Skip to main content

Windows storage event channels

22channels
8curated reasons
1themes fed
Livestatus

Disk, volume, filesystem, Storage Spaces and storage-housekeeping channels, bound as one feed: the storage port and class drivers, NTFS and its health-check arm, partitions and volumes, the Storage Spaces provider family, and the disk-cleanup and storage-settings services. Unread channels keep the severity the provider stated, capped at Warning. Measured floods are dropped by provider and event id, and pinned families are held at the band their content earns. The curated reasons read the payload rather than the line: bad blocks, controller resets, surprise removals, paging failures, NTFS corruption-handling state, volume mount failures, predicted device failure, and the device command failure the class driver reports with its sense data.

Feed id: win.eventlog.storage.

Channels​

This feed binds 22 Windows Event Log channels as one reporting axis. A channel that a given Windows edition, role or OEM does not provide is absent on that endpoint; the rest still collect.

ChannelTicket class
Microsoft-Windows-Cleanmgr/Diagnosticstorage
Microsoft-Windows-DataIntegrityScan/Adminstorage
Microsoft-Windows-EnhancedStorage-EhStorClass/Operationalstorage
Microsoft-Windows-Ntfs/Operationalstorage
Microsoft-Windows-Ntfs/WHCstorage
Microsoft-Windows-Partition/Diagnosticstorage
Microsoft-Windows-ReadyBoost/Operationalstorage
Microsoft-Windows-Storage-ClassPnP/Operationalstorage
Microsoft-Windows-Storage-Storport/Healthstorage
Microsoft-Windows-Storage-Storport/Operational (disabled by default on client Windows; enable it on the host to produce data)storage
Microsoft-Windows-StorageManagement-PartUtil/Operationalstorage
Microsoft-Windows-StorageSettings/Diagnosticstorage
Microsoft-Windows-StorageSpaces-Api/Operationalstorage
Microsoft-Windows-StorageSpaces-Driver/Diagnosticstorage
Microsoft-Windows-StorageSpaces-Driver/Operationalstorage
Microsoft-Windows-StorageSpaces-ManagementAgent/WHCstorage
Microsoft-Windows-StorageSpaces-Parser/Diagnosticstorage
Microsoft-Windows-StorageSpaces-Parser/Operationalstorage
Microsoft-Windows-StorageSpaces-SpaceManager/Diagnosticstorage
Microsoft-Windows-StorageSpaces-SpaceManager/Operationalstorage
Microsoft-Windows-StorageVolume/Operationalstorage
Microsoft-Windows-Storsvc/Diagnosticstorage

Fields​

FieldTypeUnitMeaning
win.eventlog.storage.filesystemstringFilesystem type the filesystem_corruption reason names (ntfs, refs, fat32), read from the provider that raised the event. A constant per provider: today the provider is always Microsoft-Windows-Ntfs, so the value is always ntfs.
win.eventlog.storage.sense_keyintSCSI sense key the device returned on a failed command, from Storage-ClassPnP 507 (SenseKey). The top-level classification of what the device is reporting, and the grouping key for a drive answering the same way repeatedly.
win.eventlog.storage.additional_sense_codeintSCSI additional sense code from Storage-ClassPnP 507 (AdditionalSenseCode). Read together with the sense key: the pair is what names the specific condition.
win.eventlog.storage.additional_sense_code_qualifierintSCSI additional sense code qualifier from Storage-ClassPnP 507 (AdditionalSenseCodeQualifier). The third element of the sense triple.
win.eventlog.storage.scsi_statusintSCSI status byte the device returned, from Storage-ClassPnP 507 (ScsiStatus).
win.eventlog.storage.srb_statusintSRB status as the storage port driver logged it, from Storage-ClassPnP 507 (SrbStatus). Carries flag bits above the status itself; group on srb_status_code instead.
win.eventlog.storage.srb_status_codeintThe SRB status with its flag bits removed (the low six bits of srb_status). One status arrives under several srb_status numbers depending on which flags the driver set, so this is the value a query groups on.
win.eventlog.storage.cdb_bytesstringThe SCSI command descriptor block the failing command carried, from Storage-ClassPnP 507 (CdbBytes), as hex text with a 0x prefix. The prefix is added here: Windows writes the field without one, and an all-digit hex string is otherwise read as a number and stored as one.
win.eventlog.storage.sense_key_namestringBounded meaning token decoded from the sense key (no_sense, not_ready, medium_error, hardware_error, illegal_request, unit_attention, data_protect, aborted_command and the rest of the published set). The number stays beside it; an unlisted code leaves this unset.
win.eventlog.storage.additional_sense_namestringBounded meaning token decoded from the additional sense code, for the small set this module reads (illegal_command, invalid_cdb, medium_changed, bus_reset, no_media_in_device). An unlisted code leaves this unset.
win.eventlog.storage.srb_status_namestringBounded meaning token decoded from srb_status_code, the SRB status with its flag bits removed (success, error, busy, timeout, bus_reset and the rest of the published set). An unlisted code leaves this unset.
win.eventlog.storage.bus_typeintThe bus the device sits on, as the STORAGE_BUS_TYPE number the driver wrote. The value that separates a fixed disk from a removable one, which is what decides whether a read failure is a claim about the medium.
win.eventlog.storage.bus_type_namestringBounded meaning token decoded from bus_type (bus_usb, bus_sata, bus_nvme, bus_raid, bus_sas and the rest of the published set). An unlisted code leaves this unset.
win.eventlog.storage.io_typeintThe kind of IO NTFS was performing when it failed, as the number the file system wrote (Ntfs 148 IoType).
win.eventlog.storage.io_size_bytesintSize in bytes of the IO NTFS was performing when it failed (Ntfs 148 IoSize).
win.eventlog.storage.clusters_countintHow many clusters the failed NTFS IO covered (Ntfs 148 ClustersCount). Read with starting_lcn: the pair is the extent the device would not return.
win.eventlog.storage.starting_lcnintThe first logical cluster number of the failed NTFS IO (Ntfs 148 StartingLcn). Every occurrence names a different one, which is why it is evidence rather than a grouping key.
win.eventlog.storage.is_boot_volumeboolWhether the volume NTFS was reading or writing is the boot volume (Ntfs 148 IsBootVolume).
win.eventlog.storage.volume_namestringThe volume the NTFS event is about, as the file system named it (VolumeName). Empty on a mount attempt against a device that is not present.
win.eventlog.storage.volume_guidstringThe volume GUID the NTFS event carried (VolumeGuid). The stable key for a volume across drive-letter changes; null when NTFS never got far enough to have one.
win.eventlog.storage.device_numberintThe disk number the storage class driver assigned the device (DeviceNumber). The per-host device key a repeated failure groups on.
win.eventlog.storage.retries_doneintHow many times the class driver had already retried the request before it gave up (NumberOfRetriesDone).
win.eventlog.storage.miniport_namestringThe Storport miniport driver handling the device path (MiniportName). What separates an external USB enclosure from an internal controller.
win.eventlog.storage.boot_deviceboolWhether the device the port driver reset is the boot device (BootDevice). The positive test that raises a reset out of the degraded band.
win.eventlog.storage.bus_reset_reasonintWhy the port driver reset the bus, as the number the driver wrote (BusResetReason). Microsoft publishes no value table, so the number ships undecoded rather than guessed at.
win.eventlog.storage.reset_typeintWhich level of reset the port driver performed, as the number the driver wrote (ResetType). Microsoft publishes no value table, so the number ships undecoded rather than guessed at.
win.eventlog.storage.reset_statusstringThe status the reset itself returned (ResetStatus), as the hex word the driver wrote. Zero says the reset succeeded, which is the ordinary case.
win.eventlog.storage.failed_io_countintHow many outstanding requests the port driver threw away when it reset the path (FailedIoCount).
win.eventlog.storage.srb_timeout_sintThe per-request timeout in seconds the port driver was enforcing when the request timed out (SrbTimeout).
win.eventlog.storage.port_numberintThe adapter port the device is attached to (PortNumber). Part of the device path address.
win.eventlog.storage.path_idintThe bus number within the adapter (PathID). Part of the device path address.
win.eventlog.storage.target_idintThe target number on the bus (TargetID). Part of the device path address.
win.eventlog.storage.lunintThe logical unit number on the target (LUN). Part of the device path address.
win.eventlog.storage.removableboolWhether the driver considers the device removable (Removable). A device that vanishes with this false is a path failure rather than somebody unplugging something.
win.eventlog.storage.surprise_removal_okboolWhether the device declares that removal without an eject is supported (SurpriseRemovalOK).
win.eventlog.storage.device_stateintThe device state the port driver recorded at removal, as the number the driver wrote (DeviceState).
win.eventlog.storage.device_typeintThe SCSI device type the port driver recorded, as the number the driver wrote (DeviceType).
win.eventlog.storage.hc_stateidintThe NTFS global corruption-handling state the file system moved to (Ntfs/WHC 100 hc_stateid). Microsoft publishes the template and no value map, so the number ships undecoded and the provider level carries the reading.
win.eventlog.storage.paging_priorityintThe priority the kernel attached to the paging IO that failed (PagingPriority).
win.eventlog.storage.lbastringThe logical block address of the failed paging IO (LBA), as the hex text the driver wrote.
win.eventlog.storage.transfer_bytesintHow many bytes the failed paging IO was moving (TransferByteCount).
win.eventlog.storage.nv_cache_priorityintThe non-volatile cache priority the request carried (NvCachePriority).
win.eventlog.storage.health_flag_namestringThe device-health parameter the miniport named on a Storport health sample, verbatim as the driver wrote it (the ParameterNName whose value the arm tested).
win.eventlog.storage.health_flag_valueintThe value the miniport reported for health_flag_name (the matching ParameterNValue).
win.eventlog.storage.percentage_used_pctintPercent of rated write endurance the device reports it has consumed, from an NVMe health sample. Values above 100 are legal and mean the drive is past its rated life.
win.eventlog.storage.endurance_threshold_pctintThe endurance percentage the device treats as its own threshold, from the same NVMe health sample. Read against percentage_used_pct: the comparison is the claim, not either number alone.

Severity​

A curated reason states its own severity, listed below. Every other event on these channels keeps the severity its own provider stated, capped at Warning, so a pattern no rule here has read cannot page anyone.

Curated reasons​

Severity here is what the condition is worth to the person holding the ticket, not the level the provider stated for itself.

ReasonTicket classSeverity
disk_bad_blockstorageSerious when the bus proves the device is fixed to the machine, Warning otherwise. Info on removable media taken away mid-IO, which is not a fault.
disk_failure_predictedstorageWarning
disk_paging_errorstorageError when the device returned a data error, which is the medium failing. Warning otherwise.
disk_surprise_removalstorageWarning
filesystem_corruptionstorageError
storage_controller_resetstorageError when the device is the one the machine boots from, Warning otherwise.
storage_device_command_failedstorageInfo when the device is announcing a change to itself, Notice otherwise. One occurrence claims no fault.
volume_mount_failedstorageWarning or Info

disk_bad_block​

A storage device returned a fault instead of the data.

Also reported by: Windows System event log

Severity: Serious when the bus proves the device is fixed to the machine, Warning otherwise. Info on removable media taken away mid-IO, which is not a fault.

Impact: The file did not come back, and the drive is consuming its spare-block reserve.

Channel: Microsoft-Windows-Ntfs/Operational, Microsoft-Windows-Storage-ClassPnP/Operational

Provider: Microsoft-Windows-Ntfs, Microsoft-Windows-StorDiag

Event ids: 148, 505, 506

CaseSeverityTicket classEvent ids
device_data_errorWarning to Seriousstorage
removable_verifyInfostorage148

Where to look next:

  • Read the drive's health counters.
  • Plan replacement, not repair. Bad blocks do not heal: they are remapped while spares remain and lost when they do not.

Related reasons:

Fields it can set: win.eventlog.storage.additional_sense_code, win.eventlog.storage.additional_sense_name, win.eventlog.storage.bus_type, win.eventlog.storage.bus_type_name, win.eventlog.storage.clusters_count, win.eventlog.storage.device_number, win.eventlog.storage.io_size_bytes, win.eventlog.storage.io_type, win.eventlog.storage.is_boot_volume, win.eventlog.storage.retries_done, win.eventlog.storage.sense_key, win.eventlog.storage.sense_key_name, win.eventlog.storage.srb_status, win.eventlog.storage.srb_status_code, win.eventlog.storage.srb_status_name, win.eventlog.storage.starting_lcn, win.eventlog.storage.volume_name

The file NTFS names is not shown here. It carries user document paths.

disk_failure_predicted​

A storage device reported that its own reliability is degraded or that it has passed its rated write endurance.

Severity: Warning

Impact: The drive still serves IO. It is reporting wear before reads or writes start failing.

Channel: Microsoft-Windows-Storage-Storport/Health

Provider: Microsoft-Windows-StorPort

Event ids: 539, 542, 543

Where to look next:

  • Plan a replacement window: the drive is working and the warning is early.
  • Check the backup state for the host before scheduling anything on it.
  • Read the endurance percentages together: consumed endurance above the device's own threshold is the claim.

Related reasons:

  • disk_bad_block: the drive actually failing to return data, which is what this predicts

Fields it can set: win.eventlog.storage.endurance_threshold_pct, win.eventlog.storage.health_flag_name, win.eventlog.storage.health_flag_value, win.eventlog.storage.percentage_used_pct

disk_paging_error​

A paging read or write to a storage device failed.

Also reported by: Windows System event log

Severity: Error when the device returned a data error, which is the medium failing. Warning otherwise.

Impact: Nobody chose this IO and no application error surfaces, so this line is the only record.

Channel: Microsoft-Windows-Storage-ClassPnP/Operational

Provider: Microsoft-Windows-StorDiag

Event ids: 502, 503

Where to look next:

  • Read the resolved status code and the device model. A paging failure against the boot device is a host problem. Against removable media, it is a device that vanished mid-page.

Related reasons:

Fields it can set: win.eventlog.storage.device_number, win.eventlog.storage.lba, win.eventlog.storage.nv_cache_priority, win.eventlog.storage.paging_priority, win.eventlog.storage.transfer_bytes

disk_surprise_removal​

A device disappeared without an orderly removal.

Also reported by: Windows System event log

Severity: Warning

Impact: Open handles and writes in flight were lost with it.

Channel: Microsoft-Windows-Storage-Storport/Operational, Microsoft-Windows-EnhancedStorage-EhStorClass/Operational

Provider: Microsoft-Windows-StorPort, Microsoft-Windows-EnhancedStorage-ClassDriver

Event ids: 103, 551

Where to look next:

  • Check removable and surprise_removal_ok. A device with both false vanished through a path failure, not a user action.
  • Check what was writing to it.

Related reasons:

Fields it can set: win.eventlog.storage.device_state, win.eventlog.storage.device_type, win.eventlog.storage.lun, win.eventlog.storage.miniport_name, win.eventlog.storage.port_number, win.eventlog.storage.removable, win.eventlog.storage.surprise_removal_ok

filesystem_corruption​

NTFS moved this machine's global corruption-handling state off nominal.

Also reported by: Windows System event log

Severity: Error

Impact: This reports a state change, not confirmed damage to a file, and does not name a volume.

Channel: Microsoft-Windows-Ntfs/WHC

Provider: Microsoft-Windows-Ntfs

Event ids: 100

CaseSeverityTicket class
state_errorErrorstorage
state_warningErrorstorage

Where to look next:

  • Schedule a chkdsk and check the backup state for that host.
  • Confirm the state returns to a nominal value afterwards.

Fields it can set: win.eventlog.storage.filesystem, win.eventlog.storage.hc_stateid

Microsoft publishes the template with no value map, so the state number ships undecoded.

storage_controller_reset​

The storage port driver reset the path to a device.

Also reported by: Windows System event log

Severity: Error when the device is the one the machine boots from, Warning otherwise.

Impact: Requests in flight were discarded. Repeated resets on a fixed controller usually precede a controller, cable, or backplane failure.

Channel: Microsoft-Windows-Storage-Storport/Operational

Provider: Microsoft-Windows-StorPort

Event ids: 500, 501, 550

Where to look next:

  • Check boot_device and miniport_name. A reset on a USB attached-storage miniport points to the enclosure. A reset on an internal miniport with boot_device true points to the host.
  • Check failed_io_count and the rate.

Related reasons:

Fields it can set: win.eventlog.storage.boot_device, win.eventlog.storage.bus_reset_reason, win.eventlog.storage.bus_type, win.eventlog.storage.bus_type_name, win.eventlog.storage.failed_io_count, win.eventlog.storage.lun, win.eventlog.storage.miniport_name, win.eventlog.storage.path_id, win.eventlog.storage.port_number, win.eventlog.storage.reset_status, win.eventlog.storage.reset_type, win.eventlog.storage.srb_timeout_s, win.eventlog.storage.target_id

storage_device_command_failed​

A storage device did not complete a command, and reported sense data saying why.

Severity: Info when the device is announcing a change to itself, Notice otherwise. One occurrence claims no fault.

Impact: The command was not carried out as issued. The driver reissues, so a single occurrence usually reaches no application.

Channel: Microsoft-Windows-Storage-ClassPnP/Operational

Provider: Microsoft-Windows-StorDiag

Event ids: 507

Where to look next:

  • Group by device and sense key over time. A rising count against one drive is the signal, not a single record.
  • Read the sense key with the additional sense code and its qualifier. Together the three name the condition.
  • Compare against the device's own health counters before planning a replacement.

Fields it can set: win.eventlog.storage.additional_sense_code, win.eventlog.storage.additional_sense_code_qualifier, win.eventlog.storage.cdb_bytes, win.eventlog.storage.scsi_status, win.eventlog.storage.sense_key, win.eventlog.storage.srb_status, win.eventlog.storage.srb_status_code

Sense data is the device's own account of a failure, so it is the one place a drive's answer is recorded rather than inferred. Empty removable slots and unsupported-command probes are not kept.

volume_mount_failed​

NTFS could not mount a volume.

Severity: Warning or Info

Impact: The volume did not come up. The event states the attempt, not how long the condition lasted.

Channel: Microsoft-Windows-Ntfs/Operational

Provider: Microsoft-Windows-Ntfs

Event ids: 305

CaseSeverityTicket class
device_offlineInfostorage
mount_failedWarningstorage

Where to look next:

  • Read the resolved status code. If the device is offline or has no medium, look at whether a removable bay, card reader or mounted image is being polled.
  • If the status is anything else, treat the volume as unavailable and pivot to the device-state stream's volume_unreadable for whether it stayed that way.

Related reasons:

Fields it can set: win.eventlog.storage.volume_guid, win.eventlog.storage.volume_name

Ask this feed a question​

Every reason code, token and field on this page is queryable across the endpoints you manage. Connect your AI and ask in plain language, or open the same evidence in Explore.