Windows Kernel Trace

141 events across 1 channel

Event IDTitleChannel
0ETW Trace
1ETW Trace
2ETW Trace
3ETW Trace
4ETW Trace
5ETW Trace
8ETW Trace
10ETW Trace
11ETW Trace
12ETW Trace
13ETW Trace
14ETW Trace
15ETW Trace
16ETW Trace
17ETW Trace
18ETW Trace
19ETW Trace
20ETW Trace
21ETW Trace
22ETW Trace
23ETW Trace
24ETW Trace
25ETW Trace
26ETW Trace
27ETW Trace
28ETW Trace
29ETW Trace
30ETW Trace
31ETW Trace
32ETW Trace
33ETW Trace
34ETW Trace
35ETW Trace
36ETW Trace
37ETW Trace
38ETW Trace
39ETW Trace
40ETW Trace
41ETW Trace
42ETW Trace
43ETW Trace
44ETW Trace
45ETW Trace
46ETW Trace
47ETW Trace
48ETW Trace
49ETW Trace
50ETW Trace
51ETW Trace
52ETW Trace
53ETW Trace
55ETW Trace
56ETW Trace
57ETW Trace
58ETW Trace
59ETW Trace
60ETW Trace
61ETW Trace
62ETW Trace
63ETW Trace
64ETW Trace
65ETW Trace
66ETW Trace
67ETW Trace
68ETW Trace
69ETW Trace
70ETW Trace
71ETW Trace
72ETW Trace
73ETW Trace
74ETW Trace
75ETW Trace
76ETW Trace
77ETW Trace
79ETW Trace
80ETW Trace
81ETW Trace
82ETW Trace
83ETW Trace
84ETW Trace
92ETW Trace
93ETW Trace
94ETW Trace
95ETW Trace
96ETW Trace
97ETW Trace
98ETW Trace
99ETW Trace
100ETW Trace
101ETW Trace
102ETW Trace
103ETW Trace
104ETW Trace
105ETW Trace
106ETW Trace
107ETW Trace
108ETW Trace
114ETW Trace
122ETW Trace
123ETW Trace
127ETW Trace
128ETW Trace
129ETW Trace
130ETW Trace
131ETW Trace
132ETW Trace
133ETW Trace
134ETW Trace
135ETW Trace
144ETW Trace
145ETW Trace
146ETW Trace
147ETW Trace
148ETW Trace
149ETW Trace
150ETW Trace
160ETW Trace
161ETW Trace
162ETW Trace
163ETW Trace
164ETW Trace
165ETW Trace
166ETW Trace
167ETW Trace
168ETW Trace
169ETW Trace
170ETW Trace
171ETW Trace
172ETW Trace
173ETW Trace
174ETW Trace
176ETW Trace
177ETW Trace
192ETW Trace
193ETW Trace
208ETW Trace
209ETW Trace
210ETW Trace
211ETW Trace
212ETW Trace
213ETW Trace

Event ID 0 —

Provider
Windows Kernel Trace
Channel
ETW Trace

Fields

NameDescription
FileObject
FileName

Event ID 1 —

Provider
Windows Kernel Trace
Channel
ETW Trace

Fields

NameDescription
ProcessId
TThreadId
StackBase
StackLimit
UserStackBase
UserStackLimit
Affinity
Win32StartAddr
TebBase
SubProcessTag
BasePriority
PagePriority
IoPriority
ThreadFlags
ThreadName

Event ID 2 —

Provider
Windows Kernel Trace
Channel
ETW Trace

Fields

NameDescription
ProcessId
TThreadId
StackBase
StackLimit
UserStackBase
UserStackLimit
Affinity
Win32StartAddr
TebBase
SubProcessTag
BasePriority
PagePriority
IoPriority
ThreadFlags
ThreadName

Event ID 3 —

Provider
Windows Kernel Trace
Channel
ETW Trace

Fields

NameDescription
ProcessId
TThreadId
StackBase
StackLimit
UserStackBase
UserStackLimit
Affinity
Win32StartAddr
TebBase
SubProcessTag
BasePriority
PagePriority
IoPriority
ThreadFlags
ThreadName

Event ID 4 —

Provider
Windows Kernel Trace
Channel
ETW Trace

Fields

NameDescription
ProcessId
TThreadId
StackBase
StackLimit
UserStackBase
UserStackLimit
Affinity
Win32StartAddr
TebBase
SubProcessTag
BasePriority
PagePriority
IoPriority
ThreadFlags
ThreadName

Event ID 5 —

Provider
Windows Kernel Trace
Channel
ETW Trace

Fields

NameDescription
GroupMask1
GroupMask2
GroupMask3
GroupMask4
GroupMask5
GroupMask6
GroupMask7
GroupMask8
KernelEventVersion

Event ID 8 —

Provider
Windows Kernel Trace
Channel
ETW Trace

Event ID 10 —

Provider
Windows Kernel Trace
Channel
ETW Trace

Fields

NameDescription
MHz
NumberOfProcessors
MemSize
PageSize
AllocationGranularity
ComputerName
DomainName
HyperThreadingFlag
HighestUserAddress
ProcessorArchitecture
ProcessorLevel
ProcessorRevision
PaeEnabled
NxEnabled
MemorySpeed

Event ID 11 —

Provider
Windows Kernel Trace
Channel
ETW Trace

Fields

NameDescription
DiskNumber
IrpFlags
TransferSize
Reserved
ByteOffset
FileObject
Irp
HighResResponseTime
IssuingThreadId

Event ID 12 —

Provider
Windows Kernel Trace
Channel
ETW Trace

Fields

NameDescription
Irp
IssuingThreadId

Event ID 13 —

Provider
Windows Kernel Trace
Channel
ETW Trace

Fields

NameDescription
Irp
IssuingThreadId

Event ID 14 —

Provider
Windows Kernel Trace
Channel
ETW Trace

Fields

NameDescription
DiskNumber
IrpFlags
HighResResponseTime
Irp
IssuingThreadId

Event ID 15 —

Provider
Windows Kernel Trace
Channel
ETW Trace

Fields

NameDescription
ProcessId
ServiceState
SubProcessTag
ServiceName
DisplayName
ProcessName
LoadOrderGroup
SvchostGroup

Event ID 16 —

Provider
Windows Kernel Trace
Channel
ETW Trace

Fields

NameDescription
S1
S2
S3
S4
S5
Pad1
Pad2
Pad3

Event ID 17 —

Provider
Windows Kernel Trace
Channel
ETW Trace

Fields

NameDescription
InitialTime
Status
Index
KeyHandle
KeyName

Event ID 18 —

Provider
Windows Kernel Trace
Channel
ETW Trace

Fields

NameDescription
DiskNumber
BusType
DeviceType
MediaType
StartingOffset
Size
NumberOfFreeBlocks
TotalNumberOfBlocks
NextWritableAddress
NumberOfSessions
NumberOfTracks
BytesPerSector
DiscStatus
LastSessionStatus
DriveLetter
FileSystemName
DeviceName
ManufacturerName

Event ID 19 —

Provider
Windows Kernel Trace
Channel
ETW Trace

Fields

NameDescription
InitialTime
Status
Index
KeyHandle
KeyName

Event ID 20 —

Provider
Windows Kernel Trace
Channel
ETW Trace

Fields

NameDescription
InitialTime
Status
Index
KeyHandle
KeyName

Event ID 21 —

Provider
Windows Kernel Trace
Channel
ETW Trace

Fields

NameDescription
IRQAffinity
IRQGroup
Reserved
IRQNum
DeviceDescriptionLen
DeviceDescription

Event ID 22 —

Provider
Windows Kernel Trace
Channel
ETW Trace

Fields

NameDescription
ClassGuid
UpperFiltersCount
LowerFiltersCount
DevStatus
DevProblem
DeviceID
DeviceDescription
FriendlyName
PdoName
ServiceName
UpperFilters
LowerFilters

Event ID 23 —

Provider
Windows Kernel Trace
Channel
ETW Trace

Fields

NameDescription
TargetId
DeviceType
DeviceTimingMode
LocationInformationLen
LocationInformation

Event ID 24 —

Provider
Windows Kernel Trace
Channel
ETW Trace

Fields

NameDescription
InitialTime
Status
Index
KeyHandle
KeyName

Event ID 25 —

Provider
Windows Kernel Trace
Channel
ETW Trace

Fields

NameDescription
InitialTime
Status
Index
KeyHandle
KeyName

Event ID 26 —

Provider
Windows Kernel Trace
Channel
ETW Trace

Fields

NameDescription
PID
size
daddr
saddr
dport
sport
startime
endtime
seqnum
connid

Event ID 27 —

Provider
Windows Kernel Trace
Channel
ETW Trace

Fields

NameDescription
PID
size
daddr
saddr
dport
sport
seqnum
connid

Event ID 28 —

Provider
Windows Kernel Trace
Channel
ETW Trace

Fields

NameDescription
PID
size
daddr
saddr
dport
sport
mss
sackopt
tsopt
wsopt
rcvwin
rcvwinscale
sndwinscale
seqnum
connid

Event ID 29 —

Provider
Windows Kernel Trace
Channel
ETW Trace

Fields

NameDescription
PID
size
daddr
saddr
dport
sport
seqnum
connid

Event ID 30 —

Provider
Windows Kernel Trace
Channel
ETW Trace

Fields

NameDescription
PID
size
daddr
saddr
dport
sport
seqnum
connid

Event ID 31 —

Provider
Windows Kernel Trace
Channel
ETW Trace

Fields

NameDescription
AlignmentClusters
AvgFreeSpaceSize
ClustersPerSlab
FragmentedDirectoryExtents
FragmentedExtents
FreeSpaceCount
LargestFreeSpaceSize
LastRunActualPurgeClusters
LastRunClustersTrimmed
LastRunFullDefragTime
LastRunTime
MFTSize
TotalClusters
TotalUsedClusters
AvgFragmentsPerFile
BytesPerCluster
DirectoryCount
FragmentedDirectories
FragmentedFiles
FragmentedSpace
HardwareIssue
InUseMFTRecords
InUseSlabs
LastRunActualPurgeSlabs
LastRunInitialBackedSlabs
LastRunPercentFragmentation
LastRunPinnedSlabs
LastRunPotentialPurgeSlabs
LastRunSpaceInefficientSlabs
LastRunTrimmedSlabs
LastRunUnknownEvictFailSlabs
LastRunVolsnapPinnedSlabs
MFTFragmentCount
MovableFiles
TotalMFTRecords
TotalSlabs
UnmovableFiles
VolumeId
VolumePathNames

Event ID 32 —

Provider
Windows Kernel Trace
Channel
ETW Trace

Fields

NameDescription
DeviceManufacturer
DeviceManufacturerDisplayName
DeviceModel
DeviceModelDisplayName
MobileOperator
SocVersion
BspVersion

Event ID 33 —

Provider
Windows Kernel Trace
Channel
ETW Trace

Fields

NameDescription
ProcessId
PageFaultCount
HandleCount
Reserved
PeakVirtualSize
PeakWorkingSetSize
PeakPagefileUsage
QuotaPeakPagedPoolUsage
QuotaPeakNonPagedPoolUsage
VirtualSize
WorkingSetSize
PagefileUsage
QuotaPagedPoolUsage
QuotaNonPagedPoolUsage
PrivatePageCount

Event ID 34 —

Provider
Windows Kernel Trace
Channel
ETW Trace

Fields

NameDescription
Counter1
Counter2
Counter3
Counter4
Counter5
Counter6
Counter7
Counter8
Counter9
Counter10
Counter11

Event ID 35 —

Provider
Windows Kernel Trace
Channel
ETW Trace

Fields

NameDescription
FileObject
FileName

Event ID 36 —

Provider
Windows Kernel Trace
Channel
ETW Trace

Fields

NameDescription
NewThreadId
OldThreadId
NewThreadPriority
OldThreadPriority
PreviousCState
SpareByte
OldThreadWaitReason
ThreadFlags
OldThreadState
OldThreadWaitIdealProcessor
NewThreadWaitTime
Reserved

Event ID 37 —

Provider
Windows Kernel Trace
Channel
ETW Trace

Fields

NameDescription
BootFlags
FirmwareType
SecureBootEnabled
SecureBootCapable
Reserved1
Reserved2

Event ID 38 —

Provider
Windows Kernel Trace
Channel
ETW Trace

Fields

NameDescription
Object
ProcessId
Handle
ObjectType
ObjectName

Event ID 39 —

Provider
Windows Kernel Trace
Channel
ETW Trace

Fields

NameDescription
UniqueProcessKey
ProcessId
ParentId
SessionId
ExitStatus
DirectoryTableBase
Flags
UserSID
ImageFileName
CommandLine
PackageFullName
ApplicationId
ExitTime

Event ID 40 —

Provider
Windows Kernel Trace
Channel
ETW Trace

Fields

NameDescription
ViewBase
FileObject
MiscInfo
ViewSize
ProcessId

Event ID 41 —

Provider
Windows Kernel Trace
Channel
ETW Trace

Fields

NameDescription
SpinLockAddress
CallerAddress
AcquireTime
ReleaseTime
WaitTimeInCycles
SpinCount
ThreadId
InterruptCount
Irql
AcquireDepth
Flag
Reserved

Event ID 42 —

Provider
Windows Kernel Trace
Channel
ETW Trace

Event ID 43 —

Provider
Windows Kernel Trace
Channel
ETW Trace

Event ID 44 —

Provider
Windows Kernel Trace
Channel
ETW Trace

Event ID 45 —

Provider
Windows Kernel Trace
Channel
ETW Trace

Event ID 46 —

Provider
Windows Kernel Trace
Channel
ETW Trace

Fields

NameDescription
InstructionPointer
ThreadId
Count
Reserved

Event ID 47 —

Provider
Windows Kernel Trace
Channel
ETW Trace

Fields

NameDescription
InstructionPointer
ThreadId
ProfileSource
Reserved

Event ID 48 —

Provider
Windows Kernel Trace
Channel
ETW Trace

Fields

NameDescription
ThreadId
OldPriority
NewPriority
Reserved

Event ID 49 —

Provider
Windows Kernel Trace
Channel
ETW Trace

Fields

NameDescription
ThreadId
OldPriority
NewPriority
Reserved

Event ID 50 —

Provider
Windows Kernel Trace
Channel
ETW Trace

Fields

NameDescription
InitialTime
Routine
ReturnValue
Vector
Reserved
MessageNumber

Event ID 51 —

Provider
Windows Kernel Trace
Channel
ETW Trace

Fields

NameDescription
ThreadId
OldPriority
NewPriority
Reserved

Event ID 52 —

Provider
Windows Kernel Trace
Channel
ETW Trace

Fields

NameDescription
ThreadId
OldPriority
NewPriority
Reserved

Event ID 53 —

Provider
Windows Kernel Trace
Channel
ETW Trace

Fields

NameDescription
Affinity
ThreadId
Group
Reserved

Event ID 55 —

Provider
Windows Kernel Trace
Channel
ETW Trace

Fields

NameDescription
DiskNumber
IrpFlags
TransferSize
Reserved
ByteOffset
FileObject
Irp
HighResResponseTime
IssuingThreadId

Event ID 56 —

Provider
Windows Kernel Trace
Channel
ETW Trace

Fields

NameDescription
DiskNumber
IrpFlags
TransferSize
Reserved
ByteOffset
FileObject
Irp
HighResResponseTime
IssuingThreadId

Event ID 57 —

Provider
Windows Kernel Trace
Channel
ETW Trace

Fields

NameDescription
DiskNumber
IrpFlags
HighResResponseTime
Irp
IssuingThreadId

Event ID 58 —

Provider
Windows Kernel Trace
Channel
ETW Trace

Fields

NameDescription
Irp
IssuingThreadId

Event ID 59 —

Provider
Windows Kernel Trace
Channel
ETW Trace

Fields

NameDescription
Irp
IssuingThreadId

Event ID 60 —

Provider
Windows Kernel Trace
Channel
ETW Trace

Fields

NameDescription
Irp
IssuingThreadId

Event ID 61 —

Provider
Windows Kernel Trace
Channel
ETW Trace

Fields

NameDescription
ThreadId
SourceProcessorIndex
TargetProcessorIndex
Priority
IdealProcessorAdjust
OldIdealProcessorIndex

Event ID 62 —

Provider
Windows Kernel Trace
Channel
ETW Trace

Fields

NameDescription
Entry
ThreadId

Event ID 63 —

Provider
Windows Kernel Trace
Channel
ETW Trace

Fields

NameDescription
ThreadId
EntryCount
Entries

Event ID 64 —

Provider
Windows Kernel Trace
Channel
ETW Trace

Fields

NameDescription
IrpPtr
FileObject
TTID
CreateOptions
FileAttributes
ShareAccess
OpenPath

Event ID 65 —

Provider
Windows Kernel Trace
Channel
ETW Trace

Fields

NameDescription
IrpPtr
FileObject
FileKey
TTID

Event ID 66 —

Provider
Windows Kernel Trace
Channel
ETW Trace

Fields

NameDescription
IrpPtr
FileObject
FileKey
TTID

Event ID 67 —

Provider
Windows Kernel Trace
Channel
ETW Trace

Fields

NameDescription
Offset
IrpPtr
FileObject
FileKey
TTID
IoSize
IoFlags

Event ID 68 —

Provider
Windows Kernel Trace
Channel
ETW Trace

Fields

NameDescription
Offset
IrpPtr
FileObject
FileKey
TTID
IoSize
IoFlags

Event ID 69 —

Provider
Windows Kernel Trace
Channel
ETW Trace

Fields

NameDescription
IrpPtr
FileObject
FileKey
ExtraInfo
TTID
InfoClass

Event ID 70 —

Provider
Windows Kernel Trace
Channel
ETW Trace

Fields

NameDescription
IrpPtr
FileObject
FileKey
ExtraInfo
TTID
InfoClass

Event ID 71 —

Provider
Windows Kernel Trace
Channel
ETW Trace

Fields

NameDescription
IrpPtr
FileObject
FileKey
ExtraInfo
TTID
InfoClass

Event ID 72 —

Provider
Windows Kernel Trace
Channel
ETW Trace

Fields

NameDescription
IrpPtr
FileObject
FileKey
TTID
Length
InfoClass
FileIndex
FileName

Event ID 73 —

Provider
Windows Kernel Trace
Channel
ETW Trace

Fields

NameDescription
IrpPtr
FileObject
FileKey
TTID

Event ID 74 —

Provider
Windows Kernel Trace
Channel
ETW Trace

Fields

NameDescription
IrpPtr
FileObject
FileKey
ExtraInfo
TTID
InfoClass

Event ID 75 —

Provider
Windows Kernel Trace
Channel
ETW Trace

Fields

NameDescription
IrpPtr
FileObject
FileKey
ExtraInfo
TTID
InfoClass

Event ID 76 —

Provider
Windows Kernel Trace
Channel
ETW Trace

Fields

NameDescription
SpinLockSpinThreshold
SpinLockContentionSampleRate
SpinLockAcquireSampleRate
SpinLockHoldThreshold

Event ID 77 —

Provider
Windows Kernel Trace
Channel
ETW Trace

Fields

NameDescription
IrpPtr
FileObject
FileKey
TTID
Length
InfoClass
FileIndex
FileName

Event ID 79 —

Provider
Windows Kernel Trace
Channel
ETW Trace

Fields

NameDescription
IrpPtr
FileObject
FileKey
ExtraInfo
TTID
InfoClass
FileName

Event ID 80 —

Provider
Windows Kernel Trace
Channel
ETW Trace

Fields

NameDescription
IrpPtr
FileObject
FileKey
ExtraInfo
TTID
InfoClass
FileName

Event ID 81 —

Provider
Windows Kernel Trace
Channel
ETW Trace

Fields

NameDescription
IrpPtr
FileObject
FileKey
ExtraInfo
TTID
InfoClass
FileName

Event ID 82 —

Provider
Windows Kernel Trace
Channel
ETW Trace

Fields

NameDescription
Object
Tag
ProcessId
Count

Event ID 83 —

Provider
Windows Kernel Trace
Channel
ETW Trace

Fields

NameDescription
Object
Tag
ProcessId
Count

Event ID 84 —

Provider
Windows Kernel Trace
Channel
ETW Trace

Fields

NameDescription
Object
Tag
ProcessId
Count

Event ID 92 —

Provider
Windows Kernel Trace
Channel
ETW Trace

Fields

NameDescription
Vector

Event ID 93 —

Provider
Windows Kernel Trace
Channel
ETW Trace

Fields

NameDescription
DeviceObject
TimerRoutine

Event ID 94 —

Provider
Windows Kernel Trace
Channel
ETW Trace

Fields

NameDescription
DeviceObject
TimerRoutine

Event ID 95 —

Provider
Windows Kernel Trace
Channel
ETW Trace

Fields

NameDescription
InitialTime
Routine
ReturnValue
Vector
Reserved

Event ID 96 —

Provider
Windows Kernel Trace
Channel
ETW Trace

Fields

NameDescription
RoutineAddr
FileObject
FileContext
IrpPtr
CallbackDataPtr
MajorFunction

Event ID 97 —

Provider
Windows Kernel Trace
Channel
ETW Trace

Fields

NameDescription
RoutineAddr
FileObject
FileContext
IrpPtr
CallbackDataPtr
MajorFunction

Event ID 98 —

Provider
Windows Kernel Trace
Channel
ETW Trace

Fields

NameDescription
InitialTime
RoutineAddr
FileObject
FileContext
IrpPtr
CallbackDataPtr
MajorFunction

Event ID 99 —

Provider
Windows Kernel Trace
Channel
ETW Trace

Fields

NameDescription
InitialTime
RoutineAddr
FileObject
FileContext
IrpPtr
CallbackDataPtr
MajorFunction

Event ID 100 —

Provider
Windows Kernel Trace
Channel
ETW Trace

Fields

NameDescription
HeapHandle
HRFlags
HRPid
HRRangeCount
HRHeapTag

Event ID 101 —

Provider
Windows Kernel Trace
Channel
ETW Trace

Fields

NameDescription
RoutineAddr
FileObject
FileContext
IrpPtr
CallbackDataPtr
MajorFunction
Status

Event ID 102 —

Provider
Windows Kernel Trace
Channel
ETW Trace

Fields

NameDescription
HeapHandle
HRAddress
HRSize

Event ID 103 —

Provider
Windows Kernel Trace
Channel
ETW Trace

Fields

NameDescription
HeapHandle
HRAddress
HRSize

Event ID 104 —

Provider
Windows Kernel Trace
Channel
ETW Trace

Fields

NameDescription
DueTime
MaximumDueTime
Period
Timer
Callback
CallbackContext
TimerFlags

Event ID 105 —

Provider
Windows Kernel Trace
Channel
ETW Trace

Fields

NameDescription
DueTime
MaximumDueTime
Period
Timer
Callback
CallbackContext
TimerFlags

Event ID 106 —

Provider
Windows Kernel Trace
Channel
ETW Trace

Fields

NameDescription
Timer

Event ID 107 —

Provider
Windows Kernel Trace
Channel
ETW Trace

Fields

NameDescription
Timer
DisableCallback
DisableContext
TimerFlags

Event ID 108 —

Provider
Windows Kernel Trace
Channel
ETW Trace

Fields

NameDescription
Timer
DisableCallback
DisableContext

Event ID 114 —

Provider
Windows Kernel Trace
Channel
ETW Trace

Fields

NameDescription
CallCode
IsFast
IsNested

Event ID 122 —

Provider
Windows Kernel Trace
Channel
ETW Trace

Fields

NameDescription
Rip
Rax
Rcx
Rdx
Rbx
Rsp
Rsi
Rdi
R8
R9
R10
R11
R12
R13
R14
R15

Event ID 123 —

Provider
Windows Kernel Trace
Channel
ETW Trace

Fields

NameDescription
Cpsr
X0
X1
X2
X3
X4
X5
X6
X7
X8
X9
X10
X11
X12
X13
X14
X15
X16
X17
X18
X19
X20
X21
X22
X23
X24
X25
X26
X27
X28
Fp
Lr
Sp
Pc

Event ID 127 —

Provider
Windows Kernel Trace
Channel
ETW Trace

Fields

NameDescription
BaseAddress
SizeInBytes
Flags

Event ID 128 —

Provider
Windows Kernel Trace
Channel
ETW Trace

Fields

NameDescription
BaseAddress
RegionSize
ProcessId
Flags
CommitSizeInBytes

Event ID 129 —

Provider
Windows Kernel Trace
Channel
ETW Trace

Fields

NameDescription
BaseAddress
RegionSize
ProcessId
Flags
CommitSizeInBytes

Event ID 130 —

Provider
Windows Kernel Trace
Channel
ETW Trace

Event ID 131 —

Provider
Windows Kernel Trace
Channel
ETW Trace

Event ID 132 —

Provider
Windows Kernel Trace
Channel
ETW Trace

Event ID 133 —

Provider
Windows Kernel Trace
Channel
ETW Trace

Event ID 134 —

Provider
Windows Kernel Trace
Channel
ETW Trace

Fields

NameDescription
BaseAddress
SizeInBytes
Flags

Event ID 135 —

Provider
Windows Kernel Trace
Channel
ETW Trace

Event ID 144 —

Provider
Windows Kernel Trace
Channel
ETW Trace

Fields

NameDescription
BaseAddress

Event ID 145 —

Provider
Windows Kernel Trace
Channel
ETW Trace

Fields

NameDescription
BaseAddress

Event ID 146 —

Provider
Windows Kernel Trace
Channel
ETW Trace

Fields

NameDescription
BaseAddress

Event ID 147 —

Provider
Windows Kernel Trace
Channel
ETW Trace

Fields

NameDescription
BaseAddress

Event ID 148 —

Provider
Windows Kernel Trace
Channel
ETW Trace

Fields

NameDescription
BaseAddress

Event ID 149 —

Provider
Windows Kernel Trace
Channel
ETW Trace

Fields

NameDescription
BaseAddress

Event ID 150 —

Provider
Windows Kernel Trace
Channel
ETW Trace

Fields

NameDescription
BaseAddress

Event ID 160 —

Provider
Windows Kernel Trace
Channel
ETW Trace

Fields

NameDescription
BaseAddress
ErrorOpcode
Code
String

Event ID 161 —

Provider
Windows Kernel Trace
Channel
ETW Trace

Fields

NameDescription
BaseAddress
ErrorOpcode
Code
String

Event ID 162 —

Provider
Windows Kernel Trace
Channel
ETW Trace

Fields

NameDescription
BaseAddress
ErrorOpcode
Code
String

Event ID 163 —

Provider
Windows Kernel Trace
Channel
ETW Trace

Fields

NameDescription
BaseAddress
ErrorOpcode
Code
String

Event ID 164 —

Provider
Windows Kernel Trace
Channel
ETW Trace

Fields

NameDescription
BaseAddress
ErrorOpcode
Code
String

Event ID 165 —

Provider
Windows Kernel Trace
Channel
ETW Trace

Fields

NameDescription
BaseAddress
ErrorOpcode
Code
String

Event ID 166 —

Provider
Windows Kernel Trace
Channel
ETW Trace

Fields

NameDescription
BaseAddress
ErrorOpcode
Code
String

Event ID 167 —

Provider
Windows Kernel Trace
Channel
ETW Trace

Fields

NameDescription
BaseAddress
ErrorOpcode
Code
String

Event ID 168 —

Provider
Windows Kernel Trace
Channel
ETW Trace

Fields

NameDescription
BaseAddress
ErrorOpcode
Code
String

Event ID 169 —

Provider
Windows Kernel Trace
Channel
ETW Trace

Fields

NameDescription
BaseAddress
ErrorOpcode
Code
String

Event ID 170 —

Provider
Windows Kernel Trace
Channel
ETW Trace

Fields

NameDescription
BaseAddress
ErrorOpcode
Code
String

Event ID 171 —

Provider
Windows Kernel Trace
Channel
ETW Trace

Fields

NameDescription
BaseAddress
ErrorOpcode
Code
String

Event ID 172 —

Provider
Windows Kernel Trace
Channel
ETW Trace

Fields

NameDescription
BaseAddress
ErrorOpcode
Code
String

Event ID 173 —

Provider
Windows Kernel Trace
Channel
ETW Trace

Fields

NameDescription
BaseAddress
ErrorOpcode
Code
String

Event ID 174 —

Provider
Windows Kernel Trace
Channel
ETW Trace

Fields

NameDescription
BaseAddress
ErrorOpcode
Code
String

Event ID 176 —

Provider
Windows Kernel Trace
Channel
ETW Trace

Fields

NameDescription
NewDllBaseAddress
ParentDllBaseAddress
LoadReason
FilePath

Event ID 177 —

Provider
Windows Kernel Trace
Channel
ETW Trace

Fields

NameDescription
NewDllBaseAddress
ParentDllBaseAddress
LoadReason
FilePath

Event ID 192 —

Provider
Windows Kernel Trace
Channel
ETW Trace

Fields

NameDescription
BaseAddress
ErrorOpcode
Code
String1
String2

Event ID 193 —

Provider
Windows Kernel Trace
Channel
ETW Trace

Fields

NameDescription
BaseAddress
ErrorOpcode
Code
String1
String2

Event ID 208 —

Provider
Windows Kernel Trace
Channel
ETW Trace

Fields

NameDescription
BaseAddress
ErrorOpcode
Code
String

Event ID 209 —

Provider
Windows Kernel Trace
Channel
ETW Trace

Fields

NameDescription
BaseAddress
ErrorOpcode
Code
String

Event ID 210 —

Provider
Windows Kernel Trace
Channel
ETW Trace

Fields

NameDescription
BaseAddress
ErrorOpcode
Code
String

Event ID 211 —

Provider
Windows Kernel Trace
Channel
ETW Trace

Fields

NameDescription
BaseAddress
ErrorOpcode
Code
String

Event ID 212 —

Provider
Windows Kernel Trace
Channel
ETW Trace

Fields

NameDescription
LdrLoadFlags
LdrSearchFlags
SearchInfo
LoadReason
FullDllName

Event ID 213 —

Provider
Windows Kernel Trace
Channel
ETW Trace

Fields

NameDescription
SearchInfo
Cwd
AppDir
DllDir
DllLoadDir