Microsoft-Windows-Diagnosis-PCW
20 events across 3 channels
Event ID 1 — Provider ProviderGuid failed to register.
Event ID 2 — Provider ProviderGuid failed to register counter set CounterSetGuid.
Event ID 3 — Instance (CounterSetGuid, InstanceName, InstanceId) could not be created.
Description
Instance (CounterSetGuid, InstanceName, InstanceId) could not be created. Error: "Error".
Message #
Fields #
| Name | Description |
|---|---|
Error UInt32 | — |
CounterSetGuid GUID | — |
InstanceName UnicodeString | — |
InstanceId UInt32 | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Diagnosis-PCW",
"guid": "AABF8B86-7936-4FA2-ACB0-63127F879DBF",
"event_source_name": "",
"event_id": 3,
"version": 0,
"level": 0,
"task": 0,
"opcode": 0,
"keywords": 9223372036854777856,
"time_created": "2026-03-13T20:26:07.358863+00:00",
"event_record_id": 2245,
"correlation": {
"ActivityID": "010930CA-58CC-4D55-AD7E-3768B763C942"
},
"execution": {
"process_id": 1840,
"thread_id": 4820
},
"channel": "Microsoft-Windows-Diagnosis-PCW/Operational",
"computer": "LAB-WIN11.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"Error": 183,
"CounterSetGuid": "90C3888A-474E-4932-9925-ED1DC6731F36",
"InstanceName": "D66F4153-89DD-4D11-8753-19E1BF9370ED configuration file",
"InstanceId": 0
},
"message": ""
}
Event ID 4 — About to call provider ProviderGuid callback with arguments (CallbackReason, MachineName, MachineNameSize).
Event ID 5 — Callback returned.
Description
Callback returned. Return value: "Status".
Message #
Fields #
| Name | Description |
|---|---|
Status UInt32 | — NTSTATUS reference |
Event ID 6 — Provider ProviderGuid received an invalid notification with size Size.
Event ID 7 — Provider ProviderGuid received notification: RequestCode.
Event ID 8 — Provider ProviderGuid notification handler has replied with size Size and error code "Status".
Description
Provider ProviderGuid notification handler has replied with size Size and error code "Status".
Message #
Fields #
| Name | Description |
|---|---|
ProviderGuid GUID | — |
Status UInt32 | — NTSTATUS reference |
Size UInt32 | — |
Event ID 9 — Notification returning with status: "Status".
Description
Notification returning with status: "Status".
Message #
Fields #
| Name | Description |
|---|---|
Status UInt32 | — NTSTATUS reference |
Event ID 13 — Query of provider ProviderGuid with id Id had data collected.
Event ID 16 — Counter CounterId of instance (CounterSetGuid, InstanceName, InstanceId) could not be modified.
#Description
Counter CounterId of instance (CounterSetGuid, InstanceName, InstanceId) could not be modified. Error: "Error".
Message #
Fields #
| Name | Description |
|---|---|
Error UInt32 | — |
CounterSetGuid GUID | — |
InstanceName UnicodeString | — |
InstanceId UInt32 | — |
CounterId UInt32 | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Diagnosis-PCW",
"guid": "AABF8B86-7936-4FA2-ACB0-63127F879DBF",
"event_source_name": "",
"event_id": 16,
"version": 0,
"level": 0,
"task": 0,
"opcode": 0,
"keywords": 9223372036854777856,
"time_created": "2022-04-07T08:15:12.584665+00:00",
"event_record_id": 352,
"correlation": {},
"execution": {
"process_id": 1300,
"thread_id": 1856
},
"channel": "Microsoft-Windows-Diagnosis-PCW/Operational",
"computer": "WIN-FPV0DSIC9O6.lab.local",
"security": {
"user_id": "S-1-5-19"
}
},
"event_data": {
"Error": 1168,
"CounterSetGuid": "40E6824E-1B9B-4329-9A6E-E94C8FB03A3F",
"InstanceName": "_Default",
"InstanceId": 0,
"CounterId": 84
},
"message": ""
}
References #
- Example event sourced from https://github.com/NextronSystems/evtx-baseline