Microsoft-Windows-Kernel-Process
27 events across 2 channels
Event ID 1 — Process %1 started at time %2 by parent %3 running in session %4 with name %5.
Message
Fields
| Name | Description |
|---|---|
ProcessID | — |
ProcessSequenceNumber | — |
CreateTime | — |
ParentProcessID | — |
ParentProcessSequenceNumber | — |
SessionID | — |
Flags | — |
ProcessTokenElevationType | — |
ProcessTokenIsElevated | — |
MandatoryLabel | — |
ImageName | — |
ImageChecksum | — |
TimeDateStamp | — |
PackageFullName | — |
PackageRelativeAppId | — |
SecurityMitigations | — |
Event ID 2 — Process %1 (which started at time %3) stopped at time %4 with exit code %5.
Message
Fields
| Name | Description |
|---|---|
ProcessID | — |
ProcessSequenceNumber | — |
CreateTime | — |
ExitTime | — |
ExitCode | — |
TokenElevationType | — |
HandleCount | — |
CommitCharge | — |
CommitPeak | — |
CPUCycleCount | — |
ReadOperationCount | — |
WriteOperationCount | — |
ReadTransferKiloBytes | — |
WriteTransferKiloBytes | — |
HardFaultCount | — |
ImageName | — |
Event ID 3 — Thread %2 (in Process %1) started.
Message
Fields
| Name | Description |
|---|---|
ProcessID | — |
ThreadID | — |
StackBase | — |
StackLimit | — |
UserStackBase | — |
UserStackLimit | — |
StartAddr | — |
Win32StartAddr | — |
TebBase | — |
SubProcessTag | — |
Event ID 4 — Thread %2 (in Process %1) stopped.
Message
Fields
| Name | Description |
|---|---|
ProcessID | — |
ThreadID | — |
StackBase | — |
StackLimit | — |
UserStackBase | — |
UserStackLimit | — |
StartAddr | — |
Win32StartAddr | — |
TebBase | — |
SubProcessTag | — |
CycleTime | — |
Event ID 5 — Process %3 had an image loaded with name %7.
Message
Fields
| Name | Description |
|---|---|
ImageBase | — |
ImageSize | — |
ProcessID | — |
ImageCheckSum | — |
TimeDateStamp | — |
DefaultBase | — |
ImageName | — |
Event ID 6 — Process %3 had an image unloaded with name %7.
Message
Fields
| Name | Description |
|---|---|
ImageBase | — |
ImageSize | — |
ProcessID | — |
ImageCheckSum | — |
TimeDateStamp | — |
DefaultBase | — |
ImageName | — |
Event ID 7 — Base CPU priority of thread %2 in process %1 was changed from %3 to %4.
Message
Fields
| Name | Description |
|---|---|
ProcessID | — |
ThreadID | — |
OldPriority | — |
NewPriority | — |
Event ID 8 — CPU priority of thread %2 in process %1 was changed from %3 to %4.
Message
Fields
| Name | Description |
|---|---|
ProcessID | — |
ThreadID | — |
OldPriority | — |
NewPriority | — |
Event ID 9 — Page priority of thread %2 in process %1 was changed from %3 to %4.
Message
Fields
| Name | Description |
|---|---|
ProcessID | — |
ThreadID | — |
OldPriority | — |
NewPriority | — |
Event ID 10 — I/O priority of thread %2 in process %1 was changed from %3 to %4.
Message
Fields
| Name | Description |
|---|---|
ProcessID | — |
ThreadID | — |
OldPriority | — |
NewPriority | — |
Event ID 11 — Execution of the process %1 has been suspended.
Message
Fields
| Name | Description |
|---|---|
FrozenProcessID | — |
CreateTime | — |
Event ID 12 — Execution of the process %1 has been resumed.
Message
Fields
| Name | Description |
|---|---|
FrozenProcessID | — |
CreateTime | — |
Event ID 13 — Job %1 started with status code %2.
Message
Fields
| Name | Description |
|---|---|
Container ID | — |
Job ID | — |
StatusCode | — |
ContainerID | — |
JobID | — |
Event ID 14 — Job %1 terminated with status code %2.
Message
Fields
| Name | Description |
|---|---|
Container ID | — |
Job ID | — |
StatusCode | — |
ContainerID | — |
JobID | — |
Event ID 15 — Enumerated process %1 had started at time %2 by parent %3 running in session %4 with name %6.
Message
Fields
| Name | Description |
|---|---|
ProcessID | — |
ProcessSequenceNumber | — |
CreateTime | — |
ParentProcessID | — |
ParentProcessSequenceNumber | — |
SessionID | — |
Flags | — |
ProcessTokenElevationType | — |
ProcessTokenIsElevated | — |
MandatoryLabel | — |
ImageName | — |
ImageChecksum | — |
TimeDateStamp | — |
PackageFullName | — |
PackageRelativeAppId | — |
SecurityMitigations | — |
Event ID 16 —
Event ID 17 —
Fields
| Name | Description |
|---|---|
Job ID | — |
DiskIoAttribution | — |
StatusCode | — |
JobID | — |
Event ID 18 —
Fields
| Name | Description |
|---|---|
Job ID | — |
DiskIoAttribution | — |
StatusCode | — |
JobID | — |
Event ID 19 —
Fields
| Name | Description |
|---|---|
Job ID | — |
IoRateControl | — |
MaxIops | — |
MaxBandwidth | — |
MaxTimePercent | — |
ReservationIops | — |
ReservationBandwidth | — |
ReservationTimePercent | — |
CriticalReservationIops | — |
CriticalReservationBandwidth | — |
CriticalReservationTimePercent | — |
SoftMaxIops | — |
SoftMaxBandwidth | — |
SoftMaxTimePercent | — |
ControlFlags | — |
VolumeName | — |
StatusCode | — |
JobID | — |
Event ID 20 —
Fields
| Name | Description |
|---|---|
Job ID | — |
IoRateControl | — |
MaxIops | — |
MaxBandwidth | — |
MaxTimePercent | — |
ReservationIops | — |
ReservationBandwidth | — |
ReservationTimePercent | — |
CriticalReservationIops | — |
CriticalReservationBandwidth | — |
CriticalReservationTimePercent | — |
SoftMaxIops | — |
SoftMaxBandwidth | — |
SoftMaxTimePercent | — |
ControlFlags | — |
VolumeName | — |
StatusCode | — |
JobID | — |
Event ID 21 —
Fields
| Name | Description |
|---|---|
OldWorkOnBehalfThreadID | — |
NewWorkOnBehalfThreadID | — |
Event ID 22 —
Fields
| Name | Description |
|---|---|
Container ID | — |
Job ID | — |
State | — |
ContainerID | — |
JobID | — |
Event ID 23 —
Fields
| Name | Description |
|---|---|
Container ID | — |
Job ID | — |
MonitorName | — |
ContainerID | — |
JobID | — |
Event ID 24 —
Fields
| Name | Description |
|---|---|
Container ID | — |
Job ID | — |
Status | — |
MonitorName | — |
ContainerID | — |
JobID | — |
Event ID 25 —
Fields
| Name | Description |
|---|---|
Container ID | — |
Job ID | — |
MonitorName | — |
ContainerID | — |
JobID | — |
Event ID 26 —
Fields
| Name | Description |
|---|---|
Container ID | — |
Job ID | — |
MonitorName | — |
ContainerID | — |
JobID | — |
Event ID 27 —
Fields
| Name | Description |
|---|---|
ProcessName | — |
ProcessID | — |