File Kernel Trace; Operation Set 1

43 events across 1 channel

Event IDTitleChannel
0ETW Trace
1ETW Trace
2ETW Trace
3ETW Trace
4ETW Trace
5ETW Trace
6ETW Trace
7ETW Trace
8ETW Trace
9ETW Trace
10ETW Trace
11ETW Trace
12ETW Trace
13ETW Trace
14ETW Trace
15ETW Trace
16ETW Trace
17ETW Trace
18ETW Trace
19ETW Trace
20ETW Trace
21ETW Trace
22ETW Trace
23ETW Trace
24ETW Trace
25ETW Trace
26ETW Trace
27ETW Trace
236ETW Trace
237ETW Trace
238ETW Trace
239ETW Trace
240ETW Trace
241ETW Trace
242ETW Trace
243ETW Trace
249ETW Trace
250ETW Trace
251ETW Trace
252ETW Trace
253ETW Trace
254ETW Trace
255ETW Trace

Event ID 0 —

Provider
File Kernel Trace; Operation Set 1
Channel
ETW Trace

Fields

NameDescription
Status
Operation
MinorOperation
SequenceNumber
IsPagingIO
IsFastIO
IsDirectory
CreateOnExisting
StartTime
ProcessId
ProcessCreateTime
FileObject
LastAccessTime
SessionId
WindowStation
AccessToken
SidLength
ParametersLength
ResultLength
PreviousValueLength
UserSID
OperationalParameters
ResultData
PreviousValue
FileName
VolumeDosName
VolumeGuidName
VolumeName

Event ID 1 —

Provider
File Kernel Trace; Operation Set 1
Channel
ETW Trace

Fields

NameDescription
Status
Operation
MinorOperation
SequenceNumber
IsPagingIO
IsFastIO
IsDirectory
CreateOnExisting
StartTime
ProcessId
ProcessCreateTime
FileObject
LastAccessTime
SessionId
WindowStation
AccessToken
SidLength
ParametersLength
ResultLength
PreviousValueLength
UserSID
OperationalParameters
ResultData
PreviousValue
FileName
VolumeDosName
VolumeGuidName
VolumeName

Event ID 2 —

Provider
File Kernel Trace; Operation Set 1
Channel
ETW Trace

Fields

NameDescription
Status
Operation
MinorOperation
SequenceNumber
IsPagingIO
IsFastIO
IsDirectory
CreateOnExisting
StartTime
ProcessId
ProcessCreateTime
FileObject
LastAccessTime
SessionId
WindowStation
AccessToken
SidLength
ParametersLength
ResultLength
PreviousValueLength
UserSID
OperationalParameters
ResultData
PreviousValue
FileName
VolumeDosName
VolumeGuidName
VolumeName

Event ID 3 —

Provider
File Kernel Trace; Operation Set 1
Channel
ETW Trace

Fields

NameDescription
Status
Operation
MinorOperation
SequenceNumber
IsPagingIO
IsFastIO
IsDirectory
CreateOnExisting
StartTime
ProcessId
ProcessCreateTime
FileObject
LastAccessTime
SessionId
WindowStation
AccessToken
SidLength
ParametersLength
ResultLength
PreviousValueLength
UserSID
OperationalParameters
ResultData
PreviousValue
FileName
VolumeDosName
VolumeGuidName
VolumeName

Event ID 4 —

Provider
File Kernel Trace; Operation Set 1
Channel
ETW Trace

Fields

NameDescription
Status
Operation
MinorOperation
SequenceNumber
IsPagingIO
IsFastIO
IsDirectory
CreateOnExisting
StartTime
ProcessId
ProcessCreateTime
FileObject
LastAccessTime
SessionId
WindowStation
AccessToken
SidLength
ParametersLength
ResultLength
PreviousValueLength
UserSID
OperationalParameters
ResultData
PreviousValue
FileName
VolumeDosName
VolumeGuidName
VolumeName

Event ID 5 —

Provider
File Kernel Trace; Operation Set 1
Channel
ETW Trace

Fields

NameDescription
Status
Operation
MinorOperation
SequenceNumber
IsPagingIO
IsFastIO
IsDirectory
CreateOnExisting
StartTime
ProcessId
ProcessCreateTime
FileObject
LastAccessTime
SessionId
WindowStation
AccessToken
SidLength
ParametersLength
ResultLength
PreviousValueLength
UserSID
OperationalParameters
ResultData
PreviousValue
FileName
VolumeDosName
VolumeGuidName
VolumeName

Event ID 6 —

Provider
File Kernel Trace; Operation Set 1
Channel
ETW Trace

Fields

NameDescription
Status
Operation
MinorOperation
SequenceNumber
IsPagingIO
IsFastIO
IsDirectory
CreateOnExisting
StartTime
ProcessId
ProcessCreateTime
FileObject
LastAccessTime
SessionId
WindowStation
AccessToken
SidLength
ParametersLength
ResultLength
PreviousValueLength
UserSID
OperationalParameters
ResultData
PreviousValue
FileName
VolumeDosName
VolumeGuidName
VolumeName

Event ID 7 —

Provider
File Kernel Trace; Operation Set 1
Channel
ETW Trace

Fields

NameDescription
Status
Operation
MinorOperation
SequenceNumber
IsPagingIO
IsFastIO
IsDirectory
CreateOnExisting
StartTime
ProcessId
ProcessCreateTime
FileObject
LastAccessTime
SessionId
WindowStation
AccessToken
SidLength
ParametersLength
ResultLength
PreviousValueLength
UserSID
OperationalParameters
ResultData
PreviousValue
FileName
VolumeDosName
VolumeGuidName
VolumeName

Event ID 8 —

Provider
File Kernel Trace; Operation Set 1
Channel
ETW Trace

Fields

NameDescription
Status
Operation
MinorOperation
SequenceNumber
IsPagingIO
IsFastIO
IsDirectory
CreateOnExisting
StartTime
ProcessId
ProcessCreateTime
FileObject
LastAccessTime
SessionId
WindowStation
AccessToken
SidLength
ParametersLength
ResultLength
PreviousValueLength
UserSID
OperationalParameters
ResultData
PreviousValue
FileName
VolumeDosName
VolumeGuidName
VolumeName

Event ID 9 —

Provider
File Kernel Trace; Operation Set 1
Channel
ETW Trace

Fields

NameDescription
Status
Operation
MinorOperation
SequenceNumber
IsPagingIO
IsFastIO
IsDirectory
CreateOnExisting
StartTime
ProcessId
ProcessCreateTime
FileObject
LastAccessTime
SessionId
WindowStation
AccessToken
SidLength
ParametersLength
ResultLength
PreviousValueLength
UserSID
OperationalParameters
ResultData
PreviousValue
FileName
VolumeDosName
VolumeGuidName
VolumeName

Event ID 10 —

Provider
File Kernel Trace; Operation Set 1
Channel
ETW Trace

Fields

NameDescription
Status
Operation
MinorOperation
SequenceNumber
IsPagingIO
IsFastIO
IsDirectory
CreateOnExisting
StartTime
ProcessId
ProcessCreateTime
FileObject
LastAccessTime
SessionId
WindowStation
AccessToken
SidLength
ParametersLength
ResultLength
PreviousValueLength
UserSID
OperationalParameters
ResultData
PreviousValue
FileName
VolumeDosName
VolumeGuidName
VolumeName

Event ID 11 —

Provider
File Kernel Trace; Operation Set 1
Channel
ETW Trace

Fields

NameDescription
Status
Operation
MinorOperation
SequenceNumber
IsPagingIO
IsFastIO
IsDirectory
CreateOnExisting
StartTime
ProcessId
ProcessCreateTime
FileObject
LastAccessTime
SessionId
WindowStation
AccessToken
SidLength
ParametersLength
ResultLength
PreviousValueLength
UserSID
OperationalParameters
ResultData
PreviousValue
FileName
VolumeDosName
VolumeGuidName
VolumeName

Event ID 12 —

Provider
File Kernel Trace; Operation Set 1
Channel
ETW Trace

Fields

NameDescription
Status
Operation
MinorOperation
SequenceNumber
IsPagingIO
IsFastIO
IsDirectory
CreateOnExisting
StartTime
ProcessId
ProcessCreateTime
FileObject
LastAccessTime
SessionId
WindowStation
AccessToken
SidLength
ParametersLength
ResultLength
PreviousValueLength
UserSID
OperationalParameters
ResultData
PreviousValue
FileName
VolumeDosName
VolumeGuidName
VolumeName

Event ID 13 —

Provider
File Kernel Trace; Operation Set 1
Channel
ETW Trace

Fields

NameDescription
Status
Operation
MinorOperation
SequenceNumber
IsPagingIO
IsFastIO
IsDirectory
CreateOnExisting
StartTime
ProcessId
ProcessCreateTime
FileObject
LastAccessTime
SessionId
WindowStation
AccessToken
SidLength
ParametersLength
ResultLength
PreviousValueLength
UserSID
OperationalParameters
ResultData
PreviousValue
FileName
VolumeDosName
VolumeGuidName
VolumeName

Event ID 14 —

Provider
File Kernel Trace; Operation Set 1
Channel
ETW Trace

Fields

NameDescription
Status
Operation
MinorOperation
SequenceNumber
IsPagingIO
IsFastIO
IsDirectory
CreateOnExisting
StartTime
ProcessId
ProcessCreateTime
FileObject
LastAccessTime
SessionId
WindowStation
AccessToken
SidLength
ParametersLength
ResultLength
PreviousValueLength
UserSID
OperationalParameters
ResultData
PreviousValue
FileName
VolumeDosName
VolumeGuidName
VolumeName

Event ID 15 —

Provider
File Kernel Trace; Operation Set 1
Channel
ETW Trace

Fields

NameDescription
Status
Operation
MinorOperation
SequenceNumber
IsPagingIO
IsFastIO
IsDirectory
CreateOnExisting
StartTime
ProcessId
ProcessCreateTime
FileObject
LastAccessTime
SessionId
WindowStation
AccessToken
SidLength
ParametersLength
ResultLength
PreviousValueLength
UserSID
OperationalParameters
ResultData
PreviousValue
FileName
VolumeDosName
VolumeGuidName
VolumeName

Event ID 16 —

Provider
File Kernel Trace; Operation Set 1
Channel
ETW Trace

Fields

NameDescription
Status
Operation
MinorOperation
SequenceNumber
IsPagingIO
IsFastIO
IsDirectory
CreateOnExisting
StartTime
ProcessId
ProcessCreateTime
FileObject
LastAccessTime
SessionId
WindowStation
AccessToken
SidLength
ParametersLength
ResultLength
PreviousValueLength
UserSID
OperationalParameters
ResultData
PreviousValue
FileName
VolumeDosName
VolumeGuidName
VolumeName

Event ID 17 —

Provider
File Kernel Trace; Operation Set 1
Channel
ETW Trace

Fields

NameDescription
Status
Operation
MinorOperation
SequenceNumber
IsPagingIO
IsFastIO
IsDirectory
CreateOnExisting
StartTime
ProcessId
ProcessCreateTime
FileObject
LastAccessTime
SessionId
WindowStation
AccessToken
SidLength
ParametersLength
ResultLength
PreviousValueLength
UserSID
OperationalParameters
ResultData
PreviousValue
FileName
VolumeDosName
VolumeGuidName
VolumeName

Event ID 18 —

Provider
File Kernel Trace; Operation Set 1
Channel
ETW Trace

Fields

NameDescription
Status
Operation
MinorOperation
SequenceNumber
IsPagingIO
IsFastIO
IsDirectory
CreateOnExisting
StartTime
ProcessId
ProcessCreateTime
FileObject
LastAccessTime
SessionId
WindowStation
AccessToken
SidLength
ParametersLength
ResultLength
PreviousValueLength
UserSID
OperationalParameters
ResultData
PreviousValue
FileName
VolumeDosName
VolumeGuidName
VolumeName

Event ID 19 —

Provider
File Kernel Trace; Operation Set 1
Channel
ETW Trace

Fields

NameDescription
Status
Operation
MinorOperation
SequenceNumber
IsPagingIO
IsFastIO
IsDirectory
CreateOnExisting
StartTime
ProcessId
ProcessCreateTime
FileObject
LastAccessTime
SessionId
WindowStation
AccessToken
SidLength
ParametersLength
ResultLength
PreviousValueLength
UserSID
OperationalParameters
ResultData
PreviousValue
FileName
VolumeDosName
VolumeGuidName
VolumeName

Event ID 20 —

Provider
File Kernel Trace; Operation Set 1
Channel
ETW Trace

Fields

NameDescription
Status
Operation
MinorOperation
SequenceNumber
IsPagingIO
IsFastIO
IsDirectory
CreateOnExisting
StartTime
ProcessId
ProcessCreateTime
FileObject
LastAccessTime
SessionId
WindowStation
AccessToken
SidLength
ParametersLength
ResultLength
PreviousValueLength
UserSID
OperationalParameters
ResultData
PreviousValue
FileName
VolumeDosName
VolumeGuidName
VolumeName

Event ID 21 —

Provider
File Kernel Trace; Operation Set 1
Channel
ETW Trace

Fields

NameDescription
Status
Operation
MinorOperation
SequenceNumber
IsPagingIO
IsFastIO
IsDirectory
CreateOnExisting
StartTime
ProcessId
ProcessCreateTime
FileObject
LastAccessTime
SessionId
WindowStation
AccessToken
SidLength
ParametersLength
ResultLength
PreviousValueLength
UserSID
OperationalParameters
ResultData
PreviousValue
FileName
VolumeDosName
VolumeGuidName
VolumeName

Event ID 22 —

Provider
File Kernel Trace; Operation Set 1
Channel
ETW Trace

Fields

NameDescription
Status
Operation
MinorOperation
SequenceNumber
IsPagingIO
IsFastIO
IsDirectory
CreateOnExisting
StartTime
ProcessId
ProcessCreateTime
FileObject
LastAccessTime
SessionId
WindowStation
AccessToken
SidLength
ParametersLength
ResultLength
PreviousValueLength
UserSID
OperationalParameters
ResultData
PreviousValue
FileName
VolumeDosName
VolumeGuidName
VolumeName

Event ID 23 —

Provider
File Kernel Trace; Operation Set 1
Channel
ETW Trace

Fields

NameDescription
Status
Operation
MinorOperation
SequenceNumber
IsPagingIO
IsFastIO
IsDirectory
CreateOnExisting
StartTime
ProcessId
ProcessCreateTime
FileObject
LastAccessTime
SessionId
WindowStation
AccessToken
SidLength
ParametersLength
ResultLength
PreviousValueLength
UserSID
OperationalParameters
ResultData
PreviousValue
FileName
VolumeDosName
VolumeGuidName
VolumeName

Event ID 24 —

Provider
File Kernel Trace; Operation Set 1
Channel
ETW Trace

Fields

NameDescription
Status
Operation
MinorOperation
SequenceNumber
IsPagingIO
IsFastIO
IsDirectory
CreateOnExisting
StartTime
ProcessId
ProcessCreateTime
FileObject
LastAccessTime
SessionId
WindowStation
AccessToken
SidLength
ParametersLength
ResultLength
PreviousValueLength
UserSID
OperationalParameters
ResultData
PreviousValue
FileName
VolumeDosName
VolumeGuidName
VolumeName

Event ID 25 —

Provider
File Kernel Trace; Operation Set 1
Channel
ETW Trace

Fields

NameDescription
Status
Operation
MinorOperation
SequenceNumber
IsPagingIO
IsFastIO
IsDirectory
CreateOnExisting
StartTime
ProcessId
ProcessCreateTime
FileObject
LastAccessTime
SessionId
WindowStation
AccessToken
SidLength
ParametersLength
ResultLength
PreviousValueLength
UserSID
OperationalParameters
ResultData
PreviousValue
FileName
VolumeDosName
VolumeGuidName
VolumeName

Event ID 26 —

Provider
File Kernel Trace; Operation Set 1
Channel
ETW Trace

Fields

NameDescription
Status
Operation
MinorOperation
SequenceNumber
IsPagingIO
IsFastIO
IsDirectory
CreateOnExisting
StartTime
ProcessId
ProcessCreateTime
FileObject
LastAccessTime
SessionId
WindowStation
AccessToken
SidLength
ParametersLength
ResultLength
PreviousValueLength
UserSID
OperationalParameters
ResultData
PreviousValue
FileName
VolumeDosName
VolumeGuidName
VolumeName

Event ID 27 —

Provider
File Kernel Trace; Operation Set 1
Channel
ETW Trace

Fields

NameDescription
Status
Operation
MinorOperation
SequenceNumber
IsPagingIO
IsFastIO
IsDirectory
CreateOnExisting
StartTime
ProcessId
ProcessCreateTime
FileObject
LastAccessTime
SessionId
WindowStation
AccessToken
SidLength
ParametersLength
ResultLength
PreviousValueLength
UserSID
OperationalParameters
ResultData
PreviousValue
FileName
VolumeDosName
VolumeGuidName
VolumeName

Event ID 236 —

Provider
File Kernel Trace; Operation Set 1
Channel
ETW Trace

Fields

NameDescription
Status
Operation
MinorOperation
SequenceNumber
IsPagingIO
IsFastIO
IsDirectory
CreateOnExisting
StartTime
ProcessId
ProcessCreateTime
FileObject
LastAccessTime
SessionId
WindowStation
AccessToken
SidLength
ParametersLength
ResultLength
PreviousValueLength
UserSID
OperationalParameters
ResultData
PreviousValue
FileName
VolumeDosName
VolumeGuidName
VolumeName

Event ID 237 —

Provider
File Kernel Trace; Operation Set 1
Channel
ETW Trace

Fields

NameDescription
Status
Operation
MinorOperation
SequenceNumber
IsPagingIO
IsFastIO
IsDirectory
CreateOnExisting
StartTime
ProcessId
ProcessCreateTime
FileObject
LastAccessTime
SessionId
WindowStation
AccessToken
SidLength
ParametersLength
ResultLength
PreviousValueLength
UserSID
OperationalParameters
ResultData
PreviousValue
FileName
VolumeDosName
VolumeGuidName
VolumeName

Event ID 238 —

Provider
File Kernel Trace; Operation Set 1
Channel
ETW Trace

Fields

NameDescription
Status
Operation
MinorOperation
SequenceNumber
IsPagingIO
IsFastIO
IsDirectory
CreateOnExisting
StartTime
ProcessId
ProcessCreateTime
FileObject
LastAccessTime
SessionId
WindowStation
AccessToken
SidLength
ParametersLength
ResultLength
PreviousValueLength
UserSID
OperationalParameters
ResultData
PreviousValue
FileName
VolumeDosName
VolumeGuidName
VolumeName

Event ID 239 —

Provider
File Kernel Trace; Operation Set 1
Channel
ETW Trace

Fields

NameDescription
Status
Operation
MinorOperation
SequenceNumber
IsPagingIO
IsFastIO
IsDirectory
CreateOnExisting
StartTime
ProcessId
ProcessCreateTime
FileObject
LastAccessTime
SessionId
WindowStation
AccessToken
SidLength
ParametersLength
ResultLength
PreviousValueLength
UserSID
OperationalParameters
ResultData
PreviousValue
FileName
VolumeDosName
VolumeGuidName
VolumeName

Event ID 240 —

Provider
File Kernel Trace; Operation Set 1
Channel
ETW Trace

Fields

NameDescription
Status
Operation
MinorOperation
SequenceNumber
IsPagingIO
IsFastIO
IsDirectory
CreateOnExisting
StartTime
ProcessId
ProcessCreateTime
FileObject
LastAccessTime
SessionId
WindowStation
AccessToken
SidLength
ParametersLength
ResultLength
PreviousValueLength
UserSID
OperationalParameters
ResultData
PreviousValue
FileName
VolumeDosName
VolumeGuidName
VolumeName

Event ID 241 —

Provider
File Kernel Trace; Operation Set 1
Channel
ETW Trace

Fields

NameDescription
Status
Operation
MinorOperation
SequenceNumber
IsPagingIO
IsFastIO
IsDirectory
CreateOnExisting
StartTime
ProcessId
ProcessCreateTime
FileObject
LastAccessTime
SessionId
WindowStation
AccessToken
SidLength
ParametersLength
ResultLength
PreviousValueLength
UserSID
OperationalParameters
ResultData
PreviousValue
FileName
VolumeDosName
VolumeGuidName
VolumeName

Event ID 242 —

Provider
File Kernel Trace; Operation Set 1
Channel
ETW Trace

Fields

NameDescription
Status
Operation
MinorOperation
SequenceNumber
IsPagingIO
IsFastIO
IsDirectory
CreateOnExisting
StartTime
ProcessId
ProcessCreateTime
FileObject
LastAccessTime
SessionId
WindowStation
AccessToken
SidLength
ParametersLength
ResultLength
PreviousValueLength
UserSID
OperationalParameters
ResultData
PreviousValue
FileName
VolumeDosName
VolumeGuidName
VolumeName

Event ID 243 —

Provider
File Kernel Trace; Operation Set 1
Channel
ETW Trace

Fields

NameDescription
Status
Operation
MinorOperation
SequenceNumber
IsPagingIO
IsFastIO
IsDirectory
CreateOnExisting
StartTime
ProcessId
ProcessCreateTime
FileObject
LastAccessTime
SessionId
WindowStation
AccessToken
SidLength
ParametersLength
ResultLength
PreviousValueLength
UserSID
OperationalParameters
ResultData
PreviousValue
FileName
VolumeDosName
VolumeGuidName
VolumeName

Event ID 249 —

Provider
File Kernel Trace; Operation Set 1
Channel
ETW Trace

Fields

NameDescription
Status
Operation
MinorOperation
SequenceNumber
IsPagingIO
IsFastIO
IsDirectory
CreateOnExisting
StartTime
ProcessId
ProcessCreateTime
FileObject
LastAccessTime
SessionId
WindowStation
AccessToken
SidLength
ParametersLength
ResultLength
PreviousValueLength
UserSID
OperationalParameters
ResultData
PreviousValue
FileName
VolumeDosName
VolumeGuidName
VolumeName

Event ID 250 —

Provider
File Kernel Trace; Operation Set 1
Channel
ETW Trace

Fields

NameDescription
Status
Operation
MinorOperation
SequenceNumber
IsPagingIO
IsFastIO
IsDirectory
CreateOnExisting
StartTime
ProcessId
ProcessCreateTime
FileObject
LastAccessTime
SessionId
WindowStation
AccessToken
SidLength
ParametersLength
ResultLength
PreviousValueLength
UserSID
OperationalParameters
ResultData
PreviousValue
FileName
VolumeDosName
VolumeGuidName
VolumeName

Event ID 251 —

Provider
File Kernel Trace; Operation Set 1
Channel
ETW Trace

Fields

NameDescription
Status
Operation
MinorOperation
SequenceNumber
IsPagingIO
IsFastIO
IsDirectory
CreateOnExisting
StartTime
ProcessId
ProcessCreateTime
FileObject
LastAccessTime
SessionId
WindowStation
AccessToken
SidLength
ParametersLength
ResultLength
PreviousValueLength
UserSID
OperationalParameters
ResultData
PreviousValue
FileName
VolumeDosName
VolumeGuidName
VolumeName

Event ID 252 —

Provider
File Kernel Trace; Operation Set 1
Channel
ETW Trace

Fields

NameDescription
Status
Operation
MinorOperation
SequenceNumber
IsPagingIO
IsFastIO
IsDirectory
CreateOnExisting
StartTime
ProcessId
ProcessCreateTime
FileObject
LastAccessTime
SessionId
WindowStation
AccessToken
SidLength
ParametersLength
ResultLength
PreviousValueLength
UserSID
OperationalParameters
ResultData
PreviousValue
FileName
VolumeDosName
VolumeGuidName
VolumeName

Event ID 253 —

Provider
File Kernel Trace; Operation Set 1
Channel
ETW Trace

Fields

NameDescription
Status
Operation
MinorOperation
SequenceNumber
IsPagingIO
IsFastIO
IsDirectory
CreateOnExisting
StartTime
ProcessId
ProcessCreateTime
FileObject
LastAccessTime
SessionId
WindowStation
AccessToken
SidLength
ParametersLength
ResultLength
PreviousValueLength
UserSID
OperationalParameters
ResultData
PreviousValue
FileName
VolumeDosName
VolumeGuidName
VolumeName

Event ID 254 —

Provider
File Kernel Trace; Operation Set 1
Channel
ETW Trace

Fields

NameDescription
Status
Operation
MinorOperation
SequenceNumber
IsPagingIO
IsFastIO
IsDirectory
CreateOnExisting
StartTime
ProcessId
ProcessCreateTime
FileObject
LastAccessTime
SessionId
WindowStation
AccessToken
SidLength
ParametersLength
ResultLength
PreviousValueLength
UserSID
OperationalParameters
ResultData
PreviousValue
FileName
VolumeDosName
VolumeGuidName
VolumeName

Event ID 255 —

Provider
File Kernel Trace; Operation Set 1
Channel
ETW Trace

Fields

NameDescription
Status
Operation
MinorOperation
SequenceNumber
IsPagingIO
IsFastIO
IsDirectory
CreateOnExisting
StartTime
ProcessId
ProcessCreateTime
FileObject
LastAccessTime
SessionId
WindowStation
AccessToken
SidLength
ParametersLength
ResultLength
PreviousValueLength
UserSID
OperationalParameters
ResultData
PreviousValue
FileName
VolumeDosName
VolumeGuidName
VolumeName