Microsoft-Windows-System-Restore

4 events across 1 channel

Event ID 8300: Scoping started for shadowcopy SnapshotPath.

#
Provider
Microsoft-Windows-System-Restore
Channel
Application
Level
Informational
Opcode
Start

Description

Scoping started for shadowcopy .

Message #

Scoping started for shadowcopy %1.

Fields #

NameDescription
SnapshotPath

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-System-Restore",
    "guid": "126CDB97-D346-4894-8A34-658DA5EEA1B6",
    "event_source_name": "",
    "event_id": 8300,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 1,
    "keywords": 9223653511831486465,
    "time_created": "2025-12-31T19:34:21.244176+00:00",
    "event_record_id": 35,
    "correlation": {},
    "execution": {
      "process_id": 8064,
      "thread_id": 8028
    },
    "channel": "Application",
    "computer": "WIN11-22H2-X64",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "Data": {
      "Name": "SnapshotPath",
      "Value": "\\\\?\\GLOBALROOT\\Device\\HarddiskVolumeShadowCopy1"
    }
  },
  "message": "Scoping started for shadowcopy SnapshotPath."
}

References #

Event ID 8301: Scoping completed for shadowcopy \\?

#
Provider
Microsoft-Windows-System-Restore
Channel
Application
Level
Informational
Opcode
Stop

Description

Scoping completed for shadowcopy .

Message #

Scoping completed for shadowcopy %1.

Fields #

NameDescription
SnapshotPath UnicodeString
ErrorCode HexInt32
TotalDirectories UInt64
TotalFiles UInt64
FilesScoped UInt64
FilesResident UInt64
FilesCachedFirstPass UInt64
FilesMissedSecondPass UInt64

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-System-Restore",
    "guid": "126CDB97-D346-4894-8A34-658DA5EEA1B6",
    "event_source_name": "",
    "event_id": 8301,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 2,
    "keywords": 9223653511831486465,
    "time_created": "2025-12-31T19:34:28.745120+00:00",
    "event_record_id": 42,
    "correlation": {},
    "execution": {
      "process_id": 8064,
      "thread_id": 8028
    },
    "channel": "Application",
    "computer": "WIN11-22H2-X64",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "SnapshotPath": "\\\\?\\GLOBALROOT\\Device\\HarddiskVolumeShadowCopy1",
    "ErrorCode": 0,
    "TotalDirectories": 24336,
    "TotalFiles": 77119,
    "FilesScoped": 582,
    "FilesResident": 110,
    "FilesCachedFirstPass": 224,
    "FilesMissedSecondPass": 0
  },
  "message": "Scoping completed for shadowcopy \\\\?\\GLOBALROOT\\Device\\HarddiskVolumeShadowCopy1."
}

References #

Event ID 8302: Scoping successfully completed for shadowcopy \\?

#
Provider
Microsoft-Windows-System-Restore
Channel
Application
Level
Informational
Opcode
Info

Description

Scoping successfully completed for shadowcopy .

Message #

Scoping successfully completed for shadowcopy %1.

Fields #

NameDescription
SnapshotPath UnicodeString
ErrorCode HexInt32
TotalDirectories UInt64
TotalFiles UInt64
FilesScoped UInt64
FilesResident UInt64
FilesCachedFirstPass UInt64
FilesMissedSecondPass UInt64

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-System-Restore",
    "guid": "126CDB97-D346-4894-8A34-658DA5EEA1B6",
    "event_source_name": "",
    "event_id": 8302,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775808,
    "time_created": "2025-12-31T19:34:28.745150+00:00",
    "event_record_id": 43,
    "correlation": {},
    "execution": {
      "process_id": 8064,
      "thread_id": 8028
    },
    "channel": "Application",
    "computer": "WIN11-22H2-X64",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "SnapshotPath": "\\\\?\\GLOBALROOT\\Device\\HarddiskVolumeShadowCopy1",
    "ErrorCode": 0,
    "TotalDirectories": 24336,
    "TotalFiles": 77119,
    "FilesScoped": 582,
    "FilesResident": 110,
    "FilesCachedFirstPass": 224,
    "FilesMissedSecondPass": 0
  },
  "message": "Scoping successfully completed for shadowcopy \\\\?\\GLOBALROOT\\Device\\HarddiskVolumeShadowCopy1."
}

References #

Event ID 8303: Scoping unsuccessful for shadowcopy SnapshotPath with error ErrorCode.

#
Provider
Microsoft-Windows-System-Restore
Channel
Application
Level
Warning
Opcode
Info

Description

Scoping unsuccessful for shadowcopy SnapshotPath with error ErrorCode.

Message #

Scoping unsuccessful for shadowcopy %1 with error %2.

Fields #

NameDescription
SnapshotPath UnicodeString
ErrorCode HexInt32
TotalDirectories UInt64
TotalFiles UInt64
FilesScoped UInt64
FilesResident UInt64
FilesCachedFirstPass UInt64
FilesMissedSecondPass UInt64

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-System-Restore",
    "guid": "{126CDB97-D346-4894-8A34-658DA5EEA1B6}",
    "event_source_name": "",
    "event_id": 8303,
    "version": 0,
    "level": 3,
    "task": 0,
    "opcode": 0,
    "keywords": -9223372036854775808,
    "time_created": "2026-05-30T01:24:19.3244297+00:00",
    "event_record_id": 210779,
    "correlation": {},
    "execution": {
      "process_id": 8,
      "thread_id": 7512
    },
    "channel": "Application",
    "computer": "JD-WIN11-22H2-1.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "SnapshotPath": "\\\\?\\GLOBALROOT\\Device\\HarddiskVolumeShadowCopy8",
    "ErrorCode": "0x80070057",
    "TotalDirectories": "80341",
    "TotalFiles": "302434",
    "FilesScoped": "105227",
    "FilesResident": "26353",
    "FilesCachedFirstPass": "31109",
    "FilesMissedSecondPass": "2"
  },
  "message": "Scoping unsuccessful for shadowcopy \\\\?\\GLOBALROOT\\Device\\HarddiskVolumeShadowCopy8 with error 0x80070057."
}

Provenance

Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.

ETW provider GUID 126cdb97-d346-4894-8a34-658da5eea1b6

Defined in SrEvents.dll, which carries the event manifest.

Observed on:

  • Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.1, captured 2026-06-02

Downloads