Microsoft-Windows-EtwCollector
3 events across 1 channel
| Event ID | Title | Channel |
|---|---|---|
| 1 | Profiling for target ({ProcessID}) has started. | Operational |
| 2 | Profiling for target ({ProcessID}) has stopped. | Operational |
| 5 | Machine [Name: {Name}] [OS Description: {OSDescription}] [Architecture: … | Operational |
Event ID 1 — Profiling for target ({ProcessID}) has started.
Message
Fields
| Name | Description |
|---|---|
ProcessID | — |
Event ID 2 — Profiling for target ({ProcessID}) has stopped.
Message
Fields
| Name | Description |
|---|---|
ProcessID | — |
Event ID 5 — Machine [Name: {Name}] [OS Description: {OSDescription}] [Architecture: {Architecture}].
Message
Fields
| Name | Description |
|---|---|
Name | — |
OSDescription | — |
Architecture | — |