Microsoft-Windows-DiagCpl
7 events across 1 channel
| Event | Title | Channel | Sample |
|---|---|---|---|
| 1001 | task_0 | Debug | N |
| 1002 | task_01002 | Debug | N |
| 1003 | task_01003 | Debug | N |
| 2001 | task_02001 | Debug | N |
| 2002 | task_02002 | Debug | N |
| 4000 | Begin search. | Debug | N |
| 4001 | End search. | Debug | N |
Event ID 1001: task_0
#Fields #
| Name | Description |
|---|---|
Message UnicodeString | |
FileName AnsiString | |
Function AnsiString | |
Line UInt32 | |
Result UInt32 |
Event ID 1002: task_01002
#Fields #
| Name | Description |
|---|---|
Message UnicodeString | |
FileName AnsiString | |
Function AnsiString | |
Line UInt32 | |
Result UInt32 |
Event ID 1003: task_01003
#Fields #
| Name | Description |
|---|---|
Message UnicodeString | |
FileName AnsiString | |
Function AnsiString | |
Line UInt32 | |
Result UInt32 |
Event ID 2001: task_02001
#Fields #
| Name | Description |
|---|---|
FileName AnsiString | |
Line UInt32 | |
Address Pointer | |
Size UInt32 |
Event ID 4000: Begin search.
#Event ID 4001: End search.
#Provenance
Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.
ETW provider GUID 1a396961-5f3c-4c71-8310-44c653c0bf8a
Defined in DiagCpl.dll, which carries the event manifest.
Observed on:
- WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.1, captured 2026-06-02
- Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.1, captured 2026-06-02