Microsoft-Windows-VolumeSnapshot-Driver
Event ID 100: The volume snapshot driver has begun processing for volume online.
#Message #
Fields #
| Name | Description |
|---|---|
TargetVolumeGuid GUID | |
SourceFile HexInt32 | |
SourceLine UInt16 | |
SourceTag UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-VolumeSnapshot-Driver",
"guid": "{67FE2216-727A-40CB-94B2-C02211EDB34A}",
"event_source_name": "",
"event_id": 100,
"version": 0,
"level": 4,
"task": 0,
"opcode": 1,
"keywords": 4611686018427387904,
"time_created": "2026-05-29T16:32:44.8324115+00:00",
"event_record_id": 91,
"correlation": {},
"execution": {
"process_id": 4,
"thread_id": 196
},
"channel": "Microsoft-Windows-VolumeSnapshot-Driver/Operational",
"computer": "telemetry-DC-a.cell-a.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"TargetVolumeGuid": "{77ac4d73-0000-0000-0000-100000000000}",
"SourceFile": "0x1",
"SourceLine": "38521",
"SourceTag": "124"
},
"message": "The volume snapshot driver has begun processing for volume online.\r\n\r\nVolume GUID: {77ac4d73-0000-0000-0000-100000000000}\r\n\r\nGuidance:\r\nWhen a volume is brought online the volume snapshot driver scans for any persistent snapshots that may be on the volume.\r\n\r\nYou should expect this event when a volume is brought online. No user action is required."
}
Event ID 101: The volume snapshot driver has completed processing for volume online.
#Message #
Fields #
| Name | Description |
|---|---|
TargetVolumeGuid GUID | |
SourceFile HexInt32 | |
SourceLine UInt16 | |
SourceTag UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-VolumeSnapshot-Driver",
"guid": "{67FE2216-727A-40CB-94B2-C02211EDB34A}",
"event_source_name": "",
"event_id": 101,
"version": 0,
"level": 4,
"task": 0,
"opcode": 2,
"keywords": 4611686018427387904,
"time_created": "2026-05-29T16:32:44.9120058+00:00",
"event_record_id": 98,
"correlation": {},
"execution": {
"process_id": 4,
"thread_id": 200
},
"channel": "Microsoft-Windows-VolumeSnapshot-Driver/Operational",
"computer": "telemetry-DC-a.cell-a.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"TargetVolumeGuid": "{77ac4d73-0000-0000-0000-100000000000}",
"SourceFile": "0x1",
"SourceLine": "39103",
"SourceTag": "129"
},
"message": "The volume snapshot driver has completed processing for volume online.\r\n\r\nVolume GUID: {77ac4d73-0000-0000-0000-100000000000}\r\n\r\nGuidance:\r\nThe volume snapshot driver was able to scan for any persistent snapshots on this volume.\r\n\r\nYou should expect this event when a volume is brought online. No user action is required."
}
Event ID 102: The volume snapshot driver encountered an error while performing processing for volume online.
#Event ID 103: Activation of discovered snapshots began.
#Message #
Fields #
| Name | Description |
|---|---|
TargetVolumeGuid GUID | |
SourceFile HexInt32 | |
SourceLine UInt16 | |
SourceTag UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-VolumeSnapshot-Driver",
"guid": "67FE2216-727A-40CB-94B2-C02211EDB34A",
"event_source_name": "",
"event_id": 103,
"version": 0,
"level": 4,
"task": 0,
"opcode": 1,
"keywords": 4611686018427387904,
"time_created": "2026-03-11T06:27:09.486348+00:00",
"event_record_id": 184,
"correlation": {},
"execution": {
"process_id": 4,
"thread_id": 352
},
"channel": "Microsoft-Windows-VolumeSnapshot-Driver/Operational",
"computer": "LAB-WIN11",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"TargetVolumeGuid": "CE657EBB-70C7-4B8B-A13F-FF11B9725249",
"SourceFile": "0x1",
"SourceLine": 22127,
"SourceTag": 93
},
"message": ""
}
Event ID 104: Activation of discovered snapshots completed.
#Message #
Fields #
| Name | Description |
|---|---|
TargetVolumeGuid GUID | |
SnapshotCount UInt32 | |
CountDeleted UInt32 | |
CountVisible UInt32 | |
SourceFile HexInt32 | |
SourceLine UInt16 | |
SourceTag UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-VolumeSnapshot-Driver",
"guid": "67FE2216-727A-40CB-94B2-C02211EDB34A",
"event_source_name": "",
"event_id": 104,
"version": 0,
"level": 4,
"task": 0,
"opcode": 2,
"keywords": 4611686018427387904,
"time_created": "2026-03-11T06:27:09.508914+00:00",
"event_record_id": 190,
"correlation": {},
"execution": {
"process_id": 4,
"thread_id": 352
},
"channel": "Microsoft-Windows-VolumeSnapshot-Driver/Operational",
"computer": "LAB-WIN11",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"TargetVolumeGuid": "CE657EBB-70C7-4B8B-A13F-FF11B9725249",
"SnapshotCount": 3,
"CountDeleted": 0,
"CountVisible": 0,
"SourceFile": "0x1",
"SourceLine": 23009,
"SourceTag": 107
},
"message": ""
}
Event ID 105: Activation of discovered snapshots encountered an error.
#Event ID 106: A persistent snapshot was activated.
#Message #
Fields #
| Name | Description |
|---|---|
TargetVolumeGuid GUID | |
SnapshotGuid GUID | |
Deleted Boolean | |
Visible Boolean | |
CommitTime SYSTEMTIME | |
SourceFile HexInt32 | |
SourceLine UInt16 | |
SourceTag UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-VolumeSnapshot-Driver",
"guid": "67FE2216-727A-40CB-94B2-C02211EDB34A",
"event_source_name": "",
"event_id": 106,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 4611686018427387904,
"time_created": "2026-03-11T06:27:09.499366+00:00",
"event_record_id": 189,
"correlation": {},
"execution": {
"process_id": 4,
"thread_id": 352
},
"channel": "Microsoft-Windows-VolumeSnapshot-Driver/Operational",
"computer": "LAB-WIN11",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"TargetVolumeGuid": "CE657EBB-70C7-4B8B-A13F-FF11B9725249",
"SnapshotGuid": "465863F8-1B56-11F1-9FBF-C6B26F270F0B",
"Deleted": false,
"Visible": false,
"CommitTime": "2026-03-11T03:42:04.594000Z",
"SourceFile": "0x1",
"SourceLine": 20745,
"SourceTag": 92
},
"message": ""
}
Event ID 107: Reading of a snapshot diff area's metadata began.
#Message #
Fields #
| Name | Description |
|---|---|
TargetVolumeGuid GUID | |
SnapshotGuid GUID | |
SourceFile HexInt32 | |
SourceLine UInt16 | |
SourceTag UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-VolumeSnapshot-Driver",
"guid": "67FE2216-727A-40CB-94B2-C02211EDB34A",
"event_source_name": "",
"event_id": 107,
"version": 0,
"level": 4,
"task": 0,
"opcode": 1,
"keywords": 4611686018427387904,
"time_created": "2026-03-11T06:28:15.280120+00:00",
"event_record_id": 192,
"correlation": {},
"execution": {
"process_id": 4,
"thread_id": 4156
},
"channel": "Microsoft-Windows-VolumeSnapshot-Driver/Operational",
"computer": "LAB-WIN11",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"TargetVolumeGuid": "CE657EBB-70C7-4B8B-A13F-FF11B9725249",
"SnapshotGuid": "465845A3-1B56-11F1-9FBF-C6B26F270F0B",
"SourceFile": "0x7",
"SourceLine": 4286,
"SourceTag": 84
},
"message": ""
}
Event ID 108: Reading of a snapshot diff area's metadata completed.
#Message #
Fields #
| Name | Description |
|---|---|
TargetVolumeGuid GUID | |
SnapshotGuid GUID | |
LargeReadCount UInt32 | |
SmallReadCount UInt32 | |
TableDataBytes UInt64 | |
TotalBytesRead UInt64 | |
SourceFile HexInt32 | |
SourceLine UInt16 | |
SourceTag UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-VolumeSnapshot-Driver",
"guid": "67FE2216-727A-40CB-94B2-C02211EDB34A",
"event_source_name": "",
"event_id": 108,
"version": 2,
"level": 4,
"task": 0,
"opcode": 2,
"keywords": 4611686018427387904,
"time_created": "2026-03-11T06:28:15.323019+00:00",
"event_record_id": 193,
"correlation": {},
"execution": {
"process_id": 4,
"thread_id": 4156
},
"channel": "Microsoft-Windows-VolumeSnapshot-Driver/Operational",
"computer": "LAB-WIN11",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"TargetVolumeGuid": "CE657EBB-70C7-4B8B-A13F-FF11B9725249",
"SnapshotGuid": "465845A3-1B56-11F1-9FBF-C6B26F270F0B",
"LargeReadCount": 3,
"SmallReadCount": 2,
"TableDataBytes": 3162112,
"TotalBytesRead": 3178496,
"SourceFile": "0x7",
"SourceLine": 4683,
"SourceTag": 89
},
"message": ""
}
Event ID 109: Reading of a snapshot diff area's metadata encountered an error.
#Event ID 110: Validation of diff area files began.
#Message #
Fields #
| Name | Description |
|---|---|
TargetVolumeGuid GUID | |
SourceFile HexInt32 | |
SourceLine UInt16 | |
SourceTag UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-VolumeSnapshot-Driver",
"guid": "{67FE2216-727A-40CB-94B2-C02211EDB34A}",
"event_source_name": "",
"event_id": 110,
"version": 0,
"level": 4,
"task": 0,
"opcode": 1,
"keywords": 4611686018427387904,
"time_created": "2026-05-30T02:25:57.1550528+00:00",
"event_record_id": 110,
"correlation": {
"ActivityID": "{711F4B45-D577-44CE-BE9F-CD60AE82F8E8}"
},
"execution": {
"process_id": 4,
"thread_id": 3544
},
"channel": "Microsoft-Windows-VolumeSnapshot-Driver/Operational",
"computer": "JD-DC01-2022.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"TargetVolumeGuid": "{df5f85cf-0000-0000-0000-010000000000}",
"SourceFile": "0x1",
"SourceLine": "37361",
"SourceTag": "116"
},
"message": "Validation of diff area files began.\r\n\r\nVolume GUID: {df5f85cf-0000-0000-0000-010000000000}\r\n\r\nGuidance:\r\nWhen a volume is mounted, the volume snapshot driver reads and validates all the diff area files located on the volume. These diff area files may be for persistent snapshots of the volume being mounted, or for persistent snapshots of other volumes.\r\n\r\nYou should expect this event when mounting a volume. No user action is required."
}
Event ID 111: Validation of diff area files completed.
#Message #
Fields #
| Name | Description |
|---|---|
TargetVolumeGuid GUID | |
DiffAreaCount UInt32 | |
SourceFile HexInt32 | |
SourceLine UInt16 | |
SourceTag UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-VolumeSnapshot-Driver",
"guid": "{67FE2216-727A-40CB-94B2-C02211EDB34A}",
"event_source_name": "",
"event_id": 111,
"version": 0,
"level": 4,
"task": 0,
"opcode": 2,
"keywords": 4611686018427387904,
"time_created": "2026-05-30T02:25:57.1673438+00:00",
"event_record_id": 111,
"correlation": {
"ActivityID": "{711F4B45-D577-44CE-BE9F-CD60AE82F8E8}"
},
"execution": {
"process_id": 4,
"thread_id": 3544
},
"channel": "Microsoft-Windows-VolumeSnapshot-Driver/Operational",
"computer": "JD-DC01-2022.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"TargetVolumeGuid": "{df5f85cf-0000-0000-0000-010000000000}",
"DiffAreaCount": "1",
"SourceFile": "0x1",
"SourceLine": "37372",
"SourceTag": "117"
},
"message": "Validation of diff area files completed.\r\n\r\nNumber of Diff Areas: 1\r\n\r\nGuidance:\r\nWhen a volume is mounted, the volume snapshot driver reads and validates all the diff area files located on the volume. These diff area files may be for persistent snapshots of the volume being mounted, or for persistent snapshots of other volumes.\r\n\r\nYou should expect this event when mounting a volume. No user action is required."
}
Event ID 112: Validation of diff area files encountered an error.
#Event ID 113: The volume is preparing to be taken offline.
#Event ID 114: The volume snapshot driver has begun processing for dismount.
#Message #
Fields #
| Name | Description |
|---|---|
TargetVolumeGuid GUID | |
SourceFile HexInt32 | |
SourceLine UInt16 | |
SourceTag UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-VolumeSnapshot-Driver",
"guid": "67FE2216-727A-40CB-94B2-C02211EDB34A",
"event_source_name": "",
"event_id": 114,
"version": 0,
"level": 4,
"task": 0,
"opcode": 1,
"keywords": 4611686018427387904,
"time_created": "2022-04-07T16:45:03.737710+00:00",
"event_record_id": 9,
"correlation": {},
"execution": {
"process_id": 4,
"thread_id": 32
},
"channel": "Microsoft-Windows-VolumeSnapshot-Driver/Operational",
"computer": "WIN-FPV0DSIC9O6",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"TargetVolumeGuid": "E856EAFF-60EA-4D9C-8467-32D0B50DBFFC",
"SourceFile": "0x1",
"SourceLine": 37521,
"SourceTag": 119
},
"message": ""
}
References #
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 115: The volume snapshot driver has completed processing for dismount.
#Message #
Fields #
| Name | Description |
|---|---|
TargetVolumeGuid GUID | |
SourceFile HexInt32 | |
SourceLine UInt16 | |
SourceTag UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-VolumeSnapshot-Driver",
"guid": "67FE2216-727A-40CB-94B2-C02211EDB34A",
"event_source_name": "",
"event_id": 115,
"version": 0,
"level": 4,
"task": 0,
"opcode": 2,
"keywords": 4611686018427387904,
"time_created": "2022-04-07T16:45:03.737712+00:00",
"event_record_id": 10,
"correlation": {},
"execution": {
"process_id": 4,
"thread_id": 32
},
"channel": "Microsoft-Windows-VolumeSnapshot-Driver/Operational",
"computer": "WIN-FPV0DSIC9O6",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"TargetVolumeGuid": "E856EAFF-60EA-4D9C-8467-32D0B50DBFFC",
"SourceFile": "0x1",
"SourceLine": 38322,
"SourceTag": 122
},
"message": ""
}
References #
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 116: The volume snapshot driver has begun processing for volume offline.
#Message #
Fields #
| Name | Description |
|---|---|
TargetVolumeGuid GUID | |
SourceFile HexInt32 | |
SourceLine UInt16 | |
SourceTag UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-VolumeSnapshot-Driver",
"guid": "67FE2216-727A-40CB-94B2-C02211EDB34A",
"event_source_name": "",
"event_id": 116,
"version": 0,
"level": 4,
"task": 0,
"opcode": 1,
"keywords": 4611686018427387904,
"time_created": "2026-03-13T20:08:10.764027+00:00",
"event_record_id": 113,
"correlation": {},
"execution": {
"process_id": 4,
"thread_id": 4464
},
"channel": "Microsoft-Windows-VolumeSnapshot-Driver/Operational",
"computer": "LAB-WIN11.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"TargetVolumeGuid": "E3E83FDF-1F17-11F1-9FBA-010101010000",
"SourceFile": "0x1",
"SourceLine": 34284,
"SourceTag": 113
},
"message": ""
}
Event ID 117: The volume snapshot driver has completed processing for volume offline.
#Message #
Fields #
| Name | Description |
|---|---|
TargetVolumeGuid GUID | |
SourceFile HexInt32 | |
SourceLine UInt16 | |
SourceTag UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-VolumeSnapshot-Driver",
"guid": "67FE2216-727A-40CB-94B2-C02211EDB34A",
"event_source_name": "",
"event_id": 117,
"version": 0,
"level": 4,
"task": 0,
"opcode": 2,
"keywords": 4611686018427387904,
"time_created": "2026-03-13T20:08:10.764058+00:00",
"event_record_id": 114,
"correlation": {},
"execution": {
"process_id": 4,
"thread_id": 4464
},
"channel": "Microsoft-Windows-VolumeSnapshot-Driver/Operational",
"computer": "LAB-WIN11.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"TargetVolumeGuid": "E3E83FDF-1F17-11F1-9FBA-010101010000",
"SourceFile": "0x1",
"SourceLine": 34312,
"SourceTag": 114
},
"message": ""
}
Event ID 118: The volume snapshot driver encountered an error while performing processing for volume offline.
#Event ID 119: The volume snapshot driver encountered an error while performing processing for dismount.
#Event ID 120: Activation of discovered snapshots took too long and was aborted.
#Event ID 121: The volume snapshot driver was unable to log an event to the legacy System event log.
#Message #
Fields #
| Name | Description |
|---|---|
VolumeNameLength UInt16 | |
VolumeName UnicodeString | |
DiffVolumeNameLength UInt16 | |
DiffVolumeName UnicodeString | |
OriginalErrorLogCode UInt32 | |
OriginalErrorStatus HexInt32 | |
OriginalSourceFile HexInt32 | |
OriginalSourceLine UInt16 | |
OriginalSourceTag UInt32 | |
ErrorStatus HexInt32 | |
SourceFile HexInt32 | |
SourceLine UInt16 | |
SourceTag UInt32 |
Event ID 122: The volume snapshot driver encountered an error when attempting to determine whether the volume is clustered.
#Event ID 123: Persistent snapshots are not supported on this edition of Windows.
#Event ID 1000: PrepareForSnapshot (Enter)
#Fields #
| Name | Description |
|---|---|
DiagPrefixLength UInt16 | |
DiagPrefix UnicodeString | |
VolumeNameLength UInt16 | |
VolumeName UnicodeString | |
TargetVolumeGuid GUID | |
SnapshotGuid GUID | |
SourceFile HexInt32 | |
SourceLine UInt16 | |
SourceTag UInt32 |
Event ID 1001: PrepareForSnapshot (Leave)
#Fields #
| Name | Description |
|---|---|
DiagPrefixLength UInt16 | |
DiagPrefix UnicodeString | |
VolumeNameLength UInt16 | |
VolumeName UnicodeString | |
TargetVolumeGuid GUID | |
SnapshotGuid GUID | |
ExitStatus HexInt32 | |
SourceFile HexInt32 | |
SourceLine UInt16 | |
SourceTag UInt32 |
Event ID 1002: PreExposure (Enter)
#Fields #
| Name | Description |
|---|---|
DiagPrefixLength UInt16 | |
DiagPrefix UnicodeString | |
VolumeNameLength UInt16 | |
VolumeName UnicodeString | |
TargetVolumeGuid GUID | |
SnapshotGuid GUID | |
SourceFile HexInt32 | |
SourceLine UInt16 | |
SourceTag UInt32 |
Event ID 1003: PreExposure (Leave)
#Fields #
| Name | Description |
|---|---|
DiagPrefixLength UInt16 | |
DiagPrefix UnicodeString | |
VolumeNameLength UInt16 | |
VolumeName UnicodeString | |
TargetVolumeGuid GUID | |
SnapshotGuid GUID | |
ExitStatus HexInt32 | |
SourceFile HexInt32 | |
SourceLine UInt16 | |
SourceTag UInt32 |
Event ID 1004: AdjustBitmap (Enter)
#Fields #
| Name | Description |
|---|---|
DiagPrefixLength UInt16 | |
DiagPrefix UnicodeString | |
VolumeNameLength UInt16 | |
VolumeName UnicodeString | |
TargetVolumeGuid GUID | |
SnapshotGuid GUID | |
SourceFile HexInt32 | |
SourceLine UInt16 | |
SourceTag UInt32 |
Event ID 1005: AdjustBitmap (Leave)
#Fields #
| Name | Description |
|---|---|
DiagPrefixLength UInt16 | |
DiagPrefix UnicodeString | |
VolumeNameLength UInt16 | |
VolumeName UnicodeString | |
TargetVolumeGuid GUID | |
SnapshotGuid GUID | |
ExitStatus HexInt32 | |
SourceFile HexInt32 | |
SourceLine UInt16 | |
SourceTag UInt32 |
Event ID 1006: EndCommit (Enter)
#Fields #
| Name | Description |
|---|---|
DiagPrefixLength UInt16 | |
DiagPrefix UnicodeString | |
VolumeNameLength UInt16 | |
VolumeName UnicodeString | |
TargetVolumeGuid GUID | |
SnapshotGuid GUID | |
SourceFile HexInt32 | |
SourceLine UInt16 | |
SourceTag UInt32 |
Event ID 1007: EndCommit (Leave)
#Fields #
| Name | Description |
|---|---|
DiagPrefixLength UInt16 | |
DiagPrefix UnicodeString | |
VolumeNameLength UInt16 | |
VolumeName UnicodeString | |
TargetVolumeGuid GUID | |
SnapshotGuid GUID | |
ExitStatus HexInt32 | |
SourceFile HexInt32 | |
SourceLine UInt16 | |
SourceTag UInt32 |
Event ID 1008: Activate (Enter)
#Fields #
| Name | Description |
|---|---|
DiagPrefixLength UInt16 | |
DiagPrefix UnicodeString | |
VolumeNameLength UInt16 | |
VolumeName UnicodeString | |
TargetVolumeGuid GUID | |
SnapshotGuid GUID | |
SourceFile HexInt32 | |
SourceLine UInt16 | |
SourceTag UInt32 |
Event ID 1009: Activate (Leave)
#Fields #
| Name | Description |
|---|---|
DiagPrefixLength UInt16 | |
DiagPrefix UnicodeString | |
VolumeNameLength UInt16 | |
VolumeName UnicodeString | |
TargetVolumeGuid GUID | |
SnapshotGuid GUID | |
ExitStatus HexInt32 | |
SourceFile HexInt32 | |
SourceLine UInt16 | |
SourceTag UInt32 |
Event ID 1010: SetIgnorable (Enter)
#Fields #
| Name | Description |
|---|---|
DiagPrefixLength UInt16 | |
DiagPrefix UnicodeString | |
VolumeNameLength UInt16 | |
VolumeName UnicodeString | |
TargetVolumeGuid GUID | |
SnapshotGuid GUID | |
SourceFile HexInt32 | |
SourceLine UInt16 | |
SourceTag UInt32 |
Event ID 1011: SetIgnorable (Leave)
#Fields #
| Name | Description |
|---|---|
DiagPrefixLength UInt16 | |
DiagPrefix UnicodeString | |
VolumeNameLength UInt16 | |
VolumeName UnicodeString | |
TargetVolumeGuid GUID | |
SnapshotGuid GUID | |
ExitStatus HexInt32 | |
SourceFile HexInt32 | |
SourceLine UInt16 | |
SourceTag UInt32 |
Event ID 1012: ComputeIgnorableProduct (Enter)
#Fields #
| Name | Description |
|---|---|
DiagPrefixLength UInt16 | |
DiagPrefix UnicodeString | |
VolumeNameLength UInt16 | |
VolumeName UnicodeString | |
TargetVolumeGuid GUID | |
SnapshotGuid GUID | |
SourceFile HexInt32 | |
SourceLine UInt16 | |
SourceTag UInt32 |
Event ID 1013: ComputeIgnorableProduct (Leave)
#Fields #
| Name | Description |
|---|---|
DiagPrefixLength UInt16 | |
DiagPrefix UnicodeString | |
VolumeNameLength UInt16 | |
VolumeName UnicodeString | |
TargetVolumeGuid GUID | |
SnapshotGuid GUID | |
ExitStatus HexInt32 | |
SourceFile HexInt32 | |
SourceLine UInt16 | |
SourceTag UInt32 |
Event ID 1014: Dismount (Enter)
#Fields #
| Name | Description |
|---|---|
DiagPrefixLength UInt16 | |
DiagPrefix UnicodeString | |
VolumeNameLength UInt16 | |
VolumeName UnicodeString | |
TargetVolumeGuid GUID | |
SnapshotGuid GUID | |
SourceFile HexInt32 | |
SourceLine UInt16 | |
SourceTag UInt32 |
Event ID 1015: Dismount (Leave)
#Fields #
| Name | Description |
|---|---|
DiagPrefixLength UInt16 | |
DiagPrefix UnicodeString | |
VolumeNameLength UInt16 | |
VolumeName UnicodeString | |
TargetVolumeGuid GUID | |
SnapshotGuid GUID | |
ExitStatus HexInt32 | |
SourceFile HexInt32 | |
SourceLine UInt16 | |
SourceTag UInt32 |
Event ID 1016: Remount (Enter)
#Fields #
| Name | Description |
|---|---|
DiagPrefixLength UInt16 | |
DiagPrefix UnicodeString | |
VolumeNameLength UInt16 | |
VolumeName UnicodeString | |
TargetVolumeGuid GUID | |
SnapshotGuid GUID | |
SourceFile HexInt32 | |
SourceLine UInt16 | |
SourceTag UInt32 |
Event ID 1017: Remount (Leave)
#Fields #
| Name | Description |
|---|---|
DiagPrefixLength UInt16 | |
DiagPrefix UnicodeString | |
VolumeNameLength UInt16 | |
VolumeName UnicodeString | |
TargetVolumeGuid GUID | |
SnapshotGuid GUID | |
ExitStatus HexInt32 | |
SourceFile HexInt32 | |
SourceLine UInt16 | |
SourceTag UInt32 |
Event ID 1018: DeleteProcess (Enter)
#Fields #
| Name | Description |
|---|---|
DiagPrefixLength UInt16 | |
DiagPrefix UnicodeString | |
VolumeNameLength UInt16 | |
VolumeName UnicodeString | |
TargetVolumeGuid GUID | |
SnapshotGuid GUID | |
SourceFile HexInt32 | |
SourceLine UInt16 | |
SourceTag UInt32 |
Event ID 1019: DeleteProcess (Leave)
#Fields #
| Name | Description |
|---|---|
DiagPrefixLength UInt16 | |
DiagPrefix UnicodeString | |
VolumeNameLength UInt16 | |
VolumeName UnicodeString | |
TargetVolumeGuid GUID | |
SnapshotGuid GUID | |
ExitStatus HexInt32 | |
SourceFile HexInt32 | |
SourceLine UInt16 | |
SourceTag UInt32 |
Event ID 1020: Revert (Enter)
#Fields #
| Name | Description |
|---|---|
DiagPrefixLength UInt16 | |
DiagPrefix UnicodeString | |
VolumeNameLength UInt16 | |
VolumeName UnicodeString | |
TargetVolumeGuid GUID | |
SnapshotGuid GUID | |
SourceFile HexInt32 | |
SourceLine UInt16 | |
SourceTag UInt32 |
Event ID 1021: Revert (Leave)
#Fields #
| Name | Description |
|---|---|
DiagPrefixLength UInt16 | |
DiagPrefix UnicodeString | |
VolumeNameLength UInt16 | |
VolumeName UnicodeString | |
TargetVolumeGuid GUID | |
SnapshotGuid GUID | |
ExitStatus HexInt32 | |
SourceFile HexInt32 | |
SourceLine UInt16 | |
SourceTag UInt32 |
Event ID 1022: ComputeProtectedBitmap (Enter)
#Fields #
| Name | Description |
|---|---|
DiagPrefixLength UInt16 | |
DiagPrefix UnicodeString | |
VolumeNameLength UInt16 | |
VolumeName UnicodeString | |
TargetVolumeGuid GUID | |
SnapshotGuid GUID | |
SourceFile HexInt32 | |
SourceLine UInt16 | |
SourceTag UInt32 |
Event ID 1023: ComputeProtectedBitmap (Leave)
#Fields #
| Name | Description |
|---|---|
DiagPrefixLength UInt16 | |
DiagPrefix UnicodeString | |
VolumeNameLength UInt16 | |
VolumeName UnicodeString | |
TargetVolumeGuid GUID | |
SnapshotGuid GUID | |
ExitStatus HexInt32 | |
SourceFile HexInt32 | |
SourceLine UInt16 | |
SourceTag UInt32 |
Event ID 1024: FlushHoldFs (Enter)
#Fields #
| Name | Description |
|---|---|
DiagPrefixLength UInt16 | |
DiagPrefix UnicodeString | |
VolumeNameLength UInt16 | |
VolumeName UnicodeString | |
TargetVolumeGuid GUID | |
SnapshotGuid GUID | |
SourceFile HexInt32 | |
SourceLine UInt16 | |
SourceTag UInt32 |
Event ID 1025: FlushHoldFs (Leave)
#Fields #
| Name | Description |
|---|---|
DiagPrefixLength UInt16 | |
DiagPrefix UnicodeString | |
VolumeNameLength UInt16 | |
VolumeName UnicodeString | |
TargetVolumeGuid GUID | |
SnapshotGuid GUID | |
ExitStatus HexInt32 | |
SourceFile HexInt32 | |
SourceLine UInt16 | |
SourceTag UInt32 |
Event ID 1026: ActivateLoop (Enter)
#Fields #
| Name | Description |
|---|---|
DiagPrefixLength UInt16 | |
DiagPrefix UnicodeString | |
VolumeNameLength UInt16 | |
VolumeName UnicodeString | |
TargetVolumeGuid GUID | |
SnapshotGuid GUID | |
SourceFile HexInt32 | |
SourceLine UInt16 | |
SourceTag UInt32 |
Event ID 1027: ActivateLoop (Leave)
#Fields #
| Name | Description |
|---|---|
DiagPrefixLength UInt16 | |
DiagPrefix UnicodeString | |
VolumeNameLength UInt16 | |
VolumeName UnicodeString | |
TargetVolumeGuid GUID | |
SnapshotGuid GUID | |
ExitStatus HexInt32 | |
SourceFile HexInt32 | |
SourceLine UInt16 | |
SourceTag UInt32 |
Event ID 1028: ValidateDiffAreaFiles (Enter)
#Fields #
| Name | Description |
|---|---|
DiagPrefixLength UInt16 | |
DiagPrefix UnicodeString | |
VolumeNameLength UInt16 | |
VolumeName UnicodeString | |
TargetVolumeGuid GUID | |
SnapshotGuid GUID | |
SourceFile HexInt32 | |
SourceLine UInt16 | |
SourceTag UInt32 |
Event ID 1029: ValidateDiffAreaFiles (Leave)
#Fields #
| Name | Description |
|---|---|
DiagPrefixLength UInt16 | |
DiagPrefix UnicodeString | |
VolumeNameLength UInt16 | |
VolumeName UnicodeString | |
TargetVolumeGuid GUID | |
SnapshotGuid GUID | |
ExitStatus HexInt32 | |
SourceFile HexInt32 | |
SourceLine UInt16 | |
SourceTag UInt32 |
Event ID 1030: VolumesSafeForWrite (Enter)
#Fields #
| Name | Description |
|---|---|
DiagPrefixLength UInt16 | |
DiagPrefix UnicodeString | |
VolumeNameLength UInt16 | |
VolumeName UnicodeString | |
TargetVolumeGuid GUID | |
SnapshotGuid GUID | |
SourceFile HexInt32 | |
SourceLine UInt16 | |
SourceTag UInt32 |
Event ID 1031: VolumesSafeForWrite (Leave)
#Fields #
| Name | Description |
|---|---|
DiagPrefixLength UInt16 | |
DiagPrefix UnicodeString | |
VolumeNameLength UInt16 | |
VolumeName UnicodeString | |
TargetVolumeGuid GUID | |
SnapshotGuid GUID | |
ExitStatus HexInt32 | |
SourceFile HexInt32 | |
SourceLine UInt16 | |
SourceTag UInt32 |
Provenance
ETW provider GUID 67fe2216-727a-40cb-94b2-c02211edb34a
Defined in volsnap.sys, the binary that emits these events.
- WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.1, captured 2026-06-02 — Manifest XML pack, 1.9 MB
- Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.1, captured 2026-06-02 — Manifest XML pack, 2.0 MB