Microsoft-Windows-LoadPerf
53 events across 1 channel
Event ID 1000 — Performance counters for the WmiApRpl!
#Description
Performance counters for the () service were loaded successfully. The Record Data in the data section contains the new index values assigned to this service.
Message #
Fields #
| Name | Description |
|---|---|
EventXML.param1 | — |
EventXML.param2 | — |
EventXML.binaryDataSize | — |
EventXML.binaryData | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-LoadPerf",
"guid": "122EE297-BB47-41AE-B265-1CA8D1886D40",
"event_source_name": "",
"event_id": 1000,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 9223372036854775808,
"time_created": "2022-04-07T16:59:11.051894+00:00",
"event_record_id": 207,
"correlation": {},
"execution": {
"process_id": 4204,
"thread_id": 4208
},
"channel": "Application",
"computer": "WIN-FPV0DSIC9O6.lab.local",
"security": {
"user_id": "S-1-5-18"
}
},
"user_data": {
"EventXML": {
"param1": "WmiApRpl",
"param2": "WmiApRpl",
"binaryDataSize": 16,
"binaryData": "7igAAJQpAADvKAAAlSkAAA=="
}
},
"message": "Performance counters for the WmiApRpl!s! (WmiApRpl!s!) service were loaded successfully. The Record Data in the data section contains the new index values assigned to this service."
}
References #
- Example event sourced from https://github.com/Yamato-Security/hayabusa-sample-evtx
Event ID 1001 — Performance counters for the WmiApRpl!
#Description
Performance counters for the () service were removed successfully. The Record Data contains the new values of the system Last Counter and Last Help registry entries.
Message #
Fields #
| Name | Description |
|---|---|
EventXML.param1 | — |
EventXML.param2 | — |
EventXML.binaryDataSize | — |
EventXML.binaryData | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-LoadPerf",
"guid": "122EE297-BB47-41AE-B265-1CA8D1886D40",
"event_source_name": "",
"event_id": 1001,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 9223372036854775808,
"time_created": "2022-04-07T16:59:10.681381+00:00",
"event_record_id": 206,
"correlation": {},
"execution": {
"process_id": 4204,
"thread_id": 4208
},
"channel": "Application",
"computer": "WIN-FPV0DSIC9O6.lab.local",
"security": {
"user_id": "S-1-5-18"
}
},
"user_data": {
"EventXML": {
"param1": "WmiApRpl",
"param2": "WmiApRpl",
"binaryDataSize": 12,
"binaryData": "7CgAAO0oAADSBQAA"
}
},
"message": "Performance counters for the WmiApRpl!s! (WmiApRpl!s!) service were removed successfully. The Record Data contains the new values of the system Last Counter and Last Help registry entries."
}
References #
- Example event sourced from https://github.com/Yamato-Security/hayabusa-sample-evtx
Event ID 1002 — Performance counters for the http://schemas.
#Description
Performance counters for the () service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event.
Message #
Fields #
| Name | Description |
|---|---|
EventXML.xmlns:auto-ns2 | — |
EventXML.param1 | — |
EventXML.param2 | — |
EventXML.binaryDataSize | — |
EventXML.binaryData | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-LoadPerf",
"guid": "122EE297-BB47-41AE-B265-1CA8D1886D40",
"event_source_name": "",
"event_id": 1002,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 9223372036854775808,
"time_created": "2013-10-23T18:31:55.566626+00:00",
"event_record_id": 266,
"correlation": {},
"execution": {
"process_id": 836,
"thread_id": 3012
},
"channel": "Application",
"computer": "IE8Win7",
"security": {
"user_id": "S-1-5-18"
}
},
"user_data": {
"EventXML": {
"xmlns:auto-ns2": "http://schemas.microsoft.com/win/2004/08/events",
"param1": ".NET CLR Networking 4.0.0.0",
"param2": ".NET CLR Networking 4.0.0.0",
"binaryDataSize": 4,
"binaryData": "whIAAA=="
}
},
"message": "Performance counters for the http://schemas.microsoft.com/win/2004/08/events!s! (.NET CLR Networking 4.0.0.0!s!) service are already in the registry, no need to reinstall. This only happens when you install the same counter twice. The second time install will generate this event."
}
References #
- Example event sourced from https://github.com/Yamato-Security/hayabusa-sample-evtx
Event ID 2001 — No MOF file param2 was created for the param1 service.
Event ID 2002 — The MOF file created for the param1 service could not be loaded.
Event ID 2003 — The MOF file created for the param1 service cannot be deleted as requested.
Event ID 2004 — The Performance registry value param1 string is corrupted.
Event ID 2005 — No COUNTER/HELP definition for Language param1.
Event ID 2006 — The LastCounter and LastHelp values of the performance registry are corrupted and need to be updated.
Message #
Event ID 2007 — Cannot repair performance counters for param1 service.
Event ID 3000 — The performance strings in the registry do not match the index values stored in Performance registry key.
Message #
Event ID 3001 — The performance counter name string value in the registry is not formatted correctly.
Event ID 3002 — The performance counter explain text string value in the registry is not formatted correctly.
Event ID 3003 — Unable to install counter strings because the param1 key could not be opened or accessed.
Event ID 3004 — Unable to read the param1 registry value.
Event ID 3005 — Unable to open the registry key for the performance counter strings defined for the param1 language ID.
Event ID 3006 — Unable to read the performance counter strings defined for the param1 language ID.
Event ID 3007 — Unable to read the performance counter explain text strings defined for the param1 language ID.
Event ID 3008 — Unable to allocate a required memory buffer.
Description
Unable to allocate a required memory buffer.
Message #
Event ID 3009 — Installing the performance counter strings for service param1 (param2) failed.
Event ID 3011 — Unloading the performance counter strings for service param1 (param2) failed.
Event ID 3012 — The performance strings in the Performance registry value is corrupted when process param1 extension counter provider.
Event ID 3013 — Unable to update the performance counter strings defined for the param1 language ID.
Event ID 3014 — Unable to update the performance counter explain text strings of the param1 language ID.
Event ID 3015 — Index for param1 is corrupted.
Event ID 3016 — Cannot update param1 value of param2 key.
Event ID 3017 — Cannot update param1 value of param2 key.
Event ID 3018 — param1 index range of service param2 is corrupted.
Description
param1 index range of service param2 is corrupted. The first DWORD in the Data section contains the first index value used and the second DWORD in the Data section contains last index value used.
Message #
Fields #
| Name | Description |
|---|---|
param1 UnicodeString | — |
param2 UnicodeString | — |
Size UInt32 | — |
BinaryData Binary | — |