Common Log (CLFS) Service Defaults in Windows 11
General-purpose logging service.
Default Settings
| Startup type: | Boot |
| Display name: | Common Log (CLFS) |
| Service name: | CLFS |
| Service type: | kernel |
| Error control: | critical |
| Group: | Filter |
| Path: | %SystemRoot%\System32\drivers\CLFS.sys |
| Registry key: | HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\CLFS |
Default Behavior
Common Log (CLFS) is a kernel driver. In Windows 11 it starts by the operating system Boot Loader before the Kernel initialization, as a part of the driver stack. If Common Log (CLFS) fails to start, Windows 11 tries to record the error details into Event Log and restart the PC, using the Last Known Good configuration. If the Last Known Good configuration can't be used, Windows 11 startup process halts with a Stop error. If you disable or delete the CLFS service, Windows 11 won't start.
Restore Default Startup Configuration of Common Log (CLFS)
1. Run the Command Prompt as an administrator.
2. Copy the commands below, paste them into the command window and press ENTER:
sc config CLFS start= boot
sc start CLFS
3. Close the command window and restart the computer.
The CLFS service is using the CLFS.sys file that is located in the C:\Windows\System32\drivers directory. If the file is removed or corrupted, read this article to restore its original version from Windows 11 installation media.