Microsoft-Windows-VIRTDISK

10 events across 1 channel

EventTitleChannelSample
1Opening backing store VhdFileName as type VhdVirtualStorageType.Microsoft-Windows-VIRTDISK-AnalyticN
2Opened backing store, returning handle VhdHandle, status VhdStatus.Microsoft-Windows-VIRTDISK-AnalyticN
3Attaching using handle VhdHandle.Microsoft-Windows-VIRTDISK-AnalyticN
4Attached with status VhdStatus.Microsoft-Windows-VIRTDISK-AnalyticN
5Detaching using handle VhdHandle.Microsoft-Windows-VIRTDISK-AnalyticN
6Detached with status VhdStatus.Microsoft-Windows-VIRTDISK-AnalyticN
1000TraceData.Microsoft-Windows-VIRTDISK-AnalyticN
1001TraceData.Microsoft-Windows-VIRTDISK-AnalyticN
1002TraceData.Microsoft-Windows-VIRTDISK-AnalyticN
1003TraceData.Microsoft-Windows-VIRTDISK-AnalyticN

Event ID 1: Opening backing store VhdFileName as type VhdVirtualStorageType.

#
Provider
Microsoft-Windows-VIRTDISK
Channel
Microsoft-Windows-VIRTDISK-Analytic
Task
Openvirtualdisk.
Opcode
Start

Description

Opening backing store VhdFileName as type VhdVirtualStorageType.

Message #

Opening backing store %1 as type %2.

Fields #

NameDescription
VhdFileName UnicodeString
VhdVirtualStorageType UInt32

Event ID 2: Opened backing store, returning handle VhdHandle, status VhdStatus.

#
Provider
Microsoft-Windows-VIRTDISK
Channel
Microsoft-Windows-VIRTDISK-Analytic
Task
Openvirtualdisk.
Opcode
Stop

Description

Opened backing store, returning handle VhdHandle, status VhdStatus.

Message #

Opened backing store, returning handle %1, status %2.

Fields #

NameDescription
VhdHandle Pointer
VhdStatus UInt32

Event ID 3: Attaching using handle VhdHandle.

#
Provider
Microsoft-Windows-VIRTDISK
Channel
Microsoft-Windows-VIRTDISK-Analytic
Task
Attachvirtualdisk.
Opcode
Start

Description

Attaching using handle VhdHandle.

Message #

Attaching using handle %1.

Fields #

NameDescription
VhdHandle Pointer

Event ID 4: Attached with status VhdStatus.

#
Provider
Microsoft-Windows-VIRTDISK
Channel
Microsoft-Windows-VIRTDISK-Analytic
Task
Attachvirtualdisk.
Opcode
Stop

Description

Attached with status VhdStatus.

Message #

Attached with status %1.

Fields #

NameDescription
VhdStatus UInt32

Event ID 5: Detaching using handle VhdHandle.

#
Provider
Microsoft-Windows-VIRTDISK
Channel
Microsoft-Windows-VIRTDISK-Analytic
Task
Detachvirtualdisk.
Opcode
Start

Description

Detaching using handle VhdHandle.

Message #

Detaching using handle %1.

Fields #

NameDescription
VhdHandle Pointer

Event ID 6: Detached with status VhdStatus.

#
Provider
Microsoft-Windows-VIRTDISK
Channel
Microsoft-Windows-VIRTDISK-Analytic
Task
Detachvirtualdisk.
Opcode
Stop

Description

Detached with status VhdStatus.

Message #

Detached with status %1.

Fields #

NameDescription
VhdStatus UInt32

Event ID 1000: TraceData.

#
Provider
Microsoft-Windows-VIRTDISK
Channel
Microsoft-Windows-VIRTDISK-Analytic

Description

TraceData

Message #

%1

Fields #

NameDescription
TraceData UnicodeString
VmName UnicodeString
VmId UnicodeString
StackFrameCount UInt32
StackFrame Pointer
ModuleCount UInt32
Module Int32

Event ID 1001: TraceData.

#
Provider
Microsoft-Windows-VIRTDISK
Channel
Microsoft-Windows-VIRTDISK-Analytic

Description

TraceData

Message #

%1

Fields #

NameDescription
TraceData UnicodeString
VmName UnicodeString
VmId UnicodeString
StackFrameCount UInt32
StackFrame Pointer
ModuleCount UInt32
Module Int32

Event ID 1002: TraceData.

#
Provider
Microsoft-Windows-VIRTDISK
Channel
Microsoft-Windows-VIRTDISK-Analytic

Description

TraceData

Message #

%1

Fields #

NameDescription
TraceData UnicodeString
VmName UnicodeString
VmId UnicodeString
StackFrameCount UInt32
StackFrame Pointer
ModuleCount UInt32
Module Int32

Event ID 1003: TraceData.

#
Provider
Microsoft-Windows-VIRTDISK
Channel
Microsoft-Windows-VIRTDISK-Analytic

Description

TraceData

Message #

%1

Fields #

NameDescription
TraceData UnicodeString
VmName UnicodeString
VmId UnicodeString
StackFrameCount UInt32
StackFrame Pointer
ModuleCount UInt32
Module Int32

Provenance

Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.

ETW provider GUID 4d20df22-e177-4514-a369-f1759feedeb3

Defined in virtdisk.dll, which carries the event manifest.

Observed on:

  • WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.2849, captured 2026-06-02
  • Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.5074, captured 2026-06-02

Downloads