The event that is logged in the Application log resembles the following:
    Log Name:      Application
    
Source:        VSS
    
Date:          <date and time>
    
Event ID:      12333
    
Task Category: None
    
Level:         Warning
    
User:          N/A
    
Computer:      <computer name>
    
Description:   Volume Shadow Copy Warning: The provider has reported a storage identifier 
    that is not supported by VSS.     
The following are the suggested operations for this VSS warning.
Operation:- Check whether the volume is supported by a provider.
- Add a volume to a shadow copy set.
Context:Execution Context: Provider
   Provider Name: <provider name>
   Provider Version: 1.0
   Provider ID: {b57190af-454a-4dd0-8afd-e57facd5d9af}
   Volume Name: \\?\Volume{5b1ced58-7dd1-11dc-b4df-00065ba14874}\
   Snapshot Context: 25
   Execution Context: Coordinator
   Provider ID: {00000000-0000-0000-0000-000000000000}
   Volume Name: \\?\Volume{5b1ced58-7dd1-11dc-b4df-00065ba14874}\
   Execution Context: Coordinator
- System
  - Provider
   [ Name]  VSS
  - EventID 12333
   [ Qualifiers]  0
   Level 3
   Task 0
   Keywords 0x80000000000000
  - TimeCreated
   [ SystemTime]  <time>
   EventRecordID 279
   Channel Application
   Computer <computer name>
   Security
- EventData
   1
   1
   60
   0
   1
In Words
0000: 6F43202D 203A6564 48524F43 43545557
0008: 30303030 38303331 6143202D 203A6C6C
0010: 48524F43 43545557 30303030 35333231
0018: 4950202D 20203A44 30303030 30323031
0020: 4954202D 20203A44 30303030 32393132
0028: 4D43202D 20203A44 575C3A43 6F646E69
0030: 735C7377 65747379 5C32336D 76737376
0038: 78652E63 20202065 7355202D 203A7265
0040: 4120544E 4F485455 59544952 5359535C
0048: 204D4554 20202020 6953202D 20203A64
0050: 2D312D53 38312D35
In Bytes
0000: 2D 20 43 6F 64 65 3A 20   - Code:
0008: 43 4F 52 48 57 55 54 43   CORHWUTC
0010: 30 30 30 30 31 33 30 38   00001308
0018: 2D 20 43 61 6C 6C 3A 20   - Call:
0020: 43 4F 52 48 57 55 54 43   CORHWUTC
0028: 30 30 30 30 31 32 33 35   00001235
0030: 2D 20 50 49 44 3A 20 20   - PID:
0038: 30 30 30 30 31 30 32 30   00001020
0040: 2D 20 54 49 44 3A 20 20   - TID:
0048: 30 30 30 30 32 31 39 32   00002192
0050: 2D 20 43 4D 44 3A 20 20   - CMD:
0058: 43 3A 5C 57 69 6E 64 6F   C:\Windo
0060: 77 73 5C 73 79 73 74 65   ws\syste
0068: 6D 33 32 5C 76 73 73 76   m32\vssv
0070: 63 2E 65 78 65 20 20 20   c.exe
0078: 2D 20 55 73 65 72 3A 20   - User:
0080: 4E 54 20 41 55 54 48 4F   NT AUTHO
0088: 52 49 54 59 5C 53 59 53   RITY\SYS
0090: 54 45 4D 20 20 20 20 20   TEM
0098: 2D 20 53 69 64 3A 20 20   - Sid:
00a0: 53 2D 31 2D 35 2D 31 38   S-1-5-18