Volsnap
122 events across 2 channels
Event ID 1: The shadow copy of volume {VolumeNameLength} could not create shadow copy storage on volume {VolumeName}.
#Event ID 2: The shadow copy of volume {VolumeNameLength} could not be created because volume {VolumeName}; which is specified as the location for shadow copy s...
#Event ID 3: The shadow copy of volume {VolumeNameLength} could not lock down the location of the shadow copy storage on volume {VolumeName}.
#Event ID 4: The shadow copy of volume {VolumeNameLength} could not be created due to insufficient resources for worker threads.
#Event ID 5: The shadow copy of volume {VolumeNameLength} could not be created due to insufficient non-paged memory pool for a bitmap structure.
#Event ID 6: The shadow copy of volume {VolumeNameLength} could not create a new paged heap.
#Event ID 7: The shadow copy of volume {VolumeNameLength} failed to query the shadow copy storage mappings on volume {VolumeName}.
#Event ID 8: The flush and hold writes operation on volume {VolumeNameLength} timed out while waiting for a release writes command.
#Event ID 9: The flush and hold writes operation on volume {VolumeNameLength} timed out while waiting for file system cleanup.
#Event ID 10: The shadow copy of volume {VolumeNameLength} took too long to install.
#Event ID 13: The shadow copy of volume {VolumeNameLength} could not grow its shadow copy storage on volume {VolumeName}.
#Event ID 14: The shadow copies of volume {VolumeNameLength} were aborted because of an IO failure on volume {VolumeName}.
#Event ID 15: The shadow copies of volume {VolumeNameLength} were aborted because of insufficient paged heap.
#Event ID 16: The shadow copies of volume {VolumeNameLength} were aborted because volume {VolumeName}; which contains shadow copy storage for this shadow copy; w...
#Event ID 17: An attempt to flush and hold writes on volume {VolumeNameLength} was attempted while another flush and hold was already in progress.
#Event ID 20: The shadow copies of volume {VolumeNameLength} were aborted because of a failed free space computation.
#Event ID 21: The flush and hold operation for volume {VolumeNameLength} was aborted because of low available system memory.
#Event ID 22: The shadow copy storage volume specified for shadow copies on volume {VolumeNameLength} could not be added.
#Event ID 23: There was insufficient disk space on volume {VolumeName} to create the shadow copy of volume {VolumeNameLength}.
#Event ID 24: There was insufficient disk space on volume {VolumeName} to grow the shadow copy storage for shadow copies of {VolumeNameLength}.
#Event ID 25: The shadow copies of volume {VolumeNameLength} were deleted because the shadow copy storage could not grow in time.
#Event ID 27: The shadow copies of volume {VolumeNameLength} were aborted during detection because a critical control file could not be opened.
#Event ID 28: The shadow copy of volume {VolumeNameLength} could not be created due to a failure in creating the necessary on disk structures.
#Event ID 29: The shadow copies of volume {VolumeNameLength} were aborted during detection.
#Event ID 30: An unfinished create of a shadow copy of volume {VolumeNameLength} was deleted.
#Event ID 31: A control item for shadow copies of volume {VolumeNameLength} was lost during detection.
#Event ID 32: The shadow copies of volume {VolumeNameLength} were aborted because the shadow copy storage volume was not present.
#Event ID 33: The oldest shadow copy of volume {VolumeNameLength} was deleted to keep disk space usage for shadow copies of volume {VolumeNameLength} below the u...
#Description
The oldest shadow copy of volume {VolumeNameLength} was deleted to keep disk space usage for shadow copies of volume {VolumeNameLength} below the user defined limit.
Message #
Fields #
| Name | Description |
|---|---|
DeviceName | |
VolumeName | |
NTSTATUS | |
SourceTag | |
SourceFileID | |
SourceLine | |
Binary | |
VolumeNameLength |
Example Event #
{
"system": {
"provider": "Volsnap",
"guid": "{cb017cd2-1f37-4e65-82bc-3e91f6a37559}",
"event_source_name": "volsnap",
"event_id": 33,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 36028797018963968,
"time_created": "2026-03-13T20:24:47.568855+00:00",
"event_record_id": 11832,
"correlation": {},
"execution": {
"process_id": 4,
"thread_id": 384
},
"channel": "System",
"computer": "LAB-DC01.ludus.domain",
"security": {
"user_id": ""
}
},
"event_data": {
"DeviceName": "\\Device\\HarddiskVolumeShadowCopy1",
"VolumeName": "C:",
"NTSTATUS": "00000000",
"SourceTag": "178",
"SourceFileID": "0x0001",
"SourceLine": "6386",
"Binary": "00000000060030000000000021000640B20000000000000000000000000000000000000000000000"
},
"message": ""
}
Event ID 35: The shadow copies of volume {VolumeNameLength} were aborted because the shadow copy storage failed to grow.
#Event ID 36: The shadow copies of volume {VolumeNameLength} were aborted because the shadow copy storage could not grow due to a user imposed limit.
#Description
The shadow copies of volume {VolumeNameLength} were aborted because the shadow copy storage could not grow due to a user imposed limit.
Message #
Fields #
| Name | Description |
|---|---|
VolumeNameLength |
Example Event #
{
"system": {
"provider": "volsnap",
"guid": "",
"event_source_name": "",
"event_id": 36,
"version": 0,
"level": 2,
"task": 0,
"opcode": 0,
"keywords": 36028797018963968,
"time_created": "2012-03-21T04:21:17.758144Z",
"event_record_id": 12919,
"correlation": {},
"execution": {
"process_id": 0,
"thread_id": 0
},
"channel": "System",
"computer": "WKS-WIN764BITB.shieldbase.local",
"security": {
"user_id": ""
}
},
"event_data": {
"Data": [
"\\Device\\HarddiskVolumeShadowCopy2",
"C:"
],
"Binary": "000000000200300000000000240006C0020000000000000000000000000000000000000000000000"
}
}
Event ID 38: There was a user imposed limit that prevented disk space on volume {VolumeName} from being used to grow the shadow copy storage for shadow copies o...
#Event ID 39: When preparing a new volume shadow copy for volume {VolumeNameLength}; the shadow copy storage on volume {VolumeName} could not be located in non-c...
#Event ID 40: The shadow copies of volume {VolumeNameLength} were aborted because volume {VolumeName} has been dismounted.
#Event ID 41: When preparing a new volume shadow copy for volume {VolumeNameLength}; the shadow copy storage on volume {VolumeName} did not have sufficiently lar...
#Event ID 48: When preparing a new volume shadow copy for volume {VolumeNameLength}; the shadow copy storage on volume {VolumeName} did not have sufficiently lar...
#Event ID 58: The oldest shadow copy of volume {VolumeNameLength} was deleted to keep the total number of shadow copies of volume {VolumeNameLength} below a limit.
#Event ID 59: The shadow copies of volume {VolumeNameLength} were aborted because the shadow copy storage volume was not present in time during a previous session.
#Event ID 60: The shadow copies of volume {VolumeNameLength} were aborted because volume {VolumeName}; which contains shadow copy storage for this shadow copy; h...
#Event ID 61: The revert operation on volume {VolumeNameLength} encountered a bad sector error.
#Event ID 62: The revert operation on volume {VolumeNameLength} stopped because of the loss of a volume.
#Event ID 63: An error occurred while trying to delete a snapshot of {VolumeNameLength}.
#Event ID 64: Volume {VolumeNameLength} is being reverted to the state of a previous shadow copy.
#Event ID 65: The reverting of volume {VolumeNameLength} is being restarted.
#Event ID 66: The reverting of volume {VolumeNameLength} to the state of a previous shadow copy is complete.
#Event ID 67: The shadow copy of volume {VolumeNameLength} being created failed to install.
#Event ID 80: Volume {VolumeNameLength} is offline for shadow copy protection.
#Event ID 81: Volume {VolumeNameLength} is offline for shadow copy protection.
#Event ID 82: Volume {VolumeNameLength} is offline for shadow copy protection.
#Event ID 83: Volume {VolumeNameLength} is offline for shadow copy protection.
#Event ID 84: Volume {VolumeNameLength} is offline for shadow copy protection.
#Event ID 85: Volume {VolumeNameLength} is offline for shadow copy protection.
#Event ID 86: Volume {VolumeNameLength} is offline for shadow copy protection.
#Event ID 87: Volume {VolumeNameLength} is offline for shadow copy protection.
#Event ID 88: Volume {VolumeNameLength} is offline for shadow copy protection.
#Event ID 89: Volume {VolumeNameLength} is offline for shadow copy protection.
#Event ID 90: Volume {VolumeNameLength} is offline for shadow copy protection.
#Event ID 91: Volume {VolumeNameLength} is offline for shadow copy protection.
#Event ID 92: Volume {VolumeNameLength} is offline for shadow copy protection.
#Event ID 93: Volume {VolumeNameLength} is offline for shadow copy protection.
#Event ID 94: Volume {VolumeNameLength} is offline for shadow copy protection.
#Event ID 1074135073: The oldest shadow copy of volume VolumeName was deleted to keep disk space usage for shadow copies of volume VolumeName below the user defined limit.
#Description
The oldest shadow copy of volume VolumeName was deleted to keep disk space usage for shadow copies of volume VolumeName below the user defined limit.
Message #
Fields #
| Name | Description |
|---|---|
DeviceName UnicodeString | |
VolumeName UnicodeString | |
NTSTATUS UnicodeString | |
SourceTag UnicodeString | |
SourceFileID UnicodeString | |
SourceLine UnicodeString | |
binary Binary |
Example Event #
{
"system": {
"provider": "Volsnap",
"event_id": 33,
"level": "Information",
"task": null,
"opcode": null,
"time_created": "2026-03-13T20:24:48.4197163+00:00",
"computer": "JD-DC01-2022.ludus.domain",
"channel": "System"
},
"event_data": {
"DeviceName": "\\Device\\HarddiskVolumeShadowCopy7",
"NTSTATUS": "00000000",
"VolumeName": "C:",
"SourceFileID": "0x0001",
"SourceLine": "6386",
"SourceTag": "178"
}
}
Event ID 1074135098: The oldest shadow copy of volume VolumeName was deleted to keep the total number of shadow copies of volume VolumeName below a limit.
#Description
The oldest shadow copy of volume VolumeName was deleted to keep the total number of shadow copies of volume VolumeName below a limit.
Message #
Fields #
| Name | Description |
|---|---|
DeviceName UnicodeString | |
VolumeName UnicodeString | |
NTSTATUS UnicodeString | |
SourceTag UnicodeString | |
SourceFileID UnicodeString | |
SourceLine UnicodeString | |
binary Binary |
Event ID 1074135104: Volume VolumeName is being reverted to the state of a previous shadow copy.
#Event ID 1074135105: The reverting of volume VolumeName is being restarted.
#Description
The reverting of volume VolumeName is being restarted. This is most likely because of a system shutdown or a system crash.
Message #
Fields #
| Name | Description |
|---|---|
DeviceName UnicodeString | |
VolumeName UnicodeString | |
NTSTATUS UnicodeString | |
SourceTag UnicodeString | |
SourceFileID UnicodeString | |
SourceLine UnicodeString | |
binary Binary |
Event ID 1074135106: The reverting of volume VolumeName to the state of a previous shadow copy is complete.
#Event ID 1074135135: The oldest shadow copy of volume VolumeName was deleted to allow shadow copies created afterward and marked for delete to be deleted.
#Description
The oldest shadow copy of volume VolumeName was deleted to allow shadow copies created afterward and marked for delete to be deleted.
Message #
Fields #
| Name | Description |
|---|---|
DeviceName UnicodeString | |
VolumeName UnicodeString | |
NTSTATUS UnicodeString | |
SourceTag UnicodeString | |
SourceFileID UnicodeString | |
SourceLine UnicodeString | |
binary Binary |
Event ID 2147876888: There was insufficient disk space on volume DiffAreaVolumeName to grow the shadow copy storage for shadow copies of VolumeName.
#Description
There was insufficient disk space on volume DiffAreaVolumeName to grow the shadow copy storage for shadow copies of VolumeName. As a result of this failure all shadow copies of volume VolumeName are at risk of being deleted.
Message #
Fields #
| Name | Description |
|---|---|
DeviceName UnicodeString | |
VolumeName UnicodeString | |
DiffAreaVolumeName UnicodeString | |
NTSTATUS UnicodeString | |
SourceTag UnicodeString | |
SourceFileID UnicodeString | |
SourceLine UnicodeString | |
binary Binary |
Event ID 2147876894: An unfinished create of a shadow copy of volume VolumeName was deleted.
#Event ID 2147876902: There was a user imposed limit that prevented disk space on volume DiffAreaVolumeName from being used to grow the shadow copy storage for shadow copies of VolumeName.
#Description
There was a user imposed limit that prevented disk space on volume DiffAreaVolumeName from being used to grow the shadow copy storage for shadow copies of VolumeName. As a result of this failure all shadow copies of volume VolumeName are at risk of being deleted.
Message #
Fields #
| Name | Description |
|---|---|
DeviceName UnicodeString | |
VolumeName UnicodeString | |
DiffAreaVolumeName UnicodeString | |
NTSTATUS UnicodeString | |
SourceTag UnicodeString | |
SourceFileID UnicodeString | |
SourceLine UnicodeString | |
binary Binary |
Event ID 2147876925: The revert operation on volume VolumeName encountered a bad sector error.
#Description
The revert operation on volume VolumeName encountered a bad sector error. Please validate the data on this volume.
Message #
Fields #
| Name | Description |
|---|---|
DeviceName UnicodeString | |
VolumeName UnicodeString | |
NTSTATUS UnicodeString | |
SourceTag UnicodeString | |
SourceFileID UnicodeString | |
SourceLine UnicodeString | |
binary Binary |
Event ID 2147876926: The revert operation on volume VolumeName stopped because of the loss of a volume.
#Description
The revert operation on volume VolumeName stopped because of the loss of a volume. When the volume is re-introduced, the revert will continue. You may have to reboot to trigger the revert.
Message #
Fields #
| Name | Description |
|---|---|
DeviceName UnicodeString | |
VolumeName UnicodeString | |
NTSTATUS UnicodeString | |
SourceTag UnicodeString | |
SourceFileID UnicodeString | |
SourceLine UnicodeString | |
binary Binary |
Event ID 3221618689: The shadow copy of volume VolumeName could not create shadow copy storage on volume DiffAreaVolumeName.
#Description
The shadow copy of volume VolumeName could not create shadow copy storage on volume DiffAreaVolumeName.
Message #
Fields #
| Name | Description |
|---|---|
DeviceName UnicodeString | |
VolumeName UnicodeString | |
DiffAreaVolumeName UnicodeString | |
NTSTATUS UnicodeString | |
SourceTag UnicodeString | |
SourceFileID UnicodeString | |
SourceLine UnicodeString | |
binary Binary |
Event ID 3221618690: The shadow copy of volume VolumeName could not be created because volume DiffAreaVolumeName, which is specified as the location for shadow copy storage, is not an NTFS vol...
#Description
The shadow copy of volume VolumeName could not be created because volume DiffAreaVolumeName, which is specified as the location for shadow copy storage, is not an NTFS volume or an error was encountered while trying to determine the file system type of this volume.
Message #
Fields #
| Name | Description |
|---|---|
DeviceName UnicodeString | |
VolumeName UnicodeString | |
DiffAreaVolumeName UnicodeString | |
NTSTATUS UnicodeString | |
SourceTag UnicodeString | |
SourceFileID UnicodeString | |
SourceLine UnicodeString | |
binary Binary |
Event ID 3221618691: The shadow copy of volume VolumeName could not lock down the location of the shadow copy storage on volume DiffAreaVolumeName.
#Description
The shadow copy of volume VolumeName could not lock down the location of the shadow copy storage on volume DiffAreaVolumeName.
Message #
Fields #
| Name | Description |
|---|---|
DeviceName UnicodeString | |
VolumeName UnicodeString | |
DiffAreaVolumeName UnicodeString | |
NTSTATUS UnicodeString | |
SourceTag UnicodeString | |
SourceFileID UnicodeString | |
SourceLine UnicodeString | |
binary Binary |
Event ID 3221618692: The shadow copy of volume VolumeName could not be created due to insufficient resources for worker threads.
#Description
The shadow copy of volume VolumeName could not be created due to insufficient resources for worker threads.
Message #
Fields #
| Name | Description |
|---|---|
DeviceName UnicodeString | |
VolumeName UnicodeString | |
NTSTATUS UnicodeString | |
SourceTag UnicodeString | |
SourceFileID UnicodeString | |
SourceLine UnicodeString | |
binary Binary |
Event ID 3221618693: The shadow copy of volume VolumeName could not be created due to insufficient non-paged memory pool for a bitmap structure.
#Description
The shadow copy of volume VolumeName could not be created due to insufficient non-paged memory pool for a bitmap structure.
Message #
Fields #
| Name | Description |
|---|---|
DeviceName UnicodeString | |
VolumeName UnicodeString | |
NTSTATUS UnicodeString | |
SourceTag UnicodeString | |
SourceFileID UnicodeString | |
SourceLine UnicodeString | |
binary Binary |
Event ID 3221618694: The shadow copy of volume VolumeName could not create a new paged heap.
#Description
The shadow copy of volume VolumeName could not create a new paged heap. The system may be low on virtual memory.
Message #
Fields #
| Name | Description |
|---|---|
DeviceName UnicodeString | |
VolumeName UnicodeString | |
NTSTATUS UnicodeString | |
SourceTag UnicodeString | |
SourceFileID UnicodeString | |
SourceLine UnicodeString | |
binary Binary |
Event ID 3221618695: The shadow copy of volume VolumeName failed to query the shadow copy storage mappings on volume DiffAreaVolumeName.
#Description
The shadow copy of volume VolumeName failed to query the shadow copy storage mappings on volume DiffAreaVolumeName.
Message #
Fields #
| Name | Description |
|---|---|
DeviceName UnicodeString | |
VolumeName UnicodeString | |
DiffAreaVolumeName UnicodeString | |
NTSTATUS UnicodeString | |
SourceTag UnicodeString | |
SourceFileID UnicodeString | |
SourceLine UnicodeString | |
binary Binary |
Event ID 3221618696: The flush and hold writes operation on volume VolumeName timed out while waiting for a release writes command.
#Description
The flush and hold writes operation on volume VolumeName timed out while waiting for a release writes command.
Message #
Fields #
| Name | Description |
|---|---|
DeviceName UnicodeString | |
VolumeName UnicodeString | |
NTSTATUS UnicodeString | |
SourceTag UnicodeString | |
SourceFileID UnicodeString | |
SourceLine UnicodeString | |
binary Binary |
Event ID 3221618697: The flush and hold writes operation on volume VolumeName timed out while waiting for file system cleanup.
#Description
The flush and hold writes operation on volume VolumeName timed out while waiting for file system cleanup.
Message #
Fields #
| Name | Description |
|---|---|
DeviceName UnicodeString | |
VolumeName UnicodeString | |
NTSTATUS UnicodeString | |
SourceTag UnicodeString | |
SourceFileID UnicodeString | |
SourceLine UnicodeString | |
binary Binary |
Event ID 3221618698: The shadow copy of volume VolumeName took too long to install.
#Event ID 3221618701: The shadow copy of volume VolumeName could not grow its shadow copy storage on volume DiffAreaVolumeName.
#Description
The shadow copy of volume VolumeName could not grow its shadow copy storage on volume DiffAreaVolumeName.
Message #
Fields #
| Name | Description |
|---|---|
DeviceName UnicodeString | |
VolumeName UnicodeString | |
DiffAreaVolumeName UnicodeString | |
NTSTATUS UnicodeString | |
SourceTag UnicodeString | |
SourceFileID UnicodeString | |
SourceLine UnicodeString | |
binary Binary |
Event ID 3221618702: The shadow copies of volume VolumeName were aborted because of an IO failure on volume DiffAreaVolumeName.
#Description
The shadow copies of volume VolumeName were aborted because of an IO failure on volume DiffAreaVolumeName.
Message #
Fields #
| Name | Description |
|---|---|
DeviceName UnicodeString | |
VolumeName UnicodeString | |
DiffAreaVolumeName UnicodeString | |
NTSTATUS UnicodeString | |
SourceTag UnicodeString | |
SourceFileID UnicodeString | |
SourceLine UnicodeString | |
binary Binary |
Event ID 3221618703: The shadow copies of volume VolumeName were aborted because of insufficient paged heap.
#Event ID 3221618704: The shadow copies of volume VolumeName were aborted because volume DiffAreaVolumeName, which contains shadow copy storage for this shadow copy, was force dismounted.
#Description
The shadow copies of volume VolumeName were aborted because volume DiffAreaVolumeName, which contains shadow copy storage for this shadow copy, was force dismounted.
Message #
Fields #
| Name | Description |
|---|---|
DeviceName UnicodeString | |
VolumeName UnicodeString | |
DiffAreaVolumeName UnicodeString | |
NTSTATUS UnicodeString | |
SourceTag UnicodeString | |
SourceFileID UnicodeString | |
SourceLine UnicodeString | |
binary Binary |
Event ID 3221618705: An attempt to flush and hold writes on volume VolumeName was attempted while another flush and hold was already in progress.
#Description
An attempt to flush and hold writes on volume VolumeName was attempted while another flush and hold was already in progress.
Message #
Fields #
| Name | Description |
|---|---|
DeviceName UnicodeString | |
VolumeName UnicodeString | |
NTSTATUS UnicodeString | |
SourceTag UnicodeString | |
SourceFileID UnicodeString | |
SourceLine UnicodeString | |
binary Binary |
Event ID 3221618708: The shadow copies of volume VolumeName were aborted because of a failed free space computation.
#Event ID 3221618709: The flush and hold operation for volume VolumeName was aborted because of low available system memory.
#Description
The flush and hold operation for volume VolumeName was aborted because of low available system memory.
Message #
Fields #
| Name | Description |
|---|---|
DeviceName UnicodeString | |
VolumeName UnicodeString | |
NTSTATUS UnicodeString | |
SourceTag UnicodeString | |
SourceFileID UnicodeString | |
SourceLine UnicodeString | |
binary Binary |
Event ID 3221618710: The shadow copy storage volume specified for shadow copies on volume VolumeName could not be added.
#Event ID 3221618711: There was insufficient disk space on volume DiffAreaVolumeName to create the shadow copy of volume VolumeName.
#Description
There was insufficient disk space on volume DiffAreaVolumeName to create the shadow copy of volume VolumeName. Shadow copy storage creation failed.
Message #
Fields #
| Name | Description |
|---|---|
DeviceName UnicodeString | |
VolumeName UnicodeString | |
DiffAreaVolumeName UnicodeString | |
NTSTATUS UnicodeString | |
SourceTag UnicodeString | |
SourceFileID UnicodeString | |
SourceLine UnicodeString | |
binary Binary |
Event ID 3221618713: The shadow copies of volume VolumeName were deleted because the shadow copy storage could not grow in time.
#Description
The shadow copies of volume VolumeName were deleted because the shadow copy storage could not grow in time. Consider reducing the IO load on the system or choose a shadow copy storage volume that is not being shadow copied.
Message #
Fields #
| Name | Description |
|---|---|
DeviceName UnicodeString | |
VolumeName UnicodeString | |
NTSTATUS UnicodeString | |
SourceTag UnicodeString | |
SourceFileID UnicodeString | |
SourceLine UnicodeString | |
binary Binary |
Event ID 3221618715: The shadow copies of volume VolumeName were aborted during detection because a critical control file could not be opened.
#Description
The shadow copies of volume VolumeName were aborted during detection because a critical control file could not be opened.
Message #
Fields #
| Name | Description |
|---|---|
DeviceName UnicodeString | |
VolumeName UnicodeString | |
NTSTATUS UnicodeString | |
SourceTag UnicodeString | |
SourceFileID UnicodeString | |
SourceLine UnicodeString | |
binary Binary |
Event ID 3221618716: The shadow copy of volume VolumeName could not be created due to a failure in creating the necessary on disk structures.
#Description
The shadow copy of volume VolumeName could not be created due to a failure in creating the necessary on disk structures.
Message #
Fields #
| Name | Description |
|---|---|
DeviceName UnicodeString | |
VolumeName UnicodeString | |
NTSTATUS UnicodeString | |
SourceTag UnicodeString | |
SourceFileID UnicodeString | |
SourceLine UnicodeString | |
binary Binary |
Event ID 3221618717: The shadow copies of volume VolumeName were aborted during detection.
#Event ID 3221618719: A control item for shadow copies of volume VolumeName was lost during detection.
#Event ID 3221618720: The shadow copies of volume VolumeName were aborted because the shadow copy storage volume was not present.
#Description
The shadow copies of volume VolumeName were aborted because the shadow copy storage volume was not present.
Message #
Fields #
| Name | Description |
|---|---|
DeviceName UnicodeString | |
VolumeName UnicodeString | |
NTSTATUS UnicodeString | |
SourceTag UnicodeString | |
SourceFileID UnicodeString | |
SourceLine UnicodeString | |
binary Binary |
Event ID 3221618723: The shadow copies of volume VolumeName were aborted because the shadow copy storage failed to grow.
#Event ID 3221618724: The shadow copies of volume VolumeName were aborted because the shadow copy storage could not grow due to a user imposed limit.
#Description
The shadow copies of volume VolumeName were aborted because the shadow copy storage could not grow due to a user imposed limit.
Message #
Fields #
| Name | Description |
|---|---|
DeviceName UnicodeString | |
VolumeName UnicodeString | |
NTSTATUS UnicodeString | |
SourceTag UnicodeString | |
SourceFileID UnicodeString | |
SourceLine UnicodeString | |
binary Binary |
Event ID 3221618727: When preparing a new volume shadow copy for volume VolumeName, the shadow copy storage on volume DiffAreaVolumeName could not be located in non-critical space.
#Description
When preparing a new volume shadow copy for volume VolumeName, the shadow copy storage on volume DiffAreaVolumeName could not be located in non-critical space. Consider using a shadow copy storage volume that does not have any shadow copies.
Message #
Fields #
| Name | Description |
|---|---|
DeviceName UnicodeString | |
VolumeName UnicodeString | |
DiffAreaVolumeName UnicodeString | |
NTSTATUS UnicodeString | |
SourceTag UnicodeString | |
SourceFileID UnicodeString | |
SourceLine UnicodeString | |
binary Binary |
Event ID 3221618728: The shadow copies of volume VolumeName were aborted because volume DiffAreaVolumeName has been dismounted.
#Description
The shadow copies of volume VolumeName were aborted because volume DiffAreaVolumeName has been dismounted.
Message #
Fields #
| Name | Description |
|---|---|
DeviceName UnicodeString | |
VolumeName UnicodeString | |
DiffAreaVolumeName UnicodeString | |
NTSTATUS UnicodeString | |
SourceTag UnicodeString | |
SourceFileID UnicodeString | |
SourceLine UnicodeString | |
binary Binary |
Event ID 3221618729: When preparing a new volume shadow copy for volume VolumeName, the shadow copy storage on volume DiffAreaVolumeName did not have sufficiently large contiguous blocks.
#Description
When preparing a new volume shadow copy for volume VolumeName, the shadow copy storage on volume DiffAreaVolumeName did not have sufficiently large contiguous blocks. Consider deleting unnecessary files on the shadow copy storage volume or use a different shadow copy storage volume.
Message #
Fields #
| Name | Description |
|---|---|
DeviceName UnicodeString | |
VolumeName UnicodeString | |
DiffAreaVolumeName UnicodeString | |
NTSTATUS UnicodeString | |
SourceTag UnicodeString | |
SourceFileID UnicodeString | |
SourceLine UnicodeString | |
binary Binary |
Event ID 3221618736: When preparing a new volume shadow copy for volume VolumeName, the shadow copy storage on volume DiffAreaVolumeName did not have sufficiently large contiguous blocks.
#Description
When preparing a new volume shadow copy for volume VolumeName, the shadow copy storage on volume DiffAreaVolumeName did not have sufficiently large contiguous blocks. A shadow copy create computation is in progress to find more contiguous blocks.
Message #
Fields #
| Name | Description |
|---|---|
DeviceName UnicodeString | |
VolumeName UnicodeString | |
DiffAreaVolumeName UnicodeString | |
NTSTATUS UnicodeString | |
SourceTag UnicodeString | |
SourceFileID UnicodeString | |
SourceLine UnicodeString | |
binary Binary |
Event ID 3221618747: The shadow copies of volume VolumeName were aborted because the shadow copy storage volume was not present in time during a previous session.
#Description
The shadow copies of volume VolumeName were aborted because the shadow copy storage volume was not present in time during a previous session.
Message #
Fields #
| Name | Description |
|---|---|
DeviceName UnicodeString | |
VolumeName UnicodeString | |
NTSTATUS UnicodeString | |
SourceTag UnicodeString | |
SourceFileID UnicodeString | |
SourceLine UnicodeString | |
binary Binary |
Event ID 3221618748: The shadow copies of volume VolumeName were aborted because volume DiffAreaVolumeName, which contains shadow copy storage for this shadow copy, has been taken offline.
#Description
The shadow copies of volume VolumeName were aborted because volume DiffAreaVolumeName, which contains shadow copy storage for this shadow copy, has been taken offline.
Message #
Fields #
| Name | Description |
|---|---|
DeviceName UnicodeString | |
VolumeName UnicodeString | |
DiffAreaVolumeName UnicodeString | |
NTSTATUS UnicodeString | |
SourceTag UnicodeString | |
SourceFileID UnicodeString | |
SourceLine UnicodeString | |
binary Binary |
Event ID 3221618751: An error occurred while trying to delete a snapshot of VolumeName.
#Description
An error occurred while trying to delete a snapshot of VolumeName. The delete will be retried at a later time.
Message #
Fields #
| Name | Description |
|---|---|
DeviceName UnicodeString | |
VolumeName UnicodeString | |
NTSTATUS UnicodeString | |
SourceTag UnicodeString | |
SourceFileID UnicodeString | |
SourceLine UnicodeString | |
binary Binary |
Event ID 3221618755: The shadow copy of volume VolumeName being created failed to install.
#Event ID 3221618768: Volume VolumeName is offline for shadow copy protection.
#Description
Volume VolumeName is offline for shadow copy protection. The shadow copy storage is not present. This volume will go online and its shadow copies will become available once the shadow copy storage is introduced in the system. Revert out of shadow copy protection mode to reclaim the use of the volume while losing the shadow copies.
Message #
Fields #
| Name | Description |
|---|---|
DeviceName UnicodeString | |
VolumeName UnicodeString | |
NTSTATUS UnicodeString | |
SourceTag UnicodeString | |
SourceFileID UnicodeString | |
SourceLine UnicodeString | |
binary Binary |
Event ID 3221618769: Volume VolumeName is offline for shadow copy protection.
#Description
Volume VolumeName is offline for shadow copy protection. An IO error occurred during shadow copy discovery. Please try clearing the protection fault or restart the computer. If all else fails, revert out of shadow copy protection mode to reclaim the use of the volume while losing the shadow copies.
Message #
Fields #
| Name | Description |
|---|---|
DeviceName UnicodeString | |
VolumeName UnicodeString | |
NTSTATUS UnicodeString | |
SourceTag UnicodeString | |
SourceFileID UnicodeString | |
SourceLine UnicodeString | |
binary Binary |
Event ID 3221618770: Volume VolumeName is offline for shadow copy protection.
#Description
Volume VolumeName is offline for shadow copy protection. A shadow copy meta data corruption was detected. Please try clearing the protection fault or restart the computer. If all else fails, revert out of shadow copy protection mode to reclaim the use of the volume while losing the shadow copies.
Message #
Fields #
| Name | Description |
|---|---|
DeviceName UnicodeString | |
VolumeName UnicodeString | |
NTSTATUS UnicodeString | |
SourceTag UnicodeString | |
SourceFileID UnicodeString | |
SourceLine UnicodeString | |
binary Binary |
Event ID 3221618771: Volume VolumeName is offline for shadow copy protection.
#Description
Volume VolumeName is offline for shadow copy protection. A memory allocation failed. Please try clearing the protection fault or restart the computer. If all else fails, revert out of shadow copy protection mode to reclaim the use of the volume while losing the shadow copies.
Message #
Fields #
| Name | Description |
|---|---|
DeviceName UnicodeString | |
VolumeName UnicodeString | |
NTSTATUS UnicodeString | |
SourceTag UnicodeString | |
SourceFileID UnicodeString | |
SourceLine UnicodeString | |
binary Binary |
Event ID 3221618772: Volume VolumeName is offline for shadow copy protection.
#Description
Volume VolumeName is offline for shadow copy protection. A memory mapping failed. Consider increasing the size of the page file. Please try clearing the protection fault or restart the computer. If all else fails, revert out of shadow copy protection mode to reclaim the use of the volume while losing the shadow copies.
Message #
Fields #
| Name | Description |
|---|---|
DeviceName UnicodeString | |
VolumeName UnicodeString | |
NTSTATUS UnicodeString | |
SourceTag UnicodeString | |
SourceFileID UnicodeString | |
SourceLine UnicodeString | |
binary Binary |
Event ID 3221618773: Volume VolumeName is offline for shadow copy protection.
#Description
Volume VolumeName is offline for shadow copy protection. A read failure occurred during a shadow copy on write operation. Please try clearing the protection fault or restart the computer. If all else fails, revert out of shadow copy protection mode to reclaim the use of the volume while losing the shadow copies.
Message #
Fields #
| Name | Description |
|---|---|
DeviceName UnicodeString | |
VolumeName UnicodeString | |
NTSTATUS UnicodeString | |
SourceTag UnicodeString | |
SourceFileID UnicodeString | |
SourceLine UnicodeString | |
binary Binary |
Event ID 3221618774: Volume VolumeName is offline for shadow copy protection.
#Description
Volume VolumeName is offline for shadow copy protection. A read or write failure to shadow copy storage occurred. Please ensure that the shadow copy storage is still present in the system. Please try clearing the protection fault or restart the computer. If all else fails, revert out of shadow copy protection mode to reclaim the use of the volume while losing the shadow copies.
Message #
Fields #
| Name | Description |
|---|---|
DeviceName UnicodeString | |
VolumeName UnicodeString | |
NTSTATUS UnicodeString | |
SourceTag UnicodeString | |
SourceFileID UnicodeString | |
SourceLine UnicodeString | |
binary Binary |
Event ID 3221618775: Volume VolumeName is offline for shadow copy protection.
#Description
Volume VolumeName is offline for shadow copy protection. The shadow copy storage has been exhausted. Please try clearing the protection fault or restart the computer followed by an increase of the shadow copy storage or a removal of unneeded shadow copies. If all else fails, revert out of shadow copy protection mode to reclaim the use of the volume while losing the shadow copies.
Message #
Fields #
| Name | Description |
|---|---|
DeviceName UnicodeString | |
VolumeName UnicodeString | |
NTSTATUS UnicodeString | |
SourceTag UnicodeString | |
SourceFileID UnicodeString | |
SourceLine UnicodeString | |
binary Binary |
Event ID 3221618776: Volume VolumeName is offline for shadow copy protection.
#Description
Volume VolumeName is offline for shadow copy protection. The shadow copy storage was exhausted before conditions permitted it to grow. Please try clearing the protection fault or restart the computer. If all else fails, revert out of shadow copy protection mode to reclaim the use of the volume while losing the shadow copies.
Message #
Fields #
| Name | Description |
|---|---|
DeviceName UnicodeString | |
VolumeName UnicodeString | |
NTSTATUS UnicodeString | |
SourceTag UnicodeString | |
SourceFileID UnicodeString | |
SourceLine UnicodeString | |
binary Binary |
Event ID 3221618777: Volume VolumeName is offline for shadow copy protection.
#Description
Volume VolumeName is offline for shadow copy protection. The shadow copy storage could not be increased as needed. Please try clearing the protection fault or restart the computer. If all else fails, revert out of shadow copy protection mode to reclaim the use of the volume while losing the shadow copies.
Message #
Fields #
| Name | Description |
|---|---|
DeviceName UnicodeString | |
VolumeName UnicodeString | |
NTSTATUS UnicodeString | |
SourceTag UnicodeString | |
SourceFileID UnicodeString | |
SourceLine UnicodeString | |
binary Binary |
Event ID 3221618778: Volume VolumeName is offline for shadow copy protection.
#Description
Volume VolumeName is offline for shadow copy protection. Please try clearing the protection fault or restart the computer. If all else fails, revert out of shadow copy protection mode to reclaim the use of the volume while losing the shadow copies.
Message #
Fields #
| Name | Description |
|---|---|
DeviceName UnicodeString | |
VolumeName UnicodeString | |
NTSTATUS UnicodeString | |
SourceTag UnicodeString | |
SourceFileID UnicodeString | |
SourceLine UnicodeString | |
binary Binary |
Event ID 3221618779: Volume VolumeName is offline for shadow copy protection.
#Description
Volume VolumeName is offline for shadow copy protection. An error occurred when doing a file system operation. Please try clearing the protection fault or restart the computer. If all else fails, revert out of shadow copy protection mode to reclaim the use of the volume while losing the shadow copies.
Message #
Fields #
| Name | Description |
|---|---|
DeviceName UnicodeString | |
VolumeName UnicodeString | |
NTSTATUS UnicodeString | |
SourceTag UnicodeString | |
SourceFileID UnicodeString | |
SourceLine UnicodeString | |
binary Binary |
Event ID 3221618780: Volume VolumeName is offline for shadow copy protection.
#Description
Volume VolumeName is offline for shadow copy protection. A read or write error occurred. Please try clearing the protection fault or restart the computer. If all else fails, revert out of shadow copy protection mode to reclaim the use of the volume while losing the shadow copies.
Message #
Fields #
| Name | Description |
|---|---|
DeviceName UnicodeString | |
VolumeName UnicodeString | |
NTSTATUS UnicodeString | |
SourceTag UnicodeString | |
SourceFileID UnicodeString | |
SourceLine UnicodeString | |
binary Binary |
Event ID 3221618781: Volume VolumeName is offline for shadow copy protection.
#Description
Volume VolumeName is offline for shadow copy protection. The shadow copy storage was made inaccessible or removed from the system. Please ensure that the shadow copy storage is present. Please try clearing the protection fault or restart the computer. If all else fails, revert out of shadow copy protection mode to reclaim the use of the volume while losing the shadow copies.
Message #
Fields #
| Name | Description |
|---|---|
DeviceName UnicodeString | |
VolumeName UnicodeString | |
NTSTATUS UnicodeString | |
SourceTag UnicodeString | |
SourceFileID UnicodeString | |
SourceLine UnicodeString | |
binary Binary |
Event ID 3221618782: Volume VolumeName is offline for shadow copy protection.
#Description
Volume VolumeName is offline for shadow copy protection. An application attempted to write to the shadow copy meta data. If this program was run intentionally then turn off protection mode for this volume in order to allow the application (which may be FORMAT) to run. Please try clearing the protection fault or restart the computer. If all else fails, revert out of shadow copy protection mode to reclaim the use of the volume while losing the shadow copies.
Message #
Fields #
| Name | Description |
|---|---|
DeviceName UnicodeString | |
VolumeName UnicodeString | |
NTSTATUS UnicodeString | |
SourceTag UnicodeString | |
SourceFileID UnicodeString | |
SourceLine UnicodeString | |
binary Binary |
Event ID 3221618784: The shadow copies of volume VolumeName were aborted because of an error when disabling BypassIO.
#Provenance
Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.
ETW provider GUID cb017cd2-1f37-4e65-82bc-3e91f6a37559
Defined in volsnap.sys, the binary that emits these events.
Observed on:
- WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.1, captured 2026-06-02
- Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.1, captured 2026-06-02