Windows storage event channels
Disk, volume, filesystem, Storage Spaces and storage-housekeeping channels, bound as one feed: the storage port and class drivers, NTFS and its health-check arm, partitions and volumes, the Storage Spaces provider family, and the disk-cleanup and storage-settings services. Unread channels keep the severity the provider stated, capped at Warning. Measured floods are dropped by provider and event id, and pinned families are held at the band their content earns. The curated reasons read the payload rather than the line: bad blocks, controller resets, surprise removals, paging failures, NTFS corruption-handling state, volume mount failures, predicted device failure, and the device command failure the class driver reports with its sense data.
Feed id: win.eventlog.storage.
Channels
This feed binds 22 Windows Event Log channels as one reporting axis. A channel that a given Windows edition, role or OEM does not provide is absent on that endpoint; the rest still collect.
| Channel | Ticket class |
|---|---|
Microsoft-Windows-Cleanmgr/Diagnostic | storage |
Microsoft-Windows-DataIntegrityScan/Admin | storage |
Microsoft-Windows-EnhancedStorage-EhStorClass/Operational | storage |
Microsoft-Windows-Ntfs/Operational | storage |
Microsoft-Windows-Ntfs/WHC | storage |
Microsoft-Windows-Partition/Diagnostic | storage |
Microsoft-Windows-ReadyBoost/Operational | storage |
Microsoft-Windows-Storage-ClassPnP/Operational | storage |
Microsoft-Windows-Storage-Storport/Health | storage |
Microsoft-Windows-Storage-Storport/Operational (disabled by default on client Windows; enable it on the host to produce data) | storage |
Microsoft-Windows-StorageManagement-PartUtil/Operational | storage |
Microsoft-Windows-StorageSettings/Diagnostic | storage |
Microsoft-Windows-StorageSpaces-Api/Operational | storage |
Microsoft-Windows-StorageSpaces-Driver/Diagnostic | storage |
Microsoft-Windows-StorageSpaces-Driver/Operational | storage |
Microsoft-Windows-StorageSpaces-ManagementAgent/WHC | storage |
Microsoft-Windows-StorageSpaces-Parser/Diagnostic | storage |
Microsoft-Windows-StorageSpaces-Parser/Operational | storage |
Microsoft-Windows-StorageSpaces-SpaceManager/Diagnostic | storage |
Microsoft-Windows-StorageSpaces-SpaceManager/Operational | storage |
Microsoft-Windows-StorageVolume/Operational | storage |
Microsoft-Windows-Storsvc/Diagnostic | storage |
Fields
| Field | Type | Unit | Meaning |
|---|---|---|---|
win.eventlog.storage.filesystem | string | Filesystem type the filesystem_corruption reason names (ntfs, refs, fat32), read from the provider that raised the event. A constant per provider: today the provider is always Microsoft-Windows-Ntfs, so the value is always ntfs. | |
win.eventlog.storage.sense_key | int | SCSI sense key the device returned on a failed command, from Storage-ClassPnP 507 (SenseKey). The top-level classification of what the device is reporting, and the grouping key for a drive answering the same way repeatedly. | |
win.eventlog.storage.additional_sense_code | int | SCSI additional sense code from Storage-ClassPnP 507 (AdditionalSenseCode). Read together with the sense key: the pair is what names the specific condition. | |
win.eventlog.storage.additional_sense_code_qualifier | int | SCSI additional sense code qualifier from Storage-ClassPnP 507 (AdditionalSenseCodeQualifier). The third element of the sense triple. | |
win.eventlog.storage.scsi_status | int | SCSI status byte the device returned, from Storage-ClassPnP 507 (ScsiStatus). | |
win.eventlog.storage.srb_status | int | SRB status as the storage port driver logged it, from Storage-ClassPnP 507 (SrbStatus). Carries flag bits above the status itself; group on srb_status_code instead. | |
win.eventlog.storage.srb_status_code | int | The SRB status with its flag bits removed (the low six bits of srb_status). One status arrives under several srb_status numbers depending on which flags the driver set, so this is the value a query groups on. | |
win.eventlog.storage.cdb_bytes | string | The SCSI command descriptor block the failing command carried, from Storage-ClassPnP 507 (CdbBytes), as hex text with a 0x prefix. The prefix is added here: Windows writes the field without one, and an all-digit hex string is otherwise read as a number and stored as one. | |
win.eventlog.storage.sense_key_name | string | Bounded meaning token decoded from the sense key (no_sense, not_ready, medium_error, hardware_error, illegal_request, unit_attention, data_protect, aborted_command and the rest of the published set). The number stays beside it; an unlisted code leaves this unset. | |
win.eventlog.storage.additional_sense_name | string | Bounded meaning token decoded from the additional sense code, for the small set this module reads (illegal_command, invalid_cdb, medium_changed, bus_reset, no_media_in_device). An unlisted code leaves this unset. | |
win.eventlog.storage.srb_status_name | string | Bounded meaning token decoded from srb_status_code, the SRB status with its flag bits removed (success, error, busy, timeout, bus_reset and the rest of the published set). An unlisted code leaves this unset. | |
win.eventlog.storage.bus_type | int | The bus the device sits on, as the STORAGE_BUS_TYPE number the driver wrote. The value that separates a fixed disk from a removable one, which is what decides whether a read failure is a claim about the medium. | |
win.eventlog.storage.bus_type_name | string | Bounded meaning token decoded from bus_type (bus_usb, bus_sata, bus_nvme, bus_raid, bus_sas and the rest of the published set). An unlisted code leaves this unset. | |
win.eventlog.storage.io_type | int | The kind of IO NTFS was performing when it failed, as the number the file system wrote (Ntfs 148 IoType). | |
win.eventlog.storage.io_size_bytes | int | Size in bytes of the IO NTFS was performing when it failed (Ntfs 148 IoSize). | |
win.eventlog.storage.clusters_count | int | How many clusters the failed NTFS IO covered (Ntfs 148 ClustersCount). Read with starting_lcn: the pair is the extent the device would not return. | |
win.eventlog.storage.starting_lcn | int | The first logical cluster number of the failed NTFS IO (Ntfs 148 StartingLcn). Every occurrence names a different one, which is why it is evidence rather than a grouping key. | |
win.eventlog.storage.is_boot_volume | bool | Whether the volume NTFS was reading or writing is the boot volume (Ntfs 148 IsBootVolume). | |
win.eventlog.storage.volume_name | string | The volume the NTFS event is about, as the file system named it (VolumeName). Empty on a mount attempt against a device that is not present. | |
win.eventlog.storage.volume_guid | string | The volume GUID the NTFS event carried (VolumeGuid). The stable key for a volume across drive-letter changes; null when NTFS never got far enough to have one. | |
win.eventlog.storage.device_number | int | The disk number the storage class driver assigned the device (DeviceNumber). The per-host device key a repeated failure groups on. | |
win.eventlog.storage.retries_done | int | How many times the class driver had already retried the request before it gave up (NumberOfRetriesDone). | |
win.eventlog.storage.miniport_name | string | The Storport miniport driver handling the device path (MiniportName). What separates an external USB enclosure from an internal controller. | |
win.eventlog.storage.boot_device | bool | Whether the device the port driver reset is the boot device (BootDevice). The positive test that raises a reset out of the degraded band. | |
win.eventlog.storage.bus_reset_reason | int | Why the port driver reset the bus, as the number the driver wrote (BusResetReason). Microsoft publishes no value table, so the number ships undecoded rather than guessed at. | |
win.eventlog.storage.reset_type | int | Which level of reset the port driver performed, as the number the driver wrote (ResetType). Microsoft publishes no value table, so the number ships undecoded rather than guessed at. | |
win.eventlog.storage.reset_status | string | The status the reset itself returned (ResetStatus), as the hex word the driver wrote. Zero says the reset succeeded, which is the ordinary case. | |
win.eventlog.storage.failed_io_count | int | How many outstanding requests the port driver threw away when it reset the path (FailedIoCount). | |
win.eventlog.storage.srb_timeout_s | int | The per-request timeout in seconds the port driver was enforcing when the request timed out (SrbTimeout). | |
win.eventlog.storage.port_number | int | The adapter port the device is attached to (PortNumber). Part of the device path address. | |
win.eventlog.storage.path_id | int | The bus number within the adapter (PathID). Part of the device path address. | |
win.eventlog.storage.target_id | int | The target number on the bus (TargetID). Part of the device path address. | |
win.eventlog.storage.lun | int | The logical unit number on the target (LUN). Part of the device path address. | |
win.eventlog.storage.removable | bool | Whether the driver considers the device removable (Removable). A device that vanishes with this false is a path failure rather than somebody unplugging something. | |
win.eventlog.storage.surprise_removal_ok | bool | Whether the device declares that removal without an eject is supported (SurpriseRemovalOK). | |
win.eventlog.storage.device_state | int | The device state the port driver recorded at removal, as the number the driver wrote (DeviceState). | |
win.eventlog.storage.device_type | int | The SCSI device type the port driver recorded, as the number the driver wrote (DeviceType). | |
win.eventlog.storage.hc_stateid | int | The NTFS global corruption-handling state the file system moved to (Ntfs/WHC 100 hc_stateid). Microsoft publishes the template and no value map, so the number ships undecoded and the provider level carries the reading. | |
win.eventlog.storage.paging_priority | int | The priority the kernel attached to the paging IO that failed (PagingPriority). | |
win.eventlog.storage.lba | string | The logical block address of the failed paging IO (LBA), as the hex text the driver wrote. | |
win.eventlog.storage.transfer_bytes | int | How many bytes the failed paging IO was moving (TransferByteCount). | |
win.eventlog.storage.nv_cache_priority | int | The non-volatile cache priority the request carried (NvCachePriority). | |
win.eventlog.storage.health_flag_name | string | The device-health parameter the miniport named on a Storport health sample, verbatim as the driver wrote it (the ParameterNName whose value the arm tested). | |
win.eventlog.storage.health_flag_value | int | The value the miniport reported for health_flag_name (the matching ParameterNValue). | |
win.eventlog.storage.percentage_used_pct | int | Percent of rated write endurance the device reports it has consumed, from an NVMe health sample. Values above 100 are legal and mean the drive is past its rated life. | |
win.eventlog.storage.endurance_threshold_pct | int | The endurance percentage the device treats as its own threshold, from the same NVMe health sample. Read against percentage_used_pct: the comparison is the claim, not either number alone. |
Severity
A curated reason states its own severity, listed below. Every other event on these channels keeps the severity its own provider stated, capped at Warning, so a pattern no rule here has read cannot page anyone.
Curated reasons
Severity here is what the condition is worth to the person holding the ticket, not the level the provider stated for itself.
| Reason | Ticket class | Severity |
|---|---|---|
disk_bad_block | storage | Serious when the bus proves the device is fixed to the machine, Warning otherwise. Info on removable media taken away mid-IO, which is not a fault. |
disk_failure_predicted | storage | Warning |
disk_paging_error | storage | Error when the device returned a data error, which is the medium failing. Warning otherwise. |
disk_surprise_removal | storage | Warning |
filesystem_corruption | storage | Error |
storage_controller_reset | storage | Error when the device is the one the machine boots from, Warning otherwise. |
storage_device_command_failed | storage | Info when the device is announcing a change to itself, Notice otherwise. One occurrence claims no fault. |
volume_mount_failed | storage | Warning or Info |
disk_bad_block
A storage device returned a fault instead of the data.
Also reported by: Windows System event log
Severity: Serious when the bus proves the device is fixed to the machine, Warning otherwise. Info on removable media taken away mid-IO, which is not a fault.
Impact: The file did not come back, and the drive is consuming its spare-block reserve.
Channel: Microsoft-Windows-Ntfs/Operational, Microsoft-Windows-Storage-ClassPnP/Operational
Provider: Microsoft-Windows-Ntfs, Microsoft-Windows-StorDiag
Event ids: 148, 505, 506
| Case | Severity | Ticket class | Event ids |
|---|---|---|---|
device_data_error | Warning to Serious | storage | |
removable_verify | Info | storage | 148 |
Where to look next:
- Read the drive's health counters.
- Plan replacement, not repair. Bad blocks do not heal: they are remapped while spares remain and lost when they do not.
Related reasons:
disk_paging_error: the same failure reaching us through the paging path, where no application sees itstorage_device_command_failed: a command that is not a read or a write failing on the same device
Fields it can set: win.eventlog.storage.additional_sense_code, win.eventlog.storage.additional_sense_name, win.eventlog.storage.bus_type, win.eventlog.storage.bus_type_name, win.eventlog.storage.clusters_count, win.eventlog.storage.device_number, win.eventlog.storage.io_size_bytes, win.eventlog.storage.io_type, win.eventlog.storage.is_boot_volume, win.eventlog.storage.retries_done, win.eventlog.storage.sense_key, win.eventlog.storage.sense_key_name, win.eventlog.storage.srb_status, win.eventlog.storage.srb_status_code, win.eventlog.storage.srb_status_name, win.eventlog.storage.starting_lcn, win.eventlog.storage.volume_name
The file NTFS names is not shown here. It carries user document paths.
disk_failure_predicted
A storage device reported that its own reliability is degraded or that it has passed its rated write endurance.
Severity: Warning
Impact: The drive still serves IO. It is reporting wear before reads or writes start failing.
Channel: Microsoft-Windows-Storage-Storport/Health
Provider: Microsoft-Windows-StorPort
Event ids: 539, 542, 543
Where to look next:
- Plan a replacement window: the drive is working and the warning is early.
- Check the backup state for the host before scheduling anything on it.
- Read the endurance percentages together: consumed endurance above the device's own threshold is the claim.
Related reasons:
disk_bad_block: the drive actually failing to return data, which is what this predicts
Fields it can set: win.eventlog.storage.endurance_threshold_pct, win.eventlog.storage.health_flag_name, win.eventlog.storage.health_flag_value, win.eventlog.storage.percentage_used_pct
disk_paging_error
A paging read or write to a storage device failed.
Also reported by: Windows System event log
Severity: Error when the device returned a data error, which is the medium failing. Warning otherwise.
Impact: Nobody chose this IO and no application error surfaces, so this line is the only record.
Channel: Microsoft-Windows-Storage-ClassPnP/Operational
Provider: Microsoft-Windows-StorDiag
Event ids: 502, 503
Where to look next:
- Read the resolved status code and the device model. A paging failure against the boot device is a host problem. Against removable media, it is a device that vanished mid-page.
Related reasons:
disk_bad_block: the same medium failure on an IO an application asked forstorage_controller_reset: the path to the device being reset rather than the transfer failing
Fields it can set: win.eventlog.storage.device_number, win.eventlog.storage.lba, win.eventlog.storage.nv_cache_priority, win.eventlog.storage.paging_priority, win.eventlog.storage.transfer_bytes
disk_surprise_removal
A device disappeared without an orderly removal.
Also reported by: Windows System event log
Severity: Warning
Impact: Open handles and writes in flight were lost with it.
Channel: Microsoft-Windows-Storage-Storport/Operational, Microsoft-Windows-EnhancedStorage-EhStorClass/Operational
Provider: Microsoft-Windows-StorPort, Microsoft-Windows-EnhancedStorage-ClassDriver
Event ids: 103, 551
Where to look next:
- Check removable and surprise_removal_ok. A device with both false vanished through a path failure, not a user action.
- Check what was writing to it.
Related reasons:
storage_controller_reset: the same device path being reset rather than lost
Fields it can set: win.eventlog.storage.device_state, win.eventlog.storage.device_type, win.eventlog.storage.lun, win.eventlog.storage.miniport_name, win.eventlog.storage.port_number, win.eventlog.storage.removable, win.eventlog.storage.surprise_removal_ok
filesystem_corruption
NTFS moved this machine's global corruption-handling state off nominal.
Also reported by: Windows System event log
Severity: Error
Impact: This reports a state change, not confirmed damage to a file, and does not name a volume.
Channel: Microsoft-Windows-Ntfs/WHC
Provider: Microsoft-Windows-Ntfs
Event ids: 100
| Case | Severity | Ticket class |
|---|---|---|
state_error | Error | storage |
state_warning | Error | storage |
Where to look next:
- Schedule a chkdsk and check the backup state for that host.
- Confirm the state returns to a nominal value afterwards.
Fields it can set: win.eventlog.storage.filesystem, win.eventlog.storage.hc_stateid
Microsoft publishes the template with no value map, so the state number ships undecoded.
storage_controller_reset
The storage port driver reset the path to a device.
Also reported by: Windows System event log
Severity: Error when the device is the one the machine boots from, Warning otherwise.
Impact: Requests in flight were discarded. Repeated resets on a fixed controller usually precede a controller, cable, or backplane failure.
Channel: Microsoft-Windows-Storage-Storport/Operational
Provider: Microsoft-Windows-StorPort
Event ids: 500, 501, 550
Where to look next:
- Check boot_device and miniport_name. A reset on a USB attached-storage miniport points to the enclosure. A reset on an internal miniport with boot_device true points to the host.
- Check failed_io_count and the rate.
Related reasons:
disk_bad_block: a fault in the medium rather than in the path to itdisk_surprise_removal: the same device path ending in the device disappearing rather than recovering
Fields it can set: win.eventlog.storage.boot_device, win.eventlog.storage.bus_reset_reason, win.eventlog.storage.bus_type, win.eventlog.storage.bus_type_name, win.eventlog.storage.failed_io_count, win.eventlog.storage.lun, win.eventlog.storage.miniport_name, win.eventlog.storage.path_id, win.eventlog.storage.port_number, win.eventlog.storage.reset_status, win.eventlog.storage.reset_type, win.eventlog.storage.srb_timeout_s, win.eventlog.storage.target_id
storage_device_command_failed
A storage device did not complete a command, and reported sense data saying why.
Severity: Info when the device is announcing a change to itself, Notice otherwise. One occurrence claims no fault.
Impact: The command was not carried out as issued. The driver reissues, so a single occurrence usually reaches no application.
Channel: Microsoft-Windows-Storage-ClassPnP/Operational
Provider: Microsoft-Windows-StorDiag
Event ids: 507
Where to look next:
- Group by device and sense key over time. A rising count against one drive is the signal, not a single record.
- Read the sense key with the additional sense code and its qualifier. Together the three name the condition.
- Compare against the device's own health counters before planning a replacement.
Fields it can set: win.eventlog.storage.additional_sense_code, win.eventlog.storage.additional_sense_code_qualifier, win.eventlog.storage.cdb_bytes, win.eventlog.storage.scsi_status, win.eventlog.storage.sense_key, win.eventlog.storage.srb_status, win.eventlog.storage.srb_status_code
Sense data is the device's own account of a failure, so it is the one place a drive's answer is recorded rather than inferred. Empty removable slots and unsupported-command probes are not kept.
volume_mount_failed
NTFS could not mount a volume.
Severity: Warning or Info
Impact: The volume did not come up. The event states the attempt, not how long the condition lasted.
Channel: Microsoft-Windows-Ntfs/Operational
Provider: Microsoft-Windows-Ntfs
Event ids: 305
| Case | Severity | Ticket class |
|---|---|---|
device_offline | Info | storage |
mount_failed | Warning | storage |
Where to look next:
- Read the resolved status code. If the device is offline or has no medium, look at whether a removable bay, card reader or mounted image is being polled.
- If the status is anything else, treat the volume as unavailable and pivot to the device-state stream's volume_unreadable for whether it stayed that way.
Related reasons:
disk_surprise_removal: the device behind a volume leaving the machinevolume_unreadable: the device-state stream's read of whether the volume stayed unusable
Fields it can set: win.eventlog.storage.volume_guid, win.eventlog.storage.volume_name
Ask this feed a question
Every reason code, token and field on this page is queryable across the endpoints you manage. Connect your AI and ask in plain language, or open the same evidence in Explore.