fsutil.exe

Associated Error Codes

Below lists error codes and symbolic names found for this module.

CodeFound inDescription
0x4000271010---- Commands Supported ---- 8dot3name 8dot3name management behavior Control file system behavior dax Dax volume management dirty Manage volume dirty bit file File specific commands fsInfo File system information hardlink Hardlink management objectID Object ID management quota Quota management repair Self healing management reparsePoint Reparse point management storageReserve Storage Reserve management resource Transactional Resource Manager management sparse Sparse file control tiering Storage tiering property management transaction Transaction management usn USN management volume Volume management wim Transparent wim hosting management
0x4000271178.11011Error:
0x4000271278.11011Drives:
0x4000271310Usage : fsutil fsInfo driveType Eg : fsutil fsInfo driveType C:
0x4000271478.11011%1 - Unknown Drive
0x4000271578.11011%1 - No such Root Directory
0x4000271678.11011%1 - Removable Drive
0x4000271778.11011%1 - Fixed Drive
0x4000271878.11011%1 - Remote/Network Drive
0x4000271978.11011%1 - CD-ROM Drive
0x4000271a78.11011%1 - Ram Disk
0x4000271b10Usage : fsutil fsInfo volumeInfo Eg : fsutil fsInfo volumeInfo C:
0x4000271c78.11011Supports Case-sensitive filenames
0x4000271d78.11011Preserves Case of filenames
0x4000271e78.11011Supports Unicode in filenames
0x4000271f78.11011Preserves & Enforces ACL's
0x4000272078.11011Supports file-based Compression
0x4000272178.11011Supports Disk Quotas
0x4000272278.11011Supports Sparse files
0x4000272378.11011Supports Reparse Points
0x4000272478.11011Supports Remote Storage
0x4000272578.11011Compressed volume
0x4000272678.11011Supports Object Identifiers
0x4000272778.11011Supports Encrypted File System
0x4000272878.11011Supports Transactions
0x4000272978.11011Supports Named Streams
0x4000272a78.11011Volume Name : %1
0x4000272b78.11011Volume Serial Number : 0x%1!x!
0x4000272c78.11011Max Component Length : %1!d!
0x4000272d78.11011File System Name : %1
0x4000272e10Usage : fsutil volume diskFree Eg : fsutil volume diskFree C:
0x4000272f1011Total free bytes : %1!*s! (%2!*s!%3!s!) Total bytes : %4!*s! (%5!*s!%6!s!) Total quota free bytes : %7!*s! (%8!*s!%9!s!)
0x4000273078.11011Error opening handle for eventlog
0x4000273178.11011Searching in %1 Event Log...
0x4000273278.11011**** A user hit their quota threshold ! ****
0x4000273378.11011**** A user hit their quota limit ! ****
0x4000273478.11011Event ID : 0x%1!x!
0x4000273578.11011EventType : Error
0x4000273678.11011EventType : Warning
0x4000273778.11011EventType : Information
0x4000273878.11011EventType : Audit success
0x4000273978.11011EventType : Audit failure
0x4000273a78.11011Event Category : %1!d!
0x4000273b78.11011Source : %1
0x4000273c78.11011Data: %1
0x4000273d78.11011No quota violations detected
0x4000273e78.11011User: %1\%2
0x4000274078.110Usage : fsutil volume dismount Eg : fsutil volume dismount C:
0x4000274178.11011Formerly MSG_USAGE_QUERY_CLUSTER
0x4000274278.11011Formerly MSG_QUERY_CLUSTER
0x4000274378.110Usage : fsutil dirty set Eg : fsutil dirty set C:
0x4000274410Usage : fsutil fsInfo statistics Eg : fsutil fsInfo statistics C:
0x4000274578.11011UserFileReads : %1 UserFileReadBytes : %2 UserDiskReads : %3 UserFileWrites : %4 UserFileWriteBytes : %5 UserDiskWrites : %6 MetaDataReads : %7 MetaDataReadBytes : %8 MetaDataDiskReads : %9 MetaDataWrites : %10 MetaDataWriteBytes : %11 MetaDataDiskWrites : %12
0x400027468.11011CreateHits : %1 SuccessfulCreates : %2 FailedCreates : %3 NonCachedReads : %4 NonCachedRead Bytes : %5 NonCachedWrites : %6 NonCachedWrite Bytes : %7 NonCachedDiskReads : %8 NonCachedDiskWrites : %9
0x400027471011MftReads : %1 MftReadBytes : %2 MftWrites : %3 MftWriteBytes : %4 Mft2Writes : %5 Mft2WriteBytes : %6 RootIndexReads : %7 RootIndexReadBytes : %8 RootIndexWrites : %9 RootIndexWriteBytes : %10 BitmapReads : %11 BitmapReadBytes : %12 BitmapWrites : %13 BitmapWriteBytes : %14 MftBitmapReads : %15 MftBitmapReadBytes : %16 MftBitmapWrites : %17 MftBitmapWriteBytes : %18 UserIndexReads : %19 UserIndexReadBytes : %20 UserIndexWrites : %21 UserIndexWriteBytes : %22 LogFileReads : %23 LogFileReadBytes : %24 LogFileWrites : %25 LogFileWriteBytes : %26 LogFileFull : %27 DiskResourceFailure : %28
0x4000274878.11011File System Type : FAT
0x4000274978.11011File System Type : NTFS
0x4000274a10Usage : fsutil file setValidData Eg : fsutil file setValidData C:\testfile.txt 4096
0x4000274b10Usage : fsutil file setShortName Eg : fsutil file setShortName C:\testfile.txt testfile
0x4000274c1011A local NTFS volume is required for this operation.
0x4000274d10Usage : fsutil file queryAllocRanges offset= length= offset : File Offset, the start of the range to query length : Size, in bytes, of the range Eg : fsutil file queryAllocRanges offset=1024 length=64 C:\Temp\sample.txt
0x4000274e8.11011Formerly MSG_ALLOCRANGE_RANGES
0x4000274f10Usage : fsutil file setZeroData offset= length= offset : File offset, the start of the range to set to zeroes length : Byte length of the zeroed range Eg : fsutil file setZeroData offset=100 length=150 C:\Temp\sample.txt
0x4000275010Usage : fsutil sparse setFlag [1|0] Eg : fsutil sparse setFlag C:\Temp\sample.txt
0x400027518.110Usage : fsutil fsinfo ntfsInfo Eg : fsutil fsinfo ntfsInfo C:
0x4000275210NTFS Volume Serial Number : 0x%1 NTFS Version : %2!d!.%3!d! LFS Version : %4!d!.%5!d! Total Sectors : %6!*s! (%7!*s!%8) Total Clusters : %9!*s! (%10!*s!%11) Free Clusters : %12!*s! (%13!*s!%14) Total Reserved Clusters : %15!*s! (%16!*s!%17) Reserved For Storage Reserve : %18!*s! (%19!*s!%20) Bytes Per Sector : %21!d! Bytes Per Physical Sector : %22!d! Bytes Per Cluster : %23!d! Bytes Per FileRecord Segment : %24!d! Clusters Per FileRecord Segment : %25!d! Mft Valid Data Length : %26%27 Mft Start Lcn : 0x%28 Mft2 Start Lcn : 0x%29 Mft Zone Start : 0x%30 Mft Zone End : 0x%31 MFT Zone Size : %32%33 Max Device Trim Extent Count : %34!u! Max Device Trim Byte Count : %35!#x! Max Volume Trim Extent Count : %36!u! Max Volume Trim Byte Count : %37!#x!
0x4000275378.110Usage : fsutil dirty query Eg : fsutil dirty query C:
0x4000275478.11011Volume - %1!s! is Dirty
0x4000275578.11011Volume - %1!s! is NOT Dirty
0x4000275610Usage : fsutil reparsePoint query Eg : fsutil reparsePoint query C:\Server
0x4000275778.11011Reparse Tag Value : 0x%1!08x!
0x4000275878.11011Tag value: Microsoft
0x4000275978.11011Tag value: Name Surrogate
0x4000275a78.11011Tag value: Symbolic Link
0x4000275b78.11011Tag value: Mount Point
0x4000275c78.11011Tag value: HSM
0x4000275d78.11011Tag value: SIS
0x4000275e78.11011Tag value: Filter Manager
0x4000275f78.11011Tag value: DFS
0x4000276078.11011GUID : %1!s!
0x4000276178.11011Reparse Data:
0x4000276210Usage : fsutil reparsePoint delete Eg : fsutil reparsePoint delete C:\Server
0x4000276310Usage : fsutil objectID set ObjectId : 32-digit hexadecimal data BirthVolumeId : 32-digit hexadecimal data BirthObjectId : 32-digit hexadecimal data DomainId : 32-digit hexadecimal data All values must be in Hex of the form 40dff02fc9b4d4118f120090273fa9fc Eg : fsutil objectID set 40dff02fc9b4d4118f120090273fa9fc f86ad6865fe8d21183910008c709d19e 40dff02fc9b4d4118f120090273fa9fc 00000000000000000000000000000000 C:\Temp\sample.txt
0x4000276410Usage : fsutil objectID query Eg : fsutil objectID query C:\Temp\sample.txt
0x4000276510Usage : fsutil objectID create Eg : fsutil objectID create C:\Temp\sample.txt
0x4000276610Usage : fsutil objectID delete Eg : fsutil objectID delete C:\Temp\sample.txt
0x4000276778.11011Object ID :
0x4000276878.11011BirthVolume ID :
0x4000276978.11011BirthObjectId ID :
0x4000276a78.11011Domain ID :
0x4000276b1011Usage : fsutil usn createJournal [options] Options : m= - Specifies the maximum size, in bytes, that NTFS allocates for the change journal. a= - Specifies the size, in bytes, of memory allocation that is added to the end and removed from the beginning of the change journal. ** Note: If maximum size or allocation delta is not specified, the default size will be set based on your current volume size. Eg : fsutil usn createJournal C: fsutil usn createJournal C: m=1000 fsutil usn createJournal C: m=1000 a=100
0x4000276c78.11011Major Version : 0x%1!x! Minor Version : 0x%2!x! FileRef# : 0x%3 Parent FileRef# : 0x%4 Usn : 0x%5 Time Stamp : 0x%6 %7 %8 Reason : 0x%9!lx! Source Info : 0x%10!lx! Security Id : 0x%11!lx! File Attributes : 0x%12!lx! File Name Length : 0x%13!x! File Name Offset : 0x%14!x! FileName : %15!.*ws!
0x4000276d10Usage : fsutil usn queryJournal Eg : fsutil usn queryJournal C:
0x4000276e1011Usn Journal ID : 0x%1 First Usn : 0x%2 Next Usn : 0x%3 Lowest Valid Usn : 0x%4 Max Usn : 0x%5 Maximum Size : 0x%6 (%7!*s!%8!s!) Allocation Delta : 0x%9 (%10!*s!%11!s!)
0x4000276f10Usage : fsutil usn deleteJournal /D : Delete /N : Notify Eg : usn deleteJournal /D C:
0x4000277010Usage : fsutil usn enumData Eg : fsutil usn enumData 1 0 1 C:
0x4000277178.11011File Ref# : 0x%1 ParentFile Ref# : 0x%2 Usn : 0x%3 SecurityId : 0x%4!08x! Reason : 0x%5!08x! Name (%6!03d!) : %7!.*ws!
0x4000277210Usage : fsutil usn readData Eg : fsutil usn readData C:\Temp\sample.txt
0x4000277310Usage : fsutil file findBySID Eg : fsutil file findBySID scottb C:\users
0x4000277478.11011---- BEHAVIOR Commands Supported ---- query Query the file system behavior parameters set Change the file system behavior parameters
0x4000277578.110%1 = %2!u!
0x4000277678.11011%1 is not currently set
0x4000277778.11011---- DIRTY Commands Supported ---- query Query the dirty bit set Set the dirty bit
0x4000277810---- FILE Commands Supported ---- createNew Creates a new file of a specified size findBySID Find a file by security identifier layout Query all the information available about the file optimizeMetadata Optimize metadata for a file queryAllocRanges Query the allocated ranges for a file queryCaseSensitiveInfo Query the case sensitive information for a directory queryEA Query the extended attributes (EA) information for a file queryExtents Query the extents for a file queryExtentsAndRefCounts Query the extents and their corresponding refcounts for a file queryFileID Queries the file ID of the specified file queryFileNameById Displays a random link name for the file ID queryOptimizeMetadata Query the optimize metadata state for a file queryValidData Queries the valid data length for a file setCaseSensitiveInfo Set the case sensitive information for a directory setShortName Set the short name for a file setValidData Set the valid data length for a file setZeroData Set the zero data for a file setEOF Sets the end of file for an existing file setStrictlySequential Sets ReFS SMR file as strictly sequential
0x400027791011---- FSINFO Commands Supported ---- drives List all drives driveType Query drive type for a drive ntfsInfo Query NTFS specific volume information refsInfo Query REFS specific volume information sectorInfo Query sector information statistics Query file system statistics volumeInfo Query volume information
0x4000277a78.110---- HARDLINK Commands Supported ---- create Create a hardlink list Enumerate hardlinks on a file
0x4000277b8.11011---- OBJECTID Commands Supported ---- create Create the object identifier delete Delete the object identifier query Query the object identifier set Change the object identifier
0x4000277c1011---- QUOTA Commands Supported ---- disable Disable quota tracking and enforcement enforce Enable quota enforcement modify Set disk quota for a user query Query disk quotas track Enable quota tracking violations Display quota violations
0x4000277d8.11011---- REPARSEPOINT Commands Supported ---- delete Delete a reparse point query Query a reparse point
0x4000277e1011---- RESOURCE Commands Supported ---- create Create a Secondary Transactional Resource Manager info Display information relating to a Transactional Resource Manager setAutoReset Set whether a default Transactional Resource Manager will clean its transactional metadata on next mount setAvailable Set a Transactional Resource Manager to prefer availability over consistency setConsistent Set a Transactional Resource Manager to prefer consistency over availability setLog Change characteristics of a running Transactional Resource Manager start Start a Transactional Resource Manager stop Stop a Transactional Resource Manager
0x4000277f1011---- SETLOG Commands Supported ---- growth Change the automatic growth settings maxExtents Change the maximum number of containers minExtents Change the minimum number of containers mode Switch between undo only logging and full logging rename Change the RM's Guid shrink Change the automatic shrink settings size Change the number of containers explicitly
0x4000278078.11011Formerly MSG_USAGE_SHORT_NAME
0x400027811011---- SPARSE Commands Supported ---- queryFlag Query sparse queryRange Query range setFlag Set sparse setRange Set sparse range
0x400027828.11011---- TRANSACTION Commands Supported ---- commit Commit a specified transaction fileinfo Display transaction information for a specific file list Display currently running transactions query Display information on a specified transaction rollback Rollback a specified transaction
0x400027831011---- USN Commands Supported ---- createJournal Create a USN journal deleteJournal Delete a USN journal enableRangeTracking Enable write range tracking for a volume enumData Enumerate USN data queryJournal Query the USN data for a volume readJournal Reads the USN records in the USN journal readData Read the USN data for a file
0x4000278410---- VOLUME Commands Supported ---- allocationReport Allocated clusters report diskFree Query the free space of a volume dismount Dismount a volume fileLayout Query all the information available about the file(s) flush Flush a volume list List volumes queryCluster Query which file is using a particular cluster queryLabel Query the label for a volume queryNumaInfo Queries the NUMA node for the given volume setLabel Set the label for a volume smrGC Control SMR Garbage Collection smrInfo Query SMR information thinProvisioningInfo Query thin provisioning info for the given volume
0x4000278578.110Usage : fsutil transaction rollback Eg : fsutil transaction rollback {0f2d8905-6153-449a-8e03-7d3a38187ba1}
0x4000278678.110Usage : fsutil transaction commit Eg : fsutil transaction commit {0f2d8905-6153-449a-8e03-7d3a38187ba1}
0x4000278778.110Usage : fsutil transaction query [files|all] Eg : fsutil transaction query {0f2d8905-6153-449a-8e03-7d3a38187ba1}
0x4000278810Usage : fsutil transaction fileInfo Eg : fsutil transaction fileInfo d:\foobar.txt
0x4000278978.110Usage : fsutil resource create Eg : fsutil resource create d:\foobar
0x4000278a78.110Usage : fsutil resource start [ ] Eg : fsutil resource start d:\foobar fsutil resource start d:\foobar d:\foobar\LogDir\LogBLF::TxfLog d:\foobar\LogDir\LogBLF::TmLog
0x4000278b78.110Usage : fsutil resource stop Eg : fsutil resource stop d:\foobar
0x4000278c78.110Usage : fsutil resource info Eg : fsutil resource info d:\foobar
0x4000278d78.110Usage : fsutil resource txnreset [] Eg : fsutil resource txnreset d:\foobar
0x4000278e10Usage : fsutil resource setAutoReset true fsutil resource setAutoReset false Eg : fsutil resource setAutoReset true d:\
0x4000278f10Usage : fsutil resource setLog size Eg : fsutil resource setLog size 50 d:\foobar
0x4000279010Usage : fsutil resource setLog mode full fsutil resource setLog mode undo Eg : fsutil resource setLog mode full d:\foobar
0x4000279110Usage : fsutil resource setLog extentsize Eg : fsutil resource setLog extentsize 50 d:\foobar
0x4000279210Usage : fsutil resource setLog rename Eg : fsutil resource setLog rename d:\foobar
0x4000279310Usage : fsutil resource setLog maxExtents Eg : fsutil resource setLog maxExtents 50 d:\foobar
0x4000279410Usage : fsutil resource setLog minExtents Eg : fsutil resource setLog minExtents 5 d:\foobar
0x4000279510Usage : fsutil resource setLog growth containers fsutil resource setLog growth percent Eg : fsutil resource setLog growth 5 containers d:\foobar
0x4000279610Usage : fsutil resource setLog shrink Eg : fsutil resource setLog shrink 10 d:\foobar
0x4000279778.11011The operation completed successfully.
0x4000279878.11011dwOutcome: %1!s! dwIsolationLevel: %2!s! dwIsolationFlags: %3!s! dwTimeout: %4!s!
0x4000279978.11011Owner: %1!s!
0x4000279a78.11011Number of Files: %1!s!
0x4000279b78.11011%1!s! is not being locked by a transaction.
0x4000279c78.11011%1!s! is being locked by a transaction called %2!s!.
0x4000279d78.11011An RM cannot be reset from within the RM. Please change to a directory outside the RM and try again.
0x4000279e78.11011This operation cannot be completed while the RM is running. Please shutdown the RM and try again.
0x4000279f78.11011One or more files within the RM could not be cleaned because they are in use by another application.
0x400027a078.11011One or more files within the RM could not be cleaned because this process does not have access to those files.
0x400027a178.11011Not all of the files within this RM have been cleaned.
0x400027a278.11011An unknown error occurred while attempting to clean this RM.
0x400027a31011Resource Manager Identifier : %1!s!
0x400027a478.11011KTM Log Path for RM: %1!s!
0x400027a578.11011Space used by TOPS: %1!s! Mb TOPS free space: %2!s!%
0x400027a678.11011Running transactions: %1!s! One phase commits: %2!s! Two phase commits: %3!s! System initiated rollbacks: %4!s!
0x400027a778.11011Age of oldest transaction: %1!s!
0x400027a878.11011Logging Mode: Full
0x400027a978.11011Logging Mode: Simple
0x400027aa78.11011Number of containers: %1!s! Container size: %2!s! Mb Total log capacity: %3!s! Mb Total free log space: %4!s! Mb
0x400027ab78.11011Maximum containers: No Limit
0x400027ac78.11011Maximum containers: %1!s!
0x400027ad78.11011Minimum containers: No Limit
0x400027ae78.11011Minimum containers: %1!s!
0x400027af78.11011Log growth increment: %1!s!%
0x400027b078.11011Log growth increment: %1!s! container(s)
0x400027b178.11011Auto shrink: Not enabled
0x400027b278.11011Auto shrink: %1!s!%
0x400027b378.11011Log size is now: %1!s! container(s).
0x400027b410Usage : fsutil file createNew Eg : fsutil file createNew C:\testfile.txt 1000
0x400027b578.11011Formerly MSG_USAGE_QUERYFILEID
0x400027b678.11011Formerl MSG_USAGE_QUERYFILENAMEBYID
0x400027b778.11011The FSUTIL utility requires that you have administrative privileges.
0x400027b878.110Usage : fsutil hardlink create Eg : fsutil hardlink create c:\foo.txt c:\bar.txt
0x400027b978.110Hardlink created for %1!s! <<===>> %2!s!
0x400027ba78.11011Formerly MSG_USAGE_HARDLINK_LIST
0x400027bb78.11011File %1!s! is created
0x400027bc78.11011Formerly MSG_QUERYFILEID_SUCCEEDED
0x400027bd78.11011Formerly MSG_QUERYFILENAMEBYID_SUCCEEDED
0x400027be78.11011Default quota values
0x400027bf78.11011SID Name = %1!s!\%2!s! (User)
0x400027c078.11011SID Name = %1!s!\%2!s! (Group)
0x400027c178.11011SID Name = %1!s!\%2!s! (Domain)
0x400027c278.11011SID Name = %1!s!\%2!s! (Alias)
0x400027c378.11011SID Name = %1!s!\%2!s! (WellKnownGroup)
0x400027c478.11011SID Name = %1!s!\%2!s! (DeletedAccount)
0x400027c578.11011SID Name = %1!s!\%2!s! (Invalid)
0x400027c678.11011SID Name = %1!s!\%2!s! (Unknown)
0x400027c778.11011Change time = %1!s! Quota Used = %2 Quota Threshold = %3 Quota Limit = %4
0x400027c878.110Usage : fsutil quota query Eg : fsutil quota query C:
0x400027c978.110Usage : fsutil quota modify Eg : fsutil quota modify c: 3000 5000 domain\user
0x400027ca78.110Usage : fsutil quota violations Eg : fsutil quota violations
0x400027cb78.11011FileSystemControlFlags = 0x%1!08x!
0x400027cc78.11011Quotas are disabled on this volume
0x400027cd78.11011Quotas are tracked and enforced on this volume
0x400027ce78.11011Quotas are tracked on this volume
0x400027cf78.11011Logging enable for quota limits
0x400027d078.11011Logging enable for quota thresholds
0x400027d178.11011Logging enable for quota limits and threshold
0x400027d278.11011Logging for quota events is not enabled
0x400027d378.11011The quota values are incomplete
0x400027d478.11011The quota values are up to date
0x400027d578.11011Default Quota Threshold = 0x%1 Default Quota Limit = 0x%2
0x400027d678.110Quotas are not enabled on volume %1!s!
0x400027d778.11011Volume - %1!s! is now marked dirty
0x400027d878.11011Valid data length is changed
0x400027d978.11011Zero data is changed
0x400027da78.11011No files were found
0x400027db78.11011This file is set as sparse
0x400027dc78.11011This file is NOT set as sparse
0x400027dd10Usage : fsutil sparse queryFlag Eg : fsutil sparse queryFlag C:\Temp\sample.txt
0x400027de10Usage : fsutil sparse setRange Eg : fsutil sparse setRange C:\Temp\sample.txt 65536 131072
0x400027df10Usage : fsutil sparse queryRange Eg : fsutil sparse queryRange C:\Temp\sample.txt
0x400027e078.11011The specified file is NOT sparse
0x400027e18.11011Allocated range[%1!d!]: Offset: 0x%2!-8I64x! Length: 0x%3!I64x!
0x400027e278.11011The specified file has no object id
0x400027e378.11011The new link and the existing file must be on the same volume.
0x400027e478.110Usage : fsutil quota disable Eg : fsutil quota disable C:
0x400027e578.110Usage : fsutil quota track Eg : fsutil quota track C:
0x400027e678.110Usage : fsutil quota enforce Eg : fsutil quota enforce C:
0x400027e778.11011%1 is an invalid parameter.
0x400027e810Usage : fsutil fsInfo drives
0x400027e91011The FSUTIL utility requires a local volume for this operation.
0x400027ea78.11011The specified drive is too long.
0x400027eb78.11011The specified drive format is invalid or not supported.
0x400027ec78.11011Format version: %1!d! CSid: %2!s! LinkIndex: 0x%3!08x!.%4!08x! LinkFileNtfsID: 0x%5!08x!.%6!08x! CSFileNtfsID: 0x%7!08x!.%8!08x! CSChecksum: 0x%9!08x!.%10!08x! Checksum: 0x%11!08x!.%12!08x!
0x400027ed78.11011Substitue Name offset: %1!d! Substitue Name length: %2!d! Print Name offset: %3!d! Print Name Length: %4!d!
0x400027ee78.11011Substitute Name: %1!.*s!
0x400027ef78.11011Print Name: %1!.*s!
0x400027f01011Reparse Data Length: 0x%1!-8x!
0x400027f178.11011Vendor ID: %1!s! Qualifier: 0x%2!08x! Version: 0x%3!08x! Global Flags: 0x%4!08x! Num Data Entries: %5!d! File ID: %6!s! Data: Flags: 0x%7!08x! Migration Time: %8!s! HSM ID: %9!s! Bag ID: %10!s! File Start: 0x%11!08x!.%12!08x! File Size: 0x%13!08x!.%14!08x! Data Start: 0x%15!08x!.%16!08x! Data Size: 0x%17!08x!.%18!08x! File Version: 0x%19!08x!.%20!08x! Verification Data: 0x%21!08x!.%22!08x! Verification Type: %23!u! Recall Count: %24!u! Recall Time: %25!s! Data Stream Start: 0x%26!08x!.%27!08x! Data Stream Size: 0x%28!08x!.%29!08x! Data Stream: %30!u! Data Stream CRC Type: %31!u! Data Stream CRC: 0x%32!08x!.%3!08x!
0x400027f28.11011---- REPAIR Commands Supported ---- enumerate Enumerate the entries of a volume's corruption log initiate Initiate the repair of a file query Query the self healing state of the volume set Set the self healing state of the volume state Query the corruption state of the volume(s) wait Wait for repair(s) to complete
0x400027f378.110Usage : fsutil repair query Eg : fsutil repair query C:
0x400027f478.110Usage : fsutil repair set flags: 1 - enable general repair 8 - warn about potential data loss Eg : fsutil repair set C: 1 fsutil repair set C: 9
0x400027f578.110Usage : fsutil repair wait [] WaitType: 0 to wait for all repairs (same as not specified) WaitType: 1 to wait for the current repair Eg : fsutil repair wait C: fsutil repair wait C: 1
0x400027f68.110Usage : fsutil repair enumerate [] LogName: $Corrupt - The set of confirmed corruptions in the volume (default value if LogName is not specified) LogName: $Verify - A set of potential, unverified corruptions in the volume Eg : fsutil repair enumerate C: fsutil repair enumerate C: $Corrupt fsutil repair enumerate C: $Verify
0x400027f78.110Self healing is now disabled for volume %1!s!
0x400027f88.11011No corruption records were found.
0x400027fb8.110Self healing is disabled for volume %1!s!
0x400027fd8.110Current repair is completed for volume %1!s!
0x400027fe8.110All repairs are completed for volume %1!s!
0x400027ff78.11011Tag value: IIS Caching Reparse Point
0x4000280078.11011Local File Path : %1!.*s! Remote File Path : %2!.*s!
0x4000280178.110No longer in use but do not want to shift the message ids
0x4000280278.110Usage : fsutil repair truncatelog Eg : fsutil repair truncatelog C:
0x4000280378.110Self healing repair log is now being truncated for volume %1!s!
0x4000280478.110Usage : fsutil repair initiate file ref# : File Reference including segment number of the file. Eg : fsutil repair initiate C: 0x001600000000123D
0x4000280578.11011Initiated the repair for file reference 0x%1!s!
0x4000280678.11011The data in the reparse buffer is invalid!
0x4000280778.110Local to local symbolic links are enabled.
0x4000280878.110Local to remote symbolic links are enabled.
0x4000280978.110Remote to local symbolic links are enabled.
0x4000280a78.110Remote to remote symbolic links are enabled.
0x4000280b78.110Local to local symbolic links are disabled.
0x4000280c78.110Local to remote symbolic links are disabled.
0x4000280d78.110Remote to local symbolic links are disabled.
0x4000280e78.110Remote to remote symbolic links are disabled.
0x4000280f78.11011Formally MSG_SYMLINK_USING_GP_KEY
0x4000281078.11011Formerly MSG_SHORT_NAME_USING_GP_KEY
0x4000281178.11011RM State: Not Started
0x4000281278.11011RM State: Starting
0x4000281378.11011RM State: Active
0x4000281478.11011RM State: Shutting Down
0x4000281578.11011RM State: Invalid
0x4000281678.11011NOTE: This RM will reset its metadata the next time it starts.
0x400028178.110Usage : fsutil repair set Valid Values: 0 - Disable general repair. 1 - Enable general repair. 9 - Enable repair and warn about potential data loss. 0x10 - Disable repair and bugcheck once on first corruption. Before this option can be set you must enable BugCheckOnCorrupt mode and then reboot. To enable: fsutil behavior set BugcheckOnCorrupt 1 Eg: fsutil repair set C: 0 fsutil repair set C: 1 fsutil repair set C: 9 fsutil repair set C: 0x10
0x400028188.110Self healing state on %1!s! has been changed to: 0x%2!x! Values: 0x1 - Enable general repair. 0x9 - Enable repair and warn about potential data loss. 0x10 - Disable repair and bugcheck once on first corruption.
0x400028198.110Self healing state on %1!s! is: 0x%2!x! Values: 0x1 - Enable general repair. 0x9 - Enable repair and warn about potential data loss. 0x10 - Disable repair and bugcheck once on first corruption.
0x4000281a10Usage : fsutil behavior query
0x4000281b10Usage : fsutil behavior set
0x4000281c10usage : fsutil 8dot3name set [0 through 3] | [ 1 | 0] When a volume is not specified the operation updates the registry value: 0 - Enable 8dot3 name creation on all volumes on the system 1 - Disable 8dot3 name creation on all volumes on the system 2 - Set 8dot3 name creation on a per volume basis 3 - Disable 8dot3 name creation on all volumes except the system volume When a volume is specified the operation updates the individual volume's on disk flag. This operation is only meaningful if the registry value is set to 2. 0 - Enable 8dot3 name creation on this volume 1 - Disable 8dot3 name creation on this volume This operation takes effect immediately (no reboot required). Sample commands: "fsutil 8dot3name set 1" - disable 8dot3 name creation on all volumes "fsutil 8dot3name set C: 1" - disable 8dot3 name creation on c:
0x4000281d10Usage : fsutil resource setConsistent Eg : fsutil resource setConsistent d:\foobar NOTE: The RM must be restarted for a change to this setting to take effect.
0x4000281e10Usage : fsutil resource setAvailable Eg : fsutil resource setAvailable d:\foobar NOTE: The RM must be restarted for a change to this setting to take effect.
0x4000281f78.11011RM prefers consistency over availability.
0x4000282078.11011RM prefers availability over consistency.
0x400028228.110The volume state is: 1 (8dot3 name creation is disabled).
0x400028238.110The volume state is: 0 (8dot3 name creation is enabled).
0x400028248.110The registry state is: 0 (Enable 8dot3 name creation on all volumes).
0x400028258.110The registry state is: 1 (Disable 8dot3 name creation on all volumes).
0x400028268.110The registry state is: 2 (Per volume setting - the default).
0x400028278.110The registry state is: 3 (Disable 8dot3 name creation on all non-system volumes).
0x4000282810Based on the above settings, 8dot3 name creation is enabled on %1
0x4000282910Based on the above settings, 8dot3 name creation is disabled on %1
0x4000282a78.110Based on the above two settings, 8dot3 name creation is enabled on %1 (System volume).
0x4000282b78.110Based on the above two settings, 8dot3 name creation is disabled on %1 (Non-system volume).
0x4000282c78.11011Only privileged users can perform this operation.
0x4000282d78.11011Registry Data Registry Key Path ------------------------------------------------------------------------------- ------------------------------------------
0x4000282e78.11011%1!-80ws! HKCU\%2
0x4000282f78.11011%1!-80ws! HKU\%2
0x4000283078.11011%1!-80ws! HKCR\%2
0x4000283178.11011%1!-80ws! HKLM\%2
0x4000283278.11011%1!-80ws! HKCC\%2
0x4000283378.11011%1!-80ws! HKPD\%2
0x4000283478.11011Total affected registry keys: %1!10d!
0x4000283578.11011Total files and directories scanned: %1!10d! Total 8dot3 names found: %2!10d! Total 8dot3 names stripped: %3!10d!
0x4000283678.110118dot3 Name FileId Full Path ------------- ------------------- -------------------------------------------------------------------------------------
0x4000283778.11011%1!-15.15ws! 0x%2!-16.16ws! "%3"
0x4000283878.11011Error removing short name from "%2": %1!8x! %3
0x4000283978.11011Error accessing "%2": %1!8x! %3
0x4000283a78.11011Error writing to the log. This operation has been aborted.
0x4000283b78.11011The directory path is too long.
0x4000283c78.11011The operation failed because registry entries refer to 8dot3 names in the specified path. For details on the affected registry keys please see the log: "%1"
0x4000283d78.11011For details on the operations performed please see the log: "%1"
0x4000283e78.11011Please input a valid directory.
0x4000283f78.11011Stripping 8dot3 names on the system volume is not allowed.
0x4000284078.11011Error creating the log file.
0x4000284178.11011Error parsing the volume.
0x4000284278.11011Stripping will not be performed on files with names longer than the maximum path length.
0x4000284378.11011Some registry keys will not be scanned because their names are too long.
0x4000284478.11011Scanning registry...
0x4000284578.11011Scanning 8dot3 names...
0x4000284678.11011Stripping 8dot3 names...
0x4000284778.11011Error creating the default log file. Please enter fsutil 8dot3name strip /? to learn how to specify a log file name.
0x4000284878.11011Error parsing the target directory.
0x4000284978.11011Due to an error, the strip command did not complete.
0x4000284a78.11011Could not open the target directory.
0x4000284b78.11011Invalid registry hive.
0x4000284c78.11011Supports Hard Links
0x4000284d78.11011Supports Extended Attributes
0x4000284e78.11011Supports Open By FileID
0x4000285078.110Warning: You are about to strip shortnames on the system volume. This is not recommended as it might cause unexpected behaviour of installed applications including the inability to uninstall. This may result in a system that might need to be reinstalled from scratch.
0x4000285110Usage : fsutil 8dot3name query [] When no volume is specified the global 8dot3name state is displayed. When volume is specified the volumes 8dot3name state is displayed. Sample command: "fsutil 8dot3name query" "fsutil 8dot3name query C:"
0x4000285278.110Usage : fsutil 8dot3name strip DirectoryPath This command permanently removes 8dot3 file names from your volume. It will list the registry keys pointing to the stripped 8dot3names but will not modify the affected registry keys. Stripping will not be performed on files with full path names longer than the maximum path length of 260 characters. ***WARNING*** If there are affected registry keys and you decide to use the override switch /f, it is recommended that you backup your volume as it may lead to unexpected application failures, including the inability to uninstall. /t - Test mode - specifies that all operations should be performed except the actual stripping of the file names. /s - Recurse mode - specifies that this operation should also be applied to subdirectories. /f - Force mode - specifies that the directory should be stripped even if there are registry conflicts. /v - Verbose mode - specifies that all information logged should also be printed out to the console. /l - Specifies a log file to write to. This must be followed by a path to the log file. If this option is not specified the log file will be: "% emp%\8dot3_removal_log@(GMT YYYY-MM-DD HH-MM-SS).log" Sample command: "fsutil 8dot3name strip /l mylogfile.log /s D:\MyData"
0x4000285378.110NOTE: Changes to this setting require a reboot to take effect.
0x4000285478.11011Supports USN Journal
0x4000285510Usage : fsutil volume queryCluster [ ...] Eg : fsutil volume queryCluster C: 50 0x2000 Attribute Value defintions: ----- ^^^^^ |||||- D = Data Attribute, I=Index Attribute, S=System Attribute, ?=Unknown ||||-- A = Deny defrag requests |||--- T = TxF system file ||---- S = NTFS System Metadata File |----- P = Page File
0x400028568.11011Cluster 0x%1!016I64x! used by %2!s! %3!s!
0x4000285778.110---- 8DOT3NAME Commands Supported ---- query Query the current setting for the shortname behaviour on the system scan Scan for impacted registry entries set Change the setting that controls the shortname behavior on the system strip Remove the shortnames for all files within a directory
0x4000285810Usage : fsutil file queryFileID Eg : fsutil file queryFileID C:\testfile.txt
0x4000285910Usage : fsutil file queryFileNameById Eg : fsutil file queryFileNameById C:\ 0x00040000000001bf
0x4000285a78.110Usage : fsutil hardlink list Eg : fsutil hardlink list c:\foo.txt
0x4000285b8.11011File ID is 0x%1
0x4000285c78.11011A random link name to this file is %1!s!
0x4000285d78.110NOTE: %1 is currently controlled by group policy. Changes to this setting will be superceded by policy.
0x4000285e78.110NOTE: %1 is currently controlled by group policy. It can only be changed through policy.
0x4000285f78.110Usage : fsutil 8dot3name scan DirectoryPath This command scans the specified directory path looking for registry keys that might be impacted if short names were stripped from this path. /s - Recurse mode - specifies that this operation should also be applied to subdirectories. /v - Verbose mode - specifies that all information logged should also be printed out to the console. /l - Specifies a log file to write to. This must be followed by a path to the log file. If this option is not specified the log file will be: "% emp%\8dot3_removal_log@(GMT YYYY-MM-DD HH-MM-SS).log" Sample command: "fsutil 8dot3name scan /l mylogfile.log /s D:\MyData"
0x400028608.11011---- SECURITY Commands Supported ---- enumsds Enumerate security descriptors stats Display security file statistics
0x400028618.110Usage : fsutil security enumsds [options] [offset [count]] Eg : fsutil security enumsds C: This command displays the contents of the NTFS security descriptor stream. By default every security descriptor starting from the beginning of the stream will be displayed. You can optionally provide a starting byte offset within the stream, and limit the maximum number of security descriptors to display. Options: /bare Display no extraneous output other than security descriptors. /flags Describe individual flag bits in human readable form (no effect if used with /sddl). /sddl Display security descriptors in a compact SDDL form, useful for automated processing (especially with /bare). Without this option, security descriptors are displayed in a human readable form.
0x400028628.110Usage : fsutil security stats Eg : fsutil security stats C:
0x400028638.110Successfully enabled 8dot3name generation on %1!s!
0x400028648.110Successfully disabled 8dot3name generation on %1!s!
0x400028658.11011An unexpected value was encountered.
0x400028668.11011The registry state is now: 0 (Enable 8dot3 name creation on all volumes).
0x400028678.11011The registry state is now: 1 (Disable 8dot3 name creation on all volumes).
0x400028688.11011The registry state is now: 2 (Per volume setting - the default).
0x400028698.11011The registry state is now: 3 (Disable 8dot3 name creation on all non-system volumes).
0x4000286a10Usage : fsutil file queryExtents [/R] [ []] [csv] /R : If is a reparse point, open it rather than its target : First VCN to query (if omitted, start at VCN 0) : Number of VCNs to query (if omitted or 0, query until EOF) csv : Display the result in csv format Eg : fsutil file queryExtents C:\Temp\sample.txt fsutil file queryExtents /R C:\Temp\sample.txt fsutil file queryExtents C:\Temp\sample.txt 10 fsutil file queryExtents C:\Temp\sample.txt 10 100 fsutil file queryExtents C:\Temp\sample.txt csv
0x4000286b8.11011No extents matching specified range.
0x4000286c8.11011VCN: 0x%1!-8I64x! Clusters: 0x%2!-8I64x! LCN: 0x%3!I64x!
0x4000286d8.110Usage : fsutil repair state [] Eg : fsutil repair state C:
0x4000286e8.11011Is ReadOnly
0x4000286f8.11011Is ReadWrite
0x4000287010(translates to a zone size of %1!u! MB)
0x400028711011A local NTFS or ReFS volume is required for this operation.
0x400028728.11011Offset: 0x%1!-8I64x! Length: 0x%2!-8I64x! Usage: %3!s!
0x4000287310Usage : fsutil file queryValidData [/R] [/D] /R : If is a reparse point, open it rather than its target /D : Display detailed valid data information Eg : fsutil file queryValidData C:\testfile.txt
0x400028748.11011Global Corruption State: 0x%1!02x! - %2
0x400028758.11011Volume Name: %1 (%2) Corruption State: 0x%3!02x! - %4
0x400028768.11011Clean
0x400028778.11011Full Chkdsk Needed
0x400028788.11011Spot Fix Needed
0x400028798.11011Online Scan Needed
0x4000287a8.11011Spot Verify Needed
0x4000287b10Usage : fsutil fsInfo sectorInfo Eg : fsutil fsInfo sectorInfo C:
0x4000287c8.11011LogicalBytesPerSector : %1!d! PhysicalBytesPerSectorForAtomicity : %2!d! PhysicalBytesPerSectorForPerformance : %3!d! FileSystemEffectivePhysicalBytesPerSectorForAtomicity : %4!d! Device Alignment : %5 Partition alignment on device : %6
0x4000287d8.11011Aligned (0x%1!.3x!)
0x4000287e8.11011Not Aligned (0x%1!.3x!)
0x4000287f8.11011Unknown
0x400028808.11011**** Online Scan is currently running ****
0x400028818.11011**** Online Scan is currently running on this volume ****
0x400028828.11011Volume Name: %1 (%2) NTFS log recovery is not required.
0x400028838.11011NTFS log recovery performed.
0x400028848.11011Volume Name: %1 (%2) NTFS log recovery is required.
0x400028858.11011Valid Data
0x400028868.11011Not Valid Data
0x400028878.11011Valid Data Length is 0x%1!I64x! (%1!I64d!)
0x400028888.11011Minimum record version supported : %1!d! Maximum record version supported : %2!d!
0x400028898.11011No Seek Penalty
0x4000288a8.11011Performs Normal Seeks
0x4000288b8.11011Trim Supported
0x4000288c8.11011Trim Not Supported
0x4000288d1011---- TIERING Commands Supported ---- clearFlags Disable tiering behavior flags of a volume queryFlags Display the tiering behavior flags of a volume regionList List the regions of a volume and their respective storage tiers setFlags Enable tiering behavior flags of a volume tierList List the storage tiers associated with a volume
0x4000288e10Usage : fsutil tiering queryFlags Eg : fsutil tiering queryFlags D:
0x4000288f8.11011----------------- Legend for flags: ----------------- /TrNH NTFS and ReFS Only: For volumes with tiered storage, causes Heat gathering to be disabled.
0x4000289010Usage : fsutil tiering setFlags Eg : fsutil tiering setFlags C: /TrNH
0x4000289110Usage : fsutil tiering clearFlags Eg : fsutil tiering clearFlags E: /TrNH
0x4000289210Usage : fsutil tiering tierList Eg : fsutil tiering tierList X:
0x4000289310Usage : fsutil tiering regionList Eg : fsutil tiering regionList F:
0x400028948.11011*NONE*
0x400028958.11011Current flags on volume "%1!s!" :
0x400028968.11011Error! Invalid tiering flag: %1!s!
0x400028978.11011Error! Repeated tiering flag: %1!s!
0x400028988.11011Enabling flags:
0x400028998.11011Disabling flags:
0x4000289a8.11011Total Number of Storage Tiers for this volume: %1!d!
0x4000289b8.11011Total Number of Storage Tiers returned by this operation: %1!d!
0x4000289c8.11011Tier # %1!d!:
0x4000289d8.11011Tier ID: %1!s!
0x4000289e8.11011Name: %1!s!
0x4000289f8.11011Description: %1!s!
0x400028a08.11011Flags: 0x%1!08x!
0x400028a18.11011Provisioned Capacity: 0x%1!016I64x! bytes
0x400028a28.11011Media Type:
0x400028a38.11011*unspecified*
0x400028a48.11011HDD
0x400028a58.11011SSD
0x400028a68.11011NVME
0x400028a78.11011NVDIMM
0x400028a88.11011Total Number of Regions for this volume: %1!d!
0x400028a98.11011Total Number of Regions returned by this operation: %1!d!
0x400028aa8.11011Region # %1!d!:
0x400028ab8.11011Offset: 0x%1!016I64x!
0x400028ac8.11011Length: 0x%1!016I64x!
0x400028ad8.11011Write range tracking: Enabled Write range tracking chunk size: %1!I64d! Write range tracking file size threshold: %2!I64d!
0x400028ae8.11011Write range tracking: Disabled
0x400028af10Usage : fsutil usn enableRangeTracking [c= s=] Eg : fsutil usn enableRangeTracking c=16384 s=67108864 C: Eg : fsutil usn enableRangeTracking c=0 s=0 C: Eg : fsutil usn enableRangeTracking C:
0x400028b010---- Commands Supported ---- 8dot3name 8dot3name management behavior Control file system behavior dax Dax volume management dirty Manage volume dirty bit file File specific commands fsInfo File system information hardlink Hardlink management objectID Object ID management quota Quota management repair Self healing management reparsePoint Reparse point management resource Transactional Resource Manager management sparse Sparse file control tiering Storage tiering property management transaction Transaction management usn USN management volume Volume management wim Transparent wim hosting management
0x400028b110Usage : fsutil volume fileLayout [options] * fsutil volume fileLayout [options] fsutil volume fileLayout [options] Options: /v Verbose mode - displays attribute buffer hex dump for $EA and $REPARSE_POINT. Eg : fsutil volume fileLayout C: * Eg : fsutil volume fileLayout C: 5 Eg : fsutil volume fileLayout C: 0x00040000000001bf Eg : fsutil volume fileLayout C:\$MFT Eg : fsutil volume fileLayout C:\Windows Eg : fsutil volume fileLayout /v C:\windows
0x400028b28.11011No file entries returned
0x400028b38.11011********* File 0x%1!016I64x! ********* File reference number : 0x%1!016I64x! File attributes : 0x%2!08x!: %3!s! File entry flags : 0x%4!08x!
0x400028b48.11011Extra information not present.
0x400028b51011Creation Time : %1!s! Last Access Time : %2!s! Last Write Time : %3!s! Change Time : %4!s! LastUsn : %5!s! OwnerId : %6!d! SecurityId : %7!d!
0x400028b68.11011File name information not present.
0x400028b88.11011Streams information not present.
0x400028b91011Stream : 0x%8!03x! %1!s! Attributes : 0x%2!08x!: %3!s! Flags : 0x%4!08x!: %5!s! Size : %6!s! Allocated Size : %7!s!
0x400028ba8.11011Unknown %1!s! version. Expected %2!d!, found %3!d!.
0x400028bb8.11011Extent information not present.
0x400028bc8.11011Extent information was returned in an unknown format.
0x400028bd1011Extents : %1!s! Extents
0x400028be1011: %1!s!: VCN: %2!s! Clusters: %3!s! LCN: %4!s!
0x400028bf10Usage : fsutil volume allocationReport [tier=] Options: tier= - List allocation report on specific tier class, can be either performance or capacity Eg : fsutil volume allocationReport C: fsutil volume allocationReport C: tier=performance fsutil volume allocationReport C: tier=capacity
0x400028c010Total clusters : %1!*s! (%2!*s! bytes) %3!*s!%4!s! Free clusters : %5!*s! (%6!*s! bytes) %7!*s!%8!s! Reserved clusters : %9!*s! (%10!*s! bytes) %11!*s!%12!s! Allocated clusters : %13!*s! (%14!*s! bytes) %15!*s!%16!s! Cluster Size : %19!d! Bytes The allocation is split between: System files : Count: %17!s! Allocated: %18!s! bytes
0x400028c110%1!-24s!: FileID: 0x%2!016I64x! Allocated: %3!s! bytes
0x400028c210Other system files : Count: %1!s! Allocated: %2!s! bytes
0x400028c310Other system files under %1!s! folder: Count : %2!s! Allocated : %3!s! bytes
0x400028c410%1!-28s!: Allocated: %2!s! bytes Files : Count: %3!s! Allocated: %4!s! bytes Folders : Count: %5!s! Allocated: %6!s! bytes
0x400028c51011User files : Count: %1!s! Allocated: %2!s! bytes (%3!s!%4!s!)
0x400028c61011User folders : Count: %1!s! Allocated: %2!s! bytes (%3!s!%4!s!)
0x400028c71011Default streams : %1!s! With allocation : %2!s! Space allocated : %3!s! bytes (%10!s!%11!s!) Named streams : %4!s! With Allocation : %5!s! Space allocated : %6!s! bytes (%12!s!%13!s!) Local metadata streams : %7!s! With Allocation : %8!s! Space allocated : %9!s! bytes (%14!s!%15!s!)
0x400028c88.11011Within these files there are:
0x400028c98.11011Within these folders there are:
0x400028ca1011Compressed : %1!s! Total allocated : %2!*s! bytes (%3!*s!%4!s!) Total size : %5!*s! bytes (%6!*s!%7!s!) Savings : %8!s!% Sparse : %9!s! Total allocated : %10!*s! bytes (%11!*s!%12!s!) Total size : %13!*s! bytes (%14!*s!%15!s!) Savings : %16!s!% Encrypted : %17!s! Total allocated : %18!s! bytes (%19!s!%20!s!) With named streams : %21!s! Compressed : %22!s! Sparse : %23!s! Encrypted : %24!s! With no allocation : %25!s!
0x400028cb1011Usage : fsutil usn readJournal [options] Options : minVer= - Minimum Major Version of USN_RECORD to return. Default=2. : maxVer= - Maximum Major Version of USN_RECORD to return. Default=4. : startUsn= - USN to start reading the USN journal from. Default=0. : csv - Print the USN records in CSV format. : wait - wait for more records to be added to the USN journal. : tail - starts reading at the end of the USN journal. If wait is not specified it will just return. Overrides any startusn value. Eg : fsutil usn readJournal C: : fsutil usn readJournal C: minVer=2 maxVer=3 startUsn=88 : fsutil usn readJournal C: startUsn=0xF00 : fsutil usn readJournal C: wait : fsutil usn readJournal C: wait tail : fsutil usn readJournal C: csv
0x400028cc8.11011USN Journal ID : 0x%1!016I64x! First USN : %2!I64d! Next USN : %3!I64d! Start USN : %4!I64d! Min major version : Supported=%5!d!, requested=%6!d! Max major version : Supported=%7!d!, requested=%8!d!
0x400028cd8.11011Usn : %1!I64d! File name : %2!.*ws! File name length : %3!d! Reason : 0x%4!08x!: %5!s! Time stamp : %6!s! File attributes : 0x%7!08x!: %8!s! File ID : %9!s! Parent file ID : %10!s! Source info : 0x%11!08x!: %12!s! Security ID : %13!d! Major version : %14!hu! Minor version : %15!hu! Record length : %16!u!
0x400028ce8.11011Usn : %1!I64d! Reason : 0x%2!08x!: %3!s! File ID : %4!s! Parent file ID : %5!s! Source info : 0x%6!08x!: %7!s! Major version : %8!hu! Minor version : %9!hu! Record length : %10!u! Number of extents : %11!hu! Remaining extents : %12!hu! Extents :
0x400028cf8.11011Major version : %1!hu! Minor version : %2!hu! Record length : %3!u!
0x400028d08.11011Usn,File name,File name length,Reason #,Reason,Time stamp,File attributes #,File attributes,File ID,Parent file ID,Source info #,Source info,Security ID,Major version,Minor version,Record length,Number of extents,Remaining extents,Extent,Offset,Length
0x400028d11011(Enabled)
0x400028d21011(Disabled)
0x400028d310(System Managed, Enabled)
0x400028d410(System Managed, Disabled)
0x400028d510(User Managed, Enabled)
0x400028d610(User Managed, Disabled)
0x400028d71011(Seconds)
0x400028d810Usage: fsutil behavior set disableLastAccess <0-3> Values: 0x0 - User Managed, Last Access Updates Enabled 0x1 - User Managed, Last Access Updates Disabled 0x2 - System Managed, Last Access Updates Enabled 0x3 - System Managed, Last Access Updates Disabled - When "System Managed" is enabled it allows the system to enable/disable last access time updates based on system policy. - If group policy is in effect or this registry key is uninitialized then the "System Managed" state can not be set and is not displayed.
0x400028d910Usage: fsutil behavior query disableWriteAutoTiering Values: 0 - Write auto tiering is enabled on the given volume 1 - Write auto tiering is disabled on the given volume
0x400028da10Usage: fsutil behavior set disableWriteAutoTiering <1|0> Values: 0 - Enable write auto tiering on the given volume (default) 1 - Disable write auto tiering on the given volume Eg: fsutil behavior set disableWriteAutoTiering C: 1
0x400028db10Usage: fsutil behavior set bugCheckOnCorrupt <1|0> Values: 0 - Bug checking when a corruption is detect is disabled. (default) 1 - Bug checking when a corruption is detect is enabled.
0x400028dc10Usage: fsutil behavior set disableCompression <1|0> Values: 0 - NTFS compression support is enabled. (default) 1 - NTFS compression support is disabled.
0x400028dd1011Usage: fsutil behavior query enableReallocateAllDataWrites Values: 0 - Reallocating all data writes is disabled on the given volume 1 - Reallocating all data writes is enabled on the given volume
0x400028de10Usage: fsutil behavior set enableReallocateAllDataWrites <1|0> Values: 0 - Disable Reallocating all data writes on the given volume (default) 1 - Enable Reallocating all data writes on the given volume Eg: fsutil behavior set enableReallocateAllDataWrites C: 1
0x400029038.11011*NONE*
0x400029048.11011Read only
0x400029058.11011Hidden
0x400029068.11011System
0x400029078.11011Directory
0x400029088.11011Archive
0x400029098.11011Normal
0x4000290a8.11011Temporary
0x4000290b8.11011Sparse
0x4000290c8.11011Reparse point
0x4000290d8.11011Compressed
0x4000290e8.11011Offline
0x4000290f8.11011Not content indexed
0x400029108.11011Encrypted
0x400029118.11011Integrity stream
0x400029128.11011Virtual
0x400029138.11011No scrub data
0x400029148.11011Immovable
0x400029158.11011Pinned
0x400029168.11011Resident
0x400029178.11011No clusters allocated
0x400029188.11011Data overwrite
0x400029198.11011Data extend
0x4000291a8.11011Data truncation
0x4000291b8.11011Named data overwrite
0x4000291c8.11011Named data extend
0x4000291d8.11011Named data truncation
0x4000291e8.11011File create
0x4000291f8.11011File delete
0x400029208.11011EA change
0x400029218.11011Security change
0x400029228.11011Rename: old name
0x400029238.11011Rename: new name
0x400029248.11011Indexable change
0x400029258.11011Basic info change
0x400029268.11011Hard link change
0x400029278.11011Compression change
0x400029288.11011Encryption change
0x400029298.11011Object ID change
0x4000292a8.11011Reparse point change
0x4000292b8.11011Stream change
0x4000292c8.11011Transacted change
0x4000292d8.11011Integrity change
0x4000292e8.11011Close
0x4000292f8.11011Data management
0x400029308.11011Auxiliary
0x400029318.11011Replication management
0x400029328.11011Client replication management
0x400029338.110Error! Flags not supported by this operation on volume %1:
0x400029341011---- WIM Commands Supported ---- enumFiles Enumerate WIM backed files enumWims Enumerate backing WIM files removeWim Remove a WIM from backing files queryFile Query the origin of a specific file
0x400029358.11011Objects enumerated: %1!I64d!
0x400029368.11011This file is not a WIM backed file.
0x400029378.11011%1!s! failed:
0x400029388.11011Wim DataSource: %1!I64d! Wim Hash: %2!s!
0x400029398.11011Wim State: NOT ACTIVE
0x4000293a8.11011Wim State: SUSPENDED
0x4000293b8.11011Wim State: UNKNOWN
0x4000293c8.11011Wim State: Operational
0x4000293d10Usage : fsutil wim queryFile Eg : fsutil wim queryFile C:\Windows\Notepad.exe
0x4000293e10Usage : fsutil wim enumWims Eg : fsutil wim enumWims C:
0x4000293f10Usage : fsutil wim enumFiles Eg : fsutil wim enumFiles C: 0
0x4000294010Usage : fsutil wim removeWim Eg : fsutil wim removeWim C: 9
0x400029411011Cannot remove a wim while files still refer to it. Use "fsutil wim enumFiles" to display the list of files.
0x4000294210Usage : fsutil fsInfo refsInfo [Flags] /r : Reset ReFS statistics to zero Eg : fsutil fsInfo refsInfo C:
0x4000294310REFS Volume Serial Number : 0x%1 REFS Version : %2!d!.%3!d! Number Sectors : 0x%4 Total Clusters : 0x%5 Free Clusters : 0x%6 Total Reserved : 0x%7 Bytes Per Sector : %8!d! Bytes Per Physical Sector : %10!d! Bytes Per Cluster : %9!d! Fast Tier Data Fill Percentage : %11!d!.%12!d!% Slow Tier Data Fill Percentage : %13!d!.%14!d!% Fast Tier to Slow Tier Rate (Clusters/s) : %15!d!
0x400029441011A local REFS volume is required for this operation.
0x4000294510CHECKSUM_TYPE_NONE
0x4000294610CHECKSUM_TYPE_CRC32
0x4000294710CHECKSUM_TYPE_CRC64
0x4000294810CHECKSUM_TYPE_ECC
0x4000294910Checksum Type :
0x4000294a10Usage: fsutil file optimizeMetadata [/A] /A : Analyze file metadata before and after optimization Eg: fsutil file optimizeMetadata c:\largefragmentedfile.txt Eg: fsutil file optimizeMetadata c:\$Secure:$SDS Eg: fsutil file optimizeMetadata c:\$MFT Eg: fsutil file optimizeMetadata c:\
0x4000294b10Usage: fsutil file queryOptimizeMetadata Eg: fsutil file queryOptimizeMetadata c:\largefragmentedfile.txt Eg: fsutil file queryOptimizeMetadata c:\$Secure:$SDS Eg: fsutil file queryOptimizeMetadata c:\$MFT Eg: fsutil file queryOptimizeMetadata c:\
0x4000294c1011File metadata optimization : None
0x4000294d1011File metadata optimization : In progress
0x4000294e1011File metadata optimization : Pending
0x4000294f1011File metadata optimization : Unknown (%1!d!)
0x400029501011Attribute list size : %1!u! (%1!#x!) File metadata space used : %2!u! (%2!#x!) File metadata space allocated : %3!u! (%3!#x!) File metadata space usage : %4!u!% File records count(s) : %5!u! Number of resident attribute(s) : %6!u! Number of nonresident attribute(s) : %7!u! Total number of attributes : %8!I64u! Total active file metadata optimization(s) : %9!u! Total pending file metadata optimization(s) : %10!u!
0x400029511011File metadata optimization completed.
0x400029521011Before After Attribute list size : %1!u! (%1!#x!) %9!*u! (%10!#x!) File metadata space used : %2!u! (%2!#x!) %11!*u! (%12!#x!) File metadata space allocated : %3!u! (%3!#x!) %13!*u! (%14!#x!) File metadata space usage : %4!u!% %15!*u!% File records count(s) : %5!-7u! %16!u! Number of resident attribute(s) : %6!-7u! %17!u! Number of nonresident attribute(s) : %7!-7u! %18!u! Total number of attributes : %8!-7I64u! %19!u! Total active file metadata optimization(s) : --- %20!u! Total pending file metadata optimization(s) : --- %21!u!
0x400029531011Usage: fsutil behavior query DisableFileMetadataOptimization
0x4000295410Usage: fsutil behavior set DisableFileMetadataOptimization
0x4000295510Values: 0x0 - Enable all file metadata optimization 0x1 - Disable full file metadata optimization only 0x2 - Disable incremental file metadata optimization only 0x3 - Disable all file metadata optimization
0x400029561011VCN: 0x%1!-8I64x! Clusters: 0x%2!-8I64x! LCN: 0x%3!I64x! All: 0x%4!-8I64x! Pop: 0x%5!-8I64x! Err: 0x%6!-8I64x!
0x400029571011Read Cache Totals Allocated : %1!-8I64u! (0x%1!-8I64x!) Populated : %2!-8I64u! (0x%2!-8I64x!) In Error : %3!-8I64u! (0x%3!-8I64x!)
0x400029581011Cache size in bytes : 0x%1 Cache allocated in bytes : 0x%2 Cache populated in bytes : 0x%3 Cache bytes in error : 0x%4 Cache allocation size in bytes : %5!d! Total cache blocks : %6!d! Cache blocks free : %7!d! Cache blocks in error : %8!d! Cache transactions outstanding : %9!d! Max Cache tx outstanding : %10!d! Cache block allocations : %11!d! Cache invalidations : %12!d! Invalidations in bytes : 0x%13 Cache block initial writes : %14!d! Initial writes in bytes : 0x%15 Cache block updates : %16!d! Cache updates in bytes : 0x%17 Cache over reads in bytes : 0x%18 Cache hits : %19!d! Bytes read from cache : 0x%20 Cache misses : %21!d! Bytes read for misses : 0x%22 Cache hit rate as percentage : %23!d! Metadata size in bytes : 0x%24 Metadata bytes written : 0x%25
0x400029591011Flags: 0x%1!08x! No Seek Penalty
0x4000295a1011Flags: 0x%1!08x! Read Cache
0x4000295b1011This volume has container rotation active.
0x4000295c10The volume state is: 1 (write auto tiering is disabled).
0x4000295d10The volume state is: 0 (write auto tiering is enabled).
0x4000295f1011Total free bytes : %1!*s! (%2!*s!%3!s!) Total bytes : %4!*s! (%5!*s!%6!s!) Total quota free bytes : %7!*s! (%8!*s!%9!s!) Total metadata bytes : %10!*s! (%11!*s!%12!s!)
0x400029601011MftReads : %1 MftReadBytes : %2 MftWrites : %3 MftWriteBytes : %4 Mft2Writes : %5 Mft2WriteBytes : %6 RootIndexReads : %7 RootIndexReadBytes : %8 RootIndexWrites : %9 RootIndexWriteBytes : %10 BitmapReads : %11 BitmapReadBytes : %12 BitmapWrites : %13 BitmapWriteBytes : %14 MftBitmapReads : %15 MftBitmapReadBytes : %16 MftBitmapWrites : %17 MftBitmapWriteBytes : %18 UserIndexReads : %19 UserIndexReadBytes : %20 UserIndexWrites : %21 UserIndexWriteBytes : %22 LogFileReads : %23 LogFileReadBytes : %24 LogFileWrites : %25 LogFileWriteBytes : %26 LogFileFull : %27 DiskResourceFailure : %28 VolumeTrimCount : %29 AvgVolumeTrimTime (ms) : %30 AvgVolumeTrimSize (KB) : %31 AvgVolumeTrimSpeed (KB/s) : %32 VolumeTrimSkippedCount : %33 VolumeTrimSkippedSize (KB) : %34 FileLevelTrimCount : %35 AvgFileLevelTrimTime (ms) : %36 AvgFileLevelTrimSize (KB) : %37 AvgFileLevelTrimSpeed (KB/s) : %38 NtfsFillStatInfoFromMftRecordCalledCount : %39 NtfsFillStatInfoFromMftRecordBailedBecauseOfAttributeListCount : %40 NtfsFillStatInfoFromMftRecordBailedBecauseOfNonResReparsePointCount : %41
0x400029611011File System Type : REFS
0x400029621011File System Type : ExFAT
0x400029631011File System Type : UNKNOWN
0x400029641011The FSUTIL utility requires a local NTFS/ReFS/FAT/FAT32/ExFAT volume for this operation.
0x400029651011CreateHits : %1 SuccessfulCreates : %2 FailedCreates : %3 NonCachedReads : %4 NonCachedRead Bytes : %5 NonCachedWrites : %6 NonCachedWrite Bytes : %7 NonCachedDiskReads : %8 NonCachedDiskWrites : %9
0x400029661011Is DAX volume
0x400029681011DAX capable
0x400029691011Not DAX capable
0x4000296a10Successfully disabled TxF on %1!s!
0x4000296b10Successfully enabled TxF on %1!s!
0x4000296c10The volume state is: 1 (TxF is disabled).
0x4000296d10The volume state is: 0 (TxF is enabled).
0x4000296e10usage : set 1 | 0 The operation updates the individual volume's on disk flag. 0 - Enable TxF on this volume 1 - Disable TxF on this volume This operation takes effect immediately (no reboot required). Sample commands: "fsutil behavior set DisableTxf C: 1" - disable TxF on c:
0x4000296f10usage : query Volumes txf state is displayed. Sample command: "fsutil behavior query DisableTxf C:"
0x400029701011Supports Integrity Streams
0x400029711011Supports Block Cloning
0x400029721011Supports Sparse VDL
0x400029731011Supports File Ghosting
0x4000297410Usage : fsutil file setEOF Eg : fsutil file setEOF C:\testfile.txt 1000
0x400029751011File %1!s! eof set
0x4000297610Usage : fsutil volume list
0x400029771011Possible volumes and current mount points are:
0x400029781011Stream information data not present.
0x400029791011DSC : Tier Class: %1!s! : Flags: 0x%2!08x!: %3!s!
0x4000297a1011Desired Storage Class change
0x4000297b1011Unspecified
0x4000297c1011Capacity
0x4000297d1011Performance
0x4000297e1011NVME
0x4000297f1011NVDIMM
0x400029801011Shingled Disk
0x400029811011Mixed Read Optimized
0x400029821011Slowest
0x400029831011Fastest
0x400029841011Mandatory
0x400029851011Maximum
0x400029861011Minimum
0x400029871011Can be promoted
0x400029881011Can be demoted
0x400029891011Inherited from parent
0x4000298a1011Inherited from volume
0x4000298b1011Has Parsed Information
0x4000298c1011Link (ParentID: Name) : 0x%1!016I64x!: %2!-13s!: %3!s!
0x4000298d1011DOS Name
0x4000298e1011NTFS Name
0x4000298f1011HLINK Name
0x400029901011Returns Handle Close Result Information
0x400029911011Stream Optimal Write Size : 0x%1!x! Stream Granularity Size : 0x%2!x! Minimum Stream ID : 0x%3!x! Maximum Stream ID : 0x%4!x!
0x400029921011VCN: 0x%1!-8I64x! Clusters: 0x%2!-8I64x! LCN: 0x%3!-8I64x! Ref: 0x%4!-5x! All: 0x%5!-8I64x! Pop: 0x%6!-8I64x! Err: 0x%7!-8I64x!
0x400029931011VCN: 0x%1!-8I64x! Clusters: 0x%2!-8I64x! LCN: 0x%3!-8I64x! Ref: 0x%4!-5x!
0x4000299410Usage : fsutil file queryExtentsAndRefCounts [/R] [ []] /R : If is a reparse point, open it rather than its target : First VCN to query (if omitted, start at VCN 0) : Number of VCNs to query (if omitted or 0, query until EOF) Eg : fsutil file queryExtentsAndRefCounts C:\Temp\sample.txt
0x400029951011However, the volume does not support TxF.
0x400029961011However, being a DAX volume TxF is not supported.
0x4000299710Usage : fsutil volume queryNumaInfo Eg : fsutil volume queryNumaInfo c:
0x400029981011The given volume is in Numa node: %1!u!
0x400029991011NTFS+DOS Name
0x4000299a10Cluster Count % of Tier ------------- --------- Size of randomly writable tier : %1 %2 %3!#16I64x! Free space in randomly writable tier : %4 %5 %6!#16I64x! %7!3d!% Size of SMR tier : %8 %9 %10!#16I64x! Free space in SMR tier : %11 %12 %13!#16I64x! %14!3d!% Usable free space in SMR tier : %15 %16 %17!#16I64x! %18!3d!% Recoverable Cluster(s)* : %19 %20 %21!#16I64x! %22!3d!% Free Space Efficiency : %23!d!%
0x4000299b10Garbage collection state (last status) : Inactive (%1!x!)
0x4000299c10Garbage collection state : Paused
0x4000299d10Garbage collection state : Active
0x4000299e10Garbage collection state : Active Full Speed
0x4000299f10Garbage collection state : Unknown
0x400029a010Usage : fsutil volume smrInfo Eg : fsutil volume smrInfo C:
0x400029a110Usage : fsutil volume smrGC Action=start IoGranularity= fsutil volume smrGC Action={startfullspeed|pause|stop} Eg : fsutil volume smrGC D: Action=start IoGranularity=0x10000
0x400029a21011Tier Class:
0x400029a31011Pinned
0x400029a41011Unpinned
0x400029a51011Recall on data access
0x400029a61011Supports POSIX-style Unlink and Rename
0x400029a710Usage : fsutil file setStrictlySequential Eg : fsutil file setStrictlySequential C:\testfile.txt
0x400029a81011File %1!s! set strictly sequential
0x400029a91011Zero-length file required for this operation.
0x400029aa1011KB
0x400029ab1011MB
0x400029ac1011GB
0x400029ad1011TB
0x400029ae1011* Note that up to %1!d! MB (%2!d! SMR Bands) of recoverable clusters may not be garbage collectible.
0x400029af1011Tag value: Directory
0x400029b01011---- DAX Commands Supported ---- queryFileAlignment Query file alignment on dax volume
0x400029b11011Usage : fsutil dax queryFileAlignment [options] Options : q= - Query flag, see value options below: (Default is both) value: large - Query for large page alignment. huge - Query for huge page alignment. both - Query for both large and huge page alignment. ** Note: huge page alignment query is limited to 64-bit architectures. n= - Number of output ranges. Default=all ranges. s= - Starting file offset of the range. Default=0. l= - Range length in bytes. Default=MAXLONGLONG-StartOffset. Eg : fsutil dax queryFileAlignment C:\Temp\sample.txt : fsutil dax queryFileAlignment C:\Temp\sample.txt q=large : fsutil dax queryFileAlignment C:\Temp\sample.txt q=huge n=10 : fsutil dax queryFileAlignment C:\Temp\sample.txt q=both s=0x100 l=0x10000 : fsutil dax queryFileAlignment C:\Temp\sample.txt q=both n=10 s=0x100 l=0x10000
0x400029b21011File Region Alignment:
0x400029b31011No Regions were found.
0x400029b41011Region Alignment StartOffset LengthInBytes
0x400029b51011%1!-8d! %2!#-9s! %3!-#18I64x! %4!-#18I64x!
0x400029b610Usage : fsutil file layout [options] Options: /v Verbose mode - displays attribute buffer hex dump for $EA and $REPARSE_POINT. Eg : fsutil file layout C:\testfile.txt : fsutil file layout /v C:\testfile.txt
0x400029b71011VCN: 0x%1!-8I64x! Clusters: 0x%2!-8I64x! LCN: 0x%3!-16I64x! TierClass: %4!s!
0x400029b81011Is Thinly-Provisioned
0x400029b91011Not Thinly-Provisioned
0x400029ba1011Is Thinly-Provisioned, SlabSize : %1!s! bytes (%2!s!%3!s!)
0x400029bb10Usage : fsutil volume thinProvisioningInfo Eg : fsutil volume thinProvisioningInfo C:
0x400029bc1011%1 is not a tiered volume.
0x400029bd1011%1!-20s!: File ID 0x%2!016I64x!. Total allocated: %3!s! bytes.
0x400029be1011Allocation report for "Capacity" tier:
0x400029bf1011Allocation report for "Performance" tier:
0x400029c01011VCN,Clusters,LCN,All,Pop,Err
0x400029c11011VCN,Clusters,LCN,TierClass
0x400029c21011VCN,Clusters,LCN
0x400029c31011Warning: Huge page alignment query is limited to 64-bit architectures.
0x400029c410Usage : fsutil file setCaseSensitiveInfo [flags] flags : enable - Enable case sensitive attribute on (Default value) : disable - Disable case sensitive attribute on Eg : fsutil file setCaseSensitiveInfo C:\TempFolder enable fsutil file setCaseSensitiveInfo C:\TempFolder disable
0x400029c51011Case sensitive attribute on directory %1 is enabled.
0x400029c61011Case sensitive attribute on directory %1 is disabled.
0x400029c710Usage : fsutil file queryCaseSensitiveInfo Eg : fsutil file queryCaseSensitiveInfo C:\TempFolder
0x400029c81011Error: Setting case sensitive attribute on %1 is not supported.
0x400029c91011Error: Invalid Windows Directory encountered.
0x400029ca1011---- STORAGERESERVE Commands Supported ---- query Query storage reserve area(s) of a volume repair Repair storage reserve area(s) of a volume findByID Find files by storage reserve ID
0x400029cb10Usage : fsutil storageReserve define [; ...] : [ []] : storage reserve ID (1 to 15) : the space guarantee in MB (default 0) : optional storage reserve area flags Eg : fsutil storageReserve define C: 1 0x800 ; 2 0x500
0x400029cc10Usage : fsutil storageReserve update [; ...] : [ []] : storage reserve ID (1 to 15) : the space guarantee in MB (default 0) : optional storage reserve area flags Eg : fsutil storageReserve update C: 2 0
0x400029cd10Usage : fsutil storageReserve query [ ...] Eg : fsutil storageReserve query C:
0x400029ce1011Reserve ID: %1!d! Flags: 0x%2!08lx! Space Guarantee: 0x%3!-16I64x!(%4!I64u! MB) Space Used: 0x%5!-16I64x!(%6!I64u! MB)
0x400029cf10Usage : fsutil storageReserve delete [ ...] Eg : fsutil storageReserve delete C:
0x400029d010Usage : fsutil storageReserve repair [ ...] Eg : fsutil storageReserve repair C:
0x400029d11011No storage reserve area(s) found.
0x400029d210Usage : fsutil storageReserve setID Eg : fsutil storageReserve setID C:\testfile.txt 2
0x400029d310Usage : fsutil storageReserve queryID Eg : fsutil storageReserve queryID C:\testfile.txt
0x400029d410Usage : fsutil storageReserve findByID [options] * fsutil storageReserve findByID [options] Options: /v Verbose mode - displays attribute buffer hex dump for $EA and $REPARSE_POINT. Eg : fsutil storageReserve findByID c: * : fsutil storageReserve findByID C: 2 : fsutil storageReserve findByID /v C: 2
0x400029d51011None
0x400029d61011Hard
0x400029d71011Soft
0x400029d81011*UpdateScratch*
0x400029d91011*UNKNOWN*
0x400029da1011*UNKNOWN*
0x400029db1011*UNKNOWN*
0x400029dc1011*UNKNOWN*
0x400029dd1011*UNKNOWN*
0x400029de1011*UNKNOWN*
0x400029df1011*UNKNOWN*
0x400029e01011*UNKNOWN*
0x400029e11011*UNKNOWN*
0x400029e21011*UNKNOWN*
0x400029e31011*UNKNOWN*
0x400029e41011*UNKNOWN*
0x400029e51011*UNKNOWN*
0x400029e61011StorageReserveId : %1!d!
0x400029e71011** BTT (Block Translation Table) enabled on this volume.
0x400029e81011BTT (Block Translation Table) enabled
0x400029e91011PB
0x400029ea10Usage : fsutil volume flush Eg : fsutil volume flush C:
0x400029eb10Usage : fsutil volume queryLabel Eg : fsutil volume queryLabel C:
0x400029ec10Usage : fsutil volume setLabel
0x400029ed1011Volume Label for "%1" is "%2!*.*s!"
0x400029ee10%1!-24s!: FileID: 0x%2!016I64x! Allocated: %3!*s! bytes (%4!*s!%5)
0x400029ef1011Successfully set "%1!*.*s!" as volume label for "%3"
0x400029f010The volume state is: 1 (reallocating all data writes is enabled).
0x400029f110The volume state is: 0 (reallocating all data writes is disabled).
0x400029f21011Trying to open the volume with volume GUID path.
0x400029f310Usage : fsutil file queryEA Eg : fsutil file queryEA C:\TempFile
0x400029f41011The file %1 does not have extended attributes (EA).
0x400029f51011Extended attributes (EA) Buffer corrupts at offset %1!d! - buffer too small.
0x400029f61011Extended attributes (EA) corrupt at offset %1!d! - NextEntryOffset is incorrect.
0x400029f71011Extended attributes (EA) corrupt at offset %1!d! - empty EaName in list.
0x400029f81011Extended attributes (EA) corrupt at offset %1!d! - EaName has NULL character.
0x400029f91011Extended attributes (EA) corrupt at offset %1!d! - EaName is not NULL-terminated.
0x400029fa1011Extended Attributes (EA) information for file %1: Total Ea Size: 0x%2!-8x!
0x400029fb1011Ea Buffer Offset: %1!-8x! Ea Name: %2 Ea Value Length: %3!-8x!
0x400029fc1011Stream information data buffer not present.
0x400029fd1011Size : %1!*s! (%2!*s!%3!s!) Allocated Size : %4!*s! (%5!*s!%6!s!) Vdl : %7!*s! (%8!*s!%9!s!)
0x400029fe1011Ea Information : Ea Size: 0x%1!-8x!
0x400029ff1011: Ea Buffer Offset: 0x%1!-8x! : Ea Name: %2 : Ea Value Length: 0x%3!-8x!
0x40002a001011Reparse Data : Reparse Tag Value : 0x%1!08x!
0x40002a011011: Substitue Name offset: %1!d! : Substitue Name length: %2!d! : Print Name offset: %3!d! : Print Name Length: %4!d!
0x40002a021011: Substitute Name: %1!.*s!
0x40002a031011: Print Name: %1!.*s!
0x40002a041011: Vendor ID: %1!s! : Qualifier: 0x%2!08x! : Version: 0x%3!08x! : Global Flags: 0x%4!08x! : Num Data Entries: %5!d! : File ID: %6!s! : Data: : Flags: 0x%7!08x! : Migration Time: %8!s! : HSM ID: %9!s! : Bag ID: %10!s! : File Start: 0x%11!08x!.%12!08x! : File Size: 0x%13!08x!.%14!08x! : Data Start: 0x%15!08x!.%16!08x! : Data Size: 0x%17!08x!.%18!08x! : File Version: 0x%19!08x!.%20!08x! : Verification Data: 0x%21!08x!.%22!08x! : Verification Type: %23!u! : Recall Count: %24!u! : Recall Time: %25!s! : Data Stream Start: 0x%26!08x!.%27!08x! : Data Stream Size: 0x%28!08x!.%29!08x! : Data Stream: %30!u! : Data Stream CRC Type: %31!u! : Data Stream CRC: 0x%32!08x!.%3!08x!
0x40002a051011: Format version: %1!d! : CSid: %2!s! : LinkIndex: 0x%3!08x!.%4!08x! : LinkFileNtfsID: 0x%5!08x!.%6!08x! : CSFileNtfsID: 0x%7!08x!.%8!08x! : CSChecksum: 0x%9!08x!.%10!08x! : Checksum: 0x%11!08x!.%12!08x!
0x40002a061011: Local File Path : %1!.*s! : Remote File Path : %2!.*s!
0x40002a071011Stream : 0x%6!03x! %1!s! Attributes : 0x%2!08x!: %3!s! Flags : 0x%4!08x!: %5!s!
0x40002a081011: Warning: Invalid reparse data buffer.
0x40002a091011: Warning: Invalid reparse tag.
0x40002a0a1011Stream information buffer corrupts - buffer too small.
0x4000271011---- Commands Supported ---- 8dot3name 8dot3name management behavior Control file system behavior bypassIo BypassIo management clfs CLFS logfile management dax Dax volume management devdrv Developer volume management dirty Manage volume dirty bit file File specific commands fsInfo File system information hardlink Hard link management objectID Object ID management quota Quota management repair Self healing management reparsePoint Reparse point management storageReserve Storage Reserve management resource Transactional Resource Manager management sparse Sparse file control tiering Storage tiering property management trace File system trace management transaction Transaction management usn USN management volume Volume management wim Transparent wim hosting management
0x4000271311Usage: fsutil fsInfo driveType Eg: fsutil fsInfo driveType C:
0x4000271b11Usage: fsutil fsInfo volumeInfo Eg: fsutil fsInfo volumeInfo C:
0x4000272e11Usage: fsutil volume diskFree Eg: fsutil volume diskFree C:
0x4000274011Usage: fsutil volume dismount Eg: fsutil volume dismount C:
0x4000274311Usage: fsutil dirty set Eg: fsutil dirty set C:
0x4000274411Usage: fsutil fsInfo statistics Eg: fsutil fsInfo statistics C:
0x4000274a11Usage: fsutil file setValidData Eg: fsutil file setValidData C:\testfile.txt 4096
0x4000274b11Usage: fsutil file setShortName Options: shortname - Specifies the short name to set for the filename. Specifying an empty(zero-length) string (e.g. "") will remove the short file name if it exists for the file specified by the filename. Eg: fsutil file setShortName C:\testfile.txt testfile fsutil file setShortName C:\testfile.txt ""
0x4000274d11Usage: fsutil file queryAllocRanges offset= length= offset: File Offset, the start of the range to query length: Size, in bytes, of the range Eg: fsutil file queryAllocRanges offset=1024 length=64 C:\Temp\sample.txt
0x4000274f11Usage: fsutil file setZeroData offset= length= offset: File offset, the start of the range to set to zeroes length: Byte length of the zeroed range Eg: fsutil file setZeroData offset=100 length=150 C:\Temp\sample.txt
0x4000275011Usage: fsutil sparse setFlag [1|0] Eg: fsutil sparse setFlag C:\Temp\sample.txt
0x4000275111Usage: fsutil fsinfo ntfsInfo Eg: fsutil fsinfo ntfsInfo C:
0x4000275211NTFS Volume Serial Number : 0x%1 NTFS Version : %2!d!.%3!d! LFS Version : %4!d!.%5!d! Total Sectors : %6!*s! (%7!*s!%8) Total Clusters : %9!*s! (%10!*s!%11) Free Clusters : %12!*s! (%13!*s!%14) Total Reserved Clusters : %15!*s! (%16!*s!%17) Reserved For Storage Reserve : %18!*s! (%19!*s!%20) Bytes Per Sector : %21!d! Bytes Per Physical Sector : %22!d! Bytes Per Cluster : %23!d! (%38%39) Bytes Per FileRecord Segment : %24!d! Clusters Per FileRecord Segment : %25!d! Mft Valid Data Length : %26%27 Mft Start Lcn : 0x%28 Mft2 Start Lcn : 0x%29 Mft Zone Start : 0x%30 Mft Zone End : 0x%31 MFT Zone Size : %32%33 Max Device Trim Extent Count : %34!u! Max Device Trim Byte Count : %35!#x! Max Volume Trim Extent Count : %36!u! Max Volume Trim Byte Count : %37!#x!
0x4000275311Usage: fsutil dirty query Eg: fsutil dirty query C:
0x4000275611Usage: fsutil reparsePoint query Eg: fsutil reparsePoint query C:\Server
0x4000276211Usage: fsutil reparsePoint delete Eg: fsutil reparsePoint delete C:\Server
0x4000276311Usage: fsutil objectID set ObjectId : 32-digit hexadecimal data BirthVolumeId : 32-digit hexadecimal data BirthObjectId : 32-digit hexadecimal data DomainId : 32-digit hexadecimal data All values must be in Hex of the form 40dff02fc9b4d4118f120090273fa9fc Eg: fsutil objectID set 40dff02fc9b4d4118f120090273fa9fc f86ad6865fe8d21183910008c709d19e 40dff02fc9b4d4118f120090273fa9fc 00000000000000000000000000000000 C:\Temp\sample.txt
0x4000276411Usage: fsutil objectID query Eg: fsutil objectID query C:\Temp\sample.txt
0x4000276511Usage: fsutil objectID create Eg: fsutil objectID create C:\Temp\sample.txt
0x4000276611Usage: fsutil objectID delete Eg: fsutil objectID delete C:\Temp\sample.txt
0x4000276d11Usage: fsutil usn queryJournal Eg: fsutil usn queryJournal C:
0x4000276f11Usage: fsutil usn deleteJournal /D : Delete /N : Notify Eg : usn deleteJournal /D C:
0x4000277011Usage: fsutil usn enumData Eg: fsutil usn enumData 1 0 1 C:
0x4000277211Usage: fsutil usn readData Eg: fsutil usn readData C:\Temp\sample.txt
0x4000277311Usage: fsutil file findBySID Eg: fsutil file findBySID scottb C:\users
0x4000277511%1 = %2!s!
0x4000277811---- FILE Commands Supported ---- createNew Creates a new file of a specified size findBySID Find a file by security identifier layout Query all the information available about the file optimizeMetadata Optimize metadata for a file queryAllocRanges Query the allocated ranges for a file queryCaseSensitiveInfo Query the case sensitive information for a directory queryEA Query the extended attributes (EA) information for a file queryExtents Query the extents for a file queryExtentsAndRefCounts Query the extents and their corresponding refcounts for a file queryFileID Queries the file ID of the specified file queryFileNameById Displays a random link name for the file ID queryProcessesUsing Query the set of processes which have a file opened queryOptimizeMetadata Query the optimize metadata state for a file queryValidData Queries the valid data length for a file setCaseSensitiveInfo Set the case sensitive information for a directory setShortName Set the short name for a file setValidData Set the valid data length for a file setZeroData Set the zero data for a file setEOF Sets the end of file for an existing file setStrictlySequential Sets ReFS SMR file as strictly sequential
0x4000277a11---- HARDLINK Commands Supported ---- create Create a hard link list Enumerate hard links on a file
0x4000278411---- VOLUME Commands Supported ---- allocationReport Allocated clusters report diskFree Query the free space of a volume dismount Dismount a volume findShrinkBlocker Find files that are blocking volume shrink fileLayout Query all the information available about the file(s) flush Flush a volume list List volumes queryCluster Query which file is using a particular cluster queryLabel Query the label for a volume queryNumaInfo Queries the NUMA node for the given volume setLabel Set the label for a volume smrGC Control SMR Garbage Collection smrInfo Query SMR information tpInfo Query thin provisioning info for the given volume upgrade Trigger an upgrade of the specified volume
0x4000278511Usage: fsutil transaction rollback Eg: fsutil transaction rollback {0f2d8905-6153-449a-8e03-7d3a38187ba1}
0x4000278611Usage: fsutil transaction commit Eg: fsutil transaction commit {0f2d8905-6153-449a-8e03-7d3a38187ba1}
0x4000278711Usage: fsutil transaction query [files|all] Eg: fsutil transaction query {0f2d8905-6153-449a-8e03-7d3a38187ba1}
0x4000278811Usage: fsutil transaction fileInfo Eg: fsutil transaction fileInfo d:\foobar.txt
0x4000278911Usage: fsutil resource create Eg: fsutil resource create d:\foobar
0x4000278a11Usage: fsutil resource start [ ] Eg: fsutil resource start d:\foobar fsutil resource start d:\foobar d:\foobar\LogDir\LogBLF::TxfLog d:\foobar\LogDir\LogBLF::TmLog
0x4000278b11Usage: fsutil resource stop Eg: fsutil resource stop d:\foobar
0x4000278c11Usage: fsutil resource info Eg: fsutil resource info d:\foobar
0x4000278d11Usage: fsutil resource txnreset [] Eg: fsutil resource txnreset d:\foobar
0x4000278e11Usage: fsutil resource setAutoReset Eg: fsutil resource setAutoReset true d:\
0x4000278f11Usage: fsutil resource setLog size Eg: fsutil resource setLog size 50 d:\foobar
0x4000279011Usage: fsutil resource setLog mode Eg: fsutil resource setLog mode full d:\foobar
0x4000279111Usage: fsutil resource setLog extentsize Eg: fsutil resource setLog extentsize 50 d:\foobar
0x4000279211Usage: fsutil resource setLog rename Eg: fsutil resource setLog rename d:\foobar
0x4000279311Usage: fsutil resource setLog maxExtents Eg: fsutil resource setLog maxExtents 50 d:\foobar
0x4000279411Usage: fsutil resource setLog minExtents Eg: fsutil resource setLog minExtents 5 d:\foobar
0x4000279511Usage: fsutil resource setLog growth containers fsutil resource setLog growth percent Eg: fsutil resource setLog growth 5 containers d:\foobar
0x4000279611Usage: fsutil resource setLog shrink Eg: fsutil resource setLog shrink 10 d:\foobar
0x400027b411Usage: fsutil file createNew Eg: fsutil file createNew C:\testfile.txt 1000
0x400027b811Usage: fsutil hardlink create Eg: fsutil hardlink create c:\foo.txt c:\bar.txt
0x400027b911Hard link created for %1!s! <<===>> %2!s!
0x400027c811Usage: fsutil quota query Eg: fsutil quota query C:
0x400027c911Usage: fsutil quota modify Eg: fsutil quota modify c: 3000 5000 domain\user
0x400027ca11Usage: fsutil quota violations Eg: fsutil quota violations
0x400027d611Quotas are not enabled on volume "%1!s!"
0x400027dd11Usage: fsutil sparse queryFlag Eg: fsutil sparse queryFlag C:\Temp\sample.txt
0x400027de11Usage: fsutil sparse setRange Eg: fsutil sparse setRange C:\Temp\sample.txt 65536 131072
0x400027df11Usage: fsutil sparse queryRange Eg: fsutil sparse queryRange C:\Temp\sample.txt
0x400027e411Usage: fsutil quota disable Eg: fsutil quota disable C:
0x400027e511Usage: fsutil quota track Eg: fsutil quota track C:
0x400027e611Usage: fsutil quota enforce Eg: fsutil quota enforce C:
0x400027e811Usage: fsutil fsInfo drives
0x400027f311Usage: fsutil repair query Eg: fsutil repair query C:
0x400027f411Usage: fsutil repair set flags: 1 - enable general repair 8 - warn about potential data loss Eg: fsutil repair set C: 1 fsutil repair set C: 9
0x400027f511Usage: fsutil repair wait [] Values: 0 - wait for all repairs to complete (same as not specified) 1 - wait for the current repair to complete Eg: fsutil repair wait C: fsutil repair wait C: 1
0x400027f611Usage: fsutil repair enumerate [] LogName: $Corrupt - The set of confirmed corruptions in the volume (default when LogName is not specified) LogName: $Verify - A set of potential, unverified corruptions in the volume Eg: fsutil repair enumerate C: fsutil repair enumerate C: $Corrupt fsutil repair enumerate C: $Verify
0x400027f711Self healing is now disabled for volume "%1!s!"
0x400027fb11Self healing is disabled for volume "%1!s!"
0x400027fd11Current repair is completed for volume "%1!s!"
0x400027fe11All repairs are completed for volume "%1!s!"
0x4000280111Usage: fsutil volume upgrade Eg: fsutil volume upgrade C:
0x4000280211Usage: fsutil repair truncatelog Eg: fsutil repair truncatelog C:
0x4000280311Self healing repair log is now being truncated for volume "%1!s!"
0x4000280411Usage: fsutil repair initiate file ref# : File Reference including segment number of the file. Eg: fsutil repair initiate C: 0x001600000000123D
0x4000280711Local-to-local
0x4000280811Local-to-remote
0x4000280911Remote-to-local
0x4000280a11Remote-to-remote
0x4000280b11symbolic link evaluation is:
0x4000280c11DISABLED
0x4000280d11ENABLED
0x4000280e11Usage: fsutil behavior set symlinkEvaluation {L2L|L2R|R2L|R2R}:{0|1} [...] Controls the class of symbolic links that can be traversed when opening files. Values: L2L:{0|1} - Controls local-to-local symbolic link evaluation (default ENABLED) L2R:{0|1} - Controls local-to-remote symbolic link evaluation (default ENABLED) R2L:{0|1} - Controls remote-to-local symbolic link evaluation (default DISABLED) R2R:{0|1} - Controls remote-to-remote symbolic link evaluation (default DISABLED) Eg: fsutil behavior set symlinkEvaluation L2L:1 L2R:0 - Enables local-to-local symbolic link evaluation - Disables local-to-remote symbolic link evaluation - Does not change the evaluation state of remote-to-remote or remote-to-local links. This operation takes effect immediately (no reboot required)
0x4000281711Usage: fsutil repair set Values: 0 - Disable general repair 1 - Enable general repair 9 - Enable general repair and warn about potential data loss (default) 0x10 - Disable general repair and bugcheck once on first corruption. Before this option can be set you must first enable bugCheckOnCorrupt mode and then reboot. To enable: fsutil behavior set bugcheckOnCorrupt 1 Eg: fsutil repair set C: 0 fsutil repair set C: 0x10
0x4000281811Self healing state on volume "%1!s!" has been changed to: 0x%2!x! Values: 0 - General repair disabled 1 - General repair enabled 9 - General repair enabled with warnings about potential data loss 0x10 - General repair disabled, bugcheck once on first corruption
0x4000281911Self healing state on volume "%1!s!" is: 0x%2!x! Values: 0 - General repair disabled 1 - General repair enabled 9 - General repair enabled with warnings about potential data loss 0x10 - General repair disabled, bugcheck once on first corruption
0x4000281a11Usage: fsutil behavior query
0x4000281b11Usage: fsutil behavior set
0x4000281c11usage: fsutil 8dot3name set [0 through 3] | [ <0|1>] When a volume is not specified the operation updates the registry value: 0 - Enable 8dot3 name creation on all volumes on the system 1 - Disable 8dot3 name creation on all volumes on the system 2 - Set 8dot3 name creation on a per volume basis (default) 3 - Disable 8dot3 name creation on all volumes except the system volume When a volume is specified this operation updates the individual volume's on disk state. This operation is only meaningful if the registry value is set to 2. 0 - Enable 8dot3 name creation on this volume 1 - Disable 8dot3 name creation on this volume This operation takes effect immediately (no reboot required) Sample commands: "fsutil 8dot3name set 1" - disable 8dot3 name creation on all volumes "fsutil 8dot3name set C: 1" - disable 8dot3 name creation on c:
0x4000281d11Usage: fsutil resource setConsistent Eg: fsutil resource setConsistent d:\foobar NOTE: The RM must be restarted for a change to this setting to take effect.
0x4000281e11Usage: fsutil resource setAvailable Eg: fsutil resource setAvailable d:\foobar NOTE: The RM must be restarted for a change to this setting to take effect.
0x4000282211The volume state is: 1 (8dot3 name creation is DISABLED)
0x4000282311The volume state is: 0 (8dot3 name creation is ENABLED)
0x4000282411The registry state is: 0 (8dot3 name creation is ENABLED on all volumes)
0x4000282511The registry state is: 1 (8dot3 name creation is DISABLED on all volumes)
0x4000282611The registry state is: 2 (Per volume setting - the default)
0x4000282711The registry state is: 3 (8dot3 name creation is DISABLED on all non-system volumes)
0x4000282811Based on the above settings, 8dot3 name creation is ENABLED on "%1"
0x4000282911Based on the above settings, 8dot3 name creation is DISABLED on "%1"
0x4000282a11Based on the above two settings, 8dot3 name creation is ENABLED on "%1" (System volume).
0x4000282b11Based on the above two settings, 8dot3 name creation is DISABLED on "%1" (Non-system volume).
0x4000285011Warning: You are about to strip shortnames on the system volume. This is not recommended as it might cause unexpected behavior of installed applications including the inability to uninstall. This may result in a system that might need to be reinstalled from scratch.
0x4000285111Usage: fsutil 8dot3name query [] When no volume is specified the global 8dot3name state is displayed. When volume is specified the volumes 8dot3name state is displayed. Sample command: "fsutil 8dot3name query" "fsutil 8dot3name query C:"
0x4000285211Usage: fsutil 8dot3name strip DirectoryPath This command permanently removes 8dot3 file names from your volume. It will list the registry keys pointing to the stripped 8dot3names but will not modify the affected registry keys. Stripping will not be performed on files with full path names longer than the maximum path length of 260 characters. ***WARNING*** If there are affected registry keys and you decide to use the override switch /f, it is recommended that you backup your volume as it may lead to unexpected application failures, including the inability to uninstall. /t - Test mode - specifies that all operations should be performed except the actual stripping of the file names. /s - Recurse mode - specifies that this operation should also be applied to subdirectories. /f - Force mode - specifies that the directory should be stripped even if there are registry conflicts. /v - Verbose mode - specifies that all information logged should also be printed out to the console. /l - Specifies a log file to write to. This must be followed by a path to the log file. If this option is not specified the log file will be: "% emp%\8dot3_removal_log@(GMT YYYY-MM-DD HH-MM-SS).log" Sample command: "fsutil 8dot3name strip /l mylogfile.log /s D:\MyData"
0x4000285311A reboot is required for this change to take effect
0x4000285511Usage: fsutil volume queryCluster [ ...] Eg: fsutil volume queryCluster C: 50 0x2000 Attribute Value definitions: ----- ^^^^^ |||||- D = Data Attribute, I=Index Attribute, S=System Attribute, ?=Unknown ||||-- A = Deny defrag requests |||--- T = TxF system file ||---- S = NTFS System Metadata File |----- P = Page File
0x4000285711---- 8DOT3NAME Commands Supported ---- query Query the current setting for the shortname behavior on the system scan Scan for impacted registry entries set Change the setting that controls the shortname behavior on the system strip Remove the shortnames for all files within a directory
0x4000285811Usage: fsutil file queryFileID Eg: fsutil file queryFileID C:\testfile.txt
0x4000285911Usage: fsutil file queryFileNameById Eg: fsutil file queryFileNameById C:\ 0x00040000000001bf
0x4000285a11Usage: fsutil hardlink list Eg: fsutil hardlink list c:\foo.txt
0x4000285d11NOTE: %1 is currently controlled by group policy. Changes to this setting will be superseded by the group policy setting.
0x4000285e11NOTE: %1 is currently controlled by group policy. It can only be changed by group policy.
0x4000285f11Usage: fsutil 8dot3name scan DirectoryPath This command scans the specified directory path looking for registry keys that might be impacted if short names were stripped from this path. /s - Recurse mode - specifies that this operation should also be applied to subdirectories. /v - Verbose mode - specifies that all information logged should also be printed out to the console. /l - Specifies a log file to write to. This must be followed by a path to the log file. If this option is not specified the log file will be: "% emp%\8dot3_removal_log@(GMT YYYY-MM-DD HH-MM-SS).log" Sample command: "fsutil 8dot3name scan /l mylogfile.log /s D:\MyData"
0x4000286111Usage: fsutil security enumsds [options] [offset [count]] This command displays the contents of the NTFS/REFS security descriptor stream. By default every security descriptor starting from the beginning of the stream will be displayed. You can optionally provide a starting byte offset within the stream, and limit the maximum number of security descriptors to display. Options: /bare Display no extraneous output other than security descriptors. /flags Describe individual flag bits in human readable form (no effect if used with /sddl). /sddl Display security descriptors in a compact SDDL form, useful for automated processing (especially with /bare). Without this option, security descriptors are displayed in a human readable form. Eg: fsutil security enumsds C:
0x4000286211Usage: fsutil security stats Eg: fsutil security stats C:
0x4000286311Successfully ENABLED 8dot3name generation on "%1!s!"
0x4000286411Successfully DISABLED 8dot3name generation on "%1!s!"
0x4000286a11Usage: fsutil file queryExtents [/R] [ []] [] /R : If is a reparse point, open it rather than its target : First VCN to query (if omitted, start at VCN 0) : Number of VCNs to query (if omitted or 0, query until EOF) : Display the result in csv format Eg: fsutil file queryExtents C:\Temp\sample.txt fsutil file queryExtents /R C:\Temp\sample.txt fsutil file queryExtents C:\Temp\sample.txt 10 fsutil file queryExtents C:\Temp\sample.txt 10 100 fsutil file queryExtents C:\Temp\sample.txt csv
0x4000286d11Usage: fsutil repair state [] Eg: fsutil repair state C:
0x4000287011(translates to a zone size of %1!s!%2!s!)
0x4000287311Usage: fsutil file queryValidData [/R] [/D] /R : If is a reparse point, open it rather than its target /D : Display detailed valid data information Eg: fsutil file queryValidData C:\testfile.txt
0x4000287b11Usage: fsutil fsInfo sectorInfo Eg: fsutil fsInfo sectorInfo C:
0x4000288e11Usage: fsutil tiering queryFlags Eg: fsutil tiering queryFlags D:
0x4000289011Usage: fsutil tiering setFlags Eg: fsutil tiering setFlags C: /TrNH
0x4000289111Usage: fsutil tiering clearFlags Eg: fsutil tiering clearFlags E: /TrNH
0x4000289211Usage: fsutil tiering tierList Eg: fsutil tiering tierList X:
0x4000289311Usage: fsutil tiering regionList Eg: fsutil tiering regionList F:
0x400028af11Usage: fsutil usn enableRangeTracking [c= s=] Eg: fsutil usn enableRangeTracking c=16384 s=67108864 C: fsutil usn enableRangeTracking c=0 s=0 C: fsutil usn enableRangeTracking C:
0x400028b011---- Commands Supported ---- 8dot3name 8dot3name management behavior Control file system behavior bypassIo BypassIo management dax Dax volume management devdrv Developer volume management dirty Manage volume dirty bit file File specific commands fsInfo File system information hardlink Hard link management objectID Object ID management quota Quota management repair Self healing management reparsePoint Reparse point management resource Transactional Resource Manager management sparse Sparse file control tiering Storage tiering property management trace File system trace management transaction Transaction management usn USN management volume Volume management wim Transparent wim hosting management
0x400028b111Usage: fsutil volume fileLayout [options] * fsutil volume fileLayout [options] fsutil volume fileLayout [options] Options: /v Verbose mode - displays attribute buffer hex dump for $EA and $REPARSE_POINT. Eg: fsutil volume fileLayout C: * fsutil volume fileLayout C: 5 fsutil volume fileLayout C: 0x00040000000001bf fsutil volume fileLayout C:\$MFT fsutil volume fileLayout C:\Windows fsutil volume fileLayout /v C:\windows
0x400028bf11Usage : fsutil volume allocationReport [options] Options: /tier - Displays allocation information for the selected storage tier only. Supported tier types: capacity, performance. /v - Verbose mode, displays each files under system file folders. Eg: fsutil volume allocationReport C: fsutil volume allocationReport /tier capacity C: fsutil volume allocationReport C: /v /tier performance
0x400028c011Total clusters : %1!*s! (%2!*s! bytes) %3!*s!%4!s! Free clusters : %5!*s! (%6!*s! bytes) %7!*s!%8!s! Reserved clusters : %9!*s! (%10!*s! bytes) %11!*s!%12!s! Allocated clusters : %13!*s! (%14!*s! bytes) %15!*s!%16!s! Cluster Size : %19!d! Bytes The allocation is split between: System files : Count: %17!s! Allocated: %18!s! bytes (%20!s!%21!s!)
0x400028c111FileID Allocated%1!.*s! File name ------------------ %2!.*s! -----------------------------
0x400028c211Other system files : Count: %1!s! Allocated: %2!s! bytes (%3!s!%4!s!)
0x400028c311Other system files under %1!s! folder: Count : %2!s! Allocated : %3!s! bytes (%4!s!%5!s!)
0x400028c411%1!-28s!: Allocated: %2!s! bytes (%3!s!%4!s!) Files : Count: %5!s! Allocated: %6!s! bytes (%7!s!%8!s!) Folders : Count: %9!s! Allocated: %10!s! bytes (%11!s!%12!s!)
0x400028d311(System Managed, Last Access Time Updates DISABLED)
0x400028d411(System Managed, Last Access Time Updates ENABLED)
0x400028d511(User Managed, Last Access Time Updates DISABLED)
0x400028d611(User Managed, Last Access Time Updates ENABLED)
0x400028d811Usage: fsutil behavior set disableLastAccess <0-3> Controls if file systems will update the Last Access Time when a file is read. Values: 0x0 - User Managed, Last Access Time Updates ENABLED 0x1 - User Managed, Last Access Time Updates DISABLED 0x2 - System Managed, Last Access Time Updates ENABLED 0x3 - System Managed, Last Access Time Updates DISABLED - When "System Managed" is enabled it allows the system to enable/disable last access time updates based on system policy. - When group policy controls this setting the "System Managed" state can not be set and is not displayed. This operation takes effect immediately (no reboot required)
0x400028d911Usage: fsutil behavior query disableWriteAutoTiering Values: 0 - Write auto tiering is enabled on the given ReFS volume 1 - Write auto tiering is disabled on the given Refs volume
0x400028da11Usage: fsutil behavior set disableWriteAutoTiering <0|1> Values: 0 - Enable write auto tiering on the given ReFS volume (default) 1 - Disable write auto tiering on the given ReFS volume Eg: fsutil behavior set disableWriteAutoTiering F: 1 This operation takes effect immediately (no reboot required)
0x400028db11Usage: fsutil behavior set bugCheckOnCorrupt <0|1> Values: 0 - The system will NOT bugcheck when NTFS detects a corruption in its metadata. (default) 1 - The system will bugcheck when NTFS detects a corruption in its metadata A reboot is required for this change to take effect
0x400028dc11Usage: fsutil behavior set disableCompression <0|1> Values: 0 - NTFS file compression support is enabled. (default) 1 - NTFS file compression support is disabled. A reboot is required for this change to take effect
0x400028de11Usage: fsutil behavior set enableReallocateAllDataWrites <0|1> Values: 0 - Disable Reallocating all data writes on the given volume (default) 1 - Enable Reallocating all data writes on the given volume Eg: fsutil behavior set enableReallocateAllDataWrites F: 1 This operation takes effect immediately (no reboot required)
0x400028df11(Last Access Updates are DISABLED)
0x400028e011(Last Access Updates are ENABLED)
0x400028e111(Allow Extended Characters in short file names)
0x400028e211(Do not allow Extended Characters in short file names)
0x400028e311Usage: fsutil behavior set allowExtChar <0|1> Controls usage of characters from the extended character set (including diacritic characters) to be used in short file names on NTFS volumes. Values: 0 - Do not allow extended characters in short names (default) 1 - Allow extended characters in short names A reboot is required for this change to take effect
0x400028e411(The system will bugcheck when NTFS detects a corruption in its metadata)
0x400028e511(The system will NOT bugcheck when NTFS detects a corruption in its metadata)
0x400028e611(Compression is DISABLED)
0x400028e711(Compression is ENABLED)
0x400028e811(Allows NTFS to stop compressing highly fragmented compressed files)
0x400028e911(Requires NTFS to compress the full contents of compressed files)
0x400028ea11Usage: fsutil behavior set disableCompressionLimit <0|1> When a compressed file on an NTFS volume reaches a certain level of fragmentation, rather than failing to extend the file, NTFS stops compressing additional extents of the file. This was done to allow compressed files to be larger than they normally would be. Setting this value to TRUE (1) disables this feature which limits the size of compressed files on the system. We do not recommend disabling this feature. Values: 0 - Allow NTFS to stop compressing highly fragmented compressed files (default) 1 - Requires NTFS to compress the full contents of compressed files This operation takes effect immediately (no reboot required)
0x400028eb11Usage: fsutil behavior set disableDeleteNotify [NTFS|ReFS] <0|1> Controls whether TRIM operations are sent to the storage device when clusters are freed by the file system. The TRIM operation allows storage devices like SSD's to more efficiently manage its free and used space. Also controls whether format.exe sends TRIMs when a volume is formatted. If neither NTFS nor ReFS are specified, NTFS is assumed. Values: 0 - Allow TRIM operations to be sent to storage devices. (default) 1 - Do not allow TRIM operations to be sent to storage devices This operation takes effect immediately (no reboot required)
0x400028ec11(Allows TRIM operations to be sent to the storage device)
0x400028ed11(Do not allow TRIM operations to be sent to storage devices)
0x400028ee11Usage: fsutil behavior set disableEncryption <0|1> Values: 0 - NTFS file encryption support is enabled. (default) 1 - NTFS file encryption support is disabled. A reboot is required for this change to take effect
0x400028ef11(Encryption is DISABLED)
0x400028f011(Encryption is ENABLED)
0x400028f111(All NTFS file metadata optimizations are ENABLED)
0x400028f211(Full NTFS file metadata optimizations are DISABLED, Incremental optimizations are ENABLED)
0x400028f311(Incremental NTFS file metadata optimizations are DISABLED, full optimizations are ENABLED)
0x400028f411(All NTFS file metadata optimizations are DISABLED)
0x400028f511Usage: fsutil behavior set encryptPagingFile <0|1> Controls whether the PageFile on NTFS volumes is encrypted or not. Values: 0 - PageFile encryption is DISABLED (default) 1 - PageFile encryption is ENABLED A reboot is required for this change to take effect
0x400028f611(PageFile encryption is DISABLED)
0x400028f711(PageFile encryption is ENABLED)
0x400028f811Usage: fsutil behavior set memoryUsage <1|2> This is a multiplier used by NTFS to control how much memory can be consumed to cache filesystem metadata Values: 1 - Uses the default memory consumption values for caching NTFS metadata (default) 2 - Doubles the memory consumption used for caching NTFS metadata A reboot is required for this change to take effect
0x400028f911(The default memory consumption values are used for caching NTFS metadata)
0x400028fa11(The memory consumption values are doubled for caching NTFS metadata)
0x400028fb11Usage: fsutil behavior set mftZone <1-100> This is a multiplier which controls the size of the MFT Zone. The MFT Zone is a space reserved on NTFS volumes for the $MFT file to grow into. This is used to minimize the fragmentation of $MFT. This value is multiplied by 200 MB and defines the initial Zone size when a volume is first mounted. Once the initial Zone is consumed new Zones are created in 200 MB chunks. The default value is 1. A reboot is required for this change to take effect
0x400028fc11Usage: fsutil behavior set quotaNotify <1-4,294,967,295> seconds Controls how frequently NTFS quota violations are recorded in the system event log. This value is in seconds, the default is 3600 seconds (1 hour). A reboot is required for this change to take effect
0x400028fd11Usage: fsutil behavior set enableNonpagedNtfs <0|1> By default NTFS allocates most of its internal data structures and code out of pageable memory. When enabled, NTFS switches to allocating all of its internal data structures and code out of non-pageable memory. This reduces the number of pagefaults that occur while processing file system operations. Values: 0 - NTFS uses pageable memory for most allocations (default) 1 - NTFS uses non-pageable memory for all allocations A reboot is required for this change to take effect
0x400028fe11(NTFS uses pageable memory for most allocations)
0x400028ff11(NTFS uses non-pageable memory for all allocations)
0x4000290011NOTE: %1 is currently controlled by group policy. Showing current group policy state:
0x4000290111Usage: fsutil file queryFileNameById Eg: fsutil file queryFileNameById C:\ 0x00040000000001bf This command also takes 128 bit fileid from ReFS. Usage: fsutil file queryFileNameById Eg: fsutil file queryFileNameById C:\ 0x600 0x10
0x4000293311Error! Flags not supported by this operation on volume "%1":
0x4000293d11Usage: fsutil wim queryFile Eg: fsutil wim queryFile C:\Windows\Notepad.exe
0x4000293e11Usage: fsutil wim enumWims Eg: fsutil wim enumWims C:
0x4000293f11Usage: fsutil wim enumFiles Eg: fsutil wim enumFiles C: 0
0x4000294011Usage: fsutil wim removeWim Eg: fsutil wim removeWim C: 9
0x4000294211Usage: fsutil fsInfo refsInfo /r : Reset ReFS statistics to zero Eg: fsutil fsInfo refsInfo C:
0x4000294311REFS Volume Serial Number : 0x%1 REFS Volume Version : %2!d!.%3!d! REFS Driver Maximum Supported Version : %4!d!.%5!d! Number Sectors : 0x%6 Total Clusters : 0x%7 Free Clusters : 0x%8 Total Reserved : 0x%9 Bytes Per Sector : %10!d! Bytes Per Physical Sector : %12!d! Bytes Per Cluster : %11!d! Fast Tier Data Fill Percentage : %13!d!.%14!d!% Slow Tier Data Fill Percentage : %15!d!.%16!d!% Fast Tier to Slow Tier Rate (Clusters/s) : %17!d! Metadata Checksum Type : %18!s! Data Checksum Type : %19!s!
0x4000294a11Usage: fsutil file optimizeMetadata [/A] /A : Display metadata usage Eg: fsutil file optimizeMetadata c:\largefragmentedfile.txt fsutil file optimizeMetadata c:\$Secure:$SDS fsutil file optimizeMetadata c:\$MFT fsutil file optimizeMetadata c:\
0x4000294b11Usage: fsutil file queryOptimizeMetadata Eg: fsutil file queryOptimizeMetadata c:\largefragmentedfile.txt fsutil file queryOptimizeMetadata c:\$Secure:$SDS fsutil file queryOptimizeMetadata c:\$MFT fsutil file queryOptimizeMetadata c:\
0x4000295411Usage: fsutil behavior set DisableFileMetadataOptimization <0-3> Controls the metadata optimizations that NTFS is allowed to perform on files that require multiple MFT records. Values: 0x0 - Enable all file metadata optimizations (default) 0x1 - Disable full file metadata optimizations only 0x2 - Disable incremental file metadata optimizations only 0x3 - Disable all file metadata optimizations This operation takes effect immediately (no reboot required)
0x4000295511This operation takes effect immediately (no reboot required)
0x4000295c11The volume state is: 1 (write auto tiering is DISABLED)
0x4000295d11The volume state is: 0 (write auto tiering is ENABLED)
0x4000296a11Successfully DISABLED TxF on volume "%1!s!"
0x4000296b11Successfully ENABLED TxF on volume "%1!s!"
0x4000296c11The volume TxF state is: 1 (TxF is DISABLED)
0x4000296d11The volume TxF state is: 0 (TxF is ENABLED)
0x4000296e11usage: fsutil behavior set disableTxF <0|1> Changes the TxF enablement state of the given NTFS volume TxF is an NTFS feature that provides transactional semantics to file system operations. The Windows servicing stack uses TxF so it is not recommended to disable TxF on the C: volume. TxF is a deprecated Windows feature. Values: 0 - TxF is enabled on the given volume 1 - TxF is disabled on the given volume This operation takes effect immediately (no reboot required)
0x4000296f11usage: fsutil behavior query disableTxF The current TxF enablement state of the given volume is displayed
0x4000297411Usage: fsutil file setEOF Eg: fsutil file setEOF C:\testfile.txt 1000
0x4000297611Usage: fsutil volume list
0x4000299411Usage: fsutil file queryExtentsAndRefCounts [/R] [ []] /R : If is a reparse point, open it rather than its target : First VCN to query (if omitted, start at VCN 0) : Number of VCNs to query (if omitted or 0, query until EOF) Eg: fsutil file queryExtentsAndRefCounts C:\Temp\sample.txt
0x4000299711Usage: fsutil volume queryNumaInfo Eg: fsutil volume queryNumaInfo c:
0x4000299a11Cluster Count % of Tier ------------- --------- Size of randomly writable tier : %1 %2 %3!#16I64x! Free space in randomly writable tier : %4 %5 %6!#16I64x! %7!3d!% Size of SMR tier : %8 %9 %10!#16I64x! Free space in SMR tier : %11 %12 %13!#16I64x! %14!3d!% Usable free space in SMR tier : %15 %16 %17!#16I64x! %18!3d!% Recoverable Cluster(s)* : %19 %20 %21!#16I64x! %22!3d!% Free Space Efficiency : %23!d!% Garbage collection current band fill percentage : %24!d!%
0x4000299b11Garbage collection state (last status) : Inactive (%1!x!)
0x4000299c11Garbage collection state : Paused
0x4000299d11Garbage collection state : Active
0x4000299e11Garbage collection state : Active Full Speed
0x4000299f11Garbage collection state : Unknown
0x400029a011Usage: fsutil volume smrInfo Eg: fsutil volume smrInfo C:
0x400029a111Usage: fsutil volume smrGC Action=start IoGranularity= fsutil volume smrGC Action={startfullspeed|pause|stop} Eg: fsutil volume smrGC D: Action=start IoGranularity=0x10000
0x400029a711Usage: fsutil file setStrictlySequential Eg: fsutil file setStrictlySequential C:\testfile.txt
0x400029b611Usage : fsutil file layout [options] Options: /v Verbose mode - displays attribute buffer hex dump for $EA and $REPARSE_POINT. Eg: fsutil file layout C:\testfile.txt fsutil file layout /v C:\testfile.txt
0x400029bb11Usage: fsutil volume thinProvisioningInfo Eg: fsutil volume thinProvisioningInfo C:
0x400029c411Usage: fsutil file setCaseSensitiveInfo [|] [recursive [depth]] Options: enable - Enable case sensitive attribute on (Default if not specified). disable - Disable case sensitive attribute on . recursive - Recursively traverse and set case sensitive attribute on subdirectories. depth - Specifies the depth of subdirectories to traverse and set case sensitive attribute on. A depth of 0 is the same as not specifying the 'recursive' option. When depth is notspecified, we'll travese all subdirectories. Eg: fsutil file setCaseSensitiveInfo C:\TempFolder enable fsutil file setCaseSensitiveInfo C:\TempFolder disable fsutil file setCaseSensitiveInfo C:\TempFolder enable recursive fsutil file setCaseSensitiveInfo C:\TempFolder enable recursive 2
0x400029c711Usage: fsutil file queryCaseSensitiveInfo [recursive [depth]] Options: recursive - Recursively traverse and query case sensitive attribute on subdirectories. depth - Specifies the depth of subdirectories to traverse and query case sensitive attribute on. A depth of 0 is the same as not specifying the 'recursive' option. When depth is not specified, we'll travese all subdirectories. Eg: fsutil file queryCaseSensitiveInfo C:\TempFolder fsutil file queryCaseSensitiveInfo C:\TempFolder recursive fsutil file queryCaseSensitiveInfo C:\TempFolder recursive 2
0x400029cb11Usage: fsutil storageReserve define [; ...] : [ []] : storage reserve ID (1 to 15) : the space guarantee in MB (default 0) : optional storage reserve area flags Eg: fsutil storageReserve define C: 1 0x800 ; 2 0x500
0x400029cc11Usage: fsutil storageReserve update [; ...] : [ []] : storage reserve ID (1 to 15) : the space guarantee in MB (default 0) : optional storage reserve area flags Eg: fsutil storageReserve update C: 2 0
0x400029cd11Usage: fsutil storageReserve query [ ...] Eg: fsutil storageReserve query C:
0x400029cf11Usage: fsutil storageReserve delete [ ...] Eg: fsutil storageReserve delete C:
0x400029d011Usage: fsutil storageReserve repair [ ...] Eg: fsutil storageReserve repair C:
0x400029d211Usage: fsutil storageReserve setID Eg: fsutil storageReserve setID C:\testfile.txt 2
0x400029d311Usage: fsutil storageReserve queryID Eg: fsutil storageReserve queryID C:\testfile.txt
0x400029d411Usage: fsutil storageReserve findByID [options] * fsutil storageReserve findByID [options] Options: /v Verbose mode - displays hex dump for $EA and $REPARSE_POINT data. Eg: fsutil storageReserve findByID c: * fsutil storageReserve findByID C: 2 fsutil storageReserve findByID /v C: 2
0x400029ea11Usage: fsutil volume flush Eg: fsutil volume flush C:
0x400029eb11Usage: fsutil volume queryLabel Eg: fsutil volume queryLabel C:
0x400029ec11Usage: fsutil volume setLabel
0x400029ee110x%1!016I64x! %2!*s! bytes (%3!*s!%4) %5!s!
0x400029f011The volume state is: 1 (reallocating all data writes is ENABLED)
0x400029f111The volume state is: 0 (reallocating all data writes is DISABLED)
0x400029f311Usage: fsutil file queryEA Eg: fsutil file queryEA C:\TempFile
0x40002a0b11Slab Size (bytes) : 0x%1!I64X!
0x40002a0c11Read Zeros : %1!u!
0x40002a0d11Anchor Supported : %1!u!
0x40002a0e11Unmap Granularity Alignment (bytes) : 0x%1!I64X!
0x40002a0f11Failed to query volume info; Win32 error %1!u!
0x40002a1011Failed to query storage manage dataset attributes; Win32 error %1!u!
0x40002a1111Invalid data returned from IOCTL_STORAGE_MANAGE_DATA_SET_ATTRIBUTES query
0x40002a1211%1 is not a thinly-provisioned volume.
0x40002a1311Volume Size (clusters) : 0x%1!08X!
0x40002a1411Volume Size (bytes) : 0x%1!016I64X!
0x40002a1511Cluster Size (bytes) : 0x%1!08X!
0x40002a1611Slab-Aligned Volume Size (bytes) : 0x%1!016I64X!
0x40002a1711Slab Count (Total) : 0x%1!08X!
0x40002a1811Storage Query %1!u! (Offset 0x%2!016I64X!, Length 0x%3!016I64X!) (bytes)
0x40002a1911Slab Offset Delta (bytes) : 0x%1!016I64X!
0x40002a1a11Slab Count (Mapped) : 0x%1!08X!
0x40002a1b11Slab Bitmap Length (ULONGs) : 0x%1!08X!
0x40002a1c11Slab Size (bytes) : 0x%1!016I64X!
0x40002a1d11First Bit Size (bytes) : 0x%1!016I64X!
0x40002a1e11Last Bit Size (bytes) : 0x%1!016I64X!
0x40002a1f11Slab Bitmap Array :
0x40002a2011Filesystem-Level Slab Bitmap :
0x40002a2111%1!8I64X! - %2!8I64X! : %3!s!
0x40002a2211Usage: fsutil tpInfo
0x40002a2311Usage: fsutil behavior set disableSpotCorruptionHandling <0-15> Controls which spot corruption handling features are enabled for use by NTFS. All of these features work in conjunction with CHKDSK. Any combination of the following values added together may be specified: Values: 0 - All NTFS spot corruption handling features are ENABLED (default) 1 - All NTFS spot corruption handling features are DISABLED 2 - DISABLES spot fixing of NTFS metadata corruptions 4 - DISABLES online scanning for NTFS metadata corruptions 8 - DISABLES spot verification of NTFS metadata corruptions This operation takes effect immediately (no reboot required)
0x40002a2411NTFS spot fixing of metadata corruptions is: ENABLED
0x40002a2511NTFS spot fixing of metadata corruptions is: DISABLED
0x40002a2611NTFS online scanning for metadata corruptions is: ENABLED
0x40002a2711NTFS online scanning for metadata corruptions is: DISABLED
0x40002a2811NTFS spot verification of metadata corruptions is: ENABLED
0x40002a2911NTFS spot verification of metadata corruptions is: DISABLED
0x40002a2a11Total free bytes : %1!*s! (%2!*s!%3!s!) Total bytes : %4!*s! (%5!*s!%6!s!) Total quota free bytes : %7!*s! (%8!*s!%9!s!) Unavailable pool bytes : %10!*s! (%11!*s!%12!s!) Quota unavailable pool bytes : %13!*s! (%14!*s!%15!s!) Used bytes : %16!*s! (%17!*s!%18!s!) Total Reserved bytes : %19!*s! (%20!*s!%21!s!) Volume storage reserved bytes : %22!*s! (%23!*s!%24!s!) Available committed bytes : %25!*s! (%26!*s!%27!s!) Pool available bytes : %28!*s! (%29!*s!%30!s!)
0x40002a2b11Total free bytes : %1!*s! (%2!*s!%3!s!) Total bytes : %4!*s! (%5!*s!%6!s!) Total quota free bytes : %7!*s! (%8!*s!%9!s!) Unavailable pool bytes : %10!*s! (%11!*s!%12!s!) Quota unavailable pool bytes : %13!*s! (%14!*s!%15!s!) Used bytes : %16!*s! (%17!*s!%18!s!) Total Reserved bytes : %19!*s! (%20!*s!%21!s!) Volume storage reserved bytes : %22!*s! (%23!*s!%24!s!) Available committed bytes : %25!*s! (%26!*s!%27!s!) Pool available bytes : %28!*s! (%29!*s!%30!s!) Total metadata bytes : %31!*s! (%32!*s!%33!s!)
0x40002a2c11Storage-Level Slab Bitmap :
0x40002a2d11Alignment Offset (bytes) : 0x%1!016I64X!
0x40002a2e11Bit Count (Total) : 0x%1!08X!
0x40002a2f11Bit Count (Set) : 0x%1!08X!
0x40002a3011Usage: fsutil behavior set parallelFlushOpenThreshold <100-1,000,000> When flushing a volume NTFS compares this setting to the number of open files to decide when to use multiple threads vs. a single thread. The default value is %3!d!.
0x40002a3111Usage: fsutil behavior set parallelFlushThreads <0-%2!d!> When flushing a volume using multiple threads, this controls how many threads to use. Values: 0 - Default value of %1!2d! threads (based on: (NumProcessors/2)+1) 1 - Only use one thread Max value - %2!3d! threads (based on: (NumProcessors*2))
0x40002a3211(will use %1!d! threads)
0x40002a3311(will use %1!d!)
0x40002a3411
0x40002a3511
0x40002a3611(Default)
0x40002a3711Usage: fsutil volume findShrinkBlocker [options] Options : /noFileName - Avoid printing filenames for each immovable/pinned file. /shrinkSize - The amount of space to shrink. SizeWithUnit should be in B/KB/MB/GB/TB/PB format. If no unit specified, size will be interpreted in bytes. /newSize - The new size of the volume. SizeWithUnit should be in B/KB/MB/GB/TB/PB format. If no unit specified, size will be interpreted in bytes. *Note: /shrinkSize and /newSize cannot be specified at the same time. If neither is specified, the default query starting point is 1/4 of the volume size from the end. Eg : fsutil volume findShrinkBlocker C: : fsutil volume findShrinkBlocker /noFileName /shrinkSize 200MB C: : fsutil volume findShrinkBlocker C: /newSize 2GB
0x40002a3811Invalid size %1!s! specified, beyond valid volume range.
0x40002a3911No file entries returned
0x40002a3a11Pinned
0x40002a3b11Immovable
0x40002a3c11Blocker Type FileId FileName
0x40002a3d110x%1!016I64x! %2!s!
0x40002a3e11Blocker Type FileId
0x40002a3f110x%1!016I64x!
0x40002a40111 file processed.
0x40002a4111%1!lu! files processed.
0x40002a4211No shrink blocker found.
0x40002a43111 shrink blocker found (%1!lu! immovable, %2!lu! pinned).
0x40002a4411%1!lu! shrink blockers found (%2!lu! immovable, %3!lu! pinned).
0x40002a4511Searching for shinrk blockers starting from Lcn: %1!I64d!, ClusterCount: %2!I64d!
0x40002a4611Usage: fsutil behavior set defaultNtfsTier <1-2> For NTFS tiered volumes this controls what tier to use when allocating new clusters to a file. This value is used when a file does not have an explicit desired storage tier. Values: 1 - Capacity tier 2 - Performance tier Client systems default to the Performance tier. Server systems default to the Capacity tier.
0x40002a4711(Capacity tier)
0x40002a4811(Performance tier)
0x40002a4911Supports Bypass IO
0x40002a4a11---- BYPASSIO Commands Supported ---- State Returns the BypassIo state for the given file/directory
0x40002a4b11Usage: fsutil bypassIo state /v Verbose mode - display the name of the storage driver Eg: fsutil bypassIo state c:\test\testfile.txt fsutil bypassIo state /v d:
0x40002a4c11BypassIo on "%1!s!" is currently supported Storage Type: %2!s! Storage Driver:
0x40002a4d11BypassIo on "%1!s!" is not currently supported HResult: 0x%2!x! (%3!s!) Driver: %4!*s! Reason: %5!*s! Storage Type: %6!s! Storage Driver:
0x40002a4e11BypassIo on "%1!s!" is not currently supported Status: %2!d! (%3!s!) Driver: %4!*s! Reason: %5!*s! Storage Type: %6!s! Storage Driver:
0x40002a4f11---- TRACE Commands Supported ---- decode Decode NTFS trace information query Query the state of NTFS trace session start Start a NTFS trace session stop Stop a NTFS trace session
0x40002a5011Usage : fsutil trace create [options] Options : output= - Path of the output trace file. The default path is "%Systemdrive%\PerfLogs\Admin". keywords= - Trace keywords to enable. Default is to not trace any keyword. Supported keywords are as follows: COMMON 0x0000000000000001 HASH_TABLE 0x0000000000000002 DAX 0x0000000000000004 READ 0x0000000000000008 WRITE 0x0000000000000010 COMPRESSED 0x0000000000000020 EFS 0x0000000000000040 MFT 0x0000000000000080 VOLBITMAP 0x0000000000000100 CREATE 0x0000000000000200 ALTSTREAMS 0x0000000000000400 OBJID 0x0000000000000800 INDEXES 0x0000000000001000 TXFKTM 0x0000000000002000 TXFRECOVERY 0x0000000000004000 TXFRM 0x0000000000008000 TXFFCB 0x0000000000010000 SELFHEAL 0x0000000000020000 HEALBITMAP 0x0000000000040000 USNJRNL 0x0000000000080000 DELNOTIFY 0x0000000000100000 LOGFILE 0x0000000000200000 FLUSH 0x0000000000400000 SCRUB 0x0000000000800000 STATUS_DEBUG 0x0000000001000000 FRSCONSOLIDATION 0x0000000002000000 ALLOC_FREE_CLUS 0x0000000004000000 OPERATIONS 0x0000000008000000 HOTFIX 0x0000000010000000 VOLUME 0x0000000020000000 CACHESUP 0x0000000040000000 DEVIOSUP 0x0000000080000000 FSCTRL 0x0000000100000000 MFT_ATTR_LIST 0x0000000200000000 MOUNT 0x0000000400000000 CACHEDRUNS 0x0000000800000000 SHARING_VIOLATION 0x0000001000000000 ACCESS_DENIED 0x0000002000000000 level= - Trace level to enable. Default is level 3 (warning). Supported trace levels: 1 - TRACE_LEVEL_CRITICAL - Abnormal exit or termination events 2 - TRACE_LEVEL_ERROR - Severe error events 3 - TRACE_LEVEL_WARNING - Warning events such as allocation failures 4 - TRACE_LEVEL_INFORMATION - Non-error events such as entry or exit events 5 - TRACE_LEVEL_VERBOSE - Detailed trace events Eg : fsutil trace create NtfsTrc output=C:\Temp\tracefile.etl keywords=0x3f00000000 level=4
0x40002a5111Usage : fsutil trace delete Eg : fsutil trace create NtfsTrc
0x40002a5211Usage : fsutil trace query
0x40002a5311Usage : fsutil trace start [options] Options : output= - Path of the output trace file. The default path is "%Systemdrive%\PerfLogs\Admin". keywords= - Trace keywords to enable. Default is to trace all keywords. Both numeric and string keywords are supported, use "+" to combine them, e.g. "Keywords=0x1010+CREATE" to trace INDEXES, WRITE and CREATE keywords. Supported keywords are as follows: COMMON 0x0000000000000001 HASH_TABLE 0x0000000000000002 DAX 0x0000000000000004 READ 0x0000000000000008 WRITE 0x0000000000000010 COMPRESSED 0x0000000000000020 EFS 0x0000000000000040 MFT 0x0000000000000080 VOLBITMAP 0x0000000000000100 CREATE 0x0000000000000200 ALTSTREAMS 0x0000000000000400 OBJID 0x0000000000000800 INDEXES 0x0000000000001000 TXFKTM 0x0000000000002000 TXFRECOVERY 0x0000000000004000 TXFRM 0x0000000000008000 TXFFCB 0x0000000000010000 SELFHEAL 0x0000000000020000 HEALBITMAP 0x0000000000040000 USNJRNL 0x0000000000080000 DELNOTIFY 0x0000000000100000 LOGFILE 0x0000000000200000 FLUSH 0x0000000000400000 SCRUB 0x0000000000800000 STATUS_DEBUG 0x0000000001000000 FRSCONSOLIDATION 0x0000000002000000 ALLOC_FREE_CLUS 0x0000000004000000 OPERATIONS 0x0000000008000000 HOTFIX 0x0000000010000000 VOLUME 0x0000000020000000 CACHESUP 0x0000000040000000 DEVIOSUP 0x0000000080000000 FSCTRL 0x0000000100000000 MFT_ATTR_LIST 0x0000000200000000 MOUNT 0x0000000400000000 CACHEDRUNS 0x0000000800000000 SHARING_VIOLATION 0x0000001000000000 ACCESS_DENIED 0x0000002000000000 level= - Trace level to enable. Default is level 2 (error). Supported trace levels: 1 - TRACE_LEVEL_CRITICAL - Abnormal exit or termination events 2 - TRACE_LEVEL_ERROR - Severe error events 3 - TRACE_LEVEL_WARNING - Warning events such as allocation failures 4 - TRACE_LEVEL_INFORMATION - Non-error events such as entry or exit events 5 - TRACE_LEVEL_VERBOSE - Detailed trace events Eg : fsutil trace start output=C:\Temp\tracefile.etl keywords=0x3f00000000 level=4 fsutil trace start keywords=0x1010+CREATE
0x40002a5411Usage : fsutil trace stop
0x40002a5511Usage : fsutil trace decode [trace file path] [options] [trace file path] - Path for the trace file to decode. When not specifing, we'll use the default path "%Systemdrive%\PerfLogs\Admin\Fsutil_NtfsTrace.etl". Options : output= - Output path for decoded trace format= - Output format. Default = TXT. Supported format: CSV, XML, EVTX, TXT, No Eg : fsutil trace decode fsutil trace decode C:\Temp\tracefile.etl fsutil trace decode C:\Temp\tracefile.etl output=c:\Temp\traceOutput.txt format=CSV
0x40002a5611Usage : fsutil trace update [options] Options : output= - Updated path of the output trace file. keywords= - Updated trace keywords to enable. Supported keywords are as follows: COMMON 0x0000000000000001 HASH_TABLE 0x0000000000000002 DAX 0x0000000000000004 READ 0x0000000000000008 WRITE 0x0000000000000010 COMPRESSED 0x0000000000000020 EFS 0x0000000000000040 MFT 0x0000000000000080 VOLBITMAP 0x0000000000000100 CREATE 0x0000000000000200 ALTSTREAMS 0x0000000000000400 OBJID 0x0000000000000800 INDEXES 0x0000000000001000 TXFKTM 0x0000000000002000 TXFRECOVERY 0x0000000000004000 TXFRM 0x0000000000008000 TXFFCB 0x0000000000010000 SELFHEAL 0x0000000000020000 HEALBITMAP 0x0000000000040000 USNJRNL 0x0000000000080000 DELNOTIFY 0x0000000000100000 LOGFILE 0x0000000000200000 FLUSH 0x0000000000400000 SCRUB 0x0000000000800000 STATUS_DEBUG 0x0000000001000000 FRSCONSOLIDATION 0x0000000002000000 ALLOC_FREE_CLUS 0x0000000004000000 OPERATIONS 0x0000000008000000 HOTFIX 0x0000000010000000 VOLUME 0x0000000020000000 CACHESUP 0x0000000040000000 DEVIOSUP 0x0000000080000000 FSCTRL 0x0000000100000000 MFT_ATTR_LIST 0x0000000200000000 MOUNT 0x0000000400000000 CACHEDRUNS 0x0000000800000000 SHARING_VIOLATION 0x0000001000000000 ACCESS_DENIED 0x0000002000000000 level= - Updated trace level to enable. Supported trace levels: 1 - TRACE_LEVEL_CRITICAL - Abnormal exit or termination events 2 - TRACE_LEVEL_ERROR - Severe error events 3 - TRACE_LEVEL_WARNING - Warning events such as allocation failures 4 - TRACE_LEVEL_INFORMATION - Non-error events such as entry or exit events 5 - TRACE_LEVEL_VERBOSE - Detailed trace events Eg : fsutil trace update NtfsTrc output=C:\Temp\tracefile.etl keywords=0x3f00000000 level=4
0x40002a5711Failed to query existing trace session setting.
0x40002a5811Failed to invoke logman.
0x40002a5911Failed to invoke netsh.
0x40002a5a11This operation is not supported due to required binary logman.exe is not available on this build.
0x40002a5b11This operation is not supported due to required binary netsh.exe is not available on this build.
0x40002a5c11BypassIo compatible
0x40002a5d11Not BypassIo Compatible
0x40002a5e11Driver Name: %1!*s!
0x40002a5f11Successfully started the trace session.
0x40002a6011Supports Stream Snapshots
0x40002a6111Supports Case-Sensitive Directories
0x40002a6211Supports Strictly Sequential Files
0x40002ac711Successfully stopped the trace session.
0x40002ac811Trace level: %1!s!
0x40002ac911Trace keywords: 0x%1!016I64x!
0x40002aca110x%1!016I64x! %2!s!
0x40002acb11Trace keywords: None.
0x40002acc11Trace file path: %1!s!
0x40002ace11A volume supporting case-sensitivity is required for this operation (e.g., a local REFS or NTFS volume).
0x40002acf11BypassIo on "%1!s!" is partially supported Volume stack bypass is disabled (%3!*s!) Storage Type: %2!s! Storage Driver:
0x40002ad011BypassIo on "%1!s!" is partially supported Volume stack bypass is disabled (%3!*s!) HResult: 0x%4!x! (%5!s!) Reason: %6!*s! Storage Type: %2!s! Storage Driver:
0x40002ad111BypassIo on "%1!s!" is partially supported Volume stack bypass is disabled (%3!*s!) Status: %4!d! (%5!s!) Reason: %6!*s! Storage Type: %2!s! Storage Driver:
0x40002ad211Usage: fsutil file queryProcessesUsing [/C] /C : Output in CSV format Eg: fsutil file queryProcessesUsing /C c:\foo.txt
0x40002ad311"%1!s!" is opened by the following process(es): PID Image Path
0x40002ad411PID,Image Path
0x40002ad511%1!12u! %2!s!
0x40002ad611%1!u!,%2!s!
0x40002ad711Failed to acquire debug privilege; some process image paths may not be displayed.
0x40002ad811"%1!s!" is not found to be opened by any processes.
0x40002ad911Failed to query case sensitive attribute information for file %1, error: 0x%2!08x! %3.
0x40002ada11Failed to set case sensitive attribute information for file %1, error: 0x%2!08x! %3.
0x40002adb11Failed to set short name, either the specified file has been opened in case-sensitive mode or the specified short name is invalid.
0x40002adc11Successfully set short name %1 for file %2.
0x40002add11Successfully removed short name for file %1.
0x40002ade11Usage: fsutil behavior set enableMaximumHardLinks <0|1> When enabled, NTFS will allow creation of hard links beyond the default 1024 per file hard link limit. The number of hard links that can be created for a given file is based on its available metadata space. Values: 0 - NTFS allows a maximum of 1024 hard links per file (default) 1 - NTFS will allow the maximum number of hard links per file
0x40002adf11(NTFS will allow the maximum number of hard links per file)
0x40002ae011(NTFS will allow up to 1024 hard links per file)
0x40002ae111Volume format will be upgraded upon next volume mount.
0x40002ae211Usage: fsutil devdrv query [] Eg: fsutil devdrv query Eg: fsutil devdrv query D: Query information about developer volumes in general or the given developer volume.
0x40002ae311This is a trusted developer volume.
0x40002ae411The volume is formatted as a developer volume but is not trusted on this machine.
0x40002ae511This is not a developer volume.
0x40002ae611NOTE: This won't be a developer volume after a dismount or reboot.
0x40002ae711The volume is in use and the change may not take effect immediately. Please dismount the volume for the change to take effect.
0x40002ae811Error %1!d!:
0x40002ae911Failed to update the persistent volume state.
0x40002aea11Failed to delete the stale machine specific state for the volume.
0x40002aeb11Failed to create new machine specific state for the volume.
0x40002aec11Failed to open the volume.
0x40002aed11Dev drive or a developer volume is a volume that is tuned for performance of developer scenarios. This also lets an administrator of the device control the file system filters that are attached to the volume. ---- DEVDRV Commands Supported ---- query Query developer volume information enable Enable developer volume support on this machine disable Disable developer volume support on this machine trust Trust the given developer volume untrust Untrust the given developer volume setFiltersAllowed Set the list of allowed filters for developer volume clearFiltersAllowed Clear the list of allowed filters for developer volume Please use "fsutil devdrv /?" for more information.
0x40002aee11Usage: fsutil devdrv trust [/f] Trust the given developer volume. Developer volume filter attach policy is honored only for a trusted developer volume. Options: /f - Force dismount the volume for the change to take effect immediately even if the volume is in use. Otherwise the volume is dismounted only if it is not in use. Sample commands: fsutil devdrv trust D: fsutil devdrv trust /f D:
0x40002aef11Usage: fsutil devdrv untrust [/f] Untrust the given developer volume. Developer volume filter attach policy is not honored for an untrusted developer volume. Options: /f - Force dismount the volume for the change to take effect immediately even if the volume is in use. Otherwise the volume is dismounted only if it is not in use. Sample commands: fsutil devdrv untrust D: fsutil devdrv untrust /f D:
0x40002af011Developer volumes are enabled.
0x40002af111Developer volumes are disabled.
0x40002af211Developer volumes are enabled, by group policy.
0x40002af311Developer volumes are disabled, by group policy.
0x40002af411NOTE: This setting is currently controlled by group policy. Effective value of this setting will consider group policy as well.
0x40002af511Usage: fsutil devdrv disable Disable developer volume support on this machine.
0x40002af611Usage: fsutil devdrv enable [/allowAv|/disallowAv] Eg: fsutil devdrv enable Eg: fsutil devdrv enable /allowAv Eg: fsutil devdrv enable /disallowAv Enable developer volume support on this machine. Options: /allowAv - Specifies that developer volumes are to be protected by antivirus filter. /disallowAv - Specifies that developer volumes need not be protected by antivirus filter. NOTE: If neither /allowAv nor /disallowAv is specified, antivirus policy for developer volume is not configured and system default is to have developer volumes protected by antivirus filter.
0x40002af711Filters allowed on any developer volume:
0x40002af811
0x40002af911,
0x40002afa11%1
0x40002afb11Error looking up filters allowed on any developer volume.
0x40002afc11Filters allowed on any developer volume, by group policy:
0x40002afd11Error looking up group policy, for filters allowed on any developer volume.
0x40002afe11Filters allowed on this developer volume:
0x40002aff11Error looking up filters allowed on this developer volume.
0x40002b0011Filters currently attached to this developer volume:
0x40002b0111Error looking up filters that are currently attached to this developer volume.
0x40002b0211No filters are currently attached to this developer volume.
0x40002b0311%1!.*s!
0x40002b0411Failed to create or open machine specific state for the volume.
0x40002b0511Usage: fsutil devdrv setFiltersAllowed [[/f] /volume ] "filter1, filter 2, ..." Eg: fsutil devdrv setFiltersAllowed "filter1, filter 2" Eg: fsutil devdrv setFiltersAllowed /volume D: filter1,filter2 Eg: fsutil devdrv setFiltersAllowed /f /volume D: filter1,filter2 Set the list of allowed filters for the given developer volume or any developer volume on this machine. Options: /f - Force dismount the specified volume for the change to take effect immediately even if the volume is in use. Otherwise the volume, if specified, is dismounted only if it is not in use. /volume - If specified, the allowed list of filters is set only for this volume.
0x40002b0611Usage: fsutil devdrv clearFiltersAllowed [[/f] ] Eg: fsutil devdrv clearFiltersAllowed Eg: fsutil devdrv clearFiltersAllowed D: Eg: fsutil devdrv clearFiltersAllowed /f D: Clear the list of allowed filters for the given developer volume or any developer volume on this machine. Options: /f - Force dismount the specified volume for the change to take effect immediately even if the volume is in use. Otherwise the volume, if specified, is dismounted only if it is not in use. /volume - If specified, the allowed list of filters is cleared only for this volume.
0x40002b0711A reboot is required for this change to take effect. Alternatively the volumes of interest can be dismounted to have the change take effect on those volumes.
0x40002b0811Developer volumes are protected by antivirus filter.
0x40002b0911Developer volumes are protected by antivirus filter, by group policy.
0x40002b0a11Developer volumes may not be protected by antivirus filter.
0x40002b0b11An NTFS or ReFS volume is required for this operation.
0x40002b0c11An NTFS volume is required for this operation.
0x40002b0d11Provides administrative functionality for CLFS logfiles. ---- CLFS Commands Supported ---- authenticate Add authentication codes to an existing CLFS logfile. Please use "fsutil clfs /?" for more information.
0x40002b0e11Usage: fsutil clfs authenticate Eg: fsutil clfs authenticate "C:\example_log.blf" Add authentication support to a CLFS logfile that has invalid or missing authentication codes. Authentication codes will be written to the Base Logfile (.blf) and all containers associated with the logfile. It is required that this command be executed with administrative privileges.
0xc0002ac011Failed to create process with cmdline "%1!s!", error %2!8x!.
0xc0002ac111Trace file %1!s! already existed, please delete it and try again.
0xc0002ac211Failed to rename trace file from %1!s! to %2!s!, error %3!8x!.
0xc0002ac411Failed to create trace session.
0xc0002ac511Failed to start trace session.
0xc0002ac611Failed to delete trace session.
0xc0002acd11Trace session already started, please stop it with "fsutil trace stop" before starting a new one.
0x400027107---- Commands Supported ---- 8dot3name 8dot3name managment behavior Control file system behavior dirty Manage volume dirty bit file File specific commands fsinfo File system information hardlink Hardlink management objectid Object ID management quota Quota management repair Self healing management reparsepoint Reparse point management resource Transactional Resource Manager management sparse Sparse file control transaction Transaction management usn USN management volume Volume management
0x400027137Usage : fsutil fsinfo drivetype Eg : fsutil fsinfo drivetype C:
0x4000271b7Usage : fsutil fsinfo volumeinfo Eg : fsutil fsinfo volumeinfo C:
0x4000272e78.1Usage : fsutil volume diskfree Eg : fsutil volume diskfree C:
0x4000272f78.1Total # of free bytes : %1 Total # of bytes : %2 Total # of avail free bytes : %3
0x4000273f78.1Usage : fsutil behavior query
0x4000274478.1Usage : fsutil fsinfo statistics Eg : fsutil fsinfo statistics C:
0x400027467CreateHits : %1 SuccesfulCreates : %2 FailedCreates : %3 NonCachedReads : %4 NonCachedRead Bytes : %5 NonCachedWrites : %6 NonCachedWrite Bytes : %7 NonCachedDiskReads : %8 NonCachedDiskWrites : %9
0x400027477MftReads : %1 MftReadBytes : %2 MftWrites : %3 MftWriteBytes : %4 Mft2Writes : %5 Mft2WriteBytes : %6 RootIndexReads : %7 RootIndexReadBytes : %8 RootIndexWrites : %9 RootIndexWriteBytes : %10 BitmapReads : %11 BitmapReadBytes : %12 BitmapWrites : %13 BitmapWriteBytes : %14 MftBitmapReads : %15 MftBitmapReadBytes : %16 MftBitmapWrites : %17 MftBitmapWriteBytes : %18 UserIndexReads : %19 UserIndexReadBytes : %20 UserIndexWrites : %21 UserIndexWriteBytes : %22 LogFileReads : %23 LogFileReadBytes : %24 LogFileWrites : %25 LogFileWriteBytes : %26 LogFileFull : %27
0x4000274a78.1Usage : fsutil file setvaliddata Eg : fsutil file setvaliddata C:\testfile.txt 4096
0x4000274b78.1Usage : fsutil file setshortname Eg : fsutil file setshortname C:\testfile.txt testfile
0x4000274c78.1The FSUTIL utility requires a local NTFS volume.
0x4000274d78.1Usage : fsutil file queryallocranges offset= length= offset : File Offset, the start of the range to query length : Size, in bytes, of the range Eg : fsutil file queryallocranges offset=1024 length=64 C:\Temp\sample.txt
0x4000274e7** Range : %1!d! ** Starting Offset : 0x%2 Length in bytes : 0x%3
0x4000274f78.1Usage : fsutil file setzerodata offset= length= offset : File offset, the start of the range to set to zeroes length : Byte length of the zeroed range Eg : fsutil file setzerodata offset=100 length=150 C:\Temp\sample.txt
0x400027507Usage : fsutil sparse setflag Eg : fsutil sparse setflag C:\Temp\sample.txt
0x400027517Usage : fsutil fsinfo ntfsinfo Eg : fsutil fsinfo ntfsinfo C:
0x400027527NTFS Volume Serial Number : 0x%1 Version : %2!d!.%3!d! Number Sectors : 0x%4 Total Clusters : 0x%5 Free Clusters : 0x%6 Total Reserved : 0x%7 Bytes Per Sector : %8!d! Bytes Per Cluster : %9!d! Bytes Per FileRecord Segment : %10!d! Clusters Per FileRecord Segment : %11!d! Mft Valid Data Length : 0x%12 Mft Start Lcn : 0x%13 Mft2 Start Lcn : 0x%14 Mft Zone Start : 0x%15 Mft Zone End : 0x%16
0x4000275678.1Usage : fsutil reparsepoint query Eg : fsutil reparsepoint query C:\Server
0x4000276278.1Usage : fsutil reparsepoint delete Eg : fsutil reparsepoint delete C:\Server
0x4000276378.1Usage : fsutil objectid set ObjectId : 32-digit hexadecimal data BirthVolumeId : 32-digit hexadecimal data BirthObjectId : 32-digit hexadecimal data DomainId : 32-digit hexadecimal data All values must be in Hex of the form 40dff02fc9b4d4118f120090273fa9fc Eg : fsutil objectid set 40dff02fc9b4d4118f120090273fa9fc f86ad6865fe8d21183910008c709d19e 40dff02fc9b4d4118f120090273fa9fc 00000000000000000000000000000000 C:\Temp\sample.txt
0x4000276478.1Usage : fsutil objectid query Eg : fsutil objectid query C:\Temp\sample.txt
0x4000276578.1Usage : fsutil objectid create Eg : fsutil objectid create C:\Temp\sample.txt
0x4000276678.1Usage : fsutil objectid delete Eg : fsutil objectid delete C:\Temp\sample.txt
0x4000276b78.1Usage : fsutil usn createjournal m= a= Eg : fsutil usn createjournal m=1000 a=100 C:
0x4000276d78.1Usage : fsutil usn queryjournal Eg : fsutil usn queryjournal C:
0x4000276e78.1Usn Journal ID : 0x%1 First Usn : 0x%2 Next Usn : 0x%3 Lowest Valid Usn : 0x%4 Max Usn : 0x%5 Maximum Size : 0x%6 Allocation Delta : 0x%7
0x4000276f78.1Usage : fsutil usn deletejournal /D : Delete /N : Notify Eg : usn deletejournal /D C:
0x4000277078.1Usage : fsutil usn enumdata Eg : fsutil usn enumdata 1 0 1 C:
0x4000277278.1Usage : fsutil usn readdata Eg : fsutil usn readdata C:\Temp\sample.txt
0x4000277378.1Usage : fsutil file findbysid Eg : fsutil file findbysid scottb C:\users
0x400027787---- FILE Commands Supported ---- findbysid Find a file by security identifier queryallocranges Query the allocated ranges for a file setshortname Set the short name for a file setvaliddata Set the valid data length for a file setzerodata Set the zero data for a file createnew Creates a new file of a specified size queryfileid Queries the file ID of the specified file queryfilenamebyid Displays a random link name for the file ID
0x400027797---- FSINFO Commands Supported ---- drives List all drives drivetype Query drive type for a drive volumeinfo Query volume information ntfsinfo Query NTFS specific volume information statistics Query file system statistics
0x4000277b7---- OBJECTID Commands Supported ---- query Query the object identifier set Change the object identifier delete Delete the object identifier create Create the object identifier
0x4000277c7---- QUOTA Commands Supported ---- disable Disable quota tracking and enforcement track Enable quota tracking enforce Enable quota enforcement violations Display quota violations modify Sets disk quota for a user query Query disk quotas
0x4000277d7---- REPARSEPOINT Commands Supported ---- query Query a reparse point delete Delete a reparse point
0x4000277e7---- RESOURCE Commands Supported ---- create Create a Secondary Transactional Resource Manager info Display information relating to a Transactional Resource Manager setautoreset Set whether a default Transactional Resource Manager will clean its transactional metadata on next mount setconsistent Set a Transactional Resource Manager to prefer consistency over availability setavailable Set a Transactional Resource Manager to prefer availability over consistency setlog Change characteristics of a running Transactional Resource Manager start Start a Transactional Resource Manager stop Stop a Transactional Resource Manager
0x4000277f78.1---- SETLOG Commands Supported ---- growth Change the automatic growth settings maxextents Change the maximum number of containers minextents Change the minimum number of containers mode Switch between undo only logging and full logging rename Change the RM's Guid shrink Change the automatic shrink settings size Change the number of containers explicitly
0x400027817---- SPARSE Commands Supported ---- setflag Set sparse queryflag Query sparse queryrange Query range setrange Set sparse range
0x400027827---- TRANSACTION Commands Supported ---- commit Commit a specified transaction list Display currently running transactions fileinfo Display transaction information for a specific file query Display information on a specified transaction rollback Rollback a specified transaction
0x400027837---- USN Commands Supported ---- createjournal Create a USN journal deletejournal Delete a USN journal enumdata Enumerate USN data queryjournal Query the USN data for a volume readdata Read the USN data for a file
0x400027847---- VOLUME Commands Supported ---- dismount Dismount a volume diskfree Query the free space of a volume querycluster Query which file is using a particular cluster
0x4000278878.1Usage : fsutil transaction fileinfo Eg : fsutil transaction fileinfo d:\foobar.txt
0x4000278e78.1Usage : fsutil resource setautoreset true fsutil resource setautoreset false Eg : fsutil resource setautoreset true d:\
0x4000278f78.1Usage : fsutil resource setlog size Eg : fsutil resource setlog size 50 d:\foobar
0x4000279078.1Usage : fsutil resource setlog mode full fsutil resource setlog mode undo Eg : fsutil resource setlog mode full d:\foobar
0x4000279178.1Usage : fsutil resource setlog extentsize Eg : fsutil resource setlog extentsize 50 d:\foobar
0x4000279278.1Usage : fsutil resource setlog rename Eg : fsutil resource setlog rename d:\foobar
0x4000279378.1Usage : fsutil resource setlog maxextents Eg : fsutil resource setlog maxextents 50 d:\foobar
0x4000279478.1Usage : fsutil resource setlog minextents Eg : fsutil resource setlog minextents 5 d:\foobar
0x4000279578.1Usage : fsutil resource setlog growth containers fsutil resource setlog growth percent Eg : fsutil resource setlog growth 5 containers d:\foobar
0x4000279678.1Usage : fsutil resource setlog shrink Eg : fsutil resource setlog shrink 10 d:\foobar
0x400027a37RM Identifier: %1!s!
0x400027b478.1Usage : fsutil file createnew Eg : fsutil file createnew C:\testfile.txt 1000
0x400027dd78.1Usage : fsutil sparse queryflag Eg : fsutil sparse queryflag C:\Temp\sample.txt
0x400027de78.1Usage : fsutil sparse setrange Eg : fsutil sparse setrange C:\Temp\sample.txt 65536 131072
0x400027df78.1Usage : fsutil sparse queryrange Eg : fsutil sparse queryrange C:\Temp\sample.txt
0x400027e17sparse range: %1
0x400027e878.1Usage : fsutil fsinfo drives
0x400027e978.1The FSUTIL utility requires a local volume.
0x400027f078.1Reparse Data Length: 0x%1!08x!
0x400027f27---- REPAIR Commands Supported ---- query Query the self healing state of the volume set Set the self healing state of the volume wait Wait for repair(s) to complete initiate Initiate the repair of a file
0x400027f67Self healing is now enabled for volume %1!s! with flags 0x%2!x!. flags: 1 - enable general repair 8 - warn about potential data loss
0x400027f77Self healing is now disabled for volume %1!s!.
0x400027f87Self healing (including volume bitmap regeneration and crosslink repair) is enabled for volume %1!s!.
0x400027f97Self healing (including volume bitmap regeneration) is enabled for volume %1!s!.
0x400027fa7Self healing is enabled for volume %1!s! with flags 0x%2!x!. flags: 1 - enable general repair 8 - warn about potential data loss
0x400027fb7Self healing is disabled for volume %1!s!.
0x400027fc7Self healing query returns unknown value of 0x%2!08x! for volume %1!s!.
0x400027fd7Current repair is completed for volume %1!s!.
0x400027fe7All repairs are completed for volume %1!s!.
0x400028177Usage : fsutil repair set flags: 0x01 - enable general repair 0x08 - warn about potential data loss 0x10 - disable general repair and bugcheck once on first corruption Eg : fsutil repair set C: 1 fsutil repair set C: 9 fsutil repair set C: 0x10
0x400028187Self healing is now enabled for volume %1!s! with flags 0x%2!x!. flags: 0x01 - enable general repair 0x08 - warn about potential data loss 0x10 - disable general repair and bugcheck once on first corruption
0x400028197Self healing is enabled for volume %1!s! with flags 0x%2!x!. flags: 0x01 - enable general repair 0x08 - warn about potential data loss 0x10 - disable general repair and bugcheck once on first corruption
0x4000281a7Usage : fsutil behavior query
0x4000281b7Usage : fsutil behavior set
0x4000281c78.1usage : set [0 through 3] | [ 1 | 0] When a volume is not specified the operation updates the registry value: 0 - Enable 8dot3 name creation on all volumes on the system 1 - Disable 8dot3 name creation on all volumes on the system 2 - Set 8dot3 name creation on a per volume basis 3 - Disable 8dot3 name creation on all volumes except the system volume When a volume is specified the operation updates the individual volume's on disk flag. This operation is only meaningful if the registry value is set to 2. 0 - Enable 8dot3 name creation on this volume 1 - Disable 8dot3 name creation on this volume This operation takes effect immediately (no reboot required). Sample commands: "fsutil 8dot3name set 1" - disable 8dot3 name creation on all volumes "fsutil 8dot3name set C: 1" - disable 8dot3 name creation on c:
0x4000281d78.1Usage : fsutil resource setconsistent Eg : fsutil resource setconsistent d:\foobar NOTE: The RM must be restarted for a change to this setting to take effect.
0x4000281e78.1Usage : fsutil resource setavailable Eg : fsutil resource setavailable d:\foobar NOTE: The RM must be restarted for a change to this setting to take effect.
0x400028217Successfully set 8dot3name behavior.
0x400028227The volume state for Disable8dot3 is 1 (8dot3 name creation is disabled).
0x400028237The volume state for Disable8dot3 is 0 (8dot3 name creation is enabled).
0x400028247The registry state of NtfsDisable8dot3NameCreation is 0 (Enable 8dot3 name creation on all volumes).
0x400028257The registry state of NtfsDisable8dot3NameCreation is 1 (Disable 8dot3 name creation on all volumes).
0x400028267The registry state of NtfsDisable8dot3NameCreation is 2, the default (Volume level setting).
0x400028277The registry state of NtfsDisable8dot3NameCreation is 3 (Disable 8dot3 name creation on all non system volumes).
0x400028287Based on the above two settings, 8dot3 name creation is enabled on %1.
0x400028297Based on the above two settings, 8dot3 name creation is disabled on %1.
0x4000284f78.1%1 = %2!I64u!
0x4000285178.1usage : query [] When no volume is specified the global 8dot3name state is displayed. When volume is specified the volumes 8dot3name state is displayed. Sample command: "fsutil 8dot3name query" "fsutil 8dot3name query C:"
0x400028557Usage : fsutil volume querycluster [ ...] Eg : fsutil volume querycluster C: 50 0x2000
0x400028567Cluster 0x%1!08x!%2!08x! used by %3!s! %4!s!
0x4000285878.1Usage : fsutil file queryfileid Eg : fsutil file queryfileid C:\testfile.txt
0x400028597Usage : fsutil file queryfilenamebyid Eg : fsutil file queryfilenamebyid C:\ 0x00040000000001bf
0x4000285b7File ID is 0x%1!08x!%2!08x!
0x400027108.1---- Commands Supported ---- 8dot3name 8dot3name management behavior Control file system behavior dirty Manage volume dirty bit file File specific commands fsinfo File system information hardlink Hardlink management objectid Object ID management quota Quota management repair Self healing management reparsepoint Reparse point management resource Transactional Resource Manager management sparse Sparse file control transaction Transaction management usn USN management volume Volume management wim Transparent wim hosting management
0x400027138.1Usage : fsutil fsinfo driveType Eg : fsutil fsinfo driveType C:
0x4000271b8.1Usage : fsutil fsinfo volumeInfo Eg : fsutil fsinfo volumeInfo C:
0x400027478.1MftReads : %1 MftReadBytes : %2 MftWrites : %3 MftWriteBytes : %4 Mft2Writes : %5 Mft2WriteBytes : %6 RootIndexReads : %7 RootIndexReadBytes : %8 RootIndexWrites : %9 RootIndexWriteBytes : %10 BitmapReads : %11 BitmapReadBytes : %12 BitmapWrites : %13 BitmapWriteBytes : %14 MftBitmapReads : %15 MftBitmapReadBytes : %16 MftBitmapWrites : %17 MftBitmapWriteBytes : %18 UserIndexReads : %19 UserIndexReadBytes : %20 UserIndexWrites : %21 UserIndexWriteBytes : %22 LogFileReads : %23 LogFileReadBytes : %24 LogFileWrites : %25 LogFileWriteBytes : %26 LogFileFull : %27 DiskResourceFailure : %28
0x400027508.1Usage : fsutil sparse setflag [1|0] Eg : fsutil sparse setflag C:\Temp\sample.txt
0x400027528.1NTFS Volume Serial Number : 0x%1 NTFS Version : %2!d!.%3!d! LFS Version : %18!d!.%19!d! Number Sectors : 0x%4 Total Clusters : 0x%5 Free Clusters : 0x%6 Total Reserved : 0x%7 Bytes Per Sector : %8!d! Bytes Per Physical Sector : %17!d! Bytes Per Cluster : %9!d! Bytes Per FileRecord Segment : %10!d! Clusters Per FileRecord Segment : %11!d! Mft Valid Data Length : 0x%12 Mft Start Lcn : 0x%13 Mft2 Start Lcn : 0x%14 Mft Zone Start : 0x%15 Mft Zone End : 0x%16
0x400027788.1---- FILE Commands Supported ---- createnew Creates a new file of a specified size findbysid Find a file by security identifier queryallocranges Query the allocated ranges for a file queryextents Query the extents for a file queryfileid Queries the file ID of the specified file queryfilenamebyid Displays a random link name for the file ID queryvaliddata Queries the valid data length for a file setshortname Set the short name for a file setvaliddata Set the valid data length for a file setzerodata Set the zero data for a file
0x400027798.1---- FSINFO Commands Supported ---- drives List all drives driveType Query drive type for a drive ntfsInfo Query NTFS specific volume information sectorInfo Query sector information statistics Query file system statistics volumeInfo Query volume information
0x4000277c8.1---- QUOTA Commands Supported ---- disable Disable quota tracking and enforcement enforce Enable quota enforcement modify Sets disk quota for a user query Query disk quotas track Enable quota tracking violations Display quota violations
0x4000277e8.1---- RESOURCE Commands Supported ---- create Create a Secondary Transactional Resource Manager info Display information relating to a Transactional Resource Manager setautoreset Set whether a default Transactional Resource Manager will clean its transactional metadata on next mount setavailable Set a Transactional Resource Manager to prefer availability over consistency setconsistent Set a Transactional Resource Manager to prefer consistency over availability setlog Change characteristics of a running Transactional Resource Manager start Start a Transactional Resource Manager stop Stop a Transactional Resource Manager
0x400027818.1---- SPARSE Commands Supported ---- queryflag Query sparse queryrange Query range setflag Set sparse setrange Set sparse range
0x400027838.1---- USN Commands Supported ---- createjournal Create a USN journal deletejournal Delete a USN journal enumdata Enumerate USN data readjournal Reads the USN records in the USN journal queryjournal Query the USN data for a volume readdata Read the USN data for a file enablerangetracking Enable write range tracking for a volume
0x400027848.1---- VOLUME Commands Supported ---- diskfree Query the free space of a volume dismount Dismount a volume querycluster Query which file is using a particular cluster filelayout Query all the information available about the file allocationreport Allocated clusters report
0x400027a38.1Resource Manager Identifier : %1!s!
0x4000281a8.1Usage : fsutil behavior query
0x4000281b8.1Usage : fsutil behavior set
0x400028288.1Based on the above two settings, 8dot3 name creation is enabled on %1
0x400028298.1Based on the above two settings, 8dot3 name creation is disabled on %1
0x400028558.1Usage : fsutil volume querycluster [ ...] Eg : fsutil volume querycluster C: 50 0x2000 Attribute Value defintions: ----- ^^^^^ |||||- D = Data Attribute, I=Index Attribute, S=System Attribute, ?=Unknown ||||-- A = Deny defrag requests |||--- T = TxF system file ||---- S = NTFS System Metadata File |----- P = Page File
0x400028598.1Usage : fsutil file queryfilenamebyid Eg : fsutil file queryfilenamebyid C:\ 0x00040000000001bf
0x4000286a8.1Usage : fsutil file queryextents [/R] [ []] /R : If is a reparse point, open it rather than its target : First VCN to query (if omitted, start at VCN 0) : Number of VCNs to query (if omitted or 0, query until EOF) Eg : fsutil file queryextents C:\Temp\sample.txt
0x400028708.1%1 = %2!u! (translates to a zone size of %3!u! MB)
0x400028718.1The FSUTIL utility requires a local NTFS volume or a ReFS volume for that operation.
0x400028738.1Usage : fsutil file queryvaliddata [/R] [/D] /R : If is a reparse point, open it rather than its target /D : Display detailed valid data information Eg : fsutil file queryvaliddata C:\testfile.txt
0x4000287b8.1Usage : fsutil fsinfo sectorInfo Eg : fsutil fsinfo sectorInfo C:
0x4000288d8.1---- TIERING Commands Supported ---- queryflags Display the tiering behavior flags of a volume setflags Enable tiering behavior flags of a volume clearflags Disable tiering behavior flags of a volume tierlist List the storage tiers associated with a volume regionlist List the regions of a volume and their respective storage tiers
0x4000288e8.1Usage : fsutil tiering queryflags Eg : fsutil tiering queryflags D:
0x400028908.1Usage : fsutil tiering setflags Eg : fsutil tiering setflags C: /TrNH
0x400028918.1Usage : fsutil tiering clearflags Eg : fsutil tiering clearflags E: /TrNH
0x400028928.1Usage : fsutil tiering tierlist Eg : fsutil tiering tierlist X:
0x400028938.1Usage : fsutil tiering regionlist Eg : fsutil tiering regionlist F:
0x400028af8.1Usage : fsutil usn enablerangetracking [c= s=] Eg : fsutil usn enablerangetracking c=16384 s=67108864 C: Eg : fsutil usn enablerangetracking c=0 s=0 C: Eg : fsutil usn enablerangetracking C:
0x400028b08.1---- Commands Supported ---- 8dot3name 8dot3name management behavior Control file system behavior dirty Manage volume dirty bit file File specific commands fsinfo File system information hardlink Hardlink management objectid Object ID management quota Quota management repair Self healing management reparsepoint Reparse point management resource Transactional Resource Manager management sparse Sparse file control tiering Storage tiering property management transaction Transaction management usn USN management volume Volume management
0x400028b18.1Usage : fsutil volume filelayout or : fsutil volume filelayout Eg : fsutil volume filelayout C: 5 Eg : fsutil volume filelayout C: 0x00040000000001bf Eg : fsutil volume filelayout C:\$MFT Eg : fsutil volume filelayout C:\Windows
0x400028b58.1Creation Time : %1!s! Last Access Time : %2!s! Last Write Time : %3!s! Change Time : %4!s! LastUsn : %5!I64d! OwnerId : %6!d! SecurityId : %7!d!
0x400028b78.1Link (parent ID, name) : 0x%1!016I64x!, %2!s!
0x400028b98.1Stream : %1!s! Attributes : 0x%2!08x!: %3!s! Flags : 0x%4!08x!: %5!s! Size : %6!I64d! Allocated Size : %7!I64d!
0x400028bd8.1Extents : %1!d! Extents
0x400028be8.1: %1!d!: VCN: %2!I64d! Clusters: %3!I64d! LCN: %4!I64d!
0x400028bf8.1Usage : fsutil volume allocationreport Eg : fsutil volume allocationreport C:
0x400028c08.1Allocation report: Total clusters : %1!I64d! (%2!I64d! bytes) Free clusters : %3!I64d! (%4!I64d! bytes) Reserved clusters : %5!I64d! (%6!I64d! bytes) Total allocated : %7!I64d! bytes The allocation is split between: System files : Count: %8!I64d!. Total allocated: %9!I64d! bytes.
0x400028c18.1%1!-24s!: File ID 0x%2!016I64x!. Total allocated: %3!I64d! bytes.
0x400028c28.1Other system files : Count: %1!I64d!. Total allocated: %2!I64d! bytes.
0x400028c38.1Other system files under %1!s! folder: Count : %2!I64d! Total allocated : %3!I64d! bytes.
0x400028c48.1%1!-28s!: Total allocated: %2!I64d! bytes. Files : Count: %3!I64d!. Total allocated: %4!I64d! bytes. Folders : Count: %5!I64d!. Total allocated: %6!I64d! bytes.
0x400028c58.1User files : Count: %1!I64d!. Total allocated: %2!I64d! bytes.
0x400028c68.1User folders : Count: %1!I64d!. Total allocated: %2!I64d! bytes.
0x400028c78.1Default streams : %1!I64d! Allocated : %2!I64d! Total allocated : %3!I64d! bytes. Named streams : %4!I64d! Allocated : %5!I64d! Total allocated : %6!I64d! bytes. Local metadata streams : %7!I64d! Allocated : %8!I64d! Total allocated : %9!I64d! bytes.
0x400028ca8.1Compressed : %1!I64d! Total allocated : %2!I64d! bytes Total size : %3!I64d! bytes. Savings : %4!s! % Sparse : %5!I64d! Total allocated : %6!I64d! bytes Total size : %7!I64d! bytes. Savings : %8!s! % Encrypted : %9!I64d! Total allocated : %10!I64d! bytes With named streams : %11!I64d! Compressed : %12!I64d! Sparse : %13!I64d! Encrypted : %14!I64d! With no allocation : %15!I64d!
0x400028cb8.1Usage : fsutil usn readjournal [options] Options : minver= - Minimum Major Version of USN_RECORD to return. Default=2. : maxver= - Maximum Major Version of USN_RECORD to return. Default=4. : startusn= - USN to start reading the USN journal from. Default=0. : csv - Print the USN records in CSV format. : wait - wait for more records to be added to the USN journal. : tail - starts reading at the end of the USN journal. If wait is not specified it will just return. Overrides any startusn value. Eg : fsutil usn readjournal C: : fsutil usn readjournal C: minver=2 maxver=3 startusn=88 : fsutil usn readjournal C: startusn=0xF00 : fsutil usn readjournal C: wait : fsutil usn readjournal C: wait tail : fsutil usn readjournal C: csv
0x400029348.1---- WIM Commands Supported ---- enumfiles Enumerate WIM backed files enumwims Enumerate backing WIM files removewim Removes a WIM from backing files queryfile Query the origin of a specific file
0x4000293d8.1Usage : fsutil wim queryfile Eg : fsutil wim queryfile C:\Windows\Notepad.exe
0x4000293e8.1Usage : fsutil wim enumwims Eg : fsutil wim enumwims C:
0x4000293f8.1Usage : fsutil wim enumfiles Eg : fsutil wim enumfiles C: 0
0x400029408.1Usage : fsutil wim removewim Eg : fsutil wim removewim C: 9
0x400029418.1Cannot remove a wim while files still refer to it. Use "fsutil wim enumfiles" to display the list of files.
1266 entries