Microsoft-Windows-DesktopActivityModerator
21 events across 1 channel
Event ID 1 —
Event ID 4 —
Event ID 9 —
Fields #
| Name | Description |
|---|---|
NTSTATUS UInt32 | — |
Event ID 11 —
Event ID 19 —
Event ID 21 —
Fields #
| Name | Description |
|---|---|
SuspendFlag Boolean | — |
Event ID 22 —
Fields #
| Name | Description |
|---|---|
SuspendFlag Boolean | — |
Event ID 23 —
Fields #
| Name | Description |
|---|---|
SuspendFlag Boolean | — |
Event ID 24 —
Fields #
| Name | Description |
|---|---|
SuspendFlag Boolean | — |
Event ID 25 —
Fields #
| Name | Description |
|---|---|
ActiveFlag Boolean | — |
Event ID 26 —
Fields #
| Name | Description |
|---|---|
ActiveFlag Boolean | — |
Event ID 31 —
Fields #
| Name | Description |
|---|---|
ProcessId UInt32 | — |
SessionId UInt32 | — |
ImageFileNameLength UInt16 | — |
ImageFileName UnicodeString | — |
CommandLineLength UInt16 | — |
CommandLine UnicodeString | — |
Event ID 32 —
Fields #
| Name | Description |
|---|---|
ProcessId UInt32 | — |
SessionId UInt32 | — |
Event ID 41 —
Fields #
| Name | Description |
|---|---|
ProcessId UInt32 | — |
SessionId UInt32 | — |
ExemptGroup UInt32 | — |
RegisterAtLaunch Boolean | — |
Event ID 42 —
Fields #
| Name | Description |
|---|---|
PolicyRecords UInt32 | — |
Event ID 51 —
Fields #
| Name | Description |
|---|---|
State UInt32 | — |
NTSTATUS UInt32 | — |
WorkItemQueued Boolean | — |
Event ID 52 —
Fields #
| Name | Description |
|---|---|
ClientState UInt32 | — |
Event ID 53 —
Fields #
| Name | Description |
|---|---|
Flags UInt32 | — |
Event ID 54 —
Event ID 60 —
Fields #
| Name | Description |
|---|---|
DeviceBucket UInt32 | — |
ElapsedTimeMs UInt32 | — |
FastIoCount UInt32 | — |
SlowIoCount UInt32 | — |
Event ID 61 —
Fields #
| Name | Description |
|---|---|
DeviceType UInt16 | — |
DeviceBucket UInt32 | — |
ElapsedTime UInt64 | — |
SlowIo Boolean | — |