Microsoft-Windows-Diagnosis-PLA

48 events across 2 channels

EventTitleChannel
1000Data collector set DataCollectorSetCreation.Name was created by …Operational
1001Data collector set DataCollectorSetEdit.Name was changed by …Operational
1002Data collector set DataCollectorSetDeletion.Name was deleted by …Operational
1003Data collector set DataCollectorSetStart.Name started as …Operational
1004Data collector set Name failed to start as User with error code Error.Operational
1005Data collector set DataCollectorSetStop.Name stopped.Operational
1006Data collector set Name stopped because of error Error.Operational
1007Data collector set Name launched task TaskName.Operational
1008Data collector set Name failed to launch task TaskName with error code Error.Operational
1009PLA upgrade failed with error code Error.Operational
1010Counter CounterName could not be added to collector Name, error code is Error.Operational
1011Configuration data collector DataCollecotrSet\Name completed.Operational
1012Data collector set Name is compiling.Operational
1013Data collector set Name segmented.Operational
1014Alert Data Collector Name in Data Collector Set DataCollecotrSet failed to start …Operational
1015Alert Data Collector Name in Data Collector Set DataCollecotrSet failed to start …Operational
1016Alert Data Collector Name in Data Collector Set DataCollecotrSet failed to write …Operational
1017PLA failed to send cabinet file CabName to server ServerName, error code is …Operational
2031Message.Operational
3000Description.Operational
3001Description.Operational
3002Description.Operational
5001task_05001Debug
5002task_05002Debug
5003task_05003Debug
5004task_05004Debug
5005task_05005Debug
5006task_05006Debug
5007task_05007Debug
5008task_05008Debug
5009task_05009Debug
5010task_05010Debug
5011task_05011Debug
5012task_05012Debug
5013task_05013Debug
5014task_05014Debug
5015task_05015Debug
5016task_05016Debug
5017task_05017Debug
5018task_05018Debug
5019task_05019Debug
5020task_05020Debug
5021task_05021Debug
5022task_05022Debug
5023task_05023Debug
5024task_05024Debug
5025task_05025Debug
5026task_05026Debug

Event ID 1000: Data collector set DataCollectorSetCreation.Name was created by DataCollectorSetCreation.UserName.

#
Provider
Microsoft-Windows-Diagnosis-PLA
Channel
Operational
Level
Informational

Description

Data collector set DataCollectorSetCreation.Name was created by DataCollectorSetCreation.UserName.

Message #

Data collector set %1 was created by %2.

Fields #

NameDescription
Name UnicodeString
User UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Diagnosis-PLA",
    "guid": "E4D53F84-7DE3-11D8-9435-505054503030",
    "event_source_name": "",
    "event_id": 1000,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775808,
    "time_created": "2026-03-13T22:03:17.259228+00:00",
    "event_record_id": 1,
    "correlation": {},
    "execution": {
      "process_id": 11200,
      "thread_id": 10592
    },
    "channel": "Microsoft-Windows-Diagnosis-PLA/Operational",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1105"
    }
  },
  "user_data": {
    "DataCollectorSetCreation": {
      "Name": "TestEventCollector",
      "UserName": "ludus\\domainadmin"
    }
  },
  "message": ""
}

Event ID 1001: Data collector set DataCollectorSetEdit.Name was changed by DataCollectorSetEdit.UserName.

#
Provider
Microsoft-Windows-Diagnosis-PLA
Channel
Operational
Level
Informational

Description

Data collector set DataCollectorSetEdit.Name was changed by DataCollectorSetEdit.UserName.

Message #

Data collector set %1 was changed by %2.

Fields #

NameDescription
Name UnicodeString
User UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Diagnosis-PLA",
    "guid": "E4D53F84-7DE3-11D8-9435-505054503030",
    "event_source_name": "",
    "event_id": 1001,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775808,
    "time_created": "2026-03-13T22:03:18.006697+00:00",
    "event_record_id": 2,
    "correlation": {},
    "execution": {
      "process_id": 10872,
      "thread_id": 11492
    },
    "channel": "Microsoft-Windows-Diagnosis-PLA/Operational",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-19"
    }
  },
  "user_data": {
    "DataCollectorSetEdit": {
      "Name": "TestEventCollector",
      "UserName": "NT AUTHORITY\\LOCAL SERVICE"
    }
  },
  "message": ""
}

Event ID 1002: Data collector set DataCollectorSetDeletion.Name was deleted by DataCollectorSetDeletion.UserName.

#
Provider
Microsoft-Windows-Diagnosis-PLA
Channel
Operational
Level
Informational

Description

Data collector set DataCollectorSetDeletion.Name was deleted by DataCollectorSetDeletion.UserName.

Message #

Data collector set %1 was deleted by %2.

Fields #

NameDescription
Name UnicodeString
User UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Diagnosis-PLA",
    "guid": "E4D53F84-7DE3-11D8-9435-505054503030",
    "event_source_name": "",
    "event_id": 1002,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775808,
    "time_created": "2026-03-13T22:03:24.662101+00:00",
    "event_record_id": 5,
    "correlation": {},
    "execution": {
      "process_id": 8176,
      "thread_id": 4812
    },
    "channel": "Microsoft-Windows-Diagnosis-PLA/Operational",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1105"
    }
  },
  "user_data": {
    "DataCollectorSetDeletion": {
      "Name": "TestEventCollector",
      "UserName": "ludus\\domainadmin"
    }
  },
  "message": ""
}

Event ID 1003: Data collector set DataCollectorSetStart.Name started as DataCollectorSetStart.UserName.

#
Provider
Microsoft-Windows-Diagnosis-PLA
Channel
Operational
Level
Informational

Description

Data collector set DataCollectorSetStart.Name started as DataCollectorSetStart.UserName.

Message #

Data collector set %1 started as %3.

Fields #

NameDescription
Name UnicodeString
Key UnicodeString
User UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Diagnosis-PLA",
    "guid": "E4D53F84-7DE3-11D8-9435-505054503030",
    "event_source_name": "",
    "event_id": 1003,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775808,
    "time_created": "2026-03-13T22:03:18.022218+00:00",
    "event_record_id": 3,
    "correlation": {},
    "execution": {
      "process_id": 12224,
      "thread_id": 11396
    },
    "channel": "Microsoft-Windows-Diagnosis-PLA/Operational",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "user_data": {
    "DataCollectorSetStart": {
      "Name": "TestEventCollector",
      "Key": "0x1944_0x1eac_0x225e1a275",
      "UserName": "ludus\\LAB-DC01$"
    }
  },
  "message": ""
}

Event ID 1004: Data collector set Name failed to start as User with error code Error.

#
Provider
Microsoft-Windows-Diagnosis-PLA
Channel
Operational

Description

Data collector set Name failed to start as User with error code Error.

Message #

Data collector set %1 failed to start as %3 with error code %4.

Fields #

NameDescription
Name UnicodeString
Key UnicodeString
User UnicodeString
Error UInt32

Event ID 1005: Data collector set DataCollectorSetStop.Name stopped.

#
Provider
Microsoft-Windows-Diagnosis-PLA
Channel
Operational
Level
Informational

Description

Data collector set DataCollectorSetStop.Name stopped.

Message #

Data collector set %1 stopped.

Fields #

NameDescription
Name UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Diagnosis-PLA",
    "guid": "E4D53F84-7DE3-11D8-9435-505054503030",
    "event_source_name": "",
    "event_id": 1005,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775808,
    "time_created": "2026-03-13T22:03:23.041732+00:00",
    "event_record_id": 4,
    "correlation": {},
    "execution": {
      "process_id": 12224,
      "thread_id": 5752
    },
    "channel": "Microsoft-Windows-Diagnosis-PLA/Operational",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "user_data": {
    "DataCollectorSetStop": {
      "Name": "TestEventCollector"
    }
  },
  "message": ""
}

Event ID 1006: Data collector set Name stopped because of error Error.

#
Provider
Microsoft-Windows-Diagnosis-PLA
Channel
Operational

Description

Data collector set Name stopped because of error Error.

Message #

Data collector set %1 stopped because of error %2.

Fields #

NameDescription
Name UnicodeString
Error UInt32

Event ID 1007: Data collector set Name launched task TaskName.

#
Provider
Microsoft-Windows-Diagnosis-PLA
Channel
Operational

Description

Data collector set Name launched task TaskName.

Message #

Data collector set %1 launched task %2.

Fields #

NameDescription
Name UnicodeString
TaskName UnicodeString

Event ID 1008: Data collector set Name failed to launch task TaskName with error code Error.

#
Provider
Microsoft-Windows-Diagnosis-PLA
Channel
Operational

Description

Data collector set Name failed to launch task TaskName with error code Error.

Message #

Data collector set %1 failed to launch task %2 with error code %3.

Fields #

NameDescription
Name UnicodeString
TaskName UnicodeString
Error UInt32

Event ID 1009: PLA upgrade failed with error code Error.

#
Provider
Microsoft-Windows-Diagnosis-PLA
Channel
Operational

Description

PLA upgrade failed with error code Error.

Message #

PLA upgrade failed with error code %1.

Fields #

NameDescription
Error UInt32

Event ID 1010: Counter CounterName could not be added to collector Name, error code is Error.

#
Provider
Microsoft-Windows-Diagnosis-PLA
Channel
Operational

Description

Counter CounterName could not be added to collector Name, error code is Error.

Message #

Counter %2 could not be added to collector %1, error code is %3.

Fields #

NameDescription
Name UnicodeString
CounterName UnicodeString
Error UInt32

Event ID 1011: Configuration data collector DataCollecotrSet\Name completed.

#
Provider
Microsoft-Windows-Diagnosis-PLA
Channel
Operational

Description

Configuration data collector DataCollecotrSet\Name completed.

Message #

Configuration data collector %1\%2 completed.

Fields #

NameDescription
DataCollecotrSet UnicodeString
Name UnicodeString

Event ID 1012: Data collector set Name is compiling.

#
Provider
Microsoft-Windows-Diagnosis-PLA
Channel
Operational

Description

Data collector set Name is compiling.

Message #

Data collector set %1 is compiling.

Fields #

NameDescription
Name UnicodeString

Event ID 1013: Data collector set Name segmented.

#
Provider
Microsoft-Windows-Diagnosis-PLA
Channel
Operational

Description

Data collector set Name segmented.

Message #

Data collector set %1 segmented.

Fields #

NameDescription
Name UnicodeString

Event ID 1014: Alert Data Collector Name in Data Collector Set DataCollecotrSet failed to start task, error code is Error.

#
Provider
Microsoft-Windows-Diagnosis-PLA
Channel
Operational

Description

Alert Data Collector Name in Data Collector Set DataCollecotrSet failed to start task, error code is Error.

Message #

Alert Data Collector %2 in Data Collector Set %1 failed to start task, error code is %3.

Fields #

NameDescription
DataCollecotrSet UnicodeString
Name UnicodeString
Error UInt32

Event ID 1015: Alert Data Collector Name in Data Collector Set DataCollecotrSet failed to start Data Collector Set, error code is Error.

#
Provider
Microsoft-Windows-Diagnosis-PLA
Channel
Operational

Description

Alert Data Collector Name in Data Collector Set DataCollecotrSet failed to start Data Collector Set, error code is Error.

Message #

Alert Data Collector %2 in Data Collector Set %1 failed to start Data Collector Set, error code is %3.

Fields #

NameDescription
DataCollecotrSet UnicodeString
Name UnicodeString
Error UInt32

Event ID 1016: Alert Data Collector Name in Data Collector Set DataCollecotrSet failed to write event log event, error code is Error.

#
Provider
Microsoft-Windows-Diagnosis-PLA
Channel
Operational

Description

Alert Data Collector Name in Data Collector Set DataCollecotrSet failed to write event log event, error code is Error.

Message #

Alert Data Collector %2 in Data Collector Set %1 failed to write event log event, error code is %3.

Fields #

NameDescription
DataCollecotrSet UnicodeString
Name UnicodeString
Error UInt32

Event ID 1017: PLA failed to send cabinet file CabName to server ServerName, error code is Error.

#
Provider
Microsoft-Windows-Diagnosis-PLA
Channel
Operational

Description

PLA failed to send cabinet file CabName to server ServerName, error code is Error.

Message #

PLA failed to send cabinet file %2 to server %1, error code is %3.

Fields #

NameDescription
ServerName UnicodeString
CabName UnicodeString
Error UInt32

Event ID 2031: Message.

#
Provider
Microsoft-Windows-Diagnosis-PLA
Channel
Operational

Description

Message

Message #

%5

Fields #

NameDescription
Counter UnicodeString
Value UnicodeString
Operator UnicodeString
Threshold UnicodeString
Message UnicodeString

Event ID 3000: Description.

#
Provider
Microsoft-Windows-Diagnosis-PLA
Channel
Operational

Description

Description

Message #

%2

Fields #

NameDescription
ReportFileName UnicodeString
Description UnicodeString

Event ID 3001: Description.

#
Provider
Microsoft-Windows-Diagnosis-PLA
Channel
Operational

Description

Description

Message #

%2

Fields #

NameDescription
ReportFileName UnicodeString
Description UnicodeString

Event ID 3002: Description.

#
Provider
Microsoft-Windows-Diagnosis-PLA
Channel
Operational

Description

Description

Message #

%2

Fields #

NameDescription
ReportFileName UnicodeString
Description UnicodeString

Event ID 5001: task_05001

#
Provider
Microsoft-Windows-Diagnosis-PLA
Channel
Debug
Also via
realtime ETW trace

Fields #

NameDescription
BuildNumber UInt32
BuildType AnsiString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Diagnosis-PLA",
    "guid": "{E4D53F84-7DE3-11D8-9435-505054503030}",
    "event_source_name": "",
    "event_id": 5001,
    "version": 0,
    "level": 0,
    "task": 0,
    "opcode": 0,
    "keywords": "0x4000000000000100",
    "time_created": "2026-06-02T05:15:39.405+00:00",
    "event_record_id": 0,
    "correlation": {},
    "execution": {
      "process_id": 23132,
      "thread_id": 19600
    },
    "channel": "ETW Trace",
    "computer": "JD-DC01-2022",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "BuildNumber": 7366771,
    "BuildType": ""
  },
  "message": ""
}

Event ID 5002: task_05002

#
Provider
Microsoft-Windows-Diagnosis-PLA
Channel
Debug

Fields #

NameDescription
BuildNumber UInt32
BuildType AnsiString

Event ID 5003: task_05003

#
Provider
Microsoft-Windows-Diagnosis-PLA
Channel
Debug

Fields #

NameDescription
Reason UInt32
Result UInt32

Event ID 5004: task_05004

#
Provider
Microsoft-Windows-Diagnosis-PLA
Channel
Debug

Fields #

NameDescription
Name UnicodeString
FileName UnicodeString

Event ID 5005: task_05005

#
Provider
Microsoft-Windows-Diagnosis-PLA
Channel
Debug

Fields #

NameDescription
Name UnicodeString
SerialNumber UInt32

Event ID 5006: task_05006

#
Provider
Microsoft-Windows-Diagnosis-PLA
Channel
Debug

Fields #

NameDescription
Name UnicodeString

Event ID 5007: task_05007

#
Provider
Microsoft-Windows-Diagnosis-PLA
Channel
Debug

Fields #

NameDescription
Name UnicodeString

Event ID 5008: task_05008

#
Provider
Microsoft-Windows-Diagnosis-PLA
Channel
Debug

Fields #

NameDescription
Name UnicodeString
SerialNumber UInt32

Event ID 5009: task_05009

#
Provider
Microsoft-Windows-Diagnosis-PLA
Channel
Debug

Fields #

NameDescription
Name UnicodeString
Index UInt32

Event ID 5010: task_05010

#
Provider
Microsoft-Windows-Diagnosis-PLA
Channel
Debug

Fields #

NameDescription
Name UnicodeString

Event ID 5011: task_05011

#
Provider
Microsoft-Windows-Diagnosis-PLA
Channel
Debug

Fields #

NameDescription
Name UnicodeString
FileName UnicodeString

Event ID 5012: task_05012

#
Provider
Microsoft-Windows-Diagnosis-PLA
Channel
Debug

Fields #

NameDescription
Name UnicodeString

Event ID 5013: task_05013

#
Provider
Microsoft-Windows-Diagnosis-PLA
Channel
Debug

Fields #

NameDescription
Message UnicodeString
FileName AnsiString
Line UInt32

Event ID 5014: task_05014

#
Provider
Microsoft-Windows-Diagnosis-PLA
Channel
Debug
Also via
realtime ETW trace

Fields #

NameDescription
FileName AnsiString
Line UInt32
Address Pointer
Size Pointer

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Diagnosis-PLA",
    "guid": "{E4D53F84-7DE3-11D8-9435-505054503030}",
    "event_source_name": "",
    "event_id": 5014,
    "version": 0,
    "level": 0,
    "task": 0,
    "opcode": 0,
    "keywords": "0x4000000000000200",
    "time_created": "2026-06-02T05:15:39.405+00:00",
    "event_record_id": 0,
    "correlation": {},
    "execution": {
      "process_id": 23132,
      "thread_id": 19600
    },
    "channel": "ETW Trace",
    "computer": "JD-DC01-2022",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Address": "0x1A9792FB8C0",
    "FileName": "",
    "Line": 0,
    "Size": "0x20"
  },
  "message": ""
}

Event ID 5015: task_05015

#
Provider
Microsoft-Windows-Diagnosis-PLA
Channel
Debug
Also via
realtime ETW trace

Fields #

NameDescription
FileName AnsiString
Line UInt32
Address Pointer

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Diagnosis-PLA",
    "guid": "{E4D53F84-7DE3-11D8-9435-505054503030}",
    "event_source_name": "",
    "event_id": 5015,
    "version": 0,
    "level": 0,
    "task": 0,
    "opcode": 0,
    "keywords": "0x4000000000000200",
    "time_created": "2026-06-02T05:15:39.405+00:00",
    "event_record_id": 0,
    "correlation": {},
    "execution": {
      "process_id": 23132,
      "thread_id": 19600
    },
    "channel": "ETW Trace",
    "computer": "JD-DC01-2022",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Address": "0x1A9792FB8C0",
    "FileName": "",
    "Line": 0
  },
  "message": ""
}

Event ID 5016: task_05016

#
Provider
Microsoft-Windows-Diagnosis-PLA
Channel
Debug
Also via
realtime ETW trace

Fields #

NameDescription
FileName AnsiString
Line UInt32
Address Pointer
Size Pointer

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Diagnosis-PLA",
    "guid": "{E4D53F84-7DE3-11D8-9435-505054503030}",
    "event_source_name": "",
    "event_id": 5016,
    "version": 0,
    "level": 0,
    "task": 0,
    "opcode": 0,
    "keywords": "0x4000000000000200",
    "time_created": "2026-06-02T05:15:39.407+00:00",
    "event_record_id": 0,
    "correlation": {},
    "execution": {
      "process_id": 23132,
      "thread_id": 19600
    },
    "channel": "ETW Trace",
    "computer": "JD-DC01-2022",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Address": "0x1A97930B850",
    "FileName": "",
    "Line": 0,
    "Size": "0x1098"
  },
  "message": ""
}

Event ID 5017: task_05017

#
Provider
Microsoft-Windows-Diagnosis-PLA
Channel
Debug
Also via
realtime ETW trace

Fields #

NameDescription
FileName AnsiString
Line UInt32
Address Pointer

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Diagnosis-PLA",
    "guid": "{E4D53F84-7DE3-11D8-9435-505054503030}",
    "event_source_name": "",
    "event_id": 5017,
    "version": 0,
    "level": 0,
    "task": 0,
    "opcode": 0,
    "keywords": "0x4000000000000200",
    "time_created": "2026-06-02T05:15:39.408+00:00",
    "event_record_id": 0,
    "correlation": {},
    "execution": {
      "process_id": 23132,
      "thread_id": 19600
    },
    "channel": "ETW Trace",
    "computer": "JD-DC01-2022",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Address": "0x1A97930C8F0",
    "FileName": "",
    "Line": 0
  },
  "message": ""
}

Event ID 5018: task_05018

#
Provider
Microsoft-Windows-Diagnosis-PLA
Channel
Debug

Fields #

NameDescription
FileName AnsiString
Line UInt32
Address Pointer
Size Pointer
OrigAddress Pointer

Event ID 5019: task_05019

#
Provider
Microsoft-Windows-Diagnosis-PLA
Channel
Debug
Also via
realtime ETW trace

Fields #

NameDescription
FileName AnsiString
Line UInt32
Address Pointer
Size Pointer

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Diagnosis-PLA",
    "guid": "{E4D53F84-7DE3-11D8-9435-505054503030}",
    "event_source_name": "",
    "event_id": 5019,
    "version": 0,
    "level": 0,
    "task": 0,
    "opcode": 0,
    "keywords": "0x4000000000000200",
    "time_created": "2026-06-02T05:15:39.406+00:00",
    "event_record_id": 0,
    "correlation": {},
    "execution": {
      "process_id": 23132,
      "thread_id": 19600
    },
    "channel": "ETW Trace",
    "computer": "JD-DC01-2022",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Address": "0x1A979309AB8",
    "FileName": "",
    "Line": 0,
    "Size": "0x28"
  },
  "message": ""
}

Event ID 5020: task_05020

#
Provider
Microsoft-Windows-Diagnosis-PLA
Channel
Debug
Also via
realtime ETW trace

Fields #

NameDescription
FileName AnsiString
Line UInt32
Address Pointer

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Diagnosis-PLA",
    "guid": "{E4D53F84-7DE3-11D8-9435-505054503030}",
    "event_source_name": "",
    "event_id": 5020,
    "version": 0,
    "level": 0,
    "task": 0,
    "opcode": 0,
    "keywords": "0x4000000000000200",
    "time_created": "2026-06-02T05:15:39.407+00:00",
    "event_record_id": 0,
    "correlation": {},
    "execution": {
      "process_id": 23132,
      "thread_id": 19600
    },
    "channel": "ETW Trace",
    "computer": "JD-DC01-2022",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Address": "0x1A9792FF6B8",
    "FileName": "",
    "Line": 0
  },
  "message": ""
}

Event ID 5021: task_05021

#
Provider
Microsoft-Windows-Diagnosis-PLA
Channel
Debug
Also via
realtime ETW trace

Fields #

NameDescription
Name AnsiString
Address Pointer

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Diagnosis-PLA",
    "guid": "{E4D53F84-7DE3-11D8-9435-505054503030}",
    "event_source_name": "",
    "event_id": 5021,
    "version": 0,
    "level": 0,
    "task": 0,
    "opcode": 0,
    "keywords": "0x4000000000000400",
    "time_created": "2026-06-02T05:15:39.405+00:00",
    "event_record_id": 0,
    "correlation": {},
    "execution": {
      "process_id": 23132,
      "thread_id": 19600
    },
    "channel": "ETW Trace",
    "computer": "JD-DC01-2022",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Address": "0x1A9792FEC90",
    "Name": "struct IDataCollectorSet"
  },
  "message": ""
}

Event ID 5022: task_05022

#
Provider
Microsoft-Windows-Diagnosis-PLA
Channel
Debug
Also via
realtime ETW trace

Fields #

NameDescription
Name AnsiString
Address Pointer

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Diagnosis-PLA",
    "guid": "{E4D53F84-7DE3-11D8-9435-505054503030}",
    "event_source_name": "",
    "event_id": 5022,
    "version": 0,
    "level": 0,
    "task": 0,
    "opcode": 0,
    "keywords": "0x4000000000000400",
    "time_created": "2026-06-02T05:15:39.407+00:00",
    "event_record_id": 0,
    "correlation": {},
    "execution": {
      "process_id": 23132,
      "thread_id": 19600
    },
    "channel": "ETW Trace",
    "computer": "JD-DC01-2022",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Address": "0x1A9792ECD30",
    "Name": "struct IEnumVARIANT"
  },
  "message": ""
}

Event ID 5023: task_05023

#
Provider
Microsoft-Windows-Diagnosis-PLA
Channel
Debug
Also via
realtime ETW trace

Fields #

NameDescription
Name AnsiString
Address Pointer
RefCount UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Diagnosis-PLA",
    "guid": "{E4D53F84-7DE3-11D8-9435-505054503030}",
    "event_source_name": "",
    "event_id": 5023,
    "version": 0,
    "level": 0,
    "task": 0,
    "opcode": 0,
    "keywords": "0x4000000000000400",
    "time_created": "2026-06-02T05:15:39.405+00:00",
    "event_record_id": 0,
    "correlation": {},
    "execution": {
      "process_id": 23132,
      "thread_id": 19600
    },
    "channel": "ETW Trace",
    "computer": "JD-DC01-2022",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Address": "0x1A9792FEC90",
    "Name": "struct IDataCollectorSet",
    "RefCount": 2
  },
  "message": ""
}

Event ID 5024: task_05024

#
Provider
Microsoft-Windows-Diagnosis-PLA
Channel
Debug
Also via
realtime ETW trace

Fields #

NameDescription
Name AnsiString
Address Pointer
RefCount UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Diagnosis-PLA",
    "guid": "{E4D53F84-7DE3-11D8-9435-505054503030}",
    "event_source_name": "",
    "event_id": 5024,
    "version": 0,
    "level": 0,
    "task": 0,
    "opcode": 0,
    "keywords": "0x4000000000000400",
    "time_created": "2026-06-02T05:15:39.405+00:00",
    "event_record_id": 0,
    "correlation": {},
    "execution": {
      "process_id": 23132,
      "thread_id": 19600
    },
    "channel": "ETW Trace",
    "computer": "JD-DC01-2022",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Address": "0x1A9792FEC90",
    "Name": "struct IDataCollectorSet",
    "RefCount": 1
  },
  "message": ""
}

Event ID 5025: task_05025

#
Provider
Microsoft-Windows-Diagnosis-PLA
Channel
Debug
Also via
realtime ETW trace

Fields #

NameDescription
Name AnsiString
Address Pointer
RefCount UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Diagnosis-PLA",
    "guid": "{E4D53F84-7DE3-11D8-9435-505054503030}",
    "event_source_name": "",
    "event_id": 5025,
    "version": 0,
    "level": 0,
    "task": 0,
    "opcode": 0,
    "keywords": "0x4000000000000400",
    "time_created": "2026-06-02T05:15:39.405+00:00",
    "event_record_id": 0,
    "correlation": {},
    "execution": {
      "process_id": 23132,
      "thread_id": 19600
    },
    "channel": "ETW Trace",
    "computer": "JD-DC01-2022",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Address": "0x1A9792FEC90",
    "Name": "CDataCollectorSet::Query",
    "RefCount": 1
  },
  "message": ""
}

Event ID 5026: task_05026

#
Provider
Microsoft-Windows-Diagnosis-PLA
Channel
Debug
Also via
realtime ETW trace

Fields #

NameDescription
Error UInt32
FileName AnsiString
Line UInt32
Function AnsiString
User UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Diagnosis-PLA",
    "guid": "{E4D53F84-7DE3-11D8-9435-505054503030}",
    "event_source_name": "",
    "event_id": 5026,
    "version": 0,
    "level": 0,
    "task": 0,
    "opcode": 0,
    "keywords": "0x4000000000000800",
    "time_created": "2026-06-02T05:15:39.407+00:00",
    "event_record_id": 0,
    "correlation": {},
    "execution": {
      "process_id": 23132,
      "thread_id": 19600
    },
    "channel": "ETW Trace",
    "computer": "JD-DC01-2022",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Error": 2147943568,
    "FileName": "",
    "Function": "Enumerator::GetNamedItem",
    "Line": 0,
    "User": "ludus\\domainadmin"
  },
  "message": ""
}

Provenance

Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.

ETW provider GUID {E4D53F84-7DE3-11D8-9435-505054503030}

Defined in pla.dll, which carries the event manifest.

Observed on:

  • WS2022-20348.4893 · sample captured from a live trace · binary version 10.0.20348.1 · captured 2026-06-02
  • WS2022-20348.4893 · schema read from the registered manifest · binary version 10.0.20348.1 · captured 2026-06-02
  • Win11-26200.6584 · schema read from the registered manifest · binary version 10.0.26100.1 · captured 2026-06-02

Downloads

Credits

  • Microsoft - authored the ETW manifests and PDBs the schema comes from
  • jdu2600 - the event-schema TSV format this catalog adopted
  • nasbench - the tool that dumps registered providers and manifests