Microsoft-Windows-Diagnostics-Performance
113 events across 3 channels
Event ID 100 — Windows has started up: Boot Duration : %6ms IsDegradation : %26 Incident Time (UTC) : %2.
Message
Fields
| Name | Description |
|---|---|
BootTsVersion | — |
BootStartTime | — |
BootEndTime | — |
SystemBootInstance | — |
UserBootInstance | — |
BootTime | — |
MainPathBootTime | — |
BootKernelInitTime | — |
BootDriverInitTime | — |
BootDevicesInitTime | — |
BootPrefetchInitTime | — |
BootPrefetchBytes | — |
BootAutoChkTime | — |
BootSmssInitTime | — |
BootCriticalServicesInitTime | — |
BootUserProfileProcessingTime | — |
BootMachineProfileProcessingTime | — |
BootExplorerInitTime | — |
BootNumStartupApps | — |
BootPostBootTime | — |
BootIsRebootAfterInstall | — |
BootRootCauseStepImprovementBits | — |
BootRootCauseGradualImprovementBits | — |
BootRootCauseStepDegradationBits | — |
BootRootCauseGradualDegradationBits | — |
BootIsDegradation | — |
BootIsStepDegradation | — |
BootIsGradualDegradation | — |
BootImprovementDelta | — |
BootDegradationDelta | — |
BootIsRootCauseIdentified | — |
OSLoaderDuration | — |
BootPNPInitStartTimeMS | — |
BootPNPInitDuration | — |
OtherKernelInitDuration | — |
SystemPNPInitStartTimeMS | — |
SystemPNPInitDuration | — |
SessionInitStartTimeMS | — |
Session0InitDuration | — |
Session1InitDuration | — |
SessionInitOtherDuration | — |
WinLogonStartTimeMS | — |
OtherLogonInitActivityDuration | — |
UserLogonWaitDuration | — |
Example Event
system:
provider: Microsoft-Windows-Diagnostics-Performance
guid: CFC18EC0-96B1-4EBA-961B-622CAEE05B0A
event_source_name: ''
event_id: 100
version: 2
level: 1
task: 4002
opcode: 34
keywords: 9223372036854841344
time_created: '2023-11-05T22:33:58.036254+00:00'
event_record_id: 38
correlation:
ActivityID: E4DB489E-1037-0003-0982-DBE43710DA01
execution:
process_id: 3160
thread_id: 3556
channel: Microsoft-Windows-Diagnostics-Performance/Operational
computer: WinDev2310Eval
security:
user_id: S-1-5-19
event_data:
BootTsVersion: 2
BootStartTime: '2023-11-05T22:32:00.970725Z'
BootEndTime: '2023-11-05T22:33:56.389945Z'
SystemBootInstance: 8
UserBootInstance: 2
BootTime: 110680
MainPathBootTime: 34629
BootKernelInitTime: 164
BootDriverInitTime: 1567
BootDevicesInitTime: 2810
BootPrefetchInitTime: 0
BootPrefetchBytes: 0
BootAutoChkTime: 0
BootSmssInitTime: 6391
BootCriticalServicesInitTime: 1441
BootUserProfileProcessingTime: 1084
BootMachineProfileProcessingTime: 456
BootExplorerInitTime: 18858
BootNumStartupApps: 3
BootPostBootTime: 76051
BootIsRebootAfterInstall: false
BootRootCauseStepImprovementBits: 0
BootRootCauseGradualImprovementBits: 0
BootRootCauseStepDegradationBits: 13631488
BootRootCauseGradualDegradationBits: 13631488
BootIsDegradation: true
BootIsStepDegradation: true
BootIsGradualDegradation: true
BootImprovementDelta: 0
BootDegradationDelta: 68995
BootIsRootCauseIdentified: true
OSLoaderDuration: 3107
BootPNPInitStartTimeMS: 164
BootPNPInitDuration: 4163
OtherKernelInitDuration: 445
SystemPNPInitStartTimeMS: 4495
SystemPNPInitDuration: 1301
SessionInitStartTimeMS: 5910
Session0InitDuration: 1013
Session1InitDuration: 219
SessionInitOtherDuration: 5158
WinLogonStartTimeMS: 12302
OtherLogonInitActivityDuration: 1926
UserLogonWaitDuration: 4739
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 101 — This application took longer than usual to start up, resulting in a performance degradation in the system startup process: File Name : %3 Friendly ...
Message
Fields
| Name | Description |
|---|---|
StartTime | — |
NameLength | — |
Name | — |
FriendlyNameLength | — |
FriendlyName | — |
VersionLength | — |
Version | — |
TotalTime | — |
DegradationTime | — |
PathLength | — |
Path | — |
ProductNameLength | — |
ProductName | — |
CompanyNameLength | — |
CompanyName | — |
Example Event
system:
provider: Microsoft-Windows-Diagnostics-Performance
guid: CFC18EC0-96B1-4EBA-961B-622CAEE05B0A
event_source_name: ''
event_id: 101
version: 1
level: 3
task: 4002
opcode: 33
keywords: 9223372036854841344
time_created: '2023-11-05T22:33:58.036338+00:00'
event_record_id: 44
correlation:
ActivityID: E4DB489E-1037-0003-0982-DBE43710DA01
execution:
process_id: 3160
thread_id: 3556
channel: Microsoft-Windows-Diagnostics-Performance/Operational
computer: WinDev2310Eval
security:
user_id: S-1-5-19
event_data:
StartTime: '2023-11-05T22:32:00.970725Z'
NameLength: 28
Name: StartMenuExperienceHost.exe
FriendlyNameLength: 30
FriendlyName: Windows Start Experience Host
VersionLength: 39
Version: 10.0.22621.2361 (WinBuild.160101.0800)
TotalTime: 6125
DegradationTime: 3625
PathLength: 106
Path: C:\Windows\SystemApps\Microsoft.Windows.StartMenuExperienceHost_cw5n1h2txyewy\StartMenuExperienceHost.exe
ProductNameLength: 37
ProductName: Microsoft® Windows® Operating System
CompanyNameLength: 22
CompanyName: Microsoft Corporation
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 102 — This driver took longer to initialize, resulting in a performance degradation in the system start up process: File Name : %3 Friendly Name : %5 Ver...
Message
Fields
| Name | Description |
|---|---|
StartTime | — |
NameLength | — |
Name | — |
FriendlyNameLength | — |
FriendlyName | — |
VersionLength | — |
Version | — |
TotalTime | — |
DegradationTime | — |
PathLength | — |
Path | — |
ProductNameLength | — |
ProductName | — |
CompanyNameLength | — |
CompanyName | — |
Example Event
system:
provider: Microsoft-Windows-Diagnostics-Performance
guid: CFC18EC0-96B1-4EBA-961B-622CAEE05B0A
event_source_name: ''
event_id: 102
version: 1
level: 3
task: 4002
opcode: 33
keywords: 9223372036854841344
time_created: '2023-10-25T22:05:44.601509+00:00'
event_record_id: 25
correlation:
ActivityID: 028F2288-078F-0001-413E-8F028F07DA01
execution:
process_id: 2484
thread_id: 3796
channel: Microsoft-Windows-Diagnostics-Performance/Operational
computer: WinDevEval
security:
user_id: S-1-5-19
event_data:
StartTime: '2023-10-25T22:02:56.552302Z'
NameLength: 7
Name: VfpExt
FriendlyNameLength: 30
FriendlyName: Microsoft Azure VFP Extension
VersionLength: 36
Version: 10.0.22621.1 (WinBuild.160101.0800)
TotalTime: 8403
DegradationTime: 6903
PathLength: 39
Path: C:\Windows\system32\drivers\vfpext.sys
ProductNameLength: 37
ProductName: Microsoft® Windows® Operating System
CompanyNameLength: 22
CompanyName: Microsoft Corporation
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 103 — This startup service took longer than expected to startup, resulting in a performance degradation in the system start up process: File Name : %3 Fr...
Message
Fields
| Name | Description |
|---|---|
StartTime | — |
NameLength | — |
Name | — |
FriendlyNameLength | — |
FriendlyName | — |
VersionLength | — |
Version | — |
TotalTime | — |
DegradationTime | — |
PathLength | — |
Path | — |
ProductNameLength | — |
ProductName | — |
CompanyNameLength | — |
CompanyName | — |
Event ID 104 — Core system took longer to initialize, resulting in a performance degradation in the system start up process: Name : %3 Total Time : %4ms Degradati...
Message
Fields
| Name | Description |
|---|---|
StartTime | — |
NameLength | — |
Name | — |
TotalTime | — |
DegradationTime | — |
Event ID 105 — Foreground optimizations (prefetching) took longer to complete, resulting in a performance degradation in the system start up process: Name : %3 To...
Message
Fields
| Name | Description |
|---|---|
StartTime | — |
NameLength | — |
Name | — |
TotalTime | — |
DegradationTime | — |
Event ID 106 — Background optimizations (prefetching) took longer to complete, resulting in a performance degradation in the system start up process: Name : %3 To...
Message
Fields
| Name | Description |
|---|---|
StartTime | — |
NameLength | — |
Name | — |
TotalTime | — |
DegradationTime | — |
Event ID 107 — Application of machine policy caused a slow down in the system start up process: Name : %3 Total Time : %4ms Degradation Time : %5ms Incident Time ...
Message
Fields
| Name | Description |
|---|---|
StartTime | — |
NameLength | — |
Name | — |
TotalTime | — |
DegradationTime | — |
Event ID 108 — Application of user policy caused a slow down in the system start up process: Name : %3 Total Time : %4ms Degradation Time : %5ms Incident Time.
Message
Fields
| Name | Description |
|---|---|
StartTime | — |
NameLength | — |
Name | — |
TotalTime | — |
DegradationTime | — |
Event ID 109 — This device took longer to initialize, resulting in a performance degradation in the system start up process: File Name : %3 Friendly Name : %5 Ver...
Message
Fields
| Name | Description |
|---|---|
StartTime | — |
NameLength | — |
Name | — |
FriendlyNameLength | — |
FriendlyName | — |
VersionLength | — |
Version | — |
TotalTime | — |
DegradationTime | — |
PathLength | — |
Path | — |
ProductNameLength | — |
ProductName | — |
CompanyNameLength | — |
CompanyName | — |
Event ID 110 — Session manager initialization caused a slow down in the startup process: Name : %3 Total Time : %4ms Degradation Time : %5ms Incident Time (UTC) :...
Message
Fields
| Name | Description |
|---|---|
StartTime | — |
NameLength | — |
Name | — |
TotalTime | — |
DegradationTime | — |
Example Event
system:
provider: Microsoft-Windows-Diagnostics-Performance
guid: CFC18EC0-96B1-4EBA-961B-622CAEE05B0A
event_source_name: ''
event_id: 110
version: 1
level: 3
task: 4002
opcode: 33
keywords: 9223372036854841344
time_created: '2023-10-25T22:05:44.601513+00:00'
event_record_id: 26
correlation:
ActivityID: 028F2288-078F-0001-413E-8F028F07DA01
execution:
process_id: 2484
thread_id: 3796
channel: Microsoft-Windows-Diagnostics-Performance/Operational
computer: WinDevEval
security:
user_id: S-1-5-19
event_data:
StartTime: '2023-10-25T22:02:56.552302Z'
NameLength: 9
Name: SMSSInit
TotalTime: 17567
DegradationTime: 7567
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 200 — Windows has shutdown: Shutdown Duration : %4ms IsDegradation : %16 Incident Time (UTC) : %2.
Message
Fields
| Name | Description |
|---|---|
ShutdownTsVersion | — |
ShutdownStartTime | — |
ShutdownEndTime | — |
ShutdownTime | — |
ShutdownUserSessionTime | — |
ShutdownUserPolicyTime | — |
ShutdownUserProfilesTime | — |
ShutdownSystemSessionsTime | — |
ShutdownPreShutdownNotificationsTime | — |
ShutdownServicesTime | — |
ShutdownKernelTime | — |
ShutdownRootCauseStepImprovementBits | — |
ShutdownRootCauseGradualImprovementBits | — |
ShutdownRootCauseStepDegradationBits | — |
ShutdownRootCauseGradualDegradationBits | — |
ShutdownIsDegradation | — |
ShutdownTimeChange | — |
Example Event
system:
provider: Microsoft-Windows-Diagnostics-Performance
guid: CFC18EC0-96B1-4EBA-961B-622CAEE05B0A
event_source_name: ''
event_id: 200
version: 1
level: 3
task: 4007
opcode: 40
keywords: 9223372036854841344
time_created: '2023-11-05T22:33:56.991516+00:00'
event_record_id: 36
correlation:
ActivityID: E4DB489E-1037-0001-FD89-DBE43710DA01
execution:
process_id: 3160
thread_id: 3468
channel: Microsoft-Windows-Diagnostics-Performance/Operational
computer: WinDev2310Eval
security:
user_id: S-1-5-19
event_data:
ShutdownTsVersion: 1
ShutdownStartTime: '2023-11-05T22:31:30.287074Z'
ShutdownEndTime: '2023-11-05T22:31:43.106260Z'
ShutdownTime: 12819
ShutdownUserSessionTime: 3778
ShutdownUserPolicyTime: 17
ShutdownUserProfilesTime: 236
ShutdownSystemSessionsTime: 6148
ShutdownPreShutdownNotificationsTime: 1596
ShutdownServicesTime: 4185
ShutdownKernelTime: 2892
ShutdownRootCauseStepImprovementBits: 0
ShutdownRootCauseGradualImprovementBits: 0
ShutdownRootCauseStepDegradationBits: 72
ShutdownRootCauseGradualDegradationBits: 0
ShutdownIsDegradation: true
ShutdownTimeChange: 0
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 201 — This application caused a delay in the system shutdown process: File Name : %3 Friendly Name : %5 Version : %7 Total Time : %8ms Degradation Time :...
Message
Fields
| Name | Description |
|---|---|
StartTime | — |
NameLength | — |
Name | — |
FriendlyNameLength | — |
FriendlyName | — |
VersionLength | — |
Version | — |
TotalTime | — |
DegradationTime | — |
PathLength | — |
Path | — |
ProductNameLength | — |
ProductName | — |
CompanyNameLength | — |
CompanyName | — |
Event ID 202 — This device caused a delay in the system shutdown process: File Name : %3 Friendly Name : %5 Version : %7 Total Time : %8ms Degradation Time : %9ms...
Message
Fields
| Name | Description |
|---|---|
StartTime | — |
NameLength | — |
Name | — |
FriendlyNameLength | — |
FriendlyName | — |
VersionLength | — |
Version | — |
TotalTime | — |
DegradationTime | — |
PathLength | — |
Path | — |
ProductNameLength | — |
ProductName | — |
CompanyNameLength | — |
CompanyName | — |
Event ID 203 — This service caused a delay in the system shutdown process: File Name : %3 Friendly Name : %5 Version : %7 Total Time : %8ms Degradation Time : %9m...
Message
Fields
| Name | Description |
|---|---|
StartTime | — |
NameLength | — |
Name | — |
FriendlyNameLength | — |
FriendlyName | — |
VersionLength | — |
Version | — |
TotalTime | — |
DegradationTime | — |
PathLength | — |
Path | — |
ProductNameLength | — |
ProductName | — |
CompanyNameLength | — |
CompanyName | — |
Example Event
system:
provider: Microsoft-Windows-Diagnostics-Performance
guid: CFC18EC0-96B1-4EBA-961B-622CAEE05B0A
event_source_name: ''
event_id: 203
version: 1
level: 3
task: 4007
opcode: 41
keywords: 9223372036854841344
time_created: '2023-11-05T22:33:56.991549+00:00'
event_record_id: 37
correlation:
ActivityID: E4DB489E-1037-0001-FD89-DBE43710DA01
execution:
process_id: 3160
thread_id: 3468
channel: Microsoft-Windows-Diagnostics-Performance/Operational
computer: WinDev2310Eval
security:
user_id: S-1-5-19
event_data:
StartTime: '2023-11-05T22:31:30.287074Z'
NameLength: 10
Name: WinDefend
FriendlyNameLength: 0
FriendlyName: ''
VersionLength: 0
Version: ''
TotalTime: 4054
DegradationTime: 54
PathLength: 83
Path: '"c:\programdata\microsoft\windows defender\platform\4.18.23090.2008-0\msmpeng.exe"'
ProductNameLength: 0
ProductName: ''
CompanyNameLength: 0
CompanyName: ''
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 300 — Windows has resumed from standby: Standby Duration : %7ms Standby Incident Time (UTC) : %5 Resume Duration : %39ms Resume Incident Time (UTC) : %37...
Message
Fields
| Name | Description |
|---|---|
StandbyTsVersion | — |
StandbyAppCount | — |
StandbyServicesCount | — |
StandbyDevicesCount | — |
StandbyStartTime | — |
StandbyEndTime | — |
StandbySuspendTotal | — |
StandbySuspendTotalChange | — |
StandbySuspendQueryApps | — |
StandbySuspendQueryAppsChange | — |
StandbySuspendQueryServices | — |
StandbySuspendQueryServicesChange | — |
StandbySuspendApps | — |
StandbySuspendAppsChange | — |
StandbySuspendServices | — |
StandbySuspendServicesChange | — |
StandbySuspendShowUI | — |
StandbySuspendShowUIChange | — |
StandbySuspendSuperfetchPageIn | — |
StandbySuspendSuperfetchPageInChange | — |
StandbySuspendWinlogon | — |
StandbySuspendWinlogonChange | — |
StandbySuspendLockPageableSections | — |
StandbySuspendLockPageableSectionsChange | — |
StandbySuspendPreSleepCallbacks | — |
StandbySuspendPreSleepCallbacksChange | — |
StandbySuspendSwapInWorkerThreads | — |
StandbySuspendSwapInWorkerThreadsChange | — |
StandbySuspendQueryDevices | — |
StandbySuspendQueryDevicesChange | — |
StandbySuspendFlushVolumes | — |
StandbySuspendFlushVolumesChange | — |
StandbySuspendSuspendDevices | — |
StandbySuspendSuspendDevicesChange | — |
StandbySuspendHibernateWrite | — |
StandbySuspendHibernateWriteChange | — |
ResumeStartTime | — |
ResumeEndTime | — |
StandbyResumeTotal | — |
StandbyResumeTotalChange | — |
StandbyResumeHibernateRead | — |
StandbyResumeHibernateReadChange | — |
StandbyResumeS3BiosInitTime | — |
StandbyResumeS3BiosInitTimeChange | — |
StandbyResumeResumeDevices | — |
StandbyResumeResumeDevicesChange | — |
StandbyRootCauseDegradationGradual | — |
StandbyRootCauseImprovementGradual | — |
StandbyRootCauseDegradationStep | — |
StandbyRootCauseImprovementStep | — |
StandbyIsDegradation | — |
StandbyIsTroubleshooterLaunched | — |
StandbyIsRootCauseIdentified | — |
Event ID 301 — This application caused a delay during standby: File Name : %3 Friendly Name : %5 Version : %7 Total Time : %8ms Degradation Time : %9ms Incident T...
Message
Fields
| Name | Description |
|---|---|
StartTime | — |
NameLength | — |
Name | — |
FriendlyNameLength | — |
FriendlyName | — |
VersionLength | — |
Version | — |
TotalTime | — |
DegradationTime | — |
PathLength | — |
Path | — |
ProductNameLength | — |
ProductName | — |
CompanyNameLength | — |
CompanyName | — |
Event ID 302 — This driver caused a delay during standby while servicing a device: Driver File Name : %3 Driver Friendly Name : %5 Driver Version : %7 Driver Tota...
Message
Fields
| Name | Description |
|---|---|
StartTime | — |
NameLength | — |
Name | — |
FriendlyNameLength | — |
FriendlyName | — |
VersionLength | — |
Version | — |
TotalTime | — |
DegradationTime | — |
PathLength | — |
Path | — |
ProductNameLength | — |
ProductName | — |
CompanyNameLength | — |
CompanyName | — |
DeviceNameLength | — |
DeviceName | — |
DeviceFriendlyNameLength | — |
DeviceFriendlyName | — |
DeviceTotalTime | — |
DeviceDegradationTime | — |
Event ID 303 — This service caused a delay during hybrid-sleep: File Name : %3 Friendly Name : %5 Version : %7 Total Time : %8ms Degradation Time : %9ms Incident ...
Message
Fields
| Name | Description |
|---|---|
StartTime | — |
NameLength | — |
Name | — |
FriendlyNameLength | — |
FriendlyName | — |
VersionLength | — |
Version | — |
TotalTime | — |
DegradationTime | — |
PathLength | — |
Path | — |
ProductNameLength | — |
ProductName | — |
CompanyNameLength | — |
CompanyName | — |
Event ID 304 — Creation of the hiber-file was slower than expected: Name : %3 Total Time : %4ms Degradation Time : %5ms Incident Time (UTC) : %1.
Message
Fields
| Name | Description |
|---|---|
StartTime | — |
NameLength | — |
Name | — |
TotalTime | — |
DegradationTime | — |
Event ID 305 — Persisting disk caches was slower than expected: Name : %3 Total Time : %4ms Degradation Time : %5ms Incident Time (UTC) : %1.
Message
Fields
| Name | Description |
|---|---|
StartTime | — |
NameLength | — |
Name | — |
TotalTime | — |
DegradationTime | — |
Event ID 306 — Preparing the video subsystem for sleep was slower than expected: Name : %3 Total Time : %4ms Degradation Time : %5ms Incident Time (UTC) : %1.
Message
Fields
| Name | Description |
|---|---|
StartTime | — |
NameLength | — |
Name | — |
TotalTime | — |
DegradationTime | — |
Event ID 307 — Preparing Winlogon for sleep was slower than expected: Name : %3 Total Time : %4ms Degradation Time : %5ms Incident Time (UTC) : %1.
Message
Fields
| Name | Description |
|---|---|
StartTime | — |
NameLength | — |
Name | — |
TotalTime | — |
DegradationTime | — |
Event ID 308 — Preparing system memory for sleep was slower than expected: Name : %3 Total Time : %4ms Degradation Time : %5ms Incident Time (UTC) : %1.
Message
Fields
| Name | Description |
|---|---|
StartTime | — |
NameLength | — |
Name | — |
TotalTime | — |
DegradationTime | — |
Event ID 309 — Preparing core system for sleep was slower than expected: Name : %3 Total Time : %4ms Degradation Time : %5ms Incident Time (UTC) : %1.
Message
Fields
| Name | Description |
|---|---|
StartTime | — |
NameLength | — |
Name | — |
TotalTime | — |
DegradationTime | — |
Event ID 310 — Preparing system worker threads for sleep was slower than expected: Name : %3 Total Time : %4ms Degradation Time : %5ms Incident Time (UTC) : %1.
Message
Fields
| Name | Description |
|---|---|
StartTime | — |
NameLength | — |
Name | — |
TotalTime | — |
DegradationTime | — |
Event ID 350 — Bios initialization time was greater than 250ms (logo requirement) during system resume: Name : %3 Total Time : %4ms Degradation Time : %5ms Incide...
Message
Fields
| Name | Description |
|---|---|
StartTime | — |
NameLength | — |
Name | — |
TotalTime | — |
DegradationTime | — |
Event ID 351 — This driver responded slower than expected to the resume request while servicing this device: Driver File Name : %3 Driver Friendly Name : %5 Drive...
Message
Fields
| Name | Description |
|---|---|
StartTime | — |
NameLength | — |
Name | — |
FriendlyNameLength | — |
FriendlyName | — |
VersionLength | — |
Version | — |
TotalTime | — |
DegradationTime | — |
PathLength | — |
Path | — |
ProductNameLength | — |
ProductName | — |
CompanyNameLength | — |
CompanyName | — |
DeviceNameLength | — |
DeviceName | — |
DeviceFriendlyNameLength | — |
DeviceFriendlyName | — |
DeviceTotalTime | — |
DeviceDegradationTime | — |
Event ID 352 — Reading the hiber-file was slower than expected: Name : %3 Total Time : %4ms Degradation Time : %5ms Incident Time (UTC) : %1.
Message
Fields
| Name | Description |
|---|---|
StartTime | — |
NameLength | — |
Name | — |
TotalTime | — |
DegradationTime | — |
Event ID 400 — Information about the system performance monitoring event: Scenario : %3 Analysis result : %6 Incident Time (UTC) : %1.
Message
Fields
| Name | Description |
|---|---|
ShellScenarioStartTime | — |
ShellScenarioEndTime | — |
ShellSubScenario | — |
ShellScenarioDuration | — |
ShellRootCauseBits | — |
ShellAnalysisResult | — |
ShellDegradationType | — |
ShellTsVersion | — |
ShellMachineUpTimeHours | — |
ShellMachineSleepPattern | — |
Event ID 401 — This process is using up processor time and is impacting the performance of Windows: File Name : %3 Friendly Name : %5 Version : %7 Thread time : %...
Message
Fields
| Name | Description |
|---|---|
StartTime | — |
NameLength | — |
Name | — |
FriendlyNameLength | — |
FriendlyName | — |
VersionLength | — |
Version | — |
ThreadTime | — |
BlockedTime | — |
PercentTime | — |
PathLength | — |
Path | — |
ProductNameLength | — |
ProductName | — |
CompanyNameLength | — |
CompanyName | — |
Event ID 402 — This process is doing excessive disk activities and is impacting the performance of Windows: File Name : %3 Friendly Name : %5 Version : %7 Thread ...
Message
Fields
| Name | Description |
|---|---|
StartTime | — |
NameLength | — |
Name | — |
FriendlyNameLength | — |
FriendlyName | — |
VersionLength | — |
Version | — |
ThreadTime | — |
BlockedTime | — |
PercentTime | — |
PathLength | — |
Path | — |
ProductNameLength | — |
ProductName | — |
CompanyNameLength | — |
CompanyName | — |
Event ID 403 — This driver is using up too many resources and is impacting the performance of Windows: File Name : %3 Friendly Name : %5 Version : %7 Thread time ...
Message
Fields
| Name | Description |
|---|---|
StartTime | — |
NameLength | — |
Name | — |
FriendlyNameLength | — |
FriendlyName | — |
VersionLength | — |
Version | — |
ThreadTime | — |
BlockedTime | — |
PercentTime | — |
PathLength | — |
Path | — |
ProductNameLength | — |
ProductName | — |
CompanyNameLength | — |
CompanyName | — |
Event ID 404 — This driver is waiting longer than expected on a device: File Name : %3 Friendly Name : %5 Version : %7 Thread time : %8ms Blocked Time : %9ms Inci...
Message
Fields
| Name | Description |
|---|---|
StartTime | — |
NameLength | — |
Name | — |
FriendlyNameLength | — |
FriendlyName | — |
VersionLength | — |
Version | — |
ThreadTime | — |
BlockedTime | — |
PercentTime | — |
PathLength | — |
Path | — |
ProductNameLength | — |
ProductName | — |
CompanyNameLength | — |
CompanyName | — |
Event ID 405 — This file is fragmented and is impacting the performance of Windows: File Name : %3 Friendly Name : %5 Version : %7 Thread time : %8ms Blocked Time...
Message
Fields
| Name | Description |
|---|---|
StartTime | — |
NameLength | — |
Name | — |
FriendlyNameLength | — |
FriendlyName | — |
VersionLength | — |
Version | — |
ThreadTime | — |
BlockedTime | — |
PercentTime | — |
PathLength | — |
Path | — |
ProductNameLength | — |
ProductName | — |
CompanyNameLength | — |
CompanyName | — |
Event ID 406 — Disk IO to this file is taking longer than expected: File Name : %3 Friendly Name : %5 Version : %7 Thread time : %8ms Blocked Time : %9ms Incident...
Message
Fields
| Name | Description |
|---|---|
StartTime | — |
NameLength | — |
Name | — |
FriendlyNameLength | — |
FriendlyName | — |
VersionLength | — |
Version | — |
ThreadTime | — |
BlockedTime | — |
PercentTime | — |
PathLength | — |
Path | — |
ProductNameLength | — |
ProductName | — |
CompanyNameLength | — |
CompanyName | — |
Event ID 407 — This process is using up too much system memory: File Name : %3 Friendly Name : %5 Version : %7 Workingset size : %8Kb Percent memory : %11 Inciden...
Message
Fields
| Name | Description |
|---|---|
StartTime | — |
NameLength | — |
Name | — |
FriendlyNameLength | — |
FriendlyName | — |
VersionLength | — |
Version | — |
WorkingSetSizeKb | — |
PeakWorkingSetSizeKb | — |
ProcessId | — |
PercentMemory | — |
PathLength | — |
Path | — |
ProductNameLength | — |
ProductName | — |
CompanyNameLength | — |
CompanyName | — |
Event ID 408 — Many processes are using too much system memory: Workingset size : %2Kb Percent memory : %3 Incident Time (UTC) : %1.
Message
Fields
| Name | Description |
|---|---|
StartTime | — |
WorkingSetSizeKb | — |
PercentMemory | — |
Event ID 500 — The Desktop Window Manager is experiencing heavy resource contention.
Message
Fields
| Name | Description |
|---|---|
DisplayDeviceFriendlyNameLength | — |
DisplayDeviceFriendlyName | — |
MemoryBandwidth | — |
MemorySize | — |
Scenario | — |
Event ID 501 — The Desktop Window Manager is experiencing heavy resource contention.
Message
Fields
| Name | Description |
|---|---|
Reason | — |
Diagnosis | — |
Event ID 1001 — Status
Message
Fields
| Name | Description |
|---|---|
HResult | — |
Event ID 1002 — Status
Message
Fields
| Name | Description |
|---|---|
GUID | — |
EventId | — |
InternalState | — |
Event ID 1003 — Status
Message
Fields
| Name | Description |
|---|---|
NewState | — |
Event ID 1005 — Status
Message
Fields
| Name | Description |
|---|---|
HResult | — |
Event ID 1006 — Status
Message
Event ID 1007 — Status
Message
Fields
| Name | Description |
|---|---|
GUID | — |
EventId | — |
InternalState | — |
Event ID 1010 — Status
Message
Event ID 1011 — Status
Message
Fields
| Name | Description |
|---|---|
HResult | — |
Event ID 1012 — Status
Message
Event ID 1013 — Status
Message
Fields
| Name | Description |
|---|---|
HResult | — |
Event ID 1014 — Status
Message
Event ID 1015 — Status
Message
Fields
| Name | Description |
|---|---|
HResult | — |
Event ID 1020 — Status
Message
Fields
| Name | Description |
|---|---|
HResult | — |
Event ID 1022 — Status
Message
Event ID 1024 — Status
Message
Event ID 1025 — Status
Message
Fields
| Name | Description |
|---|---|
HResult | — |
Event ID 1026 — Status
Message
Event ID 1027 — Status
Message
Event ID 1028 — Status
Message
Event ID 1029 — Status
Message
Fields
| Name | Description |
|---|---|
HResult | — |
Event ID 1030 — Status
Message
Event ID 1031 — Status
Message
Fields
| Name | Description |
|---|---|
HResult | — |
Event ID 2001 — Status
Message
Event ID 2002 — Status
Message
Event ID 2003 — Status
Message
Event ID 2004 — Status
Message
Event ID 2005 — Status
Message
Fields
| Name | Description |
|---|---|
HResult | — |
SnapshotPath | — |
Event ID 2006 — Status
Message
Fields
| Name | Description |
|---|---|
HResult | — |
SnapshotPath | — |
Event ID 2007 — Status
Message
Fields
| Name | Description |
|---|---|
ProviderId | — |
EventId | — |
HResult | — |
Event ID 2008 — Status
Message
Fields
| Name | Description |
|---|---|
ProviderId | — |
EventId | — |
HResult | — |
Event ID 2009 — Status
Message
Fields
| Name | Description |
|---|---|
ProviderId | — |
EventId | — |
HResult | — |
Event ID 2010 — Status
Message
Fields
| Name | Description |
|---|---|
ProviderId | — |
EventId | — |
HResult | — |
Event ID 2011 — Status
Message
Fields
| Name | Description |
|---|---|
ProviderId | — |
EventId | — |
HResult | — |
Event ID 2012 — Status
Message
Fields
| Name | Description |
|---|---|
ProviderId | — |
EventId | — |
HResult | — |
Event ID 2013 — Status
Message
Fields
| Name | Description |
|---|---|
ScenarioGUID | — |
HResult | — |
Event ID 2014 — Status
Message
Fields
| Name | Description |
|---|---|
ScenarioGUID | — |
HResult | — |
Event ID 2015 — Status
Message
Fields
| Name | Description |
|---|---|
ScenarioGUID | — |
HResult | — |
Event ID 2016 — Status
Message
Fields
| Name | Description |
|---|---|
ScenarioGUID | — |
HResult | — |
Event ID 7001 — Status
Message
Event ID 7101 — Status
Message
Event ID 7102 — Status
Message
Event ID 7103 — Status
Message
Event ID 7104 — Status
Message
Event ID 7105 — Status
Message
Event ID 7106 — Status
Message
Event ID 8001 — Status
Message
Fields
| Name | Description |
|---|---|
HResult | — |
Event ID 8002 — Status
Message
Fields
| Name | Description |
|---|---|
HResult | — |
Event ID 8003 — Status
Message
Event ID 8004 — Status
Message
Fields
| Name | Description |
|---|---|
HResult | — |
Event ID 8005 — Status
Message
Event ID 8006 — Status
Message
Fields
| Name | Description |
|---|---|
Path | — |
Event ID 8007 — Status
Message
Fields
| Name | Description |
|---|---|
Path | — |
Event ID 8008 — Status
Message
Event ID 8009 — Status
Message
Fields
| Name | Description |
|---|---|
HResult | — |
Event ID 8010 — Status
Message
Event ID 8011 — Status
Message
Event ID 8012 — Status
Message
Fields
| Name | Description |
|---|---|
HResult | — |
Event ID 8013 — Status
Message
Event ID 9001 — Status
Message
Fields
| Name | Description |
|---|---|
HResult | — |
Event ID 9003 — Status
Message
Fields
| Name | Description |
|---|---|
GUID | — |
EventId | — |
InternalState | — |
Event ID 9005 — Status
Message
Fields
| Name | Description |
|---|---|
NewState | — |
Event ID 9007 — Status
Message
Event ID 9009 — Status
Message
Fields
| Name | Description |
|---|---|
GUID | — |
EventId | — |
InternalState | — |
Event ID 9011 — Status
Message
Event ID 9012 — Status
Message
Fields
| Name | Description |
|---|---|
HResult | — |
Event ID 9013 — Status
Message
Event ID 9015 — Status
Message
Fields
| Name | Description |
|---|---|
HResult | — |
Event ID 10001 — Status
Message
Event ID 11001 —
Fields
| Name | Description |
|---|---|
GUID | — |
EventId | — |
InternalState | — |
Event ID 11002 —
Fields
| Name | Description |
|---|---|
NewState | — |
Event ID 11003 —
Event ID 11005 —
Event ID 11006 —
Fields
| Name | Description |
|---|---|
HResult | — |