Microsoft-Windows-Kernel-EventTracing

44 events across 3 channels

Event IDTitleChannel
0Session ".Admin
1The backing-file for the real-time session ".Admin
2Session ".Admin
3Session ".Admin
4The maximum file size for session ".Admin
5An error was encountered while tracing session ".Admin
8Provider %1 was registered with Event Tracing for Windows.Analytic
9Provider %1 was unregistered from Event Tracing for Windows.Analytic
10Session ".Analytic
11Session ".Analytic
12The configuration of session ".Analytic
13The events from session ".Analytic
14Provider %1 has been enabled to session "%2".Analytic
15Provider %1 is no longer enabled to session "%2".Analytic
17The security descriptor for session ".Analytic
18Stack correlation event.Operational
19Operational
20Operational
21Operational
22Operational
23Error saving soft restart persisted log ".Admin
24Operational
25Operational
26Operational
27Operational
28Error setting traits on Provider %1.Admin
29A registration for Provider %1 has joined Provider Group %2.Analytic
30Provider %1 from process %3 does not have permission to write events to session …Analytic
31Operational
32Failed to read debug info for WPP provider %1 from process %3 for session "%2".Admin
33Operational
34Operational
35Analytic
40The enable state for Provider %1 is about to change on session "%2".Analytic
41Provider %1 is about to be disabled from session "%2".Analytic
42Capture state requested for provider %1 on session "%2".Analytic
43Session ".Analytic
44Session ".Analytic
45Session ".Analytic
46Session ".Analytic
47Session ".Analytic
48Session ".Analytic
49Session ".Analytic
50Group Mask could not be updated for Session ".Analytic

Event ID 0 — Session ".

Provider
Microsoft-Windows-Kernel-EventTracing
Channel
Admin

Message

Session "%1" failed to write to log file "%2" with the following error: %3

Fields

NameDescription
SessionName
FileName
ErrorCode
LoggingMode

Event ID 1 — The backing-file for the real-time session ".

Provider
Microsoft-Windows-Kernel-EventTracing
Channel
Admin
Level
3
Samples
1

Message

The backing-file for the real-time session "%1" has reached its maximum size. As a result, new events will not be logged to this session until space becomes available. This error is often caused by starting a trace session in real-time mode without having any real-time consumers.

Fields

NameDescription
SessionName
ErrorCode
LoggingMode

Example Event

system:
  provider: Microsoft-Windows-Kernel-EventTracing
  guid: B675EC37-BDB6-4648-BC92-F3FDC74D3CA2
  event_source_name: ''
  event_id: 1
  version: 0
  level: 3
  task: 1
  opcode: 10
  keywords: 9223372036854775824
  time_created: '2023-11-06T00:46:15.355055+00:00'
  event_record_id: 16
  correlation: {}
  execution:
    process_id: 4
    thread_id: 5348
  channel: Microsoft-Windows-Kernel-EventTracing/Admin
  computer: WinDev2310Eval
  security:
    user_id: S-1-5-18
event_data:
  SessionName: EventLog-Microsoft-Windows-Sysmon-Operational
  ErrorCode: 3221225864
  LoggingMode: 427819392
message: ''

References

Event ID 2 — Session ".

Provider
Microsoft-Windows-Kernel-EventTracing
Channel
Admin
Level
2
Samples
1

Message

Session "%1" failed to start with the following error: %3

Fields

NameDescription
SessionName
FileName
ErrorCode1" failed to start with the following error.
LoggingMode

Example Event

system:
  provider: Microsoft-Windows-Kernel-EventTracing
  guid: B675EC37-BDB6-4648-BC92-F3FDC74D3CA2
  event_source_name: ''
  event_id: 2
  version: 0
  level: 2
  task: 2
  opcode: 12
  keywords: 9223372036854775824
  time_created: '2023-11-06T06:23:40.046454+00:00'
  event_record_id: 4
  correlation: {}
  execution:
    process_id: 4
    thread_id: 236
  channel: Microsoft-Windows-Kernel-EventTracing/Admin
  computer: WinDev2310Eval
  security:
    user_id: S-1-5-18
event_data:
  SessionName: PerfDiag Logger
  FileName: ''
  ErrorCode: 3221225525
  LoggingMode: 8388736
message: ''

References

Event ID 3 — Session ".

Provider
Microsoft-Windows-Kernel-EventTracing
Channel
Admin

Message

Session "%1" stopped due to the following error: %3

Fields

NameDescription
SessionName
FileName
ErrorCode
LoggingMode
FailureReason

Event ID 4 — The maximum file size for session ".

Provider
Microsoft-Windows-Kernel-EventTracing
Channel
Admin

Message

The maximum file size for session "%1" has been reached. As a result, events might be lost (not logged) to file "%2". The maximum files size is currently set to %5 bytes.

Fields

NameDescription
SessionName
FileName
ErrorCode
LoggingMode
MaxFileSize

Event ID 5 — An error was encountered while tracing session ".

Provider
Microsoft-Windows-Kernel-EventTracing
Channel
Admin

Message

An error was encountered while tracing session "%2" was switching to the "%1" event log file. Error: %3

Fields

NameDescription
SessionName
FileName
ErrorCode
LoggingMode

Event ID 8 — Provider %1 was registered with Event Tracing for Windows.

Provider
Microsoft-Windows-Kernel-EventTracing
Channel
Analytic

Message

Provider %1 was registered with Event Tracing for Windows.

Fields

NameDescription
ProviderName

Event ID 9 — Provider %1 was unregistered from Event Tracing for Windows.

Provider
Microsoft-Windows-Kernel-EventTracing
Channel
Analytic

Message

Provider %1 was unregistered from Event Tracing for Windows.

Fields

NameDescription
ProviderName

Event ID 10 — Session ".

Provider
Microsoft-Windows-Kernel-EventTracing
Channel
Analytic

Message

Session "%3" was started.

Fields

NameDescription
SessionGuid
LoggerMode
SessionName
LogFileName
MinimumBuffers
MaximumBuffers
BufferSize
PeakBuffersCount
CurrentBuffersCount
FlushThreshold

Event ID 11 — Session ".

Provider
Microsoft-Windows-Kernel-EventTracing
Channel
Analytic

Message

Session "%3" was stopped.

Fields

NameDescription
SessionGuid
LoggerMode
SessionName
LogFileName
MinimumBuffers
MaximumBuffers
BufferSize
PeakBuffersCount
CurrentBuffersCount
FlushThreshold
EventsLost
BuffersLost
RealTimeBuffersLost
LoggerId

Event ID 12 — The configuration of session ".

Provider
Microsoft-Windows-Kernel-EventTracing
Channel
Analytic

Message

The configuration of session "%3" has been modified.

Fields

NameDescription
SessionGuid
LoggerMode
SessionName
LogFileName

Event ID 13 — The events from session ".

Provider
Microsoft-Windows-Kernel-EventTracing
Channel
Analytic

Message

The events from session "%3" have been flushed.

Fields

NameDescription
SessionGuid
LoggerMode
SessionName
LogFileName

Event ID 14 — Provider %1 has been enabled to session "%2".

Provider
Microsoft-Windows-Kernel-EventTracing
Channel
Analytic

Message

Provider %1 has been enabled to session "%2".

Fields

NameDescription
ProviderName
SessionName
MatchAnyKeyword
MatchAllKeyword
EnableProperty
Level

Event ID 15 — Provider %1 is no longer enabled to session "%2".

Provider
Microsoft-Windows-Kernel-EventTracing
Channel
Analytic

Message

Provider %1 is no longer enabled to session "%2".

Fields

NameDescription
ProviderName
SessionName

Event ID 17 — The security descriptor for session ".

Provider
Microsoft-Windows-Kernel-EventTracing
Channel
Analytic

Message

The security descriptor for session "%3" has been updated.

Fields

NameDescription
SessionGuid
LoggerMode
SessionName
LogFileName

Event ID 18 — Stack correlation event.

Provider
Microsoft-Windows-Kernel-EventTracing
Channel
Operational

Message

Stack correlation event. This event contains a call stack which is associated with a prior event which is correlated by the MatchId.

Event ID 19 —

Provider
Microsoft-Windows-Kernel-EventTracing
Channel
Operational

Fields

NameDescription
ProviderId
StatusCode
EventId
SessionName

Event ID 20 —

Provider
Microsoft-Windows-Kernel-EventTracing
Channel
Operational

Fields

NameDescription
SessionGuid
LoggerMode
SessionName
LogFileName
MinimumBuffers
MaximumBuffers
BufferSize
PeakBuffersCount
CurrentBuffersCount
FlushThreshold
EventsLost
BuffersLost
RealTimeBuffersLost
LoggerId

Event ID 21 —

Provider
Microsoft-Windows-Kernel-EventTracing
Channel
Operational

Event ID 22 —

Provider
Microsoft-Windows-Kernel-EventTracing
Channel
Operational

Fields

NameDescription
FileName
BufferSize
BuffersPersisted
BuffersWritten
Status
BuffersLost

Event ID 23 — Error saving soft restart persisted log ".

Provider
Microsoft-Windows-Kernel-EventTracing
Channel
Admin

Message

Error saving soft restart persisted log "%1" Error: %5

Fields

NameDescription
FileName
BufferSize
BuffersPersisted
BuffersWritten
Status
BuffersLost

Event ID 24 —

Provider
Microsoft-Windows-Kernel-EventTracing
Channel
Operational

Fields

NameDescription
GUID
FilterFlags
LastEnableLoggerId

Event ID 25 —

Provider
Microsoft-Windows-Kernel-EventTracing
Channel
Operational

Fields

NameDescription
GUID
FilterFlags
LastEnableLoggerId

Event ID 26 —

Provider
Microsoft-Windows-Kernel-EventTracing
Channel
Operational

Fields

NameDescription
GUID
Index
LoggerId
MatchAnyKeyword
MatchAllKeyword
Level
EnableProperty

Event ID 27 —

Provider
Microsoft-Windows-Kernel-EventTracing
Channel
Operational

Fields

NameDescription
ProviderGUID
GroupGUID
Flags
EnableMask
GroupEnableMask
ProcessId

Event ID 28 — Error setting traits on Provider %1.

Provider
Microsoft-Windows-Kernel-EventTracing
Channel
Admin

Message

Error setting traits on Provider %1. Error: %2

Fields

NameDescription
ProviderGuid
ErrorCode

Event ID 29 — A registration for Provider %1 has joined Provider Group %2.

Provider
Microsoft-Windows-Kernel-EventTracing
Channel
Analytic

Message

A registration for Provider %1 has joined Provider Group %2

Fields

NameDescription
ProviderGuid
ProviderGroupGuid

Event ID 30 — Provider %1 from process %3 does not have permission to write events to session "%2".

Provider
Microsoft-Windows-Kernel-EventTracing
Channel
Analytic

Message

Provider %1 from process %3 does not have permission to write events to session "%2". Error: %4

Fields

NameDescription
ProviderGuid
SessionName
ProcessId
Status

Event ID 31 —

Provider
Microsoft-Windows-Kernel-EventTracing
Channel
Operational

Fields

NameDescription
ProviderId
StatusCode
EventName
SessionName

Event ID 32 — Failed to read debug info for WPP provider %1 from process %3 for session "%2".

Provider
Microsoft-Windows-Kernel-EventTracing
Channel
Admin

Message

Failed to read debug info for WPP provider %1 from process %3 for session "%2". Error: %4. The image registering the provider may be malformed or may be an unsupported format (e.g. managed C++). ETW traces for this session will not include the image's debug information.

Fields

NameDescription
ProviderGuid
SessionName
ProcessId
Status

Event ID 33 —

Provider
Microsoft-Windows-Kernel-EventTracing
Channel
Operational

Fields

NameDescription
MessageGuid
MessageNumber
StatusCode
SessionName

Event ID 34 —

Provider
Microsoft-Windows-Kernel-EventTracing
Channel
Operational

Fields

NameDescription
HookId
StatusCode
SessionName

Event ID 35 —

Provider
Microsoft-Windows-Kernel-EventTracing
Channel
Analytic

Fields

NameDescription
LoggerSlotsUsed

Event ID 40 — The enable state for Provider %1 is about to change on session "%2".

Provider
Microsoft-Windows-Kernel-EventTracing
Channel
Analytic

Message

The enable state for Provider %1 is about to change on session "%2".

Fields

NameDescription
ProviderName
SessionName
MatchAnyKeyword
MatchAllKeyword
EnableProperty
Level

Event ID 41 — Provider %1 is about to be disabled from session "%2".

Provider
Microsoft-Windows-Kernel-EventTracing
Channel
Analytic

Message

Provider %1 is about to be disabled from session "%2".

Fields

NameDescription
ProviderName
SessionName

Event ID 42 — Capture state requested for provider %1 on session "%2".

Provider
Microsoft-Windows-Kernel-EventTracing
Channel
Analytic

Message

Capture state requested for provider %1 on session "%2".

Fields

NameDescription
GUID
LoggerId
MatchAnyKeyword
MatchAllKeyword
Level
EnableProperty

Event ID 43 — Session ".

Provider
Microsoft-Windows-Kernel-EventTracing
Channel
Analytic

Message

Session "%3" could not be started because LOGGER_FLAG_LARGE_MDL_PAGES is not supported.

Fields

NameDescription
SessionGuid
LoggerMode
SessionName
LogFileName

Event ID 44 — Session ".

Provider
Microsoft-Windows-Kernel-EventTracing
Channel
Analytic

Message

Session "%1" could not be started because because the maximum %2 logging sessions are already active on the system.

Fields

NameDescription
SessionName
MaximumAllowed

Event ID 45 — Session ".

Provider
Microsoft-Windows-Kernel-EventTracing
Channel
Analytic

Message

Session "%1" could not be started because because the maximum %2 EVENT_TRACE_SYSTEM_LOGGER_MODE logging sessions are already active on the system.

Fields

NameDescription
SessionName
MaximumAllowed

Event ID 46 — Session ".

Provider
Microsoft-Windows-Kernel-EventTracing
Channel
Analytic

Message

Session "%1" could not be started because the process failed its access check to the SessionGuid.

Fields

NameDescription
SessionName
SessionGuid
DesiredAccess

Event ID 47 — Session ".

Provider
Microsoft-Windows-Kernel-EventTracing
Channel
Analytic

Message

Session "%1" could not be started because the Memory Partition Handle %2 is invalid.

Fields

NameDescription
SessionName
MemoryPartitionHandle

Event ID 48 — Session ".

Provider
Microsoft-Windows-Kernel-EventTracing
Channel
Analytic

Message

Session "%1" failed to create file %2 with error %3.

Fields

NameDescription
SessionName
FileName
ErrorCode
LoggingMode

Event ID 49 — Session ".

Provider
Microsoft-Windows-Kernel-EventTracing
Channel
Analytic

Message

Session "%1" could not be started because the process lacks the profiling privilege.

Fields

NameDescription
SessionName
FileName
ErrorCode
LoggingMode

Event ID 50 — Group Mask could not be updated for Session ".

Provider
Microsoft-Windows-Kernel-EventTracing
Channel
Analytic

Message

Group Mask could not be updated for Session "%1", because the requested Group Mask is not supported.

Fields

NameDescription
SessionName
RequestedGroupMask
PermittedGroupMask