Microsoft-Windows-Diagnostics-Performance

113 events across 3 channels

Event IDTitleChannel
100Windows has started up.Operational
101This application took longer than usual to start up, resulting in a performance …Operational
102This driver took longer to initialize, resulting in a performance degradation in …Operational
103This startup service took longer than expected to startup, resulting in a …Operational
104Core system took longer to initialize, resulting in a performance degradation in …Operational
105Foreground optimizations (prefetching) took longer to complete, resulting in a …Operational
106Background optimizations (prefetching) took longer to complete, resulting in a …Operational
107Application of machine policy caused a slow down in the system start up process.Operational
108Application of user policy caused a slow down in the system start up process.Operational
109This device took longer to initialize, resulting in a performance degradation in …Operational
110Session manager initialization caused a slow down in the startup process.Operational
200Windows has shutdown.Operational
201This application caused a delay in the system shutdown process.Operational
202This device caused a delay in the system shutdown process.Operational
203This service caused a delay in the system shutdown process.Operational
300Windows has resumed from standby.Operational
301This application caused a delay during standby.Operational
302This driver caused a delay during standby while servicing a device.Operational
303This service caused a delay during hybrid-sleep.Operational
304Creation of the hiber-file was slower than expected.Operational
305Persisting disk caches was slower than expected.Operational
306Preparing the video subsystem for sleep was slower than expected.Operational
307Preparing Winlogon for sleep was slower than expected.Operational
308Preparing system memory for sleep was slower than expected.Operational
309Preparing core system for sleep was slower than expected.Operational
310Preparing system worker threads for sleep was slower than expected.Operational
350Bios initialization time was greater than 250ms (logo requirement) during system …Operational
351This driver responded slower than expected to the resume request while servicing …Operational
352Reading the hiber-file was slower than expected.Operational
400Information about the system performance monitoring event.Operational
401This process is using up processor time and is impacting the performance of …Operational
402This process is doing excessive disk activities and is impacting the performance …Operational
403This driver is using up too many resources and is impacting the performance of …Operational
404This driver is waiting longer than expected on a device.Operational
405This file is fragmented and is impacting the performance of Windows.Operational
406Disk IO to this file is taking longer than expected.Operational
407This process is using up too much system memory.Operational
408Many processes are using too much system memory.Operational
500The Desktop Window Manager is experiencing heavy resource contention.Operational
501The Desktop Window Manager is experiencing heavy resource contention.Operational
1001StatusDiagnostic
1002StatusDiagnostic
1003StatusDiagnostic
1005StatusDiagnostic
1006StatusDiagnostic
1007StatusDiagnostic
1010StatusDiagnostic
1011StatusDiagnostic
1012StatusDiagnostic
1013StatusDiagnostic
1014StatusDiagnostic
1015StatusDiagnostic
1020StatusDiagnostic
1022StatusDiagnostic
1024StatusDiagnostic
1025StatusDiagnostic
1026StatusDiagnostic
1027StatusDiagnostic
1028StatusDiagnostic
1029StatusDiagnostic
1030StatusDiagnostic
1031StatusDiagnostic
2001StatusDiagnostic
2002StatusDiagnostic
2003StatusDiagnostic
2004StatusDiagnostic
2005StatusDiagnostic
2006StatusDiagnostic
2007StatusDiagnostic
2008StatusDiagnostic
2009StatusDiagnostic
2010StatusDiagnostic
2011StatusDiagnostic
2012StatusDiagnostic
2013StatusDiagnostic
2014StatusDiagnostic
2015StatusDiagnostic
2016StatusDiagnostic
7001StatusLoopback
7101StatusLoopback
7102StatusLoopback
7103StatusLoopback
7104StatusLoopback
7105StatusLoopback
7106StatusLoopback
8001StatusDiagnostic
8002StatusDiagnostic
8003StatusDiagnostic
8004StatusDiagnostic
8005StatusDiagnostic
8006StatusDiagnostic
8007StatusDiagnostic
8008StatusDiagnostic
8009StatusDiagnostic
8010StatusDiagnostic
8011StatusDiagnostic
8012StatusDiagnostic
8013StatusDiagnostic
9001StatusDiagnostic
9003StatusDiagnostic
9005StatusDiagnostic
9007StatusDiagnostic
9009StatusDiagnostic
9011StatusDiagnostic
9012StatusDiagnostic
9013StatusDiagnostic
9015StatusDiagnostic
10001StatusLoopback
11001Diagnostic
11002Diagnostic
11003Diagnostic
11005Diagnostic
11006Diagnostic

Event ID 100 — Windows has started up.

#
Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Operational
Level
Critical
Task
BootPerformanceMonitoring
Opcode
BootInformation

Description

Windows has started up.

Message #

Windows has started up: 

     Boot Duration		: %6ms

     IsDegradation		: %26

     Incident Time (UTC)	: %2

Fields #

NameDescription
BootTsVersion UInt32
BootStartTime FILETIME
BootEndTime FILETIME
SystemBootInstance UInt32
UserBootInstance UInt32
BootTime UInt32
MainPathBootTime UInt32
BootKernelInitTime UInt32
BootDriverInitTime UInt32
BootDevicesInitTime UInt32
BootPrefetchInitTime UInt32
BootPrefetchBytes UInt32
BootAutoChkTime UInt32
BootSmssInitTime UInt32
BootCriticalServicesInitTime UInt32
BootUserProfileProcessingTime UInt32
BootMachineProfileProcessingTime UInt32
BootExplorerInitTime UInt32
BootNumStartupApps UInt32
BootPostBootTime UInt32
BootIsRebootAfterInstall Boolean
BootRootCauseStepImprovementBits UInt32
BootRootCauseGradualImprovementBits UInt32
BootRootCauseStepDegradationBits UInt32
BootRootCauseGradualDegradationBits UInt32
BootIsDegradation Boolean
BootIsStepDegradation Boolean
BootIsGradualDegradation Boolean
BootImprovementDelta UInt32
BootDegradationDelta UInt32
BootIsRootCauseIdentified Boolean
OSLoaderDuration UInt32
BootPNPInitStartTimeMS UInt32
BootPNPInitDuration UInt32
OtherKernelInitDuration UInt32
SystemPNPInitStartTimeMS UInt32
SystemPNPInitDuration UInt32
SessionInitStartTimeMS UInt32
Session0InitDuration UInt32
Session1InitDuration UInt32
SessionInitOtherDuration UInt32
WinLogonStartTimeMS UInt32
OtherLogonInitActivityDuration UInt32
UserLogonWaitDuration UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Diagnostics-Performance",
    "guid": "CFC18EC0-96B1-4EBA-961B-622CAEE05B0A",
    "event_source_name": "",
    "event_id": 100,
    "version": 2,
    "level": 1,
    "task": 4002,
    "opcode": 34,
    "keywords": 9223372036854841344,
    "time_created": "2023-11-05T22:33:58.036254+00:00",
    "event_record_id": 38,
    "correlation": {
      "ActivityID": "E4DB489E-1037-0003-0982-DBE43710DA01"
    },
    "execution": {
      "process_id": 3160,
      "thread_id": 3556
    },
    "channel": "Microsoft-Windows-Diagnostics-Performance/Operational",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-19"
    }
  },
  "event_data": {
    "BootTsVersion": 2,
    "BootStartTime": "2023-11-05T22:32:00.970725Z",
    "BootEndTime": "2023-11-05T22:33:56.389945Z",
    "SystemBootInstance": 8,
    "UserBootInstance": 2,
    "BootTime": 110680,
    "MainPathBootTime": 34629,
    "BootKernelInitTime": 164,
    "BootDriverInitTime": 1567,
    "BootDevicesInitTime": 2810,
    "BootPrefetchInitTime": 0,
    "BootPrefetchBytes": 0,
    "BootAutoChkTime": 0,
    "BootSmssInitTime": 6391,
    "BootCriticalServicesInitTime": 1441,
    "BootUserProfileProcessingTime": 1084,
    "BootMachineProfileProcessingTime": 456,
    "BootExplorerInitTime": 18858,
    "BootNumStartupApps": 3,
    "BootPostBootTime": 76051,
    "BootIsRebootAfterInstall": false,
    "BootRootCauseStepImprovementBits": 0,
    "BootRootCauseGradualImprovementBits": 0,
    "BootRootCauseStepDegradationBits": 13631488,
    "BootRootCauseGradualDegradationBits": 13631488,
    "BootIsDegradation": true,
    "BootIsStepDegradation": true,
    "BootIsGradualDegradation": true,
    "BootImprovementDelta": 0,
    "BootDegradationDelta": 68995,
    "BootIsRootCauseIdentified": true,
    "OSLoaderDuration": 3107,
    "BootPNPInitStartTimeMS": 164,
    "BootPNPInitDuration": 4163,
    "OtherKernelInitDuration": 445,
    "SystemPNPInitStartTimeMS": 4495,
    "SystemPNPInitDuration": 1301,
    "SessionInitStartTimeMS": 5910,
    "Session0InitDuration": 1013,
    "Session1InitDuration": 219,
    "SessionInitOtherDuration": 5158,
    "WinLogonStartTimeMS": 12302,
    "OtherLogonInitActivityDuration": 1926,
    "UserLogonWaitDuration": 4739
  },
  "message": ""
}

References #

Event ID 101 — This application took longer than usual to start up, resulting in a performance degradation in the system startup process.

#
Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Operational
Level
Warning
Task
BootPerformanceMonitoring
Opcode
BootDegradation

Description

This application took longer than usual to start up, resulting in a performance degradation in the system startup process.

Message #

This application took longer than usual to start up, resulting in a performance degradation in the system startup process: 

     File Name		: %3

     Friendly Name		: %5

     Version		: %7

     Total Time		: %8ms

     Degradation Time	: %9ms

     Incident Time (UTC)	: %1

Fields #

NameDescription
StartTime FILETIME
NameLength UInt32
Name UnicodeString
FriendlyNameLength UInt32
FriendlyName UnicodeString
VersionLength UInt32
Version UnicodeString
TotalTime UInt32
DegradationTime UInt32
PathLength UInt32
Path UnicodeString
ProductNameLength UInt32
ProductName UnicodeString
CompanyNameLength UInt32
CompanyName UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Diagnostics-Performance",
    "guid": "CFC18EC0-96B1-4EBA-961B-622CAEE05B0A",
    "event_source_name": "",
    "event_id": 101,
    "version": 1,
    "level": 3,
    "task": 4002,
    "opcode": 33,
    "keywords": 9223372036854841344,
    "time_created": "2023-11-05T22:33:58.036338+00:00",
    "event_record_id": 44,
    "correlation": {
      "ActivityID": "E4DB489E-1037-0003-0982-DBE43710DA01"
    },
    "execution": {
      "process_id": 3160,
      "thread_id": 3556
    },
    "channel": "Microsoft-Windows-Diagnostics-Performance/Operational",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-19"
    }
  },
  "event_data": {
    "StartTime": "2023-11-05T22:32:00.970725Z",
    "NameLength": 28,
    "Name": "StartMenuExperienceHost.exe",
    "FriendlyNameLength": 30,
    "FriendlyName": "Windows Start Experience Host",
    "VersionLength": 39,
    "Version": "10.0.22621.2361 (WinBuild.160101.0800)",
    "TotalTime": 6125,
    "DegradationTime": 3625,
    "PathLength": 106,
    "Path": "C:\\Windows\\SystemApps\\Microsoft.Windows.StartMenuExperienceHost_cw5n1h2txyewy\\StartMenuExperienceHost.exe",
    "ProductNameLength": 37,
    "ProductName": "Microsoft® Windows® Operating System",
    "CompanyNameLength": 22,
    "CompanyName": "Microsoft Corporation"
  },
  "message": ""
}

References #

Event ID 102 — This driver took longer to initialize, resulting in a performance degradation in the system start up process.

#
Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Operational
Level
Warning
Task
BootPerformanceMonitoring
Opcode
BootDegradation

Description

This driver took longer to initialize, resulting in a performance degradation in the system start up process.

Message #

This driver took longer to initialize, resulting in a performance degradation in the system start up process: 

     File Name		: %3

     Friendly Name		: %5

     Version		: %7

     Total Time		: %8ms

     Degradation Time	: %9ms

     Incident Time (UTC)	: %1

Fields #

NameDescription
StartTime FILETIME
NameLength UInt32
Name UnicodeString
FriendlyNameLength UInt32
FriendlyName UnicodeString
VersionLength UInt32
Version UnicodeString
TotalTime UInt32
DegradationTime UInt32
PathLength UInt32
Path UnicodeString
ProductNameLength UInt32
ProductName UnicodeString
CompanyNameLength UInt32
CompanyName UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Diagnostics-Performance",
    "guid": "CFC18EC0-96B1-4EBA-961B-622CAEE05B0A",
    "event_source_name": "",
    "event_id": 102,
    "version": 1,
    "level": 3,
    "task": 4002,
    "opcode": 33,
    "keywords": 9223372036854841344,
    "time_created": "2023-10-25T22:05:44.601509+00:00",
    "event_record_id": 25,
    "correlation": {
      "ActivityID": "028F2288-078F-0001-413E-8F028F07DA01"
    },
    "execution": {
      "process_id": 2484,
      "thread_id": 3796
    },
    "channel": "Microsoft-Windows-Diagnostics-Performance/Operational",
    "computer": "WinDevEval",
    "security": {
      "user_id": "S-1-5-19"
    }
  },
  "event_data": {
    "StartTime": "2023-10-25T22:02:56.552302Z",
    "NameLength": 7,
    "Name": "VfpExt",
    "FriendlyNameLength": 30,
    "FriendlyName": "Microsoft Azure VFP Extension",
    "VersionLength": 36,
    "Version": "10.0.22621.1 (WinBuild.160101.0800)",
    "TotalTime": 8403,
    "DegradationTime": 6903,
    "PathLength": 39,
    "Path": "C:\\Windows\\system32\\drivers\\vfpext.sys",
    "ProductNameLength": 37,
    "ProductName": "Microsoft® Windows® Operating System",
    "CompanyNameLength": 22,
    "CompanyName": "Microsoft Corporation"
  },
  "message": ""
}

References #

Event ID 103 — This startup service took longer than expected to startup, resulting in a performance degradation in the system start up process.

Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Operational
Task
BootPerformanceMonitoring
Opcode
BootDegradation

Description

This startup service took longer than expected to startup, resulting in a performance degradation in the system start up process.

Message #

This startup service took longer than expected to startup, resulting in a performance degradation in the system start up process: 

     File Name		: %3

     Friendly Name		: %5

     Version		: %7

     Total Time		: %8ms

     Degradation Time	: %9ms

     Incident Time (UTC)	: %1

Fields #

NameDescription
StartTime FILETIME
NameLength UInt32
Name UnicodeString
FriendlyNameLength UInt32
FriendlyName UnicodeString
VersionLength UInt32
Version UnicodeString
TotalTime UInt32
DegradationTime UInt32
PathLength UInt32
Path UnicodeString
ProductNameLength UInt32
ProductName UnicodeString
CompanyNameLength UInt32
CompanyName UnicodeString

Event ID 104 — Core system took longer to initialize, resulting in a performance degradation in the system start up process.

Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Operational
Task
BootPerformanceMonitoring
Opcode
BootDegradation

Description

Core system took longer to initialize, resulting in a performance degradation in the system start up process.

Message #

Core system took longer to initialize, resulting in a performance degradation in the system start up process: 

     Name		: %3

     Total Time		: %4ms

     Degradation Time	: %5ms

     Incident Time (UTC)	: %1

Fields #

NameDescription
StartTime FILETIME
NameLength UInt32
Name UnicodeString
TotalTime UInt32
DegradationTime UInt32

Event ID 105 — Foreground optimizations (prefetching) took longer to complete, resulting in a performance degradation in the system start up process.

Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Operational
Task
BootPerformanceMonitoring
Opcode
BootDegradation

Description

Foreground optimizations (prefetching) took longer to complete, resulting in a performance degradation in the system start up process.

Message #

Foreground optimizations (prefetching) took longer to complete, resulting in a performance degradation in the system start up process: 

     Name		: %3

     Total Time		: %4ms

     Degradation Time	: %5ms

     Incident Time (UTC)	: %1

Fields #

NameDescription
StartTime FILETIME
NameLength UInt32
Name UnicodeString
TotalTime UInt32
DegradationTime UInt32

Event ID 106 — Background optimizations (prefetching) took longer to complete, resulting in a performance degradation in the system start up process.

Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Operational
Task
BootPerformanceMonitoring
Opcode
BootDegradation

Description

Background optimizations (prefetching) took longer to complete, resulting in a performance degradation in the system start up process.

Message #

Background optimizations (prefetching) took longer to complete, resulting in a performance degradation in the system start up process: 

     Name		: %3

     Total Time		: %4ms

     Degradation Time	: %5ms

     Incident Time (UTC)	: %1

Fields #

NameDescription
StartTime FILETIME
NameLength UInt32
Name UnicodeString
TotalTime UInt32
DegradationTime UInt32

Event ID 107 — Application of machine policy caused a slow down in the system start up process.

Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Operational
Level
Warning
Task
BootPerformanceMonitoring
Opcode
BootDegradation

Description

Application of machine policy caused a slow down in the system start up process.

Message #

Application of machine policy caused a slow down in the system start up process: 

     Name		: %3

     Total Time		: %4ms

     Degradation Time	: %5ms

     Incident Time (UTC)	: %1

Fields #

NameDescription
StartTime FILETIME
NameLength UInt32
Name UnicodeString
TotalTime UInt32
DegradationTime UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Diagnostics-Performance",
    "guid": "CFC18EC0-96B1-4EBA-961B-622CAEE05B0A",
    "event_source_name": "",
    "event_id": 107,
    "version": 1,
    "level": 3,
    "task": 4002,
    "opcode": 33,
    "keywords": 9223372036854841344,
    "time_created": "2026-02-10T04:13:48.386918+00:00",
    "event_record_id": 13,
    "correlation": {
      "ActivityID": "43A6D212-9A2A-0007-EC4C-A7432A9ADC01"
    },
    "execution": {
      "process_id": 3924,
      "thread_id": 4184
    },
    "channel": "Microsoft-Windows-Diagnostics-Performance/Operational",
    "computer": "LAB-WIN11.ludus.domain",
    "security": {
      "user_id": "S-1-5-19"
    }
  },
  "event_data": {
    "StartTime": "2026-02-10T01:12:02.866821Z",
    "NameLength": 25,
    "Name": "MachinePolicyApplication",
    "TotalTime": 2121,
    "DegradationTime": 1121
  },
  "message": ""
}

Event ID 108 — Application of user policy caused a slow down in the system start up process.

Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Operational
Task
BootPerformanceMonitoring
Opcode
BootDegradation

Description

Application of user policy caused a slow down in the system start up process.

Message #

Application of user policy caused a slow down in the system start up process: 

     Name		: %3

     Total Time		: %4ms

     Degradation Time	: %5ms

     Incident Time (UTC)	: %1

Fields #

NameDescription
StartTime FILETIME
NameLength UInt32
Name UnicodeString
TotalTime UInt32
DegradationTime UInt32

Event ID 109 — This device took longer to initialize, resulting in a performance degradation in the system start up process.

Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Operational
Task
BootPerformanceMonitoring
Opcode
BootDegradation

Description

This device took longer to initialize, resulting in a performance degradation in the system start up process.

Message #

This device took longer to initialize, resulting in a performance degradation in the system start up process: 

     File Name		: %3

     Friendly Name		: %5

     Version		: %7

     Total Time		: %8ms

     Degradation Time	: %9ms

     Incident Time (UTC)	: %1

Fields #

NameDescription
StartTime FILETIME
NameLength UInt32
Name UnicodeString
FriendlyNameLength UInt32
FriendlyName UnicodeString
VersionLength UInt32
Version UnicodeString
TotalTime UInt32
DegradationTime UInt32
PathLength UInt32
Path UnicodeString
ProductNameLength UInt32
ProductName UnicodeString
CompanyNameLength UInt32
CompanyName UnicodeString

Event ID 110 — Session manager initialization caused a slow down in the startup process.

#
Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Operational
Level
Warning
Task
BootPerformanceMonitoring
Opcode
BootDegradation

Description

Session manager initialization caused a slow down in the startup process.

Message #

Session manager initialization caused a slow down in the startup process: 

     Name		: %3

     Total Time		: %4ms

     Degradation Time	: %5ms

     Incident Time (UTC)	: %1

Fields #

NameDescription
StartTime FILETIME
NameLength UInt32
Name UnicodeString
TotalTime UInt32
DegradationTime UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Diagnostics-Performance",
    "guid": "CFC18EC0-96B1-4EBA-961B-622CAEE05B0A",
    "event_source_name": "",
    "event_id": 110,
    "version": 1,
    "level": 3,
    "task": 4002,
    "opcode": 33,
    "keywords": 9223372036854841344,
    "time_created": "2023-10-25T22:05:44.601513+00:00",
    "event_record_id": 26,
    "correlation": {
      "ActivityID": "028F2288-078F-0001-413E-8F028F07DA01"
    },
    "execution": {
      "process_id": 2484,
      "thread_id": 3796
    },
    "channel": "Microsoft-Windows-Diagnostics-Performance/Operational",
    "computer": "WinDevEval",
    "security": {
      "user_id": "S-1-5-19"
    }
  },
  "event_data": {
    "StartTime": "2023-10-25T22:02:56.552302Z",
    "NameLength": 9,
    "Name": "SMSSInit",
    "TotalTime": 17567,
    "DegradationTime": 7567
  },
  "message": ""
}

References #

Event ID 200 — Windows has shutdown.

#
Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Operational
Level
Warning
Task
ShutdownPerformanceMonitoring
Opcode
ShutdownInformation

Description

Windows has shutdown.

Message #

Windows has shutdown: 

     Shutdown Duration	: %4ms

     IsDegradation		: %16

     Incident Time (UTC)	: %2

Fields #

NameDescription
ShutdownTsVersion UInt32
ShutdownStartTime FILETIME
ShutdownEndTime FILETIME
ShutdownTime UInt32
ShutdownUserSessionTime UInt32
ShutdownUserPolicyTime UInt32
ShutdownUserProfilesTime UInt32
ShutdownSystemSessionsTime UInt32
ShutdownPreShutdownNotificationsTime UInt32
ShutdownServicesTime UInt32
ShutdownKernelTime UInt32
ShutdownRootCauseStepImprovementBits UInt32
ShutdownRootCauseGradualImprovementBits UInt32
ShutdownRootCauseStepDegradationBits UInt32
ShutdownRootCauseGradualDegradationBits UInt32
ShutdownIsDegradation Boolean
ShutdownTimeChange Int32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Diagnostics-Performance",
    "guid": "CFC18EC0-96B1-4EBA-961B-622CAEE05B0A",
    "event_source_name": "",
    "event_id": 200,
    "version": 1,
    "level": 3,
    "task": 4007,
    "opcode": 40,
    "keywords": 9223372036854841344,
    "time_created": "2023-11-05T22:33:56.991516+00:00",
    "event_record_id": 36,
    "correlation": {
      "ActivityID": "E4DB489E-1037-0001-FD89-DBE43710DA01"
    },
    "execution": {
      "process_id": 3160,
      "thread_id": 3468
    },
    "channel": "Microsoft-Windows-Diagnostics-Performance/Operational",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-19"
    }
  },
  "event_data": {
    "ShutdownTsVersion": 1,
    "ShutdownStartTime": "2023-11-05T22:31:30.287074Z",
    "ShutdownEndTime": "2023-11-05T22:31:43.106260Z",
    "ShutdownTime": 12819,
    "ShutdownUserSessionTime": 3778,
    "ShutdownUserPolicyTime": 17,
    "ShutdownUserProfilesTime": 236,
    "ShutdownSystemSessionsTime": 6148,
    "ShutdownPreShutdownNotificationsTime": 1596,
    "ShutdownServicesTime": 4185,
    "ShutdownKernelTime": 2892,
    "ShutdownRootCauseStepImprovementBits": 0,
    "ShutdownRootCauseGradualImprovementBits": 0,
    "ShutdownRootCauseStepDegradationBits": 72,
    "ShutdownRootCauseGradualDegradationBits": 0,
    "ShutdownIsDegradation": true,
    "ShutdownTimeChange": 0
  },
  "message": ""
}

References #

Event ID 201 — This application caused a delay in the system shutdown process.

Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Operational
Task
ShutdownPerformanceMonitoring
Opcode
ShutdownDegradation

Description

This application caused a delay in the system shutdown process.

Message #

This application caused a delay in the system shutdown process: 

     File Name		: %3

     Friendly Name		: %5

     Version		: %7

     Total Time		: %8ms

     Degradation Time	: %9ms

     Incident Time (UTC)	: %1

Fields #

NameDescription
StartTime FILETIME
NameLength UInt32
Name UnicodeString
FriendlyNameLength UInt32
FriendlyName UnicodeString
VersionLength UInt32
Version UnicodeString
TotalTime UInt32
DegradationTime UInt32
PathLength UInt32
Path UnicodeString
ProductNameLength UInt32
ProductName UnicodeString
CompanyNameLength UInt32
CompanyName UnicodeString

Event ID 202 — This device caused a delay in the system shutdown process.

Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Operational
Task
ShutdownPerformanceMonitoring
Opcode
ShutdownDegradation

Description

This device caused a delay in the system shutdown process.

Message #

This device caused a delay in the system shutdown process: 

     File Name		: %3

     Friendly Name		: %5

     Version		: %7

     Total Time		: %8ms

     Degradation Time	: %9ms

     Incident Time (UTC)	: %1

Fields #

NameDescription
StartTime FILETIME
NameLength UInt32
Name UnicodeString
FriendlyNameLength UInt32
FriendlyName UnicodeString
VersionLength UInt32
Version UnicodeString
TotalTime UInt32
DegradationTime UInt32
PathLength UInt32
Path UnicodeString
ProductNameLength UInt32
ProductName UnicodeString
CompanyNameLength UInt32
CompanyName UnicodeString

Event ID 203 — This service caused a delay in the system shutdown process.

#
Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Operational
Level
Warning
Task
ShutdownPerformanceMonitoring
Opcode
ShutdownDegradation

Description

This service caused a delay in the system shutdown process.

Message #

This service caused a delay in the system shutdown process: 

     File Name		: %3

     Friendly Name		: %5

     Version		: %7

     Total Time		: %8ms

     Degradation Time	: %9ms

     Incident Time (UTC)	: %1

Fields #

NameDescription
StartTime FILETIME
NameLength UInt32
Name UnicodeString
FriendlyNameLength UInt32
FriendlyName UnicodeString
VersionLength UInt32
Version UnicodeString
TotalTime UInt32
DegradationTime UInt32
PathLength UInt32
Path UnicodeString
ProductNameLength UInt32
ProductName UnicodeString
CompanyNameLength UInt32
CompanyName UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Diagnostics-Performance",
    "guid": "CFC18EC0-96B1-4EBA-961B-622CAEE05B0A",
    "event_source_name": "",
    "event_id": 203,
    "version": 1,
    "level": 3,
    "task": 4007,
    "opcode": 41,
    "keywords": 9223372036854841344,
    "time_created": "2023-11-05T22:33:56.991549+00:00",
    "event_record_id": 37,
    "correlation": {
      "ActivityID": "E4DB489E-1037-0001-FD89-DBE43710DA01"
    },
    "execution": {
      "process_id": 3160,
      "thread_id": 3468
    },
    "channel": "Microsoft-Windows-Diagnostics-Performance/Operational",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-19"
    }
  },
  "event_data": {
    "StartTime": "2023-11-05T22:31:30.287074Z",
    "NameLength": 10,
    "Name": "WinDefend",
    "FriendlyNameLength": 0,
    "FriendlyName": "",
    "VersionLength": 0,
    "Version": "",
    "TotalTime": 4054,
    "DegradationTime": 54,
    "PathLength": 83,
    "Path": "\"c:\\programdata\\microsoft\\windows defender\\platform\\4.18.23090.2008-0\\msmpeng.exe\"",
    "ProductNameLength": 0,
    "ProductName": "",
    "CompanyNameLength": 0,
    "CompanyName": ""
  },
  "message": ""
}

References #

Event ID 300 — Windows has resumed from standby.

Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Operational
Task
StandbyPerformanceMonitoring
Opcode
StandbyInformation

Description

Windows has resumed from standby.

Message #

Windows has resumed from standby: 

     Standby Duration		: %7ms

     Standby Incident Time (UTC)	: %5

     Resume  Duration		: %39ms

     Resume  Incident Time (UTC)	: %37

     IsDegradation			: %51

Fields #

NameDescription
StandbyTsVersion UInt32
StandbyAppCount UInt32
StandbyServicesCount UInt32
StandbyDevicesCount UInt32
StandbyStartTime FILETIME
StandbyEndTime FILETIME
StandbySuspendTotal UInt32
StandbySuspendTotalChange Int32
StandbySuspendQueryApps UInt32
StandbySuspendQueryAppsChange Int32
StandbySuspendQueryServices UInt32
StandbySuspendQueryServicesChange Int32
StandbySuspendApps UInt32
StandbySuspendAppsChange Int32
StandbySuspendServices UInt32
StandbySuspendServicesChange Int32
StandbySuspendShowUI UInt32
StandbySuspendShowUIChange Int32
StandbySuspendSuperfetchPageIn UInt32
StandbySuspendSuperfetchPageInChange Int32
StandbySuspendWinlogon UInt32
StandbySuspendWinlogonChange Int32
StandbySuspendLockPageableSections UInt32
StandbySuspendLockPageableSectionsChange Int32
StandbySuspendPreSleepCallbacks UInt32
StandbySuspendPreSleepCallbacksChange Int32
StandbySuspendSwapInWorkerThreads UInt32
StandbySuspendSwapInWorkerThreadsChange Int32
StandbySuspendQueryDevices UInt32
StandbySuspendQueryDevicesChange Int32
StandbySuspendFlushVolumes UInt32
StandbySuspendFlushVolumesChange Int32
StandbySuspendSuspendDevices UInt32
StandbySuspendSuspendDevicesChange Int32
StandbySuspendHibernateWrite UInt32
StandbySuspendHibernateWriteChange Int32
ResumeStartTime FILETIME
ResumeEndTime FILETIME
StandbyResumeTotal UInt32
StandbyResumeTotalChange Int32
StandbyResumeHibernateRead UInt32
StandbyResumeHibernateReadChange Int32
StandbyResumeS3BiosInitTime UInt32
StandbyResumeS3BiosInitTimeChange Int32
StandbyResumeResumeDevices UInt32
StandbyResumeResumeDevicesChange Int32
StandbyRootCauseDegradationGradual UInt32
StandbyRootCauseImprovementGradual UInt32
StandbyRootCauseDegradationStep UInt32
StandbyRootCauseImprovementStep UInt32
StandbyIsDegradation Boolean
StandbyIsTroubleshooterLaunched Boolean
StandbyIsRootCauseIdentified Boolean

Event ID 301 — This application caused a delay during standby.

Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Operational
Task
StandbyPerformanceMonitoring
Opcode
StandbyDegradation

Description

This application caused a delay during standby.

Message #

This application caused a delay during standby: 

     File Name		: %3

     Friendly Name		: %5

     Version		: %7

     Total Time		: %8ms

     Degradation Time	: %9ms

     Incident Time (UTC)	: %1

Fields #

NameDescription
StartTime FILETIME
NameLength UInt32
Name UnicodeString
FriendlyNameLength UInt32
FriendlyName UnicodeString
VersionLength UInt32
Version UnicodeString
TotalTime UInt32
DegradationTime UInt32
PathLength UInt32
Path UnicodeString
ProductNameLength UInt32
ProductName UnicodeString
CompanyNameLength UInt32
CompanyName UnicodeString

Event ID 302 — This driver caused a delay during standby while servicing a device.

Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Operational
Task
StandbyPerformanceMonitoring
Opcode
StandbyDegradation

Description

This driver caused a delay during standby while servicing a device.

Message #

This driver caused a delay during standby while servicing a device:

     Driver File Name		: %3

     Driver Friendly Name		: %5

     Driver Version			: %7

     Driver Total Time		: %8ms

     Driver Degradation Time	: %9ms

     Incident Time (UTC)		: %1

     Device Name			: %17

     Device Friendly Name		: %19

     Device Total Time		: %20ms

     Device Degradation Time	: %21ms

Fields #

NameDescription
StartTime FILETIME
NameLength UInt32
Name UnicodeString
FriendlyNameLength UInt32
FriendlyName UnicodeString
VersionLength UInt32
Version UnicodeString
TotalTime UInt32
DegradationTime UInt32
PathLength UInt32
Path UnicodeString
ProductNameLength UInt32
ProductName UnicodeString
CompanyNameLength UInt32
CompanyName UnicodeString
DeviceNameLength UInt32
DeviceName UnicodeString
DeviceFriendlyNameLength UInt32
DeviceFriendlyName UnicodeString
DeviceTotalTime UInt32
DeviceDegradationTime UInt32

Event ID 303 — This service caused a delay during hybrid-sleep.

Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Operational
Task
StandbyPerformanceMonitoring
Opcode
StandbyDegradation

Description

This service caused a delay during hybrid-sleep.

Message #

This service caused a delay during hybrid-sleep: 

     File Name		: %3

     Friendly Name		: %5

     Version		: %7

     Total Time		: %8ms

     Degradation Time	: %9ms

     Incident Time (UTC)	: %1

Fields #

NameDescription
StartTime FILETIME
NameLength UInt32
Name UnicodeString
FriendlyNameLength UInt32
FriendlyName UnicodeString
VersionLength UInt32
Version UnicodeString
TotalTime UInt32
DegradationTime UInt32
PathLength UInt32
Path UnicodeString
ProductNameLength UInt32
ProductName UnicodeString
CompanyNameLength UInt32
CompanyName UnicodeString

Event ID 304 — Creation of the hiber-file was slower than expected.

Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Operational
Task
StandbyPerformanceMonitoring
Opcode
StandbyDegradation

Description

Creation of the hiber-file was slower than expected.

Message #

Creation of the hiber-file was slower than expected: 

     Name		: %3

     Total Time		: %4ms

     Degradation Time	: %5ms

     Incident Time (UTC)	: %1

Fields #

NameDescription
StartTime FILETIME
NameLength UInt32
Name UnicodeString
TotalTime UInt32
DegradationTime UInt32

Event ID 305 — Persisting disk caches was slower than expected.

Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Operational
Task
StandbyPerformanceMonitoring
Opcode
StandbyDegradation

Description

Persisting disk caches was slower than expected.

Message #

Persisting disk caches was slower than expected: 

     Name		: %3

     Total Time		: %4ms

     Degradation Time	: %5ms

     Incident Time (UTC)	: %1

Fields #

NameDescription
StartTime FILETIME
NameLength UInt32
Name UnicodeString
TotalTime UInt32
DegradationTime UInt32

Event ID 306 — Preparing the video subsystem for sleep was slower than expected.

Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Operational
Task
StandbyPerformanceMonitoring
Opcode
StandbyDegradation

Description

Preparing the video subsystem for sleep was slower than expected.

Message #

Preparing the video subsystem for sleep was slower than expected: 

     Name		: %3

     Total Time		: %4ms

     Degradation Time	: %5ms

     Incident Time (UTC)	: %1

Fields #

NameDescription
StartTime FILETIME
NameLength UInt32
Name UnicodeString
TotalTime UInt32
DegradationTime UInt32

Event ID 307 — Preparing Winlogon for sleep was slower than expected.

Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Operational
Task
StandbyPerformanceMonitoring
Opcode
StandbyDegradation

Description

Preparing Winlogon for sleep was slower than expected.

Message #

Preparing Winlogon for sleep was slower than expected: 

     Name		: %3

     Total Time		: %4ms

     Degradation Time	: %5ms

     Incident Time (UTC)	: %1

Fields #

NameDescription
StartTime FILETIME
NameLength UInt32
Name UnicodeString
TotalTime UInt32
DegradationTime UInt32

Event ID 308 — Preparing system memory for sleep was slower than expected.

Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Operational
Task
StandbyPerformanceMonitoring
Opcode
StandbyDegradation

Description

Preparing system memory for sleep was slower than expected.

Message #

Preparing system memory for sleep was slower than expected: 

     Name		: %3

     Total Time		: %4ms

     Degradation Time	: %5ms

     Incident Time (UTC)	: %1

Fields #

NameDescription
StartTime FILETIME
NameLength UInt32
Name UnicodeString
TotalTime UInt32
DegradationTime UInt32

Event ID 309 — Preparing core system for sleep was slower than expected.

Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Operational
Task
StandbyPerformanceMonitoring
Opcode
StandbyDegradation

Description

Preparing core system for sleep was slower than expected.

Message #

Preparing core system for sleep was slower than expected: 

     Name		: %3

     Total Time		: %4ms

     Degradation Time	: %5ms

     Incident Time (UTC)	: %1

Fields #

NameDescription
StartTime FILETIME
NameLength UInt32
Name UnicodeString
TotalTime UInt32
DegradationTime UInt32

Event ID 310 — Preparing system worker threads for sleep was slower than expected.

Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Operational
Task
StandbyPerformanceMonitoring
Opcode
StandbyDegradation

Description

Preparing system worker threads for sleep was slower than expected.

Message #

Preparing system worker threads for sleep was slower than expected: 

     Name		: %3

     Total Time		: %4ms

     Degradation Time	: %5ms

     Incident Time (UTC)	: %1

Fields #

NameDescription
StartTime FILETIME
NameLength UInt32
Name UnicodeString
TotalTime UInt32
DegradationTime UInt32

Event ID 350 — Bios initialization time was greater than 250ms (logo requirement) during system resume.

Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Operational
Task
StandbyPerformanceMonitoring
Opcode
StandbyDegradation

Description

Bios initialization time was greater than 250ms (logo requirement) during system resume.

Message #

Bios initialization time was greater than 250ms (logo requirement) during system resume: 

     Name		: %3

     Total Time		: %4ms

     Degradation Time	: %5ms

     Incident Time (UTC)	: %1

Fields #

NameDescription
StartTime FILETIME
NameLength UInt32
Name UnicodeString
TotalTime UInt32
DegradationTime UInt32

Event ID 351 — This driver responded slower than expected to the resume request while servicing this device.

Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Operational
Task
StandbyPerformanceMonitoring
Opcode
StandbyDegradation

Description

This driver responded slower than expected to the resume request while servicing this device.

Message #

This driver responded slower than expected to the resume request while servicing this device: 

     Driver File Name		: %3

     Driver Friendly Name		: %5

     Driver Version			: %7

     Driver Total Time		: %8ms

     Driver Degradation Time	: %9ms

     Incident Time (UTC)		: %1

     Device Name			: %17

     Device Friendly Name		: %19

     Device Total Time		: %20ms

     Device Degradation Time	: %21ms

Fields #

NameDescription
StartTime FILETIME
NameLength UInt32
Name UnicodeString
FriendlyNameLength UInt32
FriendlyName UnicodeString
VersionLength UInt32
Version UnicodeString
TotalTime UInt32
DegradationTime UInt32
PathLength UInt32
Path UnicodeString
ProductNameLength UInt32
ProductName UnicodeString
CompanyNameLength UInt32
CompanyName UnicodeString
DeviceNameLength UInt32
DeviceName UnicodeString
DeviceFriendlyNameLength UInt32
DeviceFriendlyName UnicodeString
DeviceTotalTime UInt32
DeviceDegradationTime UInt32

Event ID 352 — Reading the hiber-file was slower than expected.

Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Operational
Task
StandbyPerformanceMonitoring
Opcode
StandbyDegradation

Description

Reading the hiber-file was slower than expected.

Message #

Reading the hiber-file was slower than expected: 

     Name		: %3

     Total Time		: %4ms

     Degradation Time	: %5ms

     Incident Time (UTC)	: %1

Fields #

NameDescription
StartTime FILETIME
NameLength UInt32
Name UnicodeString
TotalTime UInt32
DegradationTime UInt32

Event ID 400 — Information about the system performance monitoring event.

Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Operational
Task
SystemPerformanceMonitoring
Opcode
ShellInformation

Description

Information about the system performance monitoring event.

Message #

Information about the system performance monitoring event: 

     Scenario		: %3

     Analysis result		: %6

     Incident Time (UTC)	: %1

Fields #

NameDescription
ShellScenarioStartTime FILETIME
ShellScenarioEndTime FILETIME
ShellSubScenario UInt32
ShellScenarioDuration UInt32
ShellRootCauseBits UInt32
ShellAnalysisResult UInt32
ShellDegradationType UInt32
ShellTsVersion UInt32
ShellMachineUpTimeHours UInt32
ShellMachineSleepPattern UInt32

Event ID 401 — This process is using up processor time and is impacting the performance of Windows.

Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Operational
Task
SystemPerformanceMonitoring
Opcode
ShellDegradation

Description

This process is using up processor time and is impacting the performance of Windows.

Message #

This process is using up processor time and is impacting the performance of Windows: 

     File Name		: %3

     Friendly Name		: %5

     Version		: %7

     Thread time		: %8ms

     Blocked Time		: %9ms

     Incident Time (UTC)	: %1

Fields #

NameDescription
StartTime FILETIME
NameLength UInt32
Name UnicodeString
FriendlyNameLength UInt32
FriendlyName UnicodeString
VersionLength UInt32
Version UnicodeString
ThreadTime UInt32
BlockedTime UInt32
PercentTime Double
PathLength UInt32
Path UnicodeString
ProductNameLength UInt32
ProductName UnicodeString
CompanyNameLength UInt32
CompanyName UnicodeString

Event ID 402 — This process is doing excessive disk activities and is impacting the performance of Windows.

Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Operational
Task
SystemPerformanceMonitoring
Opcode
ShellDegradation

Description

This process is doing excessive disk activities and is impacting the performance of Windows.

Message #

This process is doing excessive disk activities and is impacting the performance of Windows: 

     File Name		: %3

     Friendly Name		: %5

     Version		: %7

     Thread time		: %8ms

     Blocked Time		: %9ms

     Incident Time (UTC)	: %1

Fields #

NameDescription
StartTime FILETIME
NameLength UInt32
Name UnicodeString
FriendlyNameLength UInt32
FriendlyName UnicodeString
VersionLength UInt32
Version UnicodeString
ThreadTime UInt32
BlockedTime UInt32
PercentTime Double
PathLength UInt32
Path UnicodeString
ProductNameLength UInt32
ProductName UnicodeString
CompanyNameLength UInt32
CompanyName UnicodeString

Event ID 403 — This driver is using up too many resources and is impacting the performance of Windows.

Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Operational
Task
SystemPerformanceMonitoring
Opcode
ShellDegradation

Description

This driver is using up too many resources and is impacting the performance of Windows.

Message #

This driver is using up too many resources and is impacting the performance of Windows: 

     File Name		: %3

     Friendly Name		: %5

     Version		: %7

     Thread time		: %8ms

     Blocked Time		: %9ms

     Incident Time (UTC)	: %1

Fields #

NameDescription
StartTime FILETIME
NameLength UInt32
Name UnicodeString
FriendlyNameLength UInt32
FriendlyName UnicodeString
VersionLength UInt32
Version UnicodeString
ThreadTime UInt32
BlockedTime UInt32
PercentTime Double
PathLength UInt32
Path UnicodeString
ProductNameLength UInt32
ProductName UnicodeString
CompanyNameLength UInt32
CompanyName UnicodeString

Event ID 404 — This driver is waiting longer than expected on a device.

Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Operational
Task
SystemPerformanceMonitoring
Opcode
ShellDegradation

Description

This driver is waiting longer than expected on a device.

Message #

This driver is waiting longer than expected on a device: 

     File Name		: %3

     Friendly Name		: %5

     Version		: %7

     Thread time		: %8ms

     Blocked Time		: %9ms

     Incident Time (UTC)	: %1

Fields #

NameDescription
StartTime FILETIME
NameLength UInt32
Name UnicodeString
FriendlyNameLength UInt32
FriendlyName UnicodeString
VersionLength UInt32
Version UnicodeString
ThreadTime UInt32
BlockedTime UInt32
PercentTime Double
PathLength UInt32
Path UnicodeString
ProductNameLength UInt32
ProductName UnicodeString
CompanyNameLength UInt32
CompanyName UnicodeString

Event ID 405 — This file is fragmented and is impacting the performance of Windows.

Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Operational
Task
SystemPerformanceMonitoring
Opcode
ShellDegradation

Description

This file is fragmented and is impacting the performance of Windows.

Message #

This file is fragmented and is impacting the performance of Windows: 

     File Name		: %3

     Friendly Name		: %5

     Version		: %7

     Thread time		: %8ms

     Blocked Time		: %9ms

     Incident Time (UTC)	: %1

Fields #

NameDescription
StartTime FILETIME
NameLength UInt32
Name UnicodeString
FriendlyNameLength UInt32
FriendlyName UnicodeString
VersionLength UInt32
Version UnicodeString
ThreadTime UInt32
BlockedTime UInt32
PercentTime Double
PathLength UInt32
Path UnicodeString
ProductNameLength UInt32
ProductName UnicodeString
CompanyNameLength UInt32
CompanyName UnicodeString

Event ID 406 — Disk IO to this file is taking longer than expected.

Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Operational
Task
SystemPerformanceMonitoring
Opcode
ShellDegradation

Description

Disk IO to this file is taking longer than expected.

Message #

Disk IO to this file is taking longer than expected: 

     File Name		: %3

     Friendly Name		: %5

     Version		: %7

     Thread time		: %8ms

     Blocked Time		: %9ms

     Incident Time (UTC)	: %1

Fields #

NameDescription
StartTime FILETIME
NameLength UInt32
Name UnicodeString
FriendlyNameLength UInt32
FriendlyName UnicodeString
VersionLength UInt32
Version UnicodeString
ThreadTime UInt32
BlockedTime UInt32
PercentTime Double
PathLength UInt32
Path UnicodeString
ProductNameLength UInt32
ProductName UnicodeString
CompanyNameLength UInt32
CompanyName UnicodeString

Event ID 407 — This process is using up too much system memory.

Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Operational
Task
SystemPerformanceMonitoring
Opcode
ShellDegradation

Description

This process is using up too much system memory.

Message #

This process is using up too much system memory: 

     File Name		: %3

     Friendly Name		: %5

     Version		: %7

     Workingset size	: %8Kb

     Percent memory	: %11

     Incident Time (UTC)	: %1

Fields #

NameDescription
StartTime FILETIME
NameLength UInt32
Name UnicodeString
FriendlyNameLength UInt32
FriendlyName UnicodeString
VersionLength UInt32
Version UnicodeString
WorkingSetSizeKb UInt32
PeakWorkingSetSizeKb UInt32
ProcessId UInt32
PercentMemory Double
PathLength UInt32
Path UnicodeString
ProductNameLength UInt32
ProductName UnicodeString
CompanyNameLength UInt32
CompanyName UnicodeString

Event ID 408 — Many processes are using too much system memory.

Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Operational
Task
SystemPerformanceMonitoring
Opcode
ShellDegradation

Description

Many processes are using too much system memory.

Message #

Many processes are using too much system memory: 

     Workingset size	: %2Kb

     Percent memory	: %3

     Incident Time (UTC)	: %1

Fields #

NameDescription
StartTime FILETIME
WorkingSetSizeKb UInt32
PercentMemory Double

Event ID 500 — The Desktop Window Manager is experiencing heavy resource contention.

Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Operational
Task
DesktopWindowManagerMonitoring
Opcode
VideoMemoryDegradation

Description

The Desktop Window Manager is experiencing heavy resource contention.

Message #

The Desktop Window Manager is experiencing heavy resource contention. 

     Scenario	: %5

Fields #

NameDescription
DisplayDeviceFriendlyNameLength UInt32
DisplayDeviceFriendlyName UnicodeString
MemoryBandwidth UInt32
MemorySize UInt32
Scenario UInt32

Event ID 501 — The Desktop Window Manager is experiencing heavy resource contention.

Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Operational
Task
DesktopWindowManagerMonitoring
Opcode
VideoMemoryResponsiveness

Description

The Desktop Window Manager is experiencing heavy resource contention.

Message #

The Desktop Window Manager is experiencing heavy resource contention.

     Reason	: %1

     Diagnosis	: %2

Fields #

NameDescription
Reason UInt32
Diagnosis UInt32

Event ID 1001 — Status

Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Diagnostic
Task
Boot_DMConfig
Opcode
Failed

Message #

Status

Fields #

NameDescription
HResult UInt32

Event ID 1002 — Status

Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Diagnostic
Task
Boot_UnexpectedEvent

Message #

Status

Fields #

NameDescription
GUID GUID
EventId UInt16
InternalState UInt32

Event ID 1003 — Status

Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Diagnostic
Task
Boot_ChangedState

Message #

Status

Fields #

NameDescription
NewState UInt32

Event ID 1005 — Status

Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Diagnostic
Task
Boot_CapturedDCL

Message #

Status

Fields #

NameDescription
HResult UInt32

Event ID 1006 — Status

Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Diagnostic
Task
Boot_DetectedMultipleLogons

Message #

Status

Event ID 1007 — Status

Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Diagnostic
Task
Boot_ReceivedEvent

Message #

Status

Fields #

NameDescription
GUID GUID
EventId UInt16
InternalState UInt32

Event ID 1010 — Status

Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Diagnostic
Task
Boot_Troubleshooting
Opcode
Start

Message #

Status

Event ID 1011 — Status

Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Diagnostic
Task
Boot_Troubleshooting
Opcode
Stop

Message #

Status

Fields #

NameDescription
HResult UInt32

Event ID 1012 — Status

Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Diagnostic
Task
Boot_ProcessingSystem
Opcode
Start

Message #

Status

Event ID 1013 — Status

Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Diagnostic
Task
Boot_ProcessingSystem
Opcode
Stop

Message #

Status

Fields #

NameDescription
HResult UInt32

Event ID 1014 — Status

Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Diagnostic
Task
Boot_ProcessingUser
Opcode
Start

Message #

Status

Event ID 1015 — Status

Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Diagnostic
Task
Boot_ProcessingUser
Opcode
Stop

Message #

Status

Fields #

NameDescription
HResult UInt32

Event ID 1020 — Status

Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Diagnostic
Task
Boot_ArchiveCorrupt

Message #

Status

Fields #

NameDescription
HResult UInt32

Event ID 1022 — Status

Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Diagnostic
Task
Boot_CancelledAnalysisViaRegistry

Message #

Status

Event ID 1024 — Status

Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Diagnostic
Task
Boot_RurReadAhead
Opcode
Start

Message #

Status

Event ID 1025 — Status

Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Diagnostic
Task
Boot_RurReadAhead
Opcode
Stop

Message #

Status

Fields #

NameDescription
HResult UInt32

Event ID 1026 — Status

Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Diagnostic
Task
Boot_RurLegacyResource
Opcode
Start

Message #

Status

Event ID 1027 — Status

Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Diagnostic
Task
Boot_RurLegacyResource
Opcode
Stop

Message #

Status

Event ID 1028 — Status

Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Diagnostic
Task
Boot_RurAppResourceUsage
Opcode
Start

Message #

Status

Event ID 1029 — Status

Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Diagnostic
Task
Boot_RurAppResourceUsage
Opcode
Stop

Message #

Status

Fields #

NameDescription
HResult UInt32

Event ID 1030 — Status

Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Diagnostic
Task
Boot_RurPostLogonResourceUsage
Opcode
Start

Message #

Status

Event ID 1031 — Status

Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Diagnostic
Task
Boot_RurPostLogonResourceUsage
Opcode
Stop

Message #

Status

Fields #

NameDescription
HResult UInt32

Event ID 2001 — Status

Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Diagnostic
Task
Shell_DegradationDetected
Opcode
StepUp

Message #

Status

Event ID 2002 — Status

Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Diagnostic
Task
Shell_DegradationDetected
Opcode
StepDown

Message #

Status

Event ID 2003 — Status

Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Diagnostic
Task
Shell_DegradationDetected
Opcode
GradualUp

Message #

Status

Event ID 2004 — Status

Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Diagnostic
Task
Shell_DegradationDetected
Opcode
GradualDown

Message #

Status

Event ID 2005 — Status

Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Diagnostic
Task
Scenario_CapturedCKCL

Message #

Status

Fields #

NameDescription
HResult UInt32
SnapshotPath UnicodeString

Event ID 2006 — Status

Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Diagnostic
Task
Scenario_CapturedDCL

Message #

Status

Fields #

NameDescription
HResult UInt32
SnapshotPath UnicodeString

Event ID 2007 — Status

Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Diagnostic
Task
Scenario_SimpleEvent
Opcode
Start

Message #

Status

Fields #

NameDescription
ProviderId GUID
EventId UInt16
HResult UInt32

Event ID 2008 — Status

Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Diagnostic
Task
Scenario_SimpleEvent
Opcode
Stop

Message #

Status

Fields #

NameDescription
ProviderId GUID
EventId UInt16
HResult UInt32

Event ID 2009 — Status

Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Diagnostic
Task
Scenario_StartEvent
Opcode
Start

Message #

Status

Fields #

NameDescription
ProviderId GUID
EventId UInt16
HResult UInt32

Event ID 2010 — Status

Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Diagnostic
Task
Scenario_StartEvent
Opcode
Stop

Message #

Status

Fields #

NameDescription
ProviderId GUID
EventId UInt16
HResult UInt32

Event ID 2011 — Status

Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Diagnostic
Task
Scenario_StopEvent
Opcode
Start

Message #

Status

Fields #

NameDescription
ProviderId GUID
EventId UInt16
HResult UInt32

Event ID 2012 — Status

Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Diagnostic
Task
Scenario_StopEvent
Opcode
Stop

Message #

Status

Fields #

NameDescription
ProviderId GUID
EventId UInt16
HResult UInt32

Event ID 2013 — Status

Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Diagnostic
Task
Scenario_ProblemDetection
Opcode
Start

Message #

Status

Fields #

NameDescription
ScenarioGUID GUID
HResult UInt32

Event ID 2014 — Status

Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Diagnostic
Task
Scenario_ProblemDetection
Opcode
Stop

Message #

Status

Fields #

NameDescription
ScenarioGUID GUID
HResult UInt32

Event ID 2015 — Status

Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Diagnostic
Task
Scenario_TroubleShoot
Opcode
Start

Message #

Status

Fields #

NameDescription
ScenarioGUID GUID
HResult UInt32

Event ID 2016 — Status

Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Diagnostic
Task
Scenario_TroubleShoot
Opcode
Stop

Message #

Status

Fields #

NameDescription
ScenarioGUID GUID
HResult UInt32

Event ID 7001 — Status

Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Loopback
Task
Boot_Loopback_SnapshotKMScenario

Message #

Status

Event ID 7101 — Status

Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Loopback
Task
BootApps_ResolverLoopback

Message #

Status

Event ID 7102 — Status

Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Loopback
Task
BootDrivers_ResolverLoopback

Message #

Status

Event ID 7103 — Status

Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Loopback
Task
ShutdownApps_ResolverLoopback

Message #

Status

Event ID 7104 — Status

Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Loopback
Task
SuspendApps_ResolverLoopback

Message #

Status

Event ID 7105 — Status

Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Loopback
Task
SuspendDrivers_ResolverLoopback

Message #

Status

Event ID 7106 — Status

Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Loopback
Task
ResumeDrivers_ResolverLoopback

Message #

Status

Event ID 8001 — Status

Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Diagnostic
Task
Shutdown_ArchiveCorrupt

Message #

Status

Fields #

NameDescription
HResult UInt32

Event ID 8002 — Status

Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Diagnostic
Task
Shutdown_ThreadCreateFailed
Opcode
Failed

Message #

Status

Fields #

NameDescription
HResult UInt32

Event ID 8003 — Status

Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Diagnostic
Task
Shutdown_Troubleshooting
Opcode
Start

Message #

Status

Event ID 8004 — Status

Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Diagnostic
Task
Shutdown_Troubleshooting
Opcode
Stop

Message #

Status

Fields #

NameDescription
HResult UInt32

Event ID 8005 — Status

Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Diagnostic
Task
Shutdown_WaitingForBoot

Message #

Status

Event ID 8006 — Status

Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Diagnostic
Task
Shutdown_LocatedCKCL

Message #

Status

Fields #

NameDescription
Path UnicodeString

Event ID 8007 — Status

Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Diagnostic
Task
Shutdown_LocatedPossibleDCL

Message #

Status

Fields #

NameDescription
Path UnicodeString

Event ID 8008 — Status

Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Diagnostic
Task
Shutdown_RestoringConfig

Message #

Status

Event ID 8009 — Status

Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Diagnostic
Task
Shutdown_LoadConfig
Opcode
Failed

Message #

Status

Fields #

NameDescription
HResult UInt32

Event ID 8010 — Status

Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Diagnostic
Task
Shutdown_ProxyCallback

Message #

Status

Event ID 8011 — Status

Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Diagnostic
Task
Shutdown_StartCKCL
Opcode
Start

Message #

Status

Event ID 8012 — Status

Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Diagnostic
Task
Shutdown_StartCKCL
Opcode
Stop

Message #

Status

Fields #

NameDescription
HResult UInt32

Event ID 8013 — Status

Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Diagnostic
Task
Shutdown_CancelledAnalysisViaRegistry

Message #

Status

Event ID 9001 — Status

Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Diagnostic
Task
SecondaryLogon_DMConfig
Opcode
Failed

Message #

Status

Fields #

NameDescription
HResult UInt32

Event ID 9003 — Status

Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Diagnostic
Task
SecondaryLogon_UnexpectedEvent

Message #

Status

Fields #

NameDescription
GUID GUID
EventId UInt16
InternalState UInt32

Event ID 9005 — Status

Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Diagnostic
Task
SecondaryLogon_ChangedState

Message #

Status

Fields #

NameDescription
NewState UInt32

Event ID 9007 — Status

Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Diagnostic
Task
SecondaryLogon_DetectedMultipleLogons

Message #

Status

Event ID 9009 — Status

Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Diagnostic
Task
SecondaryLogon_ReceivedEvent

Message #

Status

Fields #

NameDescription
GUID GUID
EventId UInt16
InternalState UInt32

Event ID 9011 — Status

Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Diagnostic
Task
SecondaryLogon_Troubleshooting
Opcode
Start

Message #

Status

Event ID 9012 — Status

Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Diagnostic
Task
SecondaryLogon_Troubleshooting
Opcode
Stop

Message #

Status

Fields #

NameDescription
HResult UInt32

Event ID 9013 — Status

Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Diagnostic
Task
SecondaryLogon_CancelledAnalysisViaRegistry

Message #

Status

Event ID 9015 — Status

Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Diagnostic
Task
SecondaryLogon_CapturedDCL

Message #

Status

Fields #

NameDescription
HResult UInt32

Event ID 10001 — Status

Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Loopback
Task
SecondaryLogonScenario_Stop

Message #

Status

Event ID 11001 —

Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Diagnostic
Task
Standby_ReceivedEvent

Fields #

NameDescription
GUID GUID
EventId UInt16
InternalState UInt32

Event ID 11002 —

Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Diagnostic
Task
Standby_ChangedState

Fields #

NameDescription
NewState UInt32

Event ID 11003 —

Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Diagnostic
Task
Standby_FailedTransition

Event ID 11005 —

Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Diagnostic
Task
Standby_DetectRegressions
Opcode
Start

Event ID 11006 —

Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Diagnostic
Task
Standby_DetectRegressions
Opcode
Stop

Fields #

NameDescription
HResult UInt32