": "S-1-5-20"
}
},
"event_data": {
"LoadTime_msecs": "0"
},
"message": "The Windows Storage Management WMI Provider was loaded. \r\nLoad time (milliseconds): 0"
}
Event ID 9: A Windows Storage Management WMI enumeration operation was performed.
#Description
A Windows Storage Management WMI enumeration operation was performed.
Message #
Fields #
| Name | Description |
|---|---|
ClassName UnicodeString | |
ResultCount UInt32 | |
OperationTime_msecs UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-StorageManagement",
"guid": "{7E58E69A-E361-4F06-B880-AD2F4B64C944}",
"event_source_name": "",
"event_id": 9,
"version": 1,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": -9223372036854775808,
"time_created": "2026-06-13T04:29:32.9374574+00:00",
"event_record_id": 38,
"correlation": {
"ActivityID": "{48CED4C6-793C-4347-AB40-5015BCC32186}"
},
"execution": {
"process_id": 4692,
"thread_id": 3704
},
"channel": "Microsoft-Windows-StorageManagement/Operational",
"computer": "telemetry-DC-d.cell-d.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"ClassName": "MSFT_PhysicalDisk",
"ResultCount": "1",
"OperationTime_msecs": "32"
},
"message": "A Windows Storage Management WMI enumeration operation was performed. \r\nClass: MSFT_PhysicalDisk \r\nResultCount: 1 \r\nOperation time (milliseconds): 32"
}
Event ID 10: A Windows Storage Management WMI get instance operation was performed.
#Description
A Windows Storage Management WMI get instance operation was performed.
Message #
Fields #
| Name | Description |
|---|---|
ClassName UnicodeString | |
OperationTime_msecs UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-StorageManagement",
"guid": "7E58E69A-E361-4F06-B880-AD2F4B64C944",
"event_source_name": "",
"event_id": 10,
"version": 1,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 9223372036854775808,
"time_created": "2022-04-07T17:21:56.538886+00:00",
"event_record_id": 34,
"correlation": {
"ActivityID": "81FAF879-7D33-43C8-9320-DFCB4C248FFD"
},
"execution": {
"process_id": 892,
"thread_id": 2328
},
"channel": "Microsoft-Windows-StorageManagement/Operational",
"computer": "WIN-FPV0DSIC9O6.lab.local",
"security": {
"user_id": "S-1-5-21-2121334350-1110938707-2888912545-500"
}
},
"event_data": {
"ClassName": "SPACES_PhysicalDisk",
"OperationTime_msecs": 16
},
"message": ""
}
References #
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 11: A Windows Storage Management WMI method operation was performed.
#Description
A Windows Storage Management WMI method operation was performed.
Message #
Fields #
| Name | Description |
|---|---|
ClassName UnicodeString | |
MethodName UnicodeString | |
OperationTime_msecs UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-StorageManagement",
"guid": "{7E58E69A-E361-4F06-B880-AD2F4B64C944}",
"event_source_name": "",
"event_id": 11,
"version": 1,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": -9223372036854775808,
"time_created": "2026-05-30T04:00:13.2767357+00:00",
"event_record_id": 137,
"correlation": {
"ActivityID": "{62771D43-8704-4A7A-AD68-269A9C6F6CD6}"
},
"execution": {
"process_id": 4544,
"thread_id": 12792
},
"channel": "Microsoft-Windows-StorageManagement/Operational",
"computer": "JD-WIN11-22H2-1.ludus.domain",
"security": {
"user_id": "S-1-5-21-1006758700-2167138679-1475694448-1105"
}
},
"event_data": {
"ClassName": "MSFT_FileIntegrity",
"MethodName": "Set",
"OperationTime_msecs": "0"
},
"message": "A Windows Storage Management WMI method operation was performed. \r\nClass: MSFT_FileIntegrity \r\nMethod: Set \r\nOperation time (milliseconds): 0"
}
Provenance
Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.
ETW provider GUID 7e58e69a-e361-4f06-b880-ad2f4b64c944
Defined in storagewmi.dll, which carries the event manifest.
Observed on:
- WS2022-20348.4893, schema read from the registered manifest, captured 2026-06-02
- Win11-26200.6584, schema read from the registered manifest, captured 2026-06-02