Microsoft-Windows-VolumeSnapshot-Driver
92 events across 2 channels
Event ID 100: The volume snapshot driver has begun processing for volume online.
#Description
The volume snapshot driver has begun processing for volume online.
Message #
Fields #
| Name | Description |
|---|---|
TargetVolumeGuid GUID | |
SourceFile HexInt32 | |
SourceLine UInt16 | |
SourceTag UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-VolumeSnapshot-Driver",
"guid": "{67FE2216-727A-40CB-94B2-C02211EDB34A}",
"event_source_name": "",
"event_id": 100,
"version": 0,
"level": 4,
"task": 0,
"opcode": 1,
"keywords": 4611686018427387904,
"time_created": "2026-05-29T16:32:44.8324115+00:00",
"event_record_id": 91,
"correlation": {},
"execution": {
"process_id": 4,
"thread_id": 196
},
"channel": "Microsoft-Windows-VolumeSnapshot-Driver/Operational",
"computer": "telemetry-DC-a.cell-a.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"TargetVolumeGuid": "{77ac4d73-0000-0000-0000-100000000000}",
"SourceFile": "0x1",
"SourceLine": "38521",
"SourceTag": "124"
},
"message": "The volume snapshot driver has begun processing for volume online.\r\n\r\nVolume GUID: {77ac4d73-0000-0000-0000-100000000000}\r\n\r\nGuidance:\r\nWhen a volume is brought online the volume snapshot driver scans for any persistent snapshots that may be on the volume.\r\n\r\nYou should expect this event when a volume is brought online. No user action is required."
}
Event ID 101: The volume snapshot driver has completed processing for volume online.
#Description
The volume snapshot driver has completed processing for volume online.
Message #
Fields #
| Name | Description |
|---|---|
TargetVolumeGuid GUID | |
SourceFile HexInt32 | |
SourceLine UInt16 | |
SourceTag UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-VolumeSnapshot-Driver",
"guid": "{67FE2216-727A-40CB-94B2-C02211EDB34A}",
"event_source_name": "",
"event_id": 101,
"version": 0,
"level": 4,
"task": 0,
"opcode": 2,
"keywords": 4611686018427387904,
"time_created": "2026-05-29T16:32:44.9120058+00:00",
"event_record_id": 98,
"correlation": {},
"execution": {
"process_id": 4,
"thread_id": 200
},
"channel": "Microsoft-Windows-VolumeSnapshot-Driver/Operational",
"computer": "telemetry-DC-a.cell-a.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"TargetVolumeGuid": "{77ac4d73-0000-0000-0000-100000000000}",
"SourceFile": "0x1",
"SourceLine": "39103",
"SourceTag": "129"
},
"message": "The volume snapshot driver has completed processing for volume online.\r\n\r\nVolume GUID: {77ac4d73-0000-0000-0000-100000000000}\r\n\r\nGuidance:\r\nThe volume snapshot driver was able to scan for any persistent snapshots on this volume.\r\n\r\nYou should expect this event when a volume is brought online. No user action is required."
}
Event ID 102: The volume snapshot driver encountered an error while performing processing for volume online.
#Event ID 103: Activation of discovered snapshots began.
#Description
Activation of discovered snapshots began.
Message #
Fields #
| Name | Description |
|---|---|
TargetVolumeGuid GUID | |
SourceFile HexInt32 | |
SourceLine UInt16 | |
SourceTag UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-VolumeSnapshot-Driver",
"guid": "67FE2216-727A-40CB-94B2-C02211EDB34A",
"event_source_name": "",
"event_id": 103,
"version": 0,
"level": 4,
"task": 0,
"opcode": 1,
"keywords": 4611686018427387904,
"time_created": "2026-03-11T06:27:09.486348+00:00",
"event_record_id": 184,
"correlation": {},
"execution": {
"process_id": 4,
"thread_id": 352
},
"channel": "Microsoft-Windows-VolumeSnapshot-Driver/Operational",
"computer": "LAB-WIN11",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"TargetVolumeGuid": "CE657EBB-70C7-4B8B-A13F-FF11B9725249",
"SourceFile": "0x1",
"SourceLine": 22127,
"SourceTag": 93
},
"message": ""
}
Event ID 104: Activation of discovered snapshots completed.
#Description
Activation of discovered snapshots completed.
Message #
Fields #
| Name | Description |
|---|---|
TargetVolumeGuid GUID | |
SnapshotCount UInt32 | |
CountDeleted UInt32 | |
CountVisible UInt32 | |
SourceFile HexInt32 | |
SourceLine UInt16 | |
SourceTag UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-VolumeSnapshot-Driver",
"guid": "67FE2216-727A-40CB-94B2-C02211EDB34A",
"event_source_name": "",
"event_id": 104,
"version": 0,
"level": 4,
"task": 0,
"opcode": 2,
"keywords": 4611686018427387904,
"time_created": "2026-03-11T06:27:09.508914+00:00",
"event_record_id": 190,
"correlation": {},
"execution": {
"process_id": 4,
"thread_id": 352
},
"channel": "Microsoft-Windows-VolumeSnapshot-Driver/Operational",
"computer": "LAB-WIN11",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"TargetVolumeGuid": "CE657EBB-70C7-4B8B-A13F-FF11B9725249",
"SnapshotCount": 3,
"CountDeleted": 0,
"CountVisible": 0,
"SourceFile": "0x1",
"SourceLine": 23009,
"SourceTag": 107
},
"message": ""
}
Event ID 105: Activation of discovered snapshots encountered an error.
#Event ID 106: A persistent snapshot was activated.
#Description
A persistent snapshot was activated.
Message #
Fields #
| Name | Description |
|---|---|
TargetVolumeGuid GUID | |
SnapshotGuid GUID | |
Deleted Boolean | |
Visible Boolean | |
CommitTime SYSTEMTIME | |
SourceFile HexInt32 | |
SourceLine UInt16 | |
SourceTag UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-VolumeSnapshot-Driver",
"guid": "67FE2216-727A-40CB-94B2-C02211EDB34A",
"event_source_name": "",
"event_id": 106,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 4611686018427387904,
"time_created": "2026-03-11T06:27:09.499366+00:00",
"event_record_id": 189,
"correlation": {},
"execution": {
"process_id": 4,
"thread_id": 352
},
"channel": "Microsoft-Windows-VolumeSnapshot-Driver/Operational",
"computer": "LAB-WIN11",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"TargetVolumeGuid": "CE657EBB-70C7-4B8B-A13F-FF11B9725249",
"SnapshotGuid": "465863F8-1B56-11F1-9FBF-C6B26F270F0B",
"Deleted": false,
"Visible": false,
"CommitTime": "2026-03-11T03:42:04.594000Z",
"SourceFile": "0x1",
"SourceLine": 20745,
"SourceTag": 92
},
"message": ""
}
Event ID 107: Reading of a snapshot diff area's metadata began.
#Description
Reading of a snapshot diff area's metadata began.
Message #
Fields #
| Name | Description |
|---|---|
TargetVolumeGuid GUID | |
SnapshotGuid GUID | |
SourceFile HexInt32 | |
SourceLine UInt16 | |
SourceTag UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-VolumeSnapshot-Driver",
"guid": "67FE2216-727A-40CB-94B2-C02211EDB34A",
"event_source_name": "",
"event_id": 107,
"version": 0,
"level": 4,
"task": 0,
"opcode": 1,
"keywords": 4611686018427387904,
"time_created": "2026-03-11T06:28:15.280120+00:00",
"event_record_id": 192,
"correlation": {},
"execution": {
"process_id": 4,
"thread_id": 4156
},
"channel": "Microsoft-Windows-VolumeSnapshot-Driver/Operational",
"computer": "LAB-WIN11",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"TargetVolumeGuid": "CE657EBB-70C7-4B8B-A13F-FF11B9725249",
"SnapshotGuid": "465845A3-1B56-11F1-9FBF-C6B26F270F0B",
"SourceFile": "0x7",
"SourceLine": 4286,
"SourceTag": 84
},
"message": ""
}
Event ID 108: Reading of a snapshot diff area's metadata completed.
#Description
Reading of a snapshot diff area's metadata completed.
Message #
Fields #
| Name | Description |
|---|---|
TargetVolumeGuid GUID | |
SnapshotGuid GUID | |
LargeReadCount UInt32 | |
SmallReadCount UInt32 | |
TableDataBytes UInt64 | |
TotalBytesRead UInt64 | |
SourceFile HexInt32 | |
SourceLine UInt16 | |
SourceTag UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-VolumeSnapshot-Driver",
"guid": "67FE2216-727A-40CB-94B2-C02211EDB34A",
"event_source_name": "",
"event_id": 108,
"version": 2,
"level": 4,
"task": 0,
"opcode": 2,
"keywords": 4611686018427387904,
"time_created": "2026-03-11T06:28:15.323019+00:00",
"event_record_id": 193,
"correlation": {},
"execution": {
"process_id": 4,
"thread_id": 4156
},
"channel": "Microsoft-Windows-VolumeSnapshot-Driver/Operational",
"computer": "LAB-WIN11",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"TargetVolumeGuid": "CE657EBB-70C7-4B8B-A13F-FF11B9725249",
"SnapshotGuid": "465845A3-1B56-11F1-9FBF-C6B26F270F0B",
"LargeReadCount": 3,
"SmallReadCount": 2,
"TableDataBytes": 3162112,
"TotalBytesRead": 3178496,
"SourceFile": "0x7",
"SourceLine": 4683,
"SourceTag": 89
},
"message": ""
}
Event ID 109: Reading of a snapshot diff area's metadata encountered an error.
#Event ID 110: Validation of diff area files began.
#Description
Validation of diff area files began.
Message #
Fields #
| Name | Description |
|---|---|
TargetVolumeGuid GUID | |
SourceFile HexInt32 | |
SourceLine UInt16 | |
SourceTag UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-VolumeSnapshot-Driver",
"guid": "{67FE2216-727A-40CB-94B2-C02211EDB34A}",
"event_source_name": "",
"event_id": 110,
"version": 0,
"level": 4,
"task": 0,
"opcode": 1,
"keywords": 4611686018427387904,
"time_created": "2026-05-30T02:25:57.1550528+00:00",
"event_record_id": 110,
"correlation": {
"ActivityID": "{711F4B45-D577-44CE-BE9F-CD60AE82F8E8}"
},
"execution": {
"process_id": 4,
"thread_id": 3544
},
"channel": "Microsoft-Windows-VolumeSnapshot-Driver/Operational",
"computer": "JD-DC01-2022.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"TargetVolumeGuid": "{df5f85cf-0000-0000-0000-010000000000}",
"SourceFile": "0x1",
"SourceLine": "37361",
"SourceTag": "116"
},
"message": "Validation of diff area files began.\r\n\r\nVolume GUID: {df5f85cf-0000-0000-0000-010000000000}\r\n\r\nGuidance:\r\nWhen a volume is mounted, the volume snapshot driver reads and validates all the diff area files located on the volume. These diff area files may be for persistent snapshots of the volume being mounted, or for persistent snapshots of other volumes.\r\n\r\nYou should expect this event when mounting a volume. No user action is required."
}
Event ID 111: Validation of diff area files completed.
#Description
Validation of diff area files completed.
Message #
Fields #
| Name | Description |
|---|---|
TargetVolumeGuid GUID | |
DiffAreaCount UInt32 | |
SourceFile HexInt32 | |
SourceLine UInt16 | |
SourceTag UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-VolumeSnapshot-Driver",
"guid": "{67FE2216-727A-40CB-94B2-C02211EDB34A}",
"event_source_name": "",
"event_id": 111,
"version": 0,
"level": 4,
"task": 0,
"opcode": 2,
"keywords": 4611686018427387904,
"time_created": "2026-05-30T02:25:57.1673438+00:00",
"event_record_id": 111,
"correlation": {
"ActivityID": "{711F4B45-D577-44CE-BE9F-CD60AE82F8E8}"
},
"execution": {
"process_id": 4,
"thread_id": 3544
},
"channel": "Microsoft-Windows-VolumeSnapshot-Driver/Operational",
"computer": "JD-DC01-2022.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"TargetVolumeGuid": "{df5f85cf-0000-0000-0000-010000000000}",
"DiffAreaCount": "1",
"SourceFile": "0x1",
"SourceLine": "37372",
"SourceTag": "117"
},
"message": "Validation of diff area files completed.\r\n\r\nNumber of Diff Areas: 1\r\n\r\nGuidance:\r\nWhen a volume is mounted, the volume snapshot driver reads and validates all the diff area files located on the volume. These diff area files may be for persistent snapshots of the volume being mounted, or for persistent snapshots of other volumes.\r\n\r\nYou should expect this event when mounting a volume. No user action is required."
}
Event ID 112: Validation of diff area files encountered an error.
#Event ID 113: The volume is preparing to be taken offline.
#Event ID 114: The volume snapshot driver has begun processing for dismount.
#Description
The volume snapshot driver has begun processing for dismount.
Message #
Fields #
| Name | Description |
|---|---|
TargetVolumeGuid GUID | |
SourceFile HexInt32 | |
SourceLine UInt16 | |
SourceTag UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-VolumeSnapshot-Driver",
"guid": "67FE2216-727A-40CB-94B2-C02211EDB34A",
"event_source_name": "",
"event_id": 114,
"version": 0,
"level": 4,
"task": 0,
"opcode": 1,
"keywords": 4611686018427387904,
"time_created": "2022-04-07T16:45:03.737710+00:00",
"event_record_id": 9,
"correlation": {},
"execution": {
"process_id": 4,
"thread_id": 32
},
"channel": "Microsoft-Windows-VolumeSnapshot-Driver/Operational",
"computer": "WIN-FPV0DSIC9O6",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"TargetVolumeGuid": "E856EAFF-60EA-4D9C-8467-32D0B50DBFFC",
"SourceFile": "0x1",
"SourceLine": 37521,
"SourceTag": 119
},
"message": ""
}
References #
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 115: The volume snapshot driver has completed processing for dismount.
#Description
The volume snapshot driver has completed processing for dismount.
Message #
Fields #
| Name | Description |
|---|---|
TargetVolumeGuid GUID | |
SourceFile HexInt32 | |
SourceLine UInt16 | |
SourceTag UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-VolumeSnapshot-Driver",
"guid": "67FE2216-727A-40CB-94B2-C02211EDB34A",
"event_source_name": "",
"event_id": 115,
"version": 0,
"level": 4,
"task": 0,
"opcode": 2,
"keywords": 4611686018427387904,
"time_created": "2022-04-07T16:45:03.737712+00:00",
"event_record_id": 10,
"correlation": {},
"execution": {
"process_id": 4,
"thread_id": 32
},
"channel": "Microsoft-Windows-VolumeSnapshot-Driver/Operational",
"computer": "WIN-FPV0DSIC9O6",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"TargetVolumeGuid": "E856EAFF-60EA-4D9C-8467-32D0B50DBFFC",
"SourceFile": "0x1",
"SourceLine": 38322,
"SourceTag": 122
},
"message": ""
}
References #
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 116: The volume snapshot driver has begun processing for volume offline.
#Description
The volume snapshot driver has begun processing for volume offline.
Message #
Fields #
| Name | Description |
|---|---|
TargetVolumeGuid GUID | |
SourceFile HexInt32 | |
SourceLine UInt16 | |
SourceTag UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-VolumeSnapshot-Driver",
"guid": "67FE2216-727A-40CB-94B2-C02211EDB34A",
"event_source_name": "",
"event_id": 116,
"version": 0,
"level": 4,
"task": 0,
"opcode": 1,
"keywords": 4611686018427387904,
"time_created": "2026-03-13T20:08:10.764027+00:00",
"event_record_id": 113,
"correlation": {},
"execution": {
"process_id": 4,
"thread_id": 4464
},
"channel": "Microsoft-Windows-VolumeSnapshot-Driver/Operational",
"computer": "LAB-WIN11.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"TargetVolumeGuid": "E3E83FDF-1F17-11F1-9FBA-010101010000",
"SourceFile": "0x1",
"SourceLine": 34284,
"SourceTag": 113
},
"message": ""
}
Event ID 117: The volume snapshot driver has completed processing for volume offline.
#Description
The volume snapshot driver has completed processing for volume offline.
Message #
Fields #
| Name | Description |
|---|---|
TargetVolumeGuid GUID | |
SourceFile HexInt32 | |
SourceLine UInt16 | |
SourceTag UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-VolumeSnapshot-Driver",
"guid": "67FE2216-727A-40CB-94B2-C02211EDB34A",
"event_source_name": "",
"event_id": 117,
"version": 0,
"level": 4,
"task": 0,
"opcode": 2,
"keywords": 4611686018427387904,
"time_created": "2026-03-13T20:08:10.764058+00:00",
"event_record_id": 114,
"correlation": {},
"execution": {
"process_id": 4,
"thread_id": 4464
},
"channel": "Microsoft-Windows-VolumeSnapshot-Driver/Operational",
"computer": "LAB-WIN11.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"TargetVolumeGuid": "E3E83FDF-1F17-11F1-9FBA-010101010000",
"SourceFile": "0x1",
"SourceLine": 34312,
"SourceTag": 114
},
"message": ""
}
Event ID 118: The volume snapshot driver encountered an error while performing processing for volume offline.
#Event ID 119: The volume snapshot driver encountered an error while performing processing for dismount.
#Event ID 120: Activation of discovered snapshots took too long and was aborted.
#Event ID 121: The volume snapshot driver was unable to log an event to the legacy System event log.
#Description
The volume snapshot driver was unable to log an event to the legacy System event log.
Message #
Fields #
| Name | Description |
|---|---|
VolumeNameLength UInt16 | |
VolumeName UnicodeString | |
DiffVolumeNameLength UInt16 | |
DiffVolumeName UnicodeString | |
OriginalErrorLogCode UInt32 | |
OriginalErrorStatus HexInt32 | |
OriginalSourceFile HexInt32 | |
OriginalSourceLine UInt16 | |
OriginalSourceTag UInt32 | |
ErrorStatus HexInt32 | |
SourceFile HexInt32 | |
SourceLine UInt16 | |
SourceTag UInt32 |
Event ID 122: The volume snapshot driver encountered an error when attempting to determine whether the volume is clustered.
#Event ID 123: Persistent snapshots are not supported on this edition of Windows.
#Event ID 1000: PrepareForSnapshot (Enter)
#Event ID 1001: PrepareForSnapshot (Leave)
#Event ID 1002: PreExposure (Enter)
#Event ID 1003: PreExposure (Leave)
#Event ID 1004: AdjustBitmap (Enter)
#Event ID 1005: AdjustBitmap (Leave)
#Event ID 1006: EndCommit (Enter)
#Event ID 1007: EndCommit (Leave)
#Event ID 1008: Activate (Enter)
#Event ID 1009: Activate (Leave)
#Event ID 1010: SetIgnorable (Enter)
#Event ID 1011: SetIgnorable (Leave)
#Event ID 1012: ComputeIgnorableProduct (Enter)
#Event ID 1013: ComputeIgnorableProduct (Leave)
#Event ID 1014: Dismount (Enter)
#Event ID 1015: Dismount (Leave)
#Event ID 1016: Remount (Enter)
#Event ID 1017: Remount (Leave)
#Event ID 1018: DeleteProcess (Enter)
#Event ID 1019: DeleteProcess (Leave)
#Event ID 1020: Revert (Enter)
#Event ID 1021: Revert (Leave)
#Event ID 1022: ComputeProtectedBitmap (Enter)
#Event ID 1023: ComputeProtectedBitmap (Leave)
#Event ID 1024: FlushHoldFs (Enter)
#Event ID 1025: FlushHoldFs (Leave)
#Event ID 1026: ActivateLoop (Enter)
#Event ID 1027: ActivateLoop (Leave)
#Event ID 1028: ValidateDiffAreaFiles (Enter)
#Event ID 1029: ValidateDiffAreaFiles (Leave)
#Event ID 1030: VolumesSafeForWrite (Enter)
#Event ID 1031: VolumesSafeForWrite (Leave)
#Event ID 1032: DiscoverSnapshots (Enter)
#Event ID 1033: DiscoverSnapshots (Leave)
#Provenance
Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.
ETW provider GUID 67fe2216-727a-40cb-94b2-c02211edb34a
Defined in volsnap.sys, the binary that emits these events.
Observed on:
- WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.1, captured 2026-06-02
- Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.1, captured 2026-06-02