Microsoft-Windows-WerKernel
2 events across 1 channel
| Event | Title | Channel | Sample |
|---|---|---|---|
| 1001 | Component ComponentName has requested to create a Live Kernel Dump and the … | Operational | N |
| 1002 | Component ComponentName has requested to submit a Live Kernel Dump and the … | Operational | N |
Event ID 1001: Component ComponentName has requested to create a Live Kernel Dump and the request has been completed.
#Description
Component ComponentName has requested to create a Live Kernel Dump and the request has been completed. RequestedType RequestedPolicy, GrantedType GrantedPolicy, Status Status, ThrottleCheckResult ThrottleCheckResult.
Message #
Fields #
| Name | Description |
|---|---|
ComponentName UnicodeString | |
RequestedPolicy UInt32 | |
GrantedPolicy UInt32 | |
Status UInt32 | NTSTATUS reference |
ThrottleCheckResult UInt32 |
Event ID 1002: Component ComponentName has requested to submit a Live Kernel Dump and the request has been completed.
#Description
Component ComponentName has requested to submit a Live Kernel Dump and the request has been completed. DumpType Policy, ReportId ReportId, Status Status.
Message #
Fields #
| Name | Description |
|---|---|
ComponentName UnicodeString | |
Policy UInt32 | |
ReportId UnicodeString | |
Status UInt32 | NTSTATUS reference |
Provenance
Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.
ETW provider GUID 87a623f0-8db5-5c11-7c80-a2ebbcbe5189
Defined in werkernel.sys, the binary that emits these events.
Observed on:
- Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.5074, captured 2026-06-02