Microsoft-Windows-Shell-Core

2380 events across 5 channels

Event IDTitleChannel
1Diagnostic
2Diagnostic
3Diagnostic
4Diagnostic
101Diagnostic
102Diagnostic
103Diagnostic
104Diagnostic
105Diagnostic
106Diagnostic
107Diagnostic
108Diagnostic
109Diagnostic
110Diagnostic
111Diagnostic
112Diagnostic
113Diagnostic
114Diagnostic
115Diagnostic
501Diagnostic
502Diagnostic
503Diagnostic
504Diagnostic
505Diagnostic
506Diagnostic
507Diagnostic
508Diagnostic
509Diagnostic
510Diagnostic
1001Diagnostic
1002Diagnostic
1003Diagnostic
1004Diagnostic
1005Diagnostic
1006Diagnostic
1007Diagnostic
1008Diagnostic
1011Diagnostic
1012Diagnostic
1013Diagnostic
1014Diagnostic
1015Diagnostic
1016Diagnostic
1017Diagnostic
1018Diagnostic
1019Diagnostic
1020Diagnostic
1021Diagnostic
1022Diagnostic
1023Diagnostic
1024Diagnostic
1025Diagnostic
1026Diagnostic
1027Diagnostic
1028Diagnostic
1029Diagnostic
1033Diagnostic
1035Diagnostic
1037Diagnostic
1038Diagnostic
1039Diagnostic
1040Diagnostic
1041Diagnostic
1042Diagnostic
1043Diagnostic
1044Diagnostic
1045Diagnostic
1046Diagnostic
1047Diagnostic
1048Diagnostic
1049Diagnostic
1050Diagnostic
1051Diagnostic
1054Diagnostic
1055Diagnostic
1056Diagnostic
1057Diagnostic
1058Diagnostic
1059Diagnostic
1062Diagnostic
1063Diagnostic
1064Diagnostic
1065Diagnostic
1066Diagnostic
1067Diagnostic
1068Diagnostic
1069Diagnostic
1070Diagnostic
1071Diagnostic
1072Diagnostic
1073Diagnostic
1074Diagnostic
1075Diagnostic
1076Diagnostic
1077Diagnostic
1078Diagnostic
1079Diagnostic
1080Diagnostic
1081Diagnostic
1082Diagnostic
1083Diagnostic
1084Diagnostic
1085Diagnostic
1086Diagnostic
1087Diagnostic
1088Diagnostic
1089Diagnostic
1090Diagnostic
1091Diagnostic
1092Diagnostic
1093Diagnostic
1094Diagnostic
1095Diagnostic
1096Diagnostic
1097Diagnostic
1098Diagnostic
1099Diagnostic
1100Diagnostic
1101Diagnostic
1102Diagnostic
1103Diagnostic
1104Diagnostic
1105Diagnostic
1106Diagnostic
1107Diagnostic
1108Diagnostic
1109Diagnostic
1110Diagnostic
1111Diagnostic
1112Diagnostic
1113Diagnostic
1114Diagnostic
1115Diagnostic
1116Diagnostic
1117Diagnostic
1118Diagnostic
1119Diagnostic
1120Diagnostic
1121Diagnostic
1122Diagnostic
1123Diagnostic
1124Diagnostic
1125Diagnostic
1126Diagnostic
1127Diagnostic
1128Diagnostic
1129Diagnostic
1130Diagnostic
1131Diagnostic
1132Diagnostic
1133Diagnostic
1134Diagnostic
1135Diagnostic
1140Diagnostic
1141Diagnostic
1142Diagnostic
1143Diagnostic
1144Diagnostic
1145Diagnostic
1146Diagnostic
1147Diagnostic
1148Diagnostic
1149Diagnostic
1150Diagnostic
1151Diagnostic
1152Operational
1401Diagnostic
1402Diagnostic
1403Diagnostic
1404Diagnostic
1405Diagnostic
1406Diagnostic
1409Diagnostic
1410Diagnostic
1411Diagnostic
1412Diagnostic
1413Diagnostic
1414Diagnostic
1415Diagnostic
1417Diagnostic
1419Diagnostic
1500Diagnostic
1501Diagnostic
1502Diagnostic
1503Diagnostic
1504Diagnostic
1505Diagnostic
1506Diagnostic
1507Diagnostic
1508Diagnostic
1509Diagnostic
1510Diagnostic
1511Diagnostic
1512Diagnostic
1513Diagnostic
1514Diagnostic
1515Diagnostic
1518Diagnostic
1519Diagnostic
1520Diagnostic
1521Diagnostic
1522Diagnostic
1523Diagnostic
1524Diagnostic
1525Diagnostic
1526Diagnostic
1527Diagnostic
1528Diagnostic
1529Diagnostic
1530Diagnostic
1531Diagnostic
1532Diagnostic
1533Diagnostic
1534Diagnostic
1535Diagnostic
1536Diagnostic
1537Diagnostic
1538Diagnostic
1539Diagnostic
1540Diagnostic
1541Diagnostic
1542Diagnostic
1543Diagnostic
1544Diagnostic
1545Diagnostic
1546Diagnostic
1547Diagnostic
1548Diagnostic
1549Diagnostic
1550Diagnostic
1551Diagnostic
1552Diagnostic
1553Diagnostic
1554Diagnostic
1555Diagnostic
1556Diagnostic
1557Diagnostic
1558Diagnostic
1559Diagnostic
1560Diagnostic
1561Diagnostic
1562Diagnostic
1563Diagnostic
1564Diagnostic
1565Diagnostic
1566Diagnostic
1567Diagnostic
1568Diagnostic
1569Diagnostic
1570Diagnostic
1571Diagnostic
1572Diagnostic
1573Diagnostic
1574Diagnostic
1575Diagnostic
1576Diagnostic
1577Diagnostic
1578Diagnostic
1579Diagnostic
1580Diagnostic
1581Diagnostic
1582Diagnostic
1583Diagnostic
1584Diagnostic
1585Diagnostic
1586Diagnostic
1587Diagnostic
1588Diagnostic
1589Diagnostic
1590Diagnostic
1591Diagnostic
1592Diagnostic
1593Diagnostic
1594Diagnostic
1595Diagnostic
1596Diagnostic
1597Diagnostic
1598Diagnostic
1599Diagnostic
1600Diagnostic
1601Diagnostic
1602Diagnostic
1603Diagnostic
1604Diagnostic
1605Diagnostic
1606Diagnostic
1607Diagnostic
1608Diagnostic
1609Diagnostic
1610Diagnostic
1611Diagnostic
1612Diagnostic
1613Diagnostic
1614Diagnostic
1615Diagnostic
1616Diagnostic
1617Diagnostic
1618Diagnostic
1619Diagnostic
1620Diagnostic
1621Diagnostic
1622Diagnostic
1623Diagnostic
1628Diagnostic
1629Diagnostic
1630Diagnostic
1631Diagnostic
1632Diagnostic
1633Diagnostic
1634Diagnostic
1635Diagnostic
1636Diagnostic
1637Diagnostic
1640Diagnostic
1641Diagnostic
1642Diagnostic
1643Diagnostic
1644Diagnostic
1645Diagnostic
1646Diagnostic
1647Diagnostic
1648Diagnostic
1649Diagnostic
1650Diagnostic
1651Diagnostic
1652Diagnostic
1653Diagnostic
1654Diagnostic
1655Diagnostic
1656Diagnostic
1657Diagnostic
1658Diagnostic
1659Diagnostic
1660Diagnostic
1661Diagnostic
1662Diagnostic
1663Diagnostic
1664Diagnostic
1665Diagnostic
1666Diagnostic
1667Diagnostic
1668Diagnostic
1669Diagnostic
1672Diagnostic
1673Diagnostic
1674Diagnostic
1675Diagnostic
1676Diagnostic
1677Diagnostic
1678Diagnostic
1679Diagnostic
1680Diagnostic
1681Diagnostic
1682Diagnostic
1683Diagnostic
1684Diagnostic
1685Diagnostic
1686Diagnostic
1687Diagnostic
1688Diagnostic
1689Diagnostic
1690Diagnostic
1691Diagnostic
1692Diagnostic
1693Diagnostic
1694Diagnostic
1695Diagnostic
1696Diagnostic
1697Diagnostic
1698Diagnostic
1699Diagnostic
1700Diagnostic
1701Diagnostic
1702Diagnostic
1703Diagnostic
1704Diagnostic
1705Diagnostic
1706Diagnostic
1707Diagnostic
1708Diagnostic
1709Diagnostic
1710Diagnostic
1711Diagnostic
1712Diagnostic
1713Diagnostic
1714Diagnostic
1715Diagnostic
2001Diagnostic
2002Diagnostic
2003Diagnostic
2004Diagnostic
2005Diagnostic
2006Diagnostic
2007Diagnostic
2008Diagnostic
2009Diagnostic
2010Diagnostic
2011Diagnostic
2012Diagnostic
2013Diagnostic
2014Diagnostic
2015Diagnostic
2017Diagnostic
2019Diagnostic
2021Diagnostic
2022Diagnostic
2023Diagnostic
2024Diagnostic
2025Diagnostic
2027Diagnostic
2029Diagnostic
2031Diagnostic
2033Diagnostic
2035Diagnostic
2037Diagnostic
2039Diagnostic
2041Diagnostic
2043Diagnostic
2045Diagnostic
2047Diagnostic
2049Diagnostic
2050Diagnostic
2051Diagnostic
2052Diagnostic
2053Diagnostic
2054Diagnostic
2055Diagnostic
2056Diagnostic
2057Diagnostic
2058Diagnostic
2059Diagnostic
2060Diagnostic
2061Diagnostic
2062Diagnostic
2063Diagnostic
2064Diagnostic
2065Diagnostic
2066Diagnostic
2067Diagnostic
2069Diagnostic
2070Diagnostic
2071Diagnostic
2072Diagnostic
3001Diagnostic
3002Diagnostic
3003Diagnostic
3004Diagnostic
3005Diagnostic
3006Diagnostic
3007Diagnostic
3009Diagnostic
3010Diagnostic
3011Diagnostic
3012Diagnostic
3013Diagnostic
3014Diagnostic
3015Diagnostic
3016Diagnostic
4001Diagnostic
4003Diagnostic
4005Diagnostic
4007Diagnostic
4008Diagnostic
4009Diagnostic
5001Diagnostic
5002Diagnostic
5003Diagnostic
5004Diagnostic
5005Diagnostic
6001Diagnostic
6002Diagnostic
6201Diagnostic
6202Diagnostic
6203Diagnostic
6204Diagnostic
6205Diagnostic
6206Diagnostic
6207Diagnostic
6208Diagnostic
6209Diagnostic
6210Diagnostic
6211Diagnostic
6212Diagnostic
6213Diagnostic
6214Diagnostic
6215Diagnostic
6216Diagnostic
6217Diagnostic
6218Diagnostic
6219Diagnostic
6220Diagnostic
6221Diagnostic
6222Diagnostic
6223Diagnostic
6224Diagnostic
6225Diagnostic
6226Diagnostic
6227Diagnostic
6228Diagnostic
6229Diagnostic
6230Diagnostic
6231Diagnostic
6233Diagnostic
6235Diagnostic
6236Diagnostic
6237Diagnostic
6238Diagnostic
6239Diagnostic
6240Diagnostic
6241Diagnostic
6242Diagnostic
6243Diagnostic
6501Diagnostic
6502Diagnostic
6503Diagnostic
6504Diagnostic
6505Diagnostic
6506Diagnostic
6507Diagnostic
6508Diagnostic
6509Diagnostic
6510Diagnostic
6511Diagnostic
6512Diagnostic
6513Diagnostic
6514Diagnostic
6515Diagnostic
6516Diagnostic
6517Diagnostic
6518Diagnostic
7001Diagnostic
7002Diagnostic
7003Diagnostic
7004Diagnostic
7005Diagnostic
7006Diagnostic
8001Diagnostic
8002Diagnostic
8003Diagnostic
8004Diagnostic
8005Diagnostic
8006Diagnostic
9501Diagnostic
9503Diagnostic
9505Diagnostic
9506Diagnostic
9509Diagnostic
9510Diagnostic
9511Diagnostic
9512Diagnostic
9513Diagnostic
9515Diagnostic
9517Diagnostic
9519Diagnostic
9520Diagnostic
9521Diagnostic
9522Diagnostic
9523Diagnostic
9525Diagnostic
9526Diagnostic
9527Diagnostic
9529Diagnostic
9531Diagnostic
9533Diagnostic
9535Diagnostic
9539Diagnostic
9541Diagnostic
9543Diagnostic
9545Diagnostic
9547Diagnostic
9549Diagnostic
9551Diagnostic
9553Diagnostic
9555Diagnostic
9557Diagnostic
9559Diagnostic
9560Diagnostic
9561Diagnostic
9563Diagnostic
9565Diagnostic
9567Diagnostic
9568Diagnostic
9569Diagnostic
9571Diagnostic
9573Diagnostic
9575Diagnostic
9577Diagnostic
9581Diagnostic
9583Diagnostic
9585Diagnostic
9587Diagnostic
9589Diagnostic
9591Diagnostic
9593Diagnostic
9595Diagnostic
9597Diagnostic
9599Diagnostic
9601Diagnostic
9602Diagnostic
9603Diagnostic
9604Diagnostic
9607Diagnostic
9608Diagnostic
9609Diagnostic
9610Diagnostic
9611Diagnostic
9612Diagnostic
9613Diagnostic
9615Diagnostic
9617Diagnostic
9619Diagnostic
9621Diagnostic
9622Diagnostic
9623Diagnostic
9625Diagnostic
9626Diagnostic
9627Diagnostic
9628Diagnostic
9629Diagnostic
9630Diagnostic
9631Diagnostic
9633Diagnostic
9635Diagnostic
9637Diagnostic
9638Diagnostic
9639Diagnostic
9641Diagnostic
9643Diagnostic
9644Diagnostic
9645Diagnostic
9646Diagnostic
9647Diagnostic
9648Operational
9649Operational
9650Diagnostic
9651Diagnostic
9652Operational
9653Operational
9654Diagnostic
9660Diagnostic
9662Diagnostic
9663Diagnostic
9664Diagnostic
9665Diagnostic
9666Diagnostic
9699Diagnostic
9701Diagnostic
9702Diagnostic
9703RunOnce commands started.Operational
9704RunOnce commands finished.Operational
9705Started enumeration of commands for registry key 'KeyName'.Operational
9706Finished enumeration of commands for registry key 'KeyName'.Operational
9707Started execution of command 'Command'.Operational
9708Finished execution of command 'Command' (PID PID).Operational
9709Diagnostic
9710Diagnostic
9711Diagnostic
9712Diagnostic
9713Diagnostic
9714Diagnostic
9716Diagnostic
9717Diagnostic
9801Diagnostic
9802Diagnostic
9803Diagnostic
9804Diagnostic
9805Diagnostic
9806Diagnostic
9808Diagnostic
9810Diagnostic
9811Operational
9812Operational
9901Diagnostic
9902Diagnostic
9903Diagnostic
9904Diagnostic
9905Diagnostic
9906Diagnostic
9907Diagnostic
9909Diagnostic
9910Diagnostic
9911Diagnostic
9912Diagnostic
9913Diagnostic
9914Diagnostic
9915Diagnostic
9916Diagnostic
9917Diagnostic
9918Diagnostic
9919Diagnostic
10001Diagnostic
10002Diagnostic
11001Diagnostic
11003Diagnostic
11004Diagnostic
11005Diagnostic
11006Diagnostic
11007Diagnostic
11009Diagnostic
11010Diagnostic
11011Diagnostic
11013Diagnostic
11014Diagnostic
11015Diagnostic
11016Diagnostic
11017Diagnostic
12001Diagnostic
12101Diagnostic
12102Diagnostic
12103Diagnostic
12104Diagnostic
12105Diagnostic
12106Diagnostic
12107Diagnostic
12108Diagnostic
12109Diagnostic
12110Diagnostic
12111Diagnostic
12112Diagnostic
12113Diagnostic
12114Diagnostic
13001Diagnostic
13002Diagnostic
13003Diagnostic
13004Diagnostic
13005Diagnostic
13006Diagnostic
13007Diagnostic
13008Diagnostic
13101Diagnostic
13102Diagnostic
13501Diagnostic
13502Diagnostic
13503Diagnostic
13505Diagnostic
13507Diagnostic
13509Diagnostic
13511Diagnostic
13513Diagnostic
13515Diagnostic
13517Diagnostic
14001Diagnostic
14002Diagnostic
14003Diagnostic
14004Diagnostic
14005Diagnostic
14006Diagnostic
14007Diagnostic
14008Diagnostic
14009Diagnostic
14101Diagnostic
14102Diagnostic
14103Diagnostic
14104Diagnostic
14201Diagnostic
14202Diagnostic
14203Diagnostic
14204Diagnostic
14205Diagnostic
14206Diagnostic
14207Diagnostic
14209Diagnostic
14211Diagnostic
14213Diagnostic
14215Diagnostic
14216Diagnostic
14217Diagnostic
14219Diagnostic
14220Diagnostic
14501Diagnostic
14502Diagnostic
14503Diagnostic
14504Diagnostic
14505Diagnostic
14506Diagnostic
14507Diagnostic
14508Diagnostic
14509Diagnostic
14510Diagnostic
14511Diagnostic
14512Diagnostic
14513Diagnostic
14514Diagnostic
14515Diagnostic
14516Diagnostic
14517Diagnostic
14518Diagnostic
14519Diagnostic
14520Diagnostic
14521Diagnostic
14522Diagnostic
14523Diagnostic
14524Diagnostic
14525Diagnostic
14526Diagnostic
14527Diagnostic
14528Diagnostic
14529Diagnostic
14530Diagnostic
14531Diagnostic
14532Diagnostic
14533Diagnostic
14534Diagnostic
14535Diagnostic
14536Diagnostic
14537Diagnostic
14538Diagnostic
14539Diagnostic
14540Diagnostic
14541Diagnostic
14542Diagnostic
14543Diagnostic
14544Diagnostic
14545Diagnostic
14546Diagnostic
14547Diagnostic
14548Diagnostic
14549Diagnostic
14550Diagnostic
14551Diagnostic
14552Diagnostic
14553Diagnostic
14554Diagnostic
14555Diagnostic
14556Diagnostic
14557Diagnostic
14558Diagnostic
14559Diagnostic
14560Diagnostic
14561Diagnostic
14563Diagnostic
14564Diagnostic
15001Diagnostic
15002Diagnostic
15003Diagnostic
15004Diagnostic
15501Diagnostic
15502Diagnostic
15503Diagnostic
15504Diagnostic
15505Diagnostic
15506Diagnostic
15507Diagnostic
15508Diagnostic
15509Diagnostic
15510Diagnostic
15511Diagnostic
15512Diagnostic
15513Diagnostic
15514Diagnostic
15515Diagnostic
15516Diagnostic
15517Diagnostic
15518Diagnostic
15519Diagnostic
15520Diagnostic
16501Diagnostic
16502Diagnostic
16503Diagnostic
16504Diagnostic
16505Diagnostic
16506Diagnostic
16507Diagnostic
16508Diagnostic
16509Diagnostic
16510Diagnostic
16511Diagnostic
16512Diagnostic
16513Diagnostic
16514Diagnostic
16600Diagnostic
16601Diagnostic
16602Diagnostic
16603Diagnostic
16604Diagnostic
16605Diagnostic
16606Diagnostic
16607Diagnostic
16608Diagnostic
16609Diagnostic
16610Diagnostic
16611Diagnostic
16612Diagnostic
16613Diagnostic
16614Diagnostic
16615Diagnostic
16616Diagnostic
16617Diagnostic
16618Diagnostic
16619Diagnostic
16620Diagnostic
16621Diagnostic
16700Diagnostic
16701Diagnostic
16702Diagnostic
16703Diagnostic
16704Diagnostic
16705Diagnostic
16706Diagnostic
16707Diagnostic
16708Diagnostic
16709Diagnostic
16710Diagnostic
16711Diagnostic
16712Diagnostic
16713Diagnostic
16714Diagnostic
16715Diagnostic
16716Diagnostic
16717Diagnostic
16718Diagnostic
16719Diagnostic
16720Diagnostic
16721Diagnostic
16722Diagnostic
16723Diagnostic
16724Diagnostic
16725Diagnostic
16726Diagnostic
16727Diagnostic
16728Diagnostic
16729Diagnostic
16801Diagnostic
16803Diagnostic
16804Diagnostic
16805Diagnostic
16807Diagnostic
16809Diagnostic
16811Diagnostic
16813Diagnostic
16815Diagnostic
16817Diagnostic
16901Diagnostic
16902Diagnostic
16903Diagnostic
16904Diagnostic
16905Diagnostic
16906Diagnostic
16907Diagnostic
17001Diagnostic
17002Diagnostic
17003Diagnostic
17004Diagnostic
17005Diagnostic
17006Diagnostic
17007Diagnostic
17008Diagnostic
17009Diagnostic
17010Diagnostic
17101Diagnostic
17103Diagnostic
17105Diagnostic
17107Diagnostic
17109Diagnostic
17111Diagnostic
17113Diagnostic
17115Diagnostic
17117Diagnostic
17119Diagnostic
17121Diagnostic
17501Diagnostic
17502Diagnostic
17503Diagnostic
17504Diagnostic
17505Diagnostic
17506Diagnostic
17507Diagnostic
17508Diagnostic
17509Diagnostic
17510Diagnostic
17511Diagnostic
17512Diagnostic
17513Diagnostic
17514Diagnostic
17515Diagnostic
17516Diagnostic
17517Diagnostic
17518Diagnostic
18001Diagnostic
18003Diagnostic
18005Diagnostic
18006Diagnostic
18007Diagnostic
18008Diagnostic
18009Diagnostic
18010Diagnostic
18011Diagnostic
18012Diagnostic
18013Diagnostic
18015Diagnostic
18017Diagnostic
18018Diagnostic
18501Diagnostic
18503Diagnostic
18505Diagnostic
18506Diagnostic
18507Diagnostic
18508Diagnostic
18509Diagnostic
18511Diagnostic
18512Diagnostic
18513Diagnostic
18514Diagnostic
18515Diagnostic
18516Diagnostic
18517Diagnostic
18518Diagnostic
18521Diagnostic
18522Diagnostic
18523Diagnostic
18524Diagnostic
18525Diagnostic
18526Diagnostic
18527Diagnostic
18528Diagnostic
18529Diagnostic
18530Diagnostic
18531Diagnostic
18532Diagnostic
18533Diagnostic
18534Diagnostic
18535Diagnostic
18536Diagnostic
18537Diagnostic
18538Diagnostic
18539Diagnostic
18540Diagnostic
18541Diagnostic
18543Diagnostic
18544Diagnostic
18545Diagnostic
18546Diagnostic
18547Diagnostic
18548Diagnostic
18549Diagnostic
18550Diagnostic
18551Diagnostic
18552Diagnostic
18553Diagnostic
18554Diagnostic
18555Diagnostic
18556Diagnostic
18557Diagnostic
18558Diagnostic
18559Diagnostic
18560Diagnostic
18561Diagnostic
18563Diagnostic
18565Diagnostic
18567Diagnostic
18568Diagnostic
18569Diagnostic
18570Diagnostic
18571Diagnostic
18573Diagnostic
18575Diagnostic
18576Diagnostic
18577Diagnostic
18578Diagnostic
18579Diagnostic
18580Diagnostic
18581Diagnostic
18582Diagnostic
18583Diagnostic
18584Diagnostic
18585Diagnostic
18586Diagnostic
18587Diagnostic
18588Diagnostic
18589Diagnostic
18590Diagnostic
18591Diagnostic
18592Diagnostic
18593Diagnostic
18594Diagnostic
18595Diagnostic
18596Diagnostic
18597Diagnostic
18598Diagnostic
18599Diagnostic
18600Diagnostic
18601Diagnostic
18602Diagnostic
18603Diagnostic
18604Diagnostic
18605Diagnostic
18606Diagnostic
18607Diagnostic
18608Diagnostic
18609Diagnostic
18610Diagnostic
18611Diagnostic
18612Diagnostic
18613Diagnostic
18614Diagnostic
18615Diagnostic
18616Diagnostic
18617Diagnostic
18618Diagnostic
18619Diagnostic
18620Diagnostic
18621Diagnostic
18622Diagnostic
18623Diagnostic
18624Diagnostic
18625Diagnostic
18626Diagnostic
18627Diagnostic
18628Diagnostic
18629Diagnostic
18630Diagnostic
18631Diagnostic
18632Diagnostic
18633Diagnostic
18634Diagnostic
18635Diagnostic
18636Diagnostic
18637Diagnostic
18638Diagnostic
18639Diagnostic
18640Diagnostic
18641Diagnostic
18642Diagnostic
18645Diagnostic
18646Diagnostic
18649Diagnostic
18650Diagnostic
18653Diagnostic
18654Diagnostic
18657Diagnostic
18658Diagnostic
18659Diagnostic
18660Diagnostic
18661Diagnostic
18663Diagnostic
18664Diagnostic
18665Diagnostic
18669Diagnostic
18675Diagnostic
18676Diagnostic
18677Diagnostic
18678Diagnostic
18679Diagnostic
18680Diagnostic
18681Diagnostic
18682Diagnostic
18683Diagnostic
18684Diagnostic
18685Diagnostic
18686Diagnostic
18687Diagnostic
18688Diagnostic
18689Diagnostic
18690Diagnostic
18691Diagnostic
18692Diagnostic
18693Diagnostic
18694Diagnostic
18695Diagnostic
18696Diagnostic
18697Diagnostic
18698Diagnostic
18699Diagnostic
18700Diagnostic
18701Diagnostic
18702Diagnostic
18703Diagnostic
18705Diagnostic
18707Diagnostic
18708Diagnostic
18709Diagnostic
18710Diagnostic
18711Diagnostic
18712Diagnostic
18713Diagnostic
18714Diagnostic
18715Diagnostic
18716Diagnostic
18717Diagnostic
18718Diagnostic
18719Diagnostic
18720Diagnostic
18721Diagnostic
18722Diagnostic
18723Diagnostic
18724Diagnostic
18725Diagnostic
18726Diagnostic
18727Diagnostic
18728Diagnostic
18729Diagnostic
18730Diagnostic
18731Diagnostic
18732Diagnostic
18733Diagnostic
18734Diagnostic
18735Diagnostic
18736Diagnostic
18737Diagnostic
18738Diagnostic
18739Diagnostic
18740Diagnostic
18741Diagnostic
18742Diagnostic
18743Diagnostic
18745Diagnostic
18747Diagnostic
18749Diagnostic
18751Diagnostic
18752Diagnostic
18753Diagnostic
18755Diagnostic
18761Diagnostic
18762Diagnostic
18763Diagnostic
18764Diagnostic
18765Diagnostic
18766Diagnostic
18767Diagnostic
18768Diagnostic
18769Diagnostic
18770Diagnostic
18771Diagnostic
18773Diagnostic
18775Diagnostic
18776Diagnostic
18777Diagnostic
18778Diagnostic
18779Diagnostic
18780Diagnostic
18781Diagnostic
18782Diagnostic
18783Diagnostic
18784Diagnostic
18787Diagnostic
18788Diagnostic
18789Diagnostic
18790Diagnostic
18791Diagnostic
18792Diagnostic
18793Diagnostic
18794Diagnostic
18795Diagnostic
18796Diagnostic
18797Diagnostic
18798Diagnostic
18799Diagnostic
18800Diagnostic
18801Diagnostic
18802Diagnostic
18803Diagnostic
18804Diagnostic
18805Diagnostic
18806Diagnostic
18807Diagnostic
18809Diagnostic
18810Diagnostic
18811Diagnostic
18812Diagnostic
18813Diagnostic
18814Diagnostic
18815Diagnostic
18816Diagnostic
18817Diagnostic
18818Diagnostic
18819Diagnostic
18820Diagnostic
18821Diagnostic
18823Diagnostic
18825Diagnostic
18826Diagnostic
18827Diagnostic
18828Diagnostic
18829Diagnostic
18830Diagnostic
18831Diagnostic
18832Diagnostic
18833Diagnostic
18834Diagnostic
18835Diagnostic
18836Diagnostic
18837Diagnostic
18838Diagnostic
18841Diagnostic
18843Diagnostic
18844Diagnostic
18845Diagnostic
18847Diagnostic
18848Diagnostic
18849Diagnostic
18850Diagnostic
18851Diagnostic
18852Diagnostic
18853Diagnostic
18855Diagnostic
18857Diagnostic
18858Diagnostic
18859Diagnostic
18860Diagnostic
18861Diagnostic
18862Diagnostic
18863Diagnostic
18864Diagnostic
18865Diagnostic
18867Diagnostic
18868Diagnostic
18869Diagnostic
18870Diagnostic
18871Diagnostic
18873Diagnostic
18875Diagnostic
18877Diagnostic
18878Diagnostic
18879Diagnostic
18880Diagnostic
18881Diagnostic
18882Diagnostic
18883Diagnostic
18884Diagnostic
18885Diagnostic
18886Diagnostic
18887Diagnostic
18888Diagnostic
18889Diagnostic
18901Diagnostic
18902Diagnostic
18903Diagnostic
18905Diagnostic
18907Diagnostic
18909Diagnostic
18911Diagnostic
18913Diagnostic
18915Diagnostic
18917Diagnostic
18918Diagnostic
18919Diagnostic
18920Diagnostic
18921Diagnostic
18922Diagnostic
18923Diagnostic
18924Diagnostic
18925Diagnostic
18927Diagnostic
18929Diagnostic
18931Diagnostic
18932Diagnostic
18933Diagnostic
18934Diagnostic
18935Diagnostic
18936Diagnostic
18937Diagnostic
18939Diagnostic
18941Diagnostic
18943Diagnostic
18950Diagnostic
18951Diagnostic
18952Diagnostic
18953Diagnostic
18954Diagnostic
18955Diagnostic
18956Diagnostic
18957Diagnostic
18958Diagnostic
18959Diagnostic
18960Diagnostic
18961Diagnostic
18962Diagnostic
18963Diagnostic
18964Diagnostic
18970Diagnostic
18972Diagnostic
18974Diagnostic
18976Diagnostic
18978Diagnostic
18980Diagnostic
19001Diagnostic
19002Diagnostic
19003Diagnostic
19004Diagnostic
19005Diagnostic
19006Diagnostic
19007Diagnostic
19101Diagnostic
19201Diagnostic
19203Diagnostic
19205Diagnostic
19207Diagnostic
19209Diagnostic
19211Diagnostic
19401Diagnostic
19403Diagnostic
19405Diagnostic
19407Diagnostic
19409Diagnostic
19411Diagnostic
19413Diagnostic
19415Diagnostic
19417Diagnostic
19419Diagnostic
19421Diagnostic
19423Diagnostic
19425Diagnostic
19427Diagnostic
19429Diagnostic
19431Diagnostic
19433Diagnostic
19435Diagnostic
19437Diagnostic
19439Diagnostic
19441Diagnostic
19443Diagnostic
19501Diagnostic
19502Diagnostic
19503Diagnostic
19504Diagnostic
19601Diagnostic
19602Diagnostic
19603Diagnostic
19604Diagnostic
19605Diagnostic
19606Diagnostic
19607Diagnostic
19608Diagnostic
19611Diagnostic
19613Diagnostic
19615Diagnostic
19617Diagnostic
19619Diagnostic
19621Diagnostic
19623Diagnostic
19625Diagnostic
19627Diagnostic
19628Diagnostic
19635Diagnostic
19636Diagnostic
19801Diagnostic
19803Diagnostic
19804Diagnostic
19805Diagnostic
19900Diagnostic
20001Diagnostic
20002Diagnostic
20003Diagnostic
20004Diagnostic
20005Diagnostic
20006Diagnostic
20007Diagnostic
20009Diagnostic
20011Diagnostic
20013Diagnostic
20015Diagnostic
20017Diagnostic
20019Diagnostic
20021Diagnostic
20023Diagnostic
20025Diagnostic
20027Diagnostic
20029Diagnostic
20031Diagnostic
20033Diagnostic
20035Diagnostic
20037Diagnostic
20039Diagnostic
20041Diagnostic
20043Diagnostic
20045Diagnostic
20047Diagnostic
20049Diagnostic
20051Diagnostic
20053Diagnostic
20055Diagnostic
20057Diagnostic
20059Diagnostic
20061Diagnostic
20063Diagnostic
20065Diagnostic
20066Diagnostic
20067Diagnostic
20068Diagnostic
20069Diagnostic
20070Diagnostic
20071Diagnostic
20072Diagnostic
20073Diagnostic
20075Diagnostic
20076Diagnostic
20102Diagnostic
20103Diagnostic
20104Diagnostic
20105Diagnostic
20106Diagnostic
20107Diagnostic
20108Diagnostic
20109Diagnostic
20111Diagnostic
20112Diagnostic
20900Diagnostic
20901Diagnostic
20902Diagnostic
20903Diagnostic
20905Diagnostic
20906Diagnostic
20907Diagnostic
20908Diagnostic
20909Diagnostic
20910Diagnostic
20911Diagnostic
20912Diagnostic
20914Diagnostic
20915Diagnostic
20916Diagnostic
20917Diagnostic
20918Diagnostic
20919Diagnostic
20920Diagnostic
20921Diagnostic
21001Diagnostic
21002Diagnostic
21003Diagnostic
21004Diagnostic
21005Diagnostic
21006Diagnostic
21007Diagnostic
21009Diagnostic
21011Diagnostic
21013Diagnostic
21015Diagnostic
21017Diagnostic
21018Diagnostic
22001Diagnostic
22002Diagnostic
22003Diagnostic
22004Diagnostic
22005Diagnostic
22006Diagnostic
22007Diagnostic
22009Diagnostic
22011Diagnostic
22013Diagnostic
22014Diagnostic
22015Diagnostic
22017Diagnostic
22018Diagnostic
22019Diagnostic
22020Diagnostic
22021Diagnostic
22022Diagnostic
22023Diagnostic
22025Diagnostic
22026Diagnostic
22027Diagnostic
22028Diagnostic
22029Diagnostic
22030Diagnostic
22031Diagnostic
22032Diagnostic
22033Diagnostic
22034Diagnostic
22035Diagnostic
22036Diagnostic
22037Diagnostic
22038Diagnostic
22039Diagnostic
22040Diagnostic
22041Diagnostic
22042Diagnostic
22043Diagnostic
22044Diagnostic
22045Diagnostic
22046Diagnostic
22047Diagnostic
22048Diagnostic
22049Diagnostic
22050Diagnostic
22051Diagnostic
22052Diagnostic
22053Diagnostic
22054Diagnostic
22055Diagnostic
22056Diagnostic
22057Diagnostic
22058Diagnostic
22059Diagnostic
22060Diagnostic
22061Diagnostic
22062Diagnostic
22063Diagnostic
22064Diagnostic
22065Diagnostic
22066Diagnostic
22067Diagnostic
22068Diagnostic
22069Diagnostic
22070Diagnostic
22071Diagnostic
22072Diagnostic
22073Diagnostic
22074Diagnostic
22075Diagnostic
22076Diagnostic
22077Diagnostic
22078Diagnostic
22079Diagnostic
22080Diagnostic
22081Diagnostic
22082Operational
22083Operational
23001Diagnostic
23002Diagnostic
23003Diagnostic
23004Diagnostic
23005Diagnostic
23006Diagnostic
23007Diagnostic
23008Diagnostic
23009Diagnostic
23010Diagnostic
23011Diagnostic
23012Diagnostic
23013Diagnostic
23101Diagnostic
23110Diagnostic
23111Diagnostic
23201Diagnostic
23203Diagnostic
23205Diagnostic
26001Diagnostic
26002Diagnostic
26003Diagnostic
26004Diagnostic
26005Diagnostic
26006Diagnostic
26007Diagnostic
26009Diagnostic
26010Diagnostic
26011Diagnostic
27002Diagnostic
27004Diagnostic
27005Diagnostic
27006Diagnostic
27007Diagnostic
27008Diagnostic
27009Diagnostic
27010Diagnostic
27011Diagnostic
27012Diagnostic
27013Diagnostic
27014Diagnostic
27015Diagnostic
27016Diagnostic
27018Diagnostic
27020Diagnostic
27022Diagnostic
27024Diagnostic
27026Diagnostic
27028Diagnostic
27030Diagnostic
27032Diagnostic
27034Diagnostic
27036Diagnostic
27038Diagnostic
27040Diagnostic
27042Diagnostic
27044Diagnostic
27046Diagnostic
27048Diagnostic
27050Diagnostic
27052Diagnostic
27054Diagnostic
27056Diagnostic
27058Diagnostic
27060Diagnostic
27062Diagnostic
27064Diagnostic
27078Diagnostic
27080Diagnostic
27082Diagnostic
27084Diagnostic
27086Diagnostic
27088Diagnostic
27090Diagnostic
27092Diagnostic
27094Diagnostic
27096Diagnostic
27098Diagnostic
27100Diagnostic
27102Diagnostic
27104Diagnostic
27106Diagnostic
27108Diagnostic
27110Diagnostic
27112Diagnostic
27114Diagnostic
27116Diagnostic
27118Diagnostic
27120Diagnostic
27122Diagnostic
27124Diagnostic
27126Diagnostic
27128Diagnostic
27142Diagnostic
27144Diagnostic
27145Diagnostic
27146Diagnostic
27147Diagnostic
27148Diagnostic
27149Diagnostic
27151Diagnostic
27152Diagnostic
27153Diagnostic
27154Diagnostic
27155Diagnostic
27156Diagnostic
27157Diagnostic
27158Diagnostic
27159Diagnostic
27160Diagnostic
27161Diagnostic
27162Diagnostic
27163Diagnostic
27164Diagnostic
27165Diagnostic
27166Diagnostic
27168Diagnostic
27170Diagnostic
27172Diagnostic
27173Diagnostic
27174Diagnostic
27176Diagnostic
27178Diagnostic
27180Diagnostic
27182Diagnostic
27184Diagnostic
27186Diagnostic
27188Diagnostic
27190Diagnostic
27191Diagnostic
27192Diagnostic
27193Diagnostic
27194Diagnostic
27195Diagnostic
27196Diagnostic
27197Diagnostic
27198Diagnostic
27199Diagnostic
27200Diagnostic
27202Diagnostic
27203Diagnostic
27204Diagnostic
27206Diagnostic
27208Diagnostic
27209Diagnostic
27210Diagnostic
27211Diagnostic
27212Diagnostic
27213Diagnostic
27214Diagnostic
27215Diagnostic
27216Diagnostic
27217Diagnostic
27218Diagnostic
27221Diagnostic
27222Diagnostic
27223Diagnostic
27224Diagnostic
27226Diagnostic
27227Diagnostic
27229Diagnostic
27230Diagnostic
27231Diagnostic
27233Diagnostic
27234Diagnostic
27235Diagnostic
27236Diagnostic
27237Diagnostic
27238Diagnostic
27239Diagnostic
27240Diagnostic
27241Diagnostic
27242Diagnostic
27243Diagnostic
27244Diagnostic
27248Diagnostic
27250Diagnostic
27252Diagnostic
27254Diagnostic
27255Diagnostic
27256Diagnostic
27257Diagnostic
28003Diagnostic
28004Diagnostic
28017AppResolver Scan Started.Operational
28018AppResolver Scan Stopped.Operational
28019AppResolver Cache Committed.Operational
28025Diagnostic
28026Diagnostic
28027Diagnostic
28028Diagnostic
28029Diagnostic
28030Diagnostic
28031Diagnostic
28032AppResolver has parsed the visual elements manifest for a tile.Operational
28101Diagnostic
28103Diagnostic
28105Diagnostic
28107Diagnostic
28109Application AppID state changed from OldState to NewState due to package …Operational
28111Application AppID state changed from OldState to NewState due to package …Operational
28113Change notified on {Filename} with event {Event}.Operational
28115Shortcut for application Name with ID AppID and flags Flags is added to app …Operational
28116Shortcut for application Name with ID AppID and flags Flags is removed from app …Operational
28117Shortcut for application Name with ID AppID and flags Flags is updated in app …Operational
28119Start screen loaded layout which contains Groups groups and Tiles tiles …Operational
28121Start screen loaded persisted layout which contains {Groups} groups and {Tiles} …Operational
28123Updated start screen layout: ItemsExisting items initially; ItemsAdded added; …Operational
28125Starting to refresh app resolver cache for scenario Scenario with flags Flags.Operational
28127Operational
28189Diagnostic
28191Diagnostic
28193Diagnostic
28195Diagnostic
50001Diagnostic
50002Diagnostic
50101Diagnostic
50102Diagnostic
50103Diagnostic
50104Diagnostic
50105Diagnostic
50106Diagnostic
50107Diagnostic
50108Diagnostic
50201Diagnostic
50202Diagnostic
50203Diagnostic
50204Diagnostic
50205Diagnostic
50206Diagnostic
50207Diagnostic
50208Diagnostic
50209Diagnostic
50210Diagnostic
50211Diagnostic
60000Diagnostic
60001Diagnostic
60002Diagnostic
60003Diagnostic
60004Diagnostic
60005Diagnostic
60006Diagnostic
60007Diagnostic
60008Diagnostic
60009Diagnostic
60010Diagnostic
60011Diagnostic
60012Diagnostic
60013Diagnostic
60014Diagnostic
60015Diagnostic
60016Diagnostic
60017Diagnostic
60018Diagnostic
60019Diagnostic
60020Diagnostic
60021Diagnostic
60022Diagnostic
60023Diagnostic
60025Diagnostic
60026Diagnostic
60027Diagnostic
60028Diagnostic
60029Diagnostic
60030Diagnostic
60031Diagnostic
60032Diagnostic
60033Diagnostic
60034Diagnostic
60035Diagnostic
60036Diagnostic
60037Diagnostic
60101Diagnostic
60102Diagnostic
60103Diagnostic
60104Diagnostic
60105Diagnostic
60106Diagnostic
60107Diagnostic
60108Diagnostic
60109Diagnostic
60110Diagnostic
60111Diagnostic
60112Diagnostic
60113Diagnostic
60114Diagnostic
60115Diagnostic
60116Diagnostic
60117Diagnostic
60118Diagnostic
60119Diagnostic
60120Diagnostic
60201Diagnostic
60202Diagnostic
60203Diagnostic
60204Diagnostic
60205Diagnostic
60206Diagnostic
60213Diagnostic
60214Diagnostic
60215Diagnostic
60216Diagnostic
60217Diagnostic
60218Diagnostic
60219Diagnostic
60220Diagnostic
60221Diagnostic
60222Diagnostic
60301Diagnostic
60302Diagnostic
60303Diagnostic
60304Diagnostic
60305Diagnostic
60306Diagnostic
60307Diagnostic
60308Diagnostic
60309Diagnostic
60310Diagnostic
60311Diagnostic
60312Diagnostic
60401Diagnostic
60501Diagnostic
60503Diagnostic
60601Diagnostic
60603Diagnostic
60604Diagnostic
60605Diagnostic
60606Diagnostic
60607Diagnostic
60609Diagnostic
60610Diagnostic
60611Diagnostic
60612Diagnostic
60613Diagnostic
60614Diagnostic
60615Diagnostic
60616Diagnostic
60617Diagnostic
60618Diagnostic
60619Diagnostic
60620Diagnostic
60621Diagnostic
60622Diagnostic
60623Diagnostic
60624Diagnostic
60625Diagnostic
60626Diagnostic
60627Diagnostic
60628Diagnostic
60629Diagnostic
60631Diagnostic
60632Diagnostic
60633Diagnostic
60634Diagnostic
60635Diagnostic
60636Diagnostic
60637Diagnostic
60638Diagnostic
60639Diagnostic
60640Diagnostic
60641Diagnostic
60643Diagnostic
60644Diagnostic
60645Diagnostic
60646Diagnostic
60647Diagnostic
60648Diagnostic
60649Diagnostic
60650Diagnostic
60651Diagnostic
60652Diagnostic
60653Diagnostic
60655Diagnostic
60657Diagnostic
60659Diagnostic
60661Diagnostic
60701Diagnostic
60702Diagnostic
60705Diagnostic
60706Diagnostic
60707Diagnostic
60708Diagnostic
60709Diagnostic
60710Diagnostic
60711Diagnostic
60712Diagnostic
60713Diagnostic
60714Diagnostic
60715Diagnostic
60716Diagnostic
60751Diagnostic
60752Diagnostic
60753Diagnostic
60754Diagnostic
60755Diagnostic
60756Diagnostic
60757Diagnostic
60758Diagnostic
60759Diagnostic
60760Diagnostic
60801Diagnostic
60802Diagnostic
60803Diagnostic
60804Diagnostic
60805Diagnostic
60806Diagnostic
60807Diagnostic
60808Diagnostic
60809Diagnostic
60810Diagnostic
60811Diagnostic
60812Diagnostic
60813Diagnostic
60814Diagnostic
60815Diagnostic
60816Diagnostic
60817Diagnostic
60818Diagnostic
60819Diagnostic
60820Diagnostic
60821Diagnostic
60822Diagnostic
60823Diagnostic
60824Diagnostic
60825Diagnostic
60826Diagnostic
60901Diagnostic
60902Diagnostic
60903Diagnostic
60904Diagnostic
60905Diagnostic
60906Diagnostic
60907Diagnostic
60908Diagnostic
60909Diagnostic
60910Diagnostic
60911Diagnostic
60912Diagnostic
60913Diagnostic
60914Diagnostic
60915Diagnostic
61001Diagnostic
61002Diagnostic
61003Diagnostic
61004Diagnostic
61005Diagnostic
61006Diagnostic
61201Diagnostic
61202Diagnostic
61203Diagnostic
61204Diagnostic
61205Diagnostic
61206Diagnostic
61210Diagnostic
61211Diagnostic
61212Diagnostic
61213Diagnostic
61214Diagnostic
61220Diagnostic
61221Diagnostic
61301Diagnostic
61302Diagnostic
61303Diagnostic
61320Diagnostic
61321Diagnostic
61322Diagnostic
61323Diagnostic
61324Diagnostic
61325Diagnostic
61326Diagnostic
61327Diagnostic
61340Diagnostic
61341Diagnostic
61342Diagnostic
61343Diagnostic
61344Diagnostic
61345Diagnostic
61346Diagnostic
61347Diagnostic
61348Diagnostic
61349Diagnostic
61350Diagnostic
61351Diagnostic
61352Diagnostic
61353Diagnostic
61354Diagnostic
61355Diagnostic
61356Diagnostic
61357Diagnostic
61358Diagnostic
61360Diagnostic
61361Diagnostic
61364Diagnostic
61365Diagnostic
61366Diagnostic
61367Diagnostic
61368Diagnostic
61369Diagnostic
61370Diagnostic
61371Diagnostic
61372Diagnostic
61373Diagnostic
61374Diagnostic
61375Diagnostic
61376Diagnostic
61377Diagnostic
61380Diagnostic
61381Diagnostic
61386Diagnostic
61387Diagnostic
61390Diagnostic
61391Diagnostic
61400Diagnostic
61401Diagnostic
61410Diagnostic
61411Diagnostic
61412Diagnostic
61413Diagnostic
61414Diagnostic
61415Diagnostic
61420Diagnostic
61421Diagnostic
61422Diagnostic
61423Diagnostic
61424Diagnostic
61425Diagnostic
61426Diagnostic
61427Diagnostic
61428Diagnostic
61429Diagnostic
61430Diagnostic
61431Diagnostic
61432Diagnostic
61433Diagnostic
61434Diagnostic
61435Diagnostic
61436Diagnostic
61437Diagnostic
61438Diagnostic
61439Diagnostic
61440Diagnostic
61441Diagnostic
61442Diagnostic
61443Diagnostic
61444Diagnostic
61445Diagnostic
61446Diagnostic
61448Diagnostic
61449Diagnostic
61450Diagnostic
61451Diagnostic
61452Diagnostic
61453Diagnostic
61454Diagnostic
61455Diagnostic
61456Diagnostic
61457Diagnostic
61460Diagnostic
61461Diagnostic
61462Diagnostic
61463Diagnostic
61464Diagnostic
61465Diagnostic
61501Diagnostic
61502Diagnostic
61503Diagnostic
61504Diagnostic
61505Diagnostic
61506Diagnostic
61600Diagnostic
61601Diagnostic
61602Diagnostic
61603Diagnostic
61604Diagnostic
61605Diagnostic
61606Diagnostic
61607Diagnostic
61608Diagnostic
61609Diagnostic
61610Diagnostic
61611Diagnostic
61612Diagnostic
61613Diagnostic
61614Diagnostic
61615Diagnostic
61616Diagnostic
61617Diagnostic
61618Diagnostic
61619Diagnostic
61620Diagnostic
61621Diagnostic
61622Diagnostic
61623Diagnostic
61624Diagnostic
61625Diagnostic
61626Diagnostic
61627Diagnostic
61628Diagnostic
61629Diagnostic
61630Diagnostic
61631Diagnostic
61632Diagnostic
61633Diagnostic
61634Diagnostic
61635Diagnostic
61636Diagnostic
61637Diagnostic
61638Diagnostic
61639Diagnostic
61640Diagnostic
61641Diagnostic
61642Diagnostic
61643Diagnostic
61644Diagnostic
61645Diagnostic
61646Diagnostic
61647Diagnostic
61648Diagnostic
61649Diagnostic
61650Diagnostic
61651Diagnostic
61652Diagnostic
61653Diagnostic
62000Diagnostic
62001Diagnostic
62002Diagnostic
62003Diagnostic
62004Diagnostic
62020Diagnostic
62021Diagnostic
62022Diagnostic
62023Diagnostic
62024Diagnostic
62025Diagnostic
62026Diagnostic
62027Diagnostic
62028Diagnostic
62029Diagnostic
62030Diagnostic
62031Diagnostic
62032Diagnostic
62033Diagnostic
62050Diagnostic
62051Diagnostic
62052Diagnostic
62053Diagnostic
62054Diagnostic
62055Diagnostic
62056Diagnostic
62057Diagnostic
62058Diagnostic
62059Diagnostic
62060Diagnostic
62061Diagnostic
62062Diagnostic
62063Diagnostic
62064Diagnostic
62065Diagnostic
62066Diagnostic
62067Diagnostic
62068Diagnostic
62069Diagnostic
62070Diagnostic
62071Diagnostic
62072Diagnostic
62073Diagnostic
62074Diagnostic
62075Diagnostic
62076Diagnostic
62078Diagnostic
62079Diagnostic
62100Diagnostic
62120Diagnostic
62121Diagnostic
62122Diagnostic
62123Diagnostic
62124Diagnostic
62125Diagnostic
62126Diagnostic
62127Diagnostic
62128Diagnostic
62129Diagnostic
62130Diagnostic
62131Diagnostic
62132Diagnostic
62133Diagnostic
62134Diagnostic
62135Diagnostic
62136Diagnostic
62137Diagnostic
62138Diagnostic
62139Diagnostic
62140Diagnostic
62141Diagnostic
62142Diagnostic
62143Diagnostic
62144Updating install state of package PackageFamilyName to 'InstallState' with …Operational
62145On commit, creation of shortcut with AppUserModelId AppUserModelID with HRESULT …Operational
62146On commit, update of shortcut with AppUserModelId AppUserModelID with HRESULT …Operational
62147On commit, deletion of shortcut with AppUserModelId AppUserModelID with HRESULT …Operational
62148On commit, creation of temporary shortcut with AppUserModelId AppUserModelID …Operational
62149On commit, changing property values in shortcut with AppUserModelId …Operational
62150On revert, creation of shortcut with AppUserModelId AppUserModelID with HRESULT …Operational
62151On revert, update of shortcut with AppUserModelId AppUserModelID with HRESULT …Operational
62152On revert, deletion of shortcut with AppUserModelId AppUserModelID with HRESULT …Operational
62153Removing folder for package PackageFamilyName with HRESULT ErrorCode.Operational
62154Incremented last write time of shortcut with AppUserModelId AppUserModelID by 2 …Operational
62155Updated lockscreen notifications badge registration of app with AppUserModelId …Operational
62156On revert, updated lockscreen notifications badge registration of app with …Operational
62157Removed lockscreen notifications badge registration of app with AppUserModelId …Operational
62158Updated lockscreen notifications tile registration of app with AppUserModelId …Operational
62159On revert, updated lockscreen notifications tile registration of app with …Operational
62160Removed lockscreen notifications tile registration of app with AppUserModelId …Operational
62161The namespace extension guid will be loaded in the File Picker.Diagnostic
62162The namespace extension guid will not be loaded in the File Picker.Diagnostic
62163Failed to merge PRI for Package PackageFamilyName at path Path with HRESULT …Operational
62164Package PackageFamilyName failed to install with HRESULT ErrorCode.Operational
62170Logon task 'TaskName' started with flags LogonType.Operational
62171Logon task 'TaskName' finished with flags LogonType.Operational
62200Failed to register for licensing policy change event.Diagnostic
62201Failed to create the watermark window.Diagnostic
62202Failed to render the watermark.Diagnostic
62203Failed to get genuine status.Diagnostic
62204Diagnostic
62205Diagnostic
62250Updated lockscreen alarm registration of app with AppUserModelId AppUserModelID …Operational
62251On revert, updated lockscreen alarm registration of app with AppUserModelId …Operational
62252Removed lockscreen alarm registration of app with AppUserModelId AppUserModelID …Operational
62300Diagnostic
62301Diagnostic
62302Diagnostic
62303Diagnostic
62320Diagnostic
62321Diagnostic
62322Diagnostic
62323Diagnostic
62324Diagnostic
62325Diagnostic
62326Diagnostic
62327Diagnostic
62328Diagnostic
62329Diagnostic
62330Diagnostic
62331Diagnostic
62332Diagnostic
62333Diagnostic
62334Diagnostic
62335Diagnostic
62336Diagnostic
62337Fileplaceholder hydration times out.Diagnostic
62380Diagnostic
62400CloudExperienceHost App Activity started.Operational
62401CloudExperienceHost App Activity stopped.Operational
62402CloudExperienceHost App Event 1.Operational
62403CloudExperienceHost App Event 2.Operational
62404CloudExperienceHost Web App Activity started.Operational
62405CloudExperienceHost Web App Activity stopped.Operational
62406CloudExperienceHost Web App Event 1.Operational
62407CloudExperienceHost Web App Event 2.Operational
62408Started execution of command 'Command'.Operational
62409Finished execution of command 'Command' (PID PID).Operational
62420Looking for Restore ProfilesLogonTasksChannel
62421Finished looking for Restore Profiles.LogonTasksChannel
62422Adding Profile.LogonTasksChannel
62423Set Restore Profile to Hardware Id: HardwareId.LogonTasksChannel
62440Hash mismatch detected for: ExtOrUriScheme.AppDefaults
62441User choice has been reset to prog id ProgId for ExtOrUriScheme.AppDefaults
62442Upgraded to prog id ProgId from prog id CurrentDefaultProgId for ExtOrUriScheme.AppDefaults
62443AppDefault Info: Info.AppDefaults
62444Missing Hash -- ProgId: ProgId FileExtOrUriScheme: ExtOrUriScheme.AppDefaults
62445Migration Info: Info.AppDefaults
62460OOBE Health Monitor.Operational
63200Application calls obsolete Shell APIs.ActionCenter

Event ID 1 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
AggregatePropertyProvider_GetValue
Opcode
Start

Fields #

NameDescription
FMTID GUID
PID UInt32

Event ID 2 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
AggregatePropertyProvider_GetValue
Opcode
Stop

Fields #

NameDescription
FMTID GUID
PID UInt32

Event ID 3 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
AggregatePropertyProvider_GetValueObject
Opcode
Start

Fields #

NameDescription
FMTID GUID
PID UInt32

Event ID 4 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
AggregatePropertyProvider_GetValueObject
Opcode
Stop

Fields #

NameDescription
FMTID GUID
PID UInt32

Event ID 101 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
AutoplayCPL_PopulateUI
Opcode
Start

Fields #

NameDescription
DeviceHandler UnicodeString

Event ID 102 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
AutoplayCPL_PopulateUI
Opcode
Stop

Fields #

NameDescription
DeviceHandler UnicodeString

Event ID 103 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
AutoplayCPL_Create
Opcode
Start

Event ID 104 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
AutoplayCPL_Create
Opcode
Stop

Event ID 105 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
AutoplayCPL_LayoutInitialized
Opcode
Start

Event ID 106 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
AutoplayCPL_LayoutInitialized
Opcode
Stop

Event ID 107 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DeskCPL_ShowDialog
Opcode
Start

Event ID 108 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DeskCPL_ShowDialog
Opcode
Stop

Event ID 109 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DeskCPL_ShowDialog

Event ID 110 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DeskCPL_ShowDialog

Event ID 111 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DeskCPL_DisplayDialog
Opcode
Start

Fields #

NameDescription
Command UnicodeString

Event ID 112 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DeskCPL_DisplayDialog
Opcode
Stop

Fields #

NameDescription
Command UnicodeString

Event ID 113 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
MainCPL_CPLAppletInvoked
Opcode
Start

Fields #

NameDescription
Message UInt32

Event ID 114 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
MainCPL_CPLAppletInvoked
Opcode
Stop

Fields #

NameDescription
Message UInt32

Event ID 115 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
MainCPL_DialogPaint

Fields #

NameDescription
Message UInt32

Event ID 501 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
AutoListEditor_Controls_Rendering
Opcode
Start

Event ID 502 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
AutoListEditor_Controls_Rendering
Opcode
Stop

Event ID 503 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
AutoListEditor_FilterConditions_Rendering
Opcode
Start

Event ID 504 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
AutoListEditor_FilterConditions_Rendering
Opcode
Stop

Event ID 505 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
AutoListEditor_Filter_ChangeNotify
Opcode
Start

Event ID 506 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
AutoListEditor_Filter_ChangeNotify
Opcode
Stop

Event ID 507 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
AutoListEditor_Filters_Rendering
Opcode
Start

Event ID 508 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
AutoListEditor_Filters_Rendering
Opcode
Stop

Event ID 509 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
AutoListEditor_Scopes_Rendering
Opcode
Start

Event ID 510 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
AutoListEditor_Scopes_Rendering
Opcode
Stop

Event ID 1001 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
AutoLists_QueryDefaultLocation
Opcode
Start

Event ID 1002 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
AutoLists_QueryDefaultLocation
Opcode
Stop

Event ID 1003 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
AutoLists_QueryResultsDisplayed
Opcode
Start

Event ID 1004 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
AutoLists_QueryResultsDisplayed
Opcode
Stop

Event ID 1005 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
AutoLists_QueryResultsExecuted
Opcode
Start

Event ID 1006 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
AutoLists_QueryResultsExecuted
Opcode
Stop

Event ID 1007 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
AutoLists_QueryResultsStacked
Opcode
Start

Event ID 1008 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
AutoLists_QueryResultsStacked
Opcode
Stop

Event ID 1011 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
AutoLists_GetRemoteFolderPath
Opcode
Start

Event ID 1012 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
AutoLists_GetRemoteFolderPath
Opcode
Stop

Event ID 1013 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
AutoLists_LoadFromXML
Opcode
Start

Event ID 1014 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
AutoLists_LoadFromXML
Opcode
Stop

Event ID 1015 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
AutoLists_LoadFromStream
Opcode
Start

Event ID 1016 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
AutoLists_LoadFromStream
Opcode
Stop

Event ID 1017 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
AutoLists_LoadComponentChain
Opcode
Start

Event ID 1018 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
AutoLists_LoadComponentChain
Opcode
Stop

Event ID 1019 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
AutoLists_GetWorkgroupNetInfo
Opcode
Start

Event ID 1020 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
AutoLists_GetWorkgroupNetInfo
Opcode
Stop

Event ID 1021 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
AutoLists_MSSQuery
Opcode
Start

Fields #

NameDescription
MaxResults UInt32
Query UnicodeString

Event ID 1022 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
AutoLists_MSSQuery
Opcode
Stop

Fields #

NameDescription
MaxResults UInt32
Query UnicodeString

Event ID 1023 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
AutoLists_ProcessNextBatch
Opcode
Start

Event ID 1024 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
AutoLists_ProcessNextBatch
Opcode
Stop

Event ID 1025 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
AutoLists_MergeEnumToView
Opcode
Start

Event ID 1026 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
AutoLists_MergeEnumToView
Opcode
Stop

Event ID 1027 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
AutoLists_MSSQueryAddResultsToQueue
Opcode
Start

Event ID 1028 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
AutoLists_MSSQueryAddResultsToQueue
Opcode
Stop

Fields #

NameDescription
Count UInt32

Event ID 1029 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
InfoBar_Click_Count_AddToIndex

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmDWORDDatapointValue UInt32

Event ID 1033 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
InfoBar_Display_Count_Indexer_Busy

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmDWORDDatapointValue UInt32

Event ID 1035 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
InfoBar_Display_Count_Indexer_Disabled

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmDWORDDatapointValue UInt32

Event ID 1037 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
InfoBar_NonIndexed_Location_Count

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmStreamRowLength UInt32
SqmStreamRow Int16

Event ID 1038 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DataLayer_CreateResultSets
Opcode
Start

Event ID 1039 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DataLayer_CreateResultSets
Opcode
Stop

Event ID 1040 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DataLayer_CreateSession
Opcode
Start

Fields #

NameDescription
HandlerId GUID

Event ID 1041 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DataLayer_CreateSession
Opcode
Stop

Fields #

NameDescription
HandlerId GUID

Event ID 1042 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DataLayer_CreateCommand
Opcode
Start

Fields #

NameDescription
HandlerId GUID

Event ID 1043 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DataLayer_CreateCommand
Opcode
Stop

Fields #

NameDescription
HandlerId GUID

Event ID 1044 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DataLayer_CommandExecute
Opcode
Start

Fields #

NameDescription
HandlerId GUID
fReuse UInt32

Event ID 1045 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DataLayer_CommandExecute
Opcode
Stop

Fields #

NameDescription
HandlerId GUID

Event ID 1046 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DataLayer_RowsetGetCount
Opcode
Start

Fields #

NameDescription
Value UInt32

Event ID 1047 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DataLayer_RowsetGetCount
Opcode
Stop

Fields #

NameDescription
Count UInt32

Event ID 1048 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DataLayer_RowsetGetRows
Opcode
Start

Fields #

NameDescription
ProviderId GUID
Index UInt32
Count UInt32

Event ID 1049 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DataLayer_RowsetGetRows
Opcode
Stop

Fields #

NameDescription
Count UInt32

Event ID 1050 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DataLayer_RowsetGetData
Opcode
Start

Event ID 1051 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DataLayer_RowsetGetData
Opcode
Stop

Event ID 1054 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DataLayer_ItemBindHandler
Opcode
Start

Fields #

NameDescription
HandlerId GUID

Event ID 1055 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DataLayer_ItemBindHandler
Opcode
Stop

Fields #

NameDescription
HandlerId GUID

Event ID 1056 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DataLayer_ExtractProperties
Opcode
Start

Event ID 1057 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DataLayer_ExtractProperties
Opcode
Stop

Event ID 1058 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DataLayer_RowsetGetReferencedRowset
Opcode
Start

Event ID 1059 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DataLayer_RowsetGetReferencedRowset
Opcode
Stop

Event ID 1062 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DataLayer_GetDataSourceProperties
Opcode
Start

Fields #

NameDescription
HandlerId GUID

Event ID 1063 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DataLayer_GetDataSourceProperties
Opcode
Stop

Fields #

NameDescription
HandlerId GUID

Event ID 1064 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DataLayer_SetDataSourceProperties
Opcode
Start

Fields #

NameDescription
HandlerId GUID

Event ID 1065 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DataLayer_SetDataSourceProperties
Opcode
Stop

Fields #

NameDescription
HandlerId GUID

Event ID 1066 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DataLayer_GetRowsetProperties
Opcode
Start

Event ID 1067 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DataLayer_GetRowsetProperties
Opcode
Stop

Event ID 1068 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DataLayer_RowsetFindIndex
Opcode
Start

Event ID 1069 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DataLayer_RowsetFindIndex
Opcode
Stop

Event ID 1070 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DataLayer_RowsetCountForGroup
Opcode
Start

Event ID 1071 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DataLayer_RowsetCountForGroup
Opcode
Stop

Fields #

NameDescription
Count UInt32

Event ID 1072 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DataLayer_CollectionImmediateIndex
Opcode
Start

Event ID 1073 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DataLayer_CollectionImmediateIndex
Opcode
Stop

Fields #

NameDescription
Index UInt32

Event ID 1074 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DataLayer_CollectionLeafIndex
Opcode
Start

Event ID 1075 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DataLayer_CollectionLeafIndex
Opcode
Stop

Fields #

NameDescription
iGroup UInt32
iItem UInt32

Event ID 1076 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DataLayer_RSMImmediateIndex
Opcode
Start

Event ID 1077 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DataLayer_RSMImmediateIndex
Opcode
Stop

Fields #

NameDescription
Index UInt32

Event ID 1078 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DataLayer_RSMLeafIndex
Opcode
Start

Event ID 1079 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DataLayer_RSMLeafIndex
Opcode
Stop

Fields #

NameDescription
iGroup UInt32
iItem UInt32

Event ID 1080 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DataLayer_CollectionMemberOfGroup
Opcode
Start

Event ID 1081 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DataLayer_CollectionMemberOfGroup
Opcode
Stop

Event ID 1082 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DataLayer_CollectionCount
Opcode
Start

Fields #

NameDescription
Type UInt32

Event ID 1083 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DataLayer_CollectionCount
Opcode
Stop

Fields #

NameDescription
Type UInt32
Count UInt32
State UInt32

Event ID 1084 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DataLayer_CollectionCountCached

Fields #

NameDescription
Type UInt32

Event ID 1085 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DataLayer_CollectionCountTaskPending

Fields #

NameDescription
Type UInt32

Event ID 1086 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DataLayer_CountTask
Opcode
Start

Fields #

NameDescription
Type UInt32

Event ID 1087 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DataLayer_CountTask
Opcode
Stop

Fields #

NameDescription
Type UInt32
HRESULT UInt32
Count UInt32
fWaitingOnRealization UInt32

Event ID 1088 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DataLayer_CountTaskQueued

Fields #

NameDescription
Type UInt32

Event ID 1089 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DataLayer_CountTaskCancelled

Fields #

NameDescription
Type UInt32

Event ID 1090 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DataLayer_CollectionGetItem
Opcode
Start

Fields #

NameDescription
Index UInt32
Version UInt32

Event ID 1091 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DataLayer_CollectionGetItem
Opcode
Stop

Fields #

NameDescription
Index UInt32
Version UInt32

Event ID 1092 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DataLayer_CollectionGetResultCached

Fields #

NameDescription
Index UInt32
Version UInt32

Event ID 1093 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DataLayer_GetResultTask
Opcode
Start

Fields #

NameDescription
Index UInt32
Version UInt32

Event ID 1094 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DataLayer_GetResultTask
Opcode
Stop

Fields #

NameDescription
Index UInt32
Version UInt32

Event ID 1095 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DataLayer_GetResultTaskQueued

Fields #

NameDescription
Index UInt32
Version UInt32

Event ID 1096 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DataLayer_GetResultTaskCancelled

Fields #

NameDescription

Event ID 1097 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DataLayer_RSMNotification
Opcode
Start

Fields #

NameDescription
Event UInt32

Event ID 1098 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DataLayer_RSMNotification
Opcode
Stop

Fields #

NameDescription
Event UInt32

Event ID 1099 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DataLayer_RSMNotificationArrival

Fields #

NameDescription
Event UInt32

Event ID 1100 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DataLayer_RSMRealization
Opcode
Start

Fields #

NameDescription
Index UInt32
Version UInt32

Event ID 1101 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DataLayer_RSMRealization
Opcode
Stop

Fields #

NameDescription
Index UInt32
Version UInt32

Event ID 1102 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DataLayer_RSMRealizationCancelled

Event ID 1103 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DataLayer_RSMRealization

Fields #

NameDescription
Index UInt32
Version UInt32

Event ID 1104 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DataLayer_RSMGetGroupManager
Opcode
Start

Event ID 1105 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DataLayer_RSMGetGroupManager
Opcode
Stop

Event ID 1106 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DataLayer_ResultSetRealize
Opcode
Start

Fields #

NameDescription
Value UInt32

Event ID 1107 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DataLayer_ResultSetRealize
Opcode
Stop

Event ID 1108 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DataLayer_ResultSetProcessBatch
Opcode
Start

Fields #

NameDescription
Count UInt32

Event ID 1109 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DataLayer_ResultSetProcessBatch
Opcode
Stop

Fields #

NameDescription
Count UInt32

Event ID 1110 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DataLayer_ResultSetEnum
Opcode
Start

Event ID 1111 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DataLayer_ResultSetEnum
Opcode
Stop

Event ID 1112 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DataLayer_ResultSetWaitForResults
Opcode
Start

Event ID 1113 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DataLayer_ResultSetWaitForResults
Opcode
Stop

Fields #

NameDescription
Count UInt32

Event ID 1114 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DataLayer_ResultSetFilterResults
Opcode
Start

Fields #

NameDescription
Count UInt32

Event ID 1115 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DataLayer_ResultSetFilterResults
Opcode
Stop

Fields #

NameDescription
Count UInt32

Event ID 1116 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DataLayer_ResultSetSortResults
Opcode
Start

Fields #

NameDescription
Count UInt32

Event ID 1117 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DataLayer_ResultSetSortResults
Opcode
Stop

Event ID 1118 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DataLayer_ResultSetGroupResults
Opcode
Start

Fields #

NameDescription
Count UInt32

Event ID 1119 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DataLayer_ResultSetGroupResults
Opcode
Stop

Event ID 1120 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DataLayer_ResultSetMergeBatch
Opcode
Start

Fields #

NameDescription
Count UInt32

Event ID 1121 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DataLayer_ResultSetMergeBatch
Opcode
Stop

Fields #

NameDescription
Count UInt32

Event ID 1122 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DataLayer_GenerateSnippet
Opcode
Start

Event ID 1123 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DataLayer_GenerateSnippet
Opcode
Stop

Event ID 1124 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DataLayer_CalculateStackThumbnailCacheId
Opcode
Start

Event ID 1125 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DataLayer_CalculateStackThumbnailCacheId
Opcode
Stop

Event ID 1126 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DataLayer_BuildStackThumbnail
Opcode
Start

Event ID 1127 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DataLayer_BuildStackThumbnail
Opcode
Stop

Event ID 1128 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DataLayer_ReuseFirstBatch
Opcode
Start

Fields #

NameDescription
Count UInt32

Event ID 1129 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DataLayer_ReuseFirstBatch
Opcode
Stop

Event ID 1130 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DataLayer_ReuseCached
Opcode
Start

Fields #

NameDescription
Count UInt32

Event ID 1131 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DataLayer_ReuseCached
Opcode
Stop

Event ID 1132 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DataLayer_StackThumbnails_Rendering
Opcode
Start

Event ID 1133 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DataLayer_StackThumbnails_Rendering
Opcode
Stop

Event ID 1134 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DataLayer_StackThumbnails_PickPictures
Opcode
Start

Event ID 1135 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DataLayer_StackThumbnails_PickPictures
Opcode
Stop

Event ID 1140 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DataLayer_GetRowsAt
Opcode
Start

Event ID 1141 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DataLayer_GetRowsAt
Opcode
Stop

Event ID 1142 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DataLayer_GetRowFromHROW
Opcode
Start

Event ID 1143 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DataLayer_GetRowFromHROW
Opcode
Stop

Event ID 1144 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DataLayer_ItemRealizeItem
Opcode
Start

Event ID 1145 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DataLayer_ItemRealizeItem
Opcode
Stop

Event ID 1146 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DataLayer_ItemCompareItem
Opcode
Start

Event ID 1147 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DataLayer_ItemCompareItem
Opcode
Stop

Event ID 1148 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DataLayer_ItemCompareItemIdentity
Opcode
Start

Event ID 1149 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DataLayer_ItemCompareItemIdentity
Opcode
Stop

Event ID 1150 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DataLayer_ItemGetValue
Opcode
Start

Event ID 1151 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DataLayer_ItemGetValue
Opcode
Stop

Event ID 1152 —

Provider
Microsoft-Windows-Shell-Core
Channel
Operational
Task
DataLayer_AppItemsStateModifyCommitFailure

Fields #

NameDescription
HRESULT UInt32

Event ID 1401 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
OpenSearch_RowsetInitialize
Opcode
Start

Event ID 1402 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
OpenSearch_RowsetInitialize
Opcode
Stop

Event ID 1403 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
OpenSearch_GetRowsAt
Opcode
Start

Event ID 1404 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
OpenSearch_GetRowsAt
Opcode
Stop

Event ID 1405 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
OpenSearch_FillCachedPage
Opcode
Start

Event ID 1406 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
OpenSearch_FillCachedPage
Opcode
Stop

Event ID 1409 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
OpenSearch_NormalizeResultsPage
Opcode
Start

Event ID 1410 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
OpenSearch_NormalizeResultsPage
Opcode
Stop

Event ID 1411 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
OpenSearch_ParseResultsPage
Opcode
Start

Event ID 1412 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
OpenSearch_ParseResultsPage
Opcode
Stop

Event ID 1413 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
OpenSearch_PreConnect
Opcode
Start

Event ID 1414 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
OpenSearch_PreConnect
Opcode
Stop

Event ID 1415 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
OpenSearch_Http_Response

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmDWORDDatapointValue UInt32

Event ID 1417 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
OpenSearch_Description_Installed

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmDWORDDatapointValue UInt32

Event ID 1419 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
OpenSearch_Provider_Queried

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmDWORDDatapointValue UInt32

Event ID 1500 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_UdfFormatter_FormatThread
Opcode
Start

Event ID 1501 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_UdfFormatter_FormatThread
Opcode
Stop

Event ID 1502 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
ShellTask_ShellLink_VerifyPathThread
Opcode
Start

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "1502",
    "version": "0",
    "level": "4",
    "task": "1502",
    "opcode": "1",
    "keywords": 9223372036854841344,
    "time_created": "2026-03-15T04:21:15.031275500+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "12840",
      "thread_id": "8672"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 1503 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
ShellTask_ShellLink_VerifyPathThread
Opcode
Stop

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "1503",
    "version": "0",
    "level": "4",
    "task": "1502",
    "opcode": "2",
    "keywords": 9223372036854841344,
    "time_created": "2026-03-15T04:21:15.032217300+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "12840",
      "thread_id": "8672"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 1504 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_RunDialog_CheckRunInSeparateThread
Opcode
Start

Event ID 1505 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_RunDialog_CheckRunInSeparateThread
Opcode
Stop

Event ID 1506 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_Restart_ShutdownThread
Opcode
Start

Event ID 1507 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_Restart_ShutdownThread
Opcode
Stop

Event ID 1508 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_MountPoint_RegisterThread
Opcode
Start

Event ID 1509 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_MountPoint_RegisterThread
Opcode
Stop

Event ID 1510 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_Format_FormatThread
Opcode
Start

Event ID 1511 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_Format_FormatThread
Opcode
Stop

Event ID 1512 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_FileFldr_GetFindDataThread
Opcode
Start

Event ID 1513 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_FileFldr_GetFindDataThread
Opcode
Stop

Event ID 1514 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_CloseSession_TipThread
Opcode
Start

Event ID 1515 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_CloseSession_TipThread
Opcode
Stop

Event ID 1518 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_UserLibrary_RestoreLibrariesThread
Opcode
Start

Event ID 1519 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_UserLibrary_RestoreLibrariesThread
Opcode
Stop

Event ID 1520 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_Options_SetupAndRunPropertySheetThread
Opcode
Start

Event ID 1521 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_Options_SetupAndRunPropertySheetThread
Opcode
Stop

Event ID 1522 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_Desktop_LocalServerThread
Opcode
Start

Event ID 1523 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_Desktop_LocalServerThread
Opcode
Stop

Event ID 1524 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_BackPropSheet_SizeCheckerThread
Opcode
Start

Event ID 1525 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_BackPropSheet_SizeCheckerThread
Opcode
Stop

Event ID 1526 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_Undo_UndoThread
Opcode
Start

Event ID 1527 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_Undo_UndoThread
Opcode
Stop

Event ID 1528 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_PropSheet_PropSheetThread
Opcode
Start

Event ID 1529 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_PropSheet_PropSheetThread
Opcode
Stop

Event ID 1530 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_PropSheet_FormatThread
Opcode
Start

Event ID 1531 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_PropSheet_FormatThread
Opcode
Stop

Event ID 1532 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_ShellLink_SearchThread
Opcode
Start

Event ID 1533 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_ShellLink_SearchThread
Opcode
Stop

Event ID 1534 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_Encrypt_EncryptThread
Opcode
Start

Event ID 1535 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_Encrypt_EncryptThread
Opcode
Stop

Event ID 1536 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_SDSPatch_FindPrinterThread
Opcode
Start

Event ID 1537 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_SDSPatch_FindPrinterThread
Opcode
Stop

Event ID 1538 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_ChangeNotify_ChangeNotifyThread
Opcode
Start

Event ID 1539 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_ChangeNotify_ChangeNotifyThread
Opcode
Stop

Event ID 1540 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
ShellTask_Schedule_ShellTaskThread
Opcode
Start

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "1540",
    "version": "0",
    "level": "4",
    "task": "1540",
    "opcode": "1",
    "keywords": 9223372036854841344,
    "time_created": "2026-03-15T04:20:38.452962100+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "12840",
      "thread_id": "13268"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 1541 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
ShellTask_Schedule_ShellTaskThread
Opcode
Stop

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "1541",
    "version": "0",
    "level": "4",
    "task": "1540",
    "opcode": "2",
    "keywords": 9223372036854841344,
    "time_created": "2026-03-15T04:20:18.682797800+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "12840",
      "thread_id": "11516"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 1542 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_RunAsNewUser_RunAsThread
Opcode
Start

Event ID 1543 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_RunAsNewUser_RunAsThread
Opcode
Stop

Event ID 1544 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_RichPreview_PreviewThread
Opcode
Start

Event ID 1545 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_RichPreview_PreviewThread
Opcode
Stop

Event ID 1546 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_PostBootReminder_ReminderThread
Opcode
Start

Event ID 1547 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_PostBootReminder_ReminderThread
Opcode
Stop

Event ID 1548 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_RegFldr_DisconnectDialogThread
Opcode
Start

Event ID 1549 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_RegFldr_DisconnectDialogThread
Opcode
Stop

Event ID 1550 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_ProgressDialog_DialogThread
Opcode
Start

Event ID 1551 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_ProgressDialog_DialogThread
Opcode
Stop

Event ID 1552 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_ProgressDialog_SyncDialogThread
Opcode
Start

Event ID 1553 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_ProgressDialog_SyncDialogThread
Opcode
Stop

Event ID 1554 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_PlacesFldr_RestoreFavoritesThread
Opcode
Start

Event ID 1555 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_PlacesFldr_RestoreFavoritesThread
Opcode
Stop

Event ID 1556 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_OtherUsersBarrier_WizardThread
Opcode
Start

Event ID 1557 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_OtherUsersBarrier_WizardThread
Opcode
Stop

Event ID 1558 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_OpenContainingMenu_InvokeThread
Opcode
Start

Event ID 1559 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_OpenContainingMenu_InvokeThread
Opcode
Stop

Event ID 1560 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_NamespaceWalk_AsyncWalkThread
Opcode
Start

Event ID 1561 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_NamespaceWalk_AsyncWalkThread
Opcode
Stop

Event ID 1562 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_NetApi_NetConnectThread
Opcode
Start

Event ID 1563 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_NetApi_NetConnectThread
Opcode
Stop

Event ID 1564 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_MulPropSheet_SizeThread
Opcode
Start

Event ID 1565 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_MulPropSheet_SizeThread
Opcode
Stop

Event ID 1566 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_MulPropSheet_ApplySingleThread
Opcode
Start

Event ID 1567 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_MulPropSheet_ApplySingleThread
Opcode
Stop

Event ID 1568 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_MulPropSheet_AppluMultipleThread
Opcode
Start

Event ID 1569 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_MulPropSheet_AppluMultipleThread
Opcode
Stop

Event ID 1570 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_MountPointLocal_EjectThread
Opcode
Start

Event ID 1571 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_MountPointLocal_EjectThread
Opcode
Stop

Event ID 1572 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_Autorun_AutorunPromptThread
Opcode
Start

Event ID 1573 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_Autorun_AutorunPromptThread
Opcode
Stop

Event ID 1574 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_MenuBand_FadeTaskThread
Opcode
Start

Event ID 1575 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_MenuBand_FadeTaskThread
Opcode
Stop

Event ID 1576 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_LinkProp_LinkCheckThread
Opcode
Start

Event ID 1577 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_LinkProp_LinkCheckThread
Opcode
Stop

Event ID 1578 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_Library_OpenLocationThread
Opcode
Start

Event ID 1579 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_Library_OpenLocationThread
Opcode
Stop

Event ID 1580 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_Library_RemoveLocationThread
Opcode
Start

Event ID 1581 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_Library_RemoveLocationThread
Opcode
Stop

Event ID 1582 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_Library_RunTaskThread
Opcode
Start

Event ID 1583 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_Library_RunTaskThread
Opcode
Stop

Event ID 1584 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_Library_SetPinUnpinThread
Opcode
Start

Event ID 1585 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_Library_SetPinUnpinThread
Opcode
Stop

Event ID 1586 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_Library_AddLocationThread
Opcode
Start

Event ID 1587 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_Library_AddLocationThread
Opcode
Stop

Event ID 1588 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_ItemHandlerCache_MessagePumpThread
Opcode
Start

Event ID 1589 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_ItemHandlerCache_MessagePumpThread
Opcode
Stop

Event ID 1590 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_FSDropTarget_DoDropThread
Opcode
Start

Event ID 1591 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_FSDropTarget_DoDropThread
Opcode
Stop

Event ID 1592 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_CheckDiskDialog_DialogThread
Opcode
Start

Event ID 1593 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_CheckDiskDialog_DialogThread
Opcode
Stop

Event ID 1594 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_Enum_EnumThread
Opcode
Start

Event ID 1595 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_Enum_EnumThread
Opcode
Stop

Event ID 1596 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_DrvX_MakeConnectionThread
Opcode
Start

Event ID 1597 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_DrvX_MakeConnectionThread
Opcode
Stop

Event ID 1598 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_DrvX_DrvSizeThread
Opcode
Start

Event ID 1599 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_DrvX_DrvSizeThread
Opcode
Stop

Event ID 1600 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_DefCM_DeleteItemsThread
Opcode
Start

Event ID 1601 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_DefCM_DeleteItemsThread
Opcode
Stop

Event ID 1602 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_CopyFGD_CopyThread
Opcode
Start

Event ID 1603 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_CopyFGD_CopyThread
Opcode
Stop

Event ID 1604 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_Collection_RealizeThread
Opcode
Start

Event ID 1605 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_Collection_RealizeThread
Opcode
Stop

Event ID 1606 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_CloseSession_CloseThread
Opcode
Start

Event ID 1607 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_CloseSession_CloseThread
Opcode
Stop

Event ID 1608 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_CDBurn_NotifyThread
Opcode
Start

Event ID 1609 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_CDBurn_NotifyThread
Opcode
Stop

Event ID 1610 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_CDBurn_DropThread
Opcode
Start

Event ID 1611 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_CDBurn_DropThread
Opcode
Stop

Event ID 1612 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_CDBurn_WizardThread
Opcode
Start

Event ID 1613 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_CDBurn_WizardThread
Opcode
Stop

Event ID 1614 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_CDBurn_EraseThread
Opcode
Start

Event ID 1615 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_CDBurn_EraseThread
Opcode
Stop

Event ID 1616 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_CDBurn_BurnThread
Opcode
Start

Event ID 1617 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_CDBurn_BurnThread
Opcode
Stop

Event ID 1618 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_BitBucket_DispatchThread
Opcode
Start

Event ID 1619 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_BitBucket_DispatchThread
Opcode
Stop

Event ID 1620 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_BitBucket_PurgeAllThread
Opcode
Start

Event ID 1621 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_BitBucket_PurgeAllThread
Opcode
Stop

Event ID 1622 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_AsyncInvoke_InvokeThread
Opcode
Start

Event ID 1623 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_AsyncInvoke_InvokeThread
Opcode
Stop

Event ID 1628 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_ResultSetFactory_EnumThread
Opcode
Start

Event ID 1629 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_ResultSetFactory_EnumThread
Opcode
Stop

Event ID 1630 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_IndexClusionCache_HandleNetworkPathThread
Opcode
Start

Event ID 1631 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_IndexClusionCache_HandleNetworkPathThread
Opcode
Stop

Event ID 1632 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_IndexClusionCache_HandlePathThread
Opcode
Start

Event ID 1633 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_IndexClusionCache_HandlePathThread
Opcode
Stop

Event ID 1634 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_Notify_StartupThread
Opcode
Start

Event ID 1635 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_Notify_StartupThread
Opcode
Stop

Event ID 1636 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_PublishedItems_EnumItemsThread
Opcode
Start

Event ID 1637 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_PublishedItems_EnumItemsThread
Opcode
Stop

Event ID 1640 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_Library_ShareUnshareLocationThread
Opcode
Start

Event ID 1641 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_Library_ShareUnshareLocationThread
Opcode
Stop

Event ID 1642 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_ItemHandler_GetHandlerThread
Opcode
Start

Event ID 1643 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_ItemHandler_GetHandlerThread
Opcode
Stop

Event ID 1644 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_ItemHandler_SetHandlerThread
Opcode
Start

Event ID 1645 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_ItemHandler_SetHandlerThread
Opcode
Stop

Event ID 1646 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_SearchHelpers_InitIndexDataThread
Opcode
Start

Event ID 1647 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_SearchHelpers_InitIndexDataThread
Opcode
Stop

Event ID 1648 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_SearchHelpers_CheckCrawlScopeThread
Opcode
Start

Event ID 1649 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_SearchHelpers_CheckCrawlScopeThread
Opcode
Stop

Event ID 1650 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_Library_CommitScopeChangesThread
Opcode
Start

Event ID 1651 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_Library_CommitScopeChangesThread
Opcode
Stop

Event ID 1652 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_ItemsView_SendReentrancyReportThread
Opcode
Start

Event ID 1653 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_ItemsView_SendReentrancyReportThread
Opcode
Stop

Event ID 1654 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_MtPtRemote_UpdateInfoThread
Opcode
Start

Event ID 1655 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_MtPtRemote_UpdateInfoThread
Opcode
Stop

Event ID 1656 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
ShellTask_Timeout_CallwithTimeoutThread
Opcode
Start

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "1656",
    "version": "0",
    "level": "4",
    "task": "1656",
    "opcode": "1",
    "keywords": 9223372036854841344,
    "time_created": "2026-03-16T00:21:39.181590000+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "5680",
      "thread_id": "11272"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 1657 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
ShellTask_Timeout_CallwithTimeoutThread
Opcode
Stop

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "1657",
    "version": "0",
    "level": "4",
    "task": "1656",
    "opcode": "2",
    "keywords": 9223372036854841344,
    "time_created": "2026-03-16T00:21:39.182071900+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "5680",
      "thread_id": "11272"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 1658 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_ShellBrowser_CancelNavigationReportThread
Opcode
Start

Event ID 1659 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_ShellBrowser_CancelNavigationReportThread
Opcode
Stop

Event ID 1660 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_PerfTrack_LogStartEventThread
Opcode
Start

Event ID 1661 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_PerfTrack_LogStartEventThread
Opcode
Stop

Event ID 1662 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_WSDPublisher_PublishMessageThread
Opcode
Start

Event ID 1663 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_WSDPublisher_PublishMessageThread
Opcode
Stop

Event ID 1664 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_WSDPublisher_CleanUpThread
Opcode
Start

Event ID 1665 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_WSDPublisher_CleanUpThread
Opcode
Stop

Event ID 1666 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_WSDPublisher_InitThread
Opcode
Start

Event ID 1667 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_WSDPublisher_InitThread
Opcode
Stop

Event ID 1668 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_ShellUrl_AsyncParseThread
Opcode
Start

Event ID 1669 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_ShellUrl_AsyncParseThread
Opcode
Stop

Event ID 1672 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_RecycleBin_CompactAndPurgeThread
Opcode
Start

Event ID 1673 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_RecycleBin_CompactAndPurgeThread
Opcode
Stop

Event ID 1674 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_PublishedItems_UpdatePublishedItemsThread
Opcode
Start

Event ID 1675 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_PublishedItems_UpdatePublishedItemsThread
Opcode
Stop

Event ID 1676 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_PublishedItems_UpdateLibrariesThread
Opcode
Start

Event ID 1677 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_PublishedItems_UpdateLibrariesThread
Opcode
Stop

Event ID 1678 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_PrivateProfile_AsyncUpdateCacheThread
Opcode
Start

Event ID 1679 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_PrivateProfile_AsyncUpdateCacheThread
Opcode
Stop

Event ID 1680 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_MultiComplete_WorkThread
Opcode
Start

Event ID 1681 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_MultiComplete_WorkThread
Opcode
Stop

Event ID 1682 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
ShellTask_MountPoint_InitLocalDriveThread
Opcode
Start

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "1682",
    "version": "0",
    "level": "4",
    "task": "1682",
    "opcode": "1",
    "keywords": 9223372036854841344,
    "time_created": "2026-03-16T00:21:39.181373700+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "5680",
      "thread_id": "4384"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 1683 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
ShellTask_MountPoint_InitLocalDriveThread
Opcode
Stop

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "1683",
    "version": "0",
    "level": "4",
    "task": "1682",
    "opcode": "2",
    "keywords": 9223372036854841344,
    "time_created": "2026-03-16T00:21:39.187943800+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "5680",
      "thread_id": "4384"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 1684 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_Library_UpdateLocationSupportStatusThread
Opcode
Start

Event ID 1685 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_Library_UpdateLocationSupportStatusThread
Opcode
Stop

Event ID 1686 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_LowDisk_WorkThread
Opcode
Start

Event ID 1687 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_LowDisk_WorkThread
Opcode
Stop

Event ID 1688 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
ShellTask_LowDisk_CheckDiskSpaceThread
Opcode
Start

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "1688",
    "version": "0",
    "level": "4",
    "task": "1688",
    "opcode": "1",
    "keywords": 9223372036854841344,
    "time_created": "2026-03-15T04:21:00.138341600+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "12840",
      "thread_id": "13176"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 1689 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
ShellTask_LowDisk_CheckDiskSpaceThread
Opcode
Stop

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "1689",
    "version": "0",
    "level": "4",
    "task": "1688",
    "opcode": "2",
    "keywords": 9223372036854841344,
    "time_created": "2026-03-15T04:21:00.141903300+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "12840",
      "thread_id": "13176"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 1690 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_Library_UpdateScopeOnRenameThread
Opcode
Start

Event ID 1691 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_Library_UpdateScopeOnRenameThread
Opcode
Stop

Event ID 1692 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_Library_GetLibraryDescriptionThread
Opcode
Start

Event ID 1693 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_Library_GetLibraryDescriptionThread
Opcode
Stop

Event ID 1694 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_Library_ValidateAndResolveLocationsThread
Opcode
Start

Event ID 1695 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_Library_ValidateAndResolveLocationsThread
Opcode
Stop

Event ID 1696 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_EnumFiles_CheckDiskForInsertThread
Opcode
Start

Event ID 1697 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_EnumFiles_CheckDiskForInsertThread
Opcode
Stop

Event ID 1698 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
ShellTask_SearchIndexNotificationsQueue_FlushNotificationsThread
Opcode
Start

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "1698",
    "version": "0",
    "level": "4",
    "task": "1698",
    "opcode": "1",
    "keywords": 9223372036854841344,
    "time_created": "2026-03-15T04:20:38.371230500+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "12840",
      "thread_id": "13268"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 1699 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
ShellTask_SearchIndexNotificationsQueue_FlushNotificationsThread
Opcode
Stop

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "1699",
    "version": "0",
    "level": "4",
    "task": "1698",
    "opcode": "2",
    "keywords": 9223372036854841344,
    "time_created": "2026-03-15T04:20:38.373954100+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "12840",
      "thread_id": "13268"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 1700 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_BitBucket_UpdateRecycleBinIconThread
Opcode
Start

Event ID 1701 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_BitBucket_UpdateRecycleBinIconThread
Opcode
Stop

Event ID 1702 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_AutoPlay_ProcessDevicesEventsThread
Opcode
Start

Event ID 1703 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_AutoPlay_ProcessDevicesEventsThread
Opcode
Stop

Event ID 1704 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_ACThread_GenerationCompletionListThread
Opcode
Start

Event ID 1705 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_ACThread_GenerationCompletionListThread
Opcode
Stop

Event ID 1706 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_CollectionLock_AddTaskTimerThread
Opcode
Start

Event ID 1707 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_CollectionLock_AddTaskTimerThread
Opcode
Stop

Event ID 1708 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_ShellExecute_ExecuteThread
Opcode
Start

Event ID 1709 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_ShellExecute_ExecuteThread
Opcode
Stop

Event ID 1710 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_ExecUnknown_InstallAppThread
Opcode
Start

Event ID 1711 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_ExecUnknown_InstallAppThread
Opcode
Stop

Event ID 1712 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_InvokeCommand_DoInvokeThread
Opcode
Start

Event ID 1713 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_InvokeCommand_DoInvokeThread
Opcode
Stop

Event ID 1714 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_ProfsvcPostBootReminder_ReminderThread
Opcode
Start

Event ID 1715 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_ProfsvcPostBootReminder_ReminderThread
Opcode
Stop

Event ID 2001 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Browseui_CBrowserFrame_CreateInstance
Opcode
Start

Event ID 2002 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Browseui_CBrowserFrame_CreateInstance
Opcode
Stop

Event ID 2003 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Browseui_CBrowserFrame_Close
Opcode
Start

Event ID 2004 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Browseui_CBrowserFrame_Close
Opcode
Stop

Event ID 2005 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Browseui_FeedViewer_PreviewStream
Opcode
Start

Event ID 2006 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Browseui_FeedViewer_PreviewStream
Opcode
Stop

Event ID 2007 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Browseui_Tabs_CloseTab
Opcode
Start

Event ID 2008 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Browseui_Tabs_CloseTab
Opcode
Stop

Event ID 2009 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Browseui_Tabs_SwitchTabs
Opcode
Start

Event ID 2010 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Browseui_Tabs_SwitchTabs
Opcode
Stop

Event ID 2011 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Browseui_Tabs_CloseOtherTabs
Opcode
Start

Event ID 2012 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Browseui_Tabs_CloseOtherTabs
Opcode
Stop

Event ID 2013 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Browseui_SHOpenFolderWindow
Opcode
Start

Event ID 2014 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Browseui_SHOpenFolderWindow
Opcode
Stop

Event ID 2015 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Browseui_FrameMessagePump_Return

Event ID 2017 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Browseui_FrameMessagePump_Back

Event ID 2019 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Browseui_FrameMessagePump_Next

Event ID 2021 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Browseui_FrameMessagePump_Prior

Event ID 2022 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Browseui_FrameMessagePump_KeyDown

Fields #

NameDescription
Message UInt32

Event ID 2023 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Browseui_FrameMessagePump_LButtonAction

Fields #

NameDescription
Message UInt32

Event ID 2024 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Browseui_FrameMessagePump_RButtonAction

Fields #

NameDescription
Message UInt32

Event ID 2025 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Browseui_Tabs_AddTabButton

Event ID 2027 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Browseui_Tabs_TabReadyForNavigate

Event ID 2029 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Browseui_Tabs_AddTabAPI

Event ID 2031 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Browseui_CAddressEditBox_OnEndEditA

Event ID 2033 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Browseui_Breadcrumb_Dropdown_Click

Event ID 2035 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Browseui_Breadcrumb_Dropdown_Show

Event ID 2037 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Browseui_WndProcBS_Restore

Event ID 2039 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Browseui_WndProcBS_Minimize

Event ID 2041 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Browseui_WndProcBS_Maximize

Event ID 2043 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Browseui_CShellBrowser2_BrowseObject

Event ID 2045 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Browseui_Back_Button_Clicked

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmDWORDDatapointValue UInt32

Event ID 2047 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Browseui_Forward_Button_Clicked

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmDWORDDatapointValue UInt32

Event ID 2049 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Browseui_NavBar_CreateBands
Opcode
Start

Event ID 2050 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Browseui_NavBar_CreateBands
Opcode
Stop

Event ID 2051 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Browseui_AddressBand_PositionChildWindows
Opcode
Start

Event ID 2052 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Browseui_AddressBand_PositionChildWindows
Opcode
Stop

Event ID 2053 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Browseui_SearchControl_PositionChildWindows
Opcode
Start

Event ID 2054 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Browseui_SearchControl_PositionChildWindows
Opcode
Stop

Event ID 2055 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Browseui_AddressBand_OnBackgroundStateChanged
Opcode
Start

Event ID 2056 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Browseui_AddressBand_OnBackgroundStateChanged
Opcode
Stop

Event ID 2057 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Browseui_AutoComplete_StartCompletion
Opcode
Start

Fields #

NameDescription
Path UnicodeString

Event ID 2058 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Browseui_AutoComplete_StartCompletion
Opcode
Stop

Fields #

NameDescription
Path UnicodeString

Event ID 2059 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Browseui_AutoComplete_UpdateCompletion
Opcode
Start

Fields #

NameDescription
Path UnicodeString

Event ID 2060 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Browseui_AutoComplete_UpdateCompletion
Opcode
Stop

Fields #

NameDescription
Path UnicodeString

Event ID 2061 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Browseui_AutoComplete_StartSearch
Opcode
Start

Fields #

NameDescription
Path UnicodeString

Event ID 2062 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Browseui_AutoComplete_StartSearch
Opcode
Stop

Fields #

NameDescription
Path UnicodeString

Event ID 2063 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Browseui_AutoComplete_OnSearchComplete
Opcode
Start

Fields #

NameDescription
Path UnicodeString

Event ID 2064 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Browseui_AutoComplete_OnSearchComplete
Opcode
Stop

Fields #

NameDescription
Path UnicodeString

Event ID 2065 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Browseui_AddressEditBox_ParsePath
Opcode
Start

Fields #

NameDescription
Path UnicodeString

Event ID 2066 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Browseui_AddressEditBox_ParsePath
Opcode
Stop

Event ID 2067 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Browseui_FrameMessagePump_Activate

Fields #

NameDescription
Value UInt32

Event ID 2069 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Browseui_Browser_Navigate
Opcode
Start

Event ID 2070 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Browseui_Browser_Navigate
Opcode
Stop

Event ID 2071 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Browseui_Breadcrumb_RebuildToolbar
Opcode
Start

Event ID 2072 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Browseui_Breadcrumb_RebuildToolbar
Opcode
Stop

Event ID 3001 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ComCtl32_CommandLinks_Create
Opcode
Start

Event ID 3002 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ComCtl32_CommandLinks_Create
Opcode
Stop

Event ID 3003 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ComCtl32_CommandLinks_Rendering
Opcode
Start

Event ID 3004 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ComCtl32_CommandLinks_Rendering
Opcode
Stop

Event ID 3005 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
Comctl32_ImageList_Draw
Opcode
Start

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "3005",
    "version": "0",
    "level": "4",
    "task": "4005",
    "opcode": "1",
    "keywords": 9223372036854841344,
    "time_created": "2026-03-15T04:20:18.461884100+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "12840",
      "thread_id": "4760"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 3006 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
Comctl32_ImageList_Draw
Opcode
Stop

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "3006",
    "version": "0",
    "level": "4",
    "task": "4005",
    "opcode": "2",
    "keywords": 9223372036854841344,
    "time_created": "2026-03-15T04:20:18.461897000+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "12840",
      "thread_id": "4760"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 3007 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ComCtl32_PropertyPage_CreatePropertySheetPage

Fields #

NameDescription
dwFlags UInt32
pszTemplate UnicodeString

Event ID 3009 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ComCtl32_TaskDialog_Open
Opcode
Start

Event ID 3010 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ComCtl32_TaskDialog_Open
Opcode
Stop

Event ID 3011 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ComCtl32_Wizard_Open
Opcode
Start

Event ID 3012 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ComCtl32_Wizard_Open
Opcode
Stop

Event ID 3013 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ComCtl32_Wizard_UserDismiss
Opcode
Start

Event ID 3014 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ComCtl32_Wizard_UserDismiss
Opcode
Stop

Event ID 3015 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
Comctl32_ImageList_Rebuild
Opcode
Start

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "3015",
    "version": "0",
    "level": "4",
    "task": "4015",
    "opcode": "1",
    "keywords": 9223372036854841344,
    "time_created": "2026-03-15T04:20:51.145462700+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "10312",
      "thread_id": "14168"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 3016 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
Comctl32_ImageList_Rebuild
Opcode
Stop

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "3016",
    "version": "0",
    "level": "4",
    "task": "4015",
    "opcode": "2",
    "keywords": 9223372036854841344,
    "time_created": "2026-03-15T04:20:51.145464900+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "10312",
      "thread_id": "14168"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 4001 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
CTray_MessageLoop_LButtonAction

Fields #

NameDescription
Message UInt32

Event ID 4003 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
CTray_MessageLoop_Return

Event ID 4005 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
CTray_Responsiveness

Fields #

NameDescription
ThreadID UInt32
pszName UnicodeString

Event ID 4007 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
CTray_MessageLoop_Return

Fields #

NameDescription
FakeShutdownReason UInt32

Event ID 4008 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
CTray_MessageLoop_Return

Fields #

NameDescription
WParam UInt32
LParam UInt32

Event ID 4009 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
CTray_MessageLoop_Return

Event ID 5001 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Comdlg32_FileDialog_Ready
Opcode
Start

Event ID 5002 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Comdlg32_FileDialog_Ready
Opcode
Stop

Event ID 5003 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Comdlg32_FileDialog_FrameFirstVisible

Event ID 5004 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Comdlg32_FileDialog_FrameFirstRedraw
Opcode
Start

Event ID 5005 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Comdlg32_FileDialog_FrameFirstRedraw
Opcode
Stop

Event ID 6001 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
CommandModule_ChangeNotify
Opcode
Start

Event ID 6002 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
CommandModule_ChangeNotify
Opcode
Stop

Event ID 6201 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
Thumbnails_Extract
Opcode
Start

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "6201",
    "version": "0",
    "level": "4",
    "task": "6201",
    "opcode": "1",
    "keywords": 9223372036854841344,
    "time_created": "2026-03-15T04:20:50.067714800+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "12840",
      "thread_id": "800"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 6202 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
Thumbnails_Extract
Opcode
Stop

Fields #

NameDescription
HRESULT UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "6202",
    "version": "0",
    "level": "4",
    "task": "6201",
    "opcode": "2",
    "keywords": 9223372036854841344,
    "time_created": "2026-03-15T04:20:50.108720300+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "12840",
      "thread_id": "800"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "HRESULT": "2147791360"
  },
  "message": ""
}

Event ID 6203 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Thumbnails_FastExtract
Opcode
Start

Event ID 6204 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Thumbnails_FastExtract
Opcode
Stop

Fields #

NameDescription
HRESULT UInt32

Event ID 6205 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
Thumbnails_CacheLookup
Opcode
Start

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "6205",
    "version": "0",
    "level": "4",
    "task": "6205",
    "opcode": "1",
    "keywords": 9223372036854841344,
    "time_created": "2026-03-15T04:20:50.066983600+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "12840",
      "thread_id": "800"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 6206 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
Thumbnails_CacheLookup
Opcode
Stop

Fields #

NameDescription
HRESULT UInt32
LowQuality Boolean

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "6206",
    "version": "0",
    "level": "4",
    "task": "6205",
    "opcode": "2",
    "keywords": 9223372036854841344,
    "time_created": "2026-03-15T04:20:50.067060500+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "12840",
      "thread_id": "800"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "HRESULT": "2147680258",
    "LowQuality": "true"
  },
  "message": ""
}

Event ID 6207 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Thumbnails_Adornment
Opcode
Start

Event ID 6208 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Thumbnails_Adornment
Opcode
Stop

Event ID 6209 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Thumbnails_ExtractNoCache
Opcode
Start

Event ID 6210 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Thumbnails_ExtractNoCache
Opcode
Stop

Event ID 6211 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
Thumbnails_FolderThumbnailRender
Opcode
Start

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "6211",
    "version": "0",
    "level": "4",
    "task": "6211",
    "opcode": "1",
    "keywords": 9223372036854841344,
    "time_created": "2026-03-15T04:20:50.106203200+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "12840",
      "thread_id": "800"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 6212 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
Thumbnails_FolderThumbnailRender
Opcode
Stop

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "6212",
    "version": "0",
    "level": "4",
    "task": "6211",
    "opcode": "2",
    "keywords": 9223372036854841344,
    "time_created": "2026-03-15T04:20:50.121868900+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "12840",
      "thread_id": "800"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 6213 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Thumbnails_ResizeCache
Opcode
Start

Event ID 6214 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Thumbnails_ResizeCache
Opcode
Stop

Event ID 6215 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
Thumbnails_Initialize
Opcode
Start

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "6215",
    "version": "0",
    "level": "4",
    "task": "6215",
    "opcode": "1",
    "keywords": 9223372036854841344,
    "time_created": "2026-03-15T04:21:03.188230900+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "12840",
      "thread_id": "13268"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 6216 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
Thumbnails_Initialize
Opcode
Stop

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "6216",
    "version": "0",
    "level": "4",
    "task": "6215",
    "opcode": "2",
    "keywords": 9223372036854841344,
    "time_created": "2026-03-15T04:21:03.189901400+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "12840",
      "thread_id": "13268"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 6217 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
Thumbnails_GetThumbnail
Opcode
Start

Fields #

NameDescription
FileName UnicodeString
RequestSize UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "6217",
    "version": "0",
    "level": "4",
    "task": "6217",
    "opcode": "1",
    "keywords": 9223372036854841344,
    "time_created": "2026-03-15T04:20:50.066737800+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "12840",
      "thread_id": "800"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "FileName": "automaton",
    "RequestSize": "      48"
  },
  "message": ""
}

Event ID 6218 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
Thumbnails_GetThumbnail
Opcode
Stop

Fields #

NameDescription
HRESULT UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "6218",
    "version": "0",
    "level": "4",
    "task": "6217",
    "opcode": "2",
    "keywords": 9223372036854841344,
    "time_created": "2026-03-15T04:20:50.067219200+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "12840",
      "thread_id": "800"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "HRESULT": "2147791363"
  },
  "message": ""
}

Event ID 6219 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
Thumbnails_SetThumbnail
Opcode
Start

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "6219",
    "version": "0",
    "level": "4",
    "task": "6219",
    "opcode": "1",
    "keywords": 9223372036854841344,
    "time_created": "2026-03-15T04:20:50.108897500+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "12840",
      "thread_id": "800"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 6220 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
Thumbnails_SetThumbnail
Opcode
Stop

Fields #

NameDescription
HRESULT UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "6220",
    "version": "0",
    "level": "4",
    "task": "6219",
    "opcode": "2",
    "keywords": 9223372036854841344,
    "time_created": "2026-03-15T04:20:50.109603500+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "12840",
      "thread_id": "800"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "HRESULT": "       0"
  },
  "message": ""
}

Event ID 6221 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Thumbnails_GetAspectRatio
Opcode
Start

Event ID 6222 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Thumbnails_GetAspectRatio
Opcode
Stop

Event ID 6223 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Thumbnails_DiskCleanup
Opcode
Start

Event ID 6224 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Thumbnails_DiskCleanup
Opcode
Stop

Event ID 6225 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Thumbnails_ReadThumbsDB
Opcode
Start

Event ID 6226 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Thumbnails_ReadThumbsDB
Opcode
Stop

Fields #

NameDescription
HRESULT Int32
RequestSize UInt32

Event ID 6227 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Thumbnails_LoadFromThumbsDB
Opcode
Start

Event ID 6228 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Thumbnails_LoadFromThumbsDB
Opcode
Stop

Fields #

NameDescription
HRESULT UInt32

Event ID 6229 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Thumbnails_WriteThumbsDB
Opcode
Start

Event ID 6230 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Thumbnails_WriteThumbsDB
Opcode
Stop

Fields #

NameDescription
HRESULT UInt32

Event ID 6231 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
Thumbnails_CropLookupSize

Fields #

NameDescription
CropLookupSize UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "6231",
    "version": "0",
    "level": "4",
    "task": "6231",
    "opcode": "0",
    "keywords": 9223372036854841344,
    "time_created": "2026-03-15T04:20:50.109604500+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "12840",
      "thread_id": "800"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "CropLookupSize": "    2560"
  },
  "message": ""
}

Event ID 6233 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Thumbnails_HostSelfDestruct

Event ID 6235 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Thumbnails_ExtractionTimeout

Event ID 6236 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
RemoteThumbsDb_SQM

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmDWORDDatapointValue UInt32

Event ID 6237 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
RemoteThumbsDb_SQM

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmDWORDDatapointValue UInt32

Event ID 6238 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
RemoteThumbsDb_SQM

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmDWORDDatapointValue UInt32

Event ID 6239 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Error
Task
Thumbnails_FullExtractionFailed

Fields #

NameDescription
HRESULT Int32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "6239",
    "version": "0",
    "level": "2",
    "task": "6239",
    "opcode": "0",
    "keywords": 9223372036854841344,
    "time_created": "2026-03-15T04:20:50.107825200+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "12840",
      "thread_id": "800"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "HRESULT": "-2147175936"
  },
  "message": ""
}

Event ID 6240 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
Thumbnails_CacheDataFile_GetThumbnail
Opcode
Start

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "6240",
    "version": "0",
    "level": "4",
    "task": "6240",
    "opcode": "1",
    "keywords": 9223372036854841344,
    "time_created": "2026-03-15T04:21:15.027004100+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "12840",
      "thread_id": "800"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 6241 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
Thumbnails_CacheDataFile_GetThumbnail
Opcode
Stop

Fields #

NameDescription
HRESULT UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "6241",
    "version": "0",
    "level": "4",
    "task": "6240",
    "opcode": "2",
    "keywords": 9223372036854841344,
    "time_created": "2026-03-15T04:21:15.027088300+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "12840",
      "thread_id": "800"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "HRESULT": "       0"
  },
  "message": ""
}

Event ID 6242 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Thumbnails_GetThumbnailStream
Opcode
Start

Fields #

NameDescription
FileName UnicodeString
RequestSize Int32
WTSFlags UInt32

Event ID 6243 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Thumbnails_GetThumbnailStream
Opcode
Stop

Fields #

NameDescription
HRESULT Int32
CacheFlags UInt32
SizeX Int32
SizeY Int32
StreamType Int32

Event ID 6501 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
CommonFileDialog_ApplyProperties
Opcode
Start

Event ID 6502 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
CommonFileDialog_ApplyProperties
Opcode
Stop

Event ID 6503 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
CommonFileDialog_ControlsChangeNotify
Opcode
Start

Event ID 6504 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
CommonFileDialog_ControlsChangeNotify
Opcode
Stop

Event ID 6505 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
CommonFileDialog_DetectSlowNetworkLocation
Opcode
Start

Event ID 6506 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
CommonFileDialog_DetectSlowNetworkLocation
Opcode
Stop

Event ID 6507 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
CommonFileDialog_ExecuteOpen
Opcode
Start

Event ID 6508 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
CommonFileDialog_ExecuteOpen
Opcode
Stop

Event ID 6509 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
CommonFileDialog_Open
Opcode
Start

Event ID 6510 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
CommonFileDialog_Open
Opcode
Stop

Fields #

NameDescription
Path UnicodeString

Event ID 6511 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
CommonFileDialog_PlacesBar_Rendering
Opcode
Start

Event ID 6512 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
CommonFileDialog_PlacesBar_Rendering
Opcode
Stop

Event ID 6513 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
CommonFileDialog_PopulateControls
Opcode
Start

Event ID 6514 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
CommonFileDialog_PopulateControls
Opcode
Stop

Event ID 6515 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
CommonFileDialog_SQM

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmDWORDDatapointValue UInt32

Event ID 6516 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
CommonFileDialog_SQM

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmDWORDDatapointValue UInt32

Event ID 6517 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
CommonFileDialog_SQM

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmDWORDDatapointValue UInt32

Event ID 6518 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
CommonFileDialog_SQM

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmDWORDDatapointValue UInt32

Event ID 7001 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ConflictResolution_CRUD_Open
Opcode
Start

Event ID 7002 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ConflictResolution_CRUD_Open
Opcode
Stop

Event ID 7003 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ConflictResolution_Rendering
Opcode
Start

Event ID 7004 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ConflictResolution_Rendering
Opcode
Stop

Event ID 7005 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ConflictResolution_UserIgnoreChangeNotify
Opcode
Start

Event ID 7006 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ConflictResolution_UserIgnoreChangeNotify
Opcode
Stop

Event ID 8001 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DetailsPropertyPage_AddPages
Opcode
Start

Event ID 8002 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DetailsPropertyPage_AddPages
Opcode
Stop

Event ID 8003 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DetailsPropertyPage_Open
Opcode
Start

Event ID 8004 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DetailsPropertyPage_Open
Opcode
Stop

Event ID 8005 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DetailsPropertyPage_Save
Opcode
Start

Event ID 8006 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DetailsPropertyPage_Save
Opcode
Stop

Event ID 9501 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Explorer_StartMenu_Open

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmDWORDDatapointValue UInt32

Event ID 9503 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Explorer_StartMenu_Ready

Event ID 9505 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Explorer_StartPane_AllProgram_Folder_Open
Opcode
Start

Event ID 9506 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Explorer_StartPane_AllProgram_Folder_Open
Opcode
Stop

Event ID 9509 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Explorer_StartPane_AllPrograms_Show
Opcode
Start

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmDWORDDatapointValue UInt32

Event ID 9510 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Explorer_StartPane_AllPrograms_Show
Opcode
Stop

Event ID 9511 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Explorer_StartPane_Cascade_Show
Opcode
Start

Event ID 9512 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Explorer_StartPane_Cascade_Show
Opcode
Stop

Event ID 9513 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Explorer_StartPane_OpenBox_Char

Fields #

NameDescription
Query UnicodeString

Event ID 9515 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Explorer_StartPane_OpenBox_Launch

Event ID 9517 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Explorer_StartPane_OpenBox_SearchReady

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmStreamRowLength UInt32
SqmStreamRow Int16

Event ID 9519 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Explorer_StartMenu_Show
Opcode
Start

Event ID 9520 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Explorer_StartMenu_Show
Opcode
Stop

Event ID 9521 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Explorer_StartMenu_Hide
Opcode
Start

Event ID 9522 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Explorer_StartMenu_Hide
Opcode
Stop

Event ID 9523 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Explorer_StartPane_OpenBox_TopMatchReady

Event ID 9525 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Explorer_StartMenu_ControlPanel_Launch

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmDWORDDatapointValue UInt32

Event ID 9526 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Explorer_StartMenu_ControlPanel_Launch
Opcode
Stop

Event ID 9527 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Explorer_StartMenu_Favorites_Launch

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmDWORDDatapointValue UInt32

Event ID 9529 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Explorer_StartMenu_RecentItems_Launch

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmDWORDDatapointValue UInt32

Event ID 9531 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Explorer_StartMenu_Help_Launch

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmDWORDDatapointValue UInt32

Event ID 9533 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Explorer_StartMenu_Network_Launch

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmDWORDDatapointValue UInt32

Event ID 9535 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Explorer_StartMenu_Printers_Launch

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmDWORDDatapointValue UInt32

Event ID 9539 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Explorer_StartMenu_SPAD_Launch

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmDWORDDatapointValue UInt32

Event ID 9541 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Explorer_StartMenu_AdminTools_Launch

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmDWORDDatapointValue UInt32

Event ID 9543 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Explorer_StartMenu_Run_Launch

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmDWORDDatapointValue UInt32

Event ID 9545 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Explorer_StartMenu_MFU_Launch

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmDWORDDatapointValue UInt32

Event ID 9547 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Explorer_StartMenu_Pinned_Launch

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmDWORDDatapointValue UInt32

Event ID 9549 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Explorer_StartMenu_ConnectTo_Launch

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmDWORDDatapointValue UInt32

Event ID 9551 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Explorer_StartPane_AllPrograms_BackButton

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmDWORDDatapointValue UInt32

Event ID 9553 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ExplorerFrame_OpenComputer

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmDWORDDatapointValue UInt32

Event ID 9555 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ExplorerFrame_OpenDocuments

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmDWORDDatapointValue UInt32

Event ID 9557 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ExplorerFrame_OpenMusic

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmDWORDDatapointValue UInt32

Event ID 9559 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ExplorerFrame_OpenPictures

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmDWORDDatapointValue UInt32

Event ID 9560 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ExplorerFrame_NavigateDataSource

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmStreamRowLength UInt32
SqmStreamRow Int16

Event ID 9561 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Explorer_StartMenu_Visible_Menu_Items

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmDWORDDatapointValue UInt32

Event ID 9563 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Explorer_StartMenu_Mode

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmDWORDDatapointValue UInt32

Event ID 9565 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Explorer_StartMenu_Pinned_Item_Added

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmDWORDDatapointValue UInt32

Event ID 9567 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Explorer_StartMenu_Pinned_Item_Removed

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmDWORDDatapointValue UInt32

Event ID 9568 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Explorer_StartMenu_Pinned_Items_Rearranged

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmDWORDDatapointValue UInt32

Event ID 9569 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Explorer_StartPane_AllPrograms_Launched

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmDWORDDatapointValue UInt32

Event ID 9571 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Explorer_StartMenu_Pinned_Count

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmDWORDDatapointValue UInt32

Event ID 9573 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Explorer_StartMenu_MFU_Count

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmDWORDDatapointValue UInt32

Event ID 9575 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Explorer_StartPane_AllPrograms_Folder_Opened

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmDWORDDatapointValue UInt32

Event ID 9577 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Explorer_StartPane_AllPrograms_Count

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmDWORDDatapointValue UInt32

Event ID 9581 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Explorer_StartMenu_NetworkCons_Launch

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmDWORDDatapointValue UInt32

Event ID 9583 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Explorer_Is_Mobile_PC

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmDWORDDatapointValue UInt32

Event ID 9585 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Explorer_Is_Joined_To_Domain

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmDWORDDatapointValue UInt32

Event ID 9587 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Explorer_StartMenu_Cascading_Menu_Items

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmDWORDDatapointValue UInt32

Event ID 9589 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Explorer_User_Account_Type

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmDWORDDatapointValue UInt32

Event ID 9591 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Explorer_Breadcrumbbar_Selected_Navigation

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmDWORDDatapointValue UInt32

Event ID 9593 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Explorer_Breadcrumbbar_Edited_Navigation

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmDWORDDatapointValue UInt32

Event ID 9595 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Explorer_WordWheel_Activated

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmDWORDDatapointValue UInt32

Event ID 9597 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ExplorerFrame_OpenProfile

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmDWORDDatapointValue UInt32

Event ID 9599 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Explorer_Help_Launched

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmStreamRowLength UInt32
SqmStreamRow Int16

Event ID 9601 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Explorer_InitializingExplorer
Opcode
Start

Event ID 9602 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Explorer_InitializingExplorer
Opcode
Stop

Event ID 9603 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Explorer_CreateTray
Opcode
Start

Event ID 9604 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Explorer_CreateTray
Opcode
Stop

Event ID 9607 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Explorer_CreateTrayWindow
Opcode
Start

Event ID 9608 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Explorer_CreateTrayWindow
Opcode
Stop

Event ID 9609 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Explorer_InitStartButton
Opcode
Start

Event ID 9610 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Explorer_InitStartButton
Opcode
Stop

Event ID 9611 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Explorer_CreateDesktop
Opcode
Start

Event ID 9612 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Explorer_CreateDesktop
Opcode
Stop

Event ID 9613 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Explorer_InitInstrumentation

Fields #

NameDescription
SqmType UInt32
SqmSid SID

Event ID 9615 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Explorer_FolderSettings

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmDWORDDatapointValue UInt32

Event ID 9617 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Explorer_Start

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmDWORDDatapointValue UInt32

Event ID 9619 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Explorer_StartMenu_Games_Launch

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmDWORDDatapointValue UInt32

Event ID 9621 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Explorer_MessageLoop
Opcode
Start

Event ID 9622 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Explorer_MessageLoop
Opcode
Stop

Event ID 9623 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Explorer_KickedOffDelayedBootWork

Event ID 9625 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Explorer_PlaySoundRequest
Opcode
Start

Fields #

NameDescription
FileName UnicodeString

Event ID 9626 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Explorer_PlaySoundRequest
Opcode
Stop

Fields #

NameDescription
FileName UnicodeString

Event ID 9627 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Explorer_PlaySoundExecute
Opcode
Start

Event ID 9628 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Explorer_PlaySoundExecute
Opcode
Stop

Event ID 9629 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Explorer_PlaySoundWait
Opcode
Start

Event ID 9630 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Explorer_PlaySoundWait
Opcode
Stop

Event ID 9631 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Explorer_SessionChangeMessage

Fields #

NameDescription
WParam UInt32
LParam UInt32

Event ID 9633 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Explorer_PowerMessage

Fields #

NameDescription
WParam UInt32
LParam UInt32

Event ID 9635 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Explorer_PowerBroadcastMessage

Fields #

NameDescription
WParam UInt32
LParam UInt32

Event ID 9637 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Explorer_LoadingIconCache
Opcode
Start

Event ID 9638 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Explorer_LoadingIconCache
Opcode
Stop

Event ID 9639 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Explorer_IconCache_ImageListSize

Fields #

NameDescription
psz UnicodeString

Event ID 9641 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Explorer_IconCache_TableSize

Fields #

NameDescription
psz UnicodeString

Event ID 9643 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Explorer_Roaming_SyncAtLogon
Opcode
Start

Event ID 9644 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Explorer_Roaming_SyncAtLogon
Opcode
Stop

Event ID 9645 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Explorer_Roaming_WaitAtLogon
Opcode
Start

Event ID 9646 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Explorer_Roaming_WaitAtLogon
Opcode
Stop

Event ID 9647 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Explorer_Startup_PhaseReached

Fields #

NameDescription
psz UnicodeString

Event ID 9648 —

#
Provider
Microsoft-Windows-Shell-Core
Channel
Operational
Level
Informational
Task
Explorer_Startup_Step
Opcode
Start

Fields #

NameDescription
psz UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "30336ED4-E327-447C-9DE0-51B652C86108",
    "event_source_name": "",
    "event_id": 9648,
    "version": 0,
    "level": 4,
    "task": 9648,
    "opcode": 1,
    "keywords": 2305843009280868352,
    "time_created": "2023-11-05T23:54:50.099298+00:00",
    "event_record_id": 2728,
    "correlation": {},
    "execution": {
      "process_id": 10860,
      "thread_id": 9624
    },
    "channel": "Microsoft-Windows-Shell-Core/Operational",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-21-1992711665-1655669231-58201500-1000"
    }
  },
  "event_data": {
    "psz": "Finalize"
  },
  "message": ""
}

References #

Event ID 9649 —

#
Provider
Microsoft-Windows-Shell-Core
Channel
Operational
Level
Informational
Task
Explorer_Startup_Step
Opcode
Stop

Fields #

NameDescription
psz UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "30336ED4-E327-447C-9DE0-51B652C86108",
    "event_source_name": "",
    "event_id": 9649,
    "version": 0,
    "level": 4,
    "task": 9648,
    "opcode": 2,
    "keywords": 2305843009280868352,
    "time_created": "2023-11-05T23:54:50.099591+00:00",
    "event_record_id": 2729,
    "correlation": {},
    "execution": {
      "process_id": 10860,
      "thread_id": 9624
    },
    "channel": "Microsoft-Windows-Shell-Core/Operational",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-21-1992711665-1655669231-58201500-1000"
    }
  },
  "event_data": {
    "psz": "Finalize"
  },
  "message": ""
}

References #

Event ID 9650 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Explorer_Startup_SerializationWait
Opcode
Start

Event ID 9651 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Explorer_Startup_SerializationWait
Opcode
Stop

Event ID 9652 —

#
Provider
Microsoft-Windows-Shell-Core
Channel
Operational
Level
Informational
Task
Explorer_Startup_ParallelStep
Opcode
Start

Fields #

NameDescription
psz UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "30336ED4-E327-447C-9DE0-51B652C86108",
    "event_source_name": "",
    "event_id": 9652,
    "version": 0,
    "level": 4,
    "task": 9652,
    "opcode": 1,
    "keywords": 2305843009280868352,
    "time_created": "2023-11-05T23:54:32.617653+00:00",
    "event_record_id": 2710,
    "correlation": {},
    "execution": {
      "process_id": 10860,
      "thread_id": 9624
    },
    "channel": "Microsoft-Windows-Shell-Core/Operational",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-21-1992711665-1655669231-58201500-1000"
    }
  },
  "event_data": {
    "psz": "FinalTasks"
  },
  "message": ""
}

References #

Event ID 9653 —

#
Provider
Microsoft-Windows-Shell-Core
Channel
Operational
Level
Informational
Task
Explorer_Startup_ParallelStep
Opcode
Stop

Fields #

NameDescription
psz UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "30336ED4-E327-447C-9DE0-51B652C86108",
    "event_source_name": "",
    "event_id": 9653,
    "version": 0,
    "level": 4,
    "task": 9652,
    "opcode": 2,
    "keywords": 2305843009280868352,
    "time_created": "2023-11-05T23:54:33.687660+00:00",
    "event_record_id": 2712,
    "correlation": {},
    "execution": {
      "process_id": 10860,
      "thread_id": 9624
    },
    "channel": "Microsoft-Windows-Shell-Core/Operational",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-21-1992711665-1655669231-58201500-1000"
    }
  },
  "event_data": {
    "psz": "DesktopFinalTasks"
  },
  "message": ""
}

References #

Event ID 9654 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Opcode
Info

Fields #

NameDescription
Reason UInt32

Event ID 9660 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Explorer_Roaming_BootstrapRestore
Opcode
Stop

Fields #

NameDescription
Value UInt32

Event ID 9662 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Explorer_Roaming_BootstrapRestore
Opcode
Start

Event ID 9663 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Explorer_WriteDataForOEMApp
Opcode
Start

Event ID 9664 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Explorer_WriteDataForOEMApp
Opcode
Stop

Event ID 9665 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Explorer_WriteDataForOEMApp_ShellTask
Opcode
Start

Event ID 9666 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Explorer_WriteDataForOEMApp_ShellTask
Opcode
Stop

Event ID 9699 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Explorer_Startup_InitializeDesktop
Opcode
Stop

Event ID 9701 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Explorer_ProcessRunOnceEx
Opcode
Start

Event ID 9702 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Explorer_ProcessRunOnceEx
Opcode
Stop

Event ID 9703 — RunOnce commands started.

#
Provider
Microsoft-Windows-Shell-Core
Channel
Operational
Level
Informational
Task
Explorer_ProcessRunOnce
Opcode
Start

Description

RunOnce commands started.

Message #

RunOnce commands started.

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "30336ED4-E327-447C-9DE0-51B652C86108",
    "event_source_name": "",
    "event_id": 9703,
    "version": 0,
    "level": 4,
    "task": 9703,
    "opcode": 1,
    "keywords": 2305843009280868352,
    "time_created": "2023-11-05T22:29:04.086498+00:00",
    "event_record_id": 1725,
    "correlation": {},
    "execution": {
      "process_id": 6020,
      "thread_id": 5856
    },
    "channel": "Microsoft-Windows-Shell-Core/Operational",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-21-1992711665-1655669231-58201500-1000"
    }
  },
  "event_data": {},
  "message": ""
}

References #

Event ID 9704 — RunOnce commands finished.

#
Provider
Microsoft-Windows-Shell-Core
Channel
Operational
Level
Informational
Task
Explorer_ProcessRunOnce
Opcode
Stop

Description

RunOnce commands finished.

Message #

RunOnce commands finished.

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "30336ED4-E327-447C-9DE0-51B652C86108",
    "event_source_name": "",
    "event_id": 9704,
    "version": 0,
    "level": 4,
    "task": 9703,
    "opcode": 2,
    "keywords": 2305843009280868352,
    "time_created": "2023-11-05T22:29:38.761932+00:00",
    "event_record_id": 1898,
    "correlation": {},
    "execution": {
      "process_id": 6020,
      "thread_id": 5856
    },
    "channel": "Microsoft-Windows-Shell-Core/Operational",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-21-1992711665-1655669231-58201500-1000"
    }
  },
  "event_data": {},
  "message": ""
}

References #

Event ID 9705 — Started enumeration of commands for registry key 'KeyName'.

#
Provider
Microsoft-Windows-Shell-Core
Channel
Operational
Level
Informational
Task
Explorer_EnumeratingRunKey
Opcode
Start

Description

Started enumeration of commands for registry key 'KeyName'.

Message #

Started enumeration of commands for registry key '%1'.

Fields #

NameDescription
KeyName UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "30336ED4-E327-447C-9DE0-51B652C86108",
    "event_source_name": "",
    "event_id": 9705,
    "version": 0,
    "level": 4,
    "task": 9705,
    "opcode": 1,
    "keywords": 2305843009280868352,
    "time_created": "2023-11-05T23:54:44.247520+00:00",
    "event_record_id": 2715,
    "correlation": {},
    "execution": {
      "process_id": 10860,
      "thread_id": 11316
    },
    "channel": "Microsoft-Windows-Shell-Core/Operational",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-21-1992711665-1655669231-58201500-1000"
    }
  },
  "event_data": {
    "KeyName": "Software\\Microsoft\\Windows\\CurrentVersion\\RunOnce"
  },
  "message": ""
}

References #

Event ID 9706 — Finished enumeration of commands for registry key 'KeyName'.

#
Provider
Microsoft-Windows-Shell-Core
Channel
Operational
Level
Informational
Task
Explorer_EnumeratingRunKey
Opcode
Stop

Description

Finished enumeration of commands for registry key 'KeyName'.

Message #

Finished enumeration of commands for registry key '%1'.

Fields #

NameDescription
KeyName UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "30336ED4-E327-447C-9DE0-51B652C86108",
    "event_source_name": "",
    "event_id": 9706,
    "version": 0,
    "level": 4,
    "task": 9705,
    "opcode": 2,
    "keywords": 2305843009280868352,
    "time_created": "2023-11-05T23:54:50.098749+00:00",
    "event_record_id": 2724,
    "correlation": {},
    "execution": {
      "process_id": 10860,
      "thread_id": 11316
    },
    "channel": "Microsoft-Windows-Shell-Core/Operational",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-21-1992711665-1655669231-58201500-1000"
    }
  },
  "event_data": {
    "KeyName": "Software\\Microsoft\\Windows\\CurrentVersion\\RunOnce"
  },
  "message": ""
}

References #

Event ID 9707 — Started execution of command 'Command'.

#
Provider
Microsoft-Windows-Shell-Core
Channel
Operational
Level
Informational
Task
Explorer_ExecutingFromRunKey
Opcode
Start

Description

Started execution of command 'Command'.

Message #

Started execution of command '%1'.

Fields #

NameDescription
Command UnicodeStringFull command line for the command that was executed

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "30336ED4-E327-447C-9DE0-51B652C86108",
    "event_source_name": "",
    "event_id": 9707,
    "version": 0,
    "level": 4,
    "task": 9707,
    "opcode": 1,
    "keywords": 2305843009280868352,
    "time_created": "2023-11-05T23:54:45.468332+00:00",
    "event_record_id": 2722,
    "correlation": {},
    "execution": {
      "process_id": 10860,
      "thread_id": 11316
    },
    "channel": "Microsoft-Windows-Shell-Core/Operational",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-21-1992711665-1655669231-58201500-1000"
    }
  },
  "event_data": {
    "Command": "installer.exe\" /repair"
  },
  "message": ""
}

References #

Event ID 9708 — Finished execution of command 'Command' (PID PID).

#
Provider
Microsoft-Windows-Shell-Core
Channel
Operational
Level
Informational
Task
Explorer_ExecutingFromRunKey
Opcode
Stop

Description

Finished execution of command 'Command' (PID PID).

Message #

Finished execution of command '%2' (PID %1).

Fields #

NameDescription
PID UInt32
Command UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "30336ED4-E327-447C-9DE0-51B652C86108",
    "event_source_name": "",
    "event_id": 9708,
    "version": 0,
    "level": 4,
    "task": 9707,
    "opcode": 2,
    "keywords": 2305843009280868352,
    "time_created": "2023-11-05T23:54:50.098732+00:00",
    "event_record_id": 2723,
    "correlation": {},
    "execution": {
      "process_id": 10860,
      "thread_id": 11316
    },
    "channel": "Microsoft-Windows-Shell-Core/Operational",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-21-1992711665-1655669231-58201500-1000"
    }
  },
  "event_data": {
    "PID": 11932,
    "Command": "installer.exe\" /repair"
  },
  "message": ""
}

References #

Event ID 9709 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Explorer_ExecutingFromRunKeyAsJob
Opcode
Start

Fields #

NameDescription
Command UnicodeString

Event ID 9710 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Explorer_ExecutingFromRunKeyAsJob
Opcode
Stop

Fields #

NameDescription
PID UInt32
Command UnicodeString

Event ID 9711 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Explorer_ExecutingFromStartupMenu
Opcode
Start

Fields #

NameDescription
Command UnicodeString

Event ID 9712 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Explorer_ExecutingFromStartupMenu
Opcode
Stop

Fields #

NameDescription
Command UnicodeString

Event ID 9713 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Explorer_StartupAppName

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmStreamRowLength UInt32
SqmStreamRow Int16

Event ID 9714 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Explorer_BoxingProcess

Fields #

NameDescription
PID UInt32

Event ID 9716 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Explorer_Startup_Run6432_Stats

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmStreamRowLength UInt32
SqmStreamRow Int16

Event ID 9717 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Explorer_Startup_Run6432_Failed

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmStreamRowLength UInt32
SqmStreamRow Int16

Event ID 9801 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Explorer_MinimizeAllThread

Event ID 9802 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Explorer_StartMenu_RunDialog
Opcode
Start

Event ID 9803 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Explorer_StartMenu_RunDialog
Opcode
Stop

Event ID 9804 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Explorer_StartMenu_AppTile_Hover

Event ID 9805 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Explorer_DestinationList_Close

Event ID 9806 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Explorer_DestinationList_Launch

Event ID 9808 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
EXPLORER_NAVIGATE

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmStreamRowLength UInt32
SqmStreamRow Int16

Event ID 9810 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
EXPLORER_DRAG_DROP

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmStreamRowLength UInt32
SqmStreamRow Int16

Event ID 9811 —

Provider
Microsoft-Windows-Shell-Core
Channel
Operational
Task
Explorer_PinDefaultItems_RetrievePidlFailure

Fields #

NameDescription
AppID UnicodeString
HRESULT UInt32

Event ID 9812 —

Provider
Microsoft-Windows-Shell-Core
Channel
Operational
Task
Explorer_PinnedListItemRemoved

Fields #

NameDescription
HRESULT UInt32
CallerId Int32

Event ID 9901 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
SearchFolder_StartMenu_BaseQuery
Opcode
Start

Event ID 9902 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
SearchFolder_StartMenu_BaseQuery
Opcode
Stop

Event ID 9903 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ExplorerFrame_FirstPage_RealizeGroupPass1
Opcode
Start

Fields #

NameDescription
psz UnicodeString

Event ID 9904 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ExplorerFrame_FirstPage_RealizeGroupPass1
Opcode
Stop

Fields #

NameDescription
psz UnicodeString

Event ID 9905 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ExplorerFrame_FirstPage_RealizeGroupPass2
Opcode
Start

Fields #

NameDescription
psz UnicodeString

Event ID 9906 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ExplorerFrame_FirstPage_RealizeGroupPass2
Opcode
Stop

Fields #

NameDescription
psz UnicodeString

Event ID 9907 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ExplorerFrame_ExplorerLauncher_Launch_Failure

Fields #

NameDescription
HRESULT UInt32

Event ID 9909 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
SearchFolder_CreateItemCollection
Opcode
Start

Event ID 9910 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
SearchFolder_CreateItemCollection
Opcode
Stop

Fields #

NameDescription
HRESULT UInt32

Event ID 9911 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_ObservableCollection_OnCollectionChanged

Event ID 9912 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_ObservableCollection_OnGetCountDone

Event ID 9913 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_ObservableCollection_OnPrepareDone

Event ID 9914 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_ObservableCollection_OnItemsAdded

Event ID 9915 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_ObservableCollection_OnItemsDeleted

Event ID 9916 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_ObservableCollection_OnItemMoved

Event ID 9917 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_ObservableCollection_OnItemTranslated

Event ID 9918 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_ObservableCollection_OnUniqueLeafCountChanged

Event ID 9919 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_ObservableCollection_OnCancelled

Event ID 10001 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ExplorerTemplates_ChangeNotify
Opcode
Start

Event ID 10002 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ExplorerTemplates_ChangeNotify
Opcode
Stop

Event ID 11001 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
FilterControl_ApplyingFilter

Event ID 11003 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
FilterControl_PopulateFilters
Opcode
Start

Event ID 11004 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
FilterControl_PopulateFilters
Opcode
Stop

Event ID 11005 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
FilterControl_Show
Opcode
Start

Event ID 11006 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
FilterControl_Show
Opcode
Stop

Event ID 11007 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
FilterControl_UserCheckedFilter

Event ID 11009 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
FilterControl_InsertFilters
Opcode
Start

Event ID 11010 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
FilterControl_InsertFilters
Opcode
Stop

Event ID 11011 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
FilterControl_InsertFilters

Fields #

NameDescription
Count UInt32

Event ID 11013 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ListViewPopup_SetRedraw
Opcode
Start

Fields #

NameDescription
Value UInt32

Event ID 11014 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ListViewPopup_SetRedraw
Opcode
Stop

Fields #

NameDescription
Value UInt32

Event ID 11015 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ListViewPopup_SizeToContent
Opcode
Start

Event ID 11016 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ListViewPopup_SizeToContent
Opcode
Stop

Event ID 11017 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
FilterControl_Stack

Event ID 12001 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shlwapi_SHRegisterValidateTemplate

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmStreamRowLength UInt32
SqmStreamRow Int16

Event ID 12101 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shlwapi_SHGetSignatureInfo
Opcode
Start

Event ID 12102 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shlwapi_SHGetSignatureInfo
Opcode
Stop

Event ID 12103 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shlwapi_SHGetSignatureInfo_Authenticode
Opcode
Start

Event ID 12104 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shlwapi_SHGetSignatureInfo_Authenticode
Opcode
Stop

Event ID 12105 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shlwapi_SHGetSignatureInfo_Catalog
Opcode
Start

Event ID 12106 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shlwapi_SHGetSignatureInfo_Catalog
Opcode
Stop

Event ID 12107 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shlwapi_SHGetSignatureInfo_WinVerifyTrust
Opcode
Start

Event ID 12108 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shlwapi_SHGetSignatureInfo_WinVerifyTrust
Opcode
Stop

Event ID 12109 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shlwapi_SHGetSignatureInfo_VersionInfo
Opcode
Start

Event ID 12110 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shlwapi_SHGetSignatureInfo_VersionInfo
Opcode
Stop

Event ID 12111 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shlwapi_SHGetSignatureInfo_OSCheck
Opcode
Start

Event ID 12112 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shlwapi_SHGetSignatureInfo_OSCheck
Opcode
Stop

Event ID 12113 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shlwapi_SHGetSignatureInfo_CheckChainToMSRoot
Opcode
Start

Event ID 12114 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shlwapi_SHGetSignatureInfo_CheckChainToMSRoot
Opcode
Stop

Event ID 13001 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
NamespaceControl_ChangeNotify
Opcode
Start

Event ID 13002 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
NamespaceControl_ChangeNotify
Opcode
Stop

Event ID 13003 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
NamespaceControl_Expand
Opcode
Start

Event ID 13004 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
NamespaceControl_Expand
Opcode
Stop

Event ID 13005 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
NamespaceControl_Plus_Calculation
Opcode
Start

Event ID 13006 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
NamespaceControl_Plus_Calculation
Opcode
Stop

Event ID 13007 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
NamespaceControl_Rendering
Opcode
Start

Event ID 13008 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
NamespaceControl_Rendering
Opcode
Stop

Event ID 13101 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Feed_Search
Opcode
Start

Event ID 13102 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Feed_Search
Opcode
Stop

Event ID 13501 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Notification_UserDismiss
Opcode
Start

Event ID 13502 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Notification_UserDismiss
Opcode
Stop

Event ID 13503 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Notification_Launch

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmDWORDDatapointValue UInt32

Event ID 13505 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Notification_Displayed

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmDWORDDatapointValue UInt32

Event ID 13507 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Notification_While_Busy

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmDWORDDatapointValue UInt32

Event ID 13509 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Notification_While_Inactive

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmDWORDDatapointValue UInt32

Event ID 13511 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Notification_Dismissed

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmDWORDDatapointValue UInt32

Event ID 13513 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Notification_TimedOut

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmDWORDDatapointValue UInt32

Event ID 13515 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Notification_Settings

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmDWORDDatapointValue UInt32

Event ID 13517 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Notification_WrenchDismissed

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmStreamRowLength UInt32
SqmStreamRow Int16

Event ID 14001 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PreviewPane_CommitChange
Opcode
Start

Event ID 14002 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PreviewPane_CommitChange
Opcode
Stop

Event ID 14003 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PreviewPane_UpdateSelection
Opcode
Start

Event ID 14004 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PreviewPane_UpdateSelection
Opcode
Stop

Fields #

NameDescription
Count UInt32

Event ID 14005 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PreviewPane_MetadataExtractorDoWork
Opcode
Start

Event ID 14006 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PreviewPane_MetadataExtractorDoWork
Opcode
Stop

Event ID 14007 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PreviewPane_MetadataExtractorDispatch
Opcode
Start

Event ID 14008 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PreviewPane_MetadataExtractorDispatch
Opcode
Stop

Event ID 14009 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PreviewPane_SQM

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmStreamRowLength UInt32
SqmStreamRow Int16

Event ID 14101 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
StatusBarModule_GetPropertiesWorkItemDoWork
Opcode
Start

Event ID 14102 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
StatusBarModule_GetPropertiesWorkItemDoWork
Opcode
Stop

Event ID 14103 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
StatusBarModule_GetPropertiesWorkItemDispatch
Opcode
Start

Event ID 14104 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
StatusBarModule_GetPropertiesWorkItemDispatch
Opcode
Stop

Event ID 14201 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
TypeAhead_SearchHistoryResults
Opcode
Start

Fields #

NameDescription
QueryId UInt32

Event ID 14202 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
TypeAhead_SearchHistoryResults
Opcode
Stop

Fields #

NameDescription
QueryId UInt32

Event ID 14203 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
TypeAhead_LocalMetadataResults
Opcode
Start

Fields #

NameDescription
QueryId UInt32

Event ID 14204 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
TypeAhead_LocalMetadataResults
Opcode
Stop

Fields #

NameDescription
QueryId UInt32

Event ID 14205 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
TypeAhead_ExternalResults
Opcode
Start

Fields #

NameDescription
QueryId UInt32

Event ID 14206 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
TypeAhead_ExternalResults
Opcode
Stop

Fields #

NameDescription
QueryId UInt32

Event ID 14207 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
TypeAhead_OnQuery

Fields #

NameDescription
QueryId UInt32
QueryString UnicodeString

Event ID 14209 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
TypeAhead_ResultsPrimary

Fields #

NameDescription
QueryId UInt32

Event ID 14211 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
TypeAhead_ResultsSecondary

Fields #

NameDescription
QueryId UInt32

Event ID 14213 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
TypeAhead_Timeout

Fields #

NameDescription
QueryId UInt32

Event ID 14215 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
TypeAhead_SearchHistoryStore
Opcode
Start

Event ID 14216 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
TypeAhead_SearchHistoryStore
Opcode
Stop

Event ID 14217 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
TypeAhead_SearchHistoryCleared

Event ID 14219 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
TypeAhead_CancelQuery

Event ID 14220 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
TypeAhead_Enabled

Fields #

NameDescription
Value UInt32

Event ID 14501 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Properties_BaseControl_Create
Opcode
Start

Event ID 14502 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Properties_BaseControl_Create
Opcode
Stop

Event ID 14503 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Properties_BaseControl_WindowlessDraw
Opcode
Start

Event ID 14504 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Properties_BaseControl_WindowlessDraw
Opcode
Stop

Event ID 14505 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Properties_CalendarControl_Create
Opcode
Start

Event ID 14506 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Properties_CalendarControl_Create
Opcode
Stop

Event ID 14507 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Properties_CalendarControl_GetValue
Opcode
Start

Event ID 14508 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Properties_CalendarControl_GetValue
Opcode
Stop

Event ID 14509 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Properties_CalendarControl_SetValue
Opcode
Start

Event ID 14510 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Properties_CalendarControl_SetValue
Opcode
Stop

Event ID 14511 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Properties_DrawPercentFull_WindowlessDraw
Opcode
Start

Event ID 14512 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Properties_DrawPercentFull_WindowlessDraw
Opcode
Stop

Event ID 14513 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Properties_DrawProgressBar_WindowlessDraw
Opcode
Start

Event ID 14514 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Properties_DrawProgressBar_WindowlessDraw
Opcode
Stop

Event ID 14515 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Properties_DropListControl_Create
Opcode
Start

Event ID 14516 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Properties_DropListControl_Create
Opcode
Stop

Event ID 14517 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Properties_DropListControl_GetValue
Opcode
Start

Event ID 14518 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Properties_DropListControl_GetValue
Opcode
Stop

Event ID 14519 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Properties_DropListControl_SetValue
Opcode
Start

Event ID 14520 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Properties_DropListControl_SetValue
Opcode
Stop

Event ID 14521 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Properties_MVPControl_Create
Opcode
Start

Event ID 14522 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Properties_MVPControl_Create
Opcode
Stop

Event ID 14523 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Properties_MVPControl_GetValue
Opcode
Start

Event ID 14524 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Properties_MVPControl_GetValue
Opcode
Stop

Event ID 14525 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Properties_MVPControl_SetValue
Opcode
Start

Event ID 14526 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Properties_MVPControl_SetValue
Opcode
Stop

Event ID 14527 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Properties_MVPControl_WindowlessDraw
Opcode
Start

Event ID 14528 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Properties_MVPControl_WindowlessDraw
Opcode
Stop

Event ID 14529 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Properties_MultiLineEditControl_Create
Opcode
Start

Event ID 14530 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Properties_MultiLineEditControl_Create
Opcode
Stop

Event ID 14531 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Properties_MultiLineEditControl_GetValue
Opcode
Start

Event ID 14532 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Properties_MultiLineEditControl_GetValue
Opcode
Stop

Event ID 14533 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Properties_MultiLineEditControl_SetValue
Opcode
Start

Event ID 14534 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Properties_MultiLineEditControl_SetValue
Opcode
Stop

Event ID 14535 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Properties_NavDropDownControl_Create
Opcode
Start

Event ID 14536 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Properties_NavDropDownControl_Create
Opcode
Stop

Event ID 14537 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Properties_NavDropDownControl_GetValue
Opcode
Start

Event ID 14538 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Properties_NavDropDownControl_GetValue
Opcode
Stop

Event ID 14539 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Properties_NavDropDownControl_SetValue
Opcode
Start

Event ID 14540 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Properties_NavDropDownControl_SetValue
Opcode
Stop

Event ID 14541 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Properties_RatingsControl_Create
Opcode
Start

Event ID 14542 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Properties_RatingsControl_Create
Opcode
Stop

Event ID 14543 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Properties_RatingsControl_GetValue
Opcode
Start

Event ID 14544 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Properties_RatingsControl_GetValue
Opcode
Stop

Event ID 14545 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Properties_RatingsControl_SetValue
Opcode
Start

Event ID 14546 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Properties_RatingsControl_SetValue
Opcode
Stop

Event ID 14547 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Properties_RatingsControl_WindowlessDraw
Opcode
Start

Event ID 14548 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Properties_RatingsControl_WindowlessDraw
Opcode
Stop

Event ID 14549 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Properties_SingleLineEditControl_Create
Opcode
Start

Event ID 14550 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Properties_SingleLineEditControl_Create
Opcode
Stop

Event ID 14551 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Properties_SingleLineEditControl_GetValue
Opcode
Start

Event ID 14552 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Properties_SingleLineEditControl_GetValue
Opcode
Stop

Event ID 14553 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Properties_SingleLineEditControl_SetValue
Opcode
Start

Event ID 14554 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Properties_SingleLineEditControl_SetValue
Opcode
Stop

Event ID 14555 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Properties_MultiComplete_Populate
Opcode
Start

Event ID 14556 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Properties_MultiComplete_Populate
Opcode
Stop

Event ID 14557 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Properties_MultiComplete_Query
Opcode
Start

Event ID 14558 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Properties_MultiComplete_Query
Opcode
Stop

Event ID 14559 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Properties_MultiComplete_Match
Opcode
Start

Event ID 14560 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Properties_MultiComplete_Match
Opcode
Stop

Event ID 14561 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
Properties_PropVariantChangeType_Coercion

Fields #

NameDescription
VARTYPEFrom UInt16
VARTYPETo UInt16
HRESULT UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "14561",
    "version": "0",
    "level": "4",
    "task": "14561",
    "opcode": "0",
    "keywords": 9223372036854906880,
    "time_created": "2026-03-15T04:20:38.358171500+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "12840",
      "thread_id": "4164"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "VARTYPEFrom": "8",
    "VARTYPETo": "31",
    "HRESULT": "       0"
  },
  "message": ""
}

Event ID 14563 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
Properties_PropVariantHelper_Coercion

Fields #

NameDescription
VARTYPEFrom UInt16
VARTYPETo UInt16
HRESULT UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "14563",
    "version": "0",
    "level": "4",
    "task": "14563",
    "opcode": "0",
    "keywords": 9223372036854906880,
    "time_created": "2026-03-15T04:20:38.304818400+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "12840",
      "thread_id": "8552"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "VARTYPEFrom": "8",
    "VARTYPETo": "72",
    "HRESULT": "       0"
  },
  "message": ""
}

Event ID 14564 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
Properties_VariantHelper_Coercion

Fields #

NameDescription
VARTYPEFrom UInt16
VARTYPETo UInt16
HRESULT UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "14564",
    "version": "0",
    "level": "4",
    "task": "14565",
    "opcode": "0",
    "keywords": 9223372036854906880,
    "time_created": "2026-03-15T04:21:14.994735200+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "12840",
      "thread_id": "13880"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "VARTYPEFrom": "8",
    "VARTYPETo": "72",
    "HRESULT": "       0"
  },
  "message": ""
}

Event ID 15001 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PropertyApply_DoOperation
Opcode
Start

Event ID 15002 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PropertyApply_DoOperation
Opcode
Stop

Event ID 15003 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PropertyApply_SHApplyPropertiesToItem
Opcode
Start

Event ID 15004 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PropertyApply_SHApplyPropertiesToItem
Opcode
Stop

Event ID 15501 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
PropertyDescription_FormatForDisplay
Opcode
Start

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "15501",
    "version": "0",
    "level": "4",
    "task": "15501",
    "opcode": "1",
    "keywords": 9223372036854906880,
    "time_created": "2026-03-15T04:20:38.397443500+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "12840",
      "thread_id": "8552"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 15502 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
PropertyDescription_FormatForDisplay
Opcode
Stop

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "15502",
    "version": "0",
    "level": "4",
    "task": "15501",
    "opcode": "2",
    "keywords": 9223372036854906880,
    "time_created": "2026-03-15T04:20:38.397448000+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "12840",
      "thread_id": "8552"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 15503 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
PropertyDescription_SHFormatForDisplay
Opcode
Start

Fields #

NameDescription
FMTID GUID
PID UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "15503",
    "version": "0",
    "level": "4",
    "task": "15503",
    "opcode": "1",
    "keywords": 9223372036854906880,
    "time_created": "2026-03-15T04:20:38.397440300+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "12840",
      "thread_id": "8552"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "FMTID": "{b725f130-47ef-101a-a5f1-02608c9eebac}",
    "PID": "      10"
  },
  "message": ""
}

Event ID 15504 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
PropertyDescription_SHFormatForDisplay
Opcode
Stop

Fields #

NameDescription
FMTID GUID
PID UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "15504",
    "version": "0",
    "level": "4",
    "task": "15503",
    "opcode": "2",
    "keywords": 9223372036854906880,
    "time_created": "2026-03-15T04:20:38.397448500+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "12840",
      "thread_id": "8552"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "FMTID": "{b725f130-47ef-101a-a5f1-02608c9eebac}",
    "PID": "      10"
  },
  "message": ""
}

Event ID 15505 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
PropertyDescription_SHGetPropertyDescription
Opcode
Start

Fields #

NameDescription
FMTID GUID
PID UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "15505",
    "version": "0",
    "level": "4",
    "task": "15505",
    "opcode": "1",
    "keywords": 9223372036854906880,
    "time_created": "2026-03-15T04:20:18.461203300+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "12840",
      "thread_id": "4760"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "FMTID": "{9f4c2855-9f79-4b39-a8d0-e1d42de1d5f3}",
    "PID": "       3"
  },
  "message": ""
}

Event ID 15506 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
PropertyDescription_SHGetPropertyDescription
Opcode
Stop

Fields #

NameDescription
FMTID GUID
PID UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "15506",
    "version": "0",
    "level": "4",
    "task": "15505",
    "opcode": "2",
    "keywords": 9223372036854906880,
    "time_created": "2026-03-15T04:20:18.461208500+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "12840",
      "thread_id": "4760"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "FMTID": "{9f4c2855-9f79-4b39-a8d0-e1d42de1d5f3}",
    "PID": "       3"
  },
  "message": ""
}

Event ID 15507 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PropertyDescription_SHGetPropertyDescriptionByName
Opcode
Start

Fields #

NameDescription
CanonicalName UnicodeString

Event ID 15508 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PropertyDescription_SHGetPropertyDescriptionByName
Opcode
Stop

Fields #

NameDescription
CanonicalName UnicodeString

Event ID 15509 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PropertyDescription_SHGetPropertyDescriptionListFromString
Opcode
Start

Event ID 15510 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PropertyDescription_SHGetPropertyDescriptionListFromString
Opcode
Stop

Event ID 15511 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
PropertyDescription_CoerceToCanonicalValue
Opcode
Start

Fields #

NameDescription
FMTID GUID
PID UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "15511",
    "version": "0",
    "level": "4",
    "task": "15511",
    "opcode": "1",
    "keywords": 9223372036854906880,
    "time_created": "2026-03-15T04:20:38.358169000+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "12840",
      "thread_id": "4164"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "FMTID": "{41cf5ae0-f75a-4806-bd87-59c7d9248eb9}",
    "PID": "     100"
  },
  "message": ""
}

Event ID 15512 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
PropertyDescription_CoerceToCanonicalValue
Opcode
Stop

Fields #

NameDescription
FMTID GUID
PID UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "15512",
    "version": "0",
    "level": "4",
    "task": "15511",
    "opcode": "2",
    "keywords": 9223372036854906880,
    "time_created": "2026-03-15T04:20:38.358173200+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "12840",
      "thread_id": "4164"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "FMTID": "{41cf5ae0-f75a-4806-bd87-59c7d9248eb9}",
    "PID": "     100"
  },
  "message": ""
}

Event ID 15513 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
PropertyDescription_IsValueCanonical
Opcode
Start

Fields #

NameDescription
FMTID GUID
PID UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "15513",
    "version": "0",
    "level": "4",
    "task": "15513",
    "opcode": "1",
    "keywords": 9223372036854906880,
    "time_created": "2026-03-15T04:20:38.362688800+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "12840",
      "thread_id": "5416"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "FMTID": "{32bcb03c-7f34-4e3f-bbb2-ebe63629f5e4}",
    "PID": "     100"
  },
  "message": ""
}

Event ID 15514 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
PropertyDescription_IsValueCanonical
Opcode
Stop

Fields #

NameDescription
FMTID GUID
PID UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "15514",
    "version": "0",
    "level": "4",
    "task": "15513",
    "opcode": "2",
    "keywords": 9223372036854906880,
    "time_created": "2026-03-15T04:20:38.362689700+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "12840",
      "thread_id": "5416"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "FMTID": "{32bcb03c-7f34-4e3f-bbb2-ebe63629f5e4}",
    "PID": "     100"
  },
  "message": ""
}

Event ID 15515 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
PropertySchema_LoadFromSavedBinaryForm
Opcode
Start

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "15515",
    "version": "0",
    "level": "4",
    "task": "15515",
    "opcode": "1",
    "keywords": 9223372036854906880,
    "time_created": "2026-03-15T04:22:59.123831800+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "9500",
      "thread_id": "11152"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 15516 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
PropertySchema_LoadFromSavedBinaryForm
Opcode
Stop

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "15516",
    "version": "0",
    "level": "4",
    "task": "15515",
    "opcode": "2",
    "keywords": 9223372036854906880,
    "time_created": "2026-03-15T04:22:59.123833300+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "9500",
      "thread_id": "11152"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 15517 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PropertySchema_SaveAsBinaryForm
Opcode
Start

Event ID 15518 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PropertySchema_SaveAsBinaryForm
Opcode
Stop

Event ID 15519 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
SemanticType_PSGetSemanticTypeByName
Opcode
Start

Fields #

NameDescription
CanonicalName UnicodeString

Event ID 15520 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
SemanticType_PSGetSemanticTypeByName
Opcode
Stop

Fields #

NameDescription
CanonicalName UnicodeString

Event ID 16501 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
PropertyProvider_Commit
Opcode
Start

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "16501",
    "version": "0",
    "level": "4",
    "task": "16501",
    "opcode": "1",
    "keywords": 9223372036854906880,
    "time_created": "2026-03-15T04:22:59.123848800+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "9500",
      "thread_id": "11152"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 16502 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
PropertyProvider_Commit
Opcode
Stop

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "16502",
    "version": "0",
    "level": "4",
    "task": "16501",
    "opcode": "2",
    "keywords": 9223372036854906880,
    "time_created": "2026-03-15T04:22:59.124672400+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "9500",
      "thread_id": "11152"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 16503 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
PropertyProvider_GetValue
Opcode
Start

Fields #

NameDescription
FMTID GUID
PID UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "16503",
    "version": "0",
    "level": "4",
    "task": "16503",
    "opcode": "1",
    "keywords": 9223372036854906880,
    "time_created": "2026-03-15T04:20:38.358148500+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "12840",
      "thread_id": "4164"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "FMTID": "{41cf5ae0-f75a-4806-bd87-59c7d9248eb9}",
    "PID": "     100"
  },
  "message": ""
}

Event ID 16504 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
PropertyProvider_GetValue
Opcode
Stop

Fields #

NameDescription
FMTID GUID
PID UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "16504",
    "version": "0",
    "level": "4",
    "task": "16503",
    "opcode": "2",
    "keywords": 9223372036854906880,
    "time_created": "2026-03-15T04:20:38.358173700+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "12840",
      "thread_id": "4164"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "FMTID": "{41cf5ae0-f75a-4806-bd87-59c7d9248eb9}",
    "PID": "     100"
  },
  "message": ""
}

Event ID 16505 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PropertyProvider_GetValueObject
Opcode
Start

Fields #

NameDescription
FMTID GUID
PID UInt32

Event ID 16506 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PropertyProvider_GetValueObject
Opcode
Stop

Fields #

NameDescription
FMTID GUID
PID UInt32

Event ID 16507 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
PropertyProvider_SetValue
Opcode
Start

Fields #

NameDescription
FMTID GUID
PID UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "16507",
    "version": "0",
    "level": "4",
    "task": "16507",
    "opcode": "1",
    "keywords": 9223372036854906880,
    "time_created": "2026-03-15T04:20:38.362684000+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "12840",
      "thread_id": "5416"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "FMTID": "{32bcb03c-7f34-4e3f-bbb2-ebe63629f5e4}",
    "PID": "     100"
  },
  "message": ""
}

Event ID 16508 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
PropertyProvider_SetValue
Opcode
Stop

Fields #

NameDescription
FMTID GUID
PID UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "16508",
    "version": "0",
    "level": "4",
    "task": "16507",
    "opcode": "2",
    "keywords": 9223372036854906880,
    "time_created": "2026-03-15T04:20:38.362691800+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "12840",
      "thread_id": "5416"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "FMTID": "{32bcb03c-7f34-4e3f-bbb2-ebe63629f5e4}",
    "PID": "     100"
  },
  "message": ""
}

Event ID 16509 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PropertyStoreOverPropertySetStorage_GetValue
Opcode
Start

Event ID 16510 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PropertyStoreOverPropertySetStorage_GetValue
Opcode
Stop

Event ID 16511 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PropertyStoreOverPropertySetStorage_SetValue
Opcode
Start

Fields #

NameDescription
FMTID GUID
PID UInt32

Event ID 16512 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PropertyStoreOverPropertySetStorage_SetValue
Opcode
Stop

Fields #

NameDescription
FMTID GUID
PID UInt32

Event ID 16513 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PropertyStoreOverPropertySetStorage_Commit
Opcode
Start

Event ID 16514 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PropertyStoreOverPropertySetStorage_Commit
Opcode
Stop

Event ID 16600 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
FilePropertyStoreFactory_GetPropertyHandler
Opcode
Start

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "16600",
    "version": "0",
    "level": "4",
    "task": "16600",
    "opcode": "1",
    "keywords": 9223372036854906880,
    "time_created": "2026-03-16T00:23:22.277790300+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "1452",
      "thread_id": "9352"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 16601 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
FilePropertyStoreFactory_GetPropertyHandler
Opcode
Stop

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "16601",
    "version": "0",
    "level": "4",
    "task": "16600",
    "opcode": "2",
    "keywords": 9223372036854906880,
    "time_created": "2026-03-16T00:23:22.455705100+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "1452",
      "thread_id": "9352"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 16602 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
FilePropertyStoreFactory_GetInnateStore
Opcode
Start

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "16602",
    "version": "0",
    "level": "4",
    "task": "16602",
    "opcode": "1",
    "keywords": 9223372036854906880,
    "time_created": "2026-03-15T04:20:38.358126500+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "12840",
      "thread_id": "4164"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 16603 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
FilePropertyStoreFactory_GetInnateStore
Opcode
Stop

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "16603",
    "version": "0",
    "level": "4",
    "task": "16602",
    "opcode": "2",
    "keywords": 9223372036854906880,
    "time_created": "2026-03-15T04:20:38.358130400+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "12840",
      "thread_id": "4164"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 16604 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
FilePropertyStoreFactory_GetFallbackStore
Opcode
Start

Event ID 16605 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
FilePropertyStoreFactory_GetFallbackStore
Opcode
Stop

Event ID 16606 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
FilePropertyStoreFactory_GetDesktopIniStore
Opcode
Start

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "16606",
    "version": "0",
    "level": "4",
    "task": "16606",
    "opcode": "1",
    "keywords": 9223372036854906880,
    "time_created": "2026-03-16T00:23:22.277805100+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "1452",
      "thread_id": "9352"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 16607 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
FilePropertyStoreFactory_GetDesktopIniStore
Opcode
Stop

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "16607",
    "version": "0",
    "level": "4",
    "task": "16606",
    "opcode": "2",
    "keywords": 9223372036854906880,
    "time_created": "2026-03-16T00:23:22.277819000+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "1452",
      "thread_id": "9352"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 16608 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
FileFolderInnateStore_GetValue
Opcode
Start

Fields #

NameDescription
FMTID GUID
PID UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "16608",
    "version": "0",
    "level": "4",
    "task": "16608",
    "opcode": "1",
    "keywords": 9223372036854906880,
    "time_created": "2026-03-15T04:20:38.358159100+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "12840",
      "thread_id": "4164"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "FMTID": "{41cf5ae0-f75a-4806-bd87-59c7d9248eb9}",
    "PID": "     100"
  },
  "message": ""
}

Event ID 16609 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
FileFolderInnateStore_GetValue
Opcode
Stop

Fields #

NameDescription
FMTID GUID
PID UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "16609",
    "version": "0",
    "level": "4",
    "task": "16608",
    "opcode": "2",
    "keywords": 9223372036854906880,
    "time_created": "2026-03-15T04:20:38.358162800+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "12840",
      "thread_id": "4164"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "FMTID": "{41cf5ae0-f75a-4806-bd87-59c7d9248eb9}",
    "PID": "     100"
  },
  "message": ""
}

Event ID 16610 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
FileFolderInnateStore_GetCount
Opcode
Start

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "16610",
    "version": "0",
    "level": "4",
    "task": "16610",
    "opcode": "1",
    "keywords": 9223372036854906880,
    "time_created": "2026-03-16T00:21:39.172229400+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "5680",
      "thread_id": "11856"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 16611 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
FileFolderInnateStore_GetCount
Opcode
Stop

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "16611",
    "version": "0",
    "level": "4",
    "task": "16610",
    "opcode": "2",
    "keywords": 9223372036854906880,
    "time_created": "2026-03-16T00:21:39.172245400+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "5680",
      "thread_id": "11856"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 16612 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
FileFolderInnateStore_GetAt
Opcode
Start

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "16612",
    "version": "0",
    "level": "4",
    "task": "16612",
    "opcode": "1",
    "keywords": 9223372036854906880,
    "time_created": "2026-03-16T00:21:39.172261200+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "5680",
      "thread_id": "11856"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 16613 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
FileFolderInnateStore_GetAt
Opcode
Stop

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "16613",
    "version": "0",
    "level": "4",
    "task": "16612",
    "opcode": "2",
    "keywords": 9223372036854906880,
    "time_created": "2026-03-16T00:21:39.172279700+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "5680",
      "thread_id": "11856"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 16614 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
FileFolderFallbackStore_GetValue
Opcode
Start

Fields #

NameDescription
FMTID GUID
PID UInt32

Event ID 16615 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
FileFolderFallbackStore_GetValue
Opcode
Stop

Fields #

NameDescription
FMTID GUID
PID UInt32

Event ID 16616 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
FileFolderFallbackStore_GetCount
Opcode
Start

Event ID 16617 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
FileFolderFallbackStore_GetCount
Opcode
Stop

Event ID 16618 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
FileFolderFallbackStore_GetAt
Opcode
Start

Event ID 16619 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
FileFolderFallbackStore_GetAt
Opcode
Stop

Event ID 16620 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
FilePropertyStoreFactory_GetPropertyHandler

Fields #

NameDescription
FMTID GUID
PID UInt32

Event ID 16621 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
FileFolder_UseItemCacheContext

Fields #

NameDescription
psz UnicodeString

Event ID 16700 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
ShellItem_GetPropertyStore
Opcode
Start

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "16700",
    "version": "0",
    "level": "4",
    "task": "16700",
    "opcode": "1",
    "keywords": 9223372036854906880,
    "time_created": "2026-03-15T04:20:38.358263800+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "12840",
      "thread_id": "4164"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 16701 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
ShellItem_GetPropertyStore
Opcode
Stop

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "16701",
    "version": "0",
    "level": "4",
    "task": "16700",
    "opcode": "2",
    "keywords": 9223372036854906880,
    "time_created": "2026-03-15T04:20:38.358357700+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "12840",
      "thread_id": "4164"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 16702 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
ShellItem_GetPropertyStoreForKeys
Opcode
Start

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "16702",
    "version": "0",
    "level": "4",
    "task": "16702",
    "opcode": "1",
    "keywords": 9223372036854906880,
    "time_created": "2026-03-15T04:20:38.358066600+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "12840",
      "thread_id": "4164"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 16703 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
ShellItem_GetPropertyStoreForKeys
Opcode
Stop

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "16703",
    "version": "0",
    "level": "4",
    "task": "16702",
    "opcode": "2",
    "keywords": 9223372036854906880,
    "time_created": "2026-03-15T04:20:38.358147300+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "12840",
      "thread_id": "4164"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 16704 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
ShellItem_GetPropertyStoreWithCreateObject
Opcode
Start

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "16704",
    "version": "0",
    "level": "4",
    "task": "16704",
    "opcode": "1",
    "keywords": 9223372036854906880,
    "time_created": "2026-03-16T00:21:39.099905900+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "5680",
      "thread_id": "11856"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 16705 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
ShellItem_GetPropertyStoreWithCreateObject
Opcode
Stop

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "16705",
    "version": "0",
    "level": "4",
    "task": "16704",
    "opcode": "2",
    "keywords": 9223372036854906880,
    "time_created": "2026-03-16T00:21:39.171889800+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "5680",
      "thread_id": "11856"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 16706 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellItem_GetPropertyDescriptionList
Opcode
Start

Event ID 16707 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellItem_GetPropertyDescriptionList
Opcode
Stop

Event ID 16708 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
ShellItem_CreatePropertyProviderHelper
Opcode
Start

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "16708",
    "version": "0",
    "level": "4",
    "task": "16708",
    "opcode": "1",
    "keywords": 9223372036854906880,
    "time_created": "2026-03-15T04:20:38.358133900+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "12840",
      "thread_id": "4164"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 16709 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
ShellItem_CreatePropertyProviderHelper
Opcode
Stop

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "16709",
    "version": "0",
    "level": "4",
    "task": "16708",
    "opcode": "2",
    "keywords": 9223372036854906880,
    "time_created": "2026-03-15T04:20:38.358146400+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "12840",
      "thread_id": "4164"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 16710 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellItemArray_GetPropertyStore
Opcode
Start

Event ID 16711 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellItemArray_GetPropertyStore
Opcode
Stop

Event ID 16712 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellItemArray_GetPropertyDescriptionList
Opcode
Start

Event ID 16713 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellItemArray_GetPropertyDescriptionList
Opcode
Stop

Event ID 16714 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
CachedShellItem_GetPropertyStore
Opcode
Start

Event ID 16715 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
CachedShellItem_GetPropertyStore
Opcode
Stop

Event ID 16716 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
ItemFallbackStore_GetValue
Opcode
Start

Fields #

NameDescription
FMTID GUID
PID UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "16716",
    "version": "0",
    "level": "4",
    "task": "16716",
    "opcode": "1",
    "keywords": 9223372036854906880,
    "time_created": "2026-03-15T04:20:38.360917200+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "12840",
      "thread_id": "4164"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "FMTID": "{9b174b35-40ff-11d2-a27e-00c04fc30871}",
    "PID": "      10"
  },
  "message": ""
}

Event ID 16717 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
ItemFallbackStore_GetValue
Opcode
Stop

Fields #

NameDescription
FMTID GUID
PID UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "16717",
    "version": "0",
    "level": "4",
    "task": "16716",
    "opcode": "2",
    "keywords": 9223372036854906880,
    "time_created": "2026-03-15T04:20:38.360918600+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "12840",
      "thread_id": "4164"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "FMTID": "{9b174b35-40ff-11d2-a27e-00c04fc30871}",
    "PID": "      10"
  },
  "message": ""
}

Event ID 16718 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
ItemFallbackStore_GetCount
Opcode
Start

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "16718",
    "version": "0",
    "level": "4",
    "task": "16718",
    "opcode": "1",
    "keywords": 9223372036854906880,
    "time_created": "2026-03-16T00:21:39.173847300+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "5680",
      "thread_id": "11856"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 16719 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
ItemFallbackStore_GetCount
Opcode
Stop

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "16719",
    "version": "0",
    "level": "4",
    "task": "16718",
    "opcode": "2",
    "keywords": 9223372036854906880,
    "time_created": "2026-03-16T00:21:39.199083000+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "5680",
      "thread_id": "11856"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 16720 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
ItemFallbackStore_GetAt
Opcode
Start

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "16720",
    "version": "0",
    "level": "4",
    "task": "16720",
    "opcode": "1",
    "keywords": 9223372036854906880,
    "time_created": "2026-03-16T00:21:39.199113800+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "5680",
      "thread_id": "11856"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 16721 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
ItemFallbackStore_GetAt
Opcode
Stop

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "16721",
    "version": "0",
    "level": "4",
    "task": "16720",
    "opcode": "2",
    "keywords": 9223372036854906880,
    "time_created": "2026-03-16T00:21:39.199126900+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "5680",
      "thread_id": "11856"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 16722 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
ItemStoreOverFolder_GetValue
Opcode
Start

Fields #

NameDescription
FMTID GUID
PID UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "16722",
    "version": "0",
    "level": "4",
    "task": "16722",
    "opcode": "1",
    "keywords": 9223372036854906880,
    "time_created": "2026-03-15T04:20:38.358150300+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "12840",
      "thread_id": "4164"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "FMTID": "{41cf5ae0-f75a-4806-bd87-59c7d9248eb9}",
    "PID": "     100"
  },
  "message": ""
}

Event ID 16723 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
ItemStoreOverFolder_GetValue
Opcode
Stop

Fields #

NameDescription
FMTID GUID
PID UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "16723",
    "version": "0",
    "level": "4",
    "task": "16722",
    "opcode": "2",
    "keywords": 9223372036854906880,
    "time_created": "2026-03-15T04:20:38.358151500+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "12840",
      "thread_id": "4164"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "FMTID": "{41cf5ae0-f75a-4806-bd87-59c7d9248eb9}",
    "PID": "     100"
  },
  "message": ""
}

Event ID 16724 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
ItemStoreOverFolder_GetValueFromDetailsEx
Opcode
Start

Fields #

NameDescription
FMTID GUID
PID UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "16724",
    "version": "0",
    "level": "4",
    "task": "16724",
    "opcode": "1",
    "keywords": 9223372036854906880,
    "time_created": "2026-03-15T04:20:38.360195000+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "12840",
      "thread_id": "4164"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "FMTID": "{9b174b35-40ff-11d2-a27e-00c04fc30871}",
    "PID": "      10"
  },
  "message": ""
}

Event ID 16725 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
ItemStoreOverFolder_GetValueFromDetailsEx
Opcode
Stop

Fields #

NameDescription
FMTID GUID
PID UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "16725",
    "version": "0",
    "level": "4",
    "task": "16724",
    "opcode": "2",
    "keywords": 9223372036854906880,
    "time_created": "2026-03-15T04:20:38.360371200+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "12840",
      "thread_id": "4164"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "FMTID": "{b2f9b9d6-fec4-4dd5-94d7-8957488c807b}",
    "PID": "       2"
  },
  "message": ""
}

Event ID 16726 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
ItemStoreOverFolder_GetCount
Opcode
Start

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "16726",
    "version": "0",
    "level": "4",
    "task": "16726",
    "opcode": "1",
    "keywords": 9223372036854906880,
    "time_created": "2026-03-16T00:21:39.172072600+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "5680",
      "thread_id": "11856"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 16727 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
ItemStoreOverFolder_GetCount
Opcode
Stop

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "16727",
    "version": "0",
    "level": "4",
    "task": "16726",
    "opcode": "2",
    "keywords": 9223372036854906880,
    "time_created": "2026-03-16T00:21:39.172086200+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "5680",
      "thread_id": "11856"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 16728 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
ItemStoreOverFolder_GetAt
Opcode
Start

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "16728",
    "version": "0",
    "level": "4",
    "task": "16728",
    "opcode": "1",
    "keywords": 9223372036854906880,
    "time_created": "2026-03-16T00:21:39.172099800+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "5680",
      "thread_id": "11856"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 16729 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
ItemStoreOverFolder_GetAt
Opcode
Stop

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "16729",
    "version": "0",
    "level": "4",
    "task": "16728",
    "opcode": "2",
    "keywords": 9223372036854906880,
    "time_created": "2026-03-16T00:21:39.172112200+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "5680",
      "thread_id": "11856"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 16801 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Library_SQM_CreateLibrary

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmDWORDDatapointValue UInt32

Event ID 16803 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Library_SQM_AddFolder
Opcode
Start

Event ID 16804 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Library_SQM_AddFolder
Opcode
Stop

Event ID 16805 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Library_Location_Count

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmStreamRowLength UInt32
SqmStreamRow Int16

Event ID 16807 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Library_InUsersRoot_Count

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmDWORDDatapointValue UInt32

Event ID 16809 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Library_Save_Location

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmStreamRowLength UInt32
SqmStreamRow Int16

Event ID 16811 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Library_Add_Location

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmStreamRowLength UInt32
SqmStreamRow Int16

Event ID 16813 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Library_Remove_Location

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmStreamRowLength UInt32
SqmStreamRow Int16

Event ID 16815 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Library_Has_Reordered_Locations

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmStreamRowLength UInt32
SqmStreamRow Int16

Event ID 16817 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Add_Library_Location_EntryPoint

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmDWORDDatapointValue UInt32

Event ID 16901 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PHLocationCreator_ScanSearchRoots
Opcode
Start

Event ID 16902 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PHLocationCreator_ScanSearchRoots
Opcode
Stop

Event ID 16903 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PHLocationCreator_CreateSearchRootLocations
Opcode
Start

Event ID 16904 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PHLocationCreator_CreateSearchRootLocations
Opcode
Stop

Event ID 16905 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PHLocationCreator_RemoveSearchRootLocations
Opcode
Start

Event ID 16906 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PHLocationCreator_RemoveSearchRootLocations
Opcode
Stop

Event ID 16907 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PHLocationCreator_SQM_CreateLibrary

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmStreamRowLength UInt32
SqmStreamRow Int16

Event ID 17001 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Scope_Flatten
Opcode
Start

Event ID 17002 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Scope_Flatten
Opcode
Stop

Event ID 17003 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ScopePicker_Open
Opcode
Start

Event ID 17004 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ScopePicker_Open
Opcode
Stop

Event ID 17005 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ScopePicker_Folders_Rendering
Opcode
Start

Event ID 17006 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ScopePicker_Folders_Rendering
Opcode
Stop

Event ID 17007 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Scope_Load_From_XML
Opcode
Start

Event ID 17008 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Scope_Load_From_XML
Opcode
Stop

Fields #

NameDescription
LoopCount UInt32

Event ID 17009 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Scope_Load_From_Stream
Opcode
Start

Event ID 17010 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Scope_Load_From_Stream
Opcode
Stop

Event ID 17101 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shake_Minimize
Opcode
Start

Event ID 17103 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shake_Minimize
Opcode
Stop

Event ID 17105 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shake_MinimizeWorker
Opcode
Start

Event ID 17107 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shake_MinimizeWorker
Opcode
Stop

Event ID 17109 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shake_Restore
Opcode
Start

Event ID 17111 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shake_Restore
Opcode
Stop

Event ID 17113 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shake_RestoreWorker
Opcode
Start

Event ID 17115 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shake_RestoreWorker
Opcode
Stop

Event ID 17117 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shake_MinimizeWorker

Fields #

NameDescription
psz UnicodeString

Event ID 17119 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shake_MinimizeEnabled

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmDWORDDatapointValue UInt32

Event ID 17121 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shake_DetectionCount

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmDWORDDatapointValue UInt32

Event ID 17501 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ResolveUserNames_ResolveSids
Opcode
Start

Event ID 17502 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ResolveUserNames_ResolveSids
Opcode
Stop

Event ID 17503 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ResolveUserNames_ResolveStringSid
Opcode
Start

Event ID 17504 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ResolveUserNames_ResolveStringSid
Opcode
Stop

Event ID 17505 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ResolveUserNames_SHResolveUserNames
Opcode
Start

Event ID 17506 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ResolveUserNames_SHResolveUserNames
Opcode
Stop

Event ID 17507 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ResolveUserNames_FriendlyNameLookup
Opcode
Start

Event ID 17508 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ResolveUserNames_FriendlyNameLookup
Opcode
Stop

Event ID 17509 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ResolveUserNames_SingleSidToNameLookup
Opcode
Start

Event ID 17510 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ResolveUserNames_SingleSidToNameLookup
Opcode
Stop

Event ID 17511 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ResolveUserNames_MultipleSidsToNamesLookup
Opcode
Start

Event ID 17512 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ResolveUserNames_MultipleSidsToNamesLookup
Opcode
Stop

Event ID 17513 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ResolveUserNames_CachedFriendlyNameLookup
Opcode
Start

Event ID 17514 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ResolveUserNames_CachedFriendlyNameLookup
Opcode
Stop

Event ID 17515 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
GetCorrectOwnerSid_Lookup
Opcode
Start

Fields #

NameDescription
Success UInt32
Path UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "17515",
    "version": "0",
    "level": "4",
    "task": "17515",
    "opcode": "1",
    "keywords": 9223372036854906880,
    "time_created": "2026-03-15T04:20:38.364128200+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "12840",
      "thread_id": "4164"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Success": "       1",
    "Path": "C:\\Users\\domainadmin\\AppData\\Roaming\\Microsoft\\Windows\\Themes\\CachedFiles"
  },
  "message": ""
}

Event ID 17516 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
GetCorrectOwnerSid_Lookup
Opcode
Stop

Fields #

NameDescription
Success UInt32
Path UnicodeString

Event ID 17517 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
GetCorrectOwnerSid_LookupFromRegistry
Opcode
Start

Event ID 17518 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
GetCorrectOwnerSid_LookupFromRegistry
Opcode
Stop

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmDWORDDatapointValue UInt32

Event ID 18001 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shdocvw_BaseBrowser_DocumentComplete

Event ID 18003 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shdocvw_BaseBrowser_ExplorerWindowReady

Event ID 18005 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shdocvw_BaseBrowser_Navigate
Opcode
Start

Event ID 18006 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shdocvw_BaseBrowser_Navigate
Opcode
Stop

Event ID 18007 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shdocvw_PanningTool_ScrollElementBy
Opcode
Start

Event ID 18008 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shdocvw_PanningTool_ScrollElementBy
Opcode
Stop

Event ID 18009 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shdocvw_PanningTool_GetPanningProperties
Opcode
Start

Event ID 18010 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shdocvw_PanningTool_GetPanningProperties
Opcode
Stop

Event ID 18011 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shdocvw_PanningTool_SinglePan

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmDWORDDatapointValue UInt32

Event ID 18012 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shdocvw_PanningTool_Change_PanningMode

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmStreamRowLength UInt32
SqmStreamRow Int16

Event ID 18013 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shdocvw_BaseBrowser_Explorer_Search_Query_Stream

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmStreamRowLength UInt32
SqmStreamRow Int16

Event ID 18015 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ExplorerFrame_FrameFirstVisible

Event ID 18017 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ExplorerFrame_FrameFirstRedraw
Opcode
Start

Event ID 18018 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ExplorerFrame_FrameFirstRedraw
Opcode
Stop

Event ID 18501 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_AutoListEditor_CommitSearch

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmDWORDDatapointValue UInt32

Event ID 18503 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_AutoListEditor_Displayed

Event ID 18505 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_AutoListEditor_FillScopes
Opcode
Start

Event ID 18506 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_AutoListEditor_FillScopes
Opcode
Stop

Event ID 18507 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_AutoListEditor_GetPropertyList
Opcode
Start

Event ID 18508 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_AutoListEditor_GetPropertyList
Opcode
Stop

Event ID 18509 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_AutoListEditor_LaunchSearch

Event ID 18511 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_AutoPlay_IDynamicHWHandler
Opcode
Start

Event ID 18512 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_AutoPlay_IDynamicHWHandler
Opcode
Stop

Event ID 18513 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_AutoPlay_IHWNotificationHandler
Opcode
Start

Event ID 18514 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_AutoPlay_IHWNotificationHandler
Opcode
Stop

Event ID 18515 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_AutoPlay_IQueryCancelAutoPlay
Opcode
Start

Event ID 18516 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_AutoPlay_IQueryCancelAutoPlay
Opcode
Stop

Event ID 18517 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_AutoPlay_Logic
Opcode
Start

Event ID 18518 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_AutoPlay_Logic
Opcode
Stop

Event ID 18521 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_AutoPlay_Sniff
Opcode
Start

Event ID 18522 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_AutoPlay_Sniff
Opcode
Stop

Event ID 18523 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_CDesktopBrowser_LButtonAction

Fields #

NameDescription
Message UInt32

Event ID 18524 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_CDesktopBrowser_ShellReady

Event ID 18525 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_CExplorerBrowser_BrowseObjectInternal
Opcode
Start

Event ID 18526 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_CExplorerBrowser_BrowseObjectInternal
Opcode
Stop

Event ID 18527 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_CFindCmd_DoSearch
Opcode
Start

Event ID 18528 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_CFindCmd_DoSearch
Opcode
Stop

Event ID 18529 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_CGrepQuery_Crawl
Opcode
Start

Event ID 18530 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_CGrepQuery_Crawl
Opcode
Stop

Event ID 18531 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_CommandModule_SelectionChange
Opcode
Start

Event ID 18532 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_CommandModule_SelectionChange
Opcode
Stop

Event ID 18533 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_ControlPanel_CategoryView_Init
Opcode
Start

Event ID 18534 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_ControlPanel_CategoryView_Init
Opcode
Stop

Event ID 18535 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_ControlPanel_CategoryView_LoadTasks
Opcode
Start

Event ID 18536 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_ControlPanel_CategoryView_LoadTasks
Opcode
Stop

Event ID 18537 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_ControlPanel_CategoryView_Search
Opcode
Start

Event ID 18538 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_ControlPanel_CategoryView_Search
Opcode
Stop

Event ID 18539 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_ControlPanel_NavPane_Init
Opcode
Start

Event ID 18540 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_ControlPanel_NavPane_Init
Opcode
Stop

Event ID 18541 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_PinnedApplications_SQMStream

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmStreamRowLength UInt32
SqmStreamRow Int16

Event ID 18543 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_AutoPlay_Proximity_Sniff
Opcode
Start

Event ID 18544 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_AutoPlay_Proximity_Sniff
Opcode
Stop

Event ID 18545 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_DefView_LoadImage
Opcode
Start

Fields #

NameDescription
FileName UnicodeString
ImageQualityFlags UInt32

Event ID 18546 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_DefView_LoadImage
Opcode
Stop

Fields #

NameDescription
HRESULT UInt32

Event ID 18547 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_DefView_AutoSizeColumns
Opcode
Start

Event ID 18548 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_DefView_AutoSizeColumns
Opcode
Stop

Event ID 18549 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
Shell32_DefView_Enumeration
Opcode
Start

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "18549",
    "version": "0",
    "level": "4",
    "task": "18549",
    "opcode": "1",
    "keywords": 9223372036854841344,
    "time_created": "2026-03-15T04:21:14.993884500+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "12840",
      "thread_id": "13880"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 18550 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
Shell32_DefView_Enumeration
Opcode
Stop

Fields #

NameDescription
Count UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "18550",
    "version": "0",
    "level": "4",
    "task": "18549",
    "opcode": "2",
    "keywords": 9223372036854841344,
    "time_created": "2026-03-15T04:21:15.000893300+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "12840",
      "thread_id": "13880"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Count": "      13"
  },
  "message": ""
}

Event ID 18551 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_DefView_Filter
Opcode
Start

Event ID 18552 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_DefView_Filter
Opcode
Stop

Event ID 18553 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_DefView_Filter_Generation
Opcode
Start

Event ID 18554 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_DefView_Filter_Generation
Opcode
Stop

Event ID 18555 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_DefView_FirstBatch
Opcode
Start

Event ID 18556 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_DefView_FirstBatch
Opcode
Stop

Event ID 18557 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_DefView_Group
Opcode
Start

Event ID 18558 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_DefView_Group
Opcode
Stop

Event ID 18559 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
Shell32_DefView_Initial_Sort
Opcode
Start

Fields #

NameDescription
LoopCount UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "18559",
    "version": "0",
    "level": "4",
    "task": "18559",
    "opcode": "1",
    "keywords": 9223372036854841344,
    "time_created": "2026-03-15T04:21:15.000979300+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "12840",
      "thread_id": "13880"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "LoopCount": "      13"
  },
  "message": ""
}

Event ID 18560 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
Shell32_DefView_Initial_Sort
Opcode
Stop

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "18560",
    "version": "0",
    "level": "4",
    "task": "18559",
    "opcode": "2",
    "keywords": 9223372036854841344,
    "time_created": "2026-03-15T04:21:15.001230400+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "12840",
      "thread_id": "13880"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 18561 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
Shell32_DefView_ListViewDone

Fields #

NameDescription
Count UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "18561",
    "version": "0",
    "level": "4",
    "task": "18561",
    "opcode": "0",
    "keywords": 9223372036854841344,
    "time_created": "2026-03-15T04:21:15.030524900+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "12840",
      "thread_id": "8552"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Count": "       4"
  },
  "message": ""
}

Event ID 18563 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_DefView_PropertiesDone

Event ID 18565 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_DefView_RightClickContextMenu

Event ID 18567 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_DefView_Stack
Opcode
Start

Event ID 18568 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_DefView_Stack
Opcode
Stop

Event ID 18569 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
Shell32_DefView_Thumbnail_Extract
Opcode
Start

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "18569",
    "version": "0",
    "level": "4",
    "task": "18569",
    "opcode": "1",
    "keywords": 9223372036854841344,
    "time_created": "2026-03-15T04:20:50.067361900+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "12840",
      "thread_id": "800"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 18570 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
Shell32_DefView_Thumbnail_Extract
Opcode
Stop

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "18570",
    "version": "0",
    "level": "4",
    "task": "18569",
    "opcode": "2",
    "keywords": 9223372036854841344,
    "time_created": "2026-03-15T04:20:50.123063100+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "12840",
      "thread_id": "800"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 18571 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
Shell32_CollectionLock_GetSingleQueueItem

Fields #

NameDescription
TaskID GUID
QueueItemCount Int32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "18571",
    "version": "0",
    "level": "4",
    "task": "18571",
    "opcode": "0",
    "keywords": 9223372036854841344,
    "time_created": "2026-03-15T04:20:38.891644800+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "12840",
      "thread_id": "800"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "TaskID": "{05cdcb31-adfd-4d5a-9c4e-1a5650fe0867}",
    "QueueItemCount": "0"
  },
  "message": ""
}

Event ID 18573 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
Shell32_CollectionLock_GetQueueItems

Fields #

NameDescription
TaskID GUID
QueueItemCount Int32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "18573",
    "version": "0",
    "level": "4",
    "task": "18573",
    "opcode": "0",
    "keywords": 9223372036854841344,
    "time_created": "2026-03-15T04:20:50.066811200+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "12840",
      "thread_id": "13268"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "TaskID": "{76119f10-b9e3-11d1-a7f4-006008059382}",
    "QueueItemCount": "1"
  },
  "message": ""
}

Event ID 18575 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
Shell32_DefView_Thumbnail_Update
Opcode
Start

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "18575",
    "version": "0",
    "level": "4",
    "task": "18575",
    "opcode": "1",
    "keywords": 9223372036854841344,
    "time_created": "2026-03-15T04:20:50.067220300+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "12840",
      "thread_id": "800"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 18576 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
Shell32_DefView_Thumbnail_Update
Opcode
Stop

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "18576",
    "version": "0",
    "level": "4",
    "task": "18575",
    "opcode": "2",
    "keywords": 9223372036854841344,
    "time_created": "2026-03-15T04:20:50.067237800+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "12840",
      "thread_id": "800"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 18577 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
Shell32_DefView_Thumbnail_Updateview
Opcode
Start

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "18577",
    "version": "0",
    "level": "4",
    "task": "18577",
    "opcode": "1",
    "keywords": 9223372036854841344,
    "time_created": "2026-03-15T04:20:50.067349200+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "12840",
      "thread_id": "8552"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 18578 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
Shell32_DefView_Thumbnail_Updateview
Opcode
Stop

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "18578",
    "version": "0",
    "level": "4",
    "task": "18577",
    "opcode": "2",
    "keywords": 9223372036854841344,
    "time_created": "2026-03-15T04:20:50.067356700+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "12840",
      "thread_id": "8552"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 18579 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_DefView_ViewModeChange
Opcode
Start

Fields #

NameDescription
Mode UInt32
IconSize UInt32

Event ID 18580 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_DefView_ViewModeChange
Opcode
Stop

Fields #

NameDescription
Mode UInt32
IconSize UInt32

Event ID 18581 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_Defview_Sort
Opcode
Start

Fields #

NameDescription
LoopCount UInt32

Event ID 18582 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_Defview_Sort
Opcode
Stop

Event ID 18583 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_GeneratingContextMenu
Opcode
Start

Event ID 18584 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_GeneratingContextMenu
Opcode
Stop

Event ID 18585 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_InvokingContextMenu
Opcode
Start

Event ID 18586 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_InvokingContextMenu
Opcode
Stop

Event ID 18587 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_KnownFolderManager_GetEnumKnownFolders
Opcode
Start

Event ID 18588 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_KnownFolderManager_GetEnumKnownFolders
Opcode
Stop

Event ID 18589 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_KnownFolder_GetLocation
Opcode
Start

Event ID 18590 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_KnownFolder_GetLocation
Opcode
Stop

Event ID 18591 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_KnownFolder_GetPath
Opcode
Start

Event ID 18592 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_KnownFolder_GetPath
Opcode
Stop

Event ID 18593 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_KnownFolder_SetPath
Opcode
Start

Event ID 18594 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_KnownFolder_SetPath
Opcode
Stop

Event ID 18595 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_List_Add
Opcode
Start

Event ID 18596 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_List_Add
Opcode
Stop

Event ID 18597 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_List_Enum
Opcode
Start

Event ID 18598 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_List_Enum
Opcode
Stop

Event ID 18599 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_List_Remove
Opcode
Start

Event ID 18600 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_List_Remove
Opcode
Stop

Event ID 18601 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_MountPoint_SHHardwareEvent
Opcode
Start

Event ID 18602 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_MountPoint_SHHardwareEvent
Opcode
Stop

Event ID 18603 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_MountPoint_SHHardwareEvent_DeviceArrived
Opcode
Start

Event ID 18604 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_MountPoint_SHHardwareEvent_DeviceArrived
Opcode
Stop

Event ID 18605 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_MountPoint_SHHardwareEvent_DeviceRemoved
Opcode
Start

Event ID 18606 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_MountPoint_SHHardwareEvent_DeviceRemoved
Opcode
Stop

Event ID 18607 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_MountPoint_SHHardwareEvent_DeviceUpdated
Opcode
Start

Event ID 18608 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_MountPoint_SHHardwareEvent_DeviceUpdated
Opcode
Stop

Event ID 18609 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_MountPoint_SHHardwareEvent_MountPointArrived
Opcode
Start

Event ID 18610 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_MountPoint_SHHardwareEvent_MountPointArrived
Opcode
Stop

Event ID 18611 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_MountPoint_SHHardwareEvent_MountPointRemoved
Opcode
Start

Event ID 18612 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_MountPoint_SHHardwareEvent_MountPointRemoved
Opcode
Stop

Event ID 18613 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_MountPoint_SHHardwareEvent_VolumeArrived
Opcode
Start

Event ID 18614 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_MountPoint_SHHardwareEvent_VolumeArrived
Opcode
Stop

Event ID 18615 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_MountPoint_SHHardwareEvent_VolumeDismounted
Opcode
Start

Event ID 18616 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_MountPoint_SHHardwareEvent_VolumeDismounted
Opcode
Stop

Event ID 18617 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_MountPoint_SHHardwareEvent_VolumeMounted
Opcode
Start

Event ID 18618 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_MountPoint_SHHardwareEvent_VolumeMounted
Opcode
Stop

Event ID 18619 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_MountPoint_SHHardwareEvent_VolumeRemoved
Opcode
Start

Event ID 18620 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_MountPoint_SHHardwareEvent_VolumeRemoved
Opcode
Stop

Event ID 18621 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_MountPoint_SHHardwareEvent_VolumeUpdated
Opcode
Start

Event ID 18622 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_MountPoint_SHHardwareEvent_VolumeUpdated
Opcode
Stop

Event ID 18623 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_MountPoint_WMDeviceChange
Opcode
Start

Event ID 18624 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_MountPoint_WMDeviceChange
Opcode
Stop

Event ID 18625 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_MountPoint_WMDeviceChange_MediaArrival
Opcode
Start

Event ID 18626 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_MountPoint_WMDeviceChange_MediaArrival
Opcode
Stop

Event ID 18627 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_MountPoint_WMDeviceChange_MediaRemoval
Opcode
Start

Event ID 18628 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_MountPoint_WMDeviceChange_MediaRemoval
Opcode
Stop

Event ID 18629 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_MountPoint_WMDeviceChange_MountPointArrival
Opcode
Start

Event ID 18630 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_MountPoint_WMDeviceChange_MountPointArrival
Opcode
Stop

Event ID 18631 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_MountPoint_WMDeviceChange_MountPointRemoval
Opcode
Start

Event ID 18632 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_MountPoint_WMDeviceChange_MountPointRemoval
Opcode
Stop

Event ID 18633 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_MountPoint_WMDeviceChange_NetShareArrival
Opcode
Start

Event ID 18634 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_MountPoint_WMDeviceChange_NetShareArrival
Opcode
Stop

Event ID 18635 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_MountPoint_WMDeviceChange_NetShareRemoval
Opcode
Start

Event ID 18636 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_MountPoint_WMDeviceChange_NetShareRemoval
Opcode
Stop

Event ID 18637 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_PSC_Autolist_Show
Opcode
Start

Event ID 18638 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_PSC_Autolist_Show
Opcode
Stop

Event ID 18639 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_PSC_Explorer_Template_Change
Opcode
Start

Event ID 18640 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_PSC_Explorer_Template_Change
Opcode
Stop

Event ID 18641 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_SHGetFolderLocation
Opcode
Start

Event ID 18642 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_SHGetFolderLocation
Opcode
Stop

Event ID 18645 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
Shell32_SHGetFolderPath
Opcode
Start

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "18645",
    "version": "0",
    "level": "4",
    "task": "18645",
    "opcode": "1",
    "keywords": 9223372036855824384,
    "time_created": "2026-03-15T04:20:20.624939600+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{d73f5340-b345-000c-cd30-43d745b3dc01}"
    },
    "execution": {
      "process_id": "14792",
      "thread_id": "10916"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 18646 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
Shell32_SHGetFolderPath
Opcode
Stop

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "18646",
    "version": "0",
    "level": "4",
    "task": "18645",
    "opcode": "2",
    "keywords": 9223372036855824384,
    "time_created": "2026-03-15T04:20:20.624951100+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{d73f5340-b345-000c-cd30-43d745b3dc01}"
    },
    "execution": {
      "process_id": "14792",
      "thread_id": "10916"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 18649 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_SHSetFolderPath
Opcode
Start

Event ID 18650 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_SHSetFolderPath
Opcode
Stop

Event ID 18653 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_DefView_Keydown

Event ID 18654 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_DefView_NoIShellFolder2

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmStreamRowLength UInt32
SqmStreamRow Int16

Event ID 18657 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_ControlPanel_SQM_LinkClicked

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmStreamRowLength UInt32
SqmStreamRow Int16

Event ID 18658 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_ControlPanel_SQM_ViewMode

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmDWORDDatapointValue UInt32

Event ID 18659 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_ControlPanel_FloppyOrCD_Launch

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmDWORDDatapointValue UInt32

Event ID 18660 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_ControlPanel_SQM_ViewChange

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmDWORDDatapointValue UInt32

Event ID 18661 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_ExplorerBrowser_Ready

Fields #

NameDescription
Count UInt32

Event ID 18663 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
Shell32_DefView_HighQualityStretch
Opcode
Start

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "18663",
    "version": "0",
    "level": "4",
    "task": "18663",
    "opcode": "1",
    "keywords": 9223372036854841344,
    "time_created": "2026-03-15T04:20:50.123504800+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "12840",
      "thread_id": "8552"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 18664 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
Shell32_DefView_HighQualityStretch
Opcode
Stop

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "18664",
    "version": "0",
    "level": "4",
    "task": "18663",
    "opcode": "2",
    "keywords": 9223372036854841344,
    "time_created": "2026-03-15T04:20:50.123659000+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "12840",
      "thread_id": "8552"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 18665 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_DefView_Scroll

Event ID 18669 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_DefView_Filtering_Clicked

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmDWORDDatapointValue UInt32

Event ID 18675 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_Search_Index_Enabled

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmDWORDDatapointValue UInt32

Event ID 18676 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_List_LaunchInBasket

Event ID 18677 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_ItemThumbnail_SetItems
Opcode
Start

Event ID 18678 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_ItemThumbnail_SetItems
Opcode
Stop

Event ID 18679 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_ItemThumbnail_Prefetch
Opcode
Start

Event ID 18680 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_ItemThumbnail_Prefetch
Opcode
Stop

Event ID 18681 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_ItemThumbnail_Draw
Opcode
Start

Event ID 18682 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_ItemThumbnail_Draw
Opcode
Stop

Event ID 18683 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_NetFolder_ParseDisplayName
Opcode
Start

Fields #

NameDescription
Name UnicodeString

Event ID 18684 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_NetFolder_ParseDisplayName
Opcode
Stop

Fields #

NameDescription
Name UnicodeString

Event ID 18685 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_NetFolder_ParseUNCName
Opcode
Start

Event ID 18686 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_NetFolder_ParseUNCName
Opcode
Stop

Event ID 18687 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_NetFolder_SHWNetGetResourceInformationAlloc
Opcode
Start

Event ID 18688 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_NetFolder_SHWNetGetResourceInformationAlloc
Opcode
Stop

Event ID 18689 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_NetFolder_WNetGetResourceParent
Opcode
Start

Event ID 18690 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_NetFolder_WNetGetResourceParent
Opcode
Stop

Event ID 18691 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_NetFolder_WNetUseConnection
Opcode
Start

Event ID 18692 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_NetFolder_WNetUseConnection
Opcode
Stop

Event ID 18693 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_DefView_Property_Extraction
Opcode
Start

Event ID 18694 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_DefView_Property_Extraction
Opcode
Stop

Event ID 18695 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_DefView_Property_Extract
Opcode
Start

Fields #

NameDescription
LoopCount UInt32

Event ID 18696 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_DefView_Property_Extract
Opcode
Stop

Event ID 18697 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_DefView_Property_ReadAsOneBatch
Opcode
Start

Event ID 18698 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_DefView_Property_ReadAsOneBatch
Opcode
Stop

Event ID 18699 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
Shell32_DefView_GetEnumerator
Opcode
Start

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "18699",
    "version": "0",
    "level": "4",
    "task": "18699",
    "opcode": "1",
    "keywords": 9223372036854841344,
    "time_created": "2026-03-15T04:21:14.993151600+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "12840",
      "thread_id": "13880"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 18700 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
Shell32_DefView_GetEnumerator
Opcode
Stop

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "18700",
    "version": "0",
    "level": "4",
    "task": "18699",
    "opcode": "2",
    "keywords": 9223372036854841344,
    "time_created": "2026-03-15T04:21:14.993869800+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "12840",
      "thread_id": "13880"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 18701 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_DefView_Thumbnail_EnumLookup
Opcode
Start

Event ID 18702 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_DefView_Thumbnail_EnumLookup
Opcode
Stop

Event ID 18703 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_Autoplay_Master_Switch

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmDWORDDatapointValue UInt32

Event ID 18705 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_Autoplay_Default_Handler

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmStringDatapointValue UnicodeString

Event ID 18707 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_StartMenuQueryFactory_WaitForNextResult
Opcode
Start

Event ID 18708 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_StartMenuQueryFactory_WaitForNextResult
Opcode
Stop

Event ID 18709 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_StartMenuQueryFactory_Programs
Opcode
Start

Event ID 18710 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_StartMenuQueryFactory_Programs
Opcode
Stop

Event ID 18711 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_StartMenuQueryFactory_Programs_Grep
Opcode
Start

Event ID 18712 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_StartMenuQueryFactory_Programs_Grep
Opcode
Stop

Event ID 18713 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_StartMenuQueryFactory_Programs_Run
Opcode
Start

Event ID 18714 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_StartMenuQueryFactory_Programs_Run
Opcode
Stop

Event ID 18715 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_StartMenuQueryFactory_Programs_ControlPanels
Opcode
Start

Event ID 18716 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_StartMenuQueryFactory_Programs_ControlPanels
Opcode
Stop

Event ID 18717 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_StartMenuQueryFactory_Internet
Opcode
Start

Event ID 18718 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_StartMenuQueryFactory_Internet
Opcode
Stop

Event ID 18719 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_StartMenuQueryFactory_Internet_Run
Opcode
Start

Event ID 18720 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_StartMenuQueryFactory_Internet_Run
Opcode
Stop

Event ID 18721 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_StartMenuQueryFactory_Internet_Favorites
Opcode
Start

Event ID 18722 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_StartMenuQueryFactory_Internet_Favorites
Opcode
Stop

Event ID 18723 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_StartMenuQueryFactory_Internet_History
Opcode
Start

Event ID 18724 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_StartMenuQueryFactory_Internet_History
Opcode
Stop

Event ID 18725 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_StartMenuQueryFactory_Files
Opcode
Start

Event ID 18726 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_StartMenuQueryFactory_Files
Opcode
Stop

Event ID 18727 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_StartMenuQueryFactory_Files_Recent
Opcode
Start

Event ID 18728 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_StartMenuQueryFactory_Files_Recent
Opcode
Stop

Event ID 18729 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_StartMenuQueryFactory_Files_DisplayName
Opcode
Start

Event ID 18730 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_StartMenuQueryFactory_Files_DisplayName
Opcode
Stop

Event ID 18731 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_StartMenuQueryFactory_Files_FullText
Opcode
Start

Event ID 18732 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_StartMenuQueryFactory_Files_FullText
Opcode
Stop

Event ID 18733 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_StartMenuQueryFactory_Communications
Opcode
Start

Event ID 18734 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_StartMenuQueryFactory_Communications
Opcode
Stop

Event ID 18735 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_StartMenuQueryFactory_Communications_Contacts
Opcode
Start

Event ID 18736 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_StartMenuQueryFactory_Communications_Contacts
Opcode
Stop

Event ID 18737 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_StartMenuQueryFactory_Communications_FullText
Opcode
Start

Event ID 18738 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_StartMenuQueryFactory_Communications_FullText
Opcode
Stop

Event ID 18739 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
Shell32_IsElevationRequired
Opcode
Start

Fields #

NameDescription
ExecutableName UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "18739",
    "version": "0",
    "level": "4",
    "task": "18739",
    "opcode": "1",
    "keywords": 9223372036854841344,
    "time_created": "2026-03-15T04:21:15.029195800+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "12840",
      "thread_id": "13880"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "ExecutableName": "\\\\FAKEHOST@80\\share\\execute.exe"
  },
  "message": ""
}

Event ID 18740 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
Shell32_IsElevationRequired
Opcode
Stop

Fields #

NameDescription
ExecutableName UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "18740",
    "version": "0",
    "level": "4",
    "task": "18739",
    "opcode": "2",
    "keywords": 9223372036854841344,
    "time_created": "2026-03-15T04:21:15.030696200+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "12840",
      "thread_id": "13880"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "ExecutableName": "\\\\FAKEHOST@80\\share\\execute.exe"
  },
  "message": ""
}

Event ID 18741 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_IndexInfoCache_Refresh
Opcode
Start

Event ID 18742 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_IndexInfoCache_Refresh
Opcode
Stop

Event ID 18743 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_DefView_FireFolderChanged

Event ID 18745 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
Shell32_DefView_FireContentsChanged

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "18745",
    "version": "0",
    "level": "4",
    "task": "18745",
    "opcode": "0",
    "keywords": 9223372036854841344,
    "time_created": "2026-03-15T04:20:50.049543600+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "12840",
      "thread_id": "8552"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 18747 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_DUIFrame_SendContentsChanged

Event ID 18749 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_DUIFrame_SendFolderChanged

Event ID 18751 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_SHExtCoCreateInstance_Valid

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmStreamRowLength UInt32
SqmStreamRow Int16

Event ID 18752 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_DefView_AddColumn

Event ID 18753 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
Shell32_ItemStore_ExtractProperty
Opcode
Start

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "18753",
    "version": "0",
    "level": "4",
    "task": "18753",
    "opcode": "1",
    "keywords": 9223372036854841344,
    "time_created": "2026-03-15T04:20:50.049480200+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "12840",
      "thread_id": "8552"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 18755 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
Shell32_ItemStore_ExtractProperty
Opcode
Stop

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "18755",
    "version": "0",
    "level": "4",
    "task": "18753",
    "opcode": "2",
    "keywords": 9223372036854841344,
    "time_created": "2026-03-15T04:20:50.049502100+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "12840",
      "thread_id": "8552"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 18761 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_KnownFolderManager_Redirect
Opcode
Start

Event ID 18762 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_KnownFolderManager_Redirect
Opcode
Stop

Event ID 18763 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_KnownFolderManager_Redirect_Copy
Opcode
Start

Event ID 18764 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_KnownFolderManager_Redirect_Copy
Opcode
Stop

Event ID 18765 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_CDesktopBrowser_DesktopIconLayoutRestore
Opcode
Start

Event ID 18766 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_CDesktopBrowser_DesktopIconLayoutRestore
Opcode
Stop

Fields #

NameDescription
HRESULT UInt32

Event ID 18767 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_CDesktopBrowser_DesktopIconLayoutRestore

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmStreamRowLength UInt32
SqmStreamRow Int16

Event ID 18768 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_CDesktopBrowser_DesktopAutoArrange

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmDWORDDatapointValue UInt32

Event ID 18769 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_CDesktopBrowser_DesktopAlignToGrid

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmDWORDDatapointValue UInt32

Event ID 18770 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_CDesktopBrowser_DesktopIconSize

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmDWORDDatapointValue UInt32

Event ID 18771 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_PrivProf_CacheCount

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmDWORDDatapointValue UInt32

Event ID 18773 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
Shell32_CollectionLock_InsertQueueItem

Fields #

NameDescription
TaskID GUID
QueueItemCount Int32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "18773",
    "version": "0",
    "level": "4",
    "task": "18773",
    "opcode": "0",
    "keywords": 9223372036854841344,
    "time_created": "2026-03-15T04:20:38.891582400+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "12840",
      "thread_id": "8552"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "TaskID": "{05cdcb31-adfd-4d5a-9c4e-1a5650fe0867}",
    "QueueItemCount": "1"
  },
  "message": ""
}

Event ID 18775 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_CGrepQuery_EvaluateItem
Opcode
Start

Event ID 18776 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_CGrepQuery_EvaluateItem
Opcode
Stop

Event ID 18777 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_CConditionEvaluator_DoesItemMatchCondition
Opcode
Start

Event ID 18778 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_CConditionEvaluator_DoesItemMatchCondition
Opcode
Stop

Event ID 18779 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_CGrepConditionEvaluator_DoesContentMatchCondition
Opcode
Start

Event ID 18780 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_CGrepConditionEvaluator_DoesContentMatchCondition
Opcode
Stop

Event ID 18781 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_GrepDoesItemMatchCondition
Opcode
Start

Event ID 18782 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_GrepDoesItemMatchCondition
Opcode
Stop

Event ID 18783 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_SubCommandMenu_Enumerate
Opcode
Start

Event ID 18784 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_SubCommandMenu_Enumerate
Opcode
Stop

Event ID 18787 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_MountPoint_InitLocalDrives
Opcode
Start

Event ID 18788 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_MountPoint_InitLocalDrives
Opcode
Stop

Event ID 18789 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
CDesktopBrowser_WallpaperAnimation_Setup
Opcode
Start

Event ID 18790 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
CDesktopBrowser_WallpaperAnimation_Setup
Opcode
Stop

Event ID 18791 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
CDesktopBrowser_WallpaperAnimation_Cleanup
Opcode
Start

Event ID 18792 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
CDesktopBrowser_WallpaperAnimation_Cleanup
Opcode
Stop

Event ID 18793 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_CDesktopBrowser_SortyBy

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmDWORDDatapointValue UInt32

Event ID 18794 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_CDesktopBrowser_IconPositions

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmStreamRowLength UInt32
SqmStreamRow Int16

Event ID 18795 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_CDesktopBrowser_WindowRegItem

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmDWORDDatapointValue UInt32

Event ID 18796 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_CDesktopBrowser_NonWindowRegItem

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmDWORDDatapointValue UInt32

Event ID 18797 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_CDesktopBrowser_ItemCount

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmDWORDDatapointValue UInt32

Event ID 18798 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_CDesktopBrowser_UsageTime

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmDWORDDatapointValue UInt32

Event ID 18799 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_DefView_LoadColumns
Opcode
Start

Event ID 18800 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_DefView_LoadColumns
Opcode
Stop

Event ID 18801 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
Shell32_CopyEngine_FileOperation
Opcode
Start

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "18801",
    "version": "0",
    "level": "4",
    "task": "18801",
    "opcode": "1",
    "keywords": 9223372036863164416,
    "time_created": "2026-03-15T04:20:38.365211700+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "12840",
      "thread_id": "4164"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 18802 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
Shell32_CopyEngine_FileOperation
Opcode
Stop

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "18802",
    "version": "0",
    "level": "4",
    "task": "18801",
    "opcode": "2",
    "keywords": 9223372036863164416,
    "time_created": "2026-03-15T04:20:38.366382800+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "12840",
      "thread_id": "4164"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 18803 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
Shell32_CopyEngine_OverallOperation
Opcode
Start

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "18803",
    "version": "0",
    "level": "4",
    "task": "18803",
    "opcode": "1",
    "keywords": 9223372036863164416,
    "time_created": "2026-03-15T04:20:38.357798200+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "12840",
      "thread_id": "4164"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 18804 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
Shell32_CopyEngine_OverallOperation
Opcode
Stop

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "18804",
    "version": "0",
    "level": "4",
    "task": "18803",
    "opcode": "2",
    "keywords": 9223372036863164416,
    "time_created": "2026-03-15T04:20:38.398240700+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "12840",
      "thread_id": "4164"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 18805 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
Shell32_CopyEngine_OverallTransfer
Opcode
Start

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "18805",
    "version": "0",
    "level": "4",
    "task": "18805",
    "opcode": "1",
    "keywords": 9223372036863164416,
    "time_created": "2026-03-15T04:20:38.362240100+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "12840",
      "thread_id": "4164"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 18806 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
Shell32_CopyEngine_OverallTransfer
Opcode
Stop

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "18806",
    "version": "0",
    "level": "4",
    "task": "18805",
    "opcode": "2",
    "keywords": 9223372036863164416,
    "time_created": "2026-03-15T04:20:38.371202700+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "12840",
      "thread_id": "4164"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 18807 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
Shell32_CopyEngine_ConfirmedDelete

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "18807",
    "version": "0",
    "level": "4",
    "task": "18807",
    "opcode": "0",
    "keywords": 9223372036863164416,
    "time_created": "2026-03-15T04:20:38.358768300+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "12840",
      "thread_id": "4164"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 18809 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_CopyEngine_WillRecycleToBin
Opcode
Start

Event ID 18810 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_CopyEngine_WillRecycleToBin
Opcode
Stop

Event ID 18811 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_CopyEngine_RecycleItem
Opcode
Start

Event ID 18812 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_CopyEngine_RecycleItem
Opcode
Stop

Event ID 18813 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_CopyEngine_FileOpen
Opcode
Start

Event ID 18814 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_CopyEngine_FileOpen
Opcode
Stop

Event ID 18815 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_CopyEngine_CallMoveFile
Opcode
Start

Event ID 18816 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_CopyEngine_CallMoveFile
Opcode
Stop

Event ID 18817 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_CommonPlaces_Drop

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmDWORDDatapointValue UInt32

Event ID 18818 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_ReadingPaneModule_Load
Opcode
Start

Event ID 18819 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_ReadingPaneModule_Load
Opcode
Stop

Event ID 18820 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_CopyEngine_FileOperation

Fields #

NameDescription
CompletionDelta UInt64
SecondTimeDelta Double
WindowSumOfRates Double
CalculatedRate Double

Event ID 18821 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_LinkTracking

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmStreamRowLength UInt32
SqmStreamRow Int16

Event ID 18823 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_CopyEngine_SQMStream

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmStreamRowLength UInt32
SqmStreamRow Int16

Event ID 18825 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_AppDestList_Custom_Commit
Opcode
Start

Event ID 18826 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_AppDestList_Custom_Commit
Opcode
Stop

Event ID 18827 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_AppDestList_Custom_Load
Opcode
Start

Event ID 18828 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_AppDestList_Custom_Load
Opcode
Stop

Event ID 18829 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_AppDestList_Custom_LoadRemoved
Opcode
Start

Event ID 18830 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_AppDestList_Custom_LoadRemoved
Opcode
Stop

Event ID 18831 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_AppDestList_Custom_RemoveDest
Opcode
Start

Event ID 18832 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_AppDestList_Custom_RemoveDest
Opcode
Stop

Event ID 18833 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
Shell32_UA_FireEvent
Opcode
Start

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "18833",
    "version": "0",
    "level": "4",
    "task": "18833",
    "opcode": "1",
    "keywords": 9223372036854841344,
    "time_created": "2026-03-15T04:22:47.404632000+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "12840",
      "thread_id": "4124"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 18834 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
Shell32_UA_FireEvent
Opcode
Stop

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "18834",
    "version": "0",
    "level": "4",
    "task": "18833",
    "opcode": "2",
    "keywords": 9223372036854841344,
    "time_created": "2026-03-15T04:22:47.405040600+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "12840",
      "thread_id": "4124"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 18835 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_UA_UpdateLoggerState
Opcode
Start

Event ID 18836 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_UA_UpdateLoggerState
Opcode
Stop

Event ID 18837 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_UA_SetEntry
Opcode
Start

Event ID 18838 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_UA_SetEntry
Opcode
Stop

Event ID 18841 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_UA_GarbageCollectScheduled

Event ID 18843 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_UA_GarbageCollect
Opcode
Start

Event ID 18844 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_UA_GarbageCollect
Opcode
Stop

Event ID 18845 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_UA_SnapRValuesScheduled

Event ID 18847 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_UA_SnapRValues
Opcode
Start

Event ID 18848 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_UA_SnapRValues
Opcode
Stop

Event ID 18849 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_UA_DeleteEntry
Opcode
Start

Event ID 18850 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_UA_DeleteEntry
Opcode
Stop

Event ID 18851 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_UA_RenameEntry
Opcode
Start

Event ID 18852 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_UA_RenameEntry
Opcode
Stop

Event ID 18853 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_UA_ReplaceNMaxCandidate

Event ID 18855 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_UA_RebuildSessionScheduled

Event ID 18857 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_UA_RebuildSession
Opcode
Start

Event ID 18858 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_UA_RebuildSession
Opcode
Stop

Event ID 18859 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_AutoDestList_GetList
Opcode
Start

Event ID 18860 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_AutoDestList_GetList
Opcode
Stop

Event ID 18861 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_AutoDestList_AddUsagePoint
Opcode
Start

Event ID 18862 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_AutoDestList_AddUsagePoint
Opcode
Stop

Event ID 18863 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_AutoDestList_PinItem
Opcode
Start

Event ID 18864 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_AutoDestList_PinItem
Opcode
Stop

Event ID 18865 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_DragDropHelper_UpdateLayeredWindow
Opcode
Stop

Fields #

NameDescription
Value UInt32

Event ID 18867 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_AutoDestList_IsPinned
Opcode
Start

Event ID 18868 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_AutoDestList_IsPinned
Opcode
Stop

Event ID 18869 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_AutoDestList_CalculateDecay
Opcode
Start

Event ID 18870 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_AutoDestList_CalculateDecay
Opcode
Stop

Event ID 18871 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_AutoDestList_GarbageCollecting

Event ID 18873 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_BrowserProgressAggregator_Register

Fields #

NameDescription
guid GUID

Event ID 18875 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_BrowserProgressAggregator_Unregister

Fields #

NameDescription
guid GUID

Event ID 18877 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_FilterDestByAssoc
Opcode
Start

Event ID 18878 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_FilterDestByAssoc
Opcode
Stop

Event ID 18879 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_AppDestList_Custom_AppendCategory
Opcode
Start

Event ID 18880 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_AppDestList_Custom_AppendCategory
Opcode
Stop

Event ID 18881 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_DefView_CreateNewCollection
Opcode
Start

Event ID 18882 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_DefView_CreateNewCollection
Opcode
Stop

Event ID 18883 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_DefView_ExecStop
Opcode
Start

Event ID 18884 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_DefView_ExecStop
Opcode
Stop

Event ID 18885 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_DefView_ExecRefresh
Opcode
Start

Event ID 18886 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_DefView_ExecRefresh
Opcode
Stop

Event ID 18887 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_CopyEngine_UAC_CopyEngine_Elevation

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmStreamRowLength UInt32
SqmStreamRow Int16

Event ID 18888 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_ItemThumbnail_Prefetch_Dispatch
Opcode
Stop

Event ID 18889 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_ItemThumbnail_Prefetch_Dispatch
Opcode
Start

Fields #

NameDescription
Count UInt32

Event ID 18901 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_CopyEngine_FileCreate
Opcode
Start

Event ID 18902 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_CopyEngine_FileCreate
Opcode
Stop

Event ID 18903 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_CopyEngine_ProgressUpdate

Fields #

NameDescription
PointsCurrent UInt64
PointsTotal UInt64
SizeCurrent UInt64
SizeTotal UInt64
ItemsCurrent UInt64
ItemsTotal UInt64

Event ID 18905 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
Shell32_CopyEngine_FileOperation_Info

Fields #

NameDescription
pszSource UnicodeString
pszDest UnicodeString
SourceType UInt32
DestinationType UInt32
FileOp UInt32
FileSize UInt64

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "18905",
    "version": "0",
    "level": "4",
    "task": "18905",
    "opcode": "0",
    "keywords": 9223372036854841344,
    "time_created": "2026-03-15T04:20:38.366379600+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "12840",
      "thread_id": "4164"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "pszSource": "C:\\Users\\domainadmin\\AppData\\Roaming\\Microsoft\\Windows\\Themes\\CachedFiles",
    "pszDest": "NULL",
    "SourceType": "       3",
    "DestinationType": "       0",
    "FileOp": "       3",
    "FileSize": "0"
  },
  "message": ""
}

Event ID 18907 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_CopyEngine_ProgressUpdateSkipped

Event ID 18909 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_CopyEngine_ProgressData

Fields #

NameDescription
WorkDone UInt64
TimeElapsed UInt64

Event ID 18911 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_CopyEngine_ProgressEstimate

Fields #

NameDescription
NewMean UInt64
AverageMean UInt64
Estimate UInt64

Event ID 18913 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_CopyEngine_ProgressSpeed

Fields #

NameDescription
Speed UInt64
IsBytesPerSecond UInt32

Event ID 18915 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_CopyEngine_MoveAsCopyDelete

Event ID 18917 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_DragDropHelper_AddInfoToWindow
Opcode
Start

Event ID 18918 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_DragDropHelper_AddInfoToWindow
Opcode
Stop

Event ID 18919 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_DragDropHelper_ExtractThumbnail
Opcode
Start

Event ID 18920 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_DragDropHelper_ExtractThumbnail
Opcode
Stop

Event ID 18921 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_SHDoDragDrop_Drop

Fields #

NameDescription
DROPEFFECT UInt32

Event ID 18922 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_AutoPlay_DXP
Opcode
Start

Event ID 18923 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_AutoPlay_DXP
Opcode
Start

Fields #

NameDescription
DeviceID UnicodeString

Event ID 18924 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_AutoPlay_DXP
Opcode
Stop

Event ID 18925 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_AutoPlay_DXP
Opcode
Stop

Event ID 18927 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_PerfMarker1

Event ID 18929 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_PerfMarker2

Event ID 18931 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_PerfMarker3
Opcode
Start

Event ID 18932 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_PerfMarker3
Opcode
Stop

Event ID 18933 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_NewMenu_Folder

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmDWORDDatapointValue UInt32

Event ID 18934 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_NewMenu_Shortcut

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmDWORDDatapointValue UInt32

Event ID 18935 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_NewMenu_Other

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmDWORDDatapointValue UInt32

Event ID 18936 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_DesktopContextMenu_Personalize

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmDWORDDatapointValue UInt32

Event ID 18937 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_DesktopContextMenu_Display

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmDWORDDatapointValue UInt32

Event ID 18939 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_SCFFileUsage_SQM

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmDWORDDatapointValue UInt32

Event ID 18941 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_ExternalOverlayDllLoad

Event ID 18943 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_RunFileDlgDisplayed

Event ID 18950 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_SHChangeNotify_Register_Client
Opcode
Start

Event ID 18951 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_SHChangeNotify_Register_Client
Opcode
Stop

Fields #

NameDescription
ID UInt32
HWND UInt32

Event ID 18952 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_SHChangeNotify_Register_NotifyThread
Opcode
Start

Event ID 18953 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_SHChangeNotify_Register_NotifyThread
Opcode
Stop

Fields #

NameDescription
ID UInt32
HWND UInt32

Event ID 18954 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_SHChangeNotify_Deregister_Client
Opcode
Start

Fields #

NameDescription
ID UInt32

Event ID 18955 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_SHChangeNotify_Deregister_Client
Opcode
Stop

Event ID 18956 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_SHChangeNotify_Deregister_NotifyThread
Opcode
Start

Fields #

NameDescription
ID UInt32

Event ID 18957 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_SHChangeNotify_Deregister_NotifyThread
Opcode
Stop

Event ID 18958 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
Shell32_SHChangeNotify_Notify_Client
Opcode
Start

Fields #

NameDescription
Event UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "18958",
    "version": "0",
    "level": "4",
    "task": "18958",
    "opcode": "1",
    "keywords": 9223372036854841344,
    "time_created": "2026-03-15T04:20:38.369560800+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "12840",
      "thread_id": "4164"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Event": "0x4"
  },
  "message": ""
}

Event ID 18959 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
Shell32_SHChangeNotify_Notify_Client
Opcode
Stop

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "18959",
    "version": "0",
    "level": "4",
    "task": "18958",
    "opcode": "2",
    "keywords": 9223372036854841344,
    "time_created": "2026-03-15T04:20:38.369636400+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "12840",
      "thread_id": "4164"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 18960 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
Shell32_SHChangeNotify_Notify_NotifyThread
Opcode
Start

Fields #

NameDescription
Event UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "18960",
    "version": "0",
    "level": "4",
    "task": "18960",
    "opcode": "1",
    "keywords": 9223372036854841344,
    "time_created": "2026-03-15T04:20:38.369661700+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "12840",
      "thread_id": "5416"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Event": "0x4"
  },
  "message": ""
}

Event ID 18961 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
Shell32_SHChangeNotify_Notify_NotifyThread
Opcode
Stop

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "18961",
    "version": "0",
    "level": "4",
    "task": "18960",
    "opcode": "2",
    "keywords": 9223372036854841344,
    "time_created": "2026-03-15T04:20:38.369718200+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "12840",
      "thread_id": "5416"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 18962 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
Shell32_SHChangeNotify_SendNotification_NotifyThread
Opcode
Start

Fields #

NameDescription
Event UInt32
ID UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "18962",
    "version": "0",
    "level": "4",
    "task": "18962",
    "opcode": "1",
    "keywords": 9223372036854841344,
    "time_created": "2026-03-15T04:20:38.891479100+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "12840",
      "thread_id": "5416"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Event": "0x1000",
    "ID": "       1"
  },
  "message": ""
}

Event ID 18963 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
Shell32_SHChangeNotify_SendNotification_NotifyThread
Opcode
Stop

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "18963",
    "version": "0",
    "level": "4",
    "task": "18962",
    "opcode": "2",
    "keywords": 9223372036854841344,
    "time_created": "2026-03-15T04:20:38.891496600+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "12840",
      "thread_id": "5416"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 18964 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_SHChangeNotify_HungApp

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmStreamRowLength UInt32
SqmStreamRow Int16

Event ID 18970 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
UndoNode_PreItemChanged

Fields #

NameDescription
pszOperationSource UnicodeString
pszOperationDestination UnicodeString
FileOp UInt32
IsOperationUndo Boolean
UndoFlags UInt32

Event ID 18972 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
UndoNode_PostItemChanged

Fields #

NameDescription
pszOperationSource UnicodeString
pszOperationDestination UnicodeString
FileOp UInt32
IsOperationUndo Boolean
UndoFlags UInt32

Event ID 18974 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
UndoNode_PostLeave

Fields #

NameDescription
pszOperationSource UnicodeString
pszOperationDestination UnicodeString
FileOp UInt32
IsOperationUndo Boolean
UndoFlags UInt32

Event ID 18976 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
UndoNode_Cleanup

Fields #

NameDescription
pszOperationSource UnicodeString
pszOperationDestination UnicodeString
FileOp UInt32
IsOperationUndo Boolean
UndoFlags UInt32

Event ID 18978 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
CopyEngine_PerformUndo

Fields #

NameDescription
pszOperationSource UnicodeString
pszOperationDestination UnicodeString
FileOp UInt32
IsOperationUndo Boolean
UndoFlags UInt32

Event ID 18980 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
CopyEngine_ClearUndo

Event ID 19001 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTraceId_TaskScheduler_ResumeTask
Opcode
Start

Fields #

NameDescription
TOID GUID

Event ID 19002 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTraceId_TaskScheduler_ResumeTask
Opcode
Stop

Fields #

NameDescription
TOID GUID

Event ID 19003 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
ShellTraceId_TaskScheduler_RunTask
Opcode
Start

Fields #

NameDescription
TOID GUID

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "19003",
    "version": "0",
    "level": "4",
    "task": "19003",
    "opcode": "1",
    "keywords": 9223372036871553024,
    "time_created": "2026-03-15T04:20:38.353817300+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "12840",
      "thread_id": "4164"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "TOID": "{c0d04af2-0d2d-48ad-b93f-cdf1d27437c3}"
  },
  "message": ""
}

Event ID 19004 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
ShellTraceId_TaskScheduler_RunTask
Opcode
Stop

Fields #

NameDescription
TOID GUID

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "19004",
    "version": "0",
    "level": "4",
    "task": "19003",
    "opcode": "2",
    "keywords": 9223372036871553024,
    "time_created": "2026-03-15T04:20:38.398314600+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "12840",
      "thread_id": "4164"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "TOID": "{c0d04af2-0d2d-48ad-b93f-cdf1d27437c3}"
  },
  "message": ""
}

Event ID 19005 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTraceId_TaskScheduler_PurgeTasks

Fields #

NameDescription
TOID GUID

Event ID 19006 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTraceId_TaskScheduler_AddIdleTask

Fields #

NameDescription
TOID GUID

Event ID 19007 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
ShellTraceId_TaskScheduler_AddTask

Fields #

NameDescription
TOID GUID

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "19007",
    "version": "0",
    "level": "4",
    "task": "19009",
    "opcode": "0",
    "keywords": 9223372036871553024,
    "time_created": "2026-03-15T04:20:38.353789900+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "12840",
      "thread_id": "8552"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "TOID": "{c0d04af2-0d2d-48ad-b93f-cdf1d27437c3}"
  },
  "message": ""
}

Event ID 19101 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_RecentDoc_Processed

Fields #

NameDescription
FileName UnicodeString

Event ID 19201 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
LUA_Elevation_Attempts

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmDWORDDatapointValue UInt32

Event ID 19203 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
LUA_Elevation_Attempts

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmDWORDDatapointValue UInt32

Event ID 19205 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
LUA_Elevation_Attempts

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmDWORDDatapointValue UInt32

Event ID 19207 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
LUA_Elevation_Attempts

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmDWORDDatapointValue UInt32

Event ID 19209 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
LUA_Elevation_Attempts

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmDWORDDatapointValue UInt32

Event ID 19211 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
LUA_Elevation_Attempts

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmStreamRowLength UInt32
SqmStreamRow Int16

Event ID 19401 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
FileClassStore_LookupFileClassInt
Opcode
Start

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "19401",
    "version": "0",
    "level": "4",
    "task": "19411",
    "opcode": "1",
    "keywords": 9223372036855037952,
    "time_created": "2026-03-15T04:20:37.111778000+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "10312",
      "thread_id": "14168"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 19403 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
FileClassStore_LookupFileClassInt
Opcode
Stop

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "19403",
    "version": "0",
    "level": "4",
    "task": "19411",
    "opcode": "2",
    "keywords": 9223372036855037952,
    "time_created": "2026-03-15T04:20:37.111779100+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "10312",
      "thread_id": "14168"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 19405 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
FileClassStore_LookupFileClassString
Opcode
Start

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "19405",
    "version": "0",
    "level": "4",
    "task": "19409",
    "opcode": "1",
    "keywords": 9223372036855037952,
    "time_created": "2026-03-16T00:21:39.199862900+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "5680",
      "thread_id": "11856"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 19407 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
FileClassStore_LookupFileClassString
Opcode
Stop

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "19407",
    "version": "0",
    "level": "4",
    "task": "19409",
    "opcode": "2",
    "keywords": 9223372036855037952,
    "time_created": "2026-03-16T00:21:39.199914400+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "5680",
      "thread_id": "11856"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 19409 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
FileClassStore_LookupFileClassHandler
Opcode
Start

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "19409",
    "version": "0",
    "level": "4",
    "task": "19407",
    "opcode": "1",
    "keywords": 9223372036855037952,
    "time_created": "2026-03-15T04:20:38.358119100+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "12840",
      "thread_id": "4164"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 19411 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
FileClassStore_LookupFileClassHandler
Opcode
Stop

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "19411",
    "version": "0",
    "level": "4",
    "task": "19407",
    "opcode": "2",
    "keywords": 9223372036855037952,
    "time_created": "2026-03-15T04:20:38.358124100+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "12840",
      "thread_id": "4164"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 19413 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
FileClassStore_SetFileClassInt
Opcode
Start

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "19413",
    "version": "0",
    "level": "4",
    "task": "19403",
    "opcode": "1",
    "keywords": 9223372036855037952,
    "time_created": "2026-03-15T04:20:50.033567700+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "12840",
      "thread_id": "5416"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 19415 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
FileClassStore_SetFileClassInt
Opcode
Stop

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "19415",
    "version": "0",
    "level": "4",
    "task": "19403",
    "opcode": "2",
    "keywords": 9223372036855037952,
    "time_created": "2026-03-15T04:20:50.033570500+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "12840",
      "thread_id": "5416"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 19417 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
FileClassStore_SetFileClassString
Opcode
Start

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "19417",
    "version": "0",
    "level": "4",
    "task": "19405",
    "opcode": "1",
    "keywords": 9223372036855037952,
    "time_created": "2026-03-16T00:21:39.219215800+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "5680",
      "thread_id": "11856"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 19419 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
FileClassStore_SetFileClassString
Opcode
Stop

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "19419",
    "version": "0",
    "level": "4",
    "task": "19405",
    "opcode": "2",
    "keywords": 9223372036855037952,
    "time_created": "2026-03-16T00:21:39.219230300+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "5680",
      "thread_id": "11856"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 19421 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
FileClassStore_SetFileClassHandler
Opcode
Start

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "19421",
    "version": "0",
    "level": "4",
    "task": "19401",
    "opcode": "1",
    "keywords": 9223372036855037952,
    "time_created": "2026-03-16T00:21:39.169995200+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "5680",
      "thread_id": "11856"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 19423 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
FileClassStore_SetFileClassHandler
Opcode
Stop

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "19423",
    "version": "0",
    "level": "4",
    "task": "19401",
    "opcode": "2",
    "keywords": 9223372036855037952,
    "time_created": "2026-03-16T00:21:39.170012800+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "5680",
      "thread_id": "11856"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 19425 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
IconCache_LookupIcon
Opcode
Start

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "19425",
    "version": "0",
    "level": "4",
    "task": "19413",
    "opcode": "1",
    "keywords": 9223372036855037952,
    "time_created": "2026-03-15T04:20:18.999180400+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "10312",
      "thread_id": "14168"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 19427 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
IconCache_LookupIcon
Opcode
Stop

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "19427",
    "version": "0",
    "level": "4",
    "task": "19413",
    "opcode": "2",
    "keywords": 9223372036855037952,
    "time_created": "2026-03-15T04:20:18.999187900+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "10312",
      "thread_id": "14168"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 19429 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
IconCache_AddIcon
Opcode
Start

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "19429",
    "version": "0",
    "level": "4",
    "task": "19415",
    "opcode": "1",
    "keywords": 9223372036855037952,
    "time_created": "2026-03-15T04:20:51.144814400+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "10312",
      "thread_id": "14168"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 19431 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
IconCache_AddIcon
Opcode
Stop

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "19431",
    "version": "0",
    "level": "4",
    "task": "19415",
    "opcode": "2",
    "keywords": 9223372036855037952,
    "time_created": "2026-03-15T04:20:51.144816400+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "10312",
      "thread_id": "14168"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 19433 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
IconCache_RemoveIcon
Opcode
Start

Event ID 19435 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
IconCache_RemoveIcon
Opcode
Stop

Event ID 19437 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
IconCache_GetFileOverlayInfo
Opcode
Start

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "19437",
    "version": "0",
    "level": "4",
    "task": "19419",
    "opcode": "1",
    "keywords": 9223372036855037952,
    "time_created": "2026-03-15T04:20:50.066943000+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "12840",
      "thread_id": "13268"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 19439 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
IconCache_GetFileOverlayInfo
Opcode
Stop

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "19439",
    "version": "0",
    "level": "4",
    "task": "19419",
    "opcode": "2",
    "keywords": 9223372036855037952,
    "time_created": "2026-03-15T04:20:50.067581200+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "12840",
      "thread_id": "13268"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 19441 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
IconCache_CacheMiss

Fields #

NameDescription
PathToIcon UnicodeString
IconOffset Int32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "19441",
    "version": "0",
    "level": "4",
    "task": "19421",
    "opcode": "0",
    "keywords": 9223372036855037952,
    "time_created": "2026-03-15T04:20:51.144804100+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "10312",
      "thread_id": "14168"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "PathToIcon": "C:\\Windows\\System32\\PING.EXE",
    "IconOffset": "0"
  },
  "message": ""
}

Event ID 19443 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
IconCache_ScaleImage

Fields #

NameDescription
PathToIcon UnicodeString
IconOffset Int32
FromIconSize Int32
ToIconSize Int32

Event ID 19501 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
CDesktopFolder_ParseDisplayName
Opcode
Start

Fields #

NameDescription
Name UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "19501",
    "version": "0",
    "level": "4",
    "task": "19501",
    "opcode": "1",
    "keywords": 9223372036854841344,
    "time_created": "2026-03-15T04:20:37.111299600+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "10312",
      "thread_id": "14168"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Name": "C:\\Program Files\\Git\\usr\\bin\\bash.exe"
  },
  "message": ""
}

Event ID 19502 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
CDesktopFolder_ParseDisplayName
Opcode
Stop

Fields #

NameDescription
Name UnicodeString
HRESULT UInt32
PIDL_out UInt64
HWND UInt32
IBindCtx UInt64
cbEaten UInt32
dwAttributes UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "19502",
    "version": "0",
    "level": "4",
    "task": "19501",
    "opcode": "2",
    "keywords": 9223372036854841344,
    "time_created": "2026-03-15T04:20:37.111768200+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "10312",
      "thread_id": "14168"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Name": "C:\\Program Files\\Git\\usr\\bin\\bash.exe",
    "HRESULT": "0x0",
    "PIDL_out": "0x1E332146560",
    "HWND": "0x0",
    "IBindCtx": "0x1E335296560",
    "cbEaten": "4294967295",
    "dwAttributes": "0xFFFFFFFF"
  },
  "message": ""
}

Event ID 19503 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
CDesktopFolder_GetDisplayNameOf
Opcode
Start

Fields #

NameDescription
Address UInt64
Depth UInt32
Children Int8

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "19503",
    "version": "0",
    "level": "4",
    "task": "19503",
    "opcode": "1",
    "keywords": 9223372036854841344,
    "time_created": "2026-03-15T04:20:50.047254400+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "12840",
      "thread_id": "800"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 19504 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
CDesktopFolder_GetDisplayNameOf
Opcode
Stop

Fields #

NameDescription
Address UInt64
HRESULT UInt32
Flags UInt32
Name UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "19504",
    "version": "0",
    "level": "4",
    "task": "19503",
    "opcode": "2",
    "keywords": 9223372036854841344,
    "time_created": "2026-03-15T04:20:50.047257200+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "12840",
      "thread_id": "800"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Address": "0xC7E4250",
    "HRESULT": "0x0",
    "Flags": "0x8001",
    "Name": "automaton"
  },
  "message": ""
}

Event ID 19601 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_ControlPanel_HomePage_Init
Opcode
Start

Event ID 19602 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_ControlPanel_HomePage_Init
Opcode
Stop

Event ID 19603 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_ControlPanel_LoadApplets
Opcode
Start

Event ID 19604 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_ControlPanel_LoadApplets
Opcode
Stop

Event ID 19605 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_ControlPanel_LoadTasks
Opcode
Start

Event ID 19606 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_ControlPanel_LoadTasks
Opcode
Stop

Event ID 19607 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_ControlPanel_Search
Opcode
Start

Event ID 19608 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_ControlPanel_Search
Opcode
Stop

Event ID 19611 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_ControlPanel_Search_NoResults

Event ID 19613 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_ControlPanel_SearchResults_Applet

Fields #

NameDescription
psz UnicodeString

Event ID 19615 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_ControlPanel_SearchResults_Task

Fields #

NameDescription
guid GUID

Event ID 19617 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_ControlPanel_TaskStateCondition

Fields #

NameDescription
pszName UnicodeString
fVal UInt32

Event ID 19619 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_ControlPanel_NavPane_Mode

Fields #

NameDescription
uMode UInt32

Event ID 19621 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_ControlPanel_NavPane_TransitionAnimation

Fields #

NameDescription
uAnimationType UInt32

Event ID 19623 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_ControlPanel_NavPane_LinkAdded

Fields #

NameDescription
psz UnicodeString

Event ID 19625 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_ControlPanel_TypeAheadSearch_Timeout

Event ID 19627 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_ControlPanel_TypeAheadSearch_NotFound

Event ID 19628 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_ControlPanel_SlowAppletsLoaded

Fields #

NameDescription
Value UInt32

Event ID 19635 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Explorer_ControlPanel_Settings_Sync
Opcode
Start

Event ID 19636 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Explorer_ControlPanel_Settings_Sync
Opcode
Stop

Event ID 19801 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShowDesktop_Usage

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmStreamRowLength UInt32
SqmStreamRow Int16

Event ID 19803 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShowDesktop_RaiseDesktop
Opcode
Start

Event ID 19804 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShowDesktop_RaiseDesktop
Opcode
Stop

Event ID 19805 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShowDesktop_RegistryWrite

Event ID 19900 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
StartButton_ChangeState

Fields #

NameDescription
OldState Int32
NewState Int32

Event ID 20001 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
StartMenu_OpenContextMenu
Opcode
Start

Event ID 20002 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
StartMenu_OpenContextMenu
Opcode
Stop

Event ID 20003 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
StartMenu_PinItemToMenu
Opcode
Start

Event ID 20004 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
StartMenu_PinItemToMenu
Opcode
Stop

Event ID 20005 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
StartMenu_Fill_MenuCache
Opcode
Start

Event ID 20006 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
StartMenu_Fill_MenuCache
Opcode
Stop

Event ID 20007 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
StartMenu_Left_Control_Button_Split_Open

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmDWORDDatapointValue UInt32

Event ID 20009 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
StartMenu_Right_Control_Button_Split_Open

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmDWORDDatapointValue UInt32

Event ID 20011 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
StartMenu_Left_Control_Button_Label

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmDWORDDatapointValue UInt32

Event ID 20013 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
StartMenu_Right_Control_Button_Label

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmDWORDDatapointValue UInt32

Event ID 20015 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
StartMenu_Logoff_Usage_Stream

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmStreamRowLength UInt32
SqmStreamRow Int16

Event ID 20017 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
StartMenu_Username_Clicked

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmDWORDDatapointValue UInt32

Event ID 20019 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
StartMenu_UserTile_Clicked

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmDWORDDatapointValue UInt32

Event ID 20021 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
StartMenu_Search_Usage

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmDWORDDatapointValue UInt32

Event ID 20023 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
StartMenu_AllPrograms_Search_Usage

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmDWORDDatapointValue UInt32

Event ID 20025 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
StartMenu_Search_TopResult_Launch

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmDWORDDatapointValue UInt32

Event ID 20027 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
StartMenu_Advanced_Search_Launch

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmDWORDDatapointValue UInt32

Event ID 20029 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
StartMenu_Search_Result_Launch

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmDWORDDatapointValue UInt32

Event ID 20031 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
StartMenu_Search_UNC_Path

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmDWORDDatapointValue UInt32

Event ID 20033 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
StartMenu_WordWheel_Activated

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmDWORDDatapointValue UInt32

Event ID 20035 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
StartMenu_Search_Computer_Count

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmDWORDDatapointValue UInt32

Event ID 20037 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
StartMenu_Search_Internet_Count

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmDWORDDatapointValue UInt32

Event ID 20039 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
StartMenu_Search_URL_Count

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmDWORDDatapointValue UInt32

Event ID 20041 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
StartMenu_Search_Dropdown_Count

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmDWORDDatapointValue UInt32

Event ID 20043 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
StartMenu_Search_Group_Usage

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmStreamRowLength UInt32
SqmStreamRow Int16

Event ID 20045 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
StartMenu_Applications_Launched

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmStreamRowLength UInt32
SqmStreamRow Int16

Event ID 20047 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Rearranging_StartMenuTaskbar

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmStreamRowLength UInt32
SqmStreamRow Int16

Event ID 20049 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Pinned_Applications

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmStreamRowLength UInt32
SqmStreamRow Int16

Event ID 20051 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DestinationRemoval_StartMenuTaskbar

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmStreamRowLength UInt32
SqmStreamRow Int16

Event ID 20053 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Pinned_Destinations_StartMenuTaskbar

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmStreamRowLength UInt32
SqmStreamRow Int16

Event ID 20055 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Destination_Menu_Usage_StartMenuTaskbar

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmStreamRowLength UInt32
SqmStreamRow Int16

Event ID 20057 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Start_Menu_Recent_Items_Menu

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmDWORDDatapointValue UInt32

Event ID 20059 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
StartMenu_MFU_Application_Removal

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmStreamRowLength UInt32
SqmStreamRow Int16

Event ID 20061 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Application_Launches_StartMenuTaskbar

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmStreamRowLength UInt32
SqmStreamRow Int16

Event ID 20063 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
TurnOffUsageTrackingStartMenuTaskbar

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmDWORDDatapointValue UInt32

Event ID 20065 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Taskbar_DestinationList_Prepopulate
Opcode
Start

Event ID 20066 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Taskbar_DestinationList_Prepopulate
Opcode
Stop

Event ID 20067 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
StartMenu_DestinationList_Refresh
Opcode
Start

Event ID 20068 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
StartMenu_DestinationList_Refresh
Opcode
Stop

Event ID 20069 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
StartMenu_DestinationList_EnumData
Opcode
Start

Event ID 20070 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
StartMenu_DestinationList_EnumData
Opcode
Stop

Event ID 20071 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Destination_Menu_Action_StartMenuTaskbar

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmStreamRowLength UInt32
SqmStreamRow Int16

Event ID 20072 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Destination_Menu_Layout_StartMenuTaskbar

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmStreamRowLength UInt32
SqmStreamRow Int16

Event ID 20073 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Destination_Removal_StartMenuTaskbar

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmStreamRowLength UInt32
SqmStreamRow Int16

Event ID 20075 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
StartMenu_Animation
Opcode
Start

Event ID 20076 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
StartMenu_Animation
Opcode
Stop

Fields #

NameDescription
LoopCount UInt32

Event ID 20102 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
StartMenuCPL_Load
Opcode
Start

Event ID 20103 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
StartMenuCPL_Load
Opcode
Stop

Event ID 20104 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
StartMenuCPL_Apply
Opcode
Start

Event ID 20105 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
StartMenuCPL_Apply
Opcode
Stop

Event ID 20106 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
TaskbarCPL_Load
Opcode
Start

Event ID 20107 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
TaskbarCPL_Load
Opcode
Stop

Event ID 20108 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
TaskbarCPL_Apply
Opcode
Start

Event ID 20109 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
TaskbarCPL_Apply
Opcode
Stop

Event ID 20111 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
StartMenu_ByUsage_EnumItems
Opcode
Start

Event ID 20112 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
StartMenu_ByUsage_EnumItems
Opcode
Stop

Event ID 20900 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
UserTile_Taskbar_Control_Initialize
Opcode
Start

Event ID 20901 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
UserTile_Taskbar_Control_Initialize
Opcode
Stop

Event ID 20902 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
UserTile_Store_Commit
Opcode
Start

Event ID 20903 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
UserTile_Store_Commit
Opcode
Stop

Event ID 20905 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
UserTile_Store_GetImage
Opcode
Start

Event ID 20906 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
UserTile_Store_GetImage
Opcode
Stop

Event ID 20907 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
UserTile_Store_SetImageFromFile
Opcode
Start

Event ID 20908 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
UserTile_Store_SetImageFromFile
Opcode
Stop

Event ID 20909 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
UserTile_Store_SetImageFromStream
Opcode
Start

Event ID 20910 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
UserTile_Store_SetImageFromStream
Opcode
Stop

Event ID 20911 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
UserTile_Store_SetImageFromBitmap
Opcode
Start

Event ID 20912 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
UserTile_Store_SetImageFromBitmap
Opcode
Stop

Event ID 20914 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
UserTile_DynamicTile_Init
Opcode
Start

Event ID 20915 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
UserTile_DynamicTile_Init
Opcode
Stop

Event ID 20916 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
UserTile_DynamicTile_Playback
Opcode
Start

Event ID 20917 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
UserTile_DynamicTile_Playback
Opcode
Stop

Event ID 20918 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
UserTile_Taskbar_Control_DelayInitialize
Opcode
Start

Event ID 20919 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
UserTile_Taskbar_Control_DelayInitialize
Opcode
Stop

Event ID 20920 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
UserInfo_GetUserName
Opcode
Start

Fields #

NameDescription
EXTENDED_NAME_FORMAT UInt32

Event ID 20921 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
UserInfo_GetUserName
Opcode
Stop

Fields #

NameDescription
EXTENDED_NAME_FORMAT UInt32

Event ID 21001 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
SystemTray_ChangeNotify
Opcode
Start

Fields #

NameDescription
LoopCount UInt32

Event ID 21002 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
SystemTray_ChangeNotify
Opcode
Stop

Event ID 21003 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
SystemTray_UserClickedChevon_ChangeNotify
Opcode
Start

Event ID 21004 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
SystemTray_UserClickedChevon_ChangeNotify
Opcode
Stop

Event ID 21005 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
SystemTray_OverflowShown
Opcode
Start

Fields #

NameDescription
nIcons UInt32

Event ID 21006 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
SystemTray_OverflowShown
Opcode
Stop

Event ID 21007 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
SystemTray_IconAdded

Fields #

NameDescription
TrayCode UInt32
guid GUID
uID UInt32
HWND UInt32

Event ID 21009 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
SystemTray_IconRemoved

Fields #

NameDescription
TrayCode UInt32
guid GUID
uID UInt32
HWND UInt32
uReasonForDelete UInt32

Event ID 21011 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
SystemTray_IconModified

Fields #

NameDescription
TrayCode UInt32
guid GUID
uID UInt32
HWND UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "21011",
    "version": "0",
    "level": "4",
    "task": "21011",
    "opcode": "0",
    "keywords": 9223372036854841344,
    "time_created": "2026-03-15T04:20:19.002368900+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "12840",
      "thread_id": "4760"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "TrayCode": "       1",
    "guid": "{00000000-0000-0000-0000-000000000000}",
    "uID": "       0",
    "HWND": "0x51054A"
  },
  "message": ""
}

Event ID 21013 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
SystemTray_SystemPromote

Fields #

NameDescription
guid GUID
uID UInt32
HWND UInt32
Result UInt32

Event ID 21015 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
SystemTray_ShowBalloon

Fields #

NameDescription
guid GUID
uID UInt32
HWND UInt32
Result UInt32

Event ID 21017 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
SystemTray_RearrangeIcon
Opcode
Start

Event ID 21018 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
SystemTray_RearrangeIcon
Opcode
Stop

Fields #

NameDescription
Value UInt32

Event ID 22001 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Taskbar_GroupState_ChangeNotify
Opcode
Start

Event ID 22002 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Taskbar_GroupState_ChangeNotify
Opcode
Stop

Event ID 22003 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Taskbar_LockState_ChangeNotify
Opcode
Start

Event ID 22004 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Taskbar_LockState_ChangeNotify
Opcode
Stop

Event ID 22005 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Taskbar_Click

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmDWORDDatapointValue UInt32

Event ID 22006 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
StarterEdition_AppLimitViolations

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmDWORDDatapointValue UInt32

Event ID 22007 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Taskbar_Settings

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmDWORDDatapointValue UInt32

Event ID 22009 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Taskbar_Location

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmDWORDDatapointValue UInt32

Event ID 22011 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Taskbar_Size

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmDWORDDatapointValue UInt32

Event ID 22013 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Taskbar_Quicklaunch_Item_Launch

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmDWORDDatapointValue UInt32

Event ID 22014 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
New_Taskbar_Pinned_Items_Rearranged

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmDWORDDatapointValue UInt32

Event ID 22015 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Taskbar_Glomming_Enabled

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmDWORDDatapointValue UInt32

Event ID 22017 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Taskbar_Quicklaunch_Enabled

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmDWORDDatapointValue UInt32

Event ID 22018 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Taskbar_RegisterThumbnail
Opcode
Start

Fields #

NameDescription
HWNDSrc Pointer
HWNDThumbnail Pointer

Event ID 22019 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Taskbar_RegisterThumbnail
Opcode
Stop

Fields #

NameDescription
HWNDSrc Pointer
HWNDThumbnail Pointer

Event ID 22020 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Taskbar_ShowThumbnail
Opcode
Start

Fields #

NameDescription
iId UInt32
fFromGlom UInt32

Event ID 22021 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Taskbar_ShowThumbnail
Opcode
Stop

Fields #

NameDescription
iId UInt32
fFromGlom UInt32

Event ID 22022 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Taskbar_Glomming_Count

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmStreamRowLength UInt32
SqmStreamRow Int16

Event ID 22023 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Taskbar_Window_Count

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmStreamRowLength UInt32
SqmStreamRow Int16

Event ID 22025 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Taskbar_SetProgress
Opcode
Start

Fields #

NameDescription
HWND UInt32

Event ID 22026 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Taskbar_SetProgress
Opcode
Stop

Fields #

NameDescription
HWND UInt32
dwValue UInt32

Event ID 22027 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Taskbar_SetProgressState

Fields #

NameDescription
HWND UInt32
dwFlags UInt32

Event ID 22028 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
Taskbar_ButtonGroup_Added

Fields #

NameDescription
hwndTaskBand Pointer
pTBGroup Pointer
pszExePath UnicodeString
tbgType UInt32
x Int32
y Int32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "22028",
    "version": "0",
    "level": "4",
    "task": "22030",
    "opcode": "0",
    "keywords": 9223372036854841344,
    "time_created": "2026-03-15T04:22:41.468372200+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "12840",
      "thread_id": "4760"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "hwndTaskBand": "0x20144",
    "pTBGroup": "0xC910520",
    "pszExePath": "C:\\Windows\\System32\\msdtc.exe",
    "tbgType": "       1",
    "x": "249",
    "y": "1"
  },
  "message": ""
}

Event ID 22029 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Taskbar_ButtonGroup_GlomStateChange

Fields #

NameDescription
hwndTaskBand Pointer
pTBGroup Pointer
pszExePath UnicodeString
tbgType UInt32
x Int32
y Int32

Event ID 22030 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
Taskbar_ButtonGroup_Removed

Fields #

NameDescription
hwndTaskBand Pointer
pTBGroup Pointer
pszExePath UnicodeString
tbgType UInt32
x Int32
y Int32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "22030",
    "version": "0",
    "level": "4",
    "task": "22032",
    "opcode": "0",
    "keywords": 9223372036854841344,
    "time_created": "2026-03-15T04:22:41.489988000+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "12840",
      "thread_id": "4760"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "hwndTaskBand": "0x20144",
    "pTBGroup": "0xC910520",
    "pszExePath": "C:\\Windows\\System32\\msdtc.exe",
    "tbgType": "       0",
    "x": "249",
    "y": "1"
  },
  "message": ""
}

Event ID 22031 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
Taskbar_Window_Added

Fields #

NameDescription
hwnd Pointer
hwndTaskBand Pointer
pTBGroup Pointer
pszExePath UnicodeString
tbgType UInt32
x Int32
y Int32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "22031",
    "version": "0",
    "level": "4",
    "task": "22033",
    "opcode": "0",
    "keywords": 9223372036854841344,
    "time_created": "2026-03-15T04:22:41.468376600+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "12840",
      "thread_id": "4760"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "hwnd": "0x380680",
    "hwndTaskBand": "0x20144",
    "pTBGroup": "0xC910520",
    "pszExePath": "C:\\Windows\\System32\\msdtc.exe",
    "tbgType": "       1",
    "x": "249",
    "y": "1"
  },
  "message": ""
}

Event ID 22032 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
Taskbar_Window_Active

Fields #

NameDescription
hwnd Pointer
hwndTaskBand Pointer
pTBGroup Pointer
pszExePath UnicodeString
tbgType UInt32
x Int32
y Int32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "22032",
    "version": "0",
    "level": "4",
    "task": "22034",
    "opcode": "0",
    "keywords": 9223372036854841344,
    "time_created": "2026-03-15T04:22:41.468405400+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "12840",
      "thread_id": "4760"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "hwnd": "0x380680",
    "hwndTaskBand": "0x20144",
    "pTBGroup": "0xC910520",
    "pszExePath": "C:\\Windows\\System32\\msdtc.exe",
    "tbgType": "       1",
    "x": "249",
    "y": "1"
  },
  "message": ""
}

Event ID 22033 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
Taskbar_Window_Removed

Fields #

NameDescription
hwnd Pointer
hwndTaskBand Pointer
pTBGroup Pointer
pszExePath UnicodeString
tbgType UInt32
x Int32
y Int32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "22033",
    "version": "0",
    "level": "4",
    "task": "22035",
    "opcode": "0",
    "keywords": 9223372036854841344,
    "time_created": "2026-03-15T04:22:41.489787000+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "12840",
      "thread_id": "4760"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "hwnd": "0x380680",
    "hwndTaskBand": "0x20144",
    "pTBGroup": "0xC910520",
    "pszExePath": "C:\\Windows\\System32\\msdtc.exe",
    "tbgType": "       1",
    "x": "249",
    "y": "1"
  },
  "message": ""
}

Event ID 22034 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Taskbar_HoverUIShow

Fields #

NameDescription
fShowText UInt32

Event ID 22035 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
Taskbar_Item_Created

Fields #

NameDescription
hwndItem Pointer

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "22035",
    "version": "0",
    "level": "4",
    "task": "22037",
    "opcode": "0",
    "keywords": 9223372036854841344,
    "time_created": "2026-03-15T04:22:41.461680100+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "12840",
      "thread_id": "4760"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "hwndItem": "0x380680"
  },
  "message": ""
}

Event ID 22036 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
Taskbar_Item_Destroyed

Fields #

NameDescription
hwndItem Pointer

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "22036",
    "version": "0",
    "level": "4",
    "task": "22038",
    "opcode": "0",
    "keywords": 9223372036854841344,
    "time_created": "2026-03-15T04:22:41.490201700+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "12840",
      "thread_id": "4760"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "hwndItem": "0x380680"
  },
  "message": ""
}

Event ID 22037 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
Taskbar_Group_Created

Fields #

NameDescription
pszGroup UnicodeString
hwndItem Pointer

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "22037",
    "version": "0",
    "level": "4",
    "task": "22039",
    "opcode": "0",
    "keywords": 9223372036854841344,
    "time_created": "2026-03-15T04:22:41.465049300+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "12840",
      "thread_id": "4760"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "pszGroup": "C:\\Windows\\System32\\msdtc.exe",
    "hwndItem": "0x0"
  },
  "message": ""
}

Event ID 22038 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
Taskbar_Group_Destroyed

Fields #

NameDescription
pszGroup UnicodeString
hwndItem Pointer

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "22038",
    "version": "0",
    "level": "4",
    "task": "22040",
    "opcode": "0",
    "keywords": 9223372036854841344,
    "time_created": "2026-03-15T04:22:41.490199000+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "12840",
      "thread_id": "4760"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "pszGroup": "C:\\Windows\\System32\\msdtc.exe",
    "hwndItem": "0x0"
  },
  "message": ""
}

Event ID 22039 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
Taskbar_Group_AddItem

Fields #

NameDescription
pszGroup UnicodeString
hwndItem Pointer

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "22039",
    "version": "0",
    "level": "4",
    "task": "22041",
    "opcode": "0",
    "keywords": 9223372036854841344,
    "time_created": "2026-03-15T04:22:41.461697100+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "12840",
      "thread_id": "4760"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "pszGroup": "NULL",
    "hwndItem": "0x380680"
  },
  "message": ""
}

Event ID 22040 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
Taskbar_Group_RemoveItem

Fields #

NameDescription
pszGroup UnicodeString
hwndItem Pointer

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "22040",
    "version": "0",
    "level": "4",
    "task": "22042",
    "opcode": "0",
    "keywords": 9223372036854841344,
    "time_created": "2026-03-15T04:22:41.464943600+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "12840",
      "thread_id": "4760"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "pszGroup": "NULL",
    "hwndItem": "0x380680"
  },
  "message": ""
}

Event ID 22041 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Taskbar_Animation
Opcode
Start

Fields #

NameDescription
pObj UInt64
nAnimType UInt32

Event ID 22042 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Taskbar_Animation
Opcode
Stop

Fields #

NameDescription
pObj UInt64
nAnimType UInt32

Event ID 22043 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Taskbar_AnimFrame
Opcode
Start

Event ID 22044 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Taskbar_AnimFrame
Opcode
Stop

Event ID 22045 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
Taskbar_ComputeLayout

Fields #

NameDescription
nVisibleRow UInt32
nRequiredRow UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "22045",
    "version": "0",
    "level": "4",
    "task": "22045",
    "opcode": "0",
    "keywords": 9223372036854841344,
    "time_created": "2026-03-15T04:22:41.468159300+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "12840",
      "thread_id": "4760"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "nVisibleRow": "       1",
    "nRequiredRow": "       1"
  },
  "message": ""
}

Event ID 22046 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
Taskbar_Compute_Row_Layout

Fields #

NameDescription
nTotalWidth UInt32
nTotalFixedWidth UInt32
iGroupStart UInt32
iItemStart UInt32
iGroupEnd UInt32
iItemEnd UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "22046",
    "version": "0",
    "level": "4",
    "task": "22046",
    "opcode": "0",
    "keywords": 9223372036854841344,
    "time_created": "2026-03-15T04:22:41.468192400+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "12840",
      "thread_id": "4760"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "nTotalWidth": "    1101",
    "nTotalFixedWidth": "     221",
    "iGroupStart": "       0",
    "iItemStart": "4294967295",
    "iGroupEnd": "       5",
    "iItemEnd": "4294967295"
  },
  "message": ""
}

Event ID 22047 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Taskbar_ButtonGroup_Rearranged

Fields #

NameDescription
hwndTaskBand Pointer
pTBGroup Pointer
pszExePath UnicodeString
tbgType UInt32
x Int32
y Int32

Event ID 22048 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Taskbar_Switcher_Context_Menu

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmStreamRowLength UInt32
SqmStreamRow Int16

Event ID 22049 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Taskbar_Scrolling_Stream

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmStreamRowLength UInt32
SqmStreamRow Int16

Event ID 22050 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Taskbar_Window_Picker_Triggers

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmStreamRowLength UInt32
SqmStreamRow Int16

Event ID 22051 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Thumbnail_Window_Picker_Interaction_Stream

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmStreamRowLength UInt32
SqmStreamRow Int16

Event ID 22052 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Legacy_Glom_Interaction_Stream

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmStreamRowLength UInt32
SqmStreamRow Int16

Event ID 22053 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Taskbar_Compute_Column_Layout

Fields #

NameDescription
nTotalHeight UInt32
nTotalFixedHeight UInt32
iGroupStart UInt32
iItemStart UInt32
iGroupEnd UInt32
iItemEnd UInt32

Event ID 22054 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Taskbar_Taskband_Icon_Size

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmDWORDDatapointValue UInt32

Event ID 22055 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Progress_Bars_Customers

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmStreamRowLength UInt32
SqmStreamRow Int16

Event ID 22056 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Progress_Bars_Glom_Count

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmDWORDDatapointValue UInt32

Event ID 22057 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Progress_Bars_Paused_Count

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmDWORDDatapointValue UInt32

Event ID 22058 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Taskbar_ThumbBar_AddButtons

Fields #

NameDescription
Count UInt32

Event ID 22059 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Taskbar_ThumbBar_UpdateButton

Fields #

NameDescription
Index UInt32

Event ID 22060 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Taskbar_ThumbBar_Create
Opcode
Start

Fields #

NameDescription
HWND Pointer

Event ID 22061 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Taskbar_ThumbBar_Create
Opcode
Stop

Fields #

NameDescription
HWND Pointer

Event ID 22062 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Taskbar_ThumbBar_Click

Fields #

NameDescription
Index UInt32

Event ID 22063 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Taskbar_OverlayIcon

Fields #

NameDescription
HWND Pointer

Event ID 22064 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Taskbar_Item_Flashing

Fields #

NameDescription
HWND Pointer
IsFlashed UInt32
SourceType UInt32

Event ID 22065 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Taskbar_OpenWindowContextMenu
Opcode
Start

Event ID 22066 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Taskbar_OpenWindowContextMenu
Opcode
Stop

Event ID 22067 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Taskbar_UserActivityTracker

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmStreamRowLength UInt32
SqmStreamRow Int16

Event ID 22068 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Taskbar_RunAsAdmin_ShiftCtrl_Count

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmDWORDDatapointValue UInt32

Event ID 22069 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Taskbar_NewInstanceContextMenu_Count

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmDWORDDatapointValue UInt32

Event ID 22070 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Taskbar_NewInstanceContextMenu_RunAsAdmin_Count

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmDWORDDatapointValue UInt32

Event ID 22071 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Taskbar_DeskbandStream

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmStreamRowLength UInt32
SqmStreamRow Int16

Event ID 22072 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Thumbnail_Toolbar_Stream

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmStreamRowLength UInt32
SqmStreamRow Int16

Event ID 22073 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Taskbar_NumberOfRows

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmDWORDDatapointValue UInt32

Event ID 22074 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ApplicationOverlays

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmStreamRowLength UInt32
SqmStreamRow Int16

Event ID 22075 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Taskbar_Secondary_Glomming_Enabled

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmDWORDDatapointValue UInt32

Event ID 22076 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Taskbar_Multimon_Configuration

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmDWORDDatapointValue UInt32

Event ID 22077 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Number_Of_Displays

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmDWORDDatapointValue UInt32

Event ID 22078 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Taskbar_Multimon_Window_Count

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmStreamRowLength UInt32
SqmStreamRow Int16

Event ID 22079 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
Taskbar_Settings_Changed

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "22079",
    "version": "0",
    "level": "4",
    "task": "22079",
    "opcode": "0",
    "keywords": 9223372036854841344,
    "time_created": "2026-03-15T04:20:38.364159200+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "12840",
      "thread_id": "4760"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 22080 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Taskbar_Immersive_Show

Event ID 22081 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Taskbar_Immersive_Hide

Event ID 22082 —

#
Provider
Microsoft-Windows-Shell-Core
Channel
Operational
Level
Informational
Task
Taskbar_PinInitialItems
Opcode
Start

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "30336ED4-E327-447C-9DE0-51B652C86108",
    "event_source_name": "",
    "event_id": 22082,
    "version": 0,
    "level": 4,
    "task": 22082,
    "opcode": 1,
    "keywords": 2305843009213759488,
    "time_created": "2022-04-07T16:48:29.343379+00:00",
    "event_record_id": 127,
    "correlation": {},
    "execution": {
      "process_id": 4128,
      "thread_id": 5112
    },
    "channel": "Microsoft-Windows-Shell-Core/Operational",
    "computer": "WIN-FPV0DSIC9O6",
    "security": {
      "user_id": "S-1-5-21-2121334350-1110938707-2888912545-500"
    }
  },
  "event_data": {},
  "message": ""
}

References #

Event ID 22083 —

#
Provider
Microsoft-Windows-Shell-Core
Channel
Operational
Level
Informational
Task
Taskbar_PinInitialItems
Opcode
Stop

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "30336ED4-E327-447C-9DE0-51B652C86108",
    "event_source_name": "",
    "event_id": 22083,
    "version": 0,
    "level": 4,
    "task": 22082,
    "opcode": 2,
    "keywords": 2305843009213759488,
    "time_created": "2022-04-07T16:48:29.346909+00:00",
    "event_record_id": 128,
    "correlation": {},
    "execution": {
      "process_id": 4128,
      "thread_id": 5112
    },
    "channel": "Microsoft-Windows-Shell-Core/Operational",
    "computer": "WIN-FPV0DSIC9O6",
    "security": {
      "user_id": "S-1-5-21-2121334350-1110938707-2888912545-500"
    }
  },
  "event_data": {},
  "message": ""
}

References #

Event ID 23001 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ViewControl_UserSplitButtonClick
Opcode
Start

Event ID 23002 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ViewControl_UserSplitButtonClick
Opcode
Stop

Event ID 23003 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ViewControl_UserViewModeSelect
Opcode
Start

Event ID 23004 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ViewControl_UserViewModeSelect
Opcode
Stop

Event ID 23005 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ViewControl_ViewModeChangeNotify
Opcode
Start

Event ID 23006 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ViewControl_ViewModeChangeNotify
Opcode
Stop

Event ID 23007 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ViewControl_SQMStream

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmStreamRowLength UInt32
SqmStreamRow Int16

Event ID 23008 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
TopView_Usage

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmStreamRowLength UInt32
SqmStreamRow Int16

Event ID 23009 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
TopView_Save

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmStreamRowLength UInt32
SqmStreamRow Int16

Event ID 23010 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ViewMode_Change

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmStreamRowLength UInt32
SqmStreamRow Int16

Event ID 23011 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Sort_Change

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmStreamRowLength UInt32
SqmStreamRow Int16

Event ID 23012 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Stack_Change

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmStreamRowLength UInt32
SqmStreamRow Int16

Event ID 23013 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Group_Change

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmStreamRowLength UInt32
SqmStreamRow Int16

Event ID 23101 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
WordWheel_UserKeypress_ChangeNotify

Fields #

NameDescription
Query UnicodeString

Event ID 23110 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
SendTo_Populate
Opcode
Start

Event ID 23111 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
SendTo_Populate
Opcode
Stop

Event ID 23201 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Glass_Colorization

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmDWORDDatapointValue UInt32

Event ID 23203 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Glass_Composition_Enabled

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmDWORDDatapointValue UInt32

Event ID 23205 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Glass_Theme_Active

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmDWORDDatapointValue UInt32

Event ID 26001 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
CTrackEvents_OperationEventStart

Fields #

NameDescription
Operation UnicodeString
Known values
%%2456
Open key file.
%%2457
Delete key file.
%%2458
Read persisted key from file.
%%2459
Write persisted key to file.
%%2464
Export of persistent cryptographic key.
%%2465
Import of persistent cryptographic key.
%%2480
Open Key.
%%2481
Create Key.
%%2482
Delete Key.
%%2483
Encrypt.
%%2484
Decrypt.
%%2485
Sign hash.
%%2486
Secret agreement.
%%2487
Domain settings.
%%2488
Local settings.
%%2489
Add provider.
%%2490
Remove provider.
%%2491
Add context.
%%2492
Remove context.
%%2493
Add function.
%%2494
Remove function.
%%2495
Add function provider.
%%2496
Remove function provider.
%%2497
Add function property.
%%2498
Remove function property.
%%2499
Machine key.
%%2500
User key.
%%2501
Key Derivation.
%%2502
Claim Creation.
%%2503
Claim Verification.
Type UInt32
Event UInt32

Event ID 26002 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
CTrackEvents_OperationQueueInfo

Fields #

NameDescription
Operation UnicodeString
Known values
%%2456
Open key file.
%%2457
Delete key file.
%%2458
Read persisted key from file.
%%2459
Write persisted key to file.
%%2464
Export of persistent cryptographic key.
%%2465
Import of persistent cryptographic key.
%%2480
Open Key.
%%2481
Create Key.
%%2482
Delete Key.
%%2483
Encrypt.
%%2484
Decrypt.
%%2485
Sign hash.
%%2486
Secret agreement.
%%2487
Domain settings.
%%2488
Local settings.
%%2489
Add provider.
%%2490
Remove provider.
%%2491
Add context.
%%2492
Remove context.
%%2493
Add function.
%%2494
Remove function.
%%2495
Add function provider.
%%2496
Remove function provider.
%%2497
Add function property.
%%2498
Remove function property.
%%2499
Machine key.
%%2500
User key.
%%2501
Key Derivation.
%%2502
Claim Creation.
%%2503
Claim Verification.
PendingCount UInt32
EventReadyState UInt32

Event ID 26003 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
CTrackEvents_StartTimedOperation
Opcode
Start

Event ID 26004 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
CTrackEvents_StartTimedOperation
Opcode
Stop

Event ID 26005 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
CTrackEvents_StopTimedOperation
Opcode
Start

Event ID 26006 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
CTrackEvents_StopTimedOperation
Opcode
Stop

Event ID 26007 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
CTrackEvents_OperationEventEnd

Fields #

NameDescription
Operation UnicodeString
Known values
%%2456
Open key file.
%%2457
Delete key file.
%%2458
Read persisted key from file.
%%2459
Write persisted key to file.
%%2464
Export of persistent cryptographic key.
%%2465
Import of persistent cryptographic key.
%%2480
Open Key.
%%2481
Create Key.
%%2482
Delete Key.
%%2483
Encrypt.
%%2484
Decrypt.
%%2485
Sign hash.
%%2486
Secret agreement.
%%2487
Domain settings.
%%2488
Local settings.
%%2489
Add provider.
%%2490
Remove provider.
%%2491
Add context.
%%2492
Remove context.
%%2493
Add function.
%%2494
Remove function.
%%2495
Add function provider.
%%2496
Remove function provider.
%%2497
Add function property.
%%2498
Remove function property.
%%2499
Machine key.
%%2500
User key.
%%2501
Key Derivation.
%%2502
Claim Creation.
%%2503
Claim Verification.
Type UInt32
Event UInt32

Event ID 26009 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_AdviseCollection
Opcode
Start

Fields #

NameDescription
Caller UnicodeString
IItemCollection Pointer
ICollectionEventSink Pointer
HRESULT UInt32

Event ID 26010 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_AdviseCollection
Opcode
Stop

Fields #

NameDescription
Caller UnicodeString
IItemCollection Pointer
ICollectionEventSink Pointer
HRESULT UInt32

Event ID 26011 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_CDefViewSink_PostMessage

Fields #

NameDescription
RetVal UInt32
HWND Pointer
Message UInt64
WPARAM UInt64
LPARAM UInt64
GetLastError UInt32

Event ID 27002 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PerfTrack_DesktopBackgroundCpl
Opcode
Stop

Fields #

NameDescription
BrowserId UInt32
ItemCount UInt32

Event ID 27004 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PerfTrack_ColorSchemeCpl
Opcode
Stop

Fields #

NameDescription
BrowserId UInt32
ItemCount UInt32

Event ID 27005 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PerfTrack_StartPane_AllPrograms_Show
Opcode
Start

Event ID 27006 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PerfTrack_StartPane_AllPrograms_Show
Opcode
Stop

Event ID 27007 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PerfTrack_StartPane_AllPrograms_BackButton
Opcode
Start

Event ID 27008 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PerfTrack_StartPane_AllPrograms_BackButton
Opcode
Stop

Event ID 27009 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PerfTrack_StartPane_ShowItem
Opcode
Start

Event ID 27010 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PerfTrack_StartPane_ShowItem
Opcode
Stop

Event ID 27011 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PerfTrack_StartPane_SearchItem
Opcode
Start

Event ID 27012 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PerfTrack_StartPane_SearchItem
Opcode
Stop

Event ID 27013 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PerfTrack_StartPane_LogOffMenu
Opcode
Start

Event ID 27014 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PerfTrack_StartPane_LogOffMenu
Opcode
Stop

Event ID 27015 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PerfTrack_StartPane_TopMatchReady
Opcode
Start

Event ID 27016 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PerfTrack_StartPane_TopMatchReady
Opcode
Stop

Event ID 27018 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PerfTrack_Explorer_DocumentsLibrary_Local_PageDisplayed
Opcode
Stop

Fields #

NameDescription
BrowserId UInt32
ItemCount UInt32

Event ID 27020 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PerfTrack_Explorer_DocumentsLibrary_Local_PageCompleted
Opcode
Stop

Fields #

NameDescription
BrowserId UInt32
ItemCount UInt32

Event ID 27022 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PerfTrack_Explorer_DocumentsLibrary_Network_PageDisplayed
Opcode
Stop

Fields #

NameDescription
BrowserId UInt32
ItemCount UInt32

Event ID 27024 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PerfTrack_Explorer_DocumentsLibrary_Network_PageCompleted
Opcode
Stop

Fields #

NameDescription
BrowserId UInt32
ItemCount UInt32

Event ID 27026 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PerfTrack_Explorer_DocumentsLibrary_OpenSearch_PageDisplayed
Opcode
Stop

Fields #

NameDescription
BrowserId UInt32
ItemCount UInt32

Event ID 27028 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PerfTrack_Explorer_DocumentsLibrary_OpenSearch_PageCompleted
Opcode
Stop

Fields #

NameDescription
BrowserId UInt32
ItemCount UInt32

Event ID 27030 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PerfTrack_Explorer_PicturesLibrary_Local_PageDisplayed
Opcode
Stop

Fields #

NameDescription
BrowserId UInt32
ItemCount UInt32

Event ID 27032 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PerfTrack_Explorer_PicturesLibrary_Local_PageCompleted
Opcode
Stop

Fields #

NameDescription
BrowserId UInt32
ItemCount UInt32

Event ID 27034 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PerfTrack_Explorer_PicturesLibrary_Network_PageDisplayed
Opcode
Stop

Fields #

NameDescription
BrowserId UInt32
ItemCount UInt32

Event ID 27036 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PerfTrack_Explorer_PicturesLibrary_Network_PageCompleted
Opcode
Stop

Fields #

NameDescription
BrowserId UInt32
ItemCount UInt32

Event ID 27038 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PerfTrack_Explorer_PicturesLibrary_OpenSearch_PageDisplayed
Opcode
Stop

Fields #

NameDescription
BrowserId UInt32
ItemCount UInt32

Event ID 27040 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PerfTrack_Explorer_PicturesLibrary_OpenSearch_PageCompleted
Opcode
Stop

Fields #

NameDescription
BrowserId UInt32
ItemCount UInt32

Event ID 27042 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PerfTrack_Explorer_MusicLibrary_Local_PageDisplayed
Opcode
Stop

Fields #

NameDescription
BrowserId UInt32
ItemCount UInt32

Event ID 27044 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PerfTrack_Explorer_MusicLibrary_Local_PageCompleted
Opcode
Stop

Fields #

NameDescription
BrowserId UInt32
ItemCount UInt32

Event ID 27046 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PerfTrack_Explorer_MusicLibrary_Network_PageDisplayed
Opcode
Stop

Fields #

NameDescription
BrowserId UInt32
ItemCount UInt32

Event ID 27048 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PerfTrack_Explorer_MusicLibrary_Network_PageCompleted
Opcode
Stop

Fields #

NameDescription
BrowserId UInt32
ItemCount UInt32

Event ID 27050 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PerfTrack_Explorer_MusicLibrary_OpenSearch_PageDisplayed
Opcode
Stop

Fields #

NameDescription
BrowserId UInt32
ItemCount UInt32

Event ID 27052 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PerfTrack_Explorer_MusicLibrary_OpenSearch_PageCompleted
Opcode
Stop

Fields #

NameDescription
BrowserId UInt32
ItemCount UInt32

Event ID 27054 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PerfTrack_Explorer_VideosLibrary_Local_PageDisplayed
Opcode
Stop

Fields #

NameDescription
BrowserId UInt32
ItemCount UInt32

Event ID 27056 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PerfTrack_Explorer_VideosLibrary_Local_PageCompleted
Opcode
Stop

Fields #

NameDescription
BrowserId UInt32
ItemCount UInt32

Event ID 27058 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PerfTrack_Explorer_VideosLibrary_Network_PageDisplayed
Opcode
Stop

Fields #

NameDescription
BrowserId UInt32
ItemCount UInt32

Event ID 27060 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PerfTrack_Explorer_VideosLibrary_Network_PageCompleted
Opcode
Stop

Fields #

NameDescription
BrowserId UInt32
ItemCount UInt32

Event ID 27062 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PerfTrack_Explorer_VideosLibrary_OpenSearch_PageDisplayed
Opcode
Stop

Fields #

NameDescription
BrowserId UInt32
ItemCount UInt32

Event ID 27064 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PerfTrack_Explorer_VideosLibrary_OpenSearch_PageCompleted
Opcode
Stop

Fields #

NameDescription
BrowserId UInt32
ItemCount UInt32

Event ID 27078 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PerfTrack_Explorer_UsersFiles_PageDisplayed
Opcode
Stop

Fields #

NameDescription
BrowserId UInt32
ItemCount UInt32

Event ID 27080 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PerfTrack_Explorer_UsersFiles_PageCompleted
Opcode
Stop

Fields #

NameDescription
BrowserId UInt32
ItemCount UInt32

Event ID 27082 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PerfTrack_CFD_DocumentsLibrary_Local_PageDisplayed
Opcode
Stop

Fields #

NameDescription
BrowserId UInt32
ItemCount UInt32

Event ID 27084 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PerfTrack_CFD_DocumentsLibrary_Local_PageCompleted
Opcode
Stop

Fields #

NameDescription
BrowserId UInt32
ItemCount UInt32

Event ID 27086 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PerfTrack_CFD_DocumentsLibrary_Network_PageDisplayed
Opcode
Stop

Fields #

NameDescription
BrowserId UInt32
ItemCount UInt32

Event ID 27088 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PerfTrack_CFD_DocumentsLibrary_Network_PageCompleted
Opcode
Stop

Fields #

NameDescription
BrowserId UInt32
ItemCount UInt32

Event ID 27090 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PerfTrack_CFD_DocumentsLibrary_OpenSearch_PageDisplayed
Opcode
Stop

Fields #

NameDescription
BrowserId UInt32
ItemCount UInt32

Event ID 27092 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PerfTrack_CFD_DocumentsLibrary_OpenSearch_PageCompleted
Opcode
Stop

Fields #

NameDescription
BrowserId UInt32
ItemCount UInt32

Event ID 27094 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PerfTrack_CFD_PicturesLibrary_Local_PageDisplayed
Opcode
Stop

Fields #

NameDescription
BrowserId UInt32
ItemCount UInt32

Event ID 27096 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PerfTrack_CFD_PicturesLibrary_Local_PageCompleted
Opcode
Stop

Fields #

NameDescription
BrowserId UInt32
ItemCount UInt32

Event ID 27098 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PerfTrack_CFD_PicturesLibrary_Network_PageDisplayed
Opcode
Stop

Fields #

NameDescription
BrowserId UInt32
ItemCount UInt32

Event ID 27100 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PerfTrack_CFD_PicturesLibrary_Network_PageCompleted
Opcode
Stop

Fields #

NameDescription
BrowserId UInt32
ItemCount UInt32

Event ID 27102 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PerfTrack_CFD_PicturesLibrary_OpenSearch_PageDisplayed
Opcode
Stop

Fields #

NameDescription
BrowserId UInt32
ItemCount UInt32

Event ID 27104 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PerfTrack_CFD_PicturesLibrary_OpenSearch_PageCompleted
Opcode
Stop

Fields #

NameDescription
BrowserId UInt32
ItemCount UInt32

Event ID 27106 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PerfTrack_CFD_MusicLibrary_Local_PageDisplayed
Opcode
Stop

Fields #

NameDescription
BrowserId UInt32
ItemCount UInt32

Event ID 27108 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PerfTrack_CFD_MusicLibrary_Local_PageCompleted
Opcode
Stop

Fields #

NameDescription
BrowserId UInt32
ItemCount UInt32

Event ID 27110 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PerfTrack_CFD_MusicLibrary_Network_PageDisplayed
Opcode
Stop

Fields #

NameDescription
BrowserId UInt32
ItemCount UInt32

Event ID 27112 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PerfTrack_CFD_MusicLibrary_Network_PageCompleted
Opcode
Stop

Fields #

NameDescription
BrowserId UInt32
ItemCount UInt32

Event ID 27114 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PerfTrack_CFD_MusicLibrary_OpenSearch_PageDisplayed
Opcode
Stop

Fields #

NameDescription
BrowserId UInt32
ItemCount UInt32

Event ID 27116 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PerfTrack_CFD_MusicLibrary_OpenSearch_PageCompleted
Opcode
Stop

Fields #

NameDescription
BrowserId UInt32
ItemCount UInt32

Event ID 27118 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PerfTrack_CFD_VideosLibrary_Local_PageDisplayed
Opcode
Stop

Fields #

NameDescription
BrowserId UInt32
ItemCount UInt32

Event ID 27120 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PerfTrack_CFD_VideosLibrary_Local_PageCompleted
Opcode
Stop

Fields #

NameDescription
BrowserId UInt32
ItemCount UInt32

Event ID 27122 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PerfTrack_CFD_VideosLibrary_Network_PageDisplayed
Opcode
Stop

Fields #

NameDescription
BrowserId UInt32
ItemCount UInt32

Event ID 27124 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PerfTrack_CFD_VideosLibrary_Network_PageCompleted
Opcode
Stop

Fields #

NameDescription
BrowserId UInt32
ItemCount UInt32

Event ID 27126 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PerfTrack_CFD_VideosLibrary_OpenSearch_PageDisplayed
Opcode
Stop

Fields #

NameDescription
BrowserId UInt32
ItemCount UInt32

Event ID 27128 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PerfTrack_CFD_VideosLibrary_OpenSearch_PageCompleted
Opcode
Stop

Fields #

NameDescription
BrowserId UInt32
ItemCount UInt32

Event ID 27142 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PerfTrack_CFD_UsersFiles_PageDisplayed
Opcode
Stop

Fields #

NameDescription
BrowserId UInt32
ItemCount UInt32

Event ID 27144 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PerfTrack_CFD_UsersFiles_PageCompleted
Opcode
Stop

Fields #

NameDescription
BrowserId UInt32
ItemCount UInt32

Event ID 27145 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PerfTrack_StartMenu_Search_PageDisplayed
Opcode
Start

Fields #

NameDescription
BrowserId UInt32

Event ID 27146 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PerfTrack_StartMenu_Search_PageDisplayed
Opcode
Stop

Fields #

NameDescription
BrowserId UInt32
ItemCount UInt32

Event ID 27147 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PerfTrack_StartMenu_Search_PageCompleted
Opcode
Start

Fields #

NameDescription
BrowserId UInt32

Event ID 27148 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PerfTrack_StartMenu_Search_PageCompleted
Opcode
Stop

Fields #

NameDescription
BrowserId UInt32
ItemCount UInt32

Event ID 27149 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PerfTrack_Taskbar_Launch
Opcode
Start

Event ID 27151 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PerfTrack_HoverUI_FadeIn
Opcode
Start

Event ID 27152 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PerfTrack_HoverUI_FadeIn
Opcode
Stop

Event ID 27153 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PerfTrack_StartMenu_ControlPanel
Opcode
Start

Event ID 27154 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PerfTrack_StartMenu_ControlPanel
Opcode
Stop

Event ID 27155 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PerfTrack_StartMenu_Pictures
Opcode
Start

Event ID 27156 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PerfTrack_StartMenu_Pictures
Opcode
Stop

Event ID 27157 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PerfTrack_StartMenu_Music
Opcode
Start

Event ID 27158 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PerfTrack_StartMenu_Music
Opcode
Stop

Event ID 27159 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PerfTrack_StartMenu_Documents
Opcode
Start

Event ID 27160 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PerfTrack_StartMenu_Documents
Opcode
Stop

Event ID 27161 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PerfTrack_SearchBox_CharactersTyped
Opcode
Start

Event ID 27162 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PerfTrack_SearchBox_CharactersTyped
Opcode
Stop

Event ID 27163 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PerfTrack_Taskbar_DestinationList_Up
Opcode
Start

Event ID 27164 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PerfTrack_Taskbar_DestinationList_Up
Opcode
Stop

Event ID 27165 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PerfTrack_StartMenu_DestinationList_Up
Opcode
Start

Event ID 27166 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PerfTrack_StartMenu_DestinationList_Up
Opcode
Stop

Event ID 27168 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PerfTrack_Explorer_NetworkFileFolderView
Opcode
Stop

Fields #

NameDescription
BrowserId UInt32
ItemCount UInt32

Event ID 27170 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PerfTrack_Explorer_NetworkFolderHighDPI
Opcode
Stop

Fields #

NameDescription
BrowserId UInt32
ItemCount UInt32

Event ID 27172 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PerfTrack_Explorer_LocalFolderHighDPI
Opcode
Stop

Fields #

NameDescription
BrowserId UInt32
ItemCount UInt32

Event ID 27173 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PerfTrack_Explorer_FrameClose
Opcode
Start

Event ID 27174 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PerfTrack_Explorer_FrameClose
Opcode
Stop

Event ID 27176 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PerfTrack_Explorer_Templates_GroupedView
Opcode
Stop

Fields #

NameDescription
BrowserId UInt32
ItemCount UInt32

Event ID 27178 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PerfTrack_Explorer_Templates_StackedView
Opcode
Stop

Fields #

NameDescription
BrowserId UInt32
ItemCount UInt32

Event ID 27180 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PerfTrack_Explorer_Templates_ThumbnailView
Opcode
Stop

Fields #

NameDescription
BrowserId UInt32
ItemCount UInt32

Event ID 27182 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PerfTrack_Explorer_Templates_SearchGroupedView
Opcode
Stop

Fields #

NameDescription
BrowserId UInt32
ItemCount UInt32

Event ID 27184 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PerfTrack_Explorer_Templates_SearchStackedView
Opcode
Stop

Fields #

NameDescription
BrowserId UInt32
ItemCount UInt32

Event ID 27186 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PerfTrack_Explorer_Templates_SearchThumbnailView
Opcode
Stop

Fields #

NameDescription
BrowserId UInt32
ItemCount UInt32

Event ID 27188 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PerfTrack_Explorer_Templates_SearchGrepView
Opcode
Stop

Fields #

NameDescription
BrowserId UInt32
ItemCount UInt32

Event ID 27190 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PerfTrack_Explorer_Templates_OpenSearchView
Opcode
Stop

Fields #

NameDescription
BrowserId UInt32
ItemCount UInt32

Event ID 27191 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PerfTrack_FilterMenu_EnumeratesTypeValues
Opcode
Start

Event ID 27192 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PerfTrack_FilterMenu_EnumeratesTypeValues
Opcode
Stop

Event ID 27193 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PerfTrack_FilterMenu_ListEnumeratesRange
Opcode
Start

Event ID 27194 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PerfTrack_FilterMenu_ListEnumeratesRange
Opcode
Stop

Event ID 27195 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PerfTrack_FilterMenu_MRUEnumerateValues
Opcode
Start

Event ID 27196 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PerfTrack_FilterMenu_MRUEnumerateValues
Opcode
Stop

Event ID 27197 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PerfTrack_FilterMenu_MRUListEnumeratesRanges
Opcode
Start

Event ID 27198 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PerfTrack_FilterMenu_MRUListEnumeratesRanges
Opcode
Stop

Event ID 27199 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PerfTrack_FilterMenu_MRUControlRenders
Opcode
Start

Event ID 27200 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PerfTrack_FilterMenu_MRUControlRenders
Opcode
Stop

Event ID 27202 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PerfTrack_HomeGroup_EnumInView
Opcode
Stop

Fields #

NameDescription
BrowserId UInt32
ItemCount UInt32

Event ID 27203 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PerfTrack_HomeGroup_EnumInNavPane
Opcode
Start

Event ID 27204 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PerfTrack_HomeGroup_EnumInNavPane
Opcode
Stop

Event ID 27206 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PerfTrack_HomeGroup_RemotePC_EnumInView
Opcode
Stop

Fields #

NameDescription
BrowserId UInt32
ItemCount UInt32

Event ID 27208 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PerfTrack_HomeGroup_PublishedItem_PageDisplayed
Opcode
Stop

Fields #

NameDescription
BrowserId UInt32
ItemCount UInt32

Event ID 27209 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PerfTrack_OpenSearch_QueryServer
Opcode
Start

Event ID 27210 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PerfTrack_OpenSearch_QueryServer
Opcode
Stop

Event ID 27211 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PerfTrack_Explorer_ItemsView_PageScroll
Opcode
Start

Event ID 27212 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PerfTrack_Explorer_ItemsView_PageScroll
Opcode
Stop

Event ID 27213 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PerfTrack_Shell32_CopyEngine_CancelDlg
Opcode
Start

Event ID 27214 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PerfTrack_Shell32_CopyEngine_CancelDlg
Opcode
Stop

Event ID 27215 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PerfTrack_LibraryLocation_AddedToLib
Opcode
Start

Event ID 27216 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PerfTrack_LibraryLocation_AddedToLib
Opcode
Stop

Event ID 27217 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PerfTrack_InspectorGadget

Fields #

NameDescription
PerfTrackId UInt32

Event ID 27218 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PerfTrack_InspectorWindow

Fields #

NameDescription
PerfTrackId UInt32

Event ID 27221 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PerfTrack_FilterMenu_FilterSuggestInitial
Opcode
Start

Event ID 27222 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PerfTrack_FilterMenu_FilterSuggestInitial
Opcode
Stop

Event ID 27223 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PerfTrack_FilterMenu_FilterSuggestFinal
Opcode
Start

Event ID 27224 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PerfTrack_FilterMenu_FilterSuggestFinal
Opcode
Stop

Event ID 27226 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PerfTrack_Taskbar_Launch_Explorer
Opcode
Stop

Event ID 27227 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PerfTrack_StartPane_TopMatchReady
Opcode
Stop

Event ID 27229 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PerfTrack_Explorer_Templates_SearchIndexedView
Opcode
Stop

Fields #

NameDescription
BrowserId UInt32
ItemCount UInt32

Event ID 27230 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PerfTrack_Explorer_ExplorerStartToDesktopReady
Opcode
Start

Event ID 27231 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PerfTrack_Explorer_ExplorerStartToDesktopReady
Opcode
Stop

Event ID 27233 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PerfTrack_HomeGroup_PublishedItem_PageComplete
Opcode
Stop

Fields #

NameDescription
BrowserId UInt32
ItemCount UInt32

Event ID 27234 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Delayed_Filter_Contents

Event ID 27235 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PerfTrack_Explorer_Invoke_Cancelled
Opcode
Stop

Event ID 27236 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PerfTrack_StartMenu_Pictures_Network
Opcode
Stop

Event ID 27237 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PerfTrack_StartMenu_Music_Network
Opcode
Stop

Event ID 27238 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PerfTrack_StartMenu_Documents_Network
Opcode
Stop

Event ID 27239 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PerfTrack_ControlPanel_CategoryNavigation
Opcode
Start

Event ID 27240 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PerfTrack_ControlPanel_CategoryNavigation
Opcode
Stop

Event ID 27241 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PerfTrack_StartMenu_SystemControlPanel_Launch
Opcode
Start

Event ID 27242 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PerfTrack_StartMenu_SystemControlPanel_Launch
Opcode
Stop

Event ID 27243 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PerfTrack_Explorer_Navigation
Opcode
Start

Fields #

NameDescription
BrowserId UInt32

Event ID 27244 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PerfTrack_CFD_Navigation
Opcode
Start

Fields #

NameDescription
BrowserId UInt32

Event ID 27248 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PerfTrack_HomeGroup_User_EnumInView
Opcode
Stop

Fields #

NameDescription
BrowserId UInt32
ItemCount UInt32

Event ID 27250 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PerfTrack_HomeGroup_KnownLibrary_PageComplete
Opcode
Stop

Fields #

NameDescription
BrowserId UInt32
ItemCount UInt32

Event ID 27252 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PerfTrack_HomeGroup_KnownLibrary_PageDisplayed
Opcode
Stop

Fields #

NameDescription
BrowserId UInt32
ItemCount UInt32

Event ID 27254 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PerfTrack_HomeGroup_LocalPC_EnumInView
Opcode
Stop

Fields #

NameDescription
BrowserId UInt32
ItemCount UInt32

Event ID 27255 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PerfTrack_Launcher_Login
Opcode
Start

Event ID 27256 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PerfTrack_Launcher_Login
Opcode
Stop

Fields #

NameDescription
RenderedTileCount UInt32
RealizedTileCount UInt32

Event ID 27257 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PerfTrack_DeviceUX_DeviceCenter_EnumInView
Opcode
Stop

Fields #

NameDescription
BrowserId UInt32
ItemCount UInt32

Event ID 28003 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
Shell32_AppResolver_GetAppIDForWindow
Opcode
Start

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "28003",
    "version": "0",
    "level": "4",
    "task": "28163",
    "opcode": "1",
    "keywords": 9223372036854841344,
    "time_created": "2026-03-15T04:20:38.453753500+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "12840",
      "thread_id": "13268"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 28004 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_AppResolver_GetAppIDForWindow
Opcode
Stop

Event ID 28017 — AppResolver Scan Started.

#
Provider
Microsoft-Windows-Shell-Core
Channel
Operational
Level
Informational
Task
Shell32_AppResolver_Scan
Opcode
Start

Description

AppResolver Scan Started.

Message #

AppResolver Scan Started.

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "30336ED4-E327-447C-9DE0-51B652C86108",
    "event_source_name": "",
    "event_id": 28017,
    "version": 0,
    "level": 4,
    "task": 28177,
    "opcode": 1,
    "keywords": 2305843009213759488,
    "time_created": "2023-11-06T01:43:29.982089+00:00",
    "event_record_id": 2837,
    "correlation": {
      "ActivityID": "E4DB489E-1037-0000-7E84-E2E43710DA01"
    },
    "execution": {
      "process_id": 10860,
      "thread_id": 8488
    },
    "channel": "Microsoft-Windows-Shell-Core/Operational",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-21-1992711665-1655669231-58201500-1000"
    }
  },
  "event_data": {},
  "message": ""
}

References #

Event ID 28018 — AppResolver Scan Stopped.

#
Provider
Microsoft-Windows-Shell-Core
Channel
Operational
Level
Informational
Task
Shell32_AppResolver_Scan
Opcode
Stop

Description

AppResolver Scan Stopped.

Message #

AppResolver Scan Stopped.

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "30336ED4-E327-447C-9DE0-51B652C86108",
    "event_source_name": "",
    "event_id": 28018,
    "version": 0,
    "level": 4,
    "task": 28177,
    "opcode": 2,
    "keywords": 2305843009213759488,
    "time_created": "2023-11-06T01:43:34.433011+00:00",
    "event_record_id": 2841,
    "correlation": {
      "ActivityID": "E4DB489E-1037-0000-7E84-E2E43710DA01"
    },
    "execution": {
      "process_id": 10860,
      "thread_id": 8488
    },
    "channel": "Microsoft-Windows-Shell-Core/Operational",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-21-1992711665-1655669231-58201500-1000"
    }
  },
  "event_data": {},
  "message": ""
}

References #

Event ID 28019 — AppResolver Cache Committed.

#
Provider
Microsoft-Windows-Shell-Core
Channel
Operational
Level
Informational
Task
Shell32_AppResolver_CacheCommitted

Description

AppResolver Cache Committed.

Message #

AppResolver Cache Committed.

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "30336ED4-E327-447C-9DE0-51B652C86108",
    "event_source_name": "",
    "event_id": 28019,
    "version": 0,
    "level": 4,
    "task": 28179,
    "opcode": 0,
    "keywords": 2305843009213759488,
    "time_created": "2023-11-06T01:43:34.656672+00:00",
    "event_record_id": 2842,
    "correlation": {
      "ActivityID": "E4DB489E-1037-0000-7E84-E2E43710DA01"
    },
    "execution": {
      "process_id": 10860,
      "thread_id": 8488
    },
    "channel": "Microsoft-Windows-Shell-Core/Operational",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-21-1992711665-1655669231-58201500-1000"
    }
  },
  "event_data": {},
  "message": ""
}

References #

Event ID 28025 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_AppResolverCache_DevTrace

Fields #

NameDescription
psz UnicodeString

Event ID 28026 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_AppResolverCache_ImportShortcut

Fields #

NameDescription
AppID UnicodeString
Code UInt32

Event ID 28027 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_LauncherLayoutManager_ChangeNotify

Fields #

NameDescription
AppID UnicodeString
Event Int32

Event ID 28028 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_RegistryPackageChangeListener_Rescan
Opcode
Start

Fields #

NameDescription
Identity UnicodeString

Event ID 28029 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_RegistryPackageChangeListener_Rescan
Opcode
Stop

Fields #

NameDescription
InstalledVersion Int32
HRESULT UInt32

Event ID 28030 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_RegistryPackageChangeListener_Rescan

Fields #

NameDescription
StoreVersion Int32
InstalledVersion Int32

Event ID 28031 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_RegistryPackageChangeListener_ApplyChange

Fields #

NameDescription
AppID UnicodeString
Event Int32

Event ID 28032 — AppResolver has parsed the visual elements manifest for a tile.

#
Provider
Microsoft-Windows-Shell-Core
Channel
Operational
Level
Informational
Task
Shell32_AppResolver_ParseVisualElementsManifest

Description

AppResolver has parsed the visual elements manifest for a tile.

Message #

AppResolver has parsed the visual elements manifest for a tile.

Fields #

NameDescription
Filename UnicodeString
SchemaType UInt32
ErrorCode UInt32
Failure reason UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "30336ED4-E327-447C-9DE0-51B652C86108",
    "event_source_name": "",
    "event_id": 28032,
    "version": 0,
    "level": 4,
    "task": 28180,
    "opcode": 0,
    "keywords": 2305843009213759488,
    "time_created": "2023-11-05T23:52:32.768687+00:00",
    "event_record_id": 2547,
    "correlation": {
      "ActivityID": "E4DB489E-1037-0001-8D57-DBE43710DA01"
    },
    "execution": {
      "process_id": 5044,
      "thread_id": 10156
    },
    "channel": "Microsoft-Windows-Shell-Core/Operational",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-21-1992711665-1655669231-58201500-1000"
    }
  },
  "event_data": {
    "Filename": "C:\\Program Files (x86)\\Dropbox\\Client\\Dropbox.VisualElementsManifest.xml",
    "SchemaType": 2,
    "ErrorCode": 0,
    "Failure reason": "NULL"
  },
  "message": ""
}

References #

Event ID 28101 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_WindowPropStore_SetValue

Event ID 28103 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
Shell32_WindowPropStore_GetValue

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "28103",
    "version": "0",
    "level": "4",
    "task": "28185",
    "opcode": "0",
    "keywords": 9223372036854841344,
    "time_created": "2026-03-15T04:20:18.461180100+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "12840",
      "thread_id": "4760"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 28105 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_WindowPropStore_ValueRemoved

Event ID 28107 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_AppResolver_DualModeDisallowed

Fields #

NameDescription
AppID UnicodeString
Code UInt32

Event ID 28109 — Application AppID state changed from OldState to NewState due to package PackageName having state Value in registry list.

Provider
Microsoft-Windows-Shell-Core
Channel
Operational
Task
Shell32_RegistryPackageChangeListener_AppStateChange

Description

Application AppID state changed from OldState to NewState due to package PackageName having state Value in registry list.

Message #

Application %1 state changed from %2 to %3 due to package %4 having state %5 in registry list.

Fields #

NameDescription
AppID UnicodeString
OldState UInt32
NewState UInt32
PackageName UnicodeString
Value UInt32

Event ID 28111 — Application AppID state changed from OldState to NewState due to package PackageName being removed from registry list.

Provider
Microsoft-Windows-Shell-Core
Channel
Operational
Task
Shell32_RegistryPackageChangeListener_AppStateReset

Description

Application AppID state changed from OldState to NewState due to package PackageName being removed from registry list.

Message #

Application %1 state changed from %2 to %3 due to package %4 being removed from registry list.

Fields #

NameDescription
AppID UnicodeString
OldState UInt32
NewState UInt32
PackageName UnicodeString

Event ID 28113 — Change notified on {Filename} with event {Event}.

Provider
Microsoft-Windows-Shell-Core
Channel
Operational

Description

Change notified on {Filename} with event {Event}. App resolver will be triggered to rescan.

Message #

Change notified on {Filename} with event {Event}. App resolver will be triggered to rescan.

Fields #

NameDescription
Filename
Event

Event ID 28115 — Shortcut for application Name with ID AppID and flags Flags is added to app resolver cache.

#
Provider
Microsoft-Windows-Shell-Core
Channel
Operational
Level
Informational
Task
Shell32_AppResolverCache_AddShortcut

Description

Shortcut for application Name with ID AppID and flags Flags is added to app resolver cache.

Message #

Shortcut for application %1 with ID %2 and flags %3 is added to app resolver cache.

Fields #

NameDescription
Name UnicodeString
AppID UnicodeString
Flags UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "30336ED4-E327-447C-9DE0-51B652C86108",
    "event_source_name": "",
    "event_id": 28115,
    "version": 0,
    "level": 4,
    "task": 28141,
    "opcode": 0,
    "keywords": 2305843009213759488,
    "time_created": "2023-11-06T01:43:34.432903+00:00",
    "event_record_id": 2840,
    "correlation": {
      "ActivityID": "E4DB489E-1037-0000-7E84-E2E43710DA01"
    },
    "execution": {
      "process_id": 10860,
      "thread_id": 8488
    },
    "channel": "Microsoft-Windows-Shell-Core/Operational",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-21-1992711665-1655669231-58201500-1000"
    }
  },
  "event_data": {
    "Name": "Google Password Manager",
    "AppID": "Chrome._crx_kajebgjangfejcanhanjmmbcfd",
    "Flags": 17
  },
  "message": ""
}

Detection Rules #

View all rules referencing this event →

Sigma # view in reference

References #

Event ID 28116 — Shortcut for application Name with ID AppID and flags Flags is removed from app resolver cache.

Provider
Microsoft-Windows-Shell-Core
Channel
Operational
Task
Shell32_AppResolverCache_RemoveShortcut

Description

Shortcut for application Name with ID AppID and flags Flags is removed from app resolver cache.

Message #

Shortcut for application %1 with ID %2 and flags %3 is removed from app resolver cache.

Fields #

NameDescription
Name UnicodeString
AppID UnicodeString
Flags UInt32

Event ID 28117 — Shortcut for application Name with ID AppID and flags Flags is updated in app resolver cache.

#
Provider
Microsoft-Windows-Shell-Core
Channel
Operational
Level
Informational
Task
Shell32_AppResolverCache_UpdateShortcut

Description

Shortcut for application Name with ID AppID and flags Flags is updated in app resolver cache.

Message #

Shortcut for application %1 with ID %2 and flags %3 is updated in app resolver cache.

Fields #

NameDescription
Name UnicodeString
AppID UnicodeString
Flags UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "30336ED4-E327-447C-9DE0-51B652C86108",
    "event_source_name": "",
    "event_id": 28117,
    "version": 0,
    "level": 4,
    "task": 28143,
    "opcode": 0,
    "keywords": 2305843009213759488,
    "time_created": "2023-11-06T00:55:14.841614+00:00",
    "event_record_id": 2815,
    "correlation": {},
    "execution": {
      "process_id": 10860,
      "thread_id": 17252
    },
    "channel": "Microsoft-Windows-Shell-Core/Operational",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-21-1992711665-1655669231-58201500-1000"
    }
  },
  "event_data": {
    "Name": "Avast Free Antivirus",
    "AppID": "avast! Antivirus",
    "Flags": 17
  },
  "message": ""
}

References #

Event ID 28119 — Start screen loaded layout which contains Groups groups and Tiles tiles (including Placeholders placeholders), Flags=Flags.

Provider
Microsoft-Windows-Shell-Core
Channel
Operational
Task
Shell32_AppResolver_InitialDefaultLayout

Description

Start screen loaded layout which contains Groups groups and Tiles tiles (including Placeholders placeholders), Flags=Flags.

Message #

Start screen loaded layout which contains %1 groups and %2 tiles (including %3 placeholders), Flags=%4.

Fields #

NameDescription
Groups Int32
Tiles Int32
Placeholders Int32
Flags Int32

Event ID 28121 — Start screen loaded persisted layout which contains {Groups} groups and {Tiles} tiles (including {Placeholders} placeholders).

Provider
Microsoft-Windows-Shell-Core
Channel
Operational

Description

Start screen loaded persisted layout which contains {Groups} groups and {Tiles} tiles (including {Placeholders} placeholders).

Message #

Start screen loaded persisted layout which contains {Groups} groups and {Tiles} tiles (including {Placeholders} placeholders).

Fields #

NameDescription
Groups
Tiles
Placeholders

Event ID 28123 — Updated start screen layout: ItemsExisting items initially; ItemsAdded added; ItemsRemoved removed; ItemsRemoved updated.

Provider
Microsoft-Windows-Shell-Core
Channel
Operational
Task
Shell32_AppResolver_UpdateLayout

Description

Updated start screen layout: ItemsExisting items initially; ItemsAdded added; ItemsRemoved removed; ItemsRemoved updated. Cache contains ItemsUpdated applications.

Message #

Updated start screen layout: %1 items initially; %2 added; %3 removed; %3 updated. Cache contains %4 applications.

Fields #

NameDescription
ItemsExisting Int32
ItemsAdded Int32
ItemsRemoved Int32
ItemsUpdated Int32
ItemsCached Int32

Event ID 28125 — Starting to refresh app resolver cache for scenario Scenario with flags Flags.

#
Provider
Microsoft-Windows-Shell-Core
Channel
Operational
Level
Informational
Task
Shell32_AppResolver_RefreshCache

Description

Starting to refresh app resolver cache for scenario Scenario with flags Flags.

Message #

Starting to refresh app resolver cache for scenario %1 with flags %2.

Fields #

NameDescription
Scenario Int32
Flags Int32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "30336ED4-E327-447C-9DE0-51B652C86108",
    "event_source_name": "",
    "event_id": 28125,
    "version": 0,
    "level": 4,
    "task": 28137,
    "opcode": 0,
    "keywords": 2305843009213759488,
    "time_created": "2023-11-05T23:53:59.757383+00:00",
    "event_record_id": 2613,
    "correlation": {},
    "execution": {
      "process_id": 10860,
      "thread_id": 9624
    },
    "channel": "Microsoft-Windows-Shell-Core/Operational",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-21-1992711665-1655669231-58201500-1000"
    }
  },
  "event_data": {
    "Scenario": 1,
    "Flags": 2316
  },
  "message": ""
}

References #

Event ID 28127 —

Provider
Microsoft-Windows-Shell-Core
Channel
Operational
Task
Shell32_StateStoreCommitRetry

Fields #

NameDescription
UpdateSource Int32
RetryCount Int32
ErrorCode UInt32

Event ID 28189 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
AppResolver_AppInstallation

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmStreamRowLength UInt32
SqmStreamRow Int16

Event ID 28191 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_OperationTile_SQMStream

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmStreamRowLength UInt32
SqmStreamRow Int16

Event ID 28193 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_OperationManager_SQMStream

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmStreamRowLength UInt32
SqmStreamRow Int16

Event ID 28195 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_ConflictUI_SQMStream

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmStreamRowLength UInt32
SqmStreamRow Int16

Event ID 50001 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellLib_AdjustImage
Opcode
Start

Event ID 50002 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellLib_AdjustImage
Opcode
Stop

Event ID 50101 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShutdownUX_ShowMenu
Opcode
Start

Event ID 50102 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShutdownUX_ShowMenu
Opcode
Stop

Event ID 50103 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShutdownUX_DefaultButtonPress
Opcode
Start

Event ID 50104 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShutdownUX_DefaultButtonPress
Opcode
Stop

Event ID 50105 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShutdownUX_SelectMenuItem
Opcode
Start

Event ID 50106 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShutdownUX_SelectMenuItem
Opcode
Stop

Event ID 50107 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShutdownUX_StartMenuCriticalPath
Opcode
Start

Event ID 50108 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShutdownUX_StartMenuCriticalPath
Opcode
Stop

Event ID 50201 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
CDBurn_SQM_PrepareDisc_Launch

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmDWORDDatapointValue UInt32

Event ID 50202 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
CDBurn_SQM_PrepareDisc_Mastered

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmDWORDDatapointValue UInt32

Event ID 50203 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
CDBurn_SQM_PrepareDisc_LiveFS

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmDWORDDatapointValue UInt32

Event ID 50204 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
CDBurn_SQM_Mastered_Session

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmDWORDDatapointValue UInt32

Event ID 50205 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
CDBurn_SQM_SessionOpenOnEject_Multi

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmDWORDDatapointValue UInt32

Event ID 50206 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
CDBurn_SQM_SessionOpenOnEject_Single

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmDWORDDatapointValue UInt32

Event ID 50207 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
CDBurn_SQM_IsoBurn_Session

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmDWORDDatapointValue UInt32

Event ID 50208 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
CDBurn_SQM_CloseSession_Command

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmDWORDDatapointValue UInt32

Event ID 50209 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
CDBurn_IsoBurn_Launch

Event ID 50210 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
CDBurn_IsoBurn_Task
Opcode
Start

Event ID 50211 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
CDBurn_IsoBurn_Task
Opcode
Stop

Event ID 60000 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
IE_HistoryBrokerStartup
Opcode
Start

Event ID 60001 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
IE_HistoryBrokerStartup
Opcode
Stop

Event ID 60002 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
IE_HistoryBrokerShutdown
Opcode
Start

Event ID 60003 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
IE_HistoryBrokerShutdown
Opcode
Stop

Event ID 60004 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
IE_AddToHistory
Opcode
Start

Event ID 60005 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
IE_AddToHistory
Opcode
Stop

Event ID 60006 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
IE_QueryHistory
Opcode
Start

Event ID 60007 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
IE_QueryHistory
Opcode
Stop

Event ID 60008 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
IE_EnumHistoryRecords
Opcode
Start

Event ID 60009 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
IE_EnumHistoryRecords
Opcode
Stop

Event ID 60010 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
IE_LegacyHistoryAdd
Opcode
Start

Event ID 60011 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
IE_LegacyHistoryAdd
Opcode
Stop

Event ID 60012 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
IE_LegacyHistoryQuery
Opcode
Start

Event ID 60013 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
IE_LegacyHistoryQuery
Opcode
Stop

Event ID 60014 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
IE_LegacyHistoryEnum
Opcode
Start

Event ID 60015 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
IE_LegacyHistoryEnum
Opcode
Stop

Event ID 60016 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
IE_CreateThumbnail
Opcode
Start

Event ID 60017 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
IE_CreateThumbnail
Opcode
Stop

Event ID 60018 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
IE_ScaleThumbnail
Opcode
Start

Event ID 60019 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
IE_ScaleThumbnail
Opcode
Stop

Event ID 60020 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
IE_CompressThumbnail
Opcode
Start

Event ID 60021 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
IE_CompressThumbnail
Opcode
Stop

Event ID 60022 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
IE_GenerateThumbnail
Opcode
Start

Event ID 60023 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
IE_GenerateThumbnail
Opcode
Stop

Event ID 60025 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
IE_LButtonAction

Event ID 60026 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
IE_ExtensionCreate
Opcode
Start

Event ID 60027 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
IE_ExtensionCreate
Opcode
Stop

Event ID 60028 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
IE_ExtensionSetSite
Opcode
Start

Event ID 60029 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
IE_ExtensionSetSite
Opcode
Stop

Event ID 60030 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
IE_ExtensionShowDW
Opcode
Start

Event ID 60031 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
IE_ExtensionShowDW
Opcode
Stop

Event ID 60032 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
IE_ExtensionCloseDW
Opcode
Start

Event ID 60033 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
IE_ExtensionCloseDW
Opcode
Stop

Event ID 60034 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
IE_ExtensionSetSiteNull
Opcode
Start

Event ID 60035 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
IE_ExtensionSetSiteNull
Opcode
Stop

Event ID 60036 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
IE_ExtensionRelease
Opcode
Start

Event ID 60037 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
IE_ExtensionRelease
Opcode
Stop

Event ID 60101 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
StructuredQuery_ParseText
Opcode
Start

Event ID 60102 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
StructuredQuery_ParseText
Opcode
Stop

Event ID 60103 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
StructuredQuery_Resolve
Opcode
Start

Event ID 60104 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
StructuredQuery_Resolve
Opcode
Stop

Event ID 60105 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
StructuredQuery_InitQueryParser
Opcode
Start

Event ID 60106 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
StructuredQuery_InitQueryParser
Opcode
Stop

Event ID 60107 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
StructuredQuery_RestateQuery
Opcode
Start

Event ID 60108 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
StructuredQuery_RestateQuery
Opcode
Stop

Event ID 60109 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
StructuredQuery_CreateSchemaBinary
Opcode
Start

Event ID 60110 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
StructuredQuery_CreateSchemaBinary
Opcode
Stop

Event ID 60111 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
StructuredQuery_LoadSchemaBinary
Opcode
Start

Event ID 60112 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
StructuredQuery_LoadSchemaBinary
Opcode
Stop

Event ID 60113 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
StructuredQuery_SaveSchemaBinary
Opcode
Start

Event ID 60114 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
StructuredQuery_SaveSchemaBinary
Opcode
Stop

Event ID 60115 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
StructuredQuery_FindMatches
Opcode
Start

Event ID 60116 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
StructuredQuery_FindMatches
Opcode
Stop

Event ID 60117 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
StructuredQuery_CreateWordBreaker
Opcode
Start

Event ID 60118 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
StructuredQuery_CreateWordBreaker
Opcode
Stop

Event ID 60119 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
StructuredQuery_InitWordBreaker
Opcode
Start

Event ID 60120 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
StructuredQuery_InitWordBreaker
Opcode
Stop

Event ID 60201 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
SearchBox_ColorAQS
Opcode
Start

Event ID 60202 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
SearchBox_ColorAQS
Opcode
Stop

Event ID 60203 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
SearchBox_Popup_Show
Opcode
Start

Event ID 60204 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
SearchBox_Popup_Show
Opcode
Stop

Event ID 60205 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
SearchBox_MRU_Populate
Opcode
Start

Event ID 60206 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
SearchBox_MRU_Populate
Opcode
Stop

Event ID 60213 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
SearchBox_MRU_Populate
Opcode
Start

Event ID 60214 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
SearchBox_MRU_Populate
Opcode
Stop

Event ID 60215 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
SearchBox_Acquired_Focus

Event ID 60216 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
SearchBox_LinguisticAlternativeGenerator_GenerateAlternatives
Opcode
Start

Fields #

NameDescription
CLSIDTextService GUID
LangId UInt32
LangProfile GUID

Event ID 60217 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
SearchBox_LinguisticAlternativeGenerator_GenerateAlternatives
Opcode
Stop

Fields #

NameDescription
CLSIDTextService GUID
LangId UInt32
LangProfile GUID
HRESULT UInt32
QueryLen UInt32
AltCount UInt32
ReasonCode UInt32

Event ID 60218 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
SearchBox_SearchConversionList_Animation
Opcode
Start

Fields #

NameDescription
AnimId UInt32

Event ID 60219 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
SearchBox_SearchConversionList_Animation
Opcode
Stop

Fields #

NameDescription
AnimId UInt32

Event ID 60220 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
SearchBox_SearchConversionList_BeginUIElement

Fields #

NameDescription
ElemId UInt32
IsUILess Boolean
IsIntegratable Boolean

Event ID 60221 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
SearchBox_SearchConversionList_UpdateUIElement

Fields #

NameDescription
ElemId UInt32
Flags UInt32

Event ID 60222 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
SearchBox_SearchConversionList_EndUIElement

Fields #

NameDescription
ElemId UInt32

Event ID 60301 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
TryHarder_Draw_All
Opcode
Start

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "60301",
    "version": "0",
    "level": "4",
    "task": "60301",
    "opcode": "1",
    "keywords": 9225623836668526592,
    "time_created": "2026-03-15T04:21:15.003422300+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "12840",
      "thread_id": "8552"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 60302 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
TryHarder_Draw_All
Opcode
Stop

Event ID 60303 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
TryHarder_Calculate_Scopes
Opcode
Start

Event ID 60304 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
TryHarder_Calculate_Scopes
Opcode
Stop

Event ID 60305 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
TryHarder_Calculate_Search_File_Contents
Opcode
Start

Event ID 60306 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
TryHarder_Calculate_Search_File_Contents
Opcode
Stop

Event ID 60307 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
TryHarder_Calculate_Search_Subfolders
Opcode
Start

Event ID 60308 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
TryHarder_Calculate_Search_Subfolders
Opcode
Stop

Event ID 60309 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
TryHarder_Start_New_Search
Opcode
Start

Event ID 60310 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
TryHarder_Start_New_Search
Opcode
Stop

Event ID 60311 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
TryHarder_Internet_Rollover
Opcode
Start

Event ID 60312 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
TryHarder_Internet_Rollover
Opcode
Stop

Event ID 60401 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
NetworkUX_NewNetCountMaxReached

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmDWORDDatapointValue UInt32

Event ID 60501 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
NAVPANE_ACTION

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmStreamRowLength UInt32
SqmStreamRow Int16

Event ID 60503 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
NAVIGATIONPANE_ITEMCOUNTS

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmStreamRowLength UInt32
SqmStreamRow Int16

Event ID 60601 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ItemsView_UIItemsView_BatchFirstEvent

Event ID 60603 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ItemsView_UIItemsView_BatchTimer
Opcode
Start

Fields #

NameDescription
Events UInt32

Event ID 60604 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ItemsView_UIItemsView_BatchTimer
Opcode
Stop

Fields #

NameDescription
Events UInt32

Event ID 60605 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ItemsView_UIItemsView_FlushBatch
Opcode
Start

Event ID 60606 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ItemsView_UIItemsView_FlushBatch
Opcode
Stop

Fields #

NameDescription
Events UInt32

Event ID 60607 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ItemsView_UIItemsView_EndBatching

Event ID 60609 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ItemsView_UIItemsView_NotifyContentsChanged
Opcode
Start

Event ID 60610 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ItemsView_UIItemsView_NotifyContentsChanged
Opcode
Stop

Event ID 60611 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ItemsView_UIItemsView_PreProcessEventQueue
Opcode
Start

Event ID 60612 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ItemsView_UIItemsView_PreProcessEventQueue
Opcode
Stop

Fields #

NameDescription
Flushed UInt32
Skipped UInt32
Batched UInt32

Event ID 60613 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ItemsView_UIItem_OnItemEvent
Opcode
Start

Event ID 60614 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ItemsView_UIItem_OnItemEvent
Opcode
Stop

Event ID 60615 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ItemsView_UICollection_OnCollectionEvent
Opcode
Start

Event ID 60616 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ItemsView_UICollection_OnCollectionEvent
Opcode
Stop

Event ID 60617 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ItemsView_UIItemsView_Paint
Opcode
Start

Event ID 60618 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ItemsView_UIItemsView_Paint
Opcode
Stop

Event ID 60619 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ItemsView_LineScroller_RealizeContent
Opcode
Start

Event ID 60620 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ItemsView_LineScroller_RealizeContent
Opcode
Stop

Event ID 60621 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ItemsView_LineScroller_LayoutPass
Opcode
Start

Event ID 60622 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ItemsView_LineScroller_LayoutPass
Opcode
Stop

Event ID 60623 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ItemsView_LineScroller_DesiredSizePass
Opcode
Start

Event ID 60624 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ItemsView_LineScroller_DesiredSizePass
Opcode
Stop

Event ID 60625 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ItemsView_ItemDevirtualizer_ForegroundFullDevirtualization

Event ID 60626 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ItemsView_UIColumnHeader_SortColumn
Opcode
Start

Event ID 60627 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ItemsView_UIColumnHeader_SortColumn
Opcode
Stop

Event ID 60628 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ItemsView_SelectionState_SelectionChange
Opcode
Start

Event ID 60629 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ItemsView_SelectionState_SelectionChange
Opcode
Stop

Event ID 60631 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ItemsView_AnimationManager_SetupAnimation
Opcode
Start

Fields #

NameDescription
ANIMATIONTYPE UInt32

Event ID 60632 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ItemsView_AnimationManager_SetupAnimation
Opcode
Stop

Fields #

NameDescription
ANIMATIONTYPE UInt32

Event ID 60633 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ItemsView_AnimationManager_FinishAnimationSetup
Opcode
Start

Fields #

NameDescription
ANIMATIONTYPE UInt32

Event ID 60634 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ItemsView_AnimationManager_FinishAnimationSetup
Opcode
Stop

Fields #

NameDescription
ANIMATIONTYPE UInt32

Event ID 60635 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ItemsView_AnimationManager_AllocateHBITMAP
Opcode
Start

Event ID 60636 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ItemsView_AnimationManager_AllocateHBITMAP
Opcode
Stop

Fields #

NameDescription
HRESULT UInt32
Width UInt32
Height UInt32

Event ID 60637 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ItemsView_AnimationManager_AnimationLoop
Opcode
Start

Event ID 60638 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ItemsView_AnimationManager_AnimationLoop
Opcode
Stop

Fields #

NameDescription
AnimationTime UInt32
Frames UInt32
Framerate Double
BackBuffersUsed UInt32

Event ID 60639 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ItemsView_AnimationManager_Paint
Opcode
Start

Event ID 60640 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ItemsView_AnimationManager_Paint
Opcode
Stop

Event ID 60641 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ItemsView_SQM

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmStreamRowLength UInt32
SqmStreamRow Int16

Event ID 60643 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ItemsView_UIItemsView_Prefetch
Opcode
Start

Event ID 60644 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ItemsView_UIItemsView_Prefetch
Opcode
Stop

Event ID 60645 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ItemsView_UIItemsView_PreparePrefetch
Opcode
Start

Event ID 60646 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ItemsView_UIItemsView_PreparePrefetch
Opcode
Stop

Event ID 60647 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ItemsView_UIItemsView_BlockRedraw
Opcode
Start

Event ID 60648 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ItemsView_UIItemsView_BlockRedraw
Opcode
Stop

Fields #

NameDescription
SetRedrawCount UInt32

Event ID 60649 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ItemsView_UIItemsView_RunFirstPageResults
Opcode
Start

Event ID 60650 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ItemsView_UIItemsView_RunFirstPageResults
Opcode
Stop

Event ID 60651 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ItemsView_ItemDevirtualizer_FullDevirtualization

Event ID 60652 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ItemsView_ItemDevirtualizer_PartialDevirtualization

Event ID 60653 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ItemsView_FirstPage_UpdateCountReport

Fields #

NameDescription
Items UInt32

Event ID 60655 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ItemsView_UIItemsView_StartBatchTimer

Event ID 60657 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ItemsView_UIItemsView_PostEvent

Event ID 60659 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
Shell32_CDesktopBrowser_PaintWallpaper

Fields #

NameDescription
MonitorID UInt32
Left Int32
Top Int32
Right Int32
Bottom Int32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "60659",
    "version": "0",
    "level": "4",
    "task": "60659",
    "opcode": "0",
    "keywords": 9223372036854841344,
    "time_created": "2026-03-15T04:20:38.361259000+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "12840",
      "thread_id": "8552"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "MonitorID": "       0",
    "Left": "0",
    "Top": "0",
    "Right": "1760",
    "Bottom": "2048"
  },
  "message": ""
}

Event ID 60661 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_CWallpaperWindow_CaptureWallpaper

Fields #

NameDescription
HRESULT UInt32

Event ID 60701 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell_DesktopBackgroundSlideshow_Tick
Opcode
Start

Event ID 60702 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell_DesktopBackgroundSlideshow_Tick
Opcode
Stop

Event ID 60705 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell_DesktopBackgroundSlideshow_Workitem

Fields #

NameDescription
WorkItem UnicodeString
HRESULT UInt32
TimeToNextTick UInt32
Paused UInt32

Event ID 60706 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_CDesktopBrowser_Slideshow_IsRunning

Fields #

NameDescription
ErrorCode UInt32

Event ID 60707 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_CDesktopBrowser_Slideshow_Refresh

Fields #

NameDescription
ErrorCode UInt32

Event ID 60708 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_CDesktopBrowser_Slideshow_Tick_Timer

Fields #

NameDescription
ErrorCode UInt32

Event ID 60709 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_CDesktopBrowser_Slideshow_Tick_Manual

Fields #

NameDescription
ErrorCode UInt32

Event ID 60710 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_CDesktopBrowser_Slideshow_Enable

Fields #

NameDescription
ErrorCode UInt32

Event ID 60711 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_AutoColorization_ColorChosen

Fields #

NameDescription
dwColorChosen UInt32
pszFilePath UnicodeString

Event ID 60712 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_AutoColorization_Analysis
Opcode
Start

Event ID 60713 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_AutoColorization_Analysis
Opcode
Stop

Event ID 60714 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_CDesktopWallpaper_AutoSpan

Fields #

NameDescription
pszFilePath UnicodeString
uImageWidth UInt32
uImageHeight UInt32

Event ID 60715 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_CDesktopWallpaper_AutoDecision

Fields #

NameDescription
fFillChosenOverFit Boolean
pszFilePath UnicodeString
uImageWidth UInt32
uImageHeight UInt32
uMonitorWidth UInt32
uMonitorHeight UInt32

Event ID 60716 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
Shell32_CDesktopWallpaper_WallpaperPosition

Fields #

NameDescription
uPicturePosition UInt32
pszFilePath UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "60716",
    "version": "0",
    "level": "4",
    "task": "60716",
    "opcode": "0",
    "keywords": 9223372036854841344,
    "time_created": "2026-03-15T04:20:38.361835200+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "12840",
      "thread_id": "8552"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "uPicturePosition": "       1",
    "pszFilePath": "C:\\Users\\DOMAIN~1\\AppData\\Local\\Temp\\3\\BGInfo.bmp"
  },
  "message": ""
}

Event ID 60751 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_ActiveSetup
Opcode
Start

Event ID 60752 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_ActiveSetup
Opcode
Stop

Event ID 60753 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_ActiveSetup_RunInstallUninstallStubsWorker
Opcode
Start

Fields #

NameDescription
pszBranchToRun UnicodeString

Event ID 60754 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_ActiveSetup_RunInstallUninstallStubsWorker
Opcode
Stop

Fields #

NameDescription
pszBranchToRun UnicodeString

Event ID 60755 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_ActiveSetup_RunOneInstallStub
Opcode
Start

Fields #

NameDescription
pszKeyName UnicodeString
activeSetupDisabled Boolean
allowTaskOverride Boolean
taskEnabled Boolean

Event ID 60756 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_ActiveSetup_RunOneInstallStub
Opcode
Stop

Fields #

NameDescription
pszKeyName UnicodeString
activeSetupDisabled Boolean
allowTaskOverride Boolean
taskEnabled Boolean

Event ID 60757 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_ActiveSetup_RunPendingGPOs
Opcode
Start

Event ID 60758 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_ActiveSetup_RunPendingGPOs
Opcode
Stop

Event ID 60759 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_ActiveSetup_RunSetupCommand
Opcode
Start

Fields #

NameDescription
pszPathName UnicodeString

Event ID 60760 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_ActiveSetup_RunSetupCommand
Opcode
Stop

Fields #

NameDescription
pszPathName UnicodeString

Event ID 60801 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellLib_DUIControls_CandidateList_Show

Event ID 60802 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellLib_DUIControls_CandidateList_Hide

Event ID 60803 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellLib_DUIControls_CandidateList_DataSourceChanged

Fields #

NameDescription
Value UInt32

Event ID 60804 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellLib_DUIControls_CandidateList_UIReady

Event ID 60805 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellLib_DUIControls_CandidateList_PageChanged

Fields #

NameDescription
PageIndex Int32
InteractionType UInt32

Event ID 60806 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellLib_DUIControls_CandidateList_CandidateFocusChanged

Fields #

NameDescription
Index Int32

Event ID 60807 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellLib_DUIControls_CandidateList_CloseButtonPressed

Event ID 60808 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellLib_DUIControls_CandidateList_Finalize

Fields #

NameDescription
Index Int32

Event ID 60809 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellLib_DUIControls_CandidateList_FillInterrupted

Fields #

NameDescription
CandidateCount Int32
CandidateToFocusIndex Int32
PageToFocusIndex Int32
InteractionType UInt32

Event ID 60810 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellLib_DUIControls_CandidateList_ResumeFill

Event ID 60811 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellLib_DUIControls_CandidateList_ForcedPageBreak

Fields #

NameDescription
Index Int32

Event ID 60812 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellLib_DUIControls_CandidateList_RealizePage
Opcode
Start

Fields #

NameDescription
PageCount Int32
CandidateCount Int32

Event ID 60813 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellLib_DUIControls_CandidateList_RealizePage
Opcode
Stop

Fields #

NameDescription
PageCount Int32
CandidateCount Int32

Event ID 60814 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellLib_DUIControls_CandidateList_PageLayout
Opcode
Start

Fields #

NameDescription
Index Int32

Event ID 60815 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellLib_DUIControls_CandidateList_PageLayout
Opcode
Stop

Fields #

NameDescription
Index Int32

Event ID 60816 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellLib_DUIControls_CandidateList_RealizationComplete

Fields #

NameDescription
PageCount Int32
CandidateCount Int32

Event ID 60817 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellLib_DUIControls_CandidateList_RedoPaging

Event ID 60818 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellLib_DUIControls_CandidateList_PagingComplete

Fields #

NameDescription
PageCount Int32
CandidateCount Int32

Event ID 60819 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellLib_DUIControls_CandidateList_ButtonPressed

Fields #

NameDescription
ButtonType Int32

Event ID 60820 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellLib_DUIControls_CandidateList_ButtonReleased

Fields #

NameDescription
ButtonType Int32

Event ID 60821 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellLib_DUIControls_CandidateList_PagingAnimation
Opcode
Start

Event ID 60822 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellLib_DUIControls_CandidateList_PagingAnimation
Opcode
Stop

Event ID 60823 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellLib_DUIControls_CandidateList_TouchPan
Opcode
Start

Event ID 60824 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellLib_DUIControls_CandidateList_TouchPan
Opcode
Stop

Event ID 60825 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellLib_DUIControls_CandidateList_ViewRender
Opcode
Start

Fields #

NameDescription
PageIndex Int32
Type UInt32

Event ID 60826 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellLib_DUIControls_CandidateList_ViewRender
Opcode
Stop

Fields #

NameDescription
PageIndex Int32
HRESULT UInt32

Event ID 60901 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_ExecAssoc_ReputationCheck
Opcode
Start

Fields #

NameDescription
psz UnicodeString

Event ID 60902 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_ExecAssoc_ReputationCheck
Opcode
Stop

Fields #

NameDescription
psz UnicodeString

Event ID 60903 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_ExecAssoc_ReputationTelemetry
Opcode
Start

Fields #

NameDescription
psz UnicodeString

Event ID 60904 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_ExecAssoc_ReputationTelemetry
Opcode
Stop

Fields #

NameDescription
psz UnicodeString

Event ID 60905 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_ExecAssoc_ScrubZoneIdentifier
Opcode
Start

Fields #

NameDescription
psz UnicodeString

Event ID 60906 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_ExecAssoc_ScrubZoneIdentifier
Opcode
Stop

Fields #

NameDescription
psz UnicodeString

Event ID 60907 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
ShellTask_ExecAssoc_ZoneCheckFile
Opcode
Stop

Fields #

NameDescription
psz UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "60907",
    "version": "0",
    "level": "4",
    "task": "60907",
    "opcode": "2",
    "keywords": 9223372036854841344,
    "time_created": "2026-03-16T00:23:22.271226300+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "1452",
      "thread_id": "9352"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "psz": "C:\\Windows\\system32\\notepad.exe"
  },
  "message": ""
}

Event ID 60908 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
ShellTask_ExecAssoc_ZoneCheckFile
Opcode
Stop

Fields #

NameDescription
psz UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "60908",
    "version": "0",
    "level": "4",
    "task": "60907",
    "opcode": "2",
    "keywords": 9223372036854841344,
    "time_created": "2026-03-16T00:23:22.273243300+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "1452",
      "thread_id": "9352"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "psz": "C:\\Windows\\system32\\notepad.exe"
  },
  "message": ""
}

Event ID 60909 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_ExecAssoc_ZoneCheckFile
Opcode
Stop

Fields #

NameDescription
psz UnicodeString

Event ID 60910 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_ExecAssoc_ZoneCheckFile
Opcode
Stop

Fields #

NameDescription
psz UnicodeString

Event ID 60911 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
ShellTask_ExecAssoc_ZoneCheckFile
Opcode
Stop

Fields #

NameDescription
psz UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "60911",
    "version": "0",
    "level": "4",
    "task": "60907",
    "opcode": "2",
    "keywords": 9223372036854841344,
    "time_created": "2026-03-16T00:23:22.273257900+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "1452",
      "thread_id": "9352"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "psz": "C:\\Windows\\system32\\notepad.exe"
  },
  "message": ""
}

Event ID 60912 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Opcode
Info

Fields #

NameDescription
Index UInt32

Event ID 60913 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Opcode
Stop

Event ID 60914 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_Download_SafeOpenPromptForShellExec

Fields #

NameDescription
HRESULT UInt32

Event ID 60915 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellTask_SmartScreen_CheckReputation

Fields #

NameDescription
EnumValue Int32

Event ID 61001 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_UnknownFileDialog_Create
Opcode
Start

Event ID 61002 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_UnknownFileDialog_Create
Opcode
Stop

Event ID 61003 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_DefaultAssociationsProfileHandler_OnCreate_OEM
Opcode
Start

Event ID 61004 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_DefaultAssociationsProfileHandler_OnCreate_OEM
Opcode
Stop

Fields #

NameDescription
HRESULT Int32

Event ID 61005 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_DefaultAssociationsProfileHandler_OnLoad_GroupPolicy
Opcode
Start

Event ID 61006 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_DefaultAssociationsProfileHandler_OnLoad_GroupPolicy
Opcode
Stop

Fields #

NameDescription
HRESULT Int32

Event ID 61201 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_SyncIntegration_Manager_Initialize
Opcode
Start

Event ID 61202 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_SyncIntegration_Manager_Initialize
Opcode
Stop

Event ID 61203 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_SyncIntegration_Manager_Initialize

Event ID 61204 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_SyncIntegration_Manager_Initialize

Fields #

NameDescription
CLSID GUID
Name UnicodeString
Description UnicodeString
AppliesTo UnicodeString
State UInt32

Event ID 61205 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_SyncIntegration_Manager_Initialize

Fields #

NameDescription
CLSID GUID
HRESULT UInt32

Event ID 61206 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_SyncIntegration_Manager_Initialize

Event ID 61210 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_SyncIntegration_Manager_Notifications

Fields #

NameDescription
CLSID GUID
State UInt32

Event ID 61211 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_SyncIntegration_Manager_Notifications

Fields #

NameDescription
CLSID GUID
ItemPath UnicodeString
ScopeAffetcedItems UInt32
ItemSyncState UInt32
ItemSyncStatus UnicodeString
ItemSyncStatusDescription UnicodeString
ItemSyncStatusAction UnicodeString

Event ID 61212 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_SyncIntegration_Manager_Notifications

Fields #

NameDescription
ItemPath UnicodeString
HRESULT UInt32

Event ID 61213 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_SyncIntegration_Manager_Notifications

Fields #

NameDescription
ItemPath UnicodeString
HRESULT UInt32

Event ID 61214 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_SyncIntegration_Manager_Notifications

Fields #

NameDescription
psz UnicodeString

Event ID 61220 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_SyncIntegration_Manager_GetStatus

Fields #

NameDescription
CLSID GUID
State UInt32

Event ID 61221 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_SyncIntegration_Manager_GetStatus

Fields #

NameDescription
CLSID GUID
ItemPath UnicodeString

Event ID 61301 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_DiscImage_MountVerb_SQMStream

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmStreamRowLength UInt32
SqmStreamRow Int16

Event ID 61302 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_DiscImage_MountVerb
Opcode
Start

Event ID 61303 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_DiscImage_MountVerb
Opcode
Stop

Event ID 61320 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_LibraryManagementDialog_CreateIcon
Opcode
Start

Event ID 61321 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_LibraryManagementDialog_CreateIcon
Opcode
Stop

Event ID 61322 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_LibraryManagementDialog_SaveChanges
Opcode
Start

Event ID 61323 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_LibraryManagementDialog_SaveChanges
Opcode
Stop

Event ID 61324 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_LibraryGroupPolicy_EnforceInSSO
Opcode
Start

Event ID 61325 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_LibraryGroupPolicy_EnforceInSSO
Opcode
Stop

Event ID 61326 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_LibraryGroupPolicy_CreateKnownFolder
Opcode
Start

Event ID 61327 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_LibraryGroupPolicy_CreateKnownFolder
Opcode
Stop

Event ID 61340 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
OperationManager_TileAdded

Fields #

NameDescription
TileID UInt32
TileCount UInt32

Event ID 61341 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
OperationManager_TileRemoved

Fields #

NameDescription
TileID UInt32
TileCount UInt32

Event ID 61342 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
OperationManager_TileStateChanged

Fields #

NameDescription
OldState UInt32
NewState UInt32

Event ID 61343 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
OperationManager_TileCancelled

Event ID 61344 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
OperationManager_ServiceModeChange

Fields #

NameDescription
IsEnthusiastMode Boolean

Event ID 61345 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
OperationManager_EnthusiastMode_TileRateChartProgressStart

Fields #

NameDescription
TileID UInt32

Event ID 61346 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
OperationManager_EnthusiastMode_TileRateChartRescale

Fields #

NameDescription
TileID UInt32

Event ID 61347 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
OperationManager_EnthusiastMode_TileRateChartUpdate

Fields #

NameDescription
TileID UInt32

Event ID 61348 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
OperationManager_ConfirmationCreated

Fields #

NameDescription
TileID UInt32

Event ID 61349 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
OperationManager_ConfirmationFinished

Fields #

NameDescription
TileID UInt32

Event ID 61350 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
OperationManager_ConflictCreated

Fields #

NameDescription
TileID UInt32

Event ID 61351 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
OperationManager_ConflictFinished

Fields #

NameDescription
TileID UInt32

Event ID 61352 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
OperationManager_Discovering

Fields #

NameDescription
OldState UInt32
NewState UInt32

Event ID 61353 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
OperationManager_Paused

Fields #

NameDescription
OldState UInt32
NewState UInt32

Event ID 61354 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
OperationManager_Executing

Fields #

NameDescription
OldState UInt32
NewState UInt32

Event ID 61355 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
OperationManager_Cancelled

Fields #

NameDescription
OldState UInt32
NewState UInt32

Event ID 61356 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
OperationManager_Interrupted

Fields #

NameDescription
OldState UInt32
NewState UInt32

Event ID 61357 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
OperationManager_Pausing

Fields #

NameDescription
OldState UInt32
NewState UInt32

Event ID 61358 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
OperationManager_Resuming

Fields #

NameDescription
OldState UInt32
NewState UInt32

Event ID 61360 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
FileAccessAPI_Enumeration
Opcode
Start

Fields #

NameDescription
TopViewId GUID
NumExtensionFilters UInt32
AppQuery UnicodeString
UserQuery UnicodeString
FolderDepth UInt32
IndexerOption UInt32
NumSortEntries UInt32

Event ID 61361 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
FileAccessAPI_Enumeration
Opcode
Stop

Fields #

NameDescription
HRESULT UInt32

Event ID 61364 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
FileAccessAPI_Enumeration_GetView
Opcode
Start

Fields #

NameDescription
StartIndex UInt32
Count UInt32

Event ID 61365 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
FileAccessAPI_Enumeration_GetView
Opcode
Stop

Fields #

NameDescription
HRESULT UInt32

Event ID 61366 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
FileAccessAPI_Enumeration_GetAt
Opcode
Start

Event ID 61367 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
FileAccessAPI_Enumeration_GetAt
Opcode
Stop

Fields #

NameDescription
HRESULT UInt32

Event ID 61368 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
FileAccessAPI_Enumeration_GetCount
Opcode
Start

Event ID 61369 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
FileAccessAPI_Enumeration_GetCount
Opcode
Stop

Fields #

NameDescription
Count UInt32
HRESULT UInt32

Event ID 61370 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
FileAccessAPI_StreamAccess_GetStream
Opcode
Start

Event ID 61371 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
FileAccessAPI_StreamAccess_GetStream
Opcode
Stop

Fields #

NameDescription
HRESULT UInt32

Event ID 61372 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
FileAccessAPI_StreamAccess_Read
Opcode
Start

Fields #

NameDescription
CountBytesRequested UInt32

Event ID 61373 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
FileAccessAPI_StreamAccess_Read
Opcode
Stop

Fields #

NameDescription
HRESULT UInt32

Event ID 61374 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
FileAccessAPI_StreamAccess_Write
Opcode
Start

Fields #

NameDescription
CountBytesRequested UInt32

Event ID 61375 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
FileAccessAPI_StreamAccess_Write
Opcode
Stop

Fields #

NameDescription
HRESULT UInt32

Event ID 61376 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
FileAccessAPI_StreamAccess_Commit
Opcode
Start

Event ID 61377 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
FileAccessAPI_StreamAccess_Commit
Opcode
Stop

Fields #

NameDescription
HRESULT UInt32

Event ID 61380 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
FileAccessAPI_PropertyAccess_GetProperties
Opcode
Start

Event ID 61381 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
FileAccessAPI_PropertyAccess_GetProperties
Opcode
Stop

Fields #

NameDescription
HRESULT UInt32

Event ID 61386 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
FileAccessAPI_PropertyAccess_Commit
Opcode
Start

Event ID 61387 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
FileAccessAPI_PropertyAccess_Commit
Opcode
Stop

Fields #

NameDescription
HRESULT UInt32

Event ID 61390 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
FileAccessAPI_GetKnownItem
Opcode
Start

Event ID 61391 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
FileAccessAPI_GetKnownItem
Opcode
Stop

Fields #

NameDescription
KnownItemRequested GUID
HRESULT UInt32

Event ID 61400 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
FileAccessAPI_GetThumbnail
Opcode
Start

Fields #

NameDescription
RequestedSize UInt32
Options UInt32

Event ID 61401 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
FileAccessAPI_GetThumbnail
Opcode
Stop

Fields #

NameDescription
HRESULT UInt32

Event ID 61410 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
FileAccessAPI_Create
Opcode
Start

Event ID 61411 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
FileAccessAPI_Create
Opcode
Stop

Fields #

NameDescription
HRESULT UInt32

Event ID 61412 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
FileAccessAPI_Delete
Opcode
Start

Event ID 61413 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
FileAccessAPI_Delete
Opcode
Stop

Fields #

NameDescription
HRESULT UInt32

Event ID 61414 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
FileAccessAPI_Rename
Opcode
Start

Event ID 61415 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
FileAccessAPI_Rename
Opcode
Stop

Fields #

NameDescription
HRESULT UInt32

Event ID 61420 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
FileAccessAPI_AddPersistedItem
Opcode
Start

Event ID 61421 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
FileAccessAPI_AddPersistedItem
Opcode
Stop

Fields #

NameDescription
Token UnicodeString
LifetimeOption UInt32
HRESULT UInt32

Event ID 61422 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
FileAccessAPI_AddReplacePersistedItem
Opcode
Start

Event ID 61423 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
FileAccessAPI_AddReplacePersistedItem
Opcode
Stop

Fields #

NameDescription
Token UnicodeString
LifetimeOption UInt32
HRESULT UInt32

Event ID 61424 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
FileAccessAPI_RemovePersistedItem
Opcode
Start

Event ID 61425 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
FileAccessAPI_RemovePersistedItem
Opcode
Stop

Fields #

NameDescription
Token UnicodeString
LifetimeOption UInt32
HRESULT UInt32

Event ID 61426 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
FileAccessAPI_ClearAllPersistedItems
Opcode
Start

Event ID 61427 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
FileAccessAPI_ClearAllPersistedItems
Opcode
Stop

Fields #

NameDescription
HRESULT UInt32

Event ID 61428 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
FileAccessAPI_GetPersistedItem
Opcode
Start

Fields #

NameDescription
Token UnicodeString
LifetimeOption UInt32

Event ID 61429 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
FileAccessAPI_GetPersistedItem
Opcode
Stop

Fields #

NameDescription
HRESULT UInt32

Event ID 61430 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
FileAccessAPI_EnumeratePersistedItemTokens
Opcode
Start

Event ID 61431 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
FileAccessAPI_EnumeratePersistedItemTokens
Opcode
Stop

Fields #

NameDescription
Count UInt32
LifetimeOption UInt32
HRESULT UInt32

Event ID 61432 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
FileAccessAPI_GetItemFromPath
Opcode
Start

Event ID 61433 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
FileAccessAPI_GetItemFromPath
Opcode
Stop

Fields #

NameDescription
HRESULT UInt32

Event ID 61434 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
FileAccessAPI_GetMusicProperties
Opcode
Start

Event ID 61435 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
FileAccessAPI_GetMusicProperties
Opcode
Stop

Fields #

NameDescription
HRESULT UInt32

Event ID 61436 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
FileAccessAPI_GetVideoProperties
Opcode
Start

Event ID 61437 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
FileAccessAPI_GetVideoProperties
Opcode
Stop

Fields #

NameDescription
HRESULT UInt32

Event ID 61438 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
FileAccessAPI_GetImageProperties
Opcode
Start

Event ID 61439 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
FileAccessAPI_GetImageProperties
Opcode
Stop

Fields #

NameDescription
HRESULT UInt32

Event ID 61440 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
FileAccessAPI_GetDocumentProperties
Opcode
Start

Event ID 61441 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
FileAccessAPI_GetDocumentProperties
Opcode
Stop

Fields #

NameDescription
HRESULT UInt32

Event ID 61442 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
FileAccessAPI_StreamedFile_DataRequest
Opcode
Start

Event ID 61443 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
FileAccessAPI_StreamedFile_DataRequest
Opcode
Stop

Fields #

NameDescription
HRESULT UInt32

Event ID 61444 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
FileAccessAPI_StreamedFile_WriteStream
Opcode
Start

Event ID 61445 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
FileAccessAPI_StreamedFile_WriteStream
Opcode
Stop

Event ID 61446 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
FileAccessAPI_StreamedFile_Abandoned

Event ID 61448 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
FileAccessAPI_Copy
Opcode
Start

Event ID 61449 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
FileAccessAPI_Copy
Opcode
Stop

Fields #

NameDescription
HRESULT UInt32

Event ID 61450 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
FileAccessAPI_Move
Opcode
Start

Event ID 61451 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
FileAccessAPI_Move
Opcode
Stop

Fields #

NameDescription
HRESULT UInt32

Event ID 61452 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
FileAccessAPI_GetBasicProperties
Opcode
Start

Event ID 61453 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
FileAccessAPI_GetBasicProperties
Opcode
Stop

Fields #

NameDescription
HRESULT UInt32

Event ID 61454 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
FileAccessAPI_ValidatePath
Opcode
Start

Fields #

NameDescription
Path UnicodeString

Event ID 61455 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
FileAccessAPI_ValidatePath
Opcode
Stop

Fields #

NameDescription
HRESULT UInt32
HasAccess Boolean

Event ID 61456 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
FileAccessAPI_CacheFlush

Fields #

NameDescription
Count UInt32

Event ID 61457 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DataLayerCacheFlush

Fields #

NameDescription
SqmSessionGuid GUID
SqmID UInt32
SqmType UInt32
SqmStreamRowLength UInt32
SqmStreamRow Int16

Event ID 61460 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellOplocks_NotGranted

Fields #

NameDescription
Signature UInt64
szFilename UnicodeString

Event ID 61461 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellOplocks_Broken

Event ID 61462 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellOplocks_BrokenAndWaiting
Opcode
Start

Fields #

NameDescription
Signature UInt64
szFilename UnicodeString

Event ID 61463 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellOplocks_BrokenAndWaiting
Opcode
Stop

Fields #

NameDescription
Signature UInt64
szFilename UnicodeString

Event ID 61464 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellOplocks_Acknowledged
Opcode
Start

Fields #

NameDescription
Signature UInt64
szFilename UnicodeString

Event ID 61465 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ShellOplocks_Acknowledged
Opcode
Stop

Fields #

NameDescription
Signature UInt64
szFilename UnicodeString

Event ID 61501 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
SetUserDefaults_ProgramListPopulated
Opcode
Start

Event ID 61502 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
SetUserDefaults_ProgramListPopulated
Opcode
Stop

Event ID 61503 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
SetUserDefaults_ProgramAssociationsPopulated
Opcode
Start

Event ID 61504 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
SetUserDefaults_ProgramAssociationsPopulated
Opcode
Stop

Event ID 61505 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
SetUserDefaults_DefaultSet
Opcode
Start

Event ID 61506 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
SetUserDefaults_DefaultSet
Opcode
Stop

Event ID 61600 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DataPackage_GetProperties
Opcode
Start

Event ID 61601 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DataPackage_GetProperties
Opcode
Stop

Event ID 61602 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DataPackage_GetAvailableFormats
Opcode
Start

Event ID 61603 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DataPackage_GetAvailableFormats
Opcode
Stop

Event ID 61604 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DataPackage_Contains
Opcode
Start

Event ID 61605 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DataPackage_Contains
Opcode
Stop

Event ID 61606 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DataPackage_GetDataAsync
Opcode
Start

Event ID 61607 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DataPackage_GetDataAsync
Opcode
Stop

Event ID 61608 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DataPackage_GetResourceMapAsync
Opcode
Start

Event ID 61609 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DataPackage_GetResourceMapAsync
Opcode
Stop

Event ID 61610 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DataPackage_SetData
Opcode
Start

Event ID 61611 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DataPackage_SetData
Opcode
Stop

Event ID 61612 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DataPackage_InvokeDataProviderHandler
Opcode
Start

Event ID 61613 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DataPackage_InvokeDataProviderHandler
Opcode
Stop

Event ID 61614 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DataPackage_GetText
Opcode
Start

Event ID 61615 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DataPackage_GetText
Opcode
Stop

Event ID 61616 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DataPackage_SetText
Opcode
Start

Event ID 61617 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DataPackage_SetText
Opcode
Stop

Event ID 61618 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DataPackage_GetCustomText
Opcode
Start

Fields #

NameDescription
FormatId UnicodeString

Event ID 61619 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DataPackage_GetCustomText
Opcode
Stop

Fields #

NameDescription
FormatId UnicodeString

Event ID 61620 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DataPackage_SetCustomText
Opcode
Start

Fields #

NameDescription
FormatId UnicodeString

Event ID 61621 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DataPackage_SetCustomText
Opcode
Stop

Fields #

NameDescription
FormatId UnicodeString

Event ID 61622 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DataPackage_GetHtml
Opcode
Start

Event ID 61623 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DataPackage_GetHtml
Opcode
Stop

Event ID 61624 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DataPackage_SetHtml
Opcode
Start

Event ID 61625 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DataPackage_SetHtml
Opcode
Stop

Event ID 61626 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DataPackage_GetUri
Opcode
Start

Event ID 61627 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DataPackage_GetUri
Opcode
Stop

Event ID 61628 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DataPackage_SetUri
Opcode
Start

Event ID 61629 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DataPackage_SetUri
Opcode
Stop

Event ID 61630 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DataPackage_GetRtf
Opcode
Start

Event ID 61631 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DataPackage_GetRtf
Opcode
Stop

Event ID 61632 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DataPackage_SetRtf
Opcode
Start

Event ID 61633 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DataPackage_SetRtf
Opcode
Stop

Event ID 61634 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DataPackage_GetBitmap
Opcode
Start

Event ID 61635 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DataPackage_GetBitmap
Opcode
Stop

Event ID 61636 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DataPackage_SetBitmap
Opcode
Start

Event ID 61637 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DataPackage_SetBitmap
Opcode
Stop

Event ID 61638 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DataPackage_GetStorageItemsAsync
Opcode
Start

Event ID 61639 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DataPackage_GetStorageItemsAsync
Opcode
Stop

Event ID 61640 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
HtmlFormatHelper_GetStaticFragment
Opcode
Start

Event ID 61641 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
HtmlFormatHelper_GetStaticFragment
Opcode
Stop

Fields #

NameDescription
HRESULT Int32

Event ID 61642 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DataPackage_SetStorageItems
Opcode
Start

Event ID 61643 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DataPackage_SetStorageItems
Opcode
Stop

Event ID 61644 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DataObjectProvider_GetDataObject
Opcode
Start

Event ID 61645 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DataObjectProvider_GetDataObject
Opcode
Stop

Event ID 61646 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DataObjectProvider_SetDataObject
Opcode
Start

Event ID 61647 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DataObjectProvider_SetDataObject
Opcode
Stop

Event ID 61648 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
HtmlFormatHelper_CreateHtmlFormat
Opcode
Start

Event ID 61649 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
HtmlFormatHelper_CreateHtmlFormat
Opcode
Stop

Fields #

NameDescription
HRESULT Int32

Event ID 61650 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Clipboard_GetContent
Opcode
Start

Event ID 61651 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Clipboard_GetContent
Opcode
Stop

Event ID 61652 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Clipboard_SetContent
Opcode
Start

Event ID 61653 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Clipboard_SetContent
Opcode
Stop

Event ID 62000 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PlaylistFolder_DataSource_Created

Event ID 62001 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PlaylistFolder_DataSource_ItemEnumeration
Opcode
Start

Event ID 62002 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PlaylistFolder_DataSource_ItemEnumeration
Opcode
Stop

Event ID 62003 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PlaylistFolder_DataSource_DocumentParse
Opcode
Start

Event ID 62004 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PlaylistFolder_DataSource_DocumentParse
Opcode
Stop

Event ID 62020 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PlaylistFolder_Document_Load
Opcode
Start

Fields #

NameDescription
psi Pointer
grfMode UInt32

Event ID 62021 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PlaylistFolder_Document_Load
Opcode
Stop

Fields #

NameDescription
HRESULT UInt32

Event ID 62022 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PlaylistFolder_Document_GetItem
Opcode
Start

Fields #

NameDescription
Index UInt32

Event ID 62023 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PlaylistFolder_Document_GetItem
Opcode
Stop

Fields #

NameDescription
HRESULT UInt32

Event ID 62024 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PlaylistFolder_Document_Insert
Opcode
Start

Fields #

NameDescription
Index UInt32

Event ID 62025 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PlaylistFolder_Document_Insert
Opcode
Stop

Fields #

NameDescription
HRESULT UInt32

Event ID 62026 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PlaylistFolder_Document_Remove
Opcode
Start

Fields #

NameDescription
Index UInt32

Event ID 62027 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PlaylistFolder_Document_Remove
Opcode
Stop

Fields #

NameDescription
HRESULT UInt32

Event ID 62028 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PlaylistFolder_Document_Move
Opcode
Start

Fields #

NameDescription
IndexFrom UInt32
IndexTo UInt32

Event ID 62029 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PlaylistFolder_Document_Move
Opcode
Stop

Fields #

NameDescription
HRESULT UInt32

Event ID 62030 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PlaylistFolder_Document_Commit
Opcode
Start

Event ID 62031 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PlaylistFolder_Document_Commit
Opcode
Stop

Fields #

NameDescription
HRESULT UInt32

Event ID 62032 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PlaylistFolder_Document_Save
Opcode
Start

Fields #

NameDescription
psiFolder Pointer
szPlaylistName UnicodeString
flags UInt32

Event ID 62033 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
PlaylistFolder_Document_Save
Opcode
Stop

Fields #

NameDescription
HRESULT UInt32

Event ID 62050 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_MountPoint_VolumeAddedOrUpdated
Opcode
Start

Event ID 62051 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_MountPoint_VolumeAddedOrUpdated
Opcode
Stop

Event ID 62052 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_MountPoint_VolumeRemoved
Opcode
Start

Event ID 62053 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_MountPoint_VolumeRemoved
Opcode
Stop

Event ID 62054 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_MountPoint_CreateEventForVolumeArrival
Opcode
Start

Event ID 62055 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_MountPoint_CreateEventForVolumeArrival
Opcode
Stop

Event ID 62056 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_MountPoint_GetAndRemoveVolumeAndItsMtPts
Opcode
Start

Event ID 62057 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_MountPoint_GetAndRemoveVolumeAndItsMtPts
Opcode
Stop

Event ID 62058 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_MountPoint_UpdateVolumeRegInfo
Opcode
Start

Event ID 62059 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_MountPoint_UpdateVolumeRegInfo
Opcode
Stop

Event ID 62060 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_MountPoint_CreateVolumeObject
Opcode
Start

Event ID 62061 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_MountPoint_CreateVolumeObject
Opcode
Stop

Event ID 62062 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_MountPoint_GetLabel
Opcode
Start

Event ID 62063 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_MountPoint_GetLabel
Opcode
Stop

Event ID 62064 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_MountPoint_MountPointAdded
Opcode
Start

Event ID 62065 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_MountPoint_MountPointAdded
Opcode
Stop

Event ID 62066 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
Shell32_MountPoint_CreateMtPtLocalWithVolume
Opcode
Start

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "62066",
    "version": "0",
    "level": "4",
    "task": "62066",
    "opcode": "1",
    "keywords": 9223372036854841344,
    "time_created": "2026-03-16T00:21:39.181172000+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "5680",
      "thread_id": "11856"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 62067 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
Shell32_MountPoint_CreateMtPtLocalWithVolume
Opcode
Stop

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "62067",
    "version": "0",
    "level": "4",
    "task": "62066",
    "opcode": "2",
    "keywords": 9223372036854841344,
    "time_created": "2026-03-16T00:21:39.181195800+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "5680",
      "thread_id": "11856"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 62068 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_MountPoint_OnMountPointArrival
Opcode
Start

Event ID 62069 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_MountPoint_OnMountPointArrival
Opcode
Stop

Event ID 62070 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
Shell32_MountPoint_GetMountPoint
Opcode
Start

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "62070",
    "version": "0",
    "level": "4",
    "task": "62070",
    "opcode": "1",
    "keywords": 9223372036854841344,
    "time_created": "2026-03-15T04:20:50.066796100+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "12840",
      "thread_id": "800"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 62071 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Level
Informational
Task
Shell32_MountPoint_GetMountPoint
Opcode
Stop

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "{30336ed4-e327-447c-9de0-51b652c86108}",
    "event_source_name": "",
    "event_id": "62071",
    "version": "0",
    "level": "4",
    "task": "62070",
    "opcode": "2",
    "keywords": 9223372036854841344,
    "time_created": "2026-03-15T04:20:50.066799200+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00000000-0000-0000-0000-000000000000}"
    },
    "execution": {
      "process_id": "12840",
      "thread_id": "800"
    },
    "channel": "Microsoft-Windows-Shell-Core/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 62072 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
OperationManager_TileAnimation_Started

Fields #

NameDescription
TileAutomationID UInt32
TransitionType UInt32

Event ID 62073 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
OperationManager_TileAnimation_Frame_Updated

Fields #

NameDescription
TileAutomationID UInt32
TransitionType UInt32

Event ID 62074 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
OperationManager_TileAnimation_Terminated

Fields #

NameDescription
TileAutomationID UInt32
TransitionType UInt32
AnimationStatus UInt32

Event ID 62075 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
OperationManager_TileAnimation_Frame_Skipped

Fields #

NameDescription
Delta UInt32

Event ID 62076 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Explorer_Roaming_WaitAtLogon

Fields #

NameDescription
UInt32Value UInt32

Event ID 62078 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_MountPoint_SendQueryCancelAutoPlayMessage
Opcode
Start

Event ID 62079 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell32_MountPoint_SendQueryCancelAutoPlayMessage
Opcode
Stop

Event ID 62100 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Shell_Scaling_Cache_Updated

Fields #

NameDescription
Device UInt32
GotRealDevice UInt32
VerticalResolution UInt32
HorizontalResolution UInt32
VerticalSize UInt32
HorizontalSize UInt32
ComputedScaleFactor UInt32
ComputedDPI UInt32
ChangedFlags UInt32

Event ID 62120 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
TileManagement_PackageInfo_LoadFromManifest
Opcode
Start

Fields #

NameDescription
PackageFamilyName UnicodeString

Event ID 62121 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
TileManagement_PackageInfo_LoadFromManifest
Opcode
Stop

Fields #

NameDescription
HRESULT UInt32

Event ID 62122 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
TileManagement_PackageInfo_LoadFromDisk
Opcode
Start

Fields #

NameDescription
PackageFamilyName UnicodeString

Event ID 62123 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
TileManagement_PackageInfo_LoadFromDisk
Opcode
Stop

Fields #

NameDescription
HRESULT UInt32

Event ID 62124 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
TileManagement_PackageInfo_VerifyInformation
Opcode
Start

Fields #

NameDescription
PackageFamilyName UnicodeString

Event ID 62125 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
TileManagement_PackageInfo_VerifyInformation
Opcode
Stop

Fields #

NameDescription
HRESULT UInt32

Event ID 62126 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
TileManagement_PackageInfo_Revert
Opcode
Start

Fields #

NameDescription
PackageFamilyName UnicodeString

Event ID 62127 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
TileManagement_PackageInfo_Revert
Opcode
Stop

Fields #

NameDescription
HRESULT UInt32

Event ID 62128 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
TileManagement_PackageInfo_Commit
Opcode
Start

Fields #

NameDescription
PackageFamilyName UnicodeString

Event ID 62129 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
TileManagement_PackageInfo_Commit
Opcode
Stop

Fields #

NameDescription
HRESULT UInt32

Event ID 62130 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
TileManagement_PackageInfo_Commit_InstallTile
Opcode
Start

Fields #

NameDescription
PackageFamilyName UnicodeString

Event ID 62131 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
TileManagement_PackageInfo_Commit_InstallTile
Opcode
Stop

Fields #

NameDescription
HRESULT UInt32

Event ID 62132 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
TileManagement_AppTileInfo_InitContentTileRoaming
Opcode
Start

Fields #

NameDescription
ParentShortcutPath UnicodeString

Event ID 62133 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
TileManagement_AppTileInfo_InitContentTileRoaming
Opcode
Stop

Fields #

NameDescription
HRESULT UInt32

Event ID 62134 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
TileManagement_AppTileInfo_VerifyInformation
Opcode
Start

Fields #

NameDescription
AppUserModelID UnicodeString

Event ID 62135 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
TileManagement_AppTileInfo_VerifyInformation
Opcode
Stop

Fields #

NameDescription
HRESULT UInt32

Event ID 62136 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
TileManagement_AppTileInfo_Revert
Opcode
Start

Fields #

NameDescription
AppUserModelID UnicodeString

Event ID 62137 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
TileManagement_AppTileInfo_Revert
Opcode
Stop

Fields #

NameDescription
HRESULT UInt32

Event ID 62138 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
TileManagement_AppTileInfo_Commit
Opcode
Start

Fields #

NameDescription
AppUserModelID UnicodeString

Event ID 62139 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
TileManagement_AppTileInfo_Commit
Opcode
Stop

Fields #

NameDescription
HRESULT UInt32

Event ID 62140 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
TileManagement_AppTileInfo_PopulateShortcut
Opcode
Start

Fields #

NameDescription
AppUserModelID UnicodeString

Event ID 62141 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
TileManagement_AppTileInfo_PopulateShortcut
Opcode
Stop

Fields #

NameDescription
HRESULT UInt32

Event ID 62142 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
TileManagement_AppTileInfo_CommitShortcut
Opcode
Start

Fields #

NameDescription
AppUserModelID UnicodeString

Event ID 62143 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
TileManagement_AppTileInfo_CommitShortcut
Opcode
Stop

Fields #

NameDescription
HRESULT UInt32

Event ID 62144 — Updating install state of package PackageFamilyName to 'InstallState' with HRESULT ErrorCode.

#
Provider
Microsoft-Windows-Shell-Core
Channel
Operational
Level
Informational
Task
TileManagement_PackageInfo_InstallStateChange

Description

Updating install state of package PackageFamilyName to 'InstallState' with HRESULT ErrorCode.

Message #

Updating install state of package %1 to '%2' with HRESULT %3.

Fields #

NameDescription
PackageFamilyName UnicodeString
InstallState UnicodeString
ErrorCode UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "30336ED4-E327-447C-9DE0-51B652C86108",
    "event_source_name": "",
    "event_id": 62144,
    "version": 0,
    "level": 4,
    "task": 62132,
    "opcode": 0,
    "keywords": 2305843009213759488,
    "time_created": "2023-11-05T23:49:15.852979+00:00",
    "event_record_id": 2545,
    "correlation": {},
    "execution": {
      "process_id": 10560,
      "thread_id": 5420
    },
    "channel": "Microsoft-Windows-Shell-Core/Operational",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-21-1992711665-1655669231-58201500-1000"
    }
  },
  "event_data": {
    "PackageFamilyName": "DropboxInc.Dropbox_wkt425jdc3sga",
    "InstallState": "Completed",
    "ErrorCode": 0
  },
  "message": ""
}

References #

Event ID 62145 — On commit, creation of shortcut with AppUserModelId AppUserModelID with HRESULT ErrorCode.

Provider
Microsoft-Windows-Shell-Core
Channel
Operational
Task
TileManagement_AppTileInfo_Commit_Create

Description

On commit, creation of shortcut with AppUserModelId AppUserModelID with HRESULT ErrorCode.

Message #

On commit, creation of shortcut with AppUserModelId %1 with HRESULT %2.

Fields #

NameDescription
AppUserModelID UnicodeString
ErrorCode UInt32

Event ID 62146 — On commit, update of shortcut with AppUserModelId AppUserModelID with HRESULT ErrorCode.

Provider
Microsoft-Windows-Shell-Core
Channel
Operational
Task
TileManagement_AppTileInfo_Commit_Update

Description

On commit, update of shortcut with AppUserModelId AppUserModelID with HRESULT ErrorCode.

Message #

On commit, update of shortcut with AppUserModelId %1 with HRESULT %2.

Fields #

NameDescription
AppUserModelID UnicodeString
ErrorCode UInt32

Event ID 62147 — On commit, deletion of shortcut with AppUserModelId AppUserModelID with HRESULT ErrorCode.

Provider
Microsoft-Windows-Shell-Core
Channel
Operational
Task
TileManagement_AppTileInfo_Commit_Delete

Description

On commit, deletion of shortcut with AppUserModelId AppUserModelID with HRESULT ErrorCode.

Message #

On commit, deletion of shortcut with AppUserModelId %1 with HRESULT %2.

Fields #

NameDescription
AppUserModelID UnicodeString
ErrorCode UInt32

Event ID 62148 — On commit, creation of temporary shortcut with AppUserModelId AppUserModelID with HRESULT ErrorCode.

Provider
Microsoft-Windows-Shell-Core
Channel
Operational
Task
TileManagement_AppTileInfo_Commit_Temporary

Description

On commit, creation of temporary shortcut with AppUserModelId AppUserModelID with HRESULT ErrorCode.

Message #

On commit, creation of temporary shortcut with AppUserModelId %1 with HRESULT %2.

Fields #

NameDescription
AppUserModelID UnicodeString
ErrorCode UInt32

Event ID 62149 — On commit, changing property values in shortcut with AppUserModelId AppUserModelID failed as the shortcut file does not exist.

Provider
Microsoft-Windows-Shell-Core
Channel
Operational
Task
TileManagement_AppTileInfo_Commit_ChangePropValue

Description

On commit, changing property values in shortcut with AppUserModelId AppUserModelID failed as the shortcut file does not exist.

Message #

On commit, changing property values in shortcut with AppUserModelId %1 failed as the shortcut file does not exist.

Fields #

NameDescription
AppUserModelID UnicodeString

Event ID 62150 — On revert, creation of shortcut with AppUserModelId AppUserModelID with HRESULT ErrorCode.

Provider
Microsoft-Windows-Shell-Core
Channel
Operational
Task
TileManagement_AppTileInfo_Revert_Create

Description

On revert, creation of shortcut with AppUserModelId AppUserModelID with HRESULT ErrorCode.

Message #

On revert, creation of shortcut with AppUserModelId %1 with HRESULT %2.

Fields #

NameDescription
AppUserModelID UnicodeString
ErrorCode UInt32

Event ID 62151 — On revert, update of shortcut with AppUserModelId AppUserModelID with HRESULT ErrorCode.

Provider
Microsoft-Windows-Shell-Core
Channel
Operational
Task
TileManagement_AppTileInfo_Revert_Update

Description

On revert, update of shortcut with AppUserModelId AppUserModelID with HRESULT ErrorCode.

Message #

On revert, update of shortcut with AppUserModelId %1 with HRESULT %2.

Fields #

NameDescription
AppUserModelID UnicodeString
ErrorCode UInt32

Event ID 62152 — On revert, deletion of shortcut with AppUserModelId AppUserModelID with HRESULT ErrorCode.

Provider
Microsoft-Windows-Shell-Core
Channel
Operational
Task
TileManagement_AppTileInfo_Revert_Delete

Description

On revert, deletion of shortcut with AppUserModelId AppUserModelID with HRESULT ErrorCode.

Message #

On revert, deletion of shortcut with AppUserModelId %1 with HRESULT %2.

Fields #

NameDescription
AppUserModelID UnicodeString
ErrorCode UInt32

Event ID 62153 — Removing folder for package PackageFamilyName with HRESULT ErrorCode.

Provider
Microsoft-Windows-Shell-Core
Channel
Operational
Task
TileManagement_PackageInfo_Remove_Folder

Description

Removing folder for package PackageFamilyName with HRESULT ErrorCode.

Message #

Removing folder for package %1 with HRESULT %2.

Fields #

NameDescription
PackageFamilyName UnicodeString
ErrorCode UInt32

Event ID 62154 — Incremented last write time of shortcut with AppUserModelId AppUserModelID by 2 seconds with HRESULT ErrorCode.

Provider
Microsoft-Windows-Shell-Core
Channel
Operational
Task
TileManagement_AppTileInfo_Increment_LastWriteTime

Description

Incremented last write time of shortcut with AppUserModelId AppUserModelID by 2 seconds with HRESULT ErrorCode.

Message #

Incremented last write time of shortcut with AppUserModelId %1 by 2 seconds with HRESULT %2.

Fields #

NameDescription
AppUserModelID UnicodeString
ErrorCode UInt32

Event ID 62155 — Updated lockscreen notifications badge registration of app with AppUserModelId AppUserModelID with HRESULT ErrorCode.

Provider
Microsoft-Windows-Shell-Core
Channel
Operational
Task
TileManagement_AppTileInfo_UpdateLSN_Badge

Description

Updated lockscreen notifications badge registration of app with AppUserModelId AppUserModelID with HRESULT ErrorCode.

Message #

Updated lockscreen notifications badge registration of app with AppUserModelId %1 with HRESULT %2.

Fields #

NameDescription
AppUserModelID UnicodeString
ErrorCode UInt32

Event ID 62156 — On revert, updated lockscreen notifications badge registration of app with AppUserModelId AppUserModelID with HRESULT ErrorCode.

Provider
Microsoft-Windows-Shell-Core
Channel
Operational
Task
TileManagement_AppTileInfo_RevertUpdateLSN_Badge

Description

On revert, updated lockscreen notifications badge registration of app with AppUserModelId AppUserModelID with HRESULT ErrorCode.

Message #

On revert, updated lockscreen notifications badge registration of app with AppUserModelId %1 with HRESULT %2.

Fields #

NameDescription
AppUserModelID UnicodeString
ErrorCode UInt32

Event ID 62157 — Removed lockscreen notifications badge registration of app with AppUserModelId AppUserModelID with HRESULT ErrorCode.

Provider
Microsoft-Windows-Shell-Core
Channel
Operational
Task
TileManagement_AppTileInfo_RemoveLSN_Badge

Description

Removed lockscreen notifications badge registration of app with AppUserModelId AppUserModelID with HRESULT ErrorCode.

Message #

Removed lockscreen notifications badge registration of app with AppUserModelId %1 with HRESULT %2.

Fields #

NameDescription
AppUserModelID UnicodeString
ErrorCode UInt32

Event ID 62158 — Updated lockscreen notifications tile registration of app with AppUserModelId AppUserModelID with HRESULT ErrorCode.

Provider
Microsoft-Windows-Shell-Core
Channel
Operational
Task
TileManagement_AppTileInfo_UpdateLSN_Tile

Description

Updated lockscreen notifications tile registration of app with AppUserModelId AppUserModelID with HRESULT ErrorCode.

Message #

Updated lockscreen notifications tile registration of app with AppUserModelId %1 with HRESULT %2.

Fields #

NameDescription
AppUserModelID UnicodeString
ErrorCode UInt32

Event ID 62159 — On revert, updated lockscreen notifications tile registration of app with AppUserModelId AppUserModelID with HRESULT ErrorCode.

Provider
Microsoft-Windows-Shell-Core
Channel
Operational
Task
TileManagement_AppTileInfo_RevertUpdateLSN_Tile

Description

On revert, updated lockscreen notifications tile registration of app with AppUserModelId AppUserModelID with HRESULT ErrorCode.

Message #

On revert, updated lockscreen notifications tile registration of app with AppUserModelId %1 with HRESULT %2.

Fields #

NameDescription
AppUserModelID UnicodeString
ErrorCode UInt32

Event ID 62160 — Removed lockscreen notifications tile registration of app with AppUserModelId AppUserModelID with HRESULT ErrorCode.

Provider
Microsoft-Windows-Shell-Core
Channel
Operational
Task
TileManagement_AppTileInfo_RemoveLSN_Tile

Description

Removed lockscreen notifications tile registration of app with AppUserModelId AppUserModelID with HRESULT ErrorCode.

Message #

Removed lockscreen notifications tile registration of app with AppUserModelId %1 with HRESULT %2.

Fields #

NameDescription
AppUserModelID UnicodeString
ErrorCode UInt32

Event ID 62161 — The namespace extension guid will be loaded in the File Picker.

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
FilePicker_NamespaceExtensionFilter_Allow

Description

The namespace extension guid will be loaded in the File Picker.

Message #

The namespace extension %1 will be loaded in the File Picker

Fields #

NameDescription
guid GUID

Event ID 62162 — The namespace extension guid will not be loaded in the File Picker.

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
FilePicker_NamespaceExtensionFilter_Deny

Description

The namespace extension guid will not be loaded in the File Picker.

Message #

The namespace extension %1 will not be loaded in the File Picker

Fields #

NameDescription
guid GUID

Event ID 62163 — Failed to merge PRI for Package PackageFamilyName at path Path with HRESULT ErrorCode.

Provider
Microsoft-Windows-Shell-Core
Channel
Operational
Task
TileManagement_PackageInfo_MergePriFailed

Description

Failed to merge PRI for Package PackageFamilyName at path Path with HRESULT ErrorCode.

Message #

Failed to merge PRI for Package %1 at path %2 with HRESULT %3.

Fields #

NameDescription
PackageFamilyName UnicodeString
Path UnicodeString
ErrorCode UInt32

Event ID 62164 — Package PackageFamilyName failed to install with HRESULT ErrorCode.

#
Provider
Microsoft-Windows-Shell-Core
Channel
Operational
Level
Informational
Task
TileManagement_PackageInfo_InstallFailed

Description

Package PackageFamilyName failed to install with HRESULT ErrorCode.

Message #

Package %1 failed to install with HRESULT %2.

Fields #

NameDescription
PackageFamilyName UnicodeString
ErrorCode UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "30336ED4-E327-447C-9DE0-51B652C86108",
    "event_source_name": "",
    "event_id": 62164,
    "version": 0,
    "level": 4,
    "task": 62350,
    "opcode": 0,
    "keywords": 2305843009213759488,
    "time_created": "2023-11-05T22:33:30.815908+00:00",
    "event_record_id": 2208,
    "correlation": {},
    "execution": {
      "process_id": 4952,
      "thread_id": 7932
    },
    "channel": "Microsoft-Windows-Shell-Core/Operational",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-21-1992711665-1655669231-58201500-1000"
    }
  },
  "event_data": {
    "PackageFamilyName": "Microsoft.MicrosoftEdge.Stable_8wekyb3d8bbwe",
    "ErrorCode": 2147942450
  },
  "message": ""
}

References #

Event ID 62170 — Logon task 'TaskName' started with flags LogonType.

#
Provider
Microsoft-Windows-Shell-Core
Channel
Operational
Level
Informational
Task
LogonPerformance_TaskRunTime
Opcode
Start

Description

Logon task 'TaskName' started with flags LogonType.

Message #

Logon task '%2' started with flags %1.

Fields #

NameDescription
LogonType UInt32Logon type reference
TaskName UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "30336ED4-E327-447C-9DE0-51B652C86108",
    "event_source_name": "",
    "event_id": 62170,
    "version": 0,
    "level": 4,
    "task": 62170,
    "opcode": 1,
    "keywords": 2306124492780339200,
    "time_created": "2023-11-05T23:54:19.304623+00:00",
    "event_record_id": 2682,
    "correlation": {},
    "execution": {
      "process_id": 10860,
      "thread_id": 7480
    },
    "channel": "Microsoft-Windows-Shell-Core/Operational",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-21-1992711665-1655669231-58201500-1000"
    }
  },
  "event_data": {
    "LogonType": 0,
    "TaskName": "LaunchInputDialListenerPostStart"
  },
  "message": ""
}

References #

Event ID 62171 — Logon task 'TaskName' finished with flags LogonType.

#
Provider
Microsoft-Windows-Shell-Core
Channel
Operational
Level
Informational
Task
LogonPerformance_TaskRunTime
Opcode
Stop

Description

Logon task 'TaskName' finished with flags LogonType.

Message #

Logon task '%2' finished with flags %1.

Fields #

NameDescription
LogonType UInt32Logon type reference
TaskName UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "30336ED4-E327-447C-9DE0-51B652C86108",
    "event_source_name": "",
    "event_id": 62171,
    "version": 0,
    "level": 4,
    "task": 62170,
    "opcode": 2,
    "keywords": 2306124492780339200,
    "time_created": "2023-11-05T23:54:19.542235+00:00",
    "event_record_id": 2695,
    "correlation": {},
    "execution": {
      "process_id": 10860,
      "thread_id": 7480
    },
    "channel": "Microsoft-Windows-Shell-Core/Operational",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-21-1992711665-1655669231-58201500-1000"
    }
  },
  "event_data": {
    "LogonType": 0,
    "TaskName": "LaunchInputDialListenerPostStart"
  },
  "message": ""
}

References #

Event ID 62200 — Failed to register for licensing policy change event.

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Activation_Watermark_Register_Licensing_Event_Error

Description

Failed to register for licensing policy change event. Error code is Result.

Message #

Failed to register for licensing policy change event. Error code is %1.

Fields #

NameDescription
Result UInt32

Event ID 62201 — Failed to create the watermark window.

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Activation_Watermark_Window_Creation_Error

Description

Failed to create the watermark window. Error code is Result.

Message #

Failed to create the watermark window. Error code is %1.

Fields #

NameDescription
Result UInt32

Event ID 62202 — Failed to render the watermark.

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Activation_Watermark_Render_Error

Description

Failed to render the watermark. Error code is Result.

Message #

Failed to render the watermark. Error code is %1.

Fields #

NameDescription
Result UInt32

Event ID 62203 — Failed to get genuine status.

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Activation_Watermark_Failed_To_Get_Genuine_Status

Description

Failed to get genuine status. Error code is Result.

Message #

Failed to get genuine status. Error code is %1.

Fields #

NameDescription
Result UInt32

Event ID 62204 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Activation_Watermark_Init
Opcode
Start

Event ID 62205 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
Activation_Watermark_Init
Opcode
Stop

Event ID 62250 — Updated lockscreen alarm registration of app with AppUserModelId AppUserModelID with HRESULT ErrorCode.

Provider
Microsoft-Windows-Shell-Core
Channel
Operational
Task
TileManagement_AppTileInfo_UpdateLSN_Alarm

Description

Updated lockscreen alarm registration of app with AppUserModelId AppUserModelID with HRESULT ErrorCode.

Message #

Updated lockscreen alarm registration of app with AppUserModelId %1 with HRESULT %2.

Fields #

NameDescription
AppUserModelID UnicodeString
ErrorCode UInt32

Event ID 62251 — On revert, updated lockscreen alarm registration of app with AppUserModelId AppUserModelID with HRESULT ErrorCode.

Provider
Microsoft-Windows-Shell-Core
Channel
Operational
Task
TileManagement_AppTileInfo_RevertUpdateLSN_Alarm

Description

On revert, updated lockscreen alarm registration of app with AppUserModelId AppUserModelID with HRESULT ErrorCode.

Message #

On revert, updated lockscreen alarm registration of app with AppUserModelId %1 with HRESULT %2.

Fields #

NameDescription
AppUserModelID UnicodeString
ErrorCode UInt32

Event ID 62252 — Removed lockscreen alarm registration of app with AppUserModelId AppUserModelID with HRESULT ErrorCode.

Provider
Microsoft-Windows-Shell-Core
Channel
Operational
Task
TileManagement_AppTileInfo_RemoveLSN_Alarm

Description

Removed lockscreen alarm registration of app with AppUserModelId AppUserModelID with HRESULT ErrorCode.

Message #

Removed lockscreen alarm registration of app with AppUserModelId %1 with HRESULT %2.

Fields #

NameDescription
AppUserModelID UnicodeString
ErrorCode UInt32

Event ID 62300 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DataPackage_GetApplicationLink
Opcode
Start

Event ID 62301 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DataPackage_GetApplicationLink
Opcode
Stop

Event ID 62302 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DataPackage_SetApplicationLink
Opcode
Start

Event ID 62303 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
DataPackage_SetApplicationLink
Opcode
Stop

Event ID 62320 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
FilePlaceholder_Save
Opcode
Start

Fields #

NameDescription
FileName UnicodeString

Event ID 62321 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
FilePlaceholder_Save
Opcode
Stop

Fields #

NameDescription
FileName UnicodeString
HRESULT UInt32

Event ID 62322 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
FilePlaceholder_ClearPrimaryStream
Opcode
Start

Event ID 62323 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
FilePlaceholder_ClearPrimaryStream
Opcode
Stop

Fields #

NameDescription
HRESULT UInt32

Event ID 62324 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
FilePlaceholder_SetPlaceholderStates
Opcode
Start

Fields #

NameDescription
FileName UnicodeString
NewValues UInt32
ValuesToChange UInt32

Event ID 62325 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
FilePlaceholder_SetPlaceholderStates
Opcode
Stop

Fields #

NameDescription
FileName UnicodeString
HRESULT UInt32

Event ID 62326 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ExtrinsicPropertyStore_Commit
Opcode
Start

Fields #

NameDescription
FileName UnicodeString

Event ID 62327 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
ExtrinsicPropertyStore_Commit
Opcode
Stop

Fields #

NameDescription
FileName UnicodeString
HRESULT UInt32

Event ID 62328 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
FilePlaceholder_StreamResolver_VerifyFileVersion
Opcode
Start

Fields #

NameDescription
FileName UnicodeString

Event ID 62329 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
FilePlaceholder_StreamResolver_VerifyFileVersion
Opcode
Stop

Fields #

NameDescription
FileName UnicodeString
HRESULT UInt32

Event ID 62330 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
FilePlaceholder_StreamResolver_RetrievePrimaryStream
Opcode
Start

Fields #

NameDescription
Position UInt64
Size UInt64

Event ID 62331 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
FilePlaceholder_StreamResolver_RetrievePrimaryStream
Opcode
Stop

Fields #

NameDescription
Position UInt64
Size UInt64
HRESULT UInt32

Event ID 62332 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
FileChunkMap_Create
Opcode
Start

Fields #

NameDescription
FileName UnicodeString

Event ID 62333 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
FileChunkMap_Create
Opcode
Stop

Fields #

NameDescription
FileName UnicodeString
HRESULT UInt32

Event ID 62334 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
FileChunkMap_Delete
Opcode
Start

Event ID 62335 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
FileChunkMap_SetFileCompletionState
Opcode
Start

Fields #

NameDescription
FileName UnicodeString
FileCompletionState UInt32

Event ID 62336 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
FileChunkMap_SetFileCompletionState
Opcode
Stop

Fields #

NameDescription
FileName UnicodeString
FileCompletionState UInt32
HRESULT UInt32

Event ID 62337 — Fileplaceholder hydration times out.

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
FilePlaceholder_Hydration_Timeout

Description

Fileplaceholder hydration times out.

Message #

Fileplaceholder hydration times out.

Event ID 62380 —

Provider
Microsoft-Windows-Shell-Core
Channel
Diagnostic
Task
StartMenuFeedback

Fields #

NameDescription
QuestionID Int32
ResponseType UnicodeString
QuestionType UnicodeString
Answer UnicodeString
FollowupAnswer UnicodeString

Event ID 62400 — CloudExperienceHost App Activity started.

Provider
Microsoft-Windows-Shell-Core
Channel
Operational
Level
Informational
Task
CloudExperienceHost_AppActivity
Opcode
Start

Description

CloudExperienceHost App Activity started. Source: 'Source', Experience: 'Experience'.

Message #

CloudExperienceHost App Activity started. Source: '%1', Experience: '%2'.

Fields #

NameDescription
Source UnicodeString
Experience UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "30336ED4-E327-447C-9DE0-51B652C86108",
    "event_source_name": "",
    "event_id": 62400,
    "version": 0,
    "level": 4,
    "task": 62400,
    "opcode": 1,
    "keywords": 2305843043573497856,
    "time_created": "2026-03-09T18:20:52.260063+00:00",
    "event_record_id": 4620,
    "correlation": {
      "ActivityID": "16C17DEB-9C73-44F6-B6EA-3B3069AE939F"
    },
    "execution": {
      "process_id": 7268,
      "thread_id": 7952
    },
    "channel": "Microsoft-Windows-Shell-Core/Operational",
    "computer": "LAB-WIN11",
    "security": {
      "user_id": "S-1-5-21-3407486967-1585450050-1838039599-1000"
    }
  },
  "event_data": {
    "Source": "ms-cxh://mosetMDMconnecttowork/",
    "Experience": "{\"source\":\"ms-cxh://mosetMDMconnecttowork/\",\"protocol\":\"ms-cxh\",\"host\":\"mosetMDMconnecttowork\",\"port\":\"\",\"params\":{},\"file\":\"\",\"hash\":\"\",\"path\":\"/\",\"segments\":[\"\"]}"
  },
  "message": ""
}

Event ID 62401 — CloudExperienceHost App Activity stopped.

Provider
Microsoft-Windows-Shell-Core
Channel
Operational
Level
Informational
Task
CloudExperienceHost_AppActivity
Opcode
Stop

Description

CloudExperienceHost App Activity stopped. Result: 'Result'.

Message #

CloudExperienceHost App Activity stopped. Result: '%1'.

Fields #

NameDescription
Result UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "30336ED4-E327-447C-9DE0-51B652C86108",
    "event_source_name": "",
    "event_id": 62401,
    "version": 0,
    "level": 4,
    "task": 62400,
    "opcode": 2,
    "keywords": 2305843043573497856,
    "time_created": "2026-03-09T18:21:10.189353+00:00",
    "event_record_id": 4667,
    "correlation": {
      "ActivityID": "E1341ABB-3BA3-4E91-B44B-1D9432DAB913"
    },
    "execution": {
      "process_id": 7268,
      "thread_id": 7952
    },
    "channel": "Microsoft-Windows-Shell-Core/Operational",
    "computer": "LAB-WIN11",
    "security": {
      "user_id": "S-1-5-21-3407486967-1585450050-1838039599-1000"
    }
  },
  "event_data": {
    "Result": "success"
  },
  "message": ""
}

Event ID 62402 — CloudExperienceHost App Event 1.

Provider
Microsoft-Windows-Shell-Core
Channel
Operational
Level
Informational
Task
CloudExperienceHost_AppEvent1

Description

CloudExperienceHost App Event 1. Name: 'Name'.

Message #

CloudExperienceHost App Event 1. Name: '%1'.

Fields #

NameDescription
Name UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "30336ED4-E327-447C-9DE0-51B652C86108",
    "event_source_name": "",
    "event_id": 62402,
    "version": 0,
    "level": 4,
    "task": 62402,
    "opcode": 0,
    "keywords": 2305843043573497856,
    "time_created": "2026-03-09T18:20:52.256168+00:00",
    "event_record_id": 4619,
    "correlation": {
      "ActivityID": "FEE5CECA-D7C0-4D50-B57D-0A85ED531ABB"
    },
    "execution": {
      "process_id": 7268,
      "thread_id": 7952
    },
    "channel": "Microsoft-Windows-Shell-Core/Operational",
    "computer": "LAB-WIN11",
    "security": {
      "user_id": "S-1-5-21-3407486967-1585450050-1838039599-1000"
    }
  },
  "event_data": {
    "Name": "ClearTemporaryWebDataAsyncSucceeded"
  },
  "message": ""
}

Event ID 62403 — CloudExperienceHost App Event 2.

Provider
Microsoft-Windows-Shell-Core
Channel
Operational
Level
Informational
Task
CloudExperienceHost_AppEvent2

Description

CloudExperienceHost App Event 2. Name: 'Name', Value: 'Value'.

Message #

CloudExperienceHost App Event 2. Name: '%1', Value: '%2'.

Fields #

NameDescription
Name UnicodeString
Value UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "30336ED4-E327-447C-9DE0-51B652C86108",
    "event_source_name": "",
    "event_id": 62403,
    "version": 0,
    "level": 4,
    "task": 62403,
    "opcode": 0,
    "keywords": 2305843043573497856,
    "time_created": "2026-03-09T18:20:52.876162+00:00",
    "event_record_id": 4630,
    "correlation": {
      "ActivityID": "77230D5B-4D6A-43D1-90F6-F955540E96C3"
    },
    "execution": {
      "process_id": 7268,
      "thread_id": 7952
    },
    "channel": "Microsoft-Windows-Shell-Core/Operational",
    "computer": "LAB-WIN11",
    "security": {
      "user_id": "S-1-5-21-3407486967-1585450050-1838039599-1000"
    }
  },
  "event_data": {
    "Name": "FirstWebAppVisible",
    "Value": "Work"
  },
  "message": ""
}

Event ID 62404 — CloudExperienceHost Web App Activity started.

Provider
Microsoft-Windows-Shell-Core
Channel
Operational
Level
Informational
Task
CloudExperienceHost_WebAppActivity
Opcode
Start

Description

CloudExperienceHost Web App Activity started. CXID: 'CXID'.

Message #

CloudExperienceHost Web App Activity started. CXID: '%1'.

Fields #

NameDescription
CXID UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "30336ED4-E327-447C-9DE0-51B652C86108",
    "event_source_name": "",
    "event_id": 62404,
    "version": 0,
    "level": 4,
    "task": 62404,
    "opcode": 1,
    "keywords": 2305843043573497856,
    "time_created": "2026-03-09T18:21:07.739590+00:00",
    "event_record_id": 4655,
    "correlation": {
      "ActivityID": "EB476454-99B3-4A1B-A3F5-F070716C4F29"
    },
    "execution": {
      "process_id": 7268,
      "thread_id": 7952
    },
    "channel": "Microsoft-Windows-Shell-Core/Operational",
    "computer": "LAB-WIN11",
    "security": {
      "user_id": "S-1-5-21-3407486967-1585450050-1838039599-1000"
    }
  },
  "event_data": {
    "CXID": "MDMEnrollmentFinished"
  },
  "message": ""
}

Event ID 62405 — CloudExperienceHost Web App Activity stopped.

Provider
Microsoft-Windows-Shell-Core
Channel
Operational
Level
Informational
Task
CloudExperienceHost_WebAppActivity
Opcode
Stop

Description

CloudExperienceHost Web App Activity stopped. Result: 'Result'.

Message #

CloudExperienceHost Web App Activity stopped. Result: '%1'.

Fields #

NameDescription
Result UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "30336ED4-E327-447C-9DE0-51B652C86108",
    "event_source_name": "",
    "event_id": 62405,
    "version": 0,
    "level": 4,
    "task": 62404,
    "opcode": 2,
    "keywords": 2305843043573497856,
    "time_created": "2026-03-09T18:21:10.189010+00:00",
    "event_record_id": 4666,
    "correlation": {
      "ActivityID": "DE4FD34D-5A8A-4230-80D6-9EDDABC9FB2C"
    },
    "execution": {
      "process_id": 7268,
      "thread_id": 7952
    },
    "channel": "Microsoft-Windows-Shell-Core/Operational",
    "computer": "LAB-WIN11",
    "security": {
      "user_id": "S-1-5-21-3407486967-1585450050-1838039599-1000"
    }
  },
  "event_data": {
    "Result": "success"
  },
  "message": ""
}

Event ID 62406 — CloudExperienceHost Web App Event 1.

Provider
Microsoft-Windows-Shell-Core
Channel
Operational
Task
CloudExperienceHost_WebAppEvent1

Description

CloudExperienceHost Web App Event 1. Name: 'Name'.

Message #

CloudExperienceHost Web App Event 1. Name: '%1'.

Fields #

NameDescription
Name UnicodeString

Event ID 62407 — CloudExperienceHost Web App Event 2.

Provider
Microsoft-Windows-Shell-Core
Channel
Operational
Level
Informational
Task
CloudExperienceHost_WebAppEvent2

Description

CloudExperienceHost Web App Event 2. Name: 'Name', Value: 'Value'.

Message #

CloudExperienceHost Web App Event 2. Name: '%1', Value: '%2'.

Fields #

NameDescription
Name UnicodeString
Value UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "30336ED4-E327-447C-9DE0-51B652C86108",
    "event_source_name": "",
    "event_id": 62407,
    "version": 0,
    "level": 4,
    "task": 62407,
    "opcode": 0,
    "keywords": 2305843043573497856,
    "time_created": "2026-03-09T18:21:10.188681+00:00",
    "event_record_id": 4665,
    "correlation": {
      "ActivityID": "73C6F5B7-A06D-40B1-A1D3-C103166D9BF0"
    },
    "execution": {
      "process_id": 7268,
      "thread_id": 7952
    },
    "channel": "Microsoft-Windows-Shell-Core/Operational",
    "computer": "LAB-WIN11",
    "security": {
      "user_id": "S-1-5-21-3407486967-1585450050-1838039599-1000"
    }
  },
  "event_data": {
    "Name": "Done",
    "Value": "success"
  },
  "message": ""
}

Event ID 62408 — Started execution of command 'Command'.

Provider
Microsoft-Windows-Shell-Core
Channel
Operational
Level
Informational
Task
Explorer_ExecutingPackagedStartupApp
Opcode
Start

Description

Started execution of command 'Command'.

Message #

Started execution of command '%1'.

Fields #

NameDescription
Command UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "30336ED4-E327-447C-9DE0-51B652C86108",
    "event_source_name": "",
    "event_id": 62408,
    "version": 0,
    "level": 4,
    "task": 62408,
    "opcode": 1,
    "keywords": 2305878193652957184,
    "time_created": "2026-02-10T01:03:05.779137+00:00",
    "event_record_id": 1106,
    "correlation": {},
    "execution": {
      "process_id": 5640,
      "thread_id": 7848
    },
    "channel": "Microsoft-Windows-Shell-Core/Operational",
    "computer": "LAB-WIN11",
    "security": {
      "user_id": "S-1-5-21-3407486967-1585450050-1838039599-1000"
    }
  },
  "event_data": {
    "Command": "msteams_autostarter.exe"
  },
  "message": ""
}

Event ID 62409 — Finished execution of command 'Command' (PID PID).

Provider
Microsoft-Windows-Shell-Core
Channel
Operational
Level
Informational
Task
Explorer_ExecutingPackagedStartupApp
Opcode
Stop

Description

Finished execution of command 'Command' (PID PID).

Message #

Finished execution of command '%2' (PID %1).

Fields #

NameDescription
PID UInt32
Command UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "30336ED4-E327-447C-9DE0-51B652C86108",
    "event_source_name": "",
    "event_id": 62409,
    "version": 0,
    "level": 4,
    "task": 62408,
    "opcode": 2,
    "keywords": 2305878193652957184,
    "time_created": "2026-02-10T01:03:06.583842+00:00",
    "event_record_id": 1107,
    "correlation": {},
    "execution": {
      "process_id": 5640,
      "thread_id": 7848
    },
    "channel": "Microsoft-Windows-Shell-Core/Operational",
    "computer": "LAB-WIN11",
    "security": {
      "user_id": "S-1-5-21-3407486967-1585450050-1838039599-1000"
    }
  },
  "event_data": {
    "PID": 9824,
    "Command": "msteams_autostarter.exe"
  },
  "message": ""
}

Event ID 62420 — Looking for Restore Profiles

Provider
Microsoft-Windows-Shell-Core
Channel
LogonTasksChannel
Task
LogonTask_Restore
Opcode
Start

Description

Looking for Restore Profiles.

Message #

Looking for Restore Profiles

Event ID 62421 — Finished looking for Restore Profiles.

Provider
Microsoft-Windows-Shell-Core
Channel
LogonTasksChannel
Task
LogonTask_Restore
Opcode
Stop

Description

Finished looking for Restore Profiles. Applicable Restore Profiles found: ApplicableProfileCount.

Message #

Finished looking for Restore Profiles. Applicable Restore Profiles found: %1

Fields #

NameDescription
ApplicableProfileCount UInt32

Event ID 62422 — Adding Profile.

Provider
Microsoft-Windows-Shell-Core
Channel
LogonTasksChannel
Task
LogonTask_Restore

Description

Adding Profile.

Message #

Adding Profile:
 Form Factor: %1 
 Device Name: %2 
 OEM Name: %3 
 Hardware Id: %4 
 Last Saved: %5/%6/%7 %8: %9: %10

Fields #

NameDescription
FormFactor UInt32
DeviceName UnicodeString
OEMName UnicodeString
HardwareId UnicodeString
SystemDatewMonth UInt16
SystemDatewDay UInt16
SystemDatewYear UInt16
SystemDatewHour UInt16
SystemDatewMinute UInt16
SystemDatewSecond UInt16

Event ID 62423 — Set Restore Profile to Hardware Id: HardwareId.

Provider
Microsoft-Windows-Shell-Core
Channel
LogonTasksChannel
Task
LogonTask_Restore

Description

Set Restore Profile to Hardware Id: HardwareId.

Message #

Set Restore Profile to Hardware Id: %1

Fields #

NameDescription
HardwareId UnicodeString

Event ID 62440 — Hash mismatch detected for: ExtOrUriScheme.

Provider
Microsoft-Windows-Shell-Core
Channel
AppDefaults
Task
AppDefaults_UserChoiceHashMismatch

Description

Hash mismatch detected for: ExtOrUriScheme. ProgId: ProgId. UserSid: UserSid. HashInRegistry: HashInRegistry. ComputedHash: ComputedHash. Date: SystemDatewYear : SystemDatewMonth: SystemDatewDayOfWeek : SystemDatewDay : SystemDatewHour : SystemDatewMinute.

Message #

Hash mismatch detected for: %1. ProgId: %2. UserSid: %3. HashInRegistry: %4. ComputedHash: %5. Date: %6 : %7: %8 : %9 : %10 : %11

Fields #

NameDescription
ExtOrUriScheme UnicodeString
ProgId UnicodeString
UserSid UnicodeString
HashInRegistry UnicodeString
ComputedHash UnicodeString
SystemDatewYear UInt16
SystemDatewMonth UInt16
SystemDatewDayOfWeek UInt16
SystemDatewDay UInt16
SystemDatewHour UInt16
SystemDatewMinute UInt16

Event ID 62441 — User choice has been reset to prog id ProgId for ExtOrUriScheme.

Provider
Microsoft-Windows-Shell-Core
Channel
AppDefaults
Task
AppDefaults_ResetToRecommended

Description

User choice has been reset to prog id ProgId for ExtOrUriScheme. CurrentDefaultProgId: CurrentDefaultProgId. ShouldToast: ShouldToast.

Message #

User choice has been reset to prog id %1 for %2. CurrentDefaultProgId: %3. ShouldToast: %4

Fields #

NameDescription
ProgId UnicodeString
ExtOrUriScheme UnicodeString
CurrentDefaultProgId UnicodeString
ShouldToast Boolean

Event ID 62442 — Upgraded to prog id ProgId from prog id CurrentDefaultProgId for ExtOrUriScheme.

Provider
Microsoft-Windows-Shell-Core
Channel
AppDefaults
Task
AppDefaults_UpgradeToRecommendedApp

Description

Upgraded to prog id ProgId from prog id CurrentDefaultProgId for ExtOrUriScheme.

Message #

Upgraded to prog id %1 from prog id %2 for %3

Fields #

NameDescription
ProgId UnicodeString
CurrentDefaultProgId UnicodeString
ExtOrUriScheme UnicodeString

Event ID 62443 — AppDefault Info: Info.

#
Provider
Microsoft-Windows-Shell-Core
Channel
AppDefaults
Level
Informational
Task
AppDefaults_Info

Description

AppDefault Info: Info.

Message #

AppDefault Info: %1

Fields #

NameDescription
Info UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "30336ED4-E327-447C-9DE0-51B652C86108",
    "event_source_name": "",
    "event_id": 62443,
    "version": 0,
    "level": 4,
    "task": 62443,
    "opcode": 0,
    "keywords": 1152921504606846976,
    "time_created": "2023-11-05T23:53:37.119797+00:00",
    "event_record_id": 1084,
    "correlation": {},
    "execution": {
      "process_id": 10860,
      "thread_id": 10720
    },
    "channel": "Microsoft-Windows-Shell-Core/AppDefaults",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-21-1992711665-1655669231-58201500-1000"
    }
  },
  "event_data": {
    "Info": "AppDefaults-Logon-UserProfileLoaded"
  },
  "message": ""
}

References #

Event ID 62444 — Missing Hash -- ProgId: ProgId FileExtOrUriScheme: ExtOrUriScheme.

Provider
Microsoft-Windows-Shell-Core
Channel
AppDefaults
Task
AppDefaults_HashNotFound

Description

Missing Hash -- ProgId: ProgId FileExtOrUriScheme: ExtOrUriScheme.

Message #

Missing Hash -- ProgId: %1 FileExtOrUriScheme: %2

Fields #

NameDescription
ProgId UnicodeString
ExtOrUriScheme UnicodeString

Event ID 62445 — Migration Info: Info.

Provider
Microsoft-Windows-Shell-Core
Channel
AppDefaults
Task
AppDefaults_MigrationInfo

Description

Migration Info: Info.

Message #

Migration Info: %1

Fields #

NameDescription
Info UnicodeString

Event ID 62460 — OOBE Health Monitor.

#
Provider
Microsoft-Windows-Shell-Core
Channel
Operational
Level
Informational
Task
OOBEHealth_Progress

Description

OOBE Health Monitor. Version: DataVersion, Health flags: HealthStateFlags, Census flags: CensusFlags, Seconds since boot: SecondsSinceBoot, Image identifier: 'ImageIdentifier', Detailed info: 'TrackingInfo'.

Message #

OOBE Health Monitor. Version: %1, Health flags: %2, Census flags: %3, Seconds since boot: %4, Image identifier: '%5', Detailed info: '%6'.

Fields #

NameDescription
DataVersion Int32
HealthStateFlags UInt64
CensusFlags UInt64
SecondsSinceBoot UInt64
ImageIdentifier UnicodeString
TrackingInfo UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Shell-Core",
    "guid": "30336ED4-E327-447C-9DE0-51B652C86108",
    "event_source_name": "",
    "event_id": 62460,
    "version": 0,
    "level": 4,
    "task": 62460,
    "opcode": 0,
    "keywords": 2305843146652712960,
    "time_created": "2023-11-06T06:25:35.337008+00:00",
    "event_record_id": 1692,
    "correlation": {},
    "execution": {
      "process_id": 1424,
      "thread_id": 1428
    },
    "channel": "Microsoft-Windows-Shell-Core/Operational",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "DataVersion": 14,
    "HealthStateFlags": 0,
    "CensusFlags": 14,
    "SecondsSinceBoot": 59,
    "ImageIdentifier": "",
    "TrackingInfo": "{ 0; 1; 0; 0; 0; 0; 0; 0; 0; 0; 0; 0; 0; 0; 0; 0; 0; 0; 0; 0; 0; 0; 0; 0; 0; 0; 0; 0; 0; 0; 0; 0; 0; 0; 0; 0; 0; 0; 0; 0; 0; 0; 0; 0; 0; 0; 0; 0; 0; 0; 0; 0; 0; 0; 0; 0; 0; 0; 0; 0; 0; 0; 0; 0;}"
  },
  "message": ""
}

References #

Event ID 63200 — Application calls obsolete Shell APIs.

Provider
Microsoft-Windows-Shell-Core
Channel
ActionCenter
Opcode
Info

Description

Application calls obsolete Shell APIs.

Message #

Application calls obsolete Shell APIs.