Microsoft-Windows-Kernel-Memory

14 events across 1 channel

Event IDTitleChannel
1Analytic
2Analytic
3Analytic
4Analytic
5Analytic
6Analytic
7Analytic
8Analytic
9Analytic
10Analytic
11Analytic
12Analytic
13Analytic
14Analytic

Event ID 1 —

Provider
Microsoft-Windows-Kernel-Memory
Channel
Analytic
Task
MemInfo

Fields #

NameDescription
PriorityLevels UInt8
ZeroPageCount Pointer
FreePageCount Pointer
ModifiedPageCount Pointer
ModifiedNoWritePageCount Pointer
BadPageCount Pointer
StandbyPageCounts Pointer
RepurposedPageCounts Pointer
ModifiedPageCountPageFile Pointer
PagedPoolPageCount Pointer
NonPagedPoolPageCount Pointer
MdlPageCount Pointer
CommitPageCount Pointer

Event ID 2 —

Provider
Microsoft-Windows-Kernel-Memory
Channel
Analytic
Task
MemInfoWS

Fields #

NameDescription
Count UInt32
WSCommitInfo AnsiString

Event ID 3 —

Provider
Microsoft-Windows-Kernel-Memory
Channel
Analytic
Task
MemInfoSessionWS

Fields #

NameDescription
Count UInt32
SessionWSCommitInfo AnsiString

Event ID 4 —

Provider
Microsoft-Windows-Kernel-Memory
Channel
Analytic
Task
WorkingSetOutSwap
Opcode
Start

Fields #

NameDescription
ProcessId UInt32
Flags HexInt32

Event ID 5 —

Provider
Microsoft-Windows-Kernel-Memory
Channel
Analytic
Task
WorkingSetOutSwap
Opcode
Stop

Fields #

NameDescription
ProcessId UInt32
Status HexInt32NTSTATUS reference
PagesProcessed Pointer
WriteCombinePagesProcessed Pointer
UncachedPagesProcessed Pointer
CleanPagesProcessed Pointer

Event ID 6 —

Provider
Microsoft-Windows-Kernel-Memory
Channel
Analytic
Task
WorkingSetInSwap
Opcode
Start

Fields #

NameDescription
ProcessId UInt32
Flags HexInt32

Event ID 7 —

Provider
Microsoft-Windows-Kernel-Memory
Channel
Analytic
Task
WorkingSetInSwap
Opcode
Stop

Fields #

NameDescription
ProcessId UInt32
Status HexInt32NTSTATUS reference

Event ID 8 —

Provider
Microsoft-Windows-Kernel-Memory
Channel
Analytic
Task
Acg

Fields #

NameDescription
AcgFlag UInt32

Event ID 9 —

Provider
Microsoft-Windows-Kernel-Memory
Channel
Analytic
Task
WorkingSetInSwap

Fields #

NameDescription
ProcessId UInt32
Status HexInt32NTSTATUS reference

Event ID 10 —

Provider
Microsoft-Windows-Kernel-Memory
Channel
Analytic
Task
MdlAllocation

Fields #

NameDescription
DurationInMicroseconds UInt64
TotalBytes UInt64
LowAddress UInt64
HighAddress UInt64
SkipBytes UInt64
MemoryDescriptorList Pointer
IdealNode UInt32
Flags UInt32

Event ID 11 —

Provider
Microsoft-Windows-Kernel-Memory
Channel
Analytic
Task
ContAllocation

Fields #

NameDescription
DurationInMicroseconds UInt64
TotalBytes UInt64
LowAddress UInt64
HighAddress UInt64
Boundary UInt64
PhysicalAddress UInt64
MappedAddress Pointer
ProtectionMask UInt32
PreferredNode UInt32
PartitionId UInt32
Tag UInt32
Flags UInt32
AllocatedFromPool Boolean
AllocatedFromExtension Boolean

Event ID 12 —

Provider
Microsoft-Windows-Kernel-Memory
Channel
Analytic
Task
MemInfoNode

Fields #

NameDescription
PartitionId UInt32
Count UInt32
MemoryNodeInfo Int8

Event ID 13 —

Provider
Microsoft-Windows-Kernel-Memory
Channel
Analytic
Task
MemInfoHugeIoSpace

Fields #

NameDescription
PartitionId UInt32
Count UInt32
MemoryNodeInfo Int8

Event ID 14 —

Provider
Microsoft-Windows-Kernel-Memory
Channel
Analytic
Task
ContFree

Fields #

NameDescription
BaseAddress Pointer
Size Pointer