Microsoft-Windows-Perflib
59 events across 2 channels
Event ID 0 —
Fields
| Name | Description |
|---|---|
Name | — |
Status | — |
Example Event
system:
provider: Microsoft-Windows-Perflib
guid: 13B197BD-7CEE-4B4E-8DD0-59314CE374CE
event_source_name: ''
event_id: 0
version: 0
level: 5
task: 0
opcode: 0
keywords: 4611686018427387904
time_created: '2023-11-05T22:40:53.996726+00:00'
event_record_id: 177
correlation: {}
execution:
process_id: 4360
thread_id: 4224
channel: Microsoft-Windows-Perflib/Operational
computer: WinDev2310Eval
security:
user_id: S-1-5-18
event_data:
Name: LoadPerfCounterTextStrings-End
Status: 0
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 1000 — Access to performance data was denied to user ".
Message
Fields
| Name | Description |
|---|---|
User | — |
Module | — |
Event ID 1001 — The Collect procedure in Extensible Counter DLL ".
Message
Fields
| Name | Description |
|---|---|
Library | — |
Service | — |
Size | — |
Event ID 1002 — A Guard Page was modified by a Collect procedure in Extensible Counter DLL ".
Message
Fields
| Name | Description |
|---|---|
Library | — |
Service | — |
Event ID 1003 — The Extensible Counter DLL ".
Message
Fields
| Name | Description |
|---|---|
Library | — |
Service | — |
ObjectCount | — |
Event ID 1004 — The Extensible Counter DLL ".
Message
Fields
| Name | Description |
|---|---|
Library | — |
Service | — |
ObjectIndex | — |
Event ID 1005 — The attempt to locate the Open procedure ".
Message
Fields
| Name | Description |
|---|---|
ProcName | — |
Library | — |
Service | — |
Win32Error | — |
Event ID 1006 — The attempt to locate the Collect procedure ".
Message
Fields
| Name | Description |
|---|---|
ProcName | — |
Library | — |
Service | — |
Win32Error | — |
Event ID 1007 — The attempt to locate the Close procedure ".
Message
Fields
| Name | Description |
|---|---|
ProcName | — |
Library | — |
Service | — |
Win32Error | — |
Event ID 1008 — The Open procedure for service ".
Message
Fields
| Name | Description |
|---|---|
Service | — |
Library | — |
Win32Error | — |
Event ID 1009 — The Open procedure in Extensible Counter DLL ".
Message
Fields
| Name | Description |
|---|---|
Library | — |
Service | — |
ExceptionCode | — |
ExceptionAddress | — |
Event ID 1010 — The Collect procedure in Extensible Counter DLL ".
Message
Fields
| Name | Description |
|---|---|
Library | — |
Service | — |
ExceptionCode | — |
ExceptionAddress | — |
Event ID 1011 — The Close procedure in Extensible Counter DLL ".
Message
Fields
| Name | Description |
|---|---|
Library | — |
Service | — |
ExceptionCode | — |
ExceptionAddress | — |
Event ID 1013 — The Collect procedure in Extensible Counter DLL ".
Message
Fields
| Name | Description |
|---|---|
Library | — |
Service | — |
Size | — |
Event ID 1014 — The Collect procedure for service ".
Message
Fields
| Name | Description |
|---|---|
Service | — |
Library | — |
Win32Error | — |
Event ID 1015 — The performance data collection function for the ".
Message
Fields
| Name | Description |
|---|---|
Service | — |
Library | — |
Event ID 1016 — The Collect procedure in Extensible Counter DLL ".
Message
Fields
| Name | Description |
|---|---|
Library | — |
Service | — |
Buffer | — |
BytesLeft | — |
Event ID 1017 — Disabled performance counter data collection from the ".
Message
Fields
| Name | Description |
|---|---|
Service | — |
Event ID 1018 — Disabled performance counter data collection for this session from the ".
Message
Fields
| Name | Description |
|---|---|
Service | — |
Event ID 1019 — A definition field in an object returned by Extensible Counter DLL ".
Message
Fields
| Name | Description |
|---|---|
Library | — |
Service | — |
ObjectIndex | — |
Event ID 1020 — The required buffer size is greater than the buffer size passed to the Collect function of the ".
Message
Fields
| Name | Description |
|---|---|
Library | — |
Service | — |
BufferSize | — |
RequiredSize | — |
Event ID 1021 — Windows cannot open the 32-bit extensible counter DLL ".
Message
Fields
| Name | Description |
|---|---|
Library | — |
Win32Error | — |
Event ID 1022 — Windows cannot open the 64-bit extensible counter DLL %1 in a 32-bit environment (Win32 error code %2).
Message
Fields
| Name | Description |
|---|---|
Library | — |
Win32Error | — |
Event ID 1023 — Windows cannot load the extensible counter DLL "C:\Windows\system32\ntdsperf.
Message
Fields
| Name | Description |
|---|---|
Library | — |
Win32Error | — |
Example Event
system:
provider: Microsoft-Windows-Perflib
guid: 13B197BD-7CEE-4B4E-8DD0-59314CE374CE
event_source_name: ''
event_id: 1023
version: 1
level: 2
task: 0
opcode: 0
keywords: 9223372036854775808
time_created: '2022-04-07T08:15:12.496963+00:00'
event_record_id: 107
correlation: {}
execution:
process_id: 2644
thread_id: 3324
channel: Application
computer: WIN-FPV0DSIC9O6.sigma.fr
security:
user_id: S-1-5-18
event_data:
Library: C:\Windows\system32\ntdsperf.dll
Win32Error: 126
message: Windows cannot load the extensible counter DLL "C:\Windows\system32\ntdsperf.dll"
(Win32 error code 126!s!).
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 2000 — The Collect procedure in Extensible Counter DLL ".
Message
Fields
| Name | Description |
|---|---|
Library | — |
Service | — |
BytesLeft | — |
BytesAvailable | — |
Event ID 2001 — The ".
Message
Fields
| Name | Description |
|---|---|
Service | — |
Win32Error | — |
NTSTATUS | — |
Event ID 2002 — The Open procedure for service ".
Message
Fields
| Name | Description |
|---|---|
Service | — |
Library | — |
Event ID 2003 — The configuration information of the performance library ".
Message
Fields
| Name | Description |
|---|---|
Library | — |
Service | — |
Event ID 3002 — The number of objects allowed in a performance library has exceeded the maximum supported.
Message
Event ID 3003 — Unable to find the %1 procedure name in the registry for service "%2".
Message
Fields
| Name | Description |
|---|---|
ProcName | — |
Service | — |
Event ID 2147484664 — The Collect procedure in Extensible Counter DLL ".
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
binary | — |
Event ID 2147485648 — The Collect procedure in Extensible Counter DLL ".
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
binary | — |
Event ID 2147485649 — The ".
Message
Fields
| Name | Description |
|---|---|
param1 | — |
binary | — |
Event ID 2147485650 — The Open procedure for service ".
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
Event ID 2147485651 — The configuration information of the performance library ".
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
Event ID 3221226472 — Access to performance data was denied to user ".
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
Event ID 3221226473 — The Collect procedure in Extensible Counter DLL ".
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
binary | — |
Event ID 3221226474 — A Guard Page was modified by a Collect procedure in Extensible Counter DLL ".
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
Event ID 3221226475 — The Extensible Counter DLL ".
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
binary | — |
Event ID 3221226476 — The Extensible Counter DLL ".
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
binary | — |
Event ID 3221226477 — The attempt to locate the Open procedure ".
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
binary | — |
Event ID 3221226478 — The attempt to locate the Collect procedure ".
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
binary | — |
Event ID 3221226479 — The attempt to locate the Close procedure ".
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
binary | — |
Event ID 3221226480 — The Open procedure for service ".
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
binary | — |
Event ID 3221226481 — The Open procedure in Extensible Counter DLL ".
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
binary | — |
Event ID 3221226482 — The Collect procedure in Extensible Counter DLL ".
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
binary | — |
Event ID 3221226483 — The Close procedure in Extensible Counter DLL ".
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
binary | — |
Event ID 3221226485 — The Collect procedure in Extensible Counter DLL ".
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
binary | — |
Event ID 3221226487 — The performance data collection function for the ".
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
binary | — |
Event ID 3221226489 — Disabled performance counter data collection from the ".
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 3221226490 — Disabled performance counter data collection for this session from the ".
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 3221226491 — A definition field in an object returned by Extensible Counter DLL ".
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
binary | — |
Event ID 3221226492 — The required buffer size is greater than the buffer size passed to the Collect function of the ".
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
binary | — |
Event ID 3221226493 — Windows cannot open the 32-bit extensible counter DLL ".
Message
Fields
| Name | Description |
|---|---|
param1 | — |
binary | — |
Event ID 3221226494 — Windows cannot open the 64-bit extensible counter DLL %1 in a 32-bit environment (Win32 error code %2).
Message
Fields
| Name | Description |
|---|---|
param1 | — |
binary | — |
Event ID 3221226495 — Windows cannot load the extensible counter DLL ".
Message
Fields
| Name | Description |
|---|---|
param1 | — |
binary | — |
Event ID 3221228474 — The number of objects allowed in a performance library has exceeded the maximum supported.
Message
Event ID 3221228475 — Unable to find the %1 procedure name in the registry for service "%2".
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
Event ID 3221228476 — Unable to find valid registry value '.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |