Microsoft-Windows-Diagnostics-Performance

113 events across 3 channels

EventTitleChannelSample
100Windows has started up.OperationalY
101This application took longer than usual to start up, resulting in a performance …OperationalY
102This driver took longer to initialize, resulting in a performance degradation in …OperationalY
103This startup service took longer than expected to startup, resulting in a …OperationalY
104Core system took longer to initialize, resulting in a performance degradation in …OperationalN
105Foreground optimizations (prefetching) took longer to complete, resulting in a …OperationalN
106Background optimizations (prefetching) took longer to complete, resulting in a …OperationalN
107Application of machine policy caused a slow down in the system start up process.OperationalY
108Application of user policy caused a slow down in the system start up process.OperationalN
109This device took longer to initialize, resulting in a performance degradation in …OperationalN
110Session manager initialization caused a slow down in the startup process.OperationalY
200Windows has shutdown.OperationalY
201This application caused a delay in the system shutdown process.OperationalN
202This device caused a delay in the system shutdown process.OperationalN
203This service caused a delay in the system shutdown process.OperationalY
300Windows has resumed from standby.OperationalN
301This application caused a delay during standby.OperationalN
302This driver caused a delay during standby while servicing a device.OperationalN
303This service caused a delay during hybrid-sleep.OperationalN
304Creation of the hiber-file was slower than expected.OperationalN
305Persisting disk caches was slower than expected.OperationalN
306Preparing the video subsystem for sleep was slower than expected.OperationalN
307Preparing Winlogon for sleep was slower than expected.OperationalN
308Preparing system memory for sleep was slower than expected.OperationalN
309Preparing core system for sleep was slower than expected.OperationalN
310Preparing system worker threads for sleep was slower than expected.OperationalN
350Bios initialization time was greater than 250ms (logo requirement) during system …OperationalN
351This driver responded slower than expected to the resume request while servicing …OperationalN
352Reading the hiber-file was slower than expected.OperationalN
400Information about the system performance monitoring event.OperationalN
401This process is using up processor time and is impacting the performance of …OperationalN
402This process is doing excessive disk activities and is impacting the performance …OperationalN
403This driver is using up too many resources and is impacting the performance of …OperationalN
404This driver is waiting longer than expected on a device.OperationalN
405This file is fragmented and is impacting the performance of Windows.OperationalN
406Disk IO to this file is taking longer than expected.OperationalN
407This process is using up too much system memory.OperationalN
408Many processes are using too much system memory.OperationalN
500The Desktop Window Manager is experiencing heavy resource contention.OperationalN
501The Desktop Window Manager is experiencing heavy resource contention.OperationalN
1001StatusDiagnosticN
1002StatusDiagnosticN
1003StatusDiagnosticN
1005StatusDiagnosticN
1006StatusDiagnosticN
1007StatusDiagnosticN
1010StatusDiagnosticN
1011StatusDiagnosticN
1012StatusDiagnosticN
1013StatusDiagnosticN
1014StatusDiagnosticN
1015StatusDiagnosticN
1020StatusDiagnosticN
1022StatusDiagnosticN
1024StatusDiagnosticN
1025StatusDiagnosticN
1026StatusDiagnosticN
1027StatusDiagnosticN
1028StatusDiagnosticN
1029StatusDiagnosticN
1030StatusDiagnosticN
1031StatusDiagnosticN
2001StatusDiagnosticN
2002StatusDiagnosticN
2003StatusDiagnosticN
2004StatusDiagnosticN
2005StatusDiagnosticN
2006StatusDiagnosticN
2007StatusDiagnosticN
2008StatusDiagnosticN
2009StatusDiagnosticN
2010StatusDiagnosticN
2011StatusDiagnosticN
2012StatusDiagnosticN
2013StatusDiagnosticN
2014StatusDiagnosticN
2015StatusDiagnosticN
2016StatusDiagnosticN
7001StatusLoopbackN
7101StatusLoopbackN
7102StatusLoopbackN
7103StatusLoopbackN
7104StatusLoopbackN
7105StatusLoopbackN
7106StatusLoopbackN
8001StatusDiagnosticN
8002StatusDiagnosticN
8003StatusDiagnosticN
8004StatusDiagnosticN
8005StatusDiagnosticN
8006StatusDiagnosticN
8007StatusDiagnosticN
8008StatusDiagnosticN
8009StatusDiagnosticN
8010StatusDiagnosticN
8011StatusDiagnosticN
8012StatusDiagnosticN
8013StatusDiagnosticN
9001StatusDiagnosticN
9003StatusDiagnosticN
9005StatusDiagnosticN
9007StatusDiagnosticN
9009StatusDiagnosticN
9011StatusDiagnosticN
9012StatusDiagnosticN
9013StatusDiagnosticN
9015StatusDiagnosticN
10001StatusLoopbackN
11001Standby_ReceivedEventDiagnosticN
11002Standby_ChangedStateDiagnosticN
11003Standby_FailedTransitionDiagnosticN
11005Standby_DetectRegressionsStartDiagnosticN
11006Standby_DetectRegressionsStopDiagnosticN

Event ID 100: Windows has started up.

#
Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Operational
Level
Critical
Task
BootPerformanceMonitoring
Opcode
BootInformation

Description

Windows has started up.

Message #

Windows has started up: 

     Boot Duration		: %6ms

     IsDegradation		: %26

     Incident Time (UTC)	: %2

Fields #

NameDescription
BootTsVersion UInt32
BootStartTime FILETIME
BootEndTime FILETIME
SystemBootInstance UInt32
UserBootInstance UInt32
BootTime UInt32
MainPathBootTime UInt32
BootKernelInitTime UInt32
BootDriverInitTime UInt32
BootDevicesInitTime UInt32
BootPrefetchInitTime UInt32
BootPrefetchBytes UInt32
BootAutoChkTime UInt32
BootSmssInitTime UInt32
BootCriticalServicesInitTime UInt32
BootUserProfileProcessingTime UInt32
BootMachineProfileProcessingTime UInt32
BootExplorerInitTime UInt32
BootNumStartupApps UInt32
BootPostBootTime UInt32
BootIsRebootAfterInstall Boolean
BootRootCauseStepImprovementBits UInt32
BootRootCauseGradualImprovementBits UInt32
BootRootCauseStepDegradationBits UInt32
BootRootCauseGradualDegradationBits UInt32
BootIsDegradation Boolean
BootIsStepDegradation Boolean
BootIsGradualDegradation Boolean
BootImprovementDelta UInt32
BootDegradationDelta UInt32
BootIsRootCauseIdentified Boolean
OSLoaderDuration UInt32
BootPNPInitStartTimeMS UInt32
BootPNPInitDuration UInt32
OtherKernelInitDuration UInt32
SystemPNPInitStartTimeMS UInt32
SystemPNPInitDuration UInt32
SessionInitStartTimeMS UInt32
Session0InitDuration UInt32
Session1InitDuration UInt32
SessionInitOtherDuration UInt32
WinLogonStartTimeMS UInt32
OtherLogonInitActivityDuration UInt32
UserLogonWaitDuration UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Diagnostics-Performance",
    "guid": "CFC18EC0-96B1-4EBA-961B-622CAEE05B0A",
    "event_source_name": "",
    "event_id": 100,
    "version": 2,
    "level": 1,
    "task": 4002,
    "opcode": 34,
    "keywords": 9223372036854841344,
    "time_created": "2023-11-05T22:33:58.036254+00:00",
    "event_record_id": 38,
    "correlation": {
      "ActivityID": "E4DB489E-1037-0003-0982-DBE43710DA01"
    },
    "execution": {
      "process_id": 3160,
      "thread_id": 3556
    },
    "channel": "Microsoft-Windows-Diagnostics-Performance/Operational",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-19"
    }
  },
  "event_data": {
    "BootTsVersion": 2,
    "BootStartTime": "2023-11-05T22:32:00.970725Z",
    "BootEndTime": "2023-11-05T22:33:56.389945Z",
    "SystemBootInstance": 8,
    "UserBootInstance": 2,
    "BootTime": 110680,
    "MainPathBootTime": 34629,
    "BootKernelInitTime": 164,
    "BootDriverInitTime": 1567,
    "BootDevicesInitTime": 2810,
    "BootPrefetchInitTime": 0,
    "BootPrefetchBytes": 0,
    "BootAutoChkTime": 0,
    "BootSmssInitTime": 6391,
    "BootCriticalServicesInitTime": 1441,
    "BootUserProfileProcessingTime": 1084,
    "BootMachineProfileProcessingTime": 456,
    "BootExplorerInitTime": 18858,
    "BootNumStartupApps": 3,
    "BootPostBootTime": 76051,
    "BootIsRebootAfterInstall": false,
    "BootRootCauseStepImprovementBits": 0,
    "BootRootCauseGradualImprovementBits": 0,
    "BootRootCauseStepDegradationBits": 13631488,
    "BootRootCauseGradualDegradationBits": 13631488,
    "BootIsDegradation": true,
    "BootIsStepDegradation": true,
    "BootIsGradualDegradation": true,
    "BootImprovementDelta": 0,
    "BootDegradationDelta": 68995,
    "BootIsRootCauseIdentified": true,
    "OSLoaderDuration": 3107,
    "BootPNPInitStartTimeMS": 164,
    "BootPNPInitDuration": 4163,
    "OtherKernelInitDuration": 445,
    "SystemPNPInitStartTimeMS": 4495,
    "SystemPNPInitDuration": 1301,
    "SessionInitStartTimeMS": 5910,
    "Session0InitDuration": 1013,
    "Session1InitDuration": 219,
    "SessionInitOtherDuration": 5158,
    "WinLogonStartTimeMS": 12302,
    "OtherLogonInitActivityDuration": 1926,
    "UserLogonWaitDuration": 4739
  },
  "message": ""
}

References #

Event ID 101: This application took longer than usual to start up, resulting in a performance degradation in the system startup process.

#
Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Operational
Level
Warning
Task
BootPerformanceMonitoring
Opcode
BootDegradation

Description

This application took longer than usual to start up, resulting in a performance degradation in the system startup process.

Message #

This application took longer than usual to start up, resulting in a performance degradation in the system startup process: 

     File Name		: %3

     Friendly Name		: %5

     Version		: %7

     Total Time		: %8ms

     Degradation Time	: %9ms

     Incident Time (UTC)	: %1

Fields #

NameDescription
StartTime FILETIME
NameLength UInt32
Name UnicodeString
FriendlyNameLength UInt32
FriendlyName UnicodeString
VersionLength UInt32
Version UnicodeString
TotalTime UInt32
DegradationTime UInt32
PathLength UInt32
Path UnicodeString
ProductNameLength UInt32
ProductName UnicodeString
CompanyNameLength UInt32
CompanyName UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Diagnostics-Performance",
    "guid": "CFC18EC0-96B1-4EBA-961B-622CAEE05B0A",
    "event_source_name": "",
    "event_id": 101,
    "version": 1,
    "level": 3,
    "task": 4002,
    "opcode": 33,
    "keywords": 9223372036854841344,
    "time_created": "2023-11-05T22:33:58.036338+00:00",
    "event_record_id": 44,
    "correlation": {
      "ActivityID": "E4DB489E-1037-0003-0982-DBE43710DA01"
    },
    "execution": {
      "process_id": 3160,
      "thread_id": 3556
    },
    "channel": "Microsoft-Windows-Diagnostics-Performance/Operational",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-19"
    }
  },
  "event_data": {
    "StartTime": "2023-11-05T22:32:00.970725Z",
    "NameLength": 28,
    "Name": "StartMenuExperienceHost.exe",
    "FriendlyNameLength": 30,
    "FriendlyName": "Windows Start Experience Host",
    "VersionLength": 39,
    "Version": "10.0.22621.2361 (WinBuild.160101.0800)",
    "TotalTime": 6125,
    "DegradationTime": 3625,
    "PathLength": 106,
    "Path": "C:\\Windows\\SystemApps\\Microsoft.Windows.StartMenuExperienceHost_cw5n1h2txyewy\\StartMenuExperienceHost.exe",
    "ProductNameLength": 37,
    "ProductName": "Microsoft® Windows® Operating System",
    "CompanyNameLength": 22,
    "CompanyName": "Microsoft Corporation"
  },
  "message": ""
}

References #

Event ID 102: This driver took longer to initialize, resulting in a performance degradation in the system start up process.

#
Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Operational
Level
Warning
Task
BootPerformanceMonitoring
Opcode
BootDegradation

Description

This driver took longer to initialize, resulting in a performance degradation in the system start up process.

Message #

This driver took longer to initialize, resulting in a performance degradation in the system start up process: 

     File Name		: %3

     Friendly Name		: %5

     Version		: %7

     Total Time		: %8ms

     Degradation Time	: %9ms

     Incident Time (UTC)	: %1

Fields #

NameDescription
StartTime FILETIME
NameLength UInt32
Name UnicodeString
FriendlyNameLength UInt32
FriendlyName UnicodeString
VersionLength UInt32
Version UnicodeString
TotalTime UInt32
DegradationTime UInt32
PathLength UInt32
Path UnicodeString
ProductNameLength UInt32
ProductName UnicodeString
CompanyNameLength UInt32
CompanyName UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Diagnostics-Performance",
    "guid": "CFC18EC0-96B1-4EBA-961B-622CAEE05B0A",
    "event_source_name": "",
    "event_id": 102,
    "version": 1,
    "level": 3,
    "task": 4002,
    "opcode": 33,
    "keywords": 9223372036854841344,
    "time_created": "2023-10-25T22:05:44.601509+00:00",
    "event_record_id": 25,
    "correlation": {
      "ActivityID": "028F2288-078F-0001-413E-8F028F07DA01"
    },
    "execution": {
      "process_id": 2484,
      "thread_id": 3796
    },
    "channel": "Microsoft-Windows-Diagnostics-Performance/Operational",
    "computer": "WinDevEval",
    "security": {
      "user_id": "S-1-5-19"
    }
  },
  "event_data": {
    "StartTime": "2023-10-25T22:02:56.552302Z",
    "NameLength": 7,
    "Name": "VfpExt",
    "FriendlyNameLength": 30,
    "FriendlyName": "Microsoft Azure VFP Extension",
    "VersionLength": 36,
    "Version": "10.0.22621.1 (WinBuild.160101.0800)",
    "TotalTime": 8403,
    "DegradationTime": 6903,
    "PathLength": 39,
    "Path": "C:\\Windows\\system32\\drivers\\vfpext.sys",
    "ProductNameLength": 37,
    "ProductName": "Microsoft® Windows® Operating System",
    "CompanyNameLength": 22,
    "CompanyName": "Microsoft Corporation"
  },
  "message": ""
}

References #

Event ID 103: This startup service took longer than expected to startup, resulting in a performance degradation in the system start up process.

#
Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Operational
Level
Warning
Task
BootPerformanceMonitoring
Opcode
BootDegradation

Description

This startup service took longer than expected to startup, resulting in a performance degradation in the system start up process.

Message #

This startup service took longer than expected to startup, resulting in a performance degradation in the system start up process: 

     File Name		: %3

     Friendly Name		: %5

     Version		: %7

     Total Time		: %8ms

     Degradation Time	: %9ms

     Incident Time (UTC)	: %1

Fields #

NameDescription
StartTime FILETIME
NameLength UInt32
Name UnicodeString
FriendlyNameLength UInt32
FriendlyName UnicodeString
VersionLength UInt32
Version UnicodeString
TotalTime UInt32
DegradationTime UInt32
PathLength UInt32
Path UnicodeString
ProductNameLength UInt32
ProductName UnicodeString
CompanyNameLength UInt32
CompanyName UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Diagnostics-Performance",
    "guid": "{CFC18EC0-96B1-4EBA-961B-622CAEE05B0A}",
    "event_source_name": "",
    "event_id": 103,
    "version": 1,
    "level": 3,
    "task": 4002,
    "opcode": 33,
    "keywords": -9223372036854710272,
    "time_created": "2026-03-17T18:15:25.9842765+00:00",
    "event_record_id": 61,
    "correlation": {
      "ActivityID": "{B96DB0BB-B639-000A-71BF-6DB939B6DC01}"
    },
    "execution": {
      "process_id": 3740,
      "thread_id": 4612
    },
    "channel": "Microsoft-Windows-Diagnostics-Performance/Operational",
    "computer": "JD-WIN11-22H2-1.ludus.domain",
    "security": {
      "user_id": "S-1-5-19"
    }
  },
  "event_data": {
    "StartTime": "2026-03-17T18:13:15.4645682Z",
    "NameLength": "10",
    "Name": "windefend",
    "FriendlyNameLength": "0",
    "FriendlyName": "",
    "VersionLength": "0",
    "Version": "",
    "TotalTime": "326",
    "DegradationTime": "234",
    "PathLength": "80",
    "Path": "\"c:\\programdata\\microsoft\\windows defender\\platform\\4.18.26010.5-0\\msmpeng.exe\"",
    "ProductNameLength": "0",
    "ProductName": "",
    "CompanyNameLength": "0",
    "CompanyName": ""
  },
  "message": "This startup service took longer than expected to startup, resulting in a performance degradation in the system start up process: \r\n     File Name\t\t:\twindefend\r\n     Friendly Name\t\t:\t\r\n     Version\t\t:\t\r\n     Total Time\t\t:\t326ms\r\n     Degradation Time\t:\t234ms\r\n     Incident Time (UTC)\t:\t‎2026‎-‎03‎-‎17T18:13:15.464568200Z"
}

Event ID 104: Core system took longer to initialize, resulting in a performance degradation in the system start up process.

#
Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Operational
Task
BootPerformanceMonitoring
Opcode
BootDegradation

Description

Core system took longer to initialize, resulting in a performance degradation in the system start up process.

Message #

Core system took longer to initialize, resulting in a performance degradation in the system start up process: 

     Name		: %3

     Total Time		: %4ms

     Degradation Time	: %5ms

     Incident Time (UTC)	: %1

Fields #

NameDescription
StartTime FILETIME
NameLength UInt32
Name UnicodeString
TotalTime UInt32
DegradationTime UInt32

Event ID 105: Foreground optimizations (prefetching) took longer to complete, resulting in a performance degradation in the system start up process.

#
Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Operational
Task
BootPerformanceMonitoring
Opcode
BootDegradation

Description

Foreground optimizations (prefetching) took longer to complete, resulting in a performance degradation in the system start up process.

Message #

Foreground optimizations (prefetching) took longer to complete, resulting in a performance degradation in the system start up process: 

     Name		: %3

     Total Time		: %4ms

     Degradation Time	: %5ms

     Incident Time (UTC)	: %1

Fields #

NameDescription
StartTime FILETIME
NameLength UInt32
Name UnicodeString
TotalTime UInt32
DegradationTime UInt32

Event ID 106: Background optimizations (prefetching) took longer to complete, resulting in a performance degradation in the system start up process.

#
Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Operational
Task
BootPerformanceMonitoring
Opcode
BootDegradation

Description

Background optimizations (prefetching) took longer to complete, resulting in a performance degradation in the system start up process.

Message #

Background optimizations (prefetching) took longer to complete, resulting in a performance degradation in the system start up process: 

     Name		: %3

     Total Time		: %4ms

     Degradation Time	: %5ms

     Incident Time (UTC)	: %1

Fields #

NameDescription
StartTime FILETIME
NameLength UInt32
Name UnicodeString
TotalTime UInt32
DegradationTime UInt32

Event ID 107: Application of machine policy caused a slow down in the system start up process.

#
Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Operational
Level
Warning
Task
BootPerformanceMonitoring
Opcode
BootDegradation

Description

Application of machine policy caused a slow down in the system start up process.

Message #

Application of machine policy caused a slow down in the system start up process: 

     Name		: %3

     Total Time		: %4ms

     Degradation Time	: %5ms

     Incident Time (UTC)	: %1

Fields #

NameDescription
StartTime FILETIME
NameLength UInt32
Name UnicodeString
TotalTime UInt32
DegradationTime UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Diagnostics-Performance",
    "guid": "CFC18EC0-96B1-4EBA-961B-622CAEE05B0A",
    "event_source_name": "",
    "event_id": 107,
    "version": 1,
    "level": 3,
    "task": 4002,
    "opcode": 33,
    "keywords": 9223372036854841344,
    "time_created": "2026-02-10T04:13:48.386918+00:00",
    "event_record_id": 13,
    "correlation": {
      "ActivityID": "43A6D212-9A2A-0007-EC4C-A7432A9ADC01"
    },
    "execution": {
      "process_id": 3924,
      "thread_id": 4184
    },
    "channel": "Microsoft-Windows-Diagnostics-Performance/Operational",
    "computer": "LAB-WIN11.ludus.domain",
    "security": {
      "user_id": "S-1-5-19"
    }
  },
  "event_data": {
    "StartTime": "2026-02-10T01:12:02.866821Z",
    "NameLength": 25,
    "Name": "MachinePolicyApplication",
    "TotalTime": 2121,
    "DegradationTime": 1121
  },
  "message": ""
}

Event ID 108: Application of user policy caused a slow down in the system start up process.

#
Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Operational
Task
BootPerformanceMonitoring
Opcode
BootDegradation

Description

Application of user policy caused a slow down in the system start up process.

Message #

Application of user policy caused a slow down in the system start up process: 

     Name		: %3

     Total Time		: %4ms

     Degradation Time	: %5ms

     Incident Time (UTC)	: %1

Fields #

NameDescription
StartTime FILETIME
NameLength UInt32
Name UnicodeString
TotalTime UInt32
DegradationTime UInt32

Event ID 109: This device took longer to initialize, resulting in a performance degradation in the system start up process.

#
Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Operational
Task
BootPerformanceMonitoring
Opcode
BootDegradation

Description

This device took longer to initialize, resulting in a performance degradation in the system start up process.

Message #

This device took longer to initialize, resulting in a performance degradation in the system start up process: 

     File Name		: %3

     Friendly Name		: %5

     Version		: %7

     Total Time		: %8ms

     Degradation Time	: %9ms

     Incident Time (UTC)	: %1

Fields #

NameDescription
StartTime FILETIME
NameLength UInt32
Name UnicodeString
FriendlyNameLength UInt32
FriendlyName UnicodeString
VersionLength UInt32
Version UnicodeString
TotalTime UInt32
DegradationTime UInt32
PathLength UInt32
Path UnicodeString
ProductNameLength UInt32
ProductName UnicodeString
CompanyNameLength UInt32
CompanyName UnicodeString

Event ID 110: Session manager initialization caused a slow down in the startup process.

#
Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Operational
Level
Warning
Task
BootPerformanceMonitoring
Opcode
BootDegradation

Description

Session manager initialization caused a slow down in the startup process.

Message #

Session manager initialization caused a slow down in the startup process: 

     Name		: %3

     Total Time		: %4ms

     Degradation Time	: %5ms

     Incident Time (UTC)	: %1

Fields #

NameDescription
StartTime FILETIME
NameLength UInt32
Name UnicodeString
TotalTime UInt32
DegradationTime UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Diagnostics-Performance",
    "guid": "CFC18EC0-96B1-4EBA-961B-622CAEE05B0A",
    "event_source_name": "",
    "event_id": 110,
    "version": 1,
    "level": 3,
    "task": 4002,
    "opcode": 33,
    "keywords": 9223372036854841344,
    "time_created": "2023-10-25T22:05:44.601513+00:00",
    "event_record_id": 26,
    "correlation": {
      "ActivityID": "028F2288-078F-0001-413E-8F028F07DA01"
    },
    "execution": {
      "process_id": 2484,
      "thread_id": 3796
    },
    "channel": "Microsoft-Windows-Diagnostics-Performance/Operational",
    "computer": "WinDevEval",
    "security": {
      "user_id": "S-1-5-19"
    }
  },
  "event_data": {
    "StartTime": "2023-10-25T22:02:56.552302Z",
    "NameLength": 9,
    "Name": "SMSSInit",
    "TotalTime": 17567,
    "DegradationTime": 7567
  },
  "message": ""
}

References #

Event ID 200: Windows has shutdown.

#
Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Operational
Level
Warning
Task
ShutdownPerformanceMonitoring
Opcode
ShutdownInformation

Description

Windows has shutdown.

Message #

Windows has shutdown: 

     Shutdown Duration	: %4ms

     IsDegradation		: %16

     Incident Time (UTC)	: %2

Fields #

NameDescription
ShutdownTsVersion UInt32
ShutdownStartTime FILETIME
ShutdownEndTime FILETIME
ShutdownTime UInt32
ShutdownUserSessionTime UInt32
ShutdownUserPolicyTime UInt32
ShutdownUserProfilesTime UInt32
ShutdownSystemSessionsTime UInt32
ShutdownPreShutdownNotificationsTime UInt32
ShutdownServicesTime UInt32
ShutdownKernelTime UInt32
ShutdownRootCauseStepImprovementBits UInt32
ShutdownRootCauseGradualImprovementBits UInt32
ShutdownRootCauseStepDegradationBits UInt32
ShutdownRootCauseGradualDegradationBits UInt32
ShutdownIsDegradation Boolean
ShutdownTimeChange Int32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Diagnostics-Performance",
    "guid": "CFC18EC0-96B1-4EBA-961B-622CAEE05B0A",
    "event_source_name": "",
    "event_id": 200,
    "version": 1,
    "level": 3,
    "task": 4007,
    "opcode": 40,
    "keywords": 9223372036854841344,
    "time_created": "2023-11-05T22:33:56.991516+00:00",
    "event_record_id": 36,
    "correlation": {
      "ActivityID": "E4DB489E-1037-0001-FD89-DBE43710DA01"
    },
    "execution": {
      "process_id": 3160,
      "thread_id": 3468
    },
    "channel": "Microsoft-Windows-Diagnostics-Performance/Operational",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-19"
    }
  },
  "event_data": {
    "ShutdownTsVersion": 1,
    "ShutdownStartTime": "2023-11-05T22:31:30.287074Z",
    "ShutdownEndTime": "2023-11-05T22:31:43.106260Z",
    "ShutdownTime": 12819,
    "ShutdownUserSessionTime": 3778,
    "ShutdownUserPolicyTime": 17,
    "ShutdownUserProfilesTime": 236,
    "ShutdownSystemSessionsTime": 6148,
    "ShutdownPreShutdownNotificationsTime": 1596,
    "ShutdownServicesTime": 4185,
    "ShutdownKernelTime": 2892,
    "ShutdownRootCauseStepImprovementBits": 0,
    "ShutdownRootCauseGradualImprovementBits": 0,
    "ShutdownRootCauseStepDegradationBits": 72,
    "ShutdownRootCauseGradualDegradationBits": 0,
    "ShutdownIsDegradation": true,
    "ShutdownTimeChange": 0
  },
  "message": ""
}

References #

Event ID 201: This application caused a delay in the system shutdown process.

#
Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Operational
Task
ShutdownPerformanceMonitoring
Opcode
ShutdownDegradation

Description

This application caused a delay in the system shutdown process.

Message #

This application caused a delay in the system shutdown process: 

     File Name		: %3

     Friendly Name		: %5

     Version		: %7

     Total Time		: %8ms

     Degradation Time	: %9ms

     Incident Time (UTC)	: %1

Fields #

NameDescription
StartTime FILETIME
NameLength UInt32
Name UnicodeString
FriendlyNameLength UInt32
FriendlyName UnicodeString
VersionLength UInt32
Version UnicodeString
TotalTime UInt32
DegradationTime UInt32
PathLength UInt32
Path UnicodeString
ProductNameLength UInt32
ProductName UnicodeString
CompanyNameLength UInt32
CompanyName UnicodeString

Event ID 202: This device caused a delay in the system shutdown process.

#
Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Operational
Task
ShutdownPerformanceMonitoring
Opcode
ShutdownDegradation

Description

This device caused a delay in the system shutdown process.

Message #

This device caused a delay in the system shutdown process: 

     File Name		: %3

     Friendly Name		: %5

     Version		: %7

     Total Time		: %8ms

     Degradation Time	: %9ms

     Incident Time (UTC)	: %1

Fields #

NameDescription
StartTime FILETIME
NameLength UInt32
Name UnicodeString
FriendlyNameLength UInt32
FriendlyName UnicodeString
VersionLength UInt32
Version UnicodeString
TotalTime UInt32
DegradationTime UInt32
PathLength UInt32
Path UnicodeString
ProductNameLength UInt32
ProductName UnicodeString
CompanyNameLength UInt32
CompanyName UnicodeString

Event ID 203: This service caused a delay in the system shutdown process.

#
Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Operational
Level
Warning
Task
ShutdownPerformanceMonitoring
Opcode
ShutdownDegradation

Description

This service caused a delay in the system shutdown process.

Message #

This service caused a delay in the system shutdown process: 

     File Name		: %3

     Friendly Name		: %5

     Version		: %7

     Total Time		: %8ms

     Degradation Time	: %9ms

     Incident Time (UTC)	: %1

Fields #

NameDescription
StartTime FILETIME
NameLength UInt32
Name UnicodeString
FriendlyNameLength UInt32
FriendlyName UnicodeString
VersionLength UInt32
Version UnicodeString
TotalTime UInt32
DegradationTime UInt32
PathLength UInt32
Path UnicodeString
ProductNameLength UInt32
ProductName UnicodeString
CompanyNameLength UInt32
CompanyName UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Diagnostics-Performance",
    "guid": "CFC18EC0-96B1-4EBA-961B-622CAEE05B0A",
    "event_source_name": "",
    "event_id": 203,
    "version": 1,
    "level": 3,
    "task": 4007,
    "opcode": 41,
    "keywords": 9223372036854841344,
    "time_created": "2023-11-05T22:33:56.991549+00:00",
    "event_record_id": 37,
    "correlation": {
      "ActivityID": "E4DB489E-1037-0001-FD89-DBE43710DA01"
    },
    "execution": {
      "process_id": 3160,
      "thread_id": 3468
    },
    "channel": "Microsoft-Windows-Diagnostics-Performance/Operational",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-19"
    }
  },
  "event_data": {
    "StartTime": "2023-11-05T22:31:30.287074Z",
    "NameLength": 10,
    "Name": "WinDefend",
    "FriendlyNameLength": 0,
    "FriendlyName": "",
    "VersionLength": 0,
    "Version": "",
    "TotalTime": 4054,
    "DegradationTime": 54,
    "PathLength": 83,
    "Path": "\"c:\\programdata\\microsoft\\windows defender\\platform\\4.18.23090.2008-0\\msmpeng.exe\"",
    "ProductNameLength": 0,
    "ProductName": "",
    "CompanyNameLength": 0,
    "CompanyName": ""
  },
  "message": ""
}

References #

Event ID 300: Windows has resumed from standby.

#
Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Operational
Task
StandbyPerformanceMonitoring
Opcode
StandbyInformation

Description

Windows has resumed from standby.

Message #

Windows has resumed from standby: 

     Standby Duration		: %7ms

     Standby Incident Time (UTC)	: %5

     Resume  Duration		: %39ms

     Resume  Incident Time (UTC)	: %37

     IsDegradation			: %51

Fields #

NameDescription
StandbyTsVersion UInt32
StandbyAppCount UInt32
StandbyServicesCount UInt32
StandbyDevicesCount UInt32
StandbyStartTime FILETIME
StandbyEndTime FILETIME
StandbySuspendTotal UInt32
StandbySuspendTotalChange Int32
StandbySuspendQueryApps UInt32
StandbySuspendQueryAppsChange Int32
StandbySuspendQueryServices UInt32
StandbySuspendQueryServicesChange Int32
StandbySuspendApps UInt32
StandbySuspendAppsChange Int32
StandbySuspendServices UInt32
StandbySuspendServicesChange Int32
StandbySuspendShowUI UInt32
StandbySuspendShowUIChange Int32
StandbySuspendSuperfetchPageIn UInt32
StandbySuspendSuperfetchPageInChange Int32
StandbySuspendWinlogon UInt32
StandbySuspendWinlogonChange Int32
StandbySuspendLockPageableSections UInt32
StandbySuspendLockPageableSectionsChange Int32
StandbySuspendPreSleepCallbacks UInt32
StandbySuspendPreSleepCallbacksChange Int32
StandbySuspendSwapInWorkerThreads UInt32
StandbySuspendSwapInWorkerThreadsChange Int32
StandbySuspendQueryDevices UInt32
StandbySuspendQueryDevicesChange Int32
StandbySuspendFlushVolumes UInt32
StandbySuspendFlushVolumesChange Int32
StandbySuspendSuspendDevices UInt32
StandbySuspendSuspendDevicesChange Int32
StandbySuspendHibernateWrite UInt32
StandbySuspendHibernateWriteChange Int32
ResumeStartTime FILETIME
ResumeEndTime FILETIME
StandbyResumeTotal UInt32
StandbyResumeTotalChange Int32
StandbyResumeHibernateRead UInt32
StandbyResumeHibernateReadChange Int32
StandbyResumeS3BiosInitTime UInt32
StandbyResumeS3BiosInitTimeChange Int32
StandbyResumeResumeDevices UInt32
StandbyResumeResumeDevicesChange Int32
StandbyRootCauseDegradationGradual UInt32
StandbyRootCauseImprovementGradual UInt32
StandbyRootCauseDegradationStep UInt32
StandbyRootCauseImprovementStep UInt32
StandbyIsDegradation Boolean
StandbyIsTroubleshooterLaunched Boolean
StandbyIsRootCauseIdentified Boolean

Event ID 301: This application caused a delay during standby.

#
Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Operational
Task
StandbyPerformanceMonitoring
Opcode
StandbyDegradation

Description

This application caused a delay during standby.

Message #

This application caused a delay during standby: 

     File Name		: %3

     Friendly Name		: %5

     Version		: %7

     Total Time		: %8ms

     Degradation Time	: %9ms

     Incident Time (UTC)	: %1

Fields #

NameDescription
StartTime FILETIME
NameLength UInt32
Name UnicodeString
FriendlyNameLength UInt32
FriendlyName UnicodeString
VersionLength UInt32
Version UnicodeString
TotalTime UInt32
DegradationTime UInt32
PathLength UInt32
Path UnicodeString
ProductNameLength UInt32
ProductName UnicodeString
CompanyNameLength UInt32
CompanyName UnicodeString

Event ID 302: This driver caused a delay during standby while servicing a device.

#
Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Operational
Task
StandbyPerformanceMonitoring
Opcode
StandbyDegradation

Description

This driver caused a delay during standby while servicing a device.

Message #

This driver caused a delay during standby while servicing a device:

     Driver File Name		: %3

     Driver Friendly Name		: %5

     Driver Version			: %7

     Driver Total Time		: %8ms

     Driver Degradation Time	: %9ms

     Incident Time (UTC)		: %1

     Device Name			: %17

     Device Friendly Name		: %19

     Device Total Time		: %20ms

     Device Degradation Time	: %21ms

Fields #

NameDescription
StartTime FILETIME
NameLength UInt32
Name UnicodeString
FriendlyNameLength UInt32
FriendlyName UnicodeString
VersionLength UInt32
Version UnicodeString
TotalTime UInt32
DegradationTime UInt32
PathLength UInt32
Path UnicodeString
ProductNameLength UInt32
ProductName UnicodeString
CompanyNameLength UInt32
CompanyName UnicodeString
DeviceNameLength UInt32
DeviceName UnicodeString
DeviceFriendlyNameLength UInt32
DeviceFriendlyName UnicodeString
DeviceTotalTime UInt32
DeviceDegradationTime UInt32

Event ID 303: This service caused a delay during hybrid-sleep.

#
Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Operational
Task
StandbyPerformanceMonitoring
Opcode
StandbyDegradation

Description

This service caused a delay during hybrid-sleep.

Message #

This service caused a delay during hybrid-sleep: 

     File Name		: %3

     Friendly Name		: %5

     Version		: %7

     Total Time		: %8ms

     Degradation Time	: %9ms

     Incident Time (UTC)	: %1

Fields #

NameDescription
StartTime FILETIME
NameLength UInt32
Name UnicodeString
FriendlyNameLength UInt32
FriendlyName UnicodeString
VersionLength UInt32
Version UnicodeString
TotalTime UInt32
DegradationTime UInt32
PathLength UInt32
Path UnicodeString
ProductNameLength UInt32
ProductName UnicodeString
CompanyNameLength UInt32
CompanyName UnicodeString

Event ID 304: Creation of the hiber-file was slower than expected.

#
Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Operational
Task
StandbyPerformanceMonitoring
Opcode
StandbyDegradation

Description

Creation of the hiber-file was slower than expected.

Message #

Creation of the hiber-file was slower than expected: 

     Name		: %3

     Total Time		: %4ms

     Degradation Time	: %5ms

     Incident Time (UTC)	: %1

Fields #

NameDescription
StartTime FILETIME
NameLength UInt32
Name UnicodeString
TotalTime UInt32
DegradationTime UInt32

Event ID 305: Persisting disk caches was slower than expected.

#
Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Operational
Task
StandbyPerformanceMonitoring
Opcode
StandbyDegradation

Description

Persisting disk caches was slower than expected.

Message #

Persisting disk caches was slower than expected: 

     Name		: %3

     Total Time		: %4ms

     Degradation Time	: %5ms

     Incident Time (UTC)	: %1

Fields #

NameDescription
StartTime FILETIME
NameLength UInt32
Name UnicodeString
TotalTime UInt32
DegradationTime UInt32

Event ID 306: Preparing the video subsystem for sleep was slower than expected.

#
Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Operational
Task
StandbyPerformanceMonitoring
Opcode
StandbyDegradation

Description

Preparing the video subsystem for sleep was slower than expected.

Message #

Preparing the video subsystem for sleep was slower than expected: 

     Name		: %3

     Total Time		: %4ms

     Degradation Time	: %5ms

     Incident Time (UTC)	: %1

Fields #

NameDescription
StartTime FILETIME
NameLength UInt32
Name UnicodeString
TotalTime UInt32
DegradationTime UInt32

Event ID 307: Preparing Winlogon for sleep was slower than expected.

#
Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Operational
Task
StandbyPerformanceMonitoring
Opcode
StandbyDegradation

Description

Preparing Winlogon for sleep was slower than expected.

Message #

Preparing Winlogon for sleep was slower than expected: 

     Name		: %3

     Total Time		: %4ms

     Degradation Time	: %5ms

     Incident Time (UTC)	: %1

Fields #

NameDescription
StartTime FILETIME
NameLength UInt32
Name UnicodeString
TotalTime UInt32
DegradationTime UInt32

Event ID 308: Preparing system memory for sleep was slower than expected.

#
Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Operational
Task
StandbyPerformanceMonitoring
Opcode
StandbyDegradation

Description

Preparing system memory for sleep was slower than expected.

Message #

Preparing system memory for sleep was slower than expected: 

     Name		: %3

     Total Time		: %4ms

     Degradation Time	: %5ms

     Incident Time (UTC)	: %1

Fields #

NameDescription
StartTime FILETIME
NameLength UInt32
Name UnicodeString
TotalTime UInt32
DegradationTime UInt32

Event ID 309: Preparing core system for sleep was slower than expected.

#
Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Operational
Task
StandbyPerformanceMonitoring
Opcode
StandbyDegradation

Description

Preparing core system for sleep was slower than expected.

Message #

Preparing core system for sleep was slower than expected: 

     Name		: %3

     Total Time		: %4ms

     Degradation Time	: %5ms

     Incident Time (UTC)	: %1

Fields #

NameDescription
StartTime FILETIME
NameLength UInt32
Name UnicodeString
TotalTime UInt32
DegradationTime UInt32

Event ID 310: Preparing system worker threads for sleep was slower than expected.

#
Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Operational
Task
StandbyPerformanceMonitoring
Opcode
StandbyDegradation

Description

Preparing system worker threads for sleep was slower than expected.

Message #

Preparing system worker threads for sleep was slower than expected: 

     Name		: %3

     Total Time		: %4ms

     Degradation Time	: %5ms

     Incident Time (UTC)	: %1

Fields #

NameDescription
StartTime FILETIME
NameLength UInt32
Name UnicodeString
TotalTime UInt32
DegradationTime UInt32

Event ID 350: Bios initialization time was greater than 250ms (logo requirement) during system resume.

#
Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Operational
Task
StandbyPerformanceMonitoring
Opcode
StandbyDegradation

Description

Bios initialization time was greater than 250ms (logo requirement) during system resume.

Message #

Bios initialization time was greater than 250ms (logo requirement) during system resume: 

     Name		: %3

     Total Time		: %4ms

     Degradation Time	: %5ms

     Incident Time (UTC)	: %1

Fields #

NameDescription
StartTime FILETIME
NameLength UInt32
Name UnicodeString
TotalTime UInt32
DegradationTime UInt32

Event ID 351: This driver responded slower than expected to the resume request while servicing this device.

#
Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Operational
Task
StandbyPerformanceMonitoring
Opcode
StandbyDegradation

Description

This driver responded slower than expected to the resume request while servicing this device.

Message #

This driver responded slower than expected to the resume request while servicing this device: 

     Driver File Name		: %3

     Driver Friendly Name		: %5

     Driver Version			: %7

     Driver Total Time		: %8ms

     Driver Degradation Time	: %9ms

     Incident Time (UTC)		: %1

     Device Name			: %17

     Device Friendly Name		: %19

     Device Total Time		: %20ms

     Device Degradation Time	: %21ms

Fields #

NameDescription
StartTime FILETIME
NameLength UInt32
Name UnicodeString
FriendlyNameLength UInt32
FriendlyName UnicodeString
VersionLength UInt32
Version UnicodeString
TotalTime UInt32
DegradationTime UInt32
PathLength UInt32
Path UnicodeString
ProductNameLength UInt32
ProductName UnicodeString
CompanyNameLength UInt32
CompanyName UnicodeString
DeviceNameLength UInt32
DeviceName UnicodeString
DeviceFriendlyNameLength UInt32
DeviceFriendlyName UnicodeString
DeviceTotalTime UInt32
DeviceDegradationTime UInt32

Event ID 352: Reading the hiber-file was slower than expected.

#
Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Operational
Task
StandbyPerformanceMonitoring
Opcode
StandbyDegradation

Description

Reading the hiber-file was slower than expected.

Message #

Reading the hiber-file was slower than expected: 

     Name		: %3

     Total Time		: %4ms

     Degradation Time	: %5ms

     Incident Time (UTC)	: %1

Fields #

NameDescription
StartTime FILETIME
NameLength UInt32
Name UnicodeString
TotalTime UInt32
DegradationTime UInt32

Event ID 400: Information about the system performance monitoring event.

#
Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Operational
Task
SystemPerformanceMonitoring
Opcode
ShellInformation

Description

Information about the system performance monitoring event.

Message #

Information about the system performance monitoring event: 

     Scenario		: %3

     Analysis result		: %6

     Incident Time (UTC)	: %1

Fields #

NameDescription
ShellScenarioStartTime FILETIME
ShellScenarioEndTime FILETIME
ShellSubScenario UInt32
ShellScenarioDuration UInt32
ShellRootCauseBits UInt32
ShellAnalysisResult UInt32
ShellDegradationType UInt32
ShellTsVersion UInt32
ShellMachineUpTimeHours UInt32
ShellMachineSleepPattern UInt32

Event ID 401: This process is using up processor time and is impacting the performance of Windows.

#
Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Operational
Task
SystemPerformanceMonitoring
Opcode
ShellDegradation

Description

This process is using up processor time and is impacting the performance of Windows.

Message #

This process is using up processor time and is impacting the performance of Windows: 

     File Name		: %3

     Friendly Name		: %5

     Version		: %7

     Thread time		: %8ms

     Blocked Time		: %9ms

     Incident Time (UTC)	: %1

Fields #

NameDescription
StartTime FILETIME
NameLength UInt32
Name UnicodeString
FriendlyNameLength UInt32
FriendlyName UnicodeString
VersionLength UInt32
Version UnicodeString
ThreadTime UInt32
BlockedTime UInt32
PercentTime Double
PathLength UInt32
Path UnicodeString
ProductNameLength UInt32
ProductName UnicodeString
CompanyNameLength UInt32
CompanyName UnicodeString

Event ID 402: This process is doing excessive disk activities and is impacting the performance of Windows.

#
Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Operational
Task
SystemPerformanceMonitoring
Opcode
ShellDegradation

Description

This process is doing excessive disk activities and is impacting the performance of Windows.

Message #

This process is doing excessive disk activities and is impacting the performance of Windows: 

     File Name		: %3

     Friendly Name		: %5

     Version		: %7

     Thread time		: %8ms

     Blocked Time		: %9ms

     Incident Time (UTC)	: %1

Fields #

NameDescription
StartTime FILETIME
NameLength UInt32
Name UnicodeString
FriendlyNameLength UInt32
FriendlyName UnicodeString
VersionLength UInt32
Version UnicodeString
ThreadTime UInt32
BlockedTime UInt32
PercentTime Double
PathLength UInt32
Path UnicodeString
ProductNameLength UInt32
ProductName UnicodeString
CompanyNameLength UInt32
CompanyName UnicodeString

Event ID 403: This driver is using up too many resources and is impacting the performance of Windows.

#
Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Operational
Task
SystemPerformanceMonitoring
Opcode
ShellDegradation

Description

This driver is using up too many resources and is impacting the performance of Windows.

Message #

This driver is using up too many resources and is impacting the performance of Windows: 

     File Name		: %3

     Friendly Name		: %5

     Version		: %7

     Thread time		: %8ms

     Blocked Time		: %9ms

     Incident Time (UTC)	: %1

Fields #

NameDescription
StartTime FILETIME
NameLength UInt32
Name UnicodeString
FriendlyNameLength UInt32
FriendlyName UnicodeString
VersionLength UInt32
Version UnicodeString
ThreadTime UInt32
BlockedTime UInt32
PercentTime Double
PathLength UInt32
Path UnicodeString
ProductNameLength UInt32
ProductName UnicodeString
CompanyNameLength UInt32
CompanyName UnicodeString

Event ID 404: This driver is waiting longer than expected on a device.

#
Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Operational
Task
SystemPerformanceMonitoring
Opcode
ShellDegradation

Description

This driver is waiting longer than expected on a device.

Message #

This driver is waiting longer than expected on a device: 

     File Name		: %3

     Friendly Name		: %5

     Version		: %7

     Thread time		: %8ms

     Blocked Time		: %9ms

     Incident Time (UTC)	: %1

Fields #

NameDescription
StartTime FILETIME
NameLength UInt32
Name UnicodeString
FriendlyNameLength UInt32
FriendlyName UnicodeString
VersionLength UInt32
Version UnicodeString
ThreadTime UInt32
BlockedTime UInt32
PercentTime Double
PathLength UInt32
Path UnicodeString
ProductNameLength UInt32
ProductName UnicodeString
CompanyNameLength UInt32
CompanyName UnicodeString

Event ID 405: This file is fragmented and is impacting the performance of Windows.

#
Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Operational
Task
SystemPerformanceMonitoring
Opcode
ShellDegradation

Description

This file is fragmented and is impacting the performance of Windows.

Message #

This file is fragmented and is impacting the performance of Windows: 

     File Name		: %3

     Friendly Name		: %5

     Version		: %7

     Thread time		: %8ms

     Blocked Time		: %9ms

     Incident Time (UTC)	: %1

Fields #

NameDescription
StartTime FILETIME
NameLength UInt32
Name UnicodeString
FriendlyNameLength UInt32
FriendlyName UnicodeString
VersionLength UInt32
Version UnicodeString
ThreadTime UInt32
BlockedTime UInt32
PercentTime Double
PathLength UInt32
Path UnicodeString
ProductNameLength UInt32
ProductName UnicodeString
CompanyNameLength UInt32
CompanyName UnicodeString

Event ID 406: Disk IO to this file is taking longer than expected.

#
Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Operational
Task
SystemPerformanceMonitoring
Opcode
ShellDegradation

Description

Disk IO to this file is taking longer than expected.

Message #

Disk IO to this file is taking longer than expected: 

     File Name		: %3

     Friendly Name		: %5

     Version		: %7

     Thread time		: %8ms

     Blocked Time		: %9ms

     Incident Time (UTC)	: %1

Fields #

NameDescription
StartTime FILETIME
NameLength UInt32
Name UnicodeString
FriendlyNameLength UInt32
FriendlyName UnicodeString
VersionLength UInt32
Version UnicodeString
ThreadTime UInt32
BlockedTime UInt32
PercentTime Double
PathLength UInt32
Path UnicodeString
ProductNameLength UInt32
ProductName UnicodeString
CompanyNameLength UInt32
CompanyName UnicodeString

Event ID 407: This process is using up too much system memory.

#
Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Operational
Task
SystemPerformanceMonitoring
Opcode
ShellDegradation

Description

This process is using up too much system memory.

Message #

This process is using up too much system memory: 

     File Name		: %3

     Friendly Name		: %5

     Version		: %7

     Workingset size	: %8Kb

     Percent memory	: %11

     Incident Time (UTC)	: %1

Fields #

NameDescription
StartTime FILETIME
NameLength UInt32
Name UnicodeString
FriendlyNameLength UInt32
FriendlyName UnicodeString
VersionLength UInt32
Version UnicodeString
WorkingSetSizeKb UInt32
PeakWorkingSetSizeKb UInt32
ProcessId UInt32
PercentMemory Double
PathLength UInt32
Path UnicodeString
ProductNameLength UInt32
ProductName UnicodeString
CompanyNameLength UInt32
CompanyName UnicodeString

Event ID 408: Many processes are using too much system memory.

#
Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Operational
Task
SystemPerformanceMonitoring
Opcode
ShellDegradation

Description

Many processes are using too much system memory.

Message #

Many processes are using too much system memory: 

     Workingset size	: %2Kb

     Percent memory	: %3

     Incident Time (UTC)	: %1

Fields #

NameDescription
StartTime FILETIME
WorkingSetSizeKb UInt32
PercentMemory Double

Event ID 500: The Desktop Window Manager is experiencing heavy resource contention.

#
Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Operational
Task
DesktopWindowManagerMonitoring
Opcode
VideoMemoryDegradation

Description

The Desktop Window Manager is experiencing heavy resource contention.

Message #

The Desktop Window Manager is experiencing heavy resource contention. 

     Scenario	: %5

Fields #

NameDescription
DisplayDeviceFriendlyNameLength UInt32
DisplayDeviceFriendlyName UnicodeString
MemoryBandwidth UInt32
MemorySize UInt32
Scenario UInt32

Event ID 501: The Desktop Window Manager is experiencing heavy resource contention.

#
Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Operational
Task
DesktopWindowManagerMonitoring
Opcode
VideoMemoryResponsiveness

Description

The Desktop Window Manager is experiencing heavy resource contention.

Message #

The Desktop Window Manager is experiencing heavy resource contention.

     Reason	: %1

     Diagnosis	: %2

Fields #

NameDescription
Reason UInt32
Diagnosis UInt32

Event ID 1001: Status

#
Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Diagnostic
Task
Boot_DMConfig
Opcode
Failed

Description

Status

Message #

Status

Fields #

NameDescription
HResult UInt32

Event ID 1002: Status

#
Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Diagnostic
Task
Boot_UnexpectedEvent

Description

Status

Message #

Status

Fields #

NameDescription
GUID GUID
EventId UInt16
InternalState UInt32

Event ID 1003: Status

#
Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Diagnostic
Task
Boot_ChangedState

Description

Status

Message #

Status

Fields #

NameDescription
NewState UInt32

Event ID 1005: Status

#
Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Diagnostic
Task
Boot_CapturedDCL

Description

Status

Message #

Status

Fields #

NameDescription
HResult UInt32

Event ID 1006: Status

#
Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Diagnostic
Task
Boot_DetectedMultipleLogons

Description

Status

Message #

Status

Event ID 1007: Status

#
Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Diagnostic
Task
Boot_ReceivedEvent

Description

Status

Message #

Status

Fields #

NameDescription
GUID GUID
EventId UInt16
InternalState UInt32

Event ID 1010: Status

#
Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Diagnostic
Task
Boot_Troubleshooting
Opcode
Start

Description

Status

Message #

Status

Event ID 1011: Status

#
Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Diagnostic
Task
Boot_Troubleshooting
Opcode
Stop

Description

Status

Message #

Status

Fields #

NameDescription
HResult UInt32

Event ID 1012: Status

#
Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Diagnostic
Task
Boot_ProcessingSystem
Opcode
Start

Description

Status

Message #

Status

Event ID 1013: Status

#
Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Diagnostic
Task
Boot_ProcessingSystem
Opcode
Stop

Description

Status

Message #

Status

Fields #

NameDescription
HResult UInt32

Event ID 1014: Status

#
Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Diagnostic
Task
Boot_ProcessingUser
Opcode
Start

Description

Status

Message #

Status

Event ID 1015: Status

#
Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Diagnostic
Task
Boot_ProcessingUser
Opcode
Stop

Description

Status

Message #

Status

Fields #

NameDescription
HResult UInt32

Event ID 1020: Status

#
Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Diagnostic
Task
Boot_ArchiveCorrupt

Description

Status

Message #

Status

Fields #

NameDescription
HResult UInt32

Event ID 1022: Status

#
Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Diagnostic
Task
Boot_CancelledAnalysisViaRegistry

Description

Status

Message #

Status

Event ID 1024: Status

#
Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Diagnostic
Task
Boot_RurReadAhead
Opcode
Start

Description

Status

Message #

Status

Event ID 1025: Status

#
Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Diagnostic
Task
Boot_RurReadAhead
Opcode
Stop

Description

Status

Message #

Status

Fields #

NameDescription
HResult UInt32

Event ID 1026: Status

#
Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Diagnostic
Task
Boot_RurLegacyResource
Opcode
Start

Description

Status

Message #

Status

Event ID 1027: Status

#
Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Diagnostic
Task
Boot_RurLegacyResource
Opcode
Stop

Description

Status

Message #

Status

Event ID 1028: Status

#
Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Diagnostic
Task
Boot_RurAppResourceUsage
Opcode
Start

Description

Status

Message #

Status

Event ID 1029: Status

#
Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Diagnostic
Task
Boot_RurAppResourceUsage
Opcode
Stop

Description

Status

Message #

Status

Fields #

NameDescription
HResult UInt32

Event ID 1030: Status

#
Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Diagnostic
Task
Boot_RurPostLogonResourceUsage
Opcode
Start

Description

Status

Message #

Status

Event ID 1031: Status

#
Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Diagnostic
Task
Boot_RurPostLogonResourceUsage
Opcode
Stop

Description

Status

Message #

Status

Fields #

NameDescription
HResult UInt32

Event ID 2001: Status

#
Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Diagnostic
Task
Shell_DegradationDetected
Opcode
StepUp

Description

Status

Message #

Status

Event ID 2002: Status

#
Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Diagnostic
Task
Shell_DegradationDetected
Opcode
StepDown

Description

Status

Message #

Status

Event ID 2003: Status

#
Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Diagnostic
Task
Shell_DegradationDetected
Opcode
GradualUp

Description

Status

Message #

Status

Event ID 2004: Status

#
Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Diagnostic
Task
Shell_DegradationDetected
Opcode
GradualDown

Description

Status

Message #

Status

Event ID 2005: Status

#
Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Diagnostic
Task
Scenario_CapturedCKCL

Description

Status

Message #

Status

Fields #

NameDescription
HResult UInt32
SnapshotPath UnicodeString

Event ID 2006: Status

#
Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Diagnostic
Task
Scenario_CapturedDCL

Description

Status

Message #

Status

Fields #

NameDescription
HResult UInt32
SnapshotPath UnicodeString

Event ID 2007: Status

#
Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Diagnostic
Task
Scenario_SimpleEvent
Opcode
Start

Description

Status

Message #

Status

Fields #

NameDescription
ProviderId GUID
EventId UInt16
HResult UInt32

Event ID 2008: Status

#
Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Diagnostic
Task
Scenario_SimpleEvent
Opcode
Stop

Description

Status

Message #

Status

Fields #

NameDescription
ProviderId GUID
EventId UInt16
HResult UInt32

Event ID 2009: Status

#
Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Diagnostic
Task
Scenario_StartEvent
Opcode
Start

Description

Status

Message #

Status

Fields #

NameDescription
ProviderId GUID
EventId UInt16
HResult UInt32

Event ID 2010: Status

#
Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Diagnostic
Task
Scenario_StartEvent
Opcode
Stop

Description

Status

Message #

Status

Fields #

NameDescription
ProviderId GUID
EventId UInt16
HResult UInt32

Event ID 2011: Status

#
Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Diagnostic
Task
Scenario_StopEvent
Opcode
Start

Description

Status

Message #

Status

Fields #

NameDescription
ProviderId GUID
EventId UInt16
HResult UInt32

Event ID 2012: Status

#
Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Diagnostic
Task
Scenario_StopEvent
Opcode
Stop

Description

Status

Message #

Status

Fields #

NameDescription
ProviderId GUID
EventId UInt16
HResult UInt32

Event ID 2013: Status

#
Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Diagnostic
Task
Scenario_ProblemDetection
Opcode
Start

Description

Status

Message #

Status

Fields #

NameDescription
ScenarioGUID GUID
HResult UInt32

Event ID 2014: Status

#
Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Diagnostic
Task
Scenario_ProblemDetection
Opcode
Stop

Description

Status

Message #

Status

Fields #

NameDescription
ScenarioGUID GUID
HResult UInt32

Event ID 2015: Status

#
Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Diagnostic
Task
Scenario_TroubleShoot
Opcode
Start

Description

Status

Message #

Status

Fields #

NameDescription
ScenarioGUID GUID
HResult UInt32

Event ID 2016: Status

#
Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Diagnostic
Task
Scenario_TroubleShoot
Opcode
Stop

Description

Status

Message #

Status

Fields #

NameDescription
ScenarioGUID GUID
HResult UInt32

Event ID 7001: Status

#
Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Loopback
Task
Boot_Loopback_SnapshotKMScenario

Description

Status

Message #

Status

Event ID 7101: Status

#
Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Loopback
Task
BootApps_ResolverLoopback

Description

Status

Message #

Status

Event ID 7102: Status

#
Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Loopback
Task
BootDrivers_ResolverLoopback

Description

Status

Message #

Status

Event ID 7103: Status

#
Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Loopback
Task
ShutdownApps_ResolverLoopback

Description

Status

Message #

Status

Event ID 7104: Status

#
Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Loopback
Task
SuspendApps_ResolverLoopback

Description

Status

Message #

Status

Event ID 7105: Status

#
Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Loopback
Task
SuspendDrivers_ResolverLoopback

Description

Status

Message #

Status

Event ID 7106: Status

#
Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Loopback
Task
ResumeDrivers_ResolverLoopback

Description

Status

Message #

Status

Event ID 8001: Status

#
Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Diagnostic
Task
Shutdown_ArchiveCorrupt

Description

Status

Message #

Status

Fields #

NameDescription
HResult UInt32

Event ID 8002: Status

#
Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Diagnostic
Task
Shutdown_ThreadCreateFailed
Opcode
Failed

Description

Status

Message #

Status

Fields #

NameDescription
HResult UInt32

Event ID 8003: Status

#
Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Diagnostic
Task
Shutdown_Troubleshooting
Opcode
Start

Description

Status

Message #

Status

Event ID 8004: Status

#
Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Diagnostic
Task
Shutdown_Troubleshooting
Opcode
Stop

Description

Status

Message #

Status

Fields #

NameDescription
HResult UInt32

Event ID 8005: Status

#
Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Diagnostic
Task
Shutdown_WaitingForBoot

Description

Status

Message #

Status

Event ID 8006: Status

#
Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Diagnostic
Task
Shutdown_LocatedCKCL

Description

Status

Message #

Status

Fields #

NameDescription
Path UnicodeString

Event ID 8007: Status

#
Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Diagnostic
Task
Shutdown_LocatedPossibleDCL

Description

Status

Message #

Status

Fields #

NameDescription
Path UnicodeString

Event ID 8008: Status

#
Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Diagnostic
Task
Shutdown_RestoringConfig

Description

Status

Message #

Status

Event ID 8009: Status

#
Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Diagnostic
Task
Shutdown_LoadConfig
Opcode
Failed

Description

Status

Message #

Status

Fields #

NameDescription
HResult UInt32

Event ID 8010: Status

#
Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Diagnostic
Task
Shutdown_ProxyCallback

Description

Status

Message #

Status

Event ID 8011: Status

#
Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Diagnostic
Task
Shutdown_StartCKCL
Opcode
Start

Description

Status

Message #

Status

Event ID 8012: Status

#
Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Diagnostic
Task
Shutdown_StartCKCL
Opcode
Stop

Description

Status

Message #

Status

Fields #

NameDescription
HResult UInt32

Event ID 8013: Status

#
Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Diagnostic
Task
Shutdown_CancelledAnalysisViaRegistry

Description

Status

Message #

Status

Event ID 9001: Status

#
Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Diagnostic
Task
SecondaryLogon_DMConfig
Opcode
Failed

Description

Status

Message #

Status

Fields #

NameDescription
HResult UInt32

Event ID 9003: Status

#
Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Diagnostic
Task
SecondaryLogon_UnexpectedEvent

Description

Status

Message #

Status

Fields #

NameDescription
GUID GUID
EventId UInt16
InternalState UInt32

Event ID 9005: Status

#
Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Diagnostic
Task
SecondaryLogon_ChangedState

Description

Status

Message #

Status

Fields #

NameDescription
NewState UInt32

Event ID 9007: Status

#
Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Diagnostic
Task
SecondaryLogon_DetectedMultipleLogons

Description

Status

Message #

Status

Event ID 9009: Status

#
Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Diagnostic
Task
SecondaryLogon_ReceivedEvent

Description

Status

Message #

Status

Fields #

NameDescription
GUID GUID
EventId UInt16
InternalState UInt32

Event ID 9011: Status

#
Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Diagnostic
Task
SecondaryLogon_Troubleshooting
Opcode
Start

Description

Status

Message #

Status

Event ID 9012: Status

#
Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Diagnostic
Task
SecondaryLogon_Troubleshooting
Opcode
Stop

Description

Status

Message #

Status

Fields #

NameDescription
HResult UInt32

Event ID 9013: Status

#
Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Diagnostic
Task
SecondaryLogon_CancelledAnalysisViaRegistry

Description

Status

Message #

Status

Event ID 9015: Status

#
Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Diagnostic
Task
SecondaryLogon_CapturedDCL

Description

Status

Message #

Status

Fields #

NameDescription
HResult UInt32

Event ID 10001: Status

#
Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Loopback
Task
SecondaryLogonScenario_Stop

Description

Status

Message #

Status

Event ID 11001: Standby_ReceivedEvent

#
Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Diagnostic
Task
Standby_ReceivedEvent

Fields #

NameDescription
GUID GUID
EventId UInt16
InternalState UInt32

Event ID 11002: Standby_ChangedState

#
Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Diagnostic
Task
Standby_ChangedState

Fields #

NameDescription
NewState UInt32

Event ID 11003: Standby_FailedTransition

#
Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Diagnostic
Task
Standby_FailedTransition

Event ID 11005: Standby_DetectRegressionsStart

#
Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Diagnostic
Task
Standby_DetectRegressions
Opcode
Start

Event ID 11006: Standby_DetectRegressionsStop

#
Provider
Microsoft-Windows-Diagnostics-Performance
Channel
Diagnostic
Task
Standby_DetectRegressions
Opcode
Stop

Fields #

NameDescription
HResult UInt32

Provenance

Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.

ETW provider GUID cfc18ec0-96b1-4eba-961b-622caee05b0a

Defined in diagperf.dll, which carries the event manifest.

Observed on:

  • Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.1, captured 2026-06-02

Downloads