Windows Security Log Event ID 5051

Operating Systems Windows 2008 R2 and 7
Windows 2012 R2 and 8.1
Windows 2016 and 10
Windows Server 2019 and 2022
 • Subcategory
 • Subcategory could not be determined
Type Success
Corresponding events
in Windows 2003
and before

5051: A file was virtualized

On this page

I haven't been able to produce this event. Have you? If so, please start a discussion (see above) and post a sample along with any comments you may have! Don't forget to sanitize any private information.

Free Security Log Resources by Randy

Supercharger Free Edition

Supercharger's built-in Xpath filters leave the noise behind.



Examples of 5051

A file was virtualized.


Security ID:   %1
Account Name:   %2
Account Domain:  %3
Logon ID:   %4


File Name:   %5
Virtual File Name: %6

Process Information:

Process ID:   %7
Process Name:   %8

Top 10 Windows Security Events to Monitor

Free Tool for Windows Event Collection


Additional Resources