<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v3" manifestVersion="1.0" copyright="Copyright (c) Microsoft Corporation. All Rights Reserved.">
  <assemblyIdentity name="Microsoft-Windows-SMBMiniRdr" version="10.0.10586.122" processorArchitecture="amd64" language="neutral" buildType="release" publicKeyToken="31bf3856ad364e35" versionScope="nonSxS" />
  <dependency discoverable="no" resourceType="Resources">
    <dependentAssembly dependencyType="prerequisite">
      <assemblyIdentity name="Microsoft-Windows-SMBMiniRdr.Resources" version="10.0.10586.122" processorArchitecture="amd64" language="*" buildType="release" publicKeyToken="31bf3856ad364e35" versionScope="nonSxS" />
    </dependentAssembly>
  </dependency>
  <file name="mrxsmb.sys" destinationPath="$(runtime.drivers)\" sourceName="mrxsmb.sys" sourcePath=".\" importPath="$(build.nttree)\">
    <securityDescriptor name="WRP_FILE_DEFAULT_SDDL" />
    <asmv2:hash xmlns:asmv2="urn:schemas-microsoft-com:asm.v2">
      <dsig:Transforms xmlns:dsig="http://www.w3.org/2000/09/xmldsig#">
        <dsig:Transform Algorithm="urn:schemas-microsoft-com:HashTransforms.Identity" />
      </dsig:Transforms>
      <dsig:DigestMethod xmlns:dsig="http://www.w3.org/2000/09/xmldsig#" Algorithm="http://www.w3.org/2000/09/xmldsig#sha256" />
      <dsig:DigestValue xmlns:dsig="http://www.w3.org/2000/09/xmldsig#">2+2db3qvsR9MAMH2nbeoh6MFjl+mZhWhZAJCQ5gitgw=</dsig:DigestValue>
    </asmv2:hash>
  </file>
  <memberships>
    <categoryMembership>
      <id name="Microsoft.Windows.Categories" version="1.0.0.0" publicKeyToken="365143bb27e7ac8b" typeName="BootCritical" />
    </categoryMembership>
    <categoryMembership>
      <id name="Microsoft.Windows.Categories.Services" version="10.0.10586.122" publicKeyToken="31bf3856ad364e35" typeName="Service" />
      <categoryInstance subcategory="mrxsmb">
        <serviceData name="mrxsmb" displayName="@%systemroot%\system32\wkssvc.dll,-1002" errorControl="normal" group="Network" imagePath="system32\DRIVERS\mrxsmb.sys" start="demand" tag="5" type="fileSystemDriver" description="@%systemroot%\system32\wkssvc.dll,-1003" dependOnService="rdbss" />
      </categoryInstance>
    </categoryMembership>
    <categoryMembership>
      <id name="Microsoft.Windows.Categories" version="1.0.0.0" publicKeyToken="365143bb27e7ac8b" typeName="BootRecovery" />
    </categoryMembership>
  </memberships>
  <registryKeys>
    <registryKey keyName="HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\EventLog\System\mrxsmb">
      <registryValue name="EventMessageFile" valueType="REG_EXPAND_SZ" value="%systemroot%\system32\netevent.dll;%systemroot%\system32\iologmsg.dll" />
      <registryValue name="TypesSupported" valueType="REG_DWORD" value="0x00000007" />
      <securityDescriptor name="WRP_REGKEY_DEFAULT_SDDL" />
    </registryKey>
    <registryKey keyName="HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\NetDiagFx\Microsoft\HostDLLs\WPPTrace\HelperClasses\SmbClient_wpp">
      <registryValue name="Published" valueType="REG_DWORD" value="0x00000000" />
      <registryValue name="Extensible" valueType="REG_DWORD" value="0x00000000" />
      <registryValue name="Version" valueType="REG_SZ" value="1.0" />
      <securityDescriptor name="WRP_REGKEY_DEFAULT_SDDL" />
    </registryKey>
    <registryKey keyName="HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\NetDiagFx\Microsoft\HostDLLs\WPPTrace\HelperClasses\SmbClient_wpp\Providers">
      <securityDescriptor name="WRP_REGKEY_DEFAULT_SDDL" />
    </registryKey>
    <registryKey keyName="HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\NetDiagFx\Microsoft\HostDLLs\WPPTrace\HelperClasses\SmbClient_wpp\Providers\{20c46239-d059-4214-a11e-7d6769cbe020}">
      <registryValue name="Name" valueType="REG_SZ" value="RDR WPP" />
      <registryValue name="Keywords" valueType="REG_QWORD" value="0303300300000000" />
      <registryValue name="Level" valueType="REG_DWORD" value="0x00000000" />
      <securityDescriptor name="WRP_REGKEY_DEFAULT_SDDL" />
    </registryKey>
    <registryKey keyName="HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\NetDiagFx\Microsoft\HostDLLs\WPPTrace\HelperClasses\SmbClient_wpp\Providers\{0086eae4-652e-4dc7-b58f-11fa44f927b4}">
      <registryValue name="Name" valueType="REG_SZ" value="RDBSS WPP" />
      <registryValue name="Keywords" valueType="REG_QWORD" value="FFFFFF0F00000000" />
      <registryValue name="Level" valueType="REG_DWORD" value="0x00000002" />
      <securityDescriptor name="WRP_REGKEY_DEFAULT_SDDL" />
    </registryKey>
    <registryKey keyName="HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\NetDiagFx\Microsoft\HostDLLs\WPPTrace\HelperClasses\SmbClient_wpp\Providers\{f818ebb3-fbc4-4191-96d6-4e5c37c8a237}">
      <registryValue name="Name" valueType="REG_SZ" value="MRXSMB WPP" />
      <registryValue name="Keywords" valueType="REG_QWORD" value="FFFFFF0F00000000" />
      <registryValue name="Level" valueType="REG_DWORD" value="0x00000002" />
      <securityDescriptor name="WRP_REGKEY_DEFAULT_SDDL" />
    </registryKey>
    <registryKey keyName="HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\NetDiagFx\Microsoft\HostDLLs\WPPTrace\HelperClasses\SmbClient_wpp\Providers\{e4ad554c-63b2-441b-9f86-fe66d8084963}">
      <registryValue name="Name" valueType="REG_SZ" value="SMB20 WPP" />
      <registryValue name="Keywords" valueType="REG_QWORD" value="FFFFFF0F00000000" />
      <registryValue name="Level" valueType="REG_DWORD" value="0x00000002" />
      <securityDescriptor name="WRP_REGKEY_DEFAULT_SDDL" />
    </registryKey>
    <registryKey keyName="HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\NetDiagFx\Microsoft\HostDLLs\WPPTrace\HelperClasses\SmbClient_wpp\Providers\{47eba62c-87e6-4564-9946-0dd4e361ed9b}">
      <registryValue name="Name" valueType="REG_SZ" value="WitnessClient WPP" />
      <registryValue name="Keywords" valueType="REG_QWORD" value="FFFFFF0F00000000" />
      <registryValue name="Level" valueType="REG_DWORD" value="0x00000007" />
      <securityDescriptor name="WRP_REGKEY_DEFAULT_SDDL" />
    </registryKey>
    <registryKey keyName="HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\AutoLogger\RdrLog\{f818ebb3-fbc4-4191-96d6-4e5c37c8a237}">
      <registryValue name="_Description" valueType="REG_SZ" value="MRXSMB Trace Provider" />
      <registryValue name="LoggerName" valueType="REG_SZ" value="MrxsmbLog" />
      <registryValue name="Enabled" valueType="REG_DWORD" value="0x00000000" />
      <registryValue name="EnableLevel" valueType="REG_DWORD" value="0x00000002" />
      <registryValue name="EnableFlags" valueType="REG_DWORD" value="0x00000001" />
    </registryKey>
  </registryKeys>
  <trustInfo>
    <security>
      <accessControl>
        <securityDescriptorDefinitions>
          <securityDescriptorDefinition name="WRP_FILE_DEFAULT_SDDL" sddl="O:S-1-5-80-956008885-3418522649-1831038044-1853292631-2271478464G:S-1-5-80-956008885-3418522649-1831038044-1853292631-2271478464D:P(A;;FA;;;S-1-5-80-956008885-3418522649-1831038044-1853292631-2271478464)(A;;GRGX;;;BA)(A;;GRGX;;;SY)(A;;GRGX;;;BU)(A;;GRGX;;;S-1-15-2-1)S:(AU;FASA;0x000D0116;;;WD)" operationHint="replace" description="Default SDDL for Windows Resource Protected file" />
          <securityDescriptorDefinition name="WRP_REGKEY_DEFAULT_SDDL" sddl="O:S-1-5-80-956008885-3418522649-1831038044-1853292631-2271478464G:S-1-5-80-956008885-3418522649-1831038044-1853292631-2271478464D:P(A;CI;GA;;;S-1-5-80-956008885-3418522649-1831038044-1853292631-2271478464)(A;CI;GR;;;SY)(A;CI;GR;;;BA)(A;CI;GR;;;BU)(A;CI;GR;;;S-1-15-2-1)" operationHint="replace" />
        </securityDescriptorDefinitions>
      </accessControl>
    </security>
  </trustInfo>
  <localization>
    <resources culture="en-US">
      <stringTable>
        <string id="AcquireCredHandleFailure" value="%1.%n%nError: %2%n%nSecurity status: %3%nUser name: %10%nLogon ID: %4%nSerrver name: %6" />
        <string id="CloseFailure" value="Close request failed.%n%nError: %2%n%nPath: %4%6%n%nGuidance:%nA persistent handle (Continuous Availability) or a resilient handle failed to close." />
        <string id="ConnectionTypeMapRdma" value="Rdma" />
        <string id="ConnectionTypeMapTdi" value="Tdi" />
        <string id="ConnectionTypeMapWsk" value="Wsk" />
        <string id="DecryptionFailure" value="Failed to decrypt an encrypted SMB message.%n%nError:%7%n%nServer name: %6%nSession ID:%3%n%nGuidance:%nThe client received an encrypted SMB message but cannot decrypt the data. This typically means that the communication came from a previous session that no longer exists. The encryption header may also have been damaged or tampered with on the network between the client and server." />
        <string id="description" value="Framework for the SMB filesystem redirector. (ClientCore) (All pieces)" />
        <string id="description13" value="Default SDDL for Windows Resource Protected registry key" />
        <string id="description15" value="Default SDDL for Windows Resource Protected file" />
        <string id="DisconnectIndication" value="A network connection was disconnected.%n%nServer name: %4%nServer address: %6%nConnection type: %7%n%nGuidance:%nThis indicates that the client's connection to the server was disconnected.%n%nFrequent, unexpected disconnects when using an RDMA over Converged Ethernet (RoCE) adapter may indicate a network misconfiguration. RoCE requires Priority Flow Control (PFC) to be configured for every host, switch and router on the RoCE network. Failure to properly configure PFC will cause packet loss, frequent disconnects and poor performance." />
        <string id="displayName" value="SMB Mini-Redirector Engine" />
        <string id="displayName12" value="WRP_REGKEY_DEFAULT_SDDL" />
        <string id="displayName14" value="WRP_FILE_DEFAULT_SDDL" />
        <string id="displayName2" value="SMB MiniRedirector Wrapper and Engine" />
        <string id="EnableSecuritySignatureNonDefault" value="The SMB Signing registry value is not configured with default settings.%n%nDefault Registry Value:%n[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\LanmanWorkstation\Parameters]%n&quot;EnableSecuritySignature&quot;=dword:1%nConfigured Registry Value:%n[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\LanmanWorkstation\Parameters]%n&quot;EnableSecuritySignature&quot;=dword:0%n%nGuidance:%nEven though you can disable, enable, or require SMB Signing, the negotiation rules changed starting with SMB2 and not all combinations operate like SMB1.%n%nThe effective behavior for SMB2/SMB3 is:%nClient Required and Server Required = Signed%nClient Not Required and Server Required = Signed%nServer Required and Client Not Required = Signed%nServer Not Required and Client Not Required = Not Signed%n%nWhen requiring SMB Encryption, SMB Signing is not used, regardless of settings. SMB Encryption implicitly provides the same integrity guarantees as SMB Signing." />
        <string id="EncryptionFailure" value="The client received an unencrypted message when encryption was expected.%n%nServer name: %6%nSession ID:%3%nTree ID:%4%nMessage ID:%2%nCommand: %1%n%nGuidance:%nThis error indicates that SMB messages are being modified in transit across the network from the server to the client. This may be due to the session ending on the server, a problem with the network, a problem with a third-party SMB server, or a &quot;man-in-the-middle&quot; compromise attempt." />
        <string id="eventChannelName_Diagnostic" value="Microsoft-Windows-SMBClient/Diagnostic" />
        <string id="EventProviderName" value="Microsoft-Windows-SMBClient" />
        <string id="evtCreateFile" value="Transitioned to State: %1 Context: %2" />
        <string id="evtCreateFileError" value="Create File Error: %1 Location: %2 Context: %3" />
        <string id="evtCreateSrvCallError" value="Create SrvCall Error: %1 Location: %2 Context: %3" />
        <string id="evtCreateVNetRootError" value="Create VNetRoot Error: %1 Location: %2 Context: %3" />
        <string id="evtSessionSetupError" value="Session Setup Error: %1 Location: %2 Context: %3" />
        <string id="evtTreeConnectError" value="Tree Connect Error: %1 Location: %2 Context: %3" />
        <string id="ExpiredExchange" value="A request timed out because there was no response from the server.%n%nServer name: %6%nSession ID:%3%nTree ID:%4%nMessage ID:%2%nCommand: %1%n%nGuidance:%nThe server is responding over TCP but not over SMB. Ensure the Server service is running and responsive, and the disks do not have high per-IO latency, which makes the disks appear unresponsive to SMB. Also, ensure the server is responsive overall and not paused; for instance, make sure you can log on to it." />
        <string id="HandleOpenFailure" value="Failed to open a persistent handle.%n%nError: %7%n%nFileId: %2:%3%nCreateGUID: %4%nPath: %10%12%n%nReason: %8%n%nGuidance:%nA persistent handle allows transparent failover on Windows File Server clusters. This event has many causes and does not always indicate an issue with SMB. Review online documentation for troubleshooting information." />
        <string id="HandlePersistenceNotGranted" value="The handle was created without persistence.%n%nFile ID: %2:%3%nCreateGUID: %4%nPath: %10%12%n%nGuidance:%nThe server supports Continuous Availability (persistent handles) and the request to create the handle succeeded. However, the server did not grant persistence. You should verify that the Resume Key Filter is running on the server and is attached to the target volume." />
        <string id="InsecureGuestAuthEnabled" value="The %1 registry value is not configured with default settings.%n%nDefault Registry Value:%n[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\LanmanWorkstation\Parameters]%n&quot;%1&quot;=dword:0%nConfigured Registry Value:%n[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\LanmanWorkstation\Parameters]%n&quot;%1&quot;=dword:%2%n%nGuidance:%nThis event indicates that an administrator has enabled insecure guest logons. An insecure guest logon occurs when a server logs the user on as an unauthenticated guest, typically in response to an authentication failure. Guest logons do not support standard security features such as signing and encryption. As a result, allowing guest logons makes the client vulnerable to man-in-the-middle attacks that can expose sensitive data on the network. Windows disables insecure guest logons by default. Microsoft does not recommend enabling insecure guest logons." />
        <string id="InvalidCipherSuiteOrder" value="The Cipher Suite Order group policy setting is invalid.%n%nGuidance:%n%nThis event indicates that an administrator has configured an invalid value for the &quot;Computer Configuration\Administrative Templates\Network\Lanman Workstation\Cipher Suite Order&quot; group policy setting. The client will use the default cipher suite order &quot;%1&quot; until this error is resolved." />
        <string id="IrpCodeCleanup" value="Cleanup" />
        <string id="IrpCodeClose" value="Close" />
        <string id="IrpCodeCreate" value="Create" />
        <string id="IrpCodeDeviceControl" value="Device control" />
        <string id="IrpCodeDirectoryControl" value="Directory control" />
        <string id="IrpCodeFileSystemControl" value="File system control" />
        <string id="IrpCodeFlushBuffers" value="Flush buffers" />
        <string id="IrpCodeInternalDeviceControl" value="Internal device control" />
        <string id="IrpCodeInternalProbeIO" value="Internal probe I/O" />
        <string id="IrpCodeLockControl" value="Lock control" />
        <string id="IrpCodeQueryEa" value="Query EA" />
        <string id="IrpCodeQueryInformation" value="Query information" />
        <string id="IrpCodeQueryQuotaInformation" value="Query quota information" />
        <string id="IrpCodeQuerySecurity" value="Query security" />
        <string id="IrpCodeQueryVolumeInformation" value="Query volume information" />
        <string id="IrpCodeRead" value="Read" />
        <string id="IrpCodeSetEa" value="Set EA" />
        <string id="IrpCodeSetInformation" value="Set information" />
        <string id="IrpCodeSetQuotaInformation" value="Set quota information" />
        <string id="IrpCodeSetSecurity" value="Set security" />
        <string id="IrpCodeSetVolumeInformation" value="Set volume information" />
        <string id="IrpCodeWrite" value="Write" />
        <string id="ISCFailure" value="%1.%n%nError: %2%n%nSecurity status: %3%nUser name: %10%nLogon ID: %4%nServer name: %6%nPrincipal name: %8" />
        <string id="LMCompatibilityLevel" value="The LmCompatibilityLevel value is different from the default.%n%nConfigured LM Compatibility Level: %2%nDefault LM Compatibility Level: 3%n%nGuidance:%nLAN Manager (LM) authentication is the protocol used to authenticate Windows clients for network operations. This includes joining a domain, accessing network resources, and authenticating users or computers. This determines which challenge/response authentication protocol is negotiated between the client and the server computers. Specifically, the LM authentication level determines which authentication protocols the client will try to negotiate or the server will accept. The value set for LmCompatibilityLevel determines which challenge/response authentication protocol is used for network logons. This value affects the level of authentication protocol that clients use, the level of session security negotiated, and the level of authentication accepted by servers.%n%nValue (Setting) - Description%n%n0 (Send LM &amp; NTLM responses) - Clients use LM and NTLM authentication and never use NTLMv2 session security. Domain controllers accept LM, NTLM, and NTLMv2 authentication.%n%n1 (Send LM &amp; NTLM - use NTLMv2 session security if negotiated) - Clients use LM and NTLM authentication, and use NTLMv2 session security if the server supports it. Domain controllers accept LM, NTLM, and NTLMv2 authentication.%n%n2 (Send NTLM response only) - Clients use NTLM authentication only and use NTLMv2 session security if the server supports it. Domain controllers accept LM, NTLM, and NTLMv2 authentication.%n%n3 (Send NTLM v2 response only) - Clients use NTLMv2 authentication only and use NTLMv2 session security if the server supports it. Domain controllers accept LM, NTLM, and NTLMv2 authentication.%n%n4 (Send NTLMv2 response only/refuse LM) - Clients use NTLMv2 authentication only and use NTLMv2 session security if the server supports it. Domain controllers refuse LM and accept only NTLM and NTLMv2 authentication.%n%n5 (Send NTLM v2 response only/refuse LM &amp; NTLM) - Clients use NTLMv2 authentication only and use NTLMv2 session security if the server supports it. Domain controllers refuse LM and NTLM and accept only NTLMv2 authentication.%n%nIncompatibly configured  LmCompatibility levels between a client and server (such as 0 on a client and 5 on a server) prevent access to the server. Non-Microsoft clients and servers also provide these configuration settings." />
        <string id="MADowngradeDetected" value="Mutual authentication was unexpectedly lost after re-authenticating to %6%nUser %10%nLogonID %4%nStatus %2%n" />
        <string id="MultiChannelDisabled" value="The SMB Multichannel registry value is not configured with default settings.%n%nDefault Registry Value:%n[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\LanmanWorkstation\Parameters]%n&quot;DisableMultiChannel&quot;=dword:0%nConfigured Registry Value:%n[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\LanmanWorkstation\Parameters]%n&quot;DisableMultiChannel&quot;=dword:%2%n%nGuidance:%nYou can configure SMB Multichannel on the client using the Windows PowerShell cmdlet Set-SmbClientConfiguration. Disabling SMB client multichannel support is not a recommended configuration, as it can lead to degraded performance and decreased reliability if one channel or network path fails." />
        <string id="NegotiateFailure" value="The server failed the negotiate request.%n%nError: %2%n%nServer name: %4%n%nGuidance:%nThe server does not support any dialect that the client is trying to negotiate, such as the client has SMB2/SMB3 disabled and the server has SMB1 disabled." />
        <string id="NegotiateValidation" value="The negotiate validation failed.%n%nFrom negotiate response:%nDialect: %1%nSecurityMode: %2%nCapabilities: %3%nServerGuid: %4%n%nFrom FSCTL_VALIDATE_NEGOTIATE_INFO response:%nDialect: %5%nSecurityMode: %6%nCapabilities: %7%nServerGuid: %8%n%nGuidance:%nThe client successfully negotiated SMB dialect, security mode, capabilities and server GUID with the server, but the validation of these values then failed after connecting to a share. This may be due to a &quot;man-in-the-middle&quot; compromise attempt." />
        <string id="NetConnect" value="WSK connect: SocketAddress %2 VcEndpoint %3 Socket %4" />
        <string id="NetConnectCompletion" value="WSK connect completion: VcEndpoint %1 Socket %2 Status %3" />
        <string id="NetReceive" value="WSK receive: VcEndpoint %1 Socket %2 ReceiveMdl %3 ReceiveLength %4" />
        <string id="NetReceiveCompletion" value="WSK receive completion: VcEndpoint %1 Socket %2 ReceiveMdl %3 ReceiveLength %4 Status %5" />
        <string id="NetSend" value="WSK send: VcEndpoint %1 Socket %2 SendMdl %3 SendLength %4" />
        <string id="NetSendCompletion" value="WSK send completion: VcEndpoint %1 Socket %2 SendMdl %3 SendLength %4 Status %5" />
        <string id="NetworkConnectFailure" value="Failed to establish a network connection.%n%nError: %2%n%nServer name: %4%nServer address: %6%nConnection type: %7%n%nGuidance:%nThis indicates a problem with the underlying network or transport, such as with TCP/IP, and not with SMB. A firewall that blocks TCP port 445, or TCP port 5445 when using an iWARP RDMA adapter, can also cause this issue." />
        <string id="NetworkTokenFailure" value="The outbound authentication failed using a network token.%n%nError: %2%n%nServer name: %4%n%nGuidance:%nThis typically indicates that delegation must be configured for a Kerberos double-hop scenario. If delegation is configured, confirm that the services are configured correctly on the middle-tier server." />
        <string id="opcodeCache" value="Cached Error" />
        <string id="opcodeISC" value="Initialize Security Context Error" />
        <string id="opcodeServer" value="Server Error" />
        <string id="opcodeSigning" value="Security Signature Error" />
        <string id="OpenHandleStateTransition" value="Open handle %1 to %10%12 transitioned from [%5] to [%6] with Status %7" />
        <string id="PCAP.evtPacket" value="Packet (%4 bytes)" />
        <string id="PCAP.evtPacketFragment" value="Packet Fragment (%2 bytes)" />
        <string id="PersistentHandleFailure" value="Failed to reconnect a persistent handle.%n%nError: %7%n%nFileId: %2:%3%nCreateGUID: %4%nPath: %10%12%n%nReason: %8%n%nPrevious reconnect error: %13%nPrevious reconnect reason: %14%n%nGuidance:%nA persistent handle allows transparent failover on Windows File Server clusters. This event has many causes and does not always indicate an issue with SMB. Review online documentation for troubleshooting information." />
        <string id="RdmaConnectFailure" value="The client failed to connect to the server %2 from the local IP address %4 to the remote IP address %6 over RDMA transport. Error: %7" />
        <string id="RdmaConnectSuccess" value="The client connected to the server %2 from the local IP address %4 to the remote IP address %6 over RDMA transport successfully" />
        <string id="RdmaFallback" value="RDMA interfaces are available but the client failed to connect to the server over RDMA transport.%n%nServer name: %2%n%nGuidance:%nBoth client and server have RDMA (SMB Direct) adaptors but there was a problem with the connection and the client had to fall back to using TCP/IP SMB (non-RDMA)." />
        <string id="RdmaWithEncryption" value="The client supports SMB Direct (RDMA) and SMB Encryption is in use.%n%nShare name: %2%n%nGuidance:%nFor optimal SMB Direct performance, you can disable SMB Encryption on the server for shares accessed by this client. This configuration is less secure and you should only consider this configuration on trustworthy private networks with strict access control." />
        <string id="RdmaWithSigning" value="The client supports SMB Direct (RDMA) and SMB Signing is in use.%n%nShare name: %2%n%nGuidance:%nFor optimal SMB Direct performance, you can disable SMB Signing. This configuration is less secure and you should only consider this configuration on trustworthy private networks with strict access control." />
        <string id="Reason_Status_Path" value="%1.%n%nError: %2%n%nPath: %4%6" />
        <string id="Reason_Status_ServerName" value="%1.%n%nError: %2%n%nServer name: %4" />
        <string id="RejectedInsecureGuestAuth" value="Rejected an insecure guest logon.%n%nUser name: %2%nServer name: %4%n%nGuidance:%nThis event indicates that the server attempted to log the user on as an unauthenticated guest and was denied by the client. Guest logons do not support standard security features such as signing and encryption. As a result, guest logons are vulnerable to man-in-the-middle attacks that can expose sensitive data on the network. Windows disables insecure guest logons by default. Microsoft does not recommend enabling insecure guest logons." />
        <string id="RequestRetryFailure" value="A request on persistent/resilient handle failed because the handle was invalid or it exceeded the timeout.%n%nStatus: %7%n%nType: %1%nPath: %4%6%nRestart count: %2%n%nGuidance:%nAfter retrying a request on a Continuously Available (Persistent) handle or a Resilient handle, the client was unable to reconnect the handle. This event is the result of a handle recovery failure. Review other events for more details." />
        <string id="RequireSecureNegotiateIsDeprecated" value="The RequireSecureNegotiate setting has been removed.%n%nRegistry Key: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\LanmanWorkstation\Parameters%nRegistry Value: RequireSecureNegotiate%n%nGuidance:%n%nYou should expect this event when an administrator configures the RequireSecureNegotiate setting. Secure negotiate prevents man-in-the-middle attacks against SMB connection establishment. Previous versions of Windows allowed secure negotiate to be disabled. Disabling secure negotiate is no longer allowed. The client removed the setting from the registry. No user action is required." />
        <string id="ResilientHandleFailure" value="Failed to reconnect a resilient handle.%n%nError: %7%n%nFileId: %2:%3%nPath: %10%12%n%nReason: %8.%n%nPrevious reconnect error: %13%nPrevious reconnect reason: %14%n%nGuidance:%nA resilient handle provides guarantees to applications requesting it. This event has many causes and does not always indicate an issue with SMB. Review online documentation for troubleshooting information." />
        <string id="ServerMultiChannelConstraint" value="The client cannot connect to the server due to a multichannel constraint registry setting.%n%nServer name: %2%n%nGuidance:%nThe client attempted to use SMB Multichannel, but an administrator has configured multichannel support to prevent multichannel on the client. You can configure SMB Multichannel on the client using the Windows PowerShell cmdlets: New-SmbMultichannelConstraint and Remove-SmbMultichannelConstraint." />
        <string id="ServerMultiChannelIncapable" value="The server does not support multichannel.%n%nServer name: %2%n%nGuidance:%nThe client attempted to use SMB Multichannel, but an administrator has disabled multichannel support on the server. This may also be a non-Microsoft file server that does not support multichannel or has multichannel disabled. You can enable SMB Multichannel on the server using this Windows PowerShell cmdlet: Set-SmbServerConfiguration -EnableMultiChannel:$true. This event does not apply to the multichannel settings of SMB client, which are controlled by the Set-SmbClientConfiguration Windows PowerShell cmdlet. Enabling or disabling client multichannel support does not affect server multichannel support." />
        <string id="ServerNetworkInterfaceInvalid" value="An invalid FSCTL_QUERY_NETWORK_INTERFACE_INFO response was sent by the server %2" />
        <string id="ServerWitnessMove" value="The SMB client received a request to move to a different node on a file server cluster.%n%nFile server cluster name: %4%nNew file server cluster address: %6%n%nGuidance:%nContinuous Availability (Transparent Failover) is in use and the client computer is going to move to a different node after an SMB witness request over RPC using TCP (first contacting port 135, then contacting an endpoint port above 1023). No user action is required." />
        <string id="ServerWitnessMoveFailure" value="The SMB client failed to move to a different node on a file server cluster.%n%nError: %1%n%nFile server cluster name: %4%n%nGuidance:%nContinuous Availability (Transparent Failover) is in use and the client computer failed to move to a different node after an SMB witness request over RPC using TCP (first contacting port 135, then contacting an endpoint port above 1023). The attempt to connect to the destination server failed, which is typically due to a network configuration issue. For example, this issue may occur if the destination node's IP address cannot be resolved, if the destination node is behind a firewall, or if there is no network route from the client to the node." />
        <string id="ServerWitnessMoveSuccess" value="The SMB client successfully moved to a different node on a file server cluster.%n%nFile server cluster name: %4%n New file server cluster address: %6%n%nGuidance:%nContinuous Availability (Transparent Failover) is in use and the client computer successfully moved to a different node after an SMB witness request over RPC using TCP (first contacting port 135, then contacting an endpoint port above 1023). No user action is required." />
        <string id="SessionEstablished" value="The client re-established its session to the server.%n%nServer name: %5%nServer address: %7%nSession ID: %2%n%nGuidance:%nYou should expect this event if there was a previous event 30805, but the client successfully resumed the cached connection before the timeout expired." />
        <string id="SessionFailure" value="The client lost its session to the server.%n%nError: %1%n%nServer name: %5%nSession ID: %2%n%nGuidance:%nIf the server is a Windows Failover Cluster file server, then this message occurs when the file share moves between cluster nodes. There should also be an anti-event 30806 indicating the session to the server was re-established. If the server is not a failover cluster, it is likely that the server was previously online, but it is now inaccessible over the network." />
        <string id="SessionStateTransition" value="Session %1 to %6 transitioned from [%2] to [%3] with Status %4" />
        <string id="ShareConnectionEstablished" value="The connection to the share was re-established.%n%nShare name: %5%nServer address: %7%nSession ID: %2%nTree ID: %3%n%nGuidance:%nYou should expect this event if there was a previous event 30807, but the client successfully resumed the cached connection before the timeout expired." />
        <string id="ShareConnectionFailure" value="The connection to the share was lost.%n%nError: %1%n%nShare name: %5%nSession ID: %2%nTree ID: %3%n%nGuidance:%nIf the server is a Windows Failover Cluster file server, then this message occurs when the file share moves between cluster nodes. There should also be an anti-event 30808 indicating the session to the server was re-established. If the server is not a failover cluster, it is likely that the server was previously online, but it is now inaccessible over the network." />
        <string id="ShareTypeMapAsymmetric" value="Asymmetric" />
        <string id="ShareTypeMapSymmetric" value="Symmetric" />
        <string id="SigningFailure" value="The signing validation failed.%n%nError:%7%n%nServer name: %6%nSession ID:%3%nTree ID:%4%nMessage ID:%2%nCommand: %1%n%nGuidance:%nThis error indicates that SMB messages are being modified in transit across the network from the server to the client. This may be due to the session ending on the server, a problem with the network, a problem with a third-party SMB server, or a &quot;man-in-the-middle&quot; compromise attempt." />
        <string id="Smb2CommandCancel" value="Cancel" />
        <string id="Smb2CommandChangeNotify" value="Change notify" />
        <string id="Smb2CommandClose" value="Close" />
        <string id="Smb2CommandCreate" value="Create" />
        <string id="Smb2CommandEcho" value="Echo" />
        <string id="Smb2CommandFlush" value="Flush" />
        <string id="Smb2CommandIoctl" value="Ioctl" />
        <string id="Smb2CommandLock" value="Lock" />
        <string id="Smb2CommandLogoff" value="Logoff" />
        <string id="Smb2CommandNegotiate" value="Negotiate" />
        <string id="Smb2CommandOplockBreak" value="Oplock break" />
        <string id="Smb2CommandQueryDirectory" value="Query directory" />
        <string id="Smb2CommandQueryInfo" value="Query info" />
        <string id="Smb2CommandRead" value="Read" />
        <string id="Smb2CommandSessionSetup" value="Session setup" />
        <string id="Smb2CommandSetInfo" value="Set info" />
        <string id="Smb2CommandTreeConnect" value="Tree connect" />
        <string id="Smb2CommandTreeDisconnect" value="Tree disconnect" />
        <string id="Smb2CommandWrite" value="Write" />
        <string id="Smb2DiagReasonAcquireCredHandle" value="An attempt to acquire a credential handle failed" />
        <string id="Smb2DiagReasonCreateResponse" value="The server denied the create request" />
        <string id="Smb2DiagReasonDisconnectIndication" value="Disconnected because there was a network disconnect indication" />
        <string id="Smb2DiagReasonDns" value="The server name cannot be resolved" />
        <string id="Smb2DiagReasonExchangeCancellation" value="The request was canceled by the client" />
        <string id="Smb2DiagReasonExchangeExpiry" value="Disconnected because the exchange expired" />
        <string id="Smb2DiagReasonHandleClosed" value="The file handle was closed by the application" />
        <string id="Smb2DiagReasonHandleReconnect" value="Failed to reconnect the handle" />
        <string id="Smb2DiagReasonIPSec" value="The connection attempt failed with an IPSec error" />
        <string id="Smb2DiagReasonISC" value="An attempt to initialize a security context failed" />
        <string id="Smb2DiagReasonNegativeCache" value="The connect attempt failed because the unreachable server cache contains the destination server name" />
        <string id="Smb2DiagReasonNegotiateValidation" value="The negotiate validation failed" />
        <string id="Smb2DiagReasonNetworkConnect" value="The connection attempt failed with a network error" />
        <string id="Smb2DiagReasonNotSpecified" value="The reason is not specified" />
        <string id="Smb2DiagReasonObjectSuspended" value="The connection object was suspended by the client" />
        <string id="Smb2DiagReasonSessionSetupResponse" value="The server failed a session setup request" />
        <string id="Smb2DiagReasonSetSocketSecurity" value="Set socket security failed" />
        <string id="Smb2DiagReasonTreeConnectResponse" value="The server denied the share connect request" />
        <string id="Smb2DiagReasonUserDisconnect" value="The connection was disconnected by a user or application" />
        <string id="Smb2DiagReasonValidateNegotiateFsctl" value="The validate negotiate FSCTL request failed" />
        <string id="Smb2Disabled" value="The SMB 3 and SMB 2 driver is not configured with the default start type.%n%nDefault Start Type: DEMAND_START%nConfigured Start Type: DISABLED%n%nGuidance:%nYou should expect this event when disabling SMB2/SMB3 for the client using SC.EXE or editing the Windows registry. Microsoft does not recommend disabling SMB2/SMB3. Disabling SMB2/SMB3 prevents use of features such as SMB Transparent Failover, SMB Scale Out, SMB Multichannel, SMB Direct (RDMA), SMB Encryption, VSS for SMB file shares, and SMB Directory Leasing. SMB provides alternative troubleshooting workarounds to disabling SMB2/SMB3 in most cases." />
        <string id="Smb2ObjectStateActive" value="Active" />
        <string id="Smb2ObjectStateConstructionInProgress" value="Construction in progress" />
        <string id="Smb2ObjectStateDeleted" value="Deleted" />
        <string id="Smb2ObjectStateDisconnected" value="Disconnected" />
        <string id="Smb2ObjectStateDisconnectInProgress" value="Disconnect in progress" />
        <string id="Smb2ObjectStateInvalid" value="Invalid" />
        <string id="Smb2ObjectStateInvalidationInProgress" value="Invalidation in progress" />
        <string id="Smb2ObjectStateRecoveryInProgress" value="Recovery in progress" />
        <string id="Smb2ObjectStateSuspended" value="Suspended" />
        <string id="Smb3PartSPNReauth" value="SMB 3 part SPN reauth: SessionEntry %1 ServiceName %3" />
        <string id="SmbConnectivityEventChannel" value="Microsoft-Windows-SMBClient/Connectivity" />
        <string id="SmbDataReady" value="SMB copy data completion: Status %1 VcEndpoint %2" />
        <string id="SmbDeferOpen" value="SMB defer open: Fcb %1 SrvOpen %2" />
        <string id="SmbFetchDirCache" value="SMB fetch dir cache: RxContext %1 Fcb %2 FileName %4 Status %5" />
        <string id="SmbFetchFNFCache" value="SMB fetch file not found cache: RxContext %1 Fcb %2 FileName %4 Result %5" />
        <string id="SmbFetchInfoCache" value="SMB fetch file info cache: RxContext %1 Fcb %2 FileName %4 Status %5" />
        <string id="SmbHelperClassEventChannel" value="Microsoft-Windows-SMBClient/HelperClassDiagnostic" />
        <string id="SmbInitializeMidWindow" value="SMB initialize Mid window: Server %2 Window %3" />
        <string id="SmbInvalidateFNFCache" value="SMB invalidate file not found cache: RxContext %1 Fcb %2 FileName %4" />
        <string id="SmbInvalidateInfoCache" value="SMB invalidate file info cache: RxContext %1 Fcb %2 FileName %4" />
        <string id="SmbMidWindowBlocked" value="SMB Mid window blocked: Window %1 HungSession %2" />
        <string id="SmbMidWindowState" value="SMB Mid window state: Window %1 CurrentWindowSize %2 CurrentWindowLimit %3 ThrottlingWindowLimit %4 OldestPendingMid %5 NextAvailableMid %6 CreditsGranted %7" />
        <string id="SmbObjectStateEventChannel" value="Microsoft-Windows-SMBClient/ObjectStateDiagnostic" />
        <string id="SmbOperationalEventChannel" value="Microsoft-Windows-SMBClient/Operational" />
        <string id="SmbPopulateDirCache" value="SMB populate dir cache: RxContext %1 Fcb %2 DirName %4" />
        <string id="SmbReceive" value="SMB receive: [%1] (Mid/Sid/Tid) (%2/%4/%5) Creds %6 Status %7 VcEndpoint %8" />
        <string id="SmbReceiveAsync" value="SMB receive async: [%1] (AsyncId/Sid/Tid) (%3/%4/%5) Creds %6 Status %7 VcEndpoint %8" />
        <string id="SmbReceiveInterim" value="SMB receive interim: [%1] (Mid/AsyncId/Sid/Tid) (%2/%3/%4/%5) Creds %6 Status %7 VcEndpoint %8" />
        <string id="SmbRechunkRequest" value="SMB rechunk multi-credit request: BufferCtxt %1 Exchange %2 MidCharge %3 Window %4 CurrentWindowLimit %5 ThrottlingWindowLimit %6 CurrentWindowSize %7" />
        <string id="SmbReconnect" value="SMB reconnect durable open: Fcb %1 SrvOpen %2" />
        <string id="SmbRegistryKey" value="SMB registry key: %1 = %2" />
        <string id="SmbResumeBufferCtxt" value="SMB buffer context resumed: BufferCtxt %1 Exchange %2 MidCharge %3 Window %4 CurrentWindowLimit %5 ThrottlingWindowLimit %6 CurrentWindowSize %7" />
        <string id="SmbResumeExchange" value="SMB exchange resumed: RxContext %1 Exchange %2 ExchangeState %3 ExchangeStatus %4" />
        <string id="SmbSecurityEventChannel" value="Microsoft-Windows-SMBClient/Security" />
        <string id="SmbSend" value="SMB send[%1]: [%2] (Mid/Sid/Tid) (%3/%4/%5) MidCharge %6 Creds %7 SendLengh %8 VcEndpoint %9" />
        <string id="SmbSendCompletion" value="SMB send completion: Status %1 VcEndpoint %2" />
        <string id="SmbSessionExpired" value="SMB session expired: SessionEntry %1 ServerName %3" />
        <string id="SmbSuspendBufferCtxt" value="SMB buffer context suspended: BufferCtxt %1 Exchange %2 MidCharge %3 Window %4 CurrentWindowLimit %5 ThrottlingWindowLimit %6 CurrentWindowSize %7" />
        <string id="SmbSuspendExchange" value="SMB exchange suspended: RxContext %1 Exchange %2 ListHead %3" />
        <string id="SmbTeardownMidWindow" value="SMB teardown Mid window: Server %2 Window %3" />
        <string id="SmbUndeferOpen" value="SMB undefer open: Fcb %1 SrvOpen %2" />
        <string id="SmbUpdateFNFCache" value="SMB update file not found cache: RxContext %1 Fcb %2 FileName %4" />
        <string id="SmbUpdateInfoCache" value="SMB update file info cache: RxContext %1 Fcb %2 FileName %4" />
        <string id="SmbXPerfEventChannel" value="Microsoft-Windows-SMBClient/XPerfAnalytic" />
        <string id="TcpIpTransportArrival" value="Added a TCP/IP transport interface.%n%nName: %2%nInterfaceIndex: %3%n%nGuidance:%nA TCP/IP binding was added to the specified network adapter for the SMB client. The SMB client can now send and receive SMB traffic on this network adapter using TCP/IP. You should expect this event when a computer restarts or when a previously disabled network adaptor is re-enabled. No user action is required." />
        <string id="TcpIpTransportRemoval" value="Deleted a TCP/IP transport interface.%n%nName: %2%nInterfaceIndex: %3%n%nGuidance:%nA TCP/IP binding was removed from the specified network adapter for the SMB client. You should expect this event when a computer shuts down or when a previously enabled network adaptor is disabled. No user action is required." />
        <string id="TdiTransportArrival" value="Added a TDI transport interface.%n%nName: %2%n%nGuidance:%nA TDI (NetBIOS) binding was added to the specified network adapter for the SMB client. The SMB client can now send and receive SMB traffic on this network adapter using TDI. You should expect this event when a computer restarts or when a previously disabled network adaptor is re-enabled. No user action is required." />
        <string id="TdiTransportRemoval" value="Deleted a TDI transport interface.%n%nName: %2%n%nGuidance:%nA TDI (NetBIOS) binding was removed from the specified network adapter for the SMB client. You should expect this event when a computer shuts down or when a previously enabled network adaptor is disabled. No user action is required." />
        <string id="TreeConnectFailure" value="The SMB client failed to connect to the share.%n%nError: %2%n%nPath: %4%6" />
        <string id="UT.opcodeEnd" value="End State" />
        <string id="UT.opcodeStart" value="Start State" />
        <string id="VNetRootStateTransition" value="Share connection %1 to %6 transitioned from [%2] to [%3] with Status %4" />
        <string id="WitnessDeregistration" value="Witness deregistration has completed.%n%nStatus: %1%n%nCluster share name: %4%nCluster share type: %2%n%nGuidance:%nThe client successfully de-registered with the SMB Witness through RPC using TCP (port 135, then an endpoint port above 1023). No action is required." />
        <string id="WitnessRegistration" value="Witness registration has completed.%n%nStatus: %1%n%nCluster share name: %4%nCluster share type: %2%nFile server cluster address: %6%n%nGuidance:%nThe client successfully registered with the SMB Witness through RPC using TCP (port 135, then an endpoint port above 1023). No action is required." />
        <string id="WskConnectFailure" value="The client failed to connect to the server %2 from the local IP address %4 to the remote IP address %6 over TCP transport. Error: %7" />
        <string id="WskConnectSuccess" value="The client connected to the server %2 from the local IP address %4 to the remote IP address %6 over TCP transport successfully" />
        <string id="WskGetAddressInfoFailure" value="The server name cannot be resolved.%n%nError: %2%n%nServer name: %4%n%nGuidance:%nThe client cannot resolve the server address in DNS or WINS. This issue often manifests immediately after joining a computer to the domain, when the client's DNS registration may not yet have propagated to all DNS servers. You should also expect this event at system startup on a DNS server (such as a domain controller) that points to itself for the primary DNS. You should validate the DNS client settings on this computer using IPCONFIG /ALL and NSLOOKUP." />
      </stringTable>
    </resources>
  </localization>
  <instrumentation>
    <events xmlns="http://schemas.microsoft.com/win/2004/08/events">
      <provider guid="{988c59c5-0a1c-45b6-a555-0c62276e327d}" message="$(string.EventProviderName)" messageFileName="%windir%\system32\drivers\mrxsmb.sys" name="Microsoft-Windows-SMBClient" resourceFileName="%windir%\system32\drivers\mrxsmb.sys" symbol="REMOTEFS_SMB">
        <channels>
          <channel chid="SmbHelperClassEventChannel" enabled="false" message="$(string.SmbHelperClassEventChannel)" name="Microsoft-Windows-SMBClient/HelperClassDiagnostic" symbol="CHANNEL_HC" type="Analytic" />
          <channel chid="SmbObjectStateEventChannel" enabled="false" message="$(string.SmbObjectStateEventChannel)" name="Microsoft-Windows-SMBClient/ObjectStateDiagnostic" symbol="ObjectState" type="Debug">
            <logging>
              <retention>false</retention>
              <maxSize>536870912</maxSize>
            </logging>
            <publishing>
              <bufferSize>65536</bufferSize>
              <clockType>QPC</clockType>
            </publishing>
          </channel>
          <channel access="O:BAG:SYD:(A;;0x5;;;BA)" chid="SmbOperationalEventChannel" enabled="true" isolation="System" message="$(string.SmbOperationalEventChannel)" name="Microsoft-Windows-SMBClient/Operational" symbol="Smb_Operational" type="Operational">
            <logging>
              <maxSize>8388608</maxSize>
            </logging>
          </channel>
          <channel access="O:BAG:SYD:(D;;0xf0007;;;AN)(D;;0xf0007;;;BG)(A;;0x7;;;SY)(A;;0x7;;;BA)(A;;0x2;;;WD)" chid="SmbXPerfEventChannel" isolation="Custom" message="$(string.SmbXPerfEventChannel)" name="Microsoft-Windows-SMBClient/Analytic" type="Analytic" />
          <channel chid="SmbPacketCapture" enabled="false" isolation="System" message="$(string.eventChannelName_Diagnostic)" name="Microsoft-Windows-SmbClient/Diagnostic" type="Analytic" />
          <channel access="O:BAG:SYD:(A;;0x5;;;BA)" chid="SmbConnectivityEventChannel" enabled="true" isolation="System" message="$(string.SmbConnectivityEventChannel)" name="Microsoft-Windows-SmbClient/Connectivity" type="Operational">
            <logging>
              <maxSize>8388608</maxSize>
            </logging>
          </channel>
          <channel access="O:BAG:SYD:(A;;0x5;;;BA)" chid="SmbSecurityEventChannel" enabled="true" isolation="System" message="$(string.SmbSecurityEventChannel)" name="Microsoft-Windows-SmbClient/Security" type="Operational">
            <logging>
              <maxSize>8388608</maxSize>
            </logging>
          </channel>
        </channels>
        <opcodes>
          <opcode message="$(string.opcodeServer)" name="Server" symbol="RXUT_SERVER_ERROR" value="11">Marks events generated based on server returned failures.</opcode>
          <opcode message="$(string.opcodeCache)" name="Cache" symbol="RXUT_CACHED_ERROR" value="12">Marks events generated based on data in the cache.</opcode>
          <opcode message="$(string.opcodeISC)" name="ISC" symbol="RXUT_ISC_ERROR" value="13">Marks events generated when InitializeSecurityContext fails.</opcode>
          <opcode message="$(string.opcodeSigning)" name="Signing" symbol="RXUT_SIGNING_ERROR" value="14">Marks events generated when problem is related to Security Signatures.</opcode>
          <opcode message="$(string.UT.opcodeStart)" name="ut:Start" symbol="STATE_START" value="180">Marks events generated when connection is currently not open and component is in a logical start state.</opcode>
          <opcode message="$(string.UT.opcodeEnd)" name="ut:End" symbol="STATE_END" value="181">Marks events generated when connection is currently not open and component is in a logical end state.</opcode>
        </opcodes>
        <keywords>
          <keyword mask="0x0000400000000000" name="ut:Diagnostic" symbol="KW_DIAGNOSTIC" />
          <keyword mask="0x1" name="Smb_Perf" symbol="SMB_PERF" />
          <keyword mask="0x2" name="Networking_Perf" symbol="NETWORKING_PERF" />
          <keyword mask="0x4" name="Smb_Info" symbol="SMB_INFO" />
          <keyword mask="0x8" name="InfoCache_Info" symbol="INFOCACHE_INFO" />
          <keyword mask="0x10" name="Smb_TFO" symbol="SMB_TFO" />
          <keyword mask="0x20" name="Smb_MultiChannel" symbol="SMB_MULTICHANNEL" />
          <keyword mask="0x40" name="Smb_Connectivity" symbol="SMB_CONNECTIVITY" />
          <keyword mask="0x80" name="Smb_Authentication" symbol="SMB_AUTHENTICATION" />
          <keyword mask="0x100" name="Smb_Authorization" symbol="SMB_AUTHORIZATION" />
          <keyword mask="0x200" name="Smb_Security" symbol="SMB_SECURITY" />
          <keyword mask="0x0000000040000000" name="PacketStart" symbol="KW_PACKET_START" />
          <keyword mask="0x0000000080000000" name="PacketEnd" symbol="KW_PACKET_END" />
          <keyword mask="0x0000000100000000" name="ut:SendPath" symbol="KW_SEND" />
          <keyword mask="0x0000000200000000" name="ut:ReceivePath" symbol="KW_RECEIVE" />
          <keyword mask="0x0000040000000000" name="ut:Packet" symbol="KW_PACKET" />
          <keyword mask="0x0000800000000000" name="PduFull" symbol="KW_PDU_FULL" />
        </keywords>
        <templates>
          <template tid="tidNetError">
            <data inType="win:UInt32" name="ErrorCode" outType="win:ErrorCode" />
            <data inType="win:UInt32" name="Location" outType="xs:unsignedInt" />
            <data inType="win:UInt32" name="Context" outType="xs:unsignedInt" />
          </template>
          <template tid="tidStateTransition">
            <data inType="win:UInt8" map="ut:OpcodeMap" name="CurrentOrNextState" outType="xs:unsignedByte" />
            <data inType="win:UInt32" name="Context" outType="xs:unsignedInt" />
          </template>
          <template tid="SmbRegistryKey">
            <data inType="win:UnicodeString" name="RegName" />
            <data inType="win:UInt32" name="RegValue" />
          </template>
          <template tid="SmbISCRequest">
            <data inType="win:Pointer" name="SessionEntry" />
            <data inType="win:UInt16" name="ServerNameLength" />
            <data inType="win:UnicodeString" length="ServerNameLength" name="ServerName" />
          </template>
          <template tid="SmbSuspendExchange">
            <data inType="win:Pointer" name="RxContext" />
            <data inType="win:Pointer" name="Exchange" />
            <data inType="win:Pointer" name="ListHead" />
          </template>
          <template tid="SmbResumeExchange">
            <data inType="win:Pointer" name="RxContext" />
            <data inType="win:Pointer" name="Exchange" />
            <data inType="win:UInt32" name="ExchangeState" />
            <data inType="win:UInt32" name="ExchangeStatus" />
          </template>
          <template tid="SmbSuspendBufferCtxt">
            <data inType="win:Pointer" name="BufferCtxt" />
            <data inType="win:Pointer" name="Exchange" />
            <data inType="win:UInt32" name="MidCharge" />
            <data inType="win:Pointer" name="Window" />
            <data inType="win:UInt32" name="CurrentWindowLimit" />
            <data inType="win:UInt32" name="ThrottlingWindowLimit" />
            <data inType="win:UInt32" name="CurrentWindowSize" />
          </template>
          <template tid="SmbMidWindow">
            <data inType="win:UInt16" name="ServerNameLength" />
            <data inType="win:UnicodeString" length="ServerNameLength" name="ServerName" />
            <data inType="win:Pointer" name="MidWindow" />
          </template>
          <template tid="SmbMidWindowState">
            <data inType="win:Pointer" name="MidWindow" />
            <data inType="win:UInt32" name="CurrentWindowSize" />
            <data inType="win:UInt32" name="CurrentWindowLimit" />
            <data inType="win:UInt32" name="ThrottlingWindowLimit" />
            <data inType="win:UInt64" name="OldestPendingMid" />
            <data inType="win:UInt64" name="NextAvailableMid" />
            <data inType="win:Int32" name="CreditsGranted" />
          </template>
          <template tid="SmbMidWindowBlocked">
            <data inType="win:Pointer" name="Window" />
            <data inType="win:UInt32" name="HungSession" />
          </template>
          <template tid="SmbReconnect">
            <data inType="win:Pointer" name="Fcb" />
            <data inType="win:Pointer" name="SrvOpen" />
          </template>
          <template tid="SmbInfoCache">
            <data inType="win:Pointer" name="RxContext" />
            <data inType="win:Pointer" name="Fcb" />
            <data inType="win:UInt16" name="FileNameLength" />
            <data inType="win:UnicodeString" length="FileNameLength" name="FileName" />
            <data inType="win:UInt32" name="Status" />
          </template>
          <template tid="SmbSend">
            <data inType="win:UInt32" name="Count" />
            <data inType="win:AnsiString" name="Command" />
            <data inType="win:UInt64" name="MessageId" />
            <data inType="win:UInt64" name="SessionId" />
            <data inType="win:UInt32" name="TreeId" />
            <data inType="win:UInt16" name="MidCharge" />
            <data inType="win:UInt16" name="CreditRequested" />
            <data inType="win:UInt32" name="SendLength" />
            <data inType="win:Pointer" name="VcEndpoint" />
          </template>
          <template tid="SmbReceive">
            <data inType="win:AnsiString" name="Command" />
            <data inType="win:UInt64" name="MessageId" />
            <data inType="win:UInt64" name="AsyncId" />
            <data inType="win:UInt64" name="SessionId" />
            <data inType="win:UInt32" name="TreeId" />
            <data inType="win:UInt16" name="CreditGranted" />
            <data inType="win:UInt32" name="Status" />
            <data inType="win:Pointer" name="VcEndpoint" />
          </template>
          <template tid="SmbSendCompletion">
            <data inType="win:UInt32" name="Status" />
            <data inType="win:Pointer" name="VcEndpoint" />
          </template>
          <template tid="NetConnect">
            <data inType="win:UInt32" name="RemoteAddressLength" />
            <data inType="win:Binary" length="RemoteAddressLength" name="RemoteAddress" outType="win:SocketAddress" />
            <data inType="win:Pointer" name="VcEndpoint" />
            <data inType="win:Pointer" name="Socket" />
          </template>
          <template tid="NetConnectCompletion">
            <data inType="win:Pointer" name="VcEndpoint" />
            <data inType="win:Pointer" name="Socket" />
            <data inType="win:UInt32" name="Status" />
          </template>
          <template tid="NetSend">
            <data inType="win:Pointer" name="VcEndpoint" />
            <data inType="win:Pointer" name="Socket" />
            <data inType="win:Pointer" name="SendMdl" />
            <data inType="win:UInt32" name="SendLength" />
          </template>
          <template tid="NetSendCompletion">
            <data inType="win:Pointer" name="VcEndpoint" />
            <data inType="win:Pointer" name="Socket" />
            <data inType="win:Pointer" name="SendMdl" />
            <data inType="win:UInt32" name="SendLength" />
            <data inType="win:UInt32" name="Status" />
          </template>
          <template tid="WitnessEvent">
            <data inType="win:UInt32" name="Status" outType="win:NTSTATUS" />
            <data inType="win:UInt8" map="ShareTypeMap" name="ShareType" />
            <data inType="win:UInt16" name="NameLength" />
            <data inType="win:UnicodeString" length="NameLength" name="Name" />
            <data inType="win:UInt32" name="RemoteAddressLength" />
            <data inType="win:Binary" length="RemoteAddressLength" name="RemoteAddress" outType="win:SocketAddress" />
          </template>
          <template tid="ObjectStateTransition">
            <data inType="win:Pointer" name="Object" />
            <data inType="win:UInt16" map="Smb2ObjectStateMap" name="OldState" />
            <data inType="win:UInt16" map="Smb2ObjectStateMap" name="NewState" />
            <data inType="win:UInt32" name="Status" outType="win:HexInt32" />
            <data inType="win:UInt16" name="NameLength" />
            <data inType="win:UnicodeString" length="NameLength" name="ObjectName" />
          </template>
          <template tid="HandleStateTransition">
            <data inType="win:Pointer" name="Object" />
            <data inType="win:UInt64" name="PersistentFID" outType="win:HexInt64" />
            <data inType="win:UInt64" name="VolatileFID" outType="win:HexInt64" />
            <data inType="win:GUID" name="CreateGUID" />
            <data inType="win:UInt16" map="Smb2ObjectStateMap" name="OldState" />
            <data inType="win:UInt16" map="Smb2ObjectStateMap" name="NewState" />
            <data inType="win:UInt32" name="Status" outType="win:NTSTATUS" />
            <data inType="win:UInt32" map="Smb2DiagReasonMap" name="Reason" />
            <data inType="win:UInt16" name="ShareNameLength" />
            <data inType="win:UnicodeString" length="ShareNameLength" name="ShareName" />
            <data inType="win:UInt16" name="ObjectNameLength" />
            <data inType="win:UnicodeString" length="ObjectNameLength" name="ObjectName" />
            <data inType="win:UInt32" name="PreviousStatus" outType="win:NTSTATUS" />
            <data inType="win:UInt32" map="Smb2DiagReasonMap" name="PreviousReason" />
          </template>
          <template tid="UserNameAndServerName">
            <data inType="win:UInt16" name="UserNameLength" />
            <data inType="win:UnicodeString" length="UserNameLength" name="UserName" />
            <data inType="win:UInt16" name="ServerNameLength" />
            <data inType="win:UnicodeString" length="ServerNameLength" name="ServerName" />
          </template>
          <template tid="ServerName">
            <data inType="win:UInt16" name="ServerNameLength" />
            <data inType="win:UnicodeString" length="ServerNameLength" name="ServerName" />
          </template>
          <template tid="ConnectStatus">
            <data inType="win:UInt16" name="ServerNameLength" />
            <data inType="win:UnicodeString" length="ServerNameLength" name="ServerName" />
            <data inType="win:UInt32" name="LocalAddressLength" />
            <data inType="win:Binary" length="LocalAddressLength" name="LocalAddress" outType="win:SocketAddress" />
            <data inType="win:UInt32" name="RemoteAddressLength" />
            <data inType="win:Binary" length="RemoteAddressLength" name="RemoteAddress" outType="win:SocketAddress" />
            <data inType="win:UInt32" name="Status" outType="win:NTSTATUS" />
          </template>
          <template tid="tidPacketFragment">
            <data inType="win:UInt16" name="ReassembledEventID" outType="xs:unsignedShort" />
            <data inType="win:UInt32" name="FragmentSize" outType="xs:unsignedInt" />
            <data inType="win:Binary" length="FragmentSize" name="FragmentData" outType="xs:hexBinary" />
          </template>
          <template tid="tidPacket">
            <data inType="win:UInt32" map="ConnectionTypeMap" name="ConnectionType" />
            <data inType="win:UInt32" name="PeerAddressLength" />
            <data inType="win:Binary" length="PeerAddressLength" name="PeerAddress" outType="win:SocketAddress" />
            <data inType="win:UInt32" name="PacketSize" outType="xs:unsignedInt" />
            <data inType="win:Binary" length="PacketSize" name="PacketData" outType="xs:hexBinary" />
          </template>
          <template tid="Reason_Status_ServerName">
            <data inType="win:UInt32" map="Smb2DiagReasonMap" name="Reason" />
            <data inType="win:UInt32" name="Status" outType="win:NTSTATUS" />
            <data inType="win:UInt16" name="ServerNameLength" />
            <data inType="win:UnicodeString" length="ServerNameLength" name="ServerName" />
          </template>
          <template tid="Reason_Status_Path">
            <data inType="win:UInt32" map="Smb2DiagReasonMap" name="Reason" />
            <data inType="win:UInt32" name="Status" outType="win:NTSTATUS" />
            <data inType="win:UInt16" name="ShareNameLength" />
            <data inType="win:UnicodeString" length="ShareNameLength" name="ShareName" />
            <data inType="win:UInt16" name="ObjectNameLength" />
            <data inType="win:UnicodeString" length="ObjectNameLength" name="ObjectName" />
          </template>
          <template tid="Reason_Status_ServerName_Address">
            <data inType="win:UInt32" map="Smb2DiagReasonMap" name="Reason" />
            <data inType="win:UInt32" name="Status" outType="win:NTSTATUS" />
            <data inType="win:UInt16" name="ServerNameLength" />
            <data inType="win:UnicodeString" length="ServerNameLength" name="ServerName" />
            <data inType="win:UInt32" name="AddressLength" />
            <data inType="win:Binary" length="AddressLength" name="Address" outType="win:SocketAddress" />
            <data inType="win:UInt32" map="ConnectionTypeMap" name="ConnectionType" />
          </template>
          <template tid="ExchangeInfo">
            <data inType="win:UInt16" map="Smb2CommandMap" name="Smb2Command" />
            <data inType="win:UInt64" name="MessageId" outType="win:HexInt64" />
            <data inType="win:UInt64" name="SessionId" outType="win:HexInt64" />
            <data inType="win:UInt32" name="TreeId" outType="win:HexInt32" />
            <data inType="win:UInt16" name="ServerNameLength" />
            <data inType="win:UnicodeString" length="ServerNameLength" name="ServerName" />
            <data inType="win:UInt32" name="Status" outType="win:NTSTATUS" />
          </template>
          <template tid="TcpIpTransport">
            <data inType="win:UInt16" name="NameLength" />
            <data inType="win:UnicodeString" length="NameLength" name="Name" />
            <data inType="win:UInt32" name="IfIndex" outType="win:HexInt32" />
          </template>
          <template tid="NegotiateValidation">
            <data inType="win:UInt16" name="Dialect" outType="win:HexInt16" />
            <data inType="win:UInt16" name="SecurityMode" outType="win:HexInt16" />
            <data inType="win:UInt32" name="Capabilities" outType="win:HexInt32" />
            <data inType="win:GUID" name="Guid" />
            <data inType="win:UInt16" name="Dialect2" outType="win:HexInt16" />
            <data inType="win:UInt16" name="SecurityMode2" outType="win:HexInt16" />
            <data inType="win:UInt32" name="Capabilities2" outType="win:HexInt32" />
            <data inType="win:GUID" name="Guid2" />
          </template>
          <template tid="RequestRetryInfo">
            <data inType="win:UInt8" map="IrpCodeMap" name="IrpCode" />
            <data inType="win:UInt32" name="RestartCount" />
            <data inType="win:UInt16" name="ShareNameLength" />
            <data inType="win:UnicodeString" length="ShareNameLength" name="ShareName" />
            <data inType="win:UInt16" name="ObjectNameLength" />
            <data inType="win:UnicodeString" length="ObjectNameLength" name="ObjectName" />
            <data inType="win:UInt32" name="Status" outType="win:NTSTATUS" />
          </template>
          <template tid="ShareConnect">
            <data inType="win:UInt32" name="Status" outType="win:NTSTATUS" />
            <data inType="win:UInt64" name="SessionId" outType="win:HexInt64" />
            <data inType="win:UInt32" name="TreeId" outType="win:HexInt32" />
            <data inType="win:UInt16" name="ServerNameLength" />
            <data inType="win:UnicodeString" length="ServerNameLength" name="ServerName" />
            <data inType="win:UInt32" name="AddressLength" />
            <data inType="win:Binary" length="AddressLength" name="Address" outType="win:SocketAddress" />
          </template>
          <template tid="AuthenticationCall">
            <data inType="win:UInt32" map="Smb2DiagReasonMap" name="Reason" />
            <data inType="win:UInt32" name="Status" outType="win:NTSTATUS" />
            <data inType="win:UInt32" name="SecurityStatus" outType="win:HexInt32" />
            <data inType="win:UInt64" name="LogonId" outType="win:HexInt64" />
            <data inType="win:UInt16" name="ServerNameLength" />
            <data inType="win:UnicodeString" length="ServerNameLength" name="ServerName" />
            <data inType="win:UInt16" name="PrincipalNameLength" />
            <data inType="win:UnicodeString" length="PrincipalNameLength" name="PrincipalName" />
            <data inType="win:UInt16" name="UserNameLength" />
            <data inType="win:UnicodeString" length="UserNameLength" name="UserName" />
          </template>
          <template tid="CipherSuiteOrder">
            <data inType="win:UnicodeString" name="CipherSuiteOrder" />
          </template>
          <template tid="NullTemplate" />
        </templates>
        <events>
          <event channel="SmbHelperClassEventChannel" keywords="ut:Diagnostic" level="win:Error" message="$(string.evtCreateSrvCallError)" opcode="win:Info" symbol="CreateSrvCallError" template="tidNetError" value="101" />
          <event channel="SmbHelperClassEventChannel" keywords="ut:Diagnostic" level="win:Error" message="$(string.evtSessionSetupError)" opcode="win:Info" symbol="SessionSetupError" template="tidNetError" value="201" />
          <event channel="SmbHelperClassEventChannel" keywords="ut:Diagnostic" level="win:Error" message="$(string.evtTreeConnectError)" opcode="win:Info" symbol="TreeConnectError" template="tidNetError" value="301" />
          <event channel="SmbHelperClassEventChannel" keywords="ut:Diagnostic" level="win:Error" message="$(string.evtCreateVNetRootError)" opcode="win:Info" symbol="CreateVNetRootError" template="tidNetError" value="401" />
          <event channel="SmbHelperClassEventChannel" keywords="ut:Diagnostic" level="win:Error" message="$(string.evtCreateFileError)" opcode="win:Info" symbol="CreateFileError" template="tidNetError" value="501" />
          <event channel="SmbHelperClassEventChannel" keywords="ut:Diagnostic" level="win:Informational" message="$(string.evtCreateFile)" opcode="win:Info" symbol="CreateFile" template="tidStateTransition" value="20001" />
          <event channel="SmbXPerfEventChannel" keywords="Smb_Perf" level="win:Verbose" message="$(string.SmbSuspendExchange)" opcode="win:Info" symbol="SmbSuspendExchange" template="SmbSuspendExchange" value="30103" />
          <event channel="SmbXPerfEventChannel" keywords="Smb_Perf" level="win:Verbose" message="$(string.SmbResumeExchange)" opcode="win:Info" symbol="SmbResumeExchange" template="SmbResumeExchange" value="30104" />
          <event channel="SmbXPerfEventChannel" keywords="Smb_Perf" level="win:Verbose" message="$(string.SmbSuspendBufferCtxt)" opcode="win:Info" symbol="SmbSuspendBufferCtxt" template="SmbSuspendBufferCtxt" value="30105" />
          <event channel="SmbXPerfEventChannel" keywords="Smb_Perf" level="win:Verbose" message="$(string.SmbResumeBufferCtxt)" opcode="win:Info" symbol="SmbResumeBufferCtxt" template="SmbSuspendBufferCtxt" value="30106" />
          <event channel="SmbXPerfEventChannel" keywords="Smb_Perf Smb_Info" level="win:Error" message="$(string.SmbMidWindowBlocked)" opcode="win:Info" symbol="SmbMidWindowBlocked" template="SmbMidWindowBlocked" value="30108" />
          <event channel="SmbXPerfEventChannel" keywords="Smb_Perf Smb_Info" level="win:Error" message="$(string.SmbRechunkRequest)" opcode="win:Info" symbol="SmbRechunkRequest" template="SmbSuspendBufferCtxt" value="30109" />
          <event channel="SmbXPerfEventChannel" keywords="Smb_Perf" level="win:Verbose" message="$(string.SmbInitializeMidWindow)" opcode="win:Info" symbol="SmbInitializeMidWindow" template="SmbMidWindow" value="30110" />
          <event channel="SmbXPerfEventChannel" keywords="Smb_Perf" level="win:Verbose" message="$(string.SmbMidWindowState)" opcode="win:Info" symbol="SmbMidWindowState" template="SmbMidWindowState" value="30111" />
          <event channel="SmbXPerfEventChannel" keywords="Smb_Perf" level="win:Verbose" message="$(string.SmbTeardownMidWindow)" opcode="win:Info" symbol="SmbTeardownMidWindow" template="SmbMidWindow" value="30112" />
          <event channel="SmbXPerfEventChannel" keywords="Smb_Perf" level="win:Verbose" message="$(string.SmbDataReady)" opcode="win:Info" symbol="SmbDataReady" template="SmbSendCompletion" value="30113" />
          <event channel="SmbXPerfEventChannel" keywords="Smb_Perf" level="win:Verbose" message="$(string.SmbSendCompletion)" opcode="win:Info" symbol="SmbSendCompletion" template="SmbSendCompletion" value="30114" />
          <event channel="SmbXPerfEventChannel" keywords="Networking_Perf" level="win:Informational" message="$(string.NetConnect)" opcode="win:Info" symbol="NetConnect" template="NetConnect" value="30203" />
          <event channel="SmbXPerfEventChannel" keywords="Networking_Perf" level="win:Informational" message="$(string.NetConnectCompletion)" opcode="win:Info" symbol="NetConnectCompletion" template="NetConnectCompletion" value="30204" />
          <event channel="SmbXPerfEventChannel" keywords="Networking_Perf" level="win:Verbose" message="$(string.NetSend)" opcode="win:Info" symbol="NetSend" template="NetSend" value="30205" />
          <event channel="SmbXPerfEventChannel" keywords="Networking_Perf" level="win:Verbose" message="$(string.NetSendCompletion)" opcode="win:Info" symbol="NetSendCompletion" template="NetSendCompletion" value="30206" />
          <event channel="SmbXPerfEventChannel" keywords="Networking_Perf" level="win:Verbose" message="$(string.NetReceive)" opcode="win:Info" symbol="NetReceive" template="NetSend" value="30207" />
          <event channel="SmbXPerfEventChannel" keywords="Networking_Perf" level="win:Verbose" message="$(string.NetReceiveCompletion)" opcode="win:Info" symbol="NetReceiveCompletion" template="NetSendCompletion" value="30208" />
          <event channel="SmbXPerfEventChannel" keywords="Smb_Info" level="win:Error" message="$(string.SmbSessionExpired)" opcode="win:Info" symbol="SmbSessionExpired" template="SmbISCRequest" value="30401" />
          <event channel="SmbXPerfEventChannel" keywords="Smb_Info" level="win:Error" message="$(string.Smb3PartSPNReauth)" opcode="win:Info" symbol="Smb3PartSPNReauth" template="SmbISCRequest" value="30402" />
          <event channel="SmbXPerfEventChannel" keywords="Smb_Info" level="win:Informational" message="$(string.SmbReconnect)" opcode="win:Info" symbol="SmbReconnect" template="SmbReconnect" value="30403" />
          <event channel="SmbXPerfEventChannel" keywords="Smb_Info" level="win:Informational" message="$(string.SmbDeferOpen)" opcode="win:Info" symbol="SmbDeferOpen" template="SmbReconnect" value="30404" />
          <event channel="SmbXPerfEventChannel" keywords="Smb_Info" level="win:Informational" message="$(string.SmbUndeferOpen)" opcode="win:Info" symbol="SmbUndeferOpen" template="SmbReconnect" value="30405" />
          <event channel="SmbXPerfEventChannel" keywords="Smb_Info" level="win:Informational" message="$(string.SmbSend)" opcode="win:Info" symbol="SmbSend" template="SmbSend" value="30406" />
          <event channel="SmbXPerfEventChannel" keywords="Smb_Info" level="win:Informational" message="$(string.SmbReceive)" opcode="win:Info" symbol="SmbReceive" template="SmbReceive" value="30407" />
          <event channel="SmbXPerfEventChannel" keywords="Smb_Info" level="win:Informational" message="$(string.SmbReceiveInterim)" opcode="win:Info" symbol="SmbReceiveInterim" template="SmbReceive" value="30408" />
          <event channel="SmbXPerfEventChannel" keywords="Smb_Info" level="win:Informational" message="$(string.SmbReceiveAsync)" opcode="win:Info" symbol="SmbReceiveAsync" template="SmbReceive" value="30409" />
          <event channel="SmbXPerfEventChannel" keywords="Smb_Info" level="win:Informational" message="$(string.SmbRegistryKey)" opcode="win:Info" symbol="SmbRegistryKey" template="SmbRegistryKey" value="30410" />
          <event channel="SmbXPerfEventChannel" keywords="InfoCache_Info" level="win:Verbose" message="$(string.SmbUpdateInfoCache)" opcode="win:Info" symbol="SmbUpdateInfoCache" template="SmbInfoCache" value="30501" />
          <event channel="SmbXPerfEventChannel" keywords="InfoCache_Info" level="win:Verbose" message="$(string.SmbFetchInfoCache)" opcode="win:Info" symbol="SmbFetchInfoCache" template="SmbInfoCache" value="30502" />
          <event channel="SmbXPerfEventChannel" keywords="InfoCache_Info" level="win:Verbose" message="$(string.SmbInvalidateInfoCache)" opcode="win:Info" symbol="SmbInvalidateInfoCache" template="SmbInfoCache" value="30503" />
          <event channel="SmbXPerfEventChannel" keywords="InfoCache_Info" level="win:Verbose" message="$(string.SmbUpdateFNFCache)" opcode="win:Info" symbol="SmbUpdateFNFCache" template="SmbInfoCache" value="30504" />
          <event channel="SmbXPerfEventChannel" keywords="InfoCache_Info" level="win:Verbose" message="$(string.SmbFetchFNFCache)" opcode="win:Info" symbol="SmbFetchFNFCache" template="SmbInfoCache" value="30505" />
          <event channel="SmbXPerfEventChannel" keywords="InfoCache_Info" level="win:Verbose" message="$(string.SmbInvalidateFNFCache)" opcode="win:Info" symbol="SmbInvalidateFNFCache" template="SmbInfoCache" value="30506" />
          <event channel="SmbXPerfEventChannel" keywords="InfoCache_Info" level="win:Verbose" message="$(string.SmbPopulateDirCache)" opcode="win:Info" symbol="SmbPopulateDirCache" template="SmbInfoCache" value="30507" />
          <event channel="SmbXPerfEventChannel" keywords="InfoCache_Info" level="win:Verbose" message="$(string.SmbFetchDirCache)" opcode="win:Info" symbol="SmbFetchDirCache" template="SmbInfoCache" value="30508" />
          <event channel="SmbObjectStateEventChannel" keywords="Smb_TFO" level="win:Informational" message="$(string.SessionStateTransition)" symbol="SessionStateTransition" template="ObjectStateTransition" value="30600" />
          <event channel="SmbObjectStateEventChannel" keywords="Smb_TFO" level="win:Informational" message="$(string.VNetRootStateTransition)" symbol="VNetRootStateTransition" template="ObjectStateTransition" value="30601" />
          <event channel="SmbObjectStateEventChannel" keywords="Smb_TFO" level="win:Informational" message="$(string.OpenHandleStateTransition)" symbol="OpenHandleStateTransition" template="HandleStateTransition" value="30603" />
          <event channel="SmbOperationalEventChannel" keywords="Smb_TFO" level="win:Error" message="$(string.PersistentHandleFailure)" symbol="PersistentHandleFailure" template="HandleStateTransition" value="30611" version="2" />
          <event channel="SmbOperationalEventChannel" keywords="Smb_TFO" level="win:Error" message="$(string.ResilientHandleFailure)" symbol="ResilientHandleFailure" template="HandleStateTransition" value="30612" version="2" />
          <event channel="SmbOperationalEventChannel" keywords="Smb_TFO" level="win:Error" message="$(string.HandleOpenFailure)" symbol="HandleOpenFailure" template="HandleStateTransition" value="30613" />
          <event channel="SmbObjectStateEventChannel" keywords="Smb_MultiChannel" level="win:Warning" message="$(string.ServerNetworkInterfaceInvalid)" symbol="ServerNetworkInterfaceInvalid" template="ServerName" value="30701" />
          <event channel="SmbObjectStateEventChannel" keywords="Smb_MultiChannel" level="win:Warning" message="$(string.WskConnectFailure)" symbol="WskConnectFailure" template="ConnectStatus" value="30702" />
          <event channel="SmbObjectStateEventChannel" keywords="Smb_MultiChannel" level="win:Warning" message="$(string.RdmaConnectFailure)" symbol="RdmaConnectFailure" template="ConnectStatus" value="30703" />
          <event channel="SmbObjectStateEventChannel" keywords="Smb_MultiChannel" level="win:Informational" message="$(string.WskConnectSuccess)" symbol="WskConnectSuccess" template="ConnectStatus" value="30704" />
          <event channel="SmbObjectStateEventChannel" keywords="Smb_MultiChannel" level="win:Informational" message="$(string.RdmaConnectSuccess)" symbol="RdmaConnectSuccess" template="ConnectStatus" value="30705" />
          <event channel="SmbConnectivityEventChannel" keywords="Smb_Connectivity" level="win:Error" message="$(string.WskGetAddressInfoFailure)" symbol="WskGetAddressInfoFailure" template="Reason_Status_ServerName" value="30800" />
          <event channel="SmbConnectivityEventChannel" keywords="Smb_Connectivity" level="win:Error" message="$(string.Reason_Status_ServerName)" symbol="SetSocketSecurityFailure" template="Reason_Status_ServerName" value="30801" />
          <event channel="SmbConnectivityEventChannel" keywords="Smb_Connectivity" level="win:Error" message="$(string.Reason_Status_ServerName)" symbol="IPSecFailure" template="Reason_Status_ServerName" value="30802" />
          <event channel="SmbConnectivityEventChannel" keywords="Smb_Connectivity" level="win:Error" message="$(string.NetworkConnectFailure)" symbol="NetworkConnectFailure" template="Reason_Status_ServerName_Address" value="30803" />
          <event channel="SmbConnectivityEventChannel" keywords="Smb_Connectivity" level="win:Error" message="$(string.DisconnectIndication)" symbol="DisconnectIndication" template="Reason_Status_ServerName_Address" value="30804" />
          <event channel="SmbConnectivityEventChannel" keywords="Smb_Connectivity" level="win:Warning" message="$(string.SessionFailure)" symbol="SessionFailure" template="ShareConnect" value="30805" version="2" />
          <event channel="SmbConnectivityEventChannel" keywords="Smb_Connectivity" level="win:Informational" message="$(string.SessionEstablished)" symbol="SessionEstablished" template="ShareConnect" value="30806" version="2" />
          <event channel="SmbConnectivityEventChannel" keywords="Smb_Connectivity" level="win:Warning" message="$(string.ShareConnectionFailure)" symbol="ShareConnectionFailure" template="ShareConnect" value="30807" version="2" />
          <event channel="SmbConnectivityEventChannel" keywords="Smb_Connectivity" level="win:Informational" message="$(string.ShareConnectionEstablished)" symbol="ShareConnectionEstablished" template="ShareConnect" value="30808" version="2" />
          <event channel="SmbConnectivityEventChannel" keywords="Smb_Connectivity" level="win:Error" message="$(string.ExpiredExchange)" symbol="ExpiredExchange" template="ExchangeInfo" value="30809" />
          <event channel="SmbConnectivityEventChannel" keywords="Smb_Connectivity" level="win:Informational" message="$(string.TcpIpTransportArrival)" symbol="TcpIpTransportArrival" template="TcpIpTransport" value="30810" />
          <event channel="SmbConnectivityEventChannel" keywords="Smb_Connectivity" level="win:Informational" message="$(string.TcpIpTransportRemoval)" symbol="TcpIpTransportRemoval" template="TcpIpTransport" value="30811" />
          <event channel="SmbConnectivityEventChannel" keywords="Smb_Connectivity" level="win:Informational" message="$(string.TdiTransportArrival)" symbol="TdiTransportArrival" template="ServerName" value="30812" />
          <event channel="SmbConnectivityEventChannel" keywords="Smb_Connectivity" level="win:Informational" message="$(string.TdiTransportRemoval)" symbol="TdiTransportRemoval" template="ServerName" value="30813" />
          <event channel="SmbConnectivityEventChannel" keywords="Smb_Connectivity" level="win:Informational" message="$(string.WitnessRegistration)" symbol="WitnessRegistration" template="WitnessEvent" value="30814" />
          <event channel="SmbConnectivityEventChannel" keywords="Smb_Connectivity" level="win:Informational" message="$(string.WitnessDeregistration)" symbol="WitnessDeregistration" template="WitnessEvent" value="30815" />
          <event channel="SmbConnectivityEventChannel" keywords="Smb_Connectivity" level="win:Error" message="$(string.NegotiateFailure)" symbol="NegotiateFailure" template="Reason_Status_ServerName" value="30816" />
          <event channel="SmbConnectivityEventChannel" keywords="Smb_Connectivity" level="win:Error" message="$(string.CloseFailure)" symbol="CloseFailure" template="Reason_Status_Path" value="30817" />
          <event channel="SmbConnectivityEventChannel" keywords="Smb_Connectivity" level="win:Warning" message="$(string.RdmaFallback)" symbol="RdmaFallback" template="ServerName" value="30818" />
          <event channel="SmbConnectivityEventChannel" keywords="Smb_TFO" level="win:Informational" message="$(string.ServerWitnessMove)" symbol="WitnessMove" template="WitnessEvent" value="30819" version="2" />
          <event channel="SmbConnectivityEventChannel" keywords="Smb_TFO" level="win:Informational" message="$(string.ServerWitnessMoveSuccess)" symbol="WitnessMoveSuccess" template="WitnessEvent" value="30820" version="2" />
          <event channel="SmbConnectivityEventChannel" keywords="Smb_TFO" level="win:Error" message="$(string.ServerWitnessMoveFailure)" symbol="WitnessMoveFailure" template="WitnessEvent" value="30821" version="2" />
          <event channel="SmbOperationalEventChannel" keywords="Smb_TFO" level="win:Warning" message="$(string.HandlePersistenceNotGranted)" symbol="HandlePersistenceNotGranted" template="HandleStateTransition" value="30900" version="2" />
          <event channel="SmbOperationalEventChannel" keywords="Smb_MultiChannel" level="win:Informational" message="$(string.ServerMultiChannelIncapable)" symbol="ServerMultiChannelIncapable" template="ServerName" value="30904" version="2" />
          <event channel="SmbOperationalEventChannel" keywords="Smb_MultiChannel" level="win:Error" message="$(string.ServerMultiChannelConstraint)" symbol="ServerMultiChannelConstraint" template="ServerName" value="30905" version="2" />
          <event channel="SmbOperationalEventChannel" keywords="Smb_TFO" level="win:Error" message="$(string.RequestRetryFailure)" symbol="RequestRetryFailure" template="RequestRetryInfo" value="30906" />
          <event channel="SmbOperationalEventChannel" keywords="Smb_MultiChannel" level="win:Warning" message="$(string.MultiChannelDisabled)" symbol="MultiChannelDisabled" template="SmbRegistryKey" value="30907" />
          <event channel="SmbOperationalEventChannel" keywords="Smb_Info" level="win:Warning" message="$(string.Smb2Disabled)" symbol="Smb2Disabled" template="SmbRegistryKey" value="30908" />
          <event channel="SmbOperationalEventChannel" keywords="Smb_Info" level="win:Informational" message="$(string.RdmaWithSigning)" symbol="RdmaWithSigning" template="ServerName" value="30909" />
          <event channel="SmbOperationalEventChannel" keywords="Smb_Info" level="win:Informational" message="$(string.RdmaWithEncryption)" symbol="RdmaWithEncryption" template="ServerName" value="30910" />
          <event channel="SmbOperationalEventChannel" keywords="Smb_Info" level="win:Error" message="$(string.InvalidCipherSuiteOrder)" symbol="InvalidCipherSuiteOrder" template="CipherSuiteOrder" value="30911" />
          <event channel="SmbOperationalEventChannel" keywords="Smb_Info" level="win:Warning" message="$(string.RequireSecureNegotiateIsDeprecated)" symbol="RequireSecureNegotiateIsDeprecated" template="NullTemplate" value="30912" />
          <event channel="SmbSecurityEventChannel" keywords="Smb_Authentication" level="win:Error" message="$(string.AcquireCredHandleFailure)" symbol="AcquireCredHandleFailure" template="AuthenticationCall" value="31000" />
          <event channel="SmbSecurityEventChannel" keywords="Smb_Authentication" level="win:Error" message="$(string.ISCFailure)" symbol="ISCFailure" template="AuthenticationCall" value="31001" />
          <event channel="SmbSecurityEventChannel" keywords="Smb_Authentication" level="win:Error" message="$(string.NetworkTokenFailure)" symbol="NetworkTokenFailure" template="Reason_Status_ServerName" value="31002" />
          <event channel="SmbSecurityEventChannel" keywords="Smb_Authentication" level="win:Warning" message="$(string.LMCompatibilityLevel)" opcode="win:Info" symbol="LMCompatibilityLevel" template="SmbRegistryKey" value="31003" />
          <event channel="SmbSecurityEventChannel" keywords="Smb_Authorization" level="win:Error" message="$(string.TreeConnectFailure)" symbol="TreeConnectFailure" template="Reason_Status_Path" value="31010" />
          <event channel="SmbSecurityEventChannel" keywords="Smb_Security" level="win:Error" message="$(string.NegotiateValidation)" symbol="NegotiateValidationFailure" template="NegotiateValidation" value="31012" />
          <event channel="SmbSecurityEventChannel" keywords="Smb_Security" level="win:Error" message="$(string.SigningFailure)" symbol="SigningFailure" template="ExchangeInfo" value="31013" />
          <event channel="SmbSecurityEventChannel" keywords="Smb_Security" level="win:Error" message="$(string.EncryptionFailure)" symbol="EncryptionFailure" template="ExchangeInfo" value="31014" />
          <event channel="SmbSecurityEventChannel" keywords="Smb_Security" level="win:Error" message="$(string.DecryptionFailure)" symbol="DecryptionFailure" template="ExchangeInfo" value="31015" />
          <event channel="SmbSecurityEventChannel" keywords="Smb_Security" level="win:Warning" message="$(string.EnableSecuritySignatureNonDefault)" symbol="EnableSecuritySignatureNonDefault" template="SmbRegistryKey" value="31016" />
          <event channel="SmbSecurityEventChannel" keywords="Smb_Authentication" level="win:Error" message="$(string.RejectedInsecureGuestAuth)" symbol="RejectedInsecureGuestAuth" template="UserNameAndServerName" value="31017" />
          <event channel="SmbSecurityEventChannel" keywords="Smb_Authentication" level="win:Warning" message="$(string.InsecureGuestAuthEnabled)" opcode="win:Info" symbol="InsecureGuestAuthEnabled" template="SmbRegistryKey" value="31018" />
          <event channel="SmbSecurityEventChannel" keywords="Smb_Authentication" level="win:Error" message="$(string.MADowngradeDetected)" symbol="MADowngradeDetected" template="AuthenticationCall" value="31019" />
          <event channel="SmbPacketCapture" keywords="ut:Packet" level="win:Informational" message="$(string.PCAP.evtPacketFragment)" opcode="win:Info" symbol="PacketFragment" template="tidPacketFragment" value="2000" />
          <event channel="SmbPacketCapture" keywords="ut:Packet" level="win:Informational" message="$(string.PCAP.evtPacket)" opcode="win:Info" symbol="Packet" template="tidPacket" value="40000" />
        </events>
        <maps>
          <valueMap name="ut:OpcodeMap">
            <map message="$(string.UT.opcodeStart)" value="180" />
            <map message="$(string.UT.opcodeEnd)" value="181" />
          </valueMap>
          <valueMap name="Smb2ObjectStateMap">
            <map message="$(string.Smb2ObjectStateActive)" value="0" />
            <map message="$(string.Smb2ObjectStateDisconnected)" value="1" />
            <map message="$(string.Smb2ObjectStateSuspended)" value="2" />
            <map message="$(string.Smb2ObjectStateConstructionInProgress)" value="3" />
            <map message="$(string.Smb2ObjectStateRecoveryInProgress)" value="4" />
            <map message="$(string.Smb2ObjectStateDisconnectInProgress)" value="5" />
            <map message="$(string.Smb2ObjectStateInvalidationInProgress)" value="6" />
            <map message="$(string.Smb2ObjectStateInvalid)" value="7" />
            <map message="$(string.Smb2ObjectStateDeleted)" value="8" />
          </valueMap>
          <valueMap name="ConnectionTypeMap">
            <map message="$(string.ConnectionTypeMapTdi)" value="0" />
            <map message="$(string.ConnectionTypeMapWsk)" value="1" />
            <map message="$(string.ConnectionTypeMapRdma)" value="2" />
          </valueMap>
          <valueMap name="Smb2DiagReasonMap">
            <map message="$(string.Smb2DiagReasonNotSpecified)" value="0" />
            <map message="$(string.Smb2DiagReasonDns)" value="1" />
            <map message="$(string.Smb2DiagReasonSetSocketSecurity)" value="2" />
            <map message="$(string.Smb2DiagReasonIPSec)" value="3" />
            <map message="$(string.Smb2DiagReasonNetworkConnect)" value="4" />
            <map message="$(string.Smb2DiagReasonNegotiateValidation)" value="5" />
            <map message="$(string.Smb2DiagReasonExchangeExpiry)" value="6" />
            <map message="$(string.Smb2DiagReasonDisconnectIndication)" value="7" />
            <map message="$(string.Smb2DiagReasonNegativeCache)" value="8" />
            <map message="$(string.Smb2DiagReasonAcquireCredHandle)" value="9" />
            <map message="$(string.Smb2DiagReasonISC)" value="10" />
            <map message="$(string.Smb2DiagReasonSessionSetupResponse)" value="11" />
            <map message="$(string.Smb2DiagReasonTreeConnectResponse)" value="12" />
            <map message="$(string.Smb2DiagReasonValidateNegotiateFsctl)" value="13" />
            <map message="$(string.Smb2DiagReasonHandleReconnect)" value="14" />
            <map message="$(string.Smb2DiagReasonCreateResponse)" value="15" />
            <map message="$(string.Smb2DiagReasonExchangeCancellation)" value="16" />
            <map message="$(string.Smb2DiagReasonObjectSuspended)" value="17" />
            <map message="$(string.Smb2DiagReasonUserDisconnect)" value="18" />
            <map message="$(string.Smb2DiagReasonHandleClosed)" value="19" />
          </valueMap>
          <valueMap name="Smb2CommandMap">
            <map message="$(string.Smb2CommandNegotiate)" value="0" />
            <map message="$(string.Smb2CommandSessionSetup)" value="1" />
            <map message="$(string.Smb2CommandLogoff)" value="2" />
            <map message="$(string.Smb2CommandTreeConnect)" value="3" />
            <map message="$(string.Smb2CommandTreeDisconnect)" value="4" />
            <map message="$(string.Smb2CommandCreate)" value="5" />
            <map message="$(string.Smb2CommandClose)" value="6" />
            <map message="$(string.Smb2CommandFlush)" value="7" />
            <map message="$(string.Smb2CommandRead)" value="8" />
            <map message="$(string.Smb2CommandWrite)" value="9" />
            <map message="$(string.Smb2CommandLock)" value="10" />
            <map message="$(string.Smb2CommandIoctl)" value="11" />
            <map message="$(string.Smb2CommandCancel)" value="12" />
            <map message="$(string.Smb2CommandEcho)" value="13" />
            <map message="$(string.Smb2CommandQueryDirectory)" value="14" />
            <map message="$(string.Smb2CommandChangeNotify)" value="15" />
            <map message="$(string.Smb2CommandQueryInfo)" value="16" />
            <map message="$(string.Smb2CommandSetInfo)" value="17" />
            <map message="$(string.Smb2CommandOplockBreak)" value="18" />
          </valueMap>
          <valueMap name="IrpCodeMap">
            <map message="$(string.IrpCodeCreate)" value="0" />
            <map message="$(string.IrpCodeClose)" value="2" />
            <map message="$(string.IrpCodeRead)" value="3" />
            <map message="$(string.IrpCodeWrite)" value="4" />
            <map message="$(string.IrpCodeQueryInformation)" value="5" />
            <map message="$(string.IrpCodeSetInformation)" value="6" />
            <map message="$(string.IrpCodeQueryEa)" value="7" />
            <map message="$(string.IrpCodeSetEa)" value="8" />
            <map message="$(string.IrpCodeFlushBuffers)" value="9" />
            <map message="$(string.IrpCodeQueryVolumeInformation)" value="10" />
            <map message="$(string.IrpCodeSetVolumeInformation)" value="11" />
            <map message="$(string.IrpCodeDirectoryControl)" value="12" />
            <map message="$(string.IrpCodeFileSystemControl)" value="13" />
            <map message="$(string.IrpCodeDeviceControl)" value="14" />
            <map message="$(string.IrpCodeInternalDeviceControl)" value="15" />
            <map message="$(string.IrpCodeLockControl)" value="17" />
            <map message="$(string.IrpCodeCleanup)" value="18" />
            <map message="$(string.IrpCodeQuerySecurity)" value="20" />
            <map message="$(string.IrpCodeSetSecurity)" value="21" />
            <map message="$(string.IrpCodeQueryQuotaInformation)" value="25" />
            <map message="$(string.IrpCodeSetQuotaInformation)" value="26" />
            <map message="$(string.IrpCodeInternalProbeIO)" value="27" />
          </valueMap>
          <valueMap name="ShareTypeMap">
            <map message="$(string.ShareTypeMapSymmetric)" value="0" />
            <map message="$(string.ShareTypeMapAsymmetric)" value="1" />
          </valueMap>
        </maps>
      </provider>
    </events>
    <counters xmlns="http://schemas.microsoft.com/win/2005/12/counters" schemaVersion="2.0">
      <provider applicationIdentity="%systemroot%\system32\drivers\mrxsmb.sys" providerGuid="{31A5EBE2-C765-490A-937C-B0AB2787FE15}" providerType="kernelMode">
        <counterSet description="This counter set displays information about server shares that are being accessed by the client using SMB protocol version 2 or higher." descriptionID="3" guid="{C73DFEF0-11B8-4A3F-A1AD-0DCBBC5186EF}" instances="multipleAggregate" name="SMB Client Shares" nameID="1" symbol="ShareCounters" uri="Microsoft.SMB2.Client.Share">
          <structs>
            <struct name="Smb2SharePerfCounters" type="SMB2_SHARE_PERF_COUNTERS" />
          </structs>
          <counter description="The rate at which bytes are being read from this share." descriptionID="11" detailLevel="standard" field="TotalReadBytes" id="2" name="Read Bytes/sec" nameID="9" struct="Smb2SharePerfCounters" type="perf_counter_bulk_count" uri="Microsoft.SMB2.Client.Share.BytesReadPerSec" />
          <counter description="The rate at which bytes are being written to this share." descriptionID="19" detailLevel="standard" field="TotalWriteBytes" id="4" name="Write Bytes/sec" nameID="17" struct="Smb2SharePerfCounters" type="perf_counter_bulk_count" uri="Microsoft.SMB2.Client.Share.BytesWrittenPerSec" />
          <counter description="The rate at which read requests are being sent to this share." descriptionID="27" detailLevel="standard" field="TotalReadRequests" id="6" name="Read Requests/sec" nameID="25" struct="Smb2SharePerfCounters" type="perf_counter_counter" uri="Microsoft.SMB2.Client.Share.ReadRequestsPerSec" />
          <counter description="The rate at which write requests are being sent to this share." descriptionID="35" detailLevel="standard" field="TotalWriteRequests" id="8" name="Write Requests/sec" nameID="33" struct="Smb2SharePerfCounters" type="perf_counter_counter" uri="Microsoft.SMB2.Client.Share.WriteRequestsPerSec" />
          <counter baseID="10" description="The average number of bytes per read request." descriptionID="39" detailLevel="standard" field="TotalReadBytes" id="9" name="Avg. Bytes/Read" nameID="37" struct="Smb2SharePerfCounters" type="perf_average_bulk" uri="Microsoft.SMB2.Client.Share.AvgBytesPerRead" />
          <counter detailLevel="standard" field="TotalReadRequests" id="10" struct="Smb2SharePerfCounters" type="perf_average_base" uri="Microsoft.SMB2.Client.Share.AvgBytesPerReadBase" />
          <counter baseID="12" description="The average number of bytes per write request." descriptionID="43" detailLevel="standard" field="TotalWriteBytes" id="11" name="Avg. Bytes/Write" nameID="41" struct="Smb2SharePerfCounters" type="perf_average_bulk" uri="Microsoft.SMB2.Client.Share.AvgBytesPerWrite" />
          <counter detailLevel="standard" field="TotalWriteRequests" id="12" struct="Smb2SharePerfCounters" type="perf_average_base" uri="Microsoft.SMB2.Client.Share.AvgBytesPerWriteBase" />
          <counter baseID="14" description="The average latency between the time a read request is sent and when its response is received." descriptionID="47" detailLevel="standard" field="TotalReadTime" id="13" name="Avg. sec/Read" nameID="45" struct="Smb2SharePerfCounters" type="perf_average_timer" uri="Microsoft.SMB2.Client.Share.AvgLatencyPerRead" />
          <counter detailLevel="standard" field="TotalReadRequests" id="14" struct="Smb2SharePerfCounters" type="perf_average_base" uri="Microsoft.SMB2.Client.Share.AvgLatencyPerReadBase" />
          <counter baseID="16" description="The average latency between the time a write request is sent and when its response is received." descriptionID="51" detailLevel="standard" field="TotalWriteTime" id="15" name="Avg. sec/Write" nameID="49" struct="Smb2SharePerfCounters" type="perf_average_timer" uri="Microsoft.SMB2.Client.Share.AvgLatencyPerWrite" />
          <counter detailLevel="standard" field="TotalWriteRequests" id="16" struct="Smb2SharePerfCounters" type="perf_average_base" uri="Microsoft.SMB2.Client.Share.AvgLatencyPerWriteBase" />
          <counter description="The rate at which bytes are being read or written to this share." descriptionID="55" detailLevel="standard" field="TotalReadWriteBytes" id="17" name="Data Bytes/sec" nameID="53" struct="Smb2SharePerfCounters" type="perf_counter_bulk_count" uri="Microsoft.SMB2.Client.Share.TotalDataBytesPerSec" />
          <counter description="The rate at which read or write requests are being sent to this share." descriptionID="59" detailLevel="standard" field="TotalReadWriteRequests" id="18" name="Data Requests/sec" nameID="57" struct="Smb2SharePerfCounters" type="perf_counter_counter" uri="Microsoft.SMB2.Client.Share.TotalDataRequestsPerSec" />
          <counter baseID="20" description="The average number of bytes per read or write request." descriptionID="63" detailLevel="standard" field="TotalReadWriteBytes" id="19" name="Avg. Data Bytes/Request" nameID="61" struct="Smb2SharePerfCounters" type="perf_average_bulk" uri="Microsoft.SMB2.Client.Share.AvgDataBytesPerRequest" />
          <counter detailLevel="standard" field="TotalReadWriteRequests" id="20" struct="Smb2SharePerfCounters" type="perf_average_base" uri="Microsoft.SMB2.Client.Share.AvgDataBytesPerRequestBase" />
          <counter baseID="22" description="The average latency between the time a read or write request is sent and when its response is received." descriptionID="67" detailLevel="standard" field="TotalReadWriteTime" id="21" name="Avg. sec/Data Request" nameID="65" struct="Smb2SharePerfCounters" type="perf_average_timer" uri="Microsoft.SMB2.Client.Share.AvgLatencyPerDataRequest" />
          <counter detailLevel="standard" field="TotalReadWriteRequests" id="22" struct="Smb2SharePerfCounters" type="perf_average_base" uri="Microsoft.SMB2.Client.Share.AvgLatencyPerDataRequestBase" />
          <counter description="The current number of read or write requests outstanding on this share." descriptionID="71" detailLevel="standard" field="CurrentQueueLength" id="23" name="Current Data Queue Length" nameID="69" struct="Smb2SharePerfCounters" type="perf_counter_rawcount" uri="Microsoft.SMB2.Client.Share.CurrentDataQueueLength" />
          <counter description="The average number of read requests that were queued for this share." descriptionID="75" detailLevel="standard" field="TotalReadQueueLength" id="24" name="Avg. Read Queue Length" nameID="73" struct="Smb2SharePerfCounters" type="perf_counter_100ns_queuelen_type" uri="Microsoft.SMB2.Client.Share.AvgReadQueueLength" />
          <counter description="The average number of write requests that were queued for this share." descriptionID="79" detailLevel="standard" field="TotalWriteQueueLength" id="25" name="Avg. Write Queue Length" nameID="77" struct="Smb2SharePerfCounters" type="perf_counter_100ns_queuelen_type" uri="Microsoft.SMB2.Client.Share.AvgWriteQueueLength" />
          <counter description="The average number of both read and write requests that were queued for this share." descriptionID="83" detailLevel="standard" field="TotalQueueLength" id="26" name="Avg. Data Queue Length" nameID="81" struct="Smb2SharePerfCounters" type="perf_counter_100ns_queuelen_type" uri="Microsoft.SMB2.Client.Share.AvgDataQueueLength" />
          <counter description="The rate at which metadata requests are being sent to this share." descriptionID="91" detailLevel="standard" field="TotalMetadataRequests" id="28" name="Metadata Requests/sec" nameID="89" struct="Smb2SharePerfCounters" type="perf_counter_counter" uri="Microsoft.SMB2.Client.Share.MetadataRequestsPerSec" />
          <counter description="The number of requests per second delayed based on insufficient credits for this share." descriptionID="95" detailLevel="standard" field="TotalCreditStalls" id="29" name="Credit Stalls/sec" nameID="93" struct="Smb2SharePerfCounters" type="perf_counter_counter" uri="Microsoft.SMB2.Client.Share.CreditStallsPerSec" />
        </counterSet>
      </provider>
    </counters>
  </instrumentation>
</assembly>