Windows platform event channels
Kernel, boot, power, device and driver, hardware, clock and performance channels, bound as one feed. Disks, volumes and the filesystem have their own feed, win.eventlog.storage. Reviewed platform failures, conditions, and lifecycle records receive reasons and diagnostic fields. Other events retain the Warning ceiling.
Feed id: win.eventlog.platform.
Channels
This feed binds 44 Windows Event Log channels as one reporting axis. A channel that a given Windows edition, role or OEM does not provide is absent on that endpoint; the rest still collect.
| Channel | Ticket class |
|---|---|
Dell | hardware |
Intel Graphics Software | hardware |
Intel-GFX-Info/Application | hardware |
Lenovo-Power-BaseModule/Operational | hardware |
Lenovo-Power-SmartStandby/Operational | hardware |
Lenovo-Sif-Core/Operational | hardware |
Microsoft-Windows-DeviceSetupManager/Admin | hardware |
Microsoft-Windows-DeviceSetupManager/Operational | hardware |
Microsoft-Windows-Diagnosis-DPS/Operational | |
Microsoft-Windows-Diagnosis-Scheduled/Operational | |
Microsoft-Windows-Diagnosis-Scripted/Admin | |
Microsoft-Windows-Diagnosis-Scripted/Operational | |
Microsoft-Windows-Diagnosis-ScriptedDiagnosticsProvider/Operational | |
Microsoft-Windows-Diagnostics-Performance/Operational | performance |
Microsoft-Windows-DxgKrnl-Admin | hardware |
Microsoft-Windows-DxgKrnl-Operational | hardware |
Microsoft-Windows-Kernel-Boot/Operational | os_stability |
Microsoft-Windows-Kernel-Cache/Operational | os_stability |
Microsoft-Windows-Kernel-Dump/Operational | os_stability |
Microsoft-Windows-Kernel-EventTracing/Admin | os_stability |
Microsoft-Windows-Kernel-LiveDump/Operational | os_stability |
Microsoft-Windows-Kernel-PnP/Configuration | hardware |
Microsoft-Windows-Kernel-PnP/Device Management | hardware |
Microsoft-Windows-Kernel-PnP/Driver Watchdog | hardware |
Microsoft-Windows-Kernel-PnPConfig/Configuration | hardware |
Microsoft-Windows-Kernel-Power/Thermal-Operational | hardware |
Microsoft-Windows-Kernel-WHEA/Errors | hardware |
Microsoft-Windows-Kernel-WHEA/Operational | hardware |
Microsoft-Windows-PCI/Operational | hardware |
Microsoft-Windows-PerceptionSensorDataService/Operational | hardware |
Microsoft-Windows-Perflib/Operational | performance |
Microsoft-Windows-Resource-Exhaustion-Detector/Operational | performance |
Microsoft-Windows-Resource-Exhaustion-Resolver/Operational | performance |
Microsoft-Windows-Time-Service/Operational | time_sync |
Microsoft-Windows-TZSync/Operational | time_sync |
Microsoft-Windows-USB-UCMUCSICX/Operational | hardware |
Microsoft-Windows-USB-USBXHCI-Operational | hardware |
Microsoft-Windows-UserPnp/DeviceInstall | hardware |
Microsoft-Windows-WerKernel/Operational | os_stability |
Microsoft-Windows-Win32k/Operational | os_stability |
Microsoft-Windows-WindowsSystemAssessmentTool/Operational | performance |
Microsoft-Windows-WPD-ClassInstaller/Operational | hardware |
Microsoft-Windows-WPD-MTPClassDriver/Operational | hardware |
OneApp_IGCC | hardware |
Fields
| Field | Type | Unit | Meaning |
|---|---|---|---|
win.eventlog.platform.pnp_problem_code | int | Device Manager problem code reported for a device start failure. | |
win.eventlog.platform.pnp_problem_code_name | string | Published CM_PROB name for the device problem code. | |
win.eventlog.platform.pnp_veto_type | int | Published PnP removal veto type number. | |
win.eventlog.platform.pnp_veto_type_name | string | Published PNP_Veto name for the removal veto type. | |
win.eventlog.platform.pnp_veto_holder | string | Provider label for the component that vetoed device removal. | |
win.eventlog.platform.driver_inf | string | INF basename reported for a device start failure. | |
win.eventlog.platform.device_service | string | Driver service label reported for a device. | |
win.eventlog.platform.device_class | string | Leading device-instance class without the identifying path tail. | |
win.eventlog.platform.device_count | int | Number of child devices reported in a removal event. | |
win.eventlog.platform.mem_commit_bytes | int | Committed virtual-memory bytes reported by Windows. | |
win.eventlog.platform.mem_commit_limit_bytes | int | Virtual-memory commit limit in bytes reported by Windows. | |
win.eventlog.platform.mem_commit_ratio | float | Commit charge divided by the positive commit limit. | |
win.eventlog.platform.clock_freq_error_ppm | float | Measured hardware-clock frequency error in parts per million. | |
win.eventlog.platform.clock_drift_seconds_per_day | float | Measured clock drift in seconds per day. | |
win.eventlog.platform.clock_measure_window_minutes | float | Clock frequency measurement window in minutes. | |
win.eventlog.platform.secure_boot_sbat_failure_point | int | Firmware revocation update failure point. | |
win.eventlog.platform.secure_boot_sbat_update_status | int | Firmware revocation update status number. | |
win.eventlog.platform.secure_boot_sbat_firmware_level | string | Firmware SBAT generation list reported by Windows. | |
win.eventlog.platform.firmware_indicator_category | string | Category reported for a platform tamper indicator. | |
win.eventlog.platform.firmware_indicator_events | string | Firmware setting names reported behind a tamper indicator. | |
win.eventlog.platform.firmware_scan_name | string | Vendor firmware verification scan label. | |
win.eventlog.platform.firmware_scan_result | string | Result clause reported by a firmware verification scan. | |
win.eventlog.platform.firmware_scan_result_code | int | Numeric result code reported by a firmware verification scan. | |
win.eventlog.platform.security_assessment_result | string | Result clause reported by the device security assessment. | |
win.eventlog.platform.security_assessment_score | int | Device security assessment score. | |
win.eventlog.platform.security_assessment_failed_areas | string | Risk areas the device security assessment marked failed or high. | |
win.eventlog.platform.firmware_event_store | string | Vendor secure event-store label. | |
win.eventlog.platform.trace_session_name | string | Windows tracing session that reported a failure. | |
win.eventlog.platform.boot_duration_ms | int | Measured whole-boot duration in milliseconds. | |
win.eventlog.platform.boot_main_path_ms | int | Measured main boot-path duration in milliseconds. | |
win.eventlog.platform.boot_post_boot_ms | int | Measured post-boot duration in milliseconds. | |
win.eventlog.platform.boot_is_degradation | bool | Whether Windows classified the boot measurement as degraded. | |
win.eventlog.platform.boot_startup_app_count | int | Startup application count reported for a boot. | |
win.eventlog.platform.startup_component | string | Executable or service basename associated with a startup delay. | |
win.eventlog.platform.startup_component_total_ms | int | Total startup component duration in milliseconds. | |
win.eventlog.platform.startup_component_degradation_ms | int | Startup component degradation duration in milliseconds. | |
win.eventlog.platform.shutdown_duration_ms | int | Measured whole-shutdown duration in milliseconds. | |
win.eventlog.platform.shutdown_is_degradation | bool | Whether Windows classified the shutdown measurement as degraded. | |
win.eventlog.platform.shutdown_services_ms | int | Measured shutdown service duration in milliseconds. | |
win.eventlog.platform.shutdown_user_session_ms | int | Measured user-session shutdown duration in milliseconds. | |
win.eventlog.platform.shutdown_component | string | Service basename associated with a shutdown delay. | |
win.eventlog.platform.shutdown_component_degradation_ms | int | Shutdown component degradation duration in milliseconds. | |
win.eventlog.platform.usb_failure_type | int | USB controller failure type reported by Windows. | |
win.eventlog.platform.usb_failure_subtype | int | USB controller failure subtype reported by Windows. | |
win.eventlog.platform.usb_error_reason | int | USB controller error reason reported by Windows. | |
win.eventlog.platform.usb_ucsi_command | int | UCSI command number associated with a connector-manager fault. | |
win.eventlog.platform.mtp_operation_code | int | Media transfer operation code reported for an unresponsive device. | |
win.eventlog.platform.font_load_blocked | bool | Whether Windows blocked the font load. | |
win.eventlog.platform.font_source_type | int | Font source type reported by Windows. | |
win.eventlog.platform.font_file | string | Font filename without its source path. | |
win.eventlog.platform.thermal_zone | string | ACPI thermal zone object reported by firmware. | |
win.eventlog.platform.thermal_temperature_k | float | Thermal zone temperature reported in Kelvin. | |
win.eventlog.platform.thermal_active_trip_k | float | Active cooling trip point reported in Kelvin. | |
win.eventlog.platform.thermal_passive_trip_k | float | Passive cooling trip point reported in Kelvin. | |
win.eventlog.platform.thermal_min_throttle | float | Minimum processor throttle reported for passive cooling. | |
win.eventlog.platform.live_dump_component | string | Kernel component that requested a live dump. | |
win.eventlog.platform.live_dump_requested_policy | int | Requested live-dump policy number. | |
win.eventlog.platform.live_dump_granted_policy | int | Granted live-dump policy number. | |
win.eventlog.platform.live_dump_throttled | bool | Whether the live-dump request was throttled. | |
win.eventlog.platform.gpu_memory_bytes | int | Graphics memory involved in compositor contention. | |
win.eventlog.platform.gpu_memory_bandwidth | int | Graphics memory bandwidth reported during contention. | |
win.eventlog.platform.gpu_contention_scenario | int | Desktop compositor contention scenario number. | |
win.eventlog.platform.boot_measure_reason_code | int | Measured-boot library reason code. | |
win.eventlog.platform.boot_measure_init_state | int | Measured-boot library initialization state. | |
win.eventlog.platform.tpm_init_position | int | Boot position where TPM initialization failed. | |
win.eventlog.platform.device_software_name | string | Device companion software label reported by setup. | |
win.eventlog.platform.device_software_exit_code | int | Raw process exit code reported by device software setup. | |
win.eventlog.platform.intel_graphics_category | string | Category parsed from an Intel Graphics Software JSON insert. |
Severity
A curated reason states its own severity, listed below. Every other event on these channels keeps the severity its own provider stated, capped at Warning, so a pattern no rule here has read cannot page anyone.
Curated reasons
Severity here is what the condition is worth to the person holding the ticket, not the level the provider stated for itself.
| Reason | Ticket class | Severity |
|---|---|---|
device_install_reboot_pending | hardware | Notice |
device_removal_vetoed | hardware | Notice |
device_removed_after_failure | hardware | Warning |
device_security_assessment_failed | hardware | Notice |
device_security_assessment_passed | hardware | Notice or Info |
device_software_install_failed | hardware | Warning when a vendor installer exit code is present, Notice otherwise; Info for retry or stopped-update cases |
device_start_failed | hardware | Warning |
firmware_event_store_unavailable | hardware | Warning or Notice |
firmware_verification_scan_failed | hardware | Notice or Info |
font_load_allowed | os_stability | Info |
font_load_blocked | os_stability | Notice |
gpu_resources_saturated | performance | Notice |
live_kernel_dump_requested | os_stability | Notice |
measured_boot_failed | os_stability | Warning |
os_boot_duration_high | performance | Warning for whole boot at 120 s or with BootIsDegradation; Notice for component degradation at 30 s or whole boot at 60 s |
os_clock_drift | time_sync | Notice |
os_crash_dump_unavailable | os_stability | Warning |
os_shutdown_duration_high | performance | Warning when ShutdownIsDegradation is true; Notice for long shutdown or slow service |
platform_tamper_indicator_reported | endpoint_protection | Error, Warning or Notice |
portable_device_unresponsive | hardware | Info |
ram_commit_exhausted | performance | Warning at or above 95% commit ratio, Notice for diagnosis failure or lower ratio |
secure_boot_revocation_update_failed | os_stability | Info |
thermal_cooling_engaged | hardware | Notice or Info |
tpm_initialization_failed | os_stability | Warning |
usb_controller_error | hardware | Notice |
win_trace_session_failed | os_stability | Warning or Info |
device_install_reboot_pending
Windows installed a driver and cannot finish until the host restarts.
Severity: Notice
Impact: The device may work only partly until the host restarts.
Channel: Microsoft-Windows-UserPnp/DeviceInstall
Provider: Microsoft-Windows-UserPnp
Event ids: 8000
Where to look next:
- Restart the host at the next maintenance window.
- When the same device asks on every boot, reinstall the driver package.
Related reasons:
device_software_install_failed: an install failure instead of this pending-reboot state
Fields it can set: win.eventlog.platform.device_class
device_removal_vetoed
Something on the device still holds the hardware open, so Windows refused the removal request.
Severity: Notice
Impact: The payload names the holder. The user sees a device-in-use dialog until the holder releases it.
Channel: Microsoft-Windows-Kernel-PnP/Device Management
Provider: Microsoft-Windows-Kernel-PnP
Event ids: 1000
Where to look next:
- Read VetoName in the promoted fields.
- Close the named application or service when the veto type says an app or service holds it.
- Update the driver when the veto type says the driver refused to release the device.
Related reasons:
device_removed_after_failure: the opposite outcome, when the device drops instead of being held open
Fields it can set: win.eventlog.platform.device_class, win.eventlog.platform.pnp_veto_holder, win.eventlog.platform.pnp_veto_type, win.eventlog.platform.pnp_veto_type_name
device_removed_after_failure
A device dropped off its bus while the driver was still reporting it as failing.
Severity: Warning
Impact: Windows removed the device immediately. Internal storage or network devices need hardware attention; USB peripherals often mean cable, hub, or port issues.
Channel: Microsoft-Windows-Kernel-PnP/Device Management
Provider: Microsoft-Windows-Kernel-PnP
Event ids: 1011
Where to look next:
- Read the device class from the promoted fields.
- Treat internal storage or network removal as a hardware ticket.
- For USB peripherals, check cable, hub, and port when it repeats.
Related reasons:
device_removal_vetoed: the opposite outcome, when something holds the device open insteaddriver_load_failed: a driver failure that can precede this removal
Fields it can set: win.eventlog.platform.device_class, win.eventlog.platform.device_count
device_security_assessment_failed
A Dell security assessment reported a failing result for this machine's platform posture.
Severity: Notice
Impact: The result and risk-area lines name settings an administrator controls. The score alone does not say what to fix.
Channel: Dell
Provider: Trusted Device | Security Assessment
Event ids: 14, 15
Where to look next:
- Read the risk-area lines, not just the score.
- Fix FAIL or HIGH areas such as missing BIOS password or disk encryption.
- Treat UNAVAILABLE areas as scans that did not run; see firmware verification scan failures.
Related reasons:
device_security_assessment_passed: the same assessment passing, a different factplatform_tamper_indicator_reported: a tamper finding from the same vendor security agent
Fields it can set: win.eventlog.platform.security_assessment_failed_areas, win.eventlog.platform.security_assessment_result, win.eventlog.platform.security_assessment_score
device_security_assessment_passed
A Dell security assessment reported a passing result (with or without warnings) for this machine's platform posture.
Severity: Notice or Info
Impact: The result and risk-area lines name settings an administrator controls.
Channel: Dell
Provider: Trusted Device | Security Assessment
Event ids: 14, 15
| Case | Severity | Ticket class |
|---|---|---|
passed_with_warnings | Notice | hardware |
other_assessment | Info | hardware |
Where to look next:
- Read the risk-area lines even on a pass, if warnings are present.
Related reasons:
device_security_assessment_failed: the same assessment failing, a different factplatform_tamper_indicator_reported: a tamper finding from the same vendor security agent
Fields it can set: win.eventlog.platform.security_assessment_failed_areas, win.eventlog.platform.security_assessment_result, win.eventlog.platform.security_assessment_score
device_software_install_failed
Windows failed to install companion software or a driver for a device.
Severity: Warning when a vendor installer exit code is present, Notice otherwise; Info for retry or stopped-update cases
Impact: The user may lack a control panel, vendor utility, or full driver until setup succeeds.
Channel: Microsoft-Windows-DeviceSetupManager/Admin
Provider: Microsoft-Windows-DeviceSetupManager
Event ids: 121, 151, 152, 163, 164, 172, 191
| Case | Severity | Ticket class |
|---|---|---|
transient | Info | hardware |
update_service_stopped | Info | hardware |
removal_failed | Notice | hardware |
install_failed | Notice to Warning | hardware |
Where to look next:
- Read the exit code on id 163 and the status on id 121.
- Wait or retry when Windows marks the error transient or the update service was stopped.
- Reinstall or replace the vendor package when a fatal installer exit code appears.
Related reasons:
device_install_reboot_pending: the pending-reboot state this install trouble can also producedevice_start_failed: the device-start failure that can follow a bad install
Fields it can set: win.eventlog.platform.device_class, win.eventlog.platform.device_software_exit_code, win.eventlog.platform.device_software_name
device_start_failed
Windows enumerated a device and its driver refused to start it.
Severity: Warning
Impact: The device does not work until someone fixes the driver or hardware conflict.
Channel: Microsoft-Windows-Kernel-PnP/Configuration
Provider: Microsoft-Windows-Kernel-PnP
Event ids: 411
Where to look next:
- Read the problem code first.
- Code 10: reinstall or update the driver.
- Code 12: resolve the resource conflict between two devices.
Related reasons:
device_software_install_failed: an install failure that can leave the driver unable to start the devicedriver_load_failed: the driver failure that is one cause of a device refusing to start
Fields it can set: win.eventlog.platform.device_class, win.eventlog.platform.device_service, win.eventlog.platform.driver_inf, win.eventlog.platform.pnp_problem_code, win.eventlog.platform.pnp_problem_code_name
firmware_event_store_unavailable
A Dell secure firmware-event store cannot be verified.
Severity: Warning or Notice
Impact: The platform-security agent cannot verify records from the named store until it is rebuilt.
Channel: Dell
Provider: Trusted Device | Secure Event Log
Event ids: 21, 45
| Case | Severity | Ticket class |
|---|---|---|
keys_missing | Notice | hardware |
repair_failed | Warning | hardware |
Where to look next:
- Read the store name from the promoted fields.
- Reinstall the vendor agent on affected hosts when repair failed.
- Treat tamper-indicator silence on those hosts as unknown, not clean, until the store is rebuilt.
Related reasons:
firmware_verification_scan_failed: another firmware-integrity check failing on the same vendor stack
Fields it can set: win.eventlog.platform.firmware_event_store
firmware_verification_scan_failed
A vendor firmware verification scan did not finish.
Severity: Notice or Info
Impact: The result text says why the scan stopped. It does not report a firmware integrity failure by itself.
Channel: Dell
Provider: Trusted Device | BIOS Verification, Trusted Device | Intel ME Verification, Trusted Device | Common Vulnerabilities and Exposures, Trusted Device | Secured Component Verification
Event ids: 2, 20, 42, 43, 47
| Case | Severity | Ticket class |
|---|---|---|
unreachable | Notice | hardware |
unsupported | Info | hardware |
verification_failed | Notice | hardware |
Where to look next:
- Read the result text from the promoted fields.
- Open the proxy or firewall path when the result names a network error.
- Ignore unsupported-platform results; the check never applies to that model.
Related reasons:
firmware_event_store_unavailable: the event store outage that can also block firmware verification
Fields it can set: win.eventlog.platform.firmware_scan_name, win.eventlog.platform.firmware_scan_result, win.eventlog.platform.firmware_scan_result_code
font_load_allowed
A process loaded a font under an audit-mode font-loading policy.
Severity: Info
Impact: Audit-only context; nothing was refused.
Channel: Microsoft-Windows-Win32k/Operational
Provider: Microsoft-Windows-Win32k
Event ids: 260
Where to look next:
- Treat this as audit-only context, not a user failure.
Related reasons:
font_load_blocked: the same policy refusing a load, a different fact
Fields it can set: win.eventlog.platform.font_file, win.eventlog.platform.font_load_blocked, win.eventlog.platform.font_source_type
font_load_blocked
A process tried to load a font while a font-loading restriction was in force, and Windows refused it.
Severity: Notice
Impact: The named application renders or prints text incorrectly until the font is installed system-wide or the app is exempted.
Channel: Microsoft-Windows-Win32k/Operational
Provider: Microsoft-Windows-Win32k
Event ids: 260
Where to look next:
- Install the font system-wide or exempt the application.
Related reasons:
font_load_allowed: the same policy allowing a load, a different fact
Fields it can set: win.eventlog.platform.font_file, win.eventlog.platform.font_load_blocked, win.eventlog.platform.font_source_type
gpu_resources_saturated
The desktop compositor ran short of graphics memory or bandwidth.
Severity: Notice
Impact: The user sees stutter or display interruptions while contention lasts.
Channel: Microsoft-Windows-Diagnostics-Performance/Operational
Provider: Microsoft-Windows-Diagnostics-Performance
Event ids: 500
Where to look next:
- Check the display memory figure in the promoted fields.
- Reduce display count or resolution, or move the user to hardware with more graphics memory, when it repeats on one host.
Related reasons:
gpu_driver_reset: the driver reset that can follow sustained resource contention
Fields it can set: win.eventlog.platform.gpu_contention_scenario, win.eventlog.platform.gpu_memory_bandwidth, win.eventlog.platform.gpu_memory_bytes
live_kernel_dump_requested
A kernel component requested a live kernel dump and Windows completed the request.
Severity: Notice
Impact: The component name points to the subsystem that stalled long enough to trip a watchdog.
Channel: Microsoft-Windows-WerKernel/Operational
Provider: Microsoft-Windows-WerKernel
Event ids: 1001, 1002
Where to look next:
- Read the component name from the promoted fields.
- Update the driver behind a network or power watchdog when it repeats daily on one host.
Related reasons:
Fields it can set: win.eventlog.platform.live_dump_component, win.eventlog.platform.live_dump_granted_policy, win.eventlog.platform.live_dump_requested_policy, win.eventlog.platform.live_dump_throttled
measured_boot_failed
Windows reported a boot-measurement library failure during boot.
Severity: Warning
Impact: This event identifies a boot-measurement problem. It does not establish TPM absence, BitLocker behavior, attestation results, or a boot-chain attack.
Channel: Microsoft-Windows-Kernel-Boot/Operational
Provider: Microsoft-Windows-Kernel-Boot
Event ids: 208
Where to look next:
- Read the event id and status from the promoted fields.
- Check TPM readiness, Secure Boot state, firmware state, and related Windows boot records on the affected host.
- Apply the vendor or Windows remediation for the reported status before changing TPM state.
Related reasons:
tpm_attestation_failed: the attestation failure a broken boot measurement can causetpm_initialization_failed: a TPM initialization failure on the same channel, a different fact
Fields it can set: win.eventlog.platform.boot_measure_init_state, win.eventlog.platform.boot_measure_reason_code
os_boot_duration_high
Windows logged a slow boot or a slow startup component.
Severity: Warning for whole boot at 120 s or with BootIsDegradation; Notice for component degradation at 30 s or whole boot at 60 s
Impact: The duration fields show whether the whole boot or one named startup item caused the delay.
Channel: Microsoft-Windows-Diagnostics-Performance/Operational
Provider: Microsoft-Windows-Diagnostics-Performance
Event ids: 100, 101, 103, 107, 108
| Case | Severity | Ticket class |
|---|---|---|
whole_boot | Info to Warning | performance |
component | Info to Notice | performance |
Where to look next:
- Read DegradationTime and the component name on startup delay ids.
- Remove or update the named product from startup when the same host is slow for several days.
Related reasons:
os_shutdown_duration_high: the same slowness on the shutdown side instead
Fields it can set: win.eventlog.platform.boot_duration_ms, win.eventlog.platform.boot_is_degradation, win.eventlog.platform.boot_main_path_ms, win.eventlog.platform.boot_post_boot_ms, win.eventlog.platform.boot_startup_app_count, win.eventlog.platform.startup_component, win.eventlog.platform.startup_component_degradation_ms, win.eventlog.platform.startup_component_total_ms
os_clock_drift
This host's clock hardware runs at the wrong rate.
Severity: Notice
Impact: The time service holds the clock in place with continuous correction. When synchronization stops, the clock walks away at the stated rate.
Channel: Microsoft-Windows-Time-Service/Operational
Provider: Microsoft-Windows-Time-Service
Event ids: 282
Where to look next:
- Check that the host reaches its time source.
- Replace the board battery on a desktop when correction exceeds about 50 parts per million.
Fields it can set: win.eventlog.platform.clock_drift_seconds_per_day, win.eventlog.platform.clock_freq_error_ppm, win.eventlog.platform.clock_measure_window_minutes
os_crash_dump_unavailable
Windows could not set up the path it writes a crash dump through.
Severity: Warning
Impact: The next bugcheck on this host may leave no dump to analyse.
Channel: Microsoft-Windows-Kernel-Dump/Operational
Provider: Microsoft-Windows-Kernel-Dump
Event ids: 5, 9
Where to look next:
- A kernel crash reported without dump analysis after this event is explained by it; the crash itself is still counted once.
- Check the page file on the system volume.
- Size the page file for the configured dump type when the status says the file was not found.
Related reasons:
kernel_crash: a kernel crash on this host still ships as one row, with its dump analysis reported unavailable when the dump path was never readyos_dump_pagefile_too_small: a pagefile misconfiguration that can also prevent a usable crash dump
os_shutdown_duration_high
Windows logged a slow shutdown or a service that delayed shutdown.
Severity: Warning when ShutdownIsDegradation is true; Notice for long shutdown or slow service
Impact: The duration fields show whether the whole shutdown or one named service caused the delay.
Channel: Microsoft-Windows-Diagnostics-Performance/Operational
Provider: Microsoft-Windows-Diagnostics-Performance
Event ids: 200, 203
| Case | Severity | Ticket class |
|---|---|---|
whole_shutdown | Warning | performance |
measured | Info to Notice | performance |
component | Info to Notice | performance |
Where to look next:
- Read Name on id 203 for the service that held shutdown open.
- Update or reconfigure that service when degraded shutdown repeats on one host.
Related reasons:
os_boot_duration_high: the same slowness on the startup side instead
Fields it can set: win.eventlog.platform.shutdown_component, win.eventlog.platform.shutdown_component_degradation_ms, win.eventlog.platform.shutdown_duration_ms, win.eventlog.platform.shutdown_is_degradation, win.eventlog.platform.shutdown_services_ms, win.eventlog.platform.shutdown_user_session_ms
platform_tamper_indicator_reported
A platform-security agent reported a tamper indicator against this machine.
Also reported by: Windows System event log
Severity: Error, Warning or Notice
Impact: The agent names the category it matched and the firmware or chassis events it built the indicator from. An indicator names what the agent matched; read the named settings to see what the machine is actually set to.
Channel: Dell
Provider: Trusted Device | BIOS Events and IoA
Event ids: 10, 11, 12
| Case | Severity | Ticket class |
|---|---|---|
partial | Warning | endpoint_protection |
escalated | Error | endpoint_protection |
detected | Error | endpoint_protection |
reported | Warning | endpoint_protection |
cleared | Notice | endpoint_protection |
Where to look next:
- Read the Category and the listed events from the message: they name what was matched.
- Check whether a deliberate BIOS change or a hardware service visit explains it.
- Where nothing explains it, treat the named firmware settings as the thing to put back.
- When event 10 clears an indicator, match the category to the earlier partial or escalated event on the same host.
Fields it can set: win.eventlog.platform.firmware_indicator_category, win.eventlog.platform.firmware_indicator_events
portable_device_unresponsive
A phone, camera, or media player on USB stopped answering.
Severity: Info
Impact: Nothing on the managed host is affected. The user unlocks the device and plugs it back in.
Channel: Microsoft-Windows-WPD-MTPClassDriver/Operational
Provider: Microsoft-Windows-WPD-MTPClassDriver
Event ids: 1006, 1007, 1008
Where to look next:
- Have the user unplug the device, unlock it, and plug it back in.
Fields it can set: win.eventlog.platform.mtp_operation_code
ram_commit_exhausted
Committed memory on this host reached its limit.
Severity: Warning at or above 95% commit ratio, Notice for diagnosis failure or lower ratio
Impact: Applications can fail allocations while committed memory stays near its limit.
Channel: Microsoft-Windows-Resource-Exhaustion-Detector/Operational
Provider: Microsoft-Windows-Resource-Exhaustion-Detector
Event ids: 1003, 1007, 1008
| Case | Severity | Ticket class |
|---|---|---|
notified | Notice to Warning | performance |
allocation_failed | Warning | performance |
diagnosis_failed | Notice | performance |
Where to look next:
- Find the process holding the commit and restart or update it.
- Add memory or a larger page file when no single process explains it.
Fields it can set: win.eventlog.platform.mem_commit_bytes, win.eventlog.platform.mem_commit_limit_bytes, win.eventlog.platform.mem_commit_ratio
secure_boot_revocation_update_failed
Windows tried to write its boot revocation level into firmware and the firmware refused.
Severity: Info
Impact: Revocations Microsoft ships in the SBAT list are not enforced on this host until the update succeeds.
Channel: Microsoft-Windows-Kernel-Boot/Operational
Provider: Microsoft-Windows-Kernel-Boot
Event ids: 292
Where to look next:
- Check what else boots this machine; dual-boot hosts may hold a different revocation level on purpose.
- On a Windows-only host, apply a firmware update when this appears on a minority of the fleet.
Related reasons:
secure_boot_cert_update_pending: the certificate-update counterpart of the same firmware write path
Fields it can set: win.eventlog.platform.secure_boot_sbat_failure_point, win.eventlog.platform.secure_boot_sbat_firmware_level, win.eventlog.platform.secure_boot_sbat_update_status
thermal_cooling_engaged
The platform reached a temperature trip point and engaged cooling.
Severity: Notice or Info
Impact: Active cooling is fan noise. Passive cooling slows the processor while heat persists.
Channel: Microsoft-Windows-Kernel-Power/Thermal-Operational
Provider: Microsoft-Windows-Kernel-Power
Event ids: 114, 116
| Case | Severity | Ticket class |
|---|---|---|
active | Info | hardware |
passive | Notice | hardware |
disengaged | Info | hardware |
Where to look next:
- Take no action for a single active-cooling event.
- Clean fans or improve airflow when passive cooling runs for hours on one host.
Related reasons:
cpu_busy: sustained CPU load that can trigger this cooling response
Fields it can set: win.eventlog.platform.thermal_active_trip_k, win.eventlog.platform.thermal_min_throttle, win.eventlog.platform.thermal_passive_trip_k, win.eventlog.platform.thermal_temperature_k, win.eventlog.platform.thermal_zone
tpm_initialization_failed
Windows reported a TPM initialization failure during boot.
Severity: Warning
Impact: This event identifies a TPM initialization problem. It does not establish TPM absence, BitLocker behavior, attestation results, or a boot-chain attack.
Channel: Microsoft-Windows-Kernel-Boot/Operational
Provider: Microsoft-Windows-Kernel-Boot
Event ids: 235
Where to look next:
- Read the event id and status from the promoted fields.
- Check TPM readiness, Secure Boot state, firmware state, and related Windows boot records on the affected host.
- Apply the vendor or Windows remediation for the reported status before changing TPM state.
Related reasons:
measured_boot_failed: a boot library failure on the same channel, a different facttpm_attestation_failed: the attestation failure a broken boot measurement can cause
Fields it can set: win.eventlog.platform.tpm_init_position
usb_controller_error
The USB host controller or USB-C connector manager reported a fault.
Severity: Notice
Impact: Devices on that controller stop working or charging until it resets.
Channel: Microsoft-Windows-USB-USBXHCI-Operational, Microsoft-Windows-USB-UCMUCSICX/Operational
Provider: Microsoft-Windows-USB-USBXHCI, Microsoft-Windows-USB-UCMUCSICX
Event ids: 1, 50, 62
Where to look next:
- Unplug and replug the device or dock.
- Update platform firmware when the same host reports this daily.
Related reasons:
portable_device_unresponsive: a USB device symptom this controller fault can cause
Fields it can set: win.eventlog.platform.usb_error_reason, win.eventlog.platform.usb_failure_subtype, win.eventlog.platform.usb_failure_type, win.eventlog.platform.usb_ucsi_command
win_trace_session_failed
A Windows tracing session could not start, write, or continue.
Severity: Warning or Info
Impact: The status word separates an existing session, a full trace file, a full disk, and other failures.
Channel: Microsoft-Windows-Kernel-EventTracing/Admin
Provider: Microsoft-Windows-Kernel-EventTracing
Event ids: 0, 1, 2, 3, 4, 28
| Case | Severity | Ticket class |
|---|---|---|
already_running | Info | os_stability |
file_full | Info | os_stability |
disk_full | Warning | os_stability |
other_failure | Info | os_stability |
Where to look next:
- Read the status word from the promoted fields.
- Ignore name-collision and log-file-full statuses; the session already exists or wrapped by design.
- Free disk space when the status says the volume is full.
Fields it can set: win.eventlog.platform.trace_session_name
Ask this feed a question
Every reason code, token and field on this page is queryable across the endpoints you manage. Connect your AI and ask in plain language, or open the same evidence in Explore.