Microsoft-Windows-Services

15 events across 1 channel

Event IDTitleChannel
101Diagnostic
102Diagnostic
103Diagnostic
104Diagnostic
105Diagnostic
106Diagnostic
107Diagnostic
108Diagnostic
109Diagnostic
200Diagnostic
201Diagnostic
202Diagnostic
203Diagnostic
204Diagnostic
205Diagnostic

Event ID 101 —

Provider
Microsoft-Windows-Services
Channel
Diagnostic

Event ID 102 —

Provider
Microsoft-Windows-Services
Channel
Diagnostic

Event ID 103 —

Provider
Microsoft-Windows-Services
Channel
Diagnostic

Fields

NameDescription
GroupName

Event ID 104 —

Provider
Microsoft-Windows-Services
Channel
Diagnostic

Fields

NameDescription
GroupName

Event ID 105 —

Provider
Microsoft-Windows-Services
Channel
Diagnostic

Fields

NameDescription
ExecutionPhase
CurrentState
StartType
PID
ServiceName
ImageName

Event ID 106 —

Provider
Microsoft-Windows-Services
Channel
Diagnostic

Event ID 107 —

Provider
Microsoft-Windows-Services
Channel
Diagnostic

Event ID 108 —

Provider
Microsoft-Windows-Services
Channel
Diagnostic

Event ID 109 —

Provider
Microsoft-Windows-Services
Channel
Diagnostic

Event ID 200 —

Provider
Microsoft-Windows-Services
Channel
Diagnostic

Fields

NameDescription
ServiceName
DisplayName
ControlCode
ClientProcessStartKey
ClientProcessId
ParentProcessId

Event ID 201 —

Provider
Microsoft-Windows-Services
Channel
Diagnostic

Fields

NameDescription
ServiceName
NewStartType
ClientProcessStartKey
ClientProcessId
ParentProcessId

Event ID 202 —

Provider
Microsoft-Windows-Services
Channel
Diagnostic

Fields

NameDescription
ServiceName
NewValueName
ClientProcessStartKey
ClientProcessId
ParentProcessId

Event ID 203 —

Provider
Microsoft-Windows-Services
Channel
Diagnostic

Fields

NameDescription
ServiceName
NewValueName
ClientProcessStartKey
ClientProcessId
ParentProcessId

Event ID 204 —

Provider
Microsoft-Windows-Services
Channel
Diagnostic

Fields

NameDescription
ServiceName
ServiceHostName
ClientProcessStartKey
ClientProcessId
ParentProcessId

Event ID 205 —

Provider
Microsoft-Windows-Services
Channel
Diagnostic

Fields

NameDescription
ServiceName
LoadOrderGroup
SvchostGroup
IsCritical
IsUserService
IsOwnProcess
ClientProcessStartKey
ClientProcessId
ParentProcessId