Microsoft-Windows-Services
15 events across 1 channel
Event ID 101 —
Event ID 102 —
Event ID 103 —
Fields #
| Name | Description |
|---|---|
GroupName UnicodeString | — |
Event ID 104 —
Fields #
| Name | Description |
|---|---|
GroupName UnicodeString | — |
Event ID 105 —
Fields #
| Name | Description |
|---|---|
ExecutionPhase UInt32 | — |
CurrentState UInt32 | — |
StartType UInt32 | — Known values
|
PID UInt32 | — |
ServiceName UnicodeString | — |
ImageName UnicodeString | — |
Event ID 106 —
Event ID 107 —
Event ID 108 —
Event ID 109 —
Event ID 200 —
Fields #
| Name | Description |
|---|---|
ServiceName UnicodeString | — |
DisplayName UnicodeString | — |
ControlCode UInt32 | — |
ClientProcessStartKey UInt64 | — |
ClientProcessId UInt32 | — |
ParentProcessId UInt32 | — |
Event ID 201 —
Fields #
| Name | Description |
|---|---|
ServiceName UnicodeString | — |
NewStartType UInt32 | — |
ClientProcessStartKey UInt64 | — |
ClientProcessId UInt32 | — |
ParentProcessId UInt32 | — |
Event ID 202 —
Fields #
| Name | Description |
|---|---|
ServiceName UnicodeString | — |
NewValueName UnicodeString | — |
ClientProcessStartKey UInt64 | — |
ClientProcessId UInt32 | — |
ParentProcessId UInt32 | — |
Event ID 203 —
Fields #
| Name | Description |
|---|---|
ServiceName UnicodeString | — |
NewValueName UnicodeString | — |
ClientProcessStartKey UInt64 | — |
ClientProcessId UInt32 | — |
ParentProcessId UInt32 | — |
Event ID 204 —
Fields #
| Name | Description |
|---|---|
ServiceName UnicodeString | — |
ServiceHostName UnicodeString | — |
ClientProcessStartKey UInt64 | — |
ClientProcessId UInt32 | — |
ParentProcessId UInt32 | — |
Event ID 205 —
Fields #
| Name | Description |
|---|---|
ServiceName UnicodeString | — |
LoadOrderGroup UnicodeString | — |
SvchostGroup UnicodeString | — |
IsCritical Boolean | — |
IsUserService Boolean | — |
IsOwnProcess Boolean | — |
ClientProcessStartKey UInt64 | — |
ClientProcessId UInt32 | — |
ParentProcessId UInt32 | — |