Microsoft-Windows-Kernel-EventTracing
44 events across 3 channels
Event ID 0 — Session ".
Message
Fields
| Name | Description |
|---|---|
SessionName | — |
FileName | — |
ErrorCode | — |
LoggingMode | — |
Event ID 1 — The backing-file for the real-time session ".
Message
Fields
| Name | Description |
|---|---|
SessionName | — |
ErrorCode | — |
LoggingMode | — |
Example Event
system:
provider: Microsoft-Windows-Kernel-EventTracing
guid: B675EC37-BDB6-4648-BC92-F3FDC74D3CA2
event_source_name: ''
event_id: 1
version: 0
level: 3
task: 1
opcode: 10
keywords: 9223372036854775824
time_created: '2023-11-06T00:46:15.355055+00:00'
event_record_id: 16
correlation: {}
execution:
process_id: 4
thread_id: 5348
channel: Microsoft-Windows-Kernel-EventTracing/Admin
computer: WinDev2310Eval
security:
user_id: S-1-5-18
event_data:
SessionName: EventLog-Microsoft-Windows-Sysmon-Operational
ErrorCode: 3221225864
LoggingMode: 427819392
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 2 — Session ".
Message
Fields
| Name | Description |
|---|---|
SessionName | — |
FileName | — |
ErrorCode | 1" failed to start with the following error. |
LoggingMode | — |
Example Event
system:
provider: Microsoft-Windows-Kernel-EventTracing
guid: B675EC37-BDB6-4648-BC92-F3FDC74D3CA2
event_source_name: ''
event_id: 2
version: 0
level: 2
task: 2
opcode: 12
keywords: 9223372036854775824
time_created: '2023-11-06T06:23:40.046454+00:00'
event_record_id: 4
correlation: {}
execution:
process_id: 4
thread_id: 236
channel: Microsoft-Windows-Kernel-EventTracing/Admin
computer: WinDev2310Eval
security:
user_id: S-1-5-18
event_data:
SessionName: PerfDiag Logger
FileName: ''
ErrorCode: 3221225525
LoggingMode: 8388736
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 3 — Session ".
Message
Fields
| Name | Description |
|---|---|
SessionName | — |
FileName | — |
ErrorCode | — |
LoggingMode | — |
FailureReason | — |
Event ID 4 — The maximum file size for session ".
Message
Fields
| Name | Description |
|---|---|
SessionName | — |
FileName | — |
ErrorCode | — |
LoggingMode | — |
MaxFileSize | — |
Event ID 5 — An error was encountered while tracing session ".
Message
Fields
| Name | Description |
|---|---|
SessionName | — |
FileName | — |
ErrorCode | — |
LoggingMode | — |
Event ID 8 — Provider %1 was registered with Event Tracing for Windows.
Message
Fields
| Name | Description |
|---|---|
ProviderName | — |
Event ID 9 — Provider %1 was unregistered from Event Tracing for Windows.
Message
Fields
| Name | Description |
|---|---|
ProviderName | — |
Event ID 10 — Session ".
Message
Fields
| Name | Description |
|---|---|
SessionGuid | — |
LoggerMode | — |
SessionName | — |
LogFileName | — |
MinimumBuffers | — |
MaximumBuffers | — |
BufferSize | — |
PeakBuffersCount | — |
CurrentBuffersCount | — |
FlushThreshold | — |
Event ID 11 — Session ".
Message
Fields
| Name | Description |
|---|---|
SessionGuid | — |
LoggerMode | — |
SessionName | — |
LogFileName | — |
MinimumBuffers | — |
MaximumBuffers | — |
BufferSize | — |
PeakBuffersCount | — |
CurrentBuffersCount | — |
FlushThreshold | — |
EventsLost | — |
BuffersLost | — |
RealTimeBuffersLost | — |
LoggerId | — |
Event ID 12 — The configuration of session ".
Message
Fields
| Name | Description |
|---|---|
SessionGuid | — |
LoggerMode | — |
SessionName | — |
LogFileName | — |
Event ID 13 — The events from session ".
Message
Fields
| Name | Description |
|---|---|
SessionGuid | — |
LoggerMode | — |
SessionName | — |
LogFileName | — |
Event ID 14 — Provider %1 has been enabled to session "%2".
Message
Fields
| Name | Description |
|---|---|
ProviderName | — |
SessionName | — |
MatchAnyKeyword | — |
MatchAllKeyword | — |
EnableProperty | — |
Level | — |
Event ID 15 — Provider %1 is no longer enabled to session "%2".
Message
Fields
| Name | Description |
|---|---|
ProviderName | — |
SessionName | — |
Event ID 17 — The security descriptor for session ".
Message
Fields
| Name | Description |
|---|---|
SessionGuid | — |
LoggerMode | — |
SessionName | — |
LogFileName | — |
Event ID 18 — Stack correlation event.
Message
Event ID 19 —
Fields
| Name | Description |
|---|---|
ProviderId | — |
StatusCode | — |
EventId | — |
SessionName | — |
Event ID 20 —
Fields
| Name | Description |
|---|---|
SessionGuid | — |
LoggerMode | — |
SessionName | — |
LogFileName | — |
MinimumBuffers | — |
MaximumBuffers | — |
BufferSize | — |
PeakBuffersCount | — |
CurrentBuffersCount | — |
FlushThreshold | — |
EventsLost | — |
BuffersLost | — |
RealTimeBuffersLost | — |
LoggerId | — |
Event ID 21 —
Event ID 22 —
Fields
| Name | Description |
|---|---|
FileName | — |
BufferSize | — |
BuffersPersisted | — |
BuffersWritten | — |
Status | — |
BuffersLost | — |
Event ID 23 — Error saving soft restart persisted log ".
Message
Fields
| Name | Description |
|---|---|
FileName | — |
BufferSize | — |
BuffersPersisted | — |
BuffersWritten | — |
Status | — |
BuffersLost | — |
Event ID 24 —
Fields
| Name | Description |
|---|---|
GUID | — |
FilterFlags | — |
LastEnableLoggerId | — |
Event ID 25 —
Fields
| Name | Description |
|---|---|
GUID | — |
FilterFlags | — |
LastEnableLoggerId | — |
Event ID 26 —
Fields
| Name | Description |
|---|---|
GUID | — |
Index | — |
LoggerId | — |
MatchAnyKeyword | — |
MatchAllKeyword | — |
Level | — |
EnableProperty | — |
Event ID 27 —
Fields
| Name | Description |
|---|---|
ProviderGUID | — |
GroupGUID | — |
Flags | — |
EnableMask | — |
GroupEnableMask | — |
ProcessId | — |
Event ID 28 — Error setting traits on Provider %1.
Message
Fields
| Name | Description |
|---|---|
ProviderGuid | — |
ErrorCode | — |
Event ID 29 — A registration for Provider %1 has joined Provider Group %2.
Message
Fields
| Name | Description |
|---|---|
ProviderGuid | — |
ProviderGroupGuid | — |
Event ID 30 — Provider %1 from process %3 does not have permission to write events to session "%2".
Message
Fields
| Name | Description |
|---|---|
ProviderGuid | — |
SessionName | — |
ProcessId | — |
Status | — |
Event ID 31 —
Fields
| Name | Description |
|---|---|
ProviderId | — |
StatusCode | — |
EventName | — |
SessionName | — |
Event ID 32 — Failed to read debug info for WPP provider %1 from process %3 for session "%2".
Message
Fields
| Name | Description |
|---|---|
ProviderGuid | — |
SessionName | — |
ProcessId | — |
Status | — |
Event ID 33 —
Fields
| Name | Description |
|---|---|
MessageGuid | — |
MessageNumber | — |
StatusCode | — |
SessionName | — |
Event ID 34 —
Fields
| Name | Description |
|---|---|
HookId | — |
StatusCode | — |
SessionName | — |
Event ID 35 —
Fields
| Name | Description |
|---|---|
LoggerSlotsUsed | — |
Event ID 40 — The enable state for Provider %1 is about to change on session "%2".
Message
Fields
| Name | Description |
|---|---|
ProviderName | — |
SessionName | — |
MatchAnyKeyword | — |
MatchAllKeyword | — |
EnableProperty | — |
Level | — |
Event ID 41 — Provider %1 is about to be disabled from session "%2".
Message
Fields
| Name | Description |
|---|---|
ProviderName | — |
SessionName | — |
Event ID 42 — Capture state requested for provider %1 on session "%2".
Message
Fields
| Name | Description |
|---|---|
GUID | — |
LoggerId | — |
MatchAnyKeyword | — |
MatchAllKeyword | — |
Level | — |
EnableProperty | — |
Event ID 43 — Session ".
Message
Fields
| Name | Description |
|---|---|
SessionGuid | — |
LoggerMode | — |
SessionName | — |
LogFileName | — |
Event ID 44 — Session ".
Message
Fields
| Name | Description |
|---|---|
SessionName | — |
MaximumAllowed | — |
Event ID 45 — Session ".
Message
Fields
| Name | Description |
|---|---|
SessionName | — |
MaximumAllowed | — |
Event ID 46 — Session ".
Message
Fields
| Name | Description |
|---|---|
SessionName | — |
SessionGuid | — |
DesiredAccess | — |
Event ID 47 — Session ".
Message
Fields
| Name | Description |
|---|---|
SessionName | — |
MemoryPartitionHandle | — |
Event ID 48 — Session ".
Message
Fields
| Name | Description |
|---|---|
SessionName | — |
FileName | — |
ErrorCode | — |
LoggingMode | — |
Event ID 49 — Session ".
Message
Fields
| Name | Description |
|---|---|
SessionName | — |
FileName | — |
ErrorCode | — |
LoggingMode | — |
Event ID 50 — Group Mask could not be updated for Session ".
Message
Fields
| Name | Description |
|---|---|
SessionName | — |
RequestedGroupMask | — |
PermittedGroupMask | — |