Microsoft-Windows-Ndu
23 events across 1 channel
Event ID 2002 — _FunctionName Failed with _Status.
Event ID 2003 — Interface (Luid:Interface_Luid) added to per-interface list for proc _IfLuid at active index _ProcNum.
Event ID 2004 — established_ExePath Flow (Id:SvcTag) established.
Description
established_ExePath Flow (Id:SvcTag) established. ExePath: PkgName SvcTag:UserId PkgName:Pid UserId:_Direction Pid: _FlowHandle.
Message #
Fields #
| Name | Description |
|---|---|
established_ExePath | — |
SvcTag | — |
PkgName | — |
UserId | — |
Pid | — |
_Direction UnicodeString | — |
_FlowHandle UInt64 | — |
_ExePath UnicodeString | — |
_SvcTag UInt32 | — |
_PkgName UnicodeString | — |
_UserId SID | — |
_Pid UInt32 | — |
Event ID 2005 — Flow Context (Flow Id:Flow_Context_Flow_Id) Refcount_FlowHandle.
Event ID 2006 — Updated Interface Stats IfLuid:Updated_Interface_Stats_IfLuid ProfileId:ProfileId BytesSent:BytesSent BytesRecvd:BytesRecvd.
Description
Updated Interface Stats IfLuid:Updated_Interface_Stats_IfLuid ProfileId:ProfileId BytesSent:BytesSent BytesRecvd:BytesRecvd.
Message #
Fields #
| Name | Description |
|---|---|
Updated_Interface_Stats_IfLuid UInt64 | — |
ProfileId UInt32 | — |
BytesSent UInt32 | — |
BytesRecvd UInt32 | — |
_IfLuid UInt64 | — |
_ProfileId UInt32 | — |
_BytesSent UInt32 | — |
_BytesRecvd UInt32 | — |
Event ID 2007 — Updated Flow Stats (Flow Id:Updated_Flow_Stats_Flow_Id) IfLuid:IfLuid BytesSent:BytesSent BytesRecvd:BytesRecvd.
Description
Updated Flow Stats (Flow Id:Updated_Flow_Stats_Flow_Id) IfLuid:IfLuid BytesSent:BytesSent BytesRecvd:BytesRecvd.
Message #
Fields #
| Name | Description |
|---|---|
IfLuid UInt64 | — |
Updated_Flow_Stats_Flow_Id UInt64 | — |
BytesSent UInt32 | — |
BytesRecvd UInt32 | — |
_IfLuid UInt64 | — |
_FlowHandle UInt64 | — |
_BytesSent UInt32 | — |
_BytesRecvd UInt32 | — |
Event ID 2008 — Registration for quota exceeded notification.
Event ID 2009 — Unregistered from quota exceeded notification.
Event ID 2010 — Registration for byte count limit.
Event ID 2011 — Unregistered from byte count limit notification.
Event ID 2014 — IfLuid:IfLuid ProfileId:ProfileId BytesSent:BytesSent BytesRecvd:BytesRecvd IsCosted: IsCosted.
Description
IfLuid:IfLuid ProfileId:ProfileId BytesSent:BytesSent BytesRecvd:BytesRecvd IsCosted: IsCosted.
Message #
Fields #
| Name | Description |
|---|---|
IfLuid UInt64 | — |
ProfileId UInt32 | — |
BytesSent UInt64 | — |
BytesRecvd UInt64 | — |
IsCosted Boolean | — |
_IfLuid UInt64 | — |
_ProfileId UInt32 | — |
_BytesSent UInt64 | — |
_BytesRecvd UInt64 | — |
_IsCosted Boolean | — |
Event ID 2015 —
Fields #
| Name | Description |
|---|---|
_IfLuid UInt64 | — |
TimeSinceLast UInt64 | — |
Energy UInt64 | — |
CurrentProc UInt32 | — |
BytesTxRx UInt32 | — |
Pid UInt32 | — |
IfMediaType UInt8 | — |
Event ID 2016 —
Fields #
| Name | Description |
|---|---|
ProcId UInt32 | — |
Count UInt32 | — |
Event ID 2017 — NduMergeSmbStatsList: Not transferred InterfaceLuid and ProfileId to Smb stats because there is no one-and-only-one file transfer service (SMB) in ...
Description
NduMergeSmbStatsList: Not transferred InterfaceLuid and ProfileId to Smb stats because there is no one-and-only-one file transfer service (SMB) in the system. SystemSMB count:_SystemSmbCount InContainer:_IsContainer.
Message #
Fields #
| Name | Description |
|---|---|
_SystemSmbCount UInt64 | — |
_IsContainer Boolean | — |
Event ID 2018 — ProfileIdTracker::GetProfileIdForInterface: Profile Id not found.
Event ID 2019 — NduGetHostSid::UMgrEnumerateSessionUsers could not find SessionId: _SessionId.
Event ID 2020 — NduUpdateProcessStatsForContainerOrVmId succeeded: CurrentProcNumber:NduUpdateProcessStatsForContainerOrVmId_succeeded_CurrentProcNumber PartitionId:PartitionId Direction:Direction IfLuid:IfLuid If...
Description
NduUpdateProcessStatsForContainerOrVmId succeeded: CurrentProcNumber:NduUpdateProcessStatsForContainerOrVmId_succeeded_CurrentProcNumber PartitionId:PartitionId Direction:Direction IfLuid:IfLuid IfType:IfType BytesSent:BytesSent BytesRecvd:BytesRecvd.
Message #
Fields #
| Name | Description |
|---|---|
NduUpdateProcessStatsForContainerOrVmId_succeeded_CurrentProcNumber UInt32 | NduUpdateProcessStatsForContainerOrVmId succeeded: CurrentProcNumber. |
PartitionId GUID | — |
Direction UInt8 | — Known values
|
IfLuid UInt64 | — |
IfType UInt32 | — |
BytesSent UInt64 | — |
BytesRecvd UInt64 | — |
CurrentProcNumber UInt32 | — |
Event ID 2021 — OuterProcessId: VirtualIfLuid:IfAlias OuterProcessId:Title IfAlias:VirtualIfLuid.
Event ID 2022 — Wake count updated IfLuid:IfLuid Flow Id:FlowHandle (0 means interface) WakeCount:WakeCount.
Event ID 2023 —
Fields #
| Name | Description |
|---|---|
_ProcNum UInt32 | — |
_ListIndex UInt16 | — |
_ListHead UInt64 | — |
_Entry UInt64 | — |
_EntryFlink UInt64 | — |
_EntryBlink UInt64 | — |
_Flags UInt32 | — |