Microsoft-Windows-Diagnosis-PLA
48 events across 2 channels
Event ID 1000: Data collector set DataCollectorSetCreation.Name was created by DataCollectorSetCreation.UserName.
#Description
Data collector set DataCollectorSetCreation.Name was created by DataCollectorSetCreation.UserName.
Message #
Fields #
| Name | Description |
|---|---|
Name UnicodeString | |
User UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Diagnosis-PLA",
"guid": "E4D53F84-7DE3-11D8-9435-505054503030",
"event_source_name": "",
"event_id": 1000,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 9223372036854775808,
"time_created": "2026-03-13T22:03:17.259228+00:00",
"event_record_id": 1,
"correlation": {},
"execution": {
"process_id": 11200,
"thread_id": 10592
},
"channel": "Microsoft-Windows-Diagnosis-PLA/Operational",
"computer": "LAB-DC01.ludus.domain",
"security": {
"user_id": "S-1-5-21-1006758700-2167138679-1475694448-1105"
}
},
"user_data": {
"DataCollectorSetCreation": {
"Name": "TestEventCollector",
"UserName": "ludus\\domainadmin"
}
},
"message": ""
}
Event ID 1001: Data collector set DataCollectorSetEdit.Name was changed by DataCollectorSetEdit.UserName.
#Description
Data collector set DataCollectorSetEdit.Name was changed by DataCollectorSetEdit.UserName.
Message #
Fields #
| Name | Description |
|---|---|
Name UnicodeString | |
User UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Diagnosis-PLA",
"guid": "E4D53F84-7DE3-11D8-9435-505054503030",
"event_source_name": "",
"event_id": 1001,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 9223372036854775808,
"time_created": "2026-03-13T22:03:18.006697+00:00",
"event_record_id": 2,
"correlation": {},
"execution": {
"process_id": 10872,
"thread_id": 11492
},
"channel": "Microsoft-Windows-Diagnosis-PLA/Operational",
"computer": "LAB-DC01.ludus.domain",
"security": {
"user_id": "S-1-5-19"
}
},
"user_data": {
"DataCollectorSetEdit": {
"Name": "TestEventCollector",
"UserName": "NT AUTHORITY\\LOCAL SERVICE"
}
},
"message": ""
}
Event ID 1002: Data collector set DataCollectorSetDeletion.Name was deleted by DataCollectorSetDeletion.UserName.
#Description
Data collector set DataCollectorSetDeletion.Name was deleted by DataCollectorSetDeletion.UserName.
Message #
Fields #
| Name | Description |
|---|---|
Name UnicodeString | |
User UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Diagnosis-PLA",
"guid": "E4D53F84-7DE3-11D8-9435-505054503030",
"event_source_name": "",
"event_id": 1002,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 9223372036854775808,
"time_created": "2026-03-13T22:03:24.662101+00:00",
"event_record_id": 5,
"correlation": {},
"execution": {
"process_id": 8176,
"thread_id": 4812
},
"channel": "Microsoft-Windows-Diagnosis-PLA/Operational",
"computer": "LAB-DC01.ludus.domain",
"security": {
"user_id": "S-1-5-21-1006758700-2167138679-1475694448-1105"
}
},
"user_data": {
"DataCollectorSetDeletion": {
"Name": "TestEventCollector",
"UserName": "ludus\\domainadmin"
}
},
"message": ""
}
Event ID 1003: Data collector set DataCollectorSetStart.Name started as DataCollectorSetStart.UserName.
#Description
Data collector set DataCollectorSetStart.Name started as DataCollectorSetStart.UserName.
Message #
Fields #
| Name | Description |
|---|---|
Name UnicodeString | |
Key UnicodeString | |
User UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Diagnosis-PLA",
"guid": "E4D53F84-7DE3-11D8-9435-505054503030",
"event_source_name": "",
"event_id": 1003,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 9223372036854775808,
"time_created": "2026-03-13T22:03:18.022218+00:00",
"event_record_id": 3,
"correlation": {},
"execution": {
"process_id": 12224,
"thread_id": 11396
},
"channel": "Microsoft-Windows-Diagnosis-PLA/Operational",
"computer": "LAB-DC01.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"user_data": {
"DataCollectorSetStart": {
"Name": "TestEventCollector",
"Key": "0x1944_0x1eac_0x225e1a275",
"UserName": "ludus\\LAB-DC01$"
}
},
"message": ""
}
Event ID 1004: Data collector set Name failed to start as User with error code Error.
#Event ID 1005: Data collector set DataCollectorSetStop.Name stopped.
#Description
Data collector set DataCollectorSetStop.Name stopped.
Message #
Fields #
| Name | Description |
|---|---|
Name UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Diagnosis-PLA",
"guid": "E4D53F84-7DE3-11D8-9435-505054503030",
"event_source_name": "",
"event_id": 1005,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 9223372036854775808,
"time_created": "2026-03-13T22:03:23.041732+00:00",
"event_record_id": 4,
"correlation": {},
"execution": {
"process_id": 12224,
"thread_id": 5752
},
"channel": "Microsoft-Windows-Diagnosis-PLA/Operational",
"computer": "LAB-DC01.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"user_data": {
"DataCollectorSetStop": {
"Name": "TestEventCollector"
}
},
"message": ""
}
Event ID 1006: Data collector set Name stopped because of error Error.
#Event ID 1007: Data collector set Name launched task TaskName.
#Event ID 1008: Data collector set Name failed to launch task TaskName with error code Error.
#Event ID 1009: PLA upgrade failed with error code Error.
#Event ID 1010: Counter CounterName could not be added to collector Name, error code is Error.
#Event ID 1011: Configuration data collector DataCollecotrSet\Name completed.
#Event ID 1012: Data collector set Name is compiling.
#Event ID 1013: Data collector set Name segmented.
#Event ID 1014: Alert Data Collector Name in Data Collector Set DataCollecotrSet failed to start task, error code is Error.
#Event ID 1015: Alert Data Collector Name in Data Collector Set DataCollecotrSet failed to start Data Collector Set, error code is Error.
#Event ID 1016: Alert Data Collector Name in Data Collector Set DataCollecotrSet failed to write event log event, error code is Error.
#Event ID 1017: PLA failed to send cabinet file CabName to server ServerName, error code is Error.
#Event ID 2031: Message.
#Event ID 3000: Description.
#Event ID 3001: Description.
#Event ID 3002: Description.
#Event ID 5001: task_05001
#Fields #
| Name | Description |
|---|---|
BuildNumber UInt32 | |
BuildType AnsiString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Diagnosis-PLA",
"guid": "{E4D53F84-7DE3-11D8-9435-505054503030}",
"event_source_name": "",
"event_id": 5001,
"version": 0,
"level": 0,
"task": 0,
"opcode": 0,
"keywords": "0x4000000000000100",
"time_created": "2026-06-02T05:15:39.405+00:00",
"event_record_id": 0,
"correlation": {},
"execution": {
"process_id": 23132,
"thread_id": 19600
},
"channel": "ETW Trace",
"computer": "JD-DC01-2022",
"security": {
"user_id": ""
}
},
"event_data": {
"BuildNumber": 7366771,
"BuildType": ""
},
"message": ""
}
Event ID 5013: task_05013
#Fields #
| Name | Description |
|---|---|
Message UnicodeString | |
FileName AnsiString | |
Line UInt32 |
Event ID 5014: task_05014
#Fields #
| Name | Description |
|---|---|
FileName AnsiString | |
Line UInt32 | |
Address Pointer | |
Size Pointer |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Diagnosis-PLA",
"guid": "{E4D53F84-7DE3-11D8-9435-505054503030}",
"event_source_name": "",
"event_id": 5014,
"version": 0,
"level": 0,
"task": 0,
"opcode": 0,
"keywords": "0x4000000000000200",
"time_created": "2026-06-02T05:15:39.405+00:00",
"event_record_id": 0,
"correlation": {},
"execution": {
"process_id": 23132,
"thread_id": 19600
},
"channel": "ETW Trace",
"computer": "JD-DC01-2022",
"security": {
"user_id": ""
}
},
"event_data": {
"Address": "0x1A9792FB8C0",
"FileName": "",
"Line": 0,
"Size": "0x20"
},
"message": ""
}
Event ID 5015: task_05015
#Fields #
| Name | Description |
|---|---|
FileName AnsiString | |
Line UInt32 | |
Address Pointer |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Diagnosis-PLA",
"guid": "{E4D53F84-7DE3-11D8-9435-505054503030}",
"event_source_name": "",
"event_id": 5015,
"version": 0,
"level": 0,
"task": 0,
"opcode": 0,
"keywords": "0x4000000000000200",
"time_created": "2026-06-02T05:15:39.405+00:00",
"event_record_id": 0,
"correlation": {},
"execution": {
"process_id": 23132,
"thread_id": 19600
},
"channel": "ETW Trace",
"computer": "JD-DC01-2022",
"security": {
"user_id": ""
}
},
"event_data": {
"Address": "0x1A9792FB8C0",
"FileName": "",
"Line": 0
},
"message": ""
}
Event ID 5016: task_05016
#Fields #
| Name | Description |
|---|---|
FileName AnsiString | |
Line UInt32 | |
Address Pointer | |
Size Pointer |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Diagnosis-PLA",
"guid": "{E4D53F84-7DE3-11D8-9435-505054503030}",
"event_source_name": "",
"event_id": 5016,
"version": 0,
"level": 0,
"task": 0,
"opcode": 0,
"keywords": "0x4000000000000200",
"time_created": "2026-06-02T05:15:39.407+00:00",
"event_record_id": 0,
"correlation": {},
"execution": {
"process_id": 23132,
"thread_id": 19600
},
"channel": "ETW Trace",
"computer": "JD-DC01-2022",
"security": {
"user_id": ""
}
},
"event_data": {
"Address": "0x1A97930B850",
"FileName": "",
"Line": 0,
"Size": "0x1098"
},
"message": ""
}
Event ID 5017: task_05017
#Fields #
| Name | Description |
|---|---|
FileName AnsiString | |
Line UInt32 | |
Address Pointer |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Diagnosis-PLA",
"guid": "{E4D53F84-7DE3-11D8-9435-505054503030}",
"event_source_name": "",
"event_id": 5017,
"version": 0,
"level": 0,
"task": 0,
"opcode": 0,
"keywords": "0x4000000000000200",
"time_created": "2026-06-02T05:15:39.408+00:00",
"event_record_id": 0,
"correlation": {},
"execution": {
"process_id": 23132,
"thread_id": 19600
},
"channel": "ETW Trace",
"computer": "JD-DC01-2022",
"security": {
"user_id": ""
}
},
"event_data": {
"Address": "0x1A97930C8F0",
"FileName": "",
"Line": 0
},
"message": ""
}
Event ID 5018: task_05018
#Fields #
| Name | Description |
|---|---|
FileName AnsiString | |
Line UInt32 | |
Address Pointer | |
Size Pointer | |
OrigAddress Pointer |
Event ID 5019: task_05019
#Fields #
| Name | Description |
|---|---|
FileName AnsiString | |
Line UInt32 | |
Address Pointer | |
Size Pointer |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Diagnosis-PLA",
"guid": "{E4D53F84-7DE3-11D8-9435-505054503030}",
"event_source_name": "",
"event_id": 5019,
"version": 0,
"level": 0,
"task": 0,
"opcode": 0,
"keywords": "0x4000000000000200",
"time_created": "2026-06-02T05:15:39.406+00:00",
"event_record_id": 0,
"correlation": {},
"execution": {
"process_id": 23132,
"thread_id": 19600
},
"channel": "ETW Trace",
"computer": "JD-DC01-2022",
"security": {
"user_id": ""
}
},
"event_data": {
"Address": "0x1A979309AB8",
"FileName": "",
"Line": 0,
"Size": "0x28"
},
"message": ""
}
Event ID 5020: task_05020
#Fields #
| Name | Description |
|---|---|
FileName AnsiString | |
Line UInt32 | |
Address Pointer |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Diagnosis-PLA",
"guid": "{E4D53F84-7DE3-11D8-9435-505054503030}",
"event_source_name": "",
"event_id": 5020,
"version": 0,
"level": 0,
"task": 0,
"opcode": 0,
"keywords": "0x4000000000000200",
"time_created": "2026-06-02T05:15:39.407+00:00",
"event_record_id": 0,
"correlation": {},
"execution": {
"process_id": 23132,
"thread_id": 19600
},
"channel": "ETW Trace",
"computer": "JD-DC01-2022",
"security": {
"user_id": ""
}
},
"event_data": {
"Address": "0x1A9792FF6B8",
"FileName": "",
"Line": 0
},
"message": ""
}
Event ID 5021: task_05021
#Fields #
| Name | Description |
|---|---|
Name AnsiString | |
Address Pointer |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Diagnosis-PLA",
"guid": "{E4D53F84-7DE3-11D8-9435-505054503030}",
"event_source_name": "",
"event_id": 5021,
"version": 0,
"level": 0,
"task": 0,
"opcode": 0,
"keywords": "0x4000000000000400",
"time_created": "2026-06-02T05:15:39.405+00:00",
"event_record_id": 0,
"correlation": {},
"execution": {
"process_id": 23132,
"thread_id": 19600
},
"channel": "ETW Trace",
"computer": "JD-DC01-2022",
"security": {
"user_id": ""
}
},
"event_data": {
"Address": "0x1A9792FEC90",
"Name": "struct IDataCollectorSet"
},
"message": ""
}
Event ID 5022: task_05022
#Fields #
| Name | Description |
|---|---|
Name AnsiString | |
Address Pointer |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Diagnosis-PLA",
"guid": "{E4D53F84-7DE3-11D8-9435-505054503030}",
"event_source_name": "",
"event_id": 5022,
"version": 0,
"level": 0,
"task": 0,
"opcode": 0,
"keywords": "0x4000000000000400",
"time_created": "2026-06-02T05:15:39.407+00:00",
"event_record_id": 0,
"correlation": {},
"execution": {
"process_id": 23132,
"thread_id": 19600
},
"channel": "ETW Trace",
"computer": "JD-DC01-2022",
"security": {
"user_id": ""
}
},
"event_data": {
"Address": "0x1A9792ECD30",
"Name": "struct IEnumVARIANT"
},
"message": ""
}
Event ID 5023: task_05023
#Fields #
| Name | Description |
|---|---|
Name AnsiString | |
Address Pointer | |
RefCount UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Diagnosis-PLA",
"guid": "{E4D53F84-7DE3-11D8-9435-505054503030}",
"event_source_name": "",
"event_id": 5023,
"version": 0,
"level": 0,
"task": 0,
"opcode": 0,
"keywords": "0x4000000000000400",
"time_created": "2026-06-02T05:15:39.405+00:00",
"event_record_id": 0,
"correlation": {},
"execution": {
"process_id": 23132,
"thread_id": 19600
},
"channel": "ETW Trace",
"computer": "JD-DC01-2022",
"security": {
"user_id": ""
}
},
"event_data": {
"Address": "0x1A9792FEC90",
"Name": "struct IDataCollectorSet",
"RefCount": 2
},
"message": ""
}
Event ID 5024: task_05024
#Fields #
| Name | Description |
|---|---|
Name AnsiString | |
Address Pointer | |
RefCount UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Diagnosis-PLA",
"guid": "{E4D53F84-7DE3-11D8-9435-505054503030}",
"event_source_name": "",
"event_id": 5024,
"version": 0,
"level": 0,
"task": 0,
"opcode": 0,
"keywords": "0x4000000000000400",
"time_created": "2026-06-02T05:15:39.405+00:00",
"event_record_id": 0,
"correlation": {},
"execution": {
"process_id": 23132,
"thread_id": 19600
},
"channel": "ETW Trace",
"computer": "JD-DC01-2022",
"security": {
"user_id": ""
}
},
"event_data": {
"Address": "0x1A9792FEC90",
"Name": "struct IDataCollectorSet",
"RefCount": 1
},
"message": ""
}
Event ID 5025: task_05025
#Fields #
| Name | Description |
|---|---|
Name AnsiString | |
Address Pointer | |
RefCount UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Diagnosis-PLA",
"guid": "{E4D53F84-7DE3-11D8-9435-505054503030}",
"event_source_name": "",
"event_id": 5025,
"version": 0,
"level": 0,
"task": 0,
"opcode": 0,
"keywords": "0x4000000000000400",
"time_created": "2026-06-02T05:15:39.405+00:00",
"event_record_id": 0,
"correlation": {},
"execution": {
"process_id": 23132,
"thread_id": 19600
},
"channel": "ETW Trace",
"computer": "JD-DC01-2022",
"security": {
"user_id": ""
}
},
"event_data": {
"Address": "0x1A9792FEC90",
"Name": "CDataCollectorSet::Query",
"RefCount": 1
},
"message": ""
}
Event ID 5026: task_05026
#Fields #
| Name | Description |
|---|---|
Error UInt32 | |
FileName AnsiString | |
Line UInt32 | |
Function AnsiString | |
User UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Diagnosis-PLA",
"guid": "{E4D53F84-7DE3-11D8-9435-505054503030}",
"event_source_name": "",
"event_id": 5026,
"version": 0,
"level": 0,
"task": 0,
"opcode": 0,
"keywords": "0x4000000000000800",
"time_created": "2026-06-02T05:15:39.407+00:00",
"event_record_id": 0,
"correlation": {},
"execution": {
"process_id": 23132,
"thread_id": 19600
},
"channel": "ETW Trace",
"computer": "JD-DC01-2022",
"security": {
"user_id": ""
}
},
"event_data": {
"Error": 2147943568,
"FileName": "",
"Function": "Enumerator::GetNamedItem",
"Line": 0,
"User": "ludus\\domainadmin"
},
"message": ""
}
Provenance
Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.
ETW provider GUID {E4D53F84-7DE3-11D8-9435-505054503030}
Defined in pla.dll, which carries the event manifest.
Observed on:
- WS2022-20348.4893, sample captured from a live trace, binary version 10.0.20348.1, captured 2026-06-02
- WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.1, captured 2026-06-02
- Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.1, captured 2026-06-02