Microsoft-Windows-Audio
Event ID 0: Windows Audio encountered an error while processing a device event.
#Event ID 1: Windows Audio encountered an error while processing a device event.
#Event ID 2: Windows Audio failed during a call to SetServiceStatus.
#Event ID 3: Windows Audio failed to start the szSubsystemName subsystem.
#Event ID 4: The Windows Audio Device Graph Isolation process.
#Event ID 5: The Windows Audio Device Graph Isolation process.
#Event ID 10: The Capture Monitor has failed to restart the capture monitor between szInputEndpointName and szOutputEndpointName dwRestartCount times.
#Event ID 11: StreamFlags dwAudioSrvStreamFlags.
#Event ID 14: AudioPerf_Task_EndpointVolumeStart
#Event ID 15: AudioPerf_Task_EndpointVolumeStop
#Event ID 16: AudioPerf_Task_SessionAPIStart
#Event ID 17: AudioPerf_Task_SessionAPIStop
#Event ID 18: Windows Audio Device Graph glitch threshold count exceeded.
#Event ID 19: Windows Audio Device Graph glitch threshold count exceeded.
#Event ID 20: Format: Format Sampling rate: Sampling_rateHz Offloaded: Offloaded.
#Event ID 21: Sound level for application [AppId] changed to [SoundLevel].
#Event ID 23: Released exclusive mode resource bExclusiveModeStream.
#Event ID 24: Stream started.
#Message #
Fields #
| Name | Description |
|---|---|
AppId UnicodeString | |
PID UInt32 | |
Category UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Audio",
"event_id": 24,
"level": 4,
"task": 120,
"opcode": 0,
"time_created": "2026-04-18T02:46:19.5992023+00:00",
"computer": "DESKTOP-FF3N5XK",
"channel": "Microsoft-Windows-Audio"
},
"event_data": {
"AppId": "Microsoft.Windows.ShellExperienceHost_cw5n1h2txyewy!App",
"PID": "6112",
"Category": "5"
}
}
Event ID 25: Stream stopped.
#Message #
Fields #
| Name | Description |
|---|---|
AppId UnicodeString | |
PID UInt32 | |
Category UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Audio",
"event_id": 25,
"level": 4,
"task": 122,
"opcode": 0,
"time_created": "2026-04-18T02:46:21.0095682+00:00",
"computer": "DESKTOP-FF3N5XK",
"channel": "Microsoft-Windows-Audio"
},
"event_data": {
"AppId": "Microsoft.Windows.ShellExperienceHost_cw5n1h2txyewy!App",
"PID": "6112",
"Category": "5"
}
}
Event ID 26: Capture Monitor Render Glitch: pCMonitor=[pCMonitor], DevicePosition=[DevicePosition], QPCPosition=[QPCPosition].
#Event ID 27: Capture Monitor Capture Glitch: pCMonitor=[pCMonitor], DevicePosition=[DevicePosition], QPCPosition=[QPCPosition].
#Event ID 28: APO Glitch: Format Converter INF detected: pCAudioFormatConvert=[pCAudioFormatConvert], [ConverstionType].
#Event ID 29: Engine Glitch: CP Client Input Endpoint - pCCrossProcessClientInputEndpoint=[pCCrossProcessClientInputEndpoint] No Messages in queue.
#Event ID 30: Engine Glitch: CP Client Input Endpoint - pCCrossProcessClientInputEndpoint=[pCCrossProcessClientInputEndpoint] Queue item does not match requested size.
#Event ID 31: Engine Glitch: CP Client Output Endpoint - Server Overread: pCCrossProcessClientOutputEndpoint=[pCCrossProcessClientOutputEndpoint] WritePos=[WriteBytePos] ReadPos=[ReadBytePos] BytesToWrite=[Bytes...
#Description
Engine Glitch: CP Client Output Endpoint - Server Overread: pCCrossProcessClientOutputEndpoint=[pCCrossProcessClientOutputEndpoint] WritePos=[WriteBytePos] ReadPos=[ReadBytePos] BytesToWrite=[BytesToWrite].
Message #
Fields #
| Name | Description |
|---|---|
pCCrossProcessClientOutputEndpoint Pointer | |
WriteBytePos UInt64 | |
ReadBytePos UInt64 | |
BytesToWrite UInt32 |
Event ID 32: Engine Glitch: CP Client Output Endpoint - Read Pointer Overwrite: pCCrossProcessClientOutputEndpoint=[pCCrossProcessClientOutputEndpoint] WriteOffset=[WriteOffset] ReadOffset=[ReadOffset] BytesTo...
#Description
Engine Glitch: CP Client Output Endpoint - Read Pointer Overwrite: pCCrossProcessClientOutputEndpoint=[pCCrossProcessClientOutputEndpoint] WriteOffset=[WriteOffset] ReadOffset=[ReadOffset] BytesToWrite=[BytesToWrite] EndOfDataOffset=[EndOfDataOffset].
Message #
Fields #
| Name | Description |
|---|---|
pCCrossProcessClientOutputEndpoint Pointer | |
WriteOffset UInt32 | |
ReadOffset UInt32 | |
BytesToWrite UInt32 | |
EndOfDataOffset UInt32 |
Event ID 33: Engine Glitch: CP Server Input Endpoint - Starvation: pCCrossProcessServerInputEndpoint=[pCCrossProcessServerInputEndpoint] WriteOffset=[WriteOffset] ReadOffset=[ReadOffset] BufferSize=[BufferSize]...
#Description
Engine Glitch: CP Server Input Endpoint - Starvation: pCCrossProcessServerInputEndpoint=[pCCrossProcessServerInputEndpoint] WriteOffset=[WriteOffset] ReadOffset=[ReadOffset] BufferSize=[BufferSize] BytesAvail=[BytesAvailable].
Message #
Fields #
| Name | Description |
|---|---|
pCCrossProcessServerInputEndpoint Pointer | |
WriteOffset UInt32 | |
ReadOffset UInt32 | |
BufferSize UInt32 | |
BytesAvailable UInt32 |
Event ID 34: Engine Glitch: CP Server Output Endpoint - Queue Full Packet Drop: pCCrossProcessServerOutputEndpoint=[pCCrossProcessServerOutputEndpoint] WritePos=[WriteBytePos] DroppedBytes=[DroppedBytes] ReadPo...
#Description
Engine Glitch: CP Server Output Endpoint - Queue Full Packet Drop: pCCrossProcessServerOutputEndpoint=[pCCrossProcessServerOutputEndpoint] WritePos=[WriteBytePos] DroppedBytes=[DroppedBytes] ReadPos=[ReadBytePos] BytesToWrite=[BytesToWrite].
Message #
Fields #
| Name | Description |
|---|---|
pCCrossProcessServerOutputEndpoint Pointer | |
WriteBytePos UInt64 | |
DroppedBytes UInt32 | |
ReadBytePos UInt64 | |
BytesToWrite UInt32 |
Event ID 35: Engine Glitch: CP Server Output Endpoint - Read Pointer Overwrite: pCCrossProcessServerOutputEndpoint=[pCCrossProcessServerOutputEndpoint] WriteOffset=[WriteOffset] ReadOffset=[ReadOffset] BytesTo...
#Description
Engine Glitch: CP Server Output Endpoint - Read Pointer Overwrite: pCCrossProcessServerOutputEndpoint=[pCCrossProcessServerOutputEndpoint] WriteOffset=[WriteOffset] ReadOffset=[ReadOffset] BytesToWrite=[BytesToWrite].
Message #
Fields #
| Name | Description |
|---|---|
pCCrossProcessServerOutputEndpoint Pointer | |
WriteOffset UInt32 | |
ReadOffset UInt32 | |
BytesToWrite UInt32 |
Event ID 36: KS Endpoint Glitch: IOMGR No Outstanding Packets: pOwner=[pOwner] NextStreamingPacketToComplete=[NextStreamingPacketToComplete] MaxPacketCount=[MaxPacketCount].
#Event ID 37: KS Endpoint Glitch: IOMGR Ioctl Time Limit Exceeded: pOwner=[pOwner] DeltaHNS=[IoctlTimeHNS].
#Event ID 38: KS Endpoint Glitch: BASE Output Unexpected Buffer Completed: pCAudioBasePin=[pCAudioBasePin] LockedDataPointer=[pLockedDataPointer] bLockedEqualsUnrolled=[bLockedEqualsUnrolled].
#Event ID 39: KS Endpoint Glitch: BASE Input Null Last Buffer with LockedData !
#Event ID 40: KS Endpoint Glitch: BASE Input Buffer Index Mismatch: pCAudioBasePin=[pCAudioBasePin] LockedDataPointer=[LockedDataPointer].
#Event ID 41: KS Endpoint Glitch: BASE End Glitch: pCAudioBasePin=[pCAudioBasePin] StreamPosition=[GlitchStreamPosition] GlitchDuration=[GlitchDuration].
#Event ID 42: KS Endpoint Glitch: RTCAP StreamPos Ahead of HW Pos: pCAudioCapturePinRealtimeStreaming=[pCAudioCapturePinRealtimeStreaming] WritePos=[WritePosition] PlayPos=[PlayPosition] StreamPos=[StreamPositio...
#Description
KS Endpoint Glitch: RTCAP StreamPos Ahead of HW Pos: pCAudioCapturePinRealtimeStreaming=[pCAudioCapturePinRealtimeStreaming] WritePos=[WritePosition] PlayPos=[PlayPosition] StreamPos=[StreamPosition] StreamPosMinusReadPos=[StreamPosMinusReadPos].
Message #
Fields #
| Name | Description |
|---|---|
pCAudioCapturePinRealtimeStreaming Pointer | |
WritePosition UInt64 | |
PlayPosition UInt64 | |
StreamPosition UInt64 | |
StreamPosMinusReadPos UInt64 |
Event ID 43: KS Endpoint Glitch: RTCAP StreamPos Too Far Behind: pCAudioCapturePinRealtimeStreaming=[pCAudioCapturePinRealtimeStreaming] WritePos=[WritePosition] PlayPos=[PlayPosition] StreamPos=[StreamPosition...
#Description
KS Endpoint Glitch: RTCAP StreamPos Too Far Behind: pCAudioCapturePinRealtimeStreaming=[pCAudioCapturePinRealtimeStreaming] WritePos=[WritePosition] PlayPos=[PlayPosition] StreamPos=[StreamPosition] ReadPosMinusStreamPos=[ReadPosMinusStreamPos].
Message #
Fields #
| Name | Description |
|---|---|
pCAudioCapturePinRealtimeStreaming Pointer | |
WritePosition UInt64 | |
PlayPosition UInt64 | |
StreamPosition UInt64 | |
ReadPosMinusStreamPos UInt64 |
Event ID 44: KS Endpoint Glitch: RTREN WritePos Exceeds TotalPos: pCAudioRenderPinRealtimeStreaming=[pCAudioRenderPinRealtimeStreaming] WritePos=[WritePosition] PlayPos=[PlayPosition] TotalPos=[TotalPosition] W...
#Description
KS Endpoint Glitch: RTREN WritePos Exceeds TotalPos: pCAudioRenderPinRealtimeStreaming=[pCAudioRenderPinRealtimeStreaming] WritePos=[WritePosition] PlayPos=[PlayPosition] TotalPos=[TotalPosition] WritePosMinusTotalPos=[WritePosMinusTotalPos].
Message #
Fields #
| Name | Description |
|---|---|
pCAudioRenderPinRealtimeStreaming Pointer | |
WritePosition UInt64 | |
PlayPosition UInt64 | |
TotalPosition UInt64 | |
WritePosMinusTotalPos UInt64 |
Event ID 45: KS Endpoint Glitch: STCAP Capture Ahead: pCAudioCapturePinStandardStreaming=[pCAudioCapturePinStandardStreaming] ValidPosEnd=[ValidPositionEnd] ValidPosStart=[ValidPositionStart] StreamPos=[StreamP...
#Description
KS Endpoint Glitch: STCAP Capture Ahead: pCAudioCapturePinStandardStreaming=[pCAudioCapturePinStandardStreaming] ValidPosEnd=[ValidPositionEnd] ValidPosStart=[ValidPositionStart] StreamPos=[StreamPosition] StreamPosMinusValidPosEnd=[StreamPosMinusValidPosEnd].
Message #
Fields #
| Name | Description |
|---|---|
pCAudioCapturePinStandardStreaming Pointer | |
ValidPositionEnd UInt64 | |
ValidPositionStart UInt64 | |
StreamPosition UInt64 | |
StreamPosMinusValidPosEnd UInt64 |
Event ID 46: KS Endpoint Glitch: STCAP Capture Behind: pCAudioCapturePinStandardStreaming=[pCAudioCapturePinStandardStreaming] ValidPosEnd=[ValidPositionEnd] ValidPosStart=[ValidPositionStart] StreamPos=[Stream...
#Description
KS Endpoint Glitch: STCAP Capture Behind: pCAudioCapturePinStandardStreaming=[pCAudioCapturePinStandardStreaming] ValidPosEnd=[ValidPositionEnd] ValidPosStart=[ValidPositionStart] StreamPos=[StreamPosition] ValidPosStartMinusStreamPos=[ValidPosStartMinusStreamPos].
Message #
Fields #
| Name | Description |
|---|---|
pCAudioCapturePinStandardStreaming Pointer | |
ValidPositionEnd UInt64 | |
ValidPositionStart UInt64 | |
StreamPosition UInt64 | |
ValidPosStartMinusStreamPos UInt64 |
Event ID 47: KS Endpoint Glitch: STCAP Device Starved: pCAudioCapturePinStandardStreaming=[pCAudioCapturePinStandardStreaming] StreamPos=[StreamPosition] FrameCount=[FrameCount].
#Event ID 48: KS Endpoint Glitch: STREN Device Starved: pCAudioRenderPinStandardStreaming=[pCAudioRenderPinStandardStreaming] DevicePos=[DevicePosition] StreamPos=[StreamPosition] AvailFrames=[AvailableFrames].
#Event ID 49: KS Endpoint Glitch: STREN EXCL PULL Invalid Buffer Count: pCAudioRenderPinStandardStreaming=[pCAudioRenderPinStandardStreaming] DevicePos=[DevicePosition] StreamPos=[StreamPosition] AvailFrames=[Av...
#Description
KS Endpoint Glitch: STREN EXCL PULL Invalid Buffer Count: pCAudioRenderPinStandardStreaming=[pCAudioRenderPinStandardStreaming] DevicePos=[DevicePosition] StreamPos=[StreamPosition] AvailFrames=[AvailableFrames].
Message #
Fields #
| Name | Description |
|---|---|
pCAudioRenderPinStandardStreaming Pointer | |
DevicePosition UInt64 | |
StreamPosition UInt64 | |
AvailableFrames UInt32 |
Event ID 50: System effect initialized: CLSID=[APOCLSID] AudioSignalProcessingMode=[AudioSignalProcessingMode] InitializeForDiscoveryOnly=[InitializeForDiscoveryOnly].
#Event ID 51: Volume limit event signalled to audiosrv enter
#Fields #
| Name | Description |
|---|---|
objectpointer Pointer |
Event ID 54: AudioSrv calls PdcActivationClientRegister
#Event ID 55: AudioSrv calls PdcActivationClientUnregister
#Event ID 56: AudioSrv calls PdcActivationClientTakeTimerReference
#Event ID 57: AudioSrv calls PdcActivationClientReleaseTimerReference
#Event ID 58: MMDevAPI: Default device changed triggered
#Fields #
| Name | Description |
|---|---|
flow UInt32 | |
role UInt32 | |
TargetProcessId UInt32 | Process ID of the target process. |
Event ID 61: MMDevAPI: DeviceStateChanged callback
#Fields #
| Name | Description |
|---|---|
object Pointer | |
NewState UInt32 |
Event ID 64: MMDevAPI: DefaultDeviceChanged callback
#Fields #
| Name | Description |
|---|---|
object Pointer | |
flow UInt32 | |
role UInt32 |
Event ID 65: MMDevAPI: Audio device state changed
#Fields #
| Name | Description |
|---|---|
DeviceName UnicodeString | |
DeviceId UnicodeString | |
flow UInt32 | |
NewState UInt32 |
Event ID 108: MidiRT: Begin binding to DeviceId: DeviceId.
#Event ID 109: MidiRT: Done binding to device interface
#Fields #
| Name | Description |
|---|---|
object Pointer | |
hResult UInt32 |
Event ID 110: MidiRT: Create new MidiPortDeviceIoControl
#Fields #
| Name | Description |
|---|---|
DeviceId UnicodeString | |
object Pointer |
Event ID 111: MidiRT: Beginning Synchronous I/O
#Fields #
| Name | Description |
|---|---|
object Pointer | |
ioControlCode UInt32 |
Event ID 113: MidiRT: Beginning Asynchronous I/O
#Fields #
| Name | Description |
|---|---|
object Pointer | |
ioControlCode UInt32 |
Event ID 114: MidiRT: Done with Asynchronous I/O
#Fields #
| Name | Description |
|---|---|
object Pointer | |
hResult UInt32 |
Event ID 115: CrossProcess packet added
#Fields #
| Name | Description |
|---|---|
CrossProcessInstance Pointer | |
ReadIndex UInt32 | |
WriteIndexIndex UInt32 | |
FramesInPacket UInt32 | |
QPC UInt64 |
Event ID 116: Pump: setting deadline
#Fields #
| Name | Description |
|---|---|
PumpInstance Pointer | |
TaskGroup UInt32 | |
SoftDeadlineHns Int64 | |
HardDeadlineHns Int64 | |
success Boolean |
Event ID 117: Pump: cancelling deadline
#Fields #
| Name | Description |
|---|---|
PumpInstance Pointer | |
TaskGroup UInt32 | |
Hns Int64 | |
success Boolean |
Event ID 118: Pump: missed deadline!
#Fields #
| Name | Description |
|---|---|
PumpInstance Pointer | |
TaskGroup UInt32 | |
Hns Int64 | |
success Boolean |
Event ID 119: Pump: Start - setting MultimediMode to AVRT_MULTIMEDIA_MODE_BUFFERING
#Fields #
| Name | Description |
|---|---|
PumpInstance Pointer | |
TaskGroup UInt32 | |
Hns Int64 | |
success Boolean |
Event ID 120: Pump: Stop - setting MultimediMode to AVRT_MULTIMEDIA_MODE_IDLE
#Fields #
| Name | Description |
|---|---|
PumpInstance Pointer | |
TaskGroup UInt32 | |
Hns Int64 | |
success Boolean |
Event ID 121: Discovering EndpointCharacteristics for [Endpoint Id].
#Event ID 122: Discovered EndpointCharacteristics for [Endpoint Id] (hr = hr).
#Event ID 123: GetMixFormat starting on endpoint [Endpoint Id] (category=category, raw=Raw, matchformat=MatchFormat, connector=ConnectorType).
#Event ID 124: GetMixFormat ended
#Event ID 125: IsFormatSupported starting on endpoint [Endpoint Id] (category=category, raw=Raw, matchformat=MatchFormat, connector=ConnectorType).
#Event ID 126: IsFormatSupported ended
#Event ID 127: Vadserver_CreateStream starting on endpoint [Endpoint Id] (category=category, raw=Raw, matchformat=MatchFormat, connector=ConnectorType).
#Event ID 128: Vadserver_CreateStream ended
#Event ID 129: Derived stream settings for stream
#Event ID 130: Created StreamGroup and stream
#Event ID 131: Created SaDevice
#Event ID 132: Connected StreamGroup to SaDevice
#Event ID 133: CreateDeviceEndpointInstance starting on endpoint [Endpoint Id] (connector=ConnectorType).
#Event ID 134: CreateDeviceEndpointInstance ended
#Event ID 135: Pump: Correct Position
#Fields #
| Name | Description |
|---|---|
PumpInstance Pointer | |
SampleIndex UInt64 | |
OrigProcessingStart UInt64 | |
NewProcessingStart UInt64 | |
StartCorrection Int64 | |
TimeDelta UInt64 | |
SampleDelta UInt32 | |
DevicePeriod UInt64 | |
ActualDevicePeriod UInt64 | |
WindowWidth_ms UInt64 |
Event ID 136: Pump: Start - Yield start
#Fields #
| Name | Description |
|---|---|
PumpInstance Pointer | |
uEventMask UInt32 |
Event ID 140: Pump: ProcPassDuration
#Fields #
| Name | Description |
|---|---|
PumpInstance Pointer | |
WorkDuration Int64 | |
MaxWorkDuration Int64 |
Event ID 142: AE Glitch
#Fields #
| Name | Description |
|---|---|
objInstance Pointer | |
ucType UInt32 | |
WritePosition Int64 | |
PlayPosition UInt64 | |
StreamPosition UInt64 | |
GlitchFrameCount UInt64 |
Event ID 143: AE Drop
#Fields #
| Name | Description |
|---|---|
objInstance Pointer | |
SampleTime UInt64 | |
u64ByteCount UInt64 |
Event ID 146: AE Position
#Fields #
| Name | Description |
|---|---|
objInstance Pointer | |
ucType UInt32 | |
WritePosition UInt64 | |
PlayPosition UInt64 | |
StreamPosition UInt64 | |
LoopPosition UInt64 |
Event ID 148: AE Data
#Fields #
| Name | Description |
|---|---|
objInstance Pointer | |
ucType UInt32 | |
Data1 UInt64 | |
Data2 UInt64 | |
Data3 UInt64 |
Event ID 149: AE IRP
#Fields #
| Name | Description |
|---|---|
objInstance Pointer | |
ucType UInt32 | |
Index UInt32 | |
OutStandingCount UInt32 | |
FrameExtent UInt64 |
Event ID 150: AE Endpoint
#Fields #
| Name | Description |
|---|---|
objInstance Pointer | |
ucType UInt32 | |
PinHandle UInt64 | |
FormatTag UInt32 | |
SampleRate UInt32 | |
BitsPerSample UInt32 | |
Channels UInt32 | |
Period UInt32 | |
Latency UInt32 | |
BufferSize UInt32 |
Event ID 151: AE Interpolator
#Fields #
| Name | Description |
|---|---|
objInstance Pointer | |
ucType UInt32 | |
InterpolatedPlayPosition UInt64 | |
InterpolatedWritePosition UInt64 | |
RealPlayPosition UInt64 | |
RealWritePosition UInt64 | |
SampleRate Float | |
FilteredError Float |
Event ID 152: AE Timestamp
#Fields #
| Name | Description |
|---|---|
objInstance Pointer | |
ucType UInt32 | |
Flag UInt64 | |
Padding UInt64 | |
QPCPos UInt64 | |
DevPos UInt64 | |
StrmPos UInt64 |
Event ID 153: AE Performance
#Fields #
| Name | Description |
|---|---|
objInstance Pointer | |
ucType UInt32 | |
Custom1 UInt64 | |
Custom2 UInt64 |
Event ID 154: AE Generic
#Fields #
| Name | Description |
|---|---|
objInstance Pointer | |
ucType UInt32 | |
u64Param1 UInt64 | |
u64Param2 UInt64 | |
u64Param3 UInt64 | |
u64Param4 UInt64 | |
f64Param1 Float | |
f64Param2 Float | |
f64Param3 Float | |
f64Param4 Float |
Event ID 155: AE Memory
#Fields #
| Name | Description |
|---|---|
objInstance Pointer | |
ucType UInt32 | |
hHeap Pointer | |
ulInitial UInt32 | |
ulMin UInt32 | |
ulMax UInt32 | |
ulAllocCount UInt32 | |
ulExtendCount UInt32 | |
ulTotalAlloc UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Audio",
"guid": "AE4BD3BE-F36F-45B6-8D21-BDD6FB832853",
"event_source_name": "",
"event_id": 155,
"version": 0,
"level": 5,
"task": 162,
"opcode": 0,
"keywords": 144115188075855872,
"time_created": "2026-03-13T20:31:02.009926+00:00",
"event_record_id": 1,
"correlation": {},
"execution": {
"process_id": 8868,
"thread_id": 1992
},
"channel": "Microsoft-Windows-Audio/Informational",
"computer": "LAB-WIN11.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"objInstance": "0x0",
"ucType": 2,
"hHeap": "0x2e0",
"ulInitial": 0,
"ulMin": 0,
"ulMax": 0,
"ulAllocCount": 0,
"ulExtendCount": 0,
"ulTotalAlloc": 0
},
"message": ""
}
Event ID 156: AE Memory
#Fields #
| Name | Description |
|---|---|
objInstance Pointer | |
ucType UInt32 | |
u64Param1 UInt64 | |
u64Param2 UInt64 | |
u64Param3 UInt64 | |
u64Param4 UInt64 |
Event ID 157: AE Memory
#Fields #
| Name | Description |
|---|---|
objInstance Pointer | |
ucType UInt32 | |
u64Param1 UInt64 | |
u64Param2 UInt64 | |
u64Param3 UInt64 | |
u64Param4 UInt64 |
Event ID 158: SetCurrentTimeStamp
#Fields #
| Name | Description |
|---|---|
objInstance Pointer | |
AEPositionFlag UInt32 | |
EndpointFlags UInt32 | |
PaddingFrames UInt64 | |
Qpc UInt64 | |
DevicePosition UInt64 | |
StreamPosition UInt64 |
Event ID 159: Writing history packet
#Fields #
| Name | Description |
|---|---|
objInstance Pointer | |
FrameCount UInt32 | |
ApoBufferFlags UInt32 | |
Qpc UInt64 |
Event ID 160: Signal pump pass completion
#Fields #
| Name | Description |
|---|---|
objInstance Pointer | |
ClientProcessId UInt32 | |
EventHandle Pointer |
Event ID 161: Pump: Processing pass skipped
#Fields #
| Name | Description |
|---|---|
objInstance Pointer | |
DurationToProcess Int64 |
Event ID 163: Pump: GetCurrentPadding Stop
#Fields #
| Name | Description |
|---|---|
PumpInstance Pointer | |
CurrentPadding UInt64 | |
DurationToProcess UInt64 |
Event ID 168: Pump: Start - skipping setting MultimediMode to AVRT_MULTIMEDIA_MODE_BUFFERING
#Fields #
| Name | Description |
|---|---|
PumpInstance Pointer | |
TaskGroup UInt32 | |
Hns Int64 | |
success Boolean |
Event ID 169: Pump: Stop - skipping setting MultimediMode to AVRT_MULTIMEDIA_MODE_IDLE
#Fields #
| Name | Description |
|---|---|
PumpInstance Pointer | |
TaskGroup UInt32 | |
Hns Int64 | |
success Boolean |
Event ID 174: Pump: Init RTMode
#Fields #
| Name | Description |
|---|---|
objInstance Pointer | |
RTMode UInt32 | |
ProAudio Boolean | |
PumpQueueID UInt32 | |
PumpTaskID UInt32 | |
APOQueueID UInt32 | |
APOTaskID UInt32 |
Event ID 175: Pump: CreateLocalWorkQueue RTMode
#Fields #
| Name | Description |
|---|---|
objInstance Pointer | |
QueueID UInt32 | |
TaskID UInt32 |
Event ID 176: Pump: GetAPOWorkqueue
#Fields #
| Name | Description |
|---|---|
objInstance Pointer | |
RTMode UInt32 | |
APOQueueID UInt32 | |
APOTaskID UInt32 |
Event ID 177: Received console locked notification
#Fields #
| Name | Description |
|---|---|
SessionId UInt32 | |
ConsoleLocked Boolean | |
ChangeInLockStatus Boolean |
Event ID 178: Global user presence detected
#Fields #
| Name | Description |
|---|---|
SessionId UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Audio",
"event_id": 178,
"level": 4,
"task": 178,
"opcode": 0,
"time_created": "2026-05-27T20:01:08.8393680+00:00",
"computer": "DESKTOP-FF3N5XK.ludus.domain",
"channel": "Microsoft-Windows-Audio"
},
"event_data": {
"SessionId": "1"
}
}
Event ID 179: Received session display notification
#Fields #
| Name | Description |
|---|---|
SessionId UInt32 | |
SessionDisplayOn Boolean | |
ChangeInSessionDisplayStatus Boolean |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Audio",
"event_id": 179,
"level": 4,
"task": 179,
"opcode": 0,
"time_created": "2026-05-27T20:01:08.8498129+00:00",
"computer": "DESKTOP-FF3N5XK.ludus.domain",
"channel": "Microsoft-Windows-Audio"
},
"event_data": {
"SessionDisplayOn": "true",
"ChangeInSessionDisplayStatus": "false",
"SessionId": "1"
}
}
Event ID 180: Received Po AudioStandby request
#Fields #
| Name | Description |
|---|---|
AudioStandbyPolicy UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Audio",
"event_id": 180,
"level": 4,
"task": 180,
"opcode": 0,
"time_created": "2026-05-27T19:31:58.6926818+00:00",
"computer": "DESKTOP-FF3N5XK.ludus.domain",
"channel": "Microsoft-Windows-Audio"
},
"event_data": {
"AudioStandbyPolicy": "1"
}
}
Provenance
ETW provider GUID ae4bd3be-f36f-45b6-8d21-bdd6fb832853
Defined in audioses.dll, which carries the event manifest.
- WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.1, captured 2026-06-02 — Manifest XML pack, 1.9 MB
- Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.1, captured 2026-06-02 — Manifest XML pack, 2.0 MB