Skip to main content

Windows storage event channels

22channels
0curated reasons
0themes fed
Plannedstatus

Disk, volume, filesystem, Storage Spaces and storage-housekeeping channels, bound as one feed: the storage port and class drivers, NTFS and its health-check arm, partitions and volumes, the Storage Spaces provider family, and the disk-cleanup and storage-settings services. Light curation: every event keeps the severity the provider stated, capped at Warning, and one measured flood is dropped by event id. No reasons yet; the fleet data this feed produces is what the curated storage rules will be written from.

Feed id: win.eventlog.storage.

Channels

This feed binds 22 Windows Event Log channels as one reporting axis. A channel that a given Windows edition, role or OEM does not provide is absent on that endpoint; the rest still collect.

The ticket class is the subject area an event on the channel is evidence for, and it is what fleet-wide questions group by.

ChannelTicket class
Microsoft-Windows-Cleanmgr/Diagnosticstorage
Microsoft-Windows-DataIntegrityScan/Adminstorage
Microsoft-Windows-EnhancedStorage-EhStorClass/Operationalstorage
Microsoft-Windows-Ntfs/Operationalstorage
Microsoft-Windows-Ntfs/WHCstorage
Microsoft-Windows-Partition/Diagnosticstorage
Microsoft-Windows-ReadyBoost/Operationalstorage
Microsoft-Windows-Storage-ClassPnP/Operationalstorage
Microsoft-Windows-Storage-Storport/Healthstorage
Microsoft-Windows-Storage-Storport/Operationalstorage
Microsoft-Windows-StorageManagement-PartUtil/Operationalstorage
Microsoft-Windows-StorageSettings/Diagnosticstorage
Microsoft-Windows-StorageSpaces-Api/Operationalstorage
Microsoft-Windows-StorageSpaces-Driver/Diagnosticstorage
Microsoft-Windows-StorageSpaces-Driver/Operationalstorage
Microsoft-Windows-StorageSpaces-ManagementAgent/WHCstorage
Microsoft-Windows-StorageSpaces-Parser/Diagnosticstorage
Microsoft-Windows-StorageSpaces-Parser/Operationalstorage
Microsoft-Windows-StorageSpaces-SpaceManager/Diagnosticstorage
Microsoft-Windows-StorageSpaces-SpaceManager/Operationalstorage
Microsoft-Windows-StorageVolume/Operationalstorage
Microsoft-Windows-Storsvc/Diagnosticstorage

Severity

This feed is bound for collection but is not yet curated per event. Every event keeps the severity its own provider stated, capped at Warning.

Ask this feed a question

Every reason code, token and field on this page is queryable across the endpoints you manage. Connect your AI and ask in plain language, or open the same evidence in Explore.