Microsoft-Windows-Diagnostics-Performance

EventTitleChannelSampleRule
100Windows has started up.OperationalYN
101This application took longer than usual to start up, resulting in a performance …OperationalYN
102This driver took longer to initialize, resulting in a performance degradation in …OperationalYN
103This startup service took longer than expected to startup, resulting in a …OperationalYN
104Core system took longer to initialize, resulting in a performance degradation in …OperationalNN
105Foreground optimizations (prefetching) took longer to complete, resulting in a …OperationalNN
106Background optimizations (prefetching) took longer to complete, resulting in a …OperationalNN
107Application of machine policy caused a slow down in the system start up process.OperationalYN
108Application of user policy caused a slow down in the system start up process.OperationalYN
109This device took longer to initialize, resulting in a performance degradation in …OperationalNN
110Session manager initialization caused a slow down in the startup process.OperationalYN
200Windows has shutdown.OperationalYN
201This application caused a delay in the system shutdown process.OperationalNN
202This device caused a delay in the system shutdown process.OperationalNN
203This service caused a delay in the system shutdown process.OperationalYN
300Windows has resumed from standby.OperationalNN
301This application caused a delay during standby.OperationalNN
302This driver caused a delay during standby while servicing a device.OperationalNN
303This service caused a delay during hybrid-sleep.OperationalNN
304Creation of the hiber-file was slower than expected.OperationalNN
305Persisting disk caches was slower than expected.OperationalNN
306Preparing the video subsystem for sleep was slower than expected.OperationalNN
307Preparing Winlogon for sleep was slower than expected.OperationalNN
308Preparing system memory for sleep was slower than expected.OperationalNN
309Preparing core system for sleep was slower than expected.OperationalNN
310Preparing system worker threads for sleep was slower than expected.OperationalNN
350Bios initialization time was greater than 250ms (logo requirement) during system …OperationalNN
351This driver responded slower than expected to the resume request while servicing …OperationalNN
352Reading the hiber-file was slower than expected.OperationalNN
400Information about the system performance monitoring event.OperationalNN
401This process is using up processor time and is impacting the performance of …OperationalNN
402This process is doing excessive disk activities and is impacting the performance …OperationalNN
403This driver is using up too many resources and is impacting the performance of …OperationalNN
404This driver is waiting longer than expected on a device.OperationalNN
405This file is fragmented and is impacting the performance of Windows.OperationalNN
406Disk IO to this file is taking longer than expected.OperationalNN
407This process is using up too much system memory.OperationalNN
408Many processes are using too much system memory.OperationalNN
500The Desktop Window Manager is experiencing heavy resource contention.OperationalNN
501The Desktop Window Manager is experiencing heavy resource contention.OperationalNN
1001StatusDiagnosticNN
1002StatusDiagnosticNN
1003StatusDiagnosticNN
1005StatusDiagnosticNN
1006StatusDiagnosticNN
1007StatusDiagnosticNN
1010StatusDiagnosticNN
1011StatusDiagnosticNN
1012StatusDiagnosticNN
1013StatusDiagnosticNN
1014StatusDiagnosticNN
1015StatusDiagnosticNN
1020StatusDiagnosticNN
1022StatusDiagnosticNN
1024StatusDiagnosticNN
1025StatusDiagnosticNN
1026StatusDiagnosticNN
1027StatusDiagnosticNN
1028StatusDiagnosticNN
1029StatusDiagnosticNN
1030StatusDiagnosticNN
1031StatusDiagnosticNN
2001StatusDiagnosticNN
2002StatusDiagnosticNN
2003StatusDiagnosticNN
2004StatusDiagnosticNN
2005StatusDiagnosticNN
2006StatusDiagnosticNN
2007StatusDiagnosticNN
2008StatusDiagnosticNN
2009StatusDiagnosticNN
2010StatusDiagnosticNN
2011StatusDiagnosticNN
2012StatusDiagnosticNN
2013StatusDiagnosticNN
2014StatusDiagnosticNN
2015StatusDiagnosticNN
2016StatusDiagnosticNN
7001StatusLoopbackNN
7101StatusLoopbackNN
7102StatusLoopbackNN
7103StatusLoopbackNN
7104StatusLoopbackNN
7105StatusLoopbackNN
7106StatusLoopbackNN
8001StatusDiagnosticNN
8002StatusDiagnosticNN
8003StatusDiagnosticNN
8004StatusDiagnosticNN
8005StatusDiagnosticNN
8006StatusDiagnosticNN
8007StatusDiagnosticNN
8008StatusDiagnosticNN
8009StatusDiagnosticNN
8010StatusDiagnosticNN
8011StatusDiagnosticNN
8012StatusDiagnosticNN
8013StatusDiagnosticNN
9001StatusDiagnosticNN
9003StatusDiagnosticNN
9005StatusDiagnosticNN
9007StatusDiagnosticNN
9009StatusDiagnosticNN
9011StatusDiagnosticNN
9012StatusDiagnosticNN
9013StatusDiagnosticNN
9015StatusDiagnosticNN
10001StatusLoopbackNN
11001Standby_ReceivedEventDiagnosticNN
11002Standby_ChangedStateDiagnosticNN
11003Standby_FailedTransitionDiagnosticNN
11005Standby_DetectRegressionsStartDiagnosticNN
11006Standby_DetectRegressionsStopDiagnosticNN

Event ID 100: Windows has started up.

#
Channel
Operational
Level
Critical
Task
BootPerformanceMonitoring
Opcode
BootInformation

Message #

Windows has started up: 

     Boot Duration		: %6ms

     IsDegradation		: %26

     Incident Time (UTC)	: %2

Fields #

NameDescription
BootTsVersion UInt32
BootStartTime FILETIME
BootEndTime FILETIME
SystemBootInstance UInt32
UserBootInstance UInt32
BootTime UInt32
MainPathBootTime UInt32
BootKernelInitTime UInt32
BootDriverInitTime UInt32
BootDevicesInitTime UInt32
BootPrefetchInitTime UInt32
BootPrefetchBytes UInt32
BootAutoChkTime UInt32
BootSmssInitTime UInt32
BootCriticalServicesInitTime UInt32
BootUserProfileProcessingTime UInt32
BootMachineProfileProcessingTime UInt32
BootExplorerInitTime UInt32
BootNumStartupApps UInt32
BootPostBootTime UInt32
BootIsRebootAfterInstall Boolean
BootRootCauseStepImprovementBits UInt32
BootRootCauseGradualImprovementBits UInt32
BootRootCauseStepDegradationBits UInt32
BootRootCauseGradualDegradationBits UInt32
BootIsDegradation Boolean
BootIsStepDegradation Boolean
BootIsGradualDegradation Boolean
BootImprovementDelta UInt32
BootDegradationDelta UInt32
BootIsRootCauseIdentified Boolean
OSLoaderDuration UInt32
BootPNPInitStartTimeMS UInt32
BootPNPInitDuration UInt32
OtherKernelInitDuration UInt32
SystemPNPInitStartTimeMS UInt32
SystemPNPInitDuration UInt32
SessionInitStartTimeMS UInt32
Session0InitDuration UInt32
Session1InitDuration UInt32
SessionInitOtherDuration UInt32
WinLogonStartTimeMS UInt32
OtherLogonInitActivityDuration UInt32
UserLogonWaitDuration UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Diagnostics-Performance",
    "guid": "CFC18EC0-96B1-4EBA-961B-622CAEE05B0A",
    "event_source_name": "",
    "event_id": 100,
    "version": 2,
    "level": 1,
    "task": 4002,
    "opcode": 34,
    "keywords": 9223372036854841344,
    "time_created": "2023-11-05T22:33:58.036254+00:00",
    "event_record_id": 38,
    "correlation": {
      "ActivityID": "E4DB489E-1037-0003-0982-DBE43710DA01"
    },
    "execution": {
      "process_id": 3160,
      "thread_id": 3556
    },
    "channel": "Microsoft-Windows-Diagnostics-Performance/Operational",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-19"
    }
  },
  "event_data": {
    "BootTsVersion": 2,
    "BootStartTime": "2023-11-05T22:32:00.970725Z",
    "BootEndTime": "2023-11-05T22:33:56.389945Z",
    "SystemBootInstance": 8,
    "UserBootInstance": 2,
    "BootTime": 110680,
    "MainPathBootTime": 34629,
    "BootKernelInitTime": 164,
    "BootDriverInitTime": 1567,
    "BootDevicesInitTime": 2810,
    "BootPrefetchInitTime": 0,
    "BootPrefetchBytes": 0,
    "BootAutoChkTime": 0,
    "BootSmssInitTime": 6391,
    "BootCriticalServicesInitTime": 1441,
    "BootUserProfileProcessingTime": 1084,
    "BootMachineProfileProcessingTime": 456,
    "BootExplorerInitTime": 18858,
    "BootNumStartupApps": 3,
    "BootPostBootTime": 76051,
    "BootIsRebootAfterInstall": false,
    "BootRootCauseStepImprovementBits": 0,
    "BootRootCauseGradualImprovementBits": 0,
    "BootRootCauseStepDegradationBits": 13631488,
    "BootRootCauseGradualDegradationBits": 13631488,
    "BootIsDegradation": true,
    "BootIsStepDegradation": true,
    "BootIsGradualDegradation": true,
    "BootImprovementDelta": 0,
    "BootDegradationDelta": 68995,
    "BootIsRootCauseIdentified": true,
    "OSLoaderDuration": 3107,
    "BootPNPInitStartTimeMS": 164,
    "BootPNPInitDuration": 4163,
    "OtherKernelInitDuration": 445,
    "SystemPNPInitStartTimeMS": 4495,
    "SystemPNPInitDuration": 1301,
    "SessionInitStartTimeMS": 5910,
    "Session0InitDuration": 1013,
    "Session1InitDuration": 219,
    "SessionInitOtherDuration": 5158,
    "WinLogonStartTimeMS": 12302,
    "OtherLogonInitActivityDuration": 1926,
    "UserLogonWaitDuration": 4739
  },
  "message": ""
}

References #

Event ID 101: This application took longer than usual to start up, resulting in a performance degradation in the system startup process.

#
Channel
Operational
Level
Warning
Task
BootPerformanceMonitoring
Opcode
BootDegradation

Message #

This application took longer than usual to start up, resulting in a performance degradation in the system startup process: 

     File Name		: %3

     Friendly Name		: %5

     Version		: %7

     Total Time		: %8ms

     Degradation Time	: %9ms

     Incident Time (UTC)	: %1

Fields #

NameDescription
StartTime FILETIME
NameLength UInt32
Name UnicodeString
FriendlyNameLength UInt32
FriendlyName UnicodeString
VersionLength UInt32
Version UnicodeString
TotalTime UInt32
DegradationTime UInt32
PathLength UInt32
Path UnicodeString
ProductNameLength UInt32
ProductName UnicodeString
CompanyNameLength UInt32
CompanyName UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Diagnostics-Performance",
    "guid": "CFC18EC0-96B1-4EBA-961B-622CAEE05B0A",
    "event_source_name": "",
    "event_id": 101,
    "version": 1,
    "level": 3,
    "task": 4002,
    "opcode": 33,
    "keywords": 9223372036854841344,
    "time_created": "2023-11-05T22:33:58.036338+00:00",
    "event_record_id": 44,
    "correlation": {
      "ActivityID": "E4DB489E-1037-0003-0982-DBE43710DA01"
    },
    "execution": {
      "process_id": 3160,
      "thread_id": 3556
    },
    "channel": "Microsoft-Windows-Diagnostics-Performance/Operational",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-19"
    }
  },
  "event_data": {
    "StartTime": "2023-11-05T22:32:00.970725Z",
    "NameLength": 28,
    "Name": "StartMenuExperienceHost.exe",
    "FriendlyNameLength": 30,
    "FriendlyName": "Windows Start Experience Host",
    "VersionLength": 39,
    "Version": "10.0.22621.2361 (WinBuild.160101.0800)",
    "TotalTime": 6125,
    "DegradationTime": 3625,
    "PathLength": 106,
    "Path": "C:\\Windows\\SystemApps\\Microsoft.Windows.StartMenuExperienceHost_cw5n1h2txyewy\\StartMenuExperienceHost.exe",
    "ProductNameLength": 37,
    "ProductName": "Microsoft® Windows® Operating System",
    "CompanyNameLength": 22,
    "CompanyName": "Microsoft Corporation"
  },
  "message": ""
}

References #

Event ID 102: This driver took longer to initialize, resulting in a performance degradation in the system start up process.

#
Channel
Operational
Level
Warning
Task
BootPerformanceMonitoring
Opcode
BootDegradation

Message #

This driver took longer to initialize, resulting in a performance degradation in the system start up process: 

     File Name		: %3

     Friendly Name		: %5

     Version		: %7

     Total Time		: %8ms

     Degradation Time	: %9ms

     Incident Time (UTC)	: %1

Fields #

NameDescription
StartTime FILETIME
NameLength UInt32
Name UnicodeString
FriendlyNameLength UInt32
FriendlyName UnicodeString
VersionLength UInt32
Version UnicodeString
TotalTime UInt32
DegradationTime UInt32
PathLength UInt32
Path UnicodeString
ProductNameLength UInt32
ProductName UnicodeString
CompanyNameLength UInt32
CompanyName UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Diagnostics-Performance",
    "guid": "CFC18EC0-96B1-4EBA-961B-622CAEE05B0A",
    "event_source_name": "",
    "event_id": 102,
    "version": 1,
    "level": 3,
    "task": 4002,
    "opcode": 33,
    "keywords": 9223372036854841344,
    "time_created": "2023-10-25T22:05:44.601509+00:00",
    "event_record_id": 25,
    "correlation": {
      "ActivityID": "028F2288-078F-0001-413E-8F028F07DA01"
    },
    "execution": {
      "process_id": 2484,
      "thread_id": 3796
    },
    "channel": "Microsoft-Windows-Diagnostics-Performance/Operational",
    "computer": "WinDevEval",
    "security": {
      "user_id": "S-1-5-19"
    }
  },
  "event_data": {
    "StartTime": "2023-10-25T22:02:56.552302Z",
    "NameLength": 7,
    "Name": "VfpExt",
    "FriendlyNameLength": 30,
    "FriendlyName": "Microsoft Azure VFP Extension",
    "VersionLength": 36,
    "Version": "10.0.22621.1 (WinBuild.160101.0800)",
    "TotalTime": 8403,
    "DegradationTime": 6903,
    "PathLength": 39,
    "Path": "C:\\Windows\\system32\\drivers\\vfpext.sys",
    "ProductNameLength": 37,
    "ProductName": "Microsoft® Windows® Operating System",
    "CompanyNameLength": 22,
    "CompanyName": "Microsoft Corporation"
  },
  "message": ""
}

References #

Event ID 103: This startup service took longer than expected to startup, resulting in a performance degradation in the system start up process.

#
Channel
Operational
Level
Warning
Task
BootPerformanceMonitoring
Opcode
BootDegradation

Message #

This startup service took longer than expected to startup, resulting in a performance degradation in the system start up process: 

     File Name		: %3

     Friendly Name		: %5

     Version		: %7

     Total Time		: %8ms

     Degradation Time	: %9ms

     Incident Time (UTC)	: %1

Fields #

NameDescription
StartTime FILETIME
NameLength UInt32
Name UnicodeString
FriendlyNameLength UInt32
FriendlyName UnicodeString
VersionLength UInt32
Version UnicodeString
TotalTime UInt32
DegradationTime UInt32
PathLength UInt32
Path UnicodeString
ProductNameLength UInt32
ProductName UnicodeString
CompanyNameLength UInt32
CompanyName UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Diagnostics-Performance",
    "guid": "{CFC18EC0-96B1-4EBA-961B-622CAEE05B0A}",
    "event_source_name": "",
    "event_id": 103,
    "version": 1,
    "level": 3,
    "task": 4002,
    "opcode": 33,
    "keywords": -9223372036854710272,
    "time_created": "2026-03-17T18:15:25.9842765+00:00",
    "event_record_id": 61,
    "correlation": {
      "ActivityID": "{B96DB0BB-B639-000A-71BF-6DB939B6DC01}"
    },
    "execution": {
      "process_id": 3740,
      "thread_id": 4612
    },
    "channel": "Microsoft-Windows-Diagnostics-Performance/Operational",
    "computer": "JD-WIN11-22H2-1.ludus.domain",
    "security": {
      "user_id": "S-1-5-19"
    }
  },
  "event_data": {
    "StartTime": "2026-03-17T18:13:15.4645682Z",
    "NameLength": "10",
    "Name": "windefend",
    "FriendlyNameLength": "0",
    "FriendlyName": "",
    "VersionLength": "0",
    "Version": "",
    "TotalTime": "326",
    "DegradationTime": "234",
    "PathLength": "80",
    "Path": "\"c:\\programdata\\microsoft\\windows defender\\platform\\4.18.26010.5-0\\msmpeng.exe\"",
    "ProductNameLength": "0",
    "ProductName": "",
    "CompanyNameLength": "0",
    "CompanyName": ""
  },
  "message": "This startup service took longer than expected to startup, resulting in a performance degradation in the system start up process: \r\n     File Name\t\t:\twindefend\r\n     Friendly Name\t\t:\t\r\n     Version\t\t:\t\r\n     Total Time\t\t:\t326ms\r\n     Degradation Time\t:\t234ms\r\n     Incident Time (UTC)\t:\t‎2026‎-‎03‎-‎17T18:13:15.464568200Z"
}

Event ID 104: Core system took longer to initialize, resulting in a performance degradation in the system start up process.

#
Channel
Operational
Task
BootPerformanceMonitoring
Opcode
BootDegradation

Message #

Core system took longer to initialize, resulting in a performance degradation in the system start up process: 

     Name		: %3

     Total Time		: %4ms

     Degradation Time	: %5ms

     Incident Time (UTC)	: %1

Fields #

NameDescription
StartTime FILETIME
NameLength UInt32
Name UnicodeString
TotalTime UInt32
DegradationTime UInt32

Event ID 105: Foreground optimizations (prefetching) took longer to complete, resulting in a performance degradation in the system start up process.

#
Channel
Operational
Task
BootPerformanceMonitoring
Opcode
BootDegradation

Message #

Foreground optimizations (prefetching) took longer to complete, resulting in a performance degradation in the system start up process: 

     Name		: %3

     Total Time		: %4ms

     Degradation Time	: %5ms

     Incident Time (UTC)	: %1

Fields #

NameDescription
StartTime FILETIME
NameLength UInt32
Name UnicodeString
TotalTime UInt32
DegradationTime UInt32

Event ID 106: Background optimizations (prefetching) took longer to complete, resulting in a performance degradation in the system start up process.

#
Channel
Operational
Task
BootPerformanceMonitoring
Opcode
BootDegradation

Message #

Background optimizations (prefetching) took longer to complete, resulting in a performance degradation in the system start up process: 

     Name		: %3

     Total Time		: %4ms

     Degradation Time	: %5ms

     Incident Time (UTC)	: %1

Fields #

NameDescription
StartTime FILETIME
NameLength UInt32
Name UnicodeString
TotalTime UInt32
DegradationTime UInt32

Event ID 107: Application of machine policy caused a slow down in the system start up process.

#
Channel
Operational
Level
Warning
Task
BootPerformanceMonitoring
Opcode
BootDegradation

Message #

Application of machine policy caused a slow down in the system start up process: 

     Name		: %3

     Total Time		: %4ms

     Degradation Time	: %5ms

     Incident Time (UTC)	: %1

Fields #

NameDescription
StartTime FILETIME
NameLength UInt32
Name UnicodeString
TotalTime UInt32
DegradationTime UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Diagnostics-Performance",
    "guid": "CFC18EC0-96B1-4EBA-961B-622CAEE05B0A",
    "event_source_name": "",
    "event_id": 107,
    "version": 1,
    "level": 3,
    "task": 4002,
    "opcode": 33,
    "keywords": 9223372036854841344,
    "time_created": "2026-02-10T04:13:48.386918+00:00",
    "event_record_id": 13,
    "correlation": {
      "ActivityID": "43A6D212-9A2A-0007-EC4C-A7432A9ADC01"
    },
    "execution": {
      "process_id": 3924,
      "thread_id": 4184
    },
    "channel": "Microsoft-Windows-Diagnostics-Performance/Operational",
    "computer": "LAB-WIN11.ludus.domain",
    "security": {
      "user_id": "S-1-5-19"
    }
  },
  "event_data": {
    "StartTime": "2026-02-10T01:12:02.866821Z",
    "NameLength": 25,
    "Name": "MachinePolicyApplication",
    "TotalTime": 2121,
    "DegradationTime": 1121
  },
  "message": ""
}

Event ID 108: Application of user policy caused a slow down in the system start up process.

#
Channel
Operational
Level
Warning
Task
BootPerformanceMonitoring
Opcode
BootDegradation

Message #

Application of user policy caused a slow down in the system start up process: 

     Name		: %3

     Total Time		: %4ms

     Degradation Time	: %5ms

     Incident Time (UTC)	: %1

Fields #

NameDescription
StartTime FILETIME
NameLength UInt32
Name UnicodeString
TotalTime UInt32
DegradationTime UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Diagnostics-Performance",
    "guid": "cfc18ec0-96b1-4eba-961b-622caee05b0a",
    "event_source_name": "",
    "event_id": 108,
    "version": 1,
    "level": 3,
    "task": 4002,
    "opcode": 33,
    "keywords": 9223372036854841344,
    "time_created": "2026-07-04T19:59:42.5676646+00:00",
    "event_record_id": 140,
    "correlation": {
      "ActivityID": "aa915e67-0bb4-000b-997f-91aab40bdd01",
      "RelatedActivityID": ""
    },
    "execution": {
      "process_id": 2944,
      "thread_id": 6700
    },
    "channel": "Microsoft-Windows-Diagnostics-Performance/Operational",
    "computer": "JD-WIN11-22H2-1.ludus.domain",
    "security": {
      "user_id": "S-1-5-19"
    }
  },
  "event_data": {
    "StartTime": "2026-07-04T12:57:27.4665423Z",
    "NameLength": "13",
    "Name": "PreShellInit",
    "TotalTime": "4933",
    "DegradationTime": "933"
  },
  "message": "Application of user policy caused a slow down in the system start up process: \r\n     Name\t\t:\tPreShellInit\r\n     Total Time\t\t:\t4933ms\r\n     Degradation Time\t:\t933ms\r\n     Incident Time (UTC)\t:\t‎2026‎-‎07‎-‎04T12:57:27.466542300Z"
}

Event ID 109: This device took longer to initialize, resulting in a performance degradation in the system start up process.

#
Channel
Operational
Task
BootPerformanceMonitoring
Opcode
BootDegradation

Message #

This device took longer to initialize, resulting in a performance degradation in the system start up process: 

     File Name		: %3

     Friendly Name		: %5

     Version		: %7

     Total Time		: %8ms

     Degradation Time	: %9ms

     Incident Time (UTC)	: %1

Fields #

NameDescription
StartTime FILETIME
NameLength UInt32
Name UnicodeString
FriendlyNameLength UInt32
FriendlyName UnicodeString
VersionLength UInt32
Version UnicodeString
TotalTime UInt32
DegradationTime UInt32
PathLength UInt32
Path UnicodeString
ProductNameLength UInt32
ProductName UnicodeString
CompanyNameLength UInt32
CompanyName UnicodeString

Event ID 110: Session manager initialization caused a slow down in the startup process.

#
Channel
Operational
Level
Warning
Task
BootPerformanceMonitoring
Opcode
BootDegradation

Message #

Session manager initialization caused a slow down in the startup process: 

     Name		: %3

     Total Time		: %4ms

     Degradation Time	: %5ms

     Incident Time (UTC)	: %1

Fields #

NameDescription
StartTime FILETIME
NameLength UInt32
Name UnicodeString
TotalTime UInt32
DegradationTime UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Diagnostics-Performance",
    "guid": "CFC18EC0-96B1-4EBA-961B-622CAEE05B0A",
    "event_source_name": "",
    "event_id": 110,
    "version": 1,
    "level": 3,
    "task": 4002,
    "opcode": 33,
    "keywords": 9223372036854841344,
    "time_created": "2023-10-25T22:05:44.601513+00:00",
    "event_record_id": 26,
    "correlation": {
      "ActivityID": "028F2288-078F-0001-413E-8F028F07DA01"
    },
    "execution": {
      "process_id": 2484,
      "thread_id": 3796
    },
    "channel": "Microsoft-Windows-Diagnostics-Performance/Operational",
    "computer": "WinDevEval",
    "security": {
      "user_id": "S-1-5-19"
    }
  },
  "event_data": {
    "StartTime": "2023-10-25T22:02:56.552302Z",
    "NameLength": 9,
    "Name": "SMSSInit",
    "TotalTime": 17567,
    "DegradationTime": 7567
  },
  "message": ""
}

References #

Event ID 200: Windows has shutdown.

#
Channel
Operational
Level
Warning
Task
ShutdownPerformanceMonitoring
Opcode
ShutdownInformation

Message #

Windows has shutdown: 

     Shutdown Duration	: %4ms

     IsDegradation		: %16

     Incident Time (UTC)	: %2

Fields #

NameDescription
ShutdownTsVersion UInt32
ShutdownStartTime FILETIME
ShutdownEndTime FILETIME
ShutdownTime UInt32
ShutdownUserSessionTime UInt32
ShutdownUserPolicyTime UInt32
ShutdownUserProfilesTime UInt32
ShutdownSystemSessionsTime UInt32
ShutdownPreShutdownNotificationsTime UInt32
ShutdownServicesTime UInt32
ShutdownKernelTime UInt32
ShutdownRootCauseStepImprovementBits UInt32
ShutdownRootCauseGradualImprovementBits UInt32
ShutdownRootCauseStepDegradationBits UInt32
ShutdownRootCauseGradualDegradationBits UInt32
ShutdownIsDegradation Boolean
ShutdownTimeChange Int32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Diagnostics-Performance",
    "guid": "CFC18EC0-96B1-4EBA-961B-622CAEE05B0A",
    "event_source_name": "",
    "event_id": 200,
    "version": 1,
    "level": 3,
    "task": 4007,
    "opcode": 40,
    "keywords": 9223372036854841344,
    "time_created": "2023-11-05T22:33:56.991516+00:00",
    "event_record_id": 36,
    "correlation": {
      "ActivityID": "E4DB489E-1037-0001-FD89-DBE43710DA01"
    },
    "execution": {
      "process_id": 3160,
      "thread_id": 3468
    },
    "channel": "Microsoft-Windows-Diagnostics-Performance/Operational",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-19"
    }
  },
  "event_data": {
    "ShutdownTsVersion": 1,
    "ShutdownStartTime": "2023-11-05T22:31:30.287074Z",
    "ShutdownEndTime": "2023-11-05T22:31:43.106260Z",
    "ShutdownTime": 12819,
    "ShutdownUserSessionTime": 3778,
    "ShutdownUserPolicyTime": 17,
    "ShutdownUserProfilesTime": 236,
    "ShutdownSystemSessionsTime": 6148,
    "ShutdownPreShutdownNotificationsTime": 1596,
    "ShutdownServicesTime": 4185,
    "ShutdownKernelTime": 2892,
    "ShutdownRootCauseStepImprovementBits": 0,
    "ShutdownRootCauseGradualImprovementBits": 0,
    "ShutdownRootCauseStepDegradationBits": 72,
    "ShutdownRootCauseGradualDegradationBits": 0,
    "ShutdownIsDegradation": true,
    "ShutdownTimeChange": 0
  },
  "message": ""
}

References #

Event ID 201: This application caused a delay in the system shutdown process.

#
Channel
Operational
Task
ShutdownPerformanceMonitoring
Opcode
ShutdownDegradation

Message #

This application caused a delay in the system shutdown process: 

     File Name		: %3

     Friendly Name		: %5

     Version		: %7

     Total Time		: %8ms

     Degradation Time	: %9ms

     Incident Time (UTC)	: %1

Fields #

NameDescription
StartTime FILETIME
NameLength UInt32
Name UnicodeString
FriendlyNameLength UInt32
FriendlyName UnicodeString
VersionLength UInt32
Version UnicodeString
TotalTime UInt32
DegradationTime UInt32
PathLength UInt32
Path UnicodeString
ProductNameLength UInt32
ProductName UnicodeString
CompanyNameLength UInt32
CompanyName UnicodeString

Event ID 202: This device caused a delay in the system shutdown process.

#
Channel
Operational
Task
ShutdownPerformanceMonitoring
Opcode
ShutdownDegradation

Message #

This device caused a delay in the system shutdown process: 

     File Name		: %3

     Friendly Name		: %5

     Version		: %7

     Total Time		: %8ms

     Degradation Time	: %9ms

     Incident Time (UTC)	: %1

Fields #

NameDescription
StartTime FILETIME
NameLength UInt32
Name UnicodeString
FriendlyNameLength UInt32
FriendlyName UnicodeString
VersionLength UInt32
Version UnicodeString
TotalTime UInt32
DegradationTime UInt32
PathLength UInt32
Path UnicodeString
ProductNameLength UInt32
ProductName UnicodeString
CompanyNameLength UInt32
CompanyName UnicodeString

Event ID 203: This service caused a delay in the system shutdown process.

#
Channel
Operational
Level
Warning
Task
ShutdownPerformanceMonitoring
Opcode
ShutdownDegradation

Message #

This service caused a delay in the system shutdown process: 

     File Name		: %3

     Friendly Name		: %5

     Version		: %7

     Total Time		: %8ms

     Degradation Time	: %9ms

     Incident Time (UTC)	: %1

Fields #

NameDescription
StartTime FILETIME
NameLength UInt32
Name UnicodeString
FriendlyNameLength UInt32
FriendlyName UnicodeString
VersionLength UInt32
Version UnicodeString
TotalTime UInt32
DegradationTime UInt32
PathLength UInt32
Path UnicodeString
ProductNameLength UInt32
ProductName UnicodeString
CompanyNameLength UInt32
CompanyName UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Diagnostics-Performance",
    "guid": "CFC18EC0-96B1-4EBA-961B-622CAEE05B0A",
    "event_source_name": "",
    "event_id": 203,
    "version": 1,
    "level": 3,
    "task": 4007,
    "opcode": 41,
    "keywords": 9223372036854841344,
    "time_created": "2023-11-05T22:33:56.991549+00:00",
    "event_record_id": 37,
    "correlation": {
      "ActivityID": "E4DB489E-1037-0001-FD89-DBE43710DA01"
    },
    "execution": {
      "process_id": 3160,
      "thread_id": 3468
    },
    "channel": "Microsoft-Windows-Diagnostics-Performance/Operational",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-19"
    }
  },
  "event_data": {
    "StartTime": "2023-11-05T22:31:30.287074Z",
    "NameLength": 10,
    "Name": "WinDefend",
    "FriendlyNameLength": 0,
    "FriendlyName": "",
    "VersionLength": 0,
    "Version": "",
    "TotalTime": 4054,
    "DegradationTime": 54,
    "PathLength": 83,
    "Path": "\"c:\\programdata\\microsoft\\windows defender\\platform\\4.18.23090.2008-0\\msmpeng.exe\"",
    "ProductNameLength": 0,
    "ProductName": "",
    "CompanyNameLength": 0,
    "CompanyName": ""
  },
  "message": ""
}

References #

Event ID 300: Windows has resumed from standby.

#
Channel
Operational
Task
StandbyPerformanceMonitoring
Opcode
StandbyInformation

Message #

Windows has resumed from standby: 

     Standby Duration		: %7ms

     Standby Incident Time (UTC)	: %5

     Resume  Duration		: %39ms

     Resume  Incident Time (UTC)	: %37

     IsDegradation			: %51

Fields #

NameDescription
StandbyTsVersion UInt32
StandbyAppCount UInt32
StandbyServicesCount UInt32
StandbyDevicesCount UInt32
StandbyStartTime FILETIME
StandbyEndTime FILETIME
StandbySuspendTotal UInt32
StandbySuspendTotalChange Int32
StandbySuspendQueryApps UInt32
StandbySuspendQueryAppsChange Int32
StandbySuspendQueryServices UInt32
StandbySuspendQueryServicesChange Int32
StandbySuspendApps UInt32
StandbySuspendAppsChange Int32
StandbySuspendServices UInt32
StandbySuspendServicesChange Int32
StandbySuspendShowUI UInt32
StandbySuspendShowUIChange Int32
StandbySuspendSuperfetchPageIn UInt32
StandbySuspendSuperfetchPageInChange Int32
StandbySuspendWinlogon UInt32
StandbySuspendWinlogonChange Int32
StandbySuspendLockPageableSections UInt32
StandbySuspendLockPageableSectionsChange Int32
StandbySuspendPreSleepCallbacks UInt32
StandbySuspendPreSleepCallbacksChange Int32
StandbySuspendSwapInWorkerThreads UInt32
StandbySuspendSwapInWorkerThreadsChange Int32
StandbySuspendQueryDevices UInt32
StandbySuspendQueryDevicesChange Int32
StandbySuspendFlushVolumes UInt32
StandbySuspendFlushVolumesChange Int32
StandbySuspendSuspendDevices UInt32
StandbySuspendSuspendDevicesChange Int32
StandbySuspendHibernateWrite UInt32
StandbySuspendHibernateWriteChange Int32
ResumeStartTime FILETIME
ResumeEndTime FILETIME
StandbyResumeTotal UInt32
StandbyResumeTotalChange Int32
StandbyResumeHibernateRead UInt32
StandbyResumeHibernateReadChange Int32
StandbyResumeS3BiosInitTime UInt32
StandbyResumeS3BiosInitTimeChange Int32
StandbyResumeResumeDevices UInt32
StandbyResumeResumeDevicesChange Int32
StandbyRootCauseDegradationGradual UInt32
StandbyRootCauseImprovementGradual UInt32
StandbyRootCauseDegradationStep UInt32
StandbyRootCauseImprovementStep UInt32
StandbyIsDegradation Boolean
StandbyIsTroubleshooterLaunched Boolean
StandbyIsRootCauseIdentified Boolean

Event ID 301: This application caused a delay during standby.

#
Channel
Operational
Task
StandbyPerformanceMonitoring
Opcode
StandbyDegradation

Message #

This application caused a delay during standby: 

     File Name		: %3

     Friendly Name		: %5

     Version		: %7

     Total Time		: %8ms

     Degradation Time	: %9ms

     Incident Time (UTC)	: %1

Fields #

NameDescription
StartTime FILETIME
NameLength UInt32
Name UnicodeString
FriendlyNameLength UInt32
FriendlyName UnicodeString
VersionLength UInt32
Version UnicodeString
TotalTime UInt32
DegradationTime UInt32
PathLength UInt32
Path UnicodeString
ProductNameLength UInt32
ProductName UnicodeString
CompanyNameLength UInt32
CompanyName UnicodeString

Event ID 302: This driver caused a delay during standby while servicing a device.

#
Channel
Operational
Task
StandbyPerformanceMonitoring
Opcode
StandbyDegradation

Message #

This driver caused a delay during standby while servicing a device:

     Driver File Name		: %3

     Driver Friendly Name		: %5

     Driver Version			: %7

     Driver Total Time		: %8ms

     Driver Degradation Time	: %9ms

     Incident Time (UTC)		: %1

     Device Name			: %17

     Device Friendly Name		: %19

     Device Total Time		: %20ms

     Device Degradation Time	: %21ms

Fields #

NameDescription
StartTime FILETIME
NameLength UInt32
Name UnicodeString
FriendlyNameLength UInt32
FriendlyName UnicodeString
VersionLength UInt32
Version UnicodeString
TotalTime UInt32
DegradationTime UInt32
PathLength UInt32
Path UnicodeString
ProductNameLength UInt32
ProductName UnicodeString
CompanyNameLength UInt32
CompanyName UnicodeString
DeviceNameLength UInt32
DeviceName UnicodeString
DeviceFriendlyNameLength UInt32
DeviceFriendlyName UnicodeString
DeviceTotalTime UInt32
DeviceDegradationTime UInt32

Event ID 303: This service caused a delay during hybrid-sleep.

#
Channel
Operational
Task
StandbyPerformanceMonitoring
Opcode
StandbyDegradation

Message #

This service caused a delay during hybrid-sleep: 

     File Name		: %3

     Friendly Name		: %5

     Version		: %7

     Total Time		: %8ms

     Degradation Time	: %9ms

     Incident Time (UTC)	: %1

Fields #

NameDescription
StartTime FILETIME
NameLength UInt32
Name UnicodeString
FriendlyNameLength UInt32
FriendlyName UnicodeString
VersionLength UInt32
Version UnicodeString
TotalTime UInt32
DegradationTime UInt32
PathLength UInt32
Path UnicodeString
ProductNameLength UInt32
ProductName UnicodeString
CompanyNameLength UInt32
CompanyName UnicodeString

Event ID 304: Creation of the hiber-file was slower than expected.

#
Channel
Operational
Task
StandbyPerformanceMonitoring
Opcode
StandbyDegradation

Message #

Creation of the hiber-file was slower than expected: 

     Name		: %3

     Total Time		: %4ms

     Degradation Time	: %5ms

     Incident Time (UTC)	: %1

Fields #

NameDescription
StartTime FILETIME
NameLength UInt32
Name UnicodeString
TotalTime UInt32
DegradationTime UInt32

Event ID 305: Persisting disk caches was slower than expected.

#
Channel
Operational
Task
StandbyPerformanceMonitoring
Opcode
StandbyDegradation

Message #

Persisting disk caches was slower than expected: 

     Name		: %3

     Total Time		: %4ms

     Degradation Time	: %5ms

     Incident Time (UTC)	: %1

Fields #

NameDescription
StartTime FILETIME
NameLength UInt32
Name UnicodeString
TotalTime UInt32
DegradationTime UInt32

Event ID 306: Preparing the video subsystem for sleep was slower than expected.

#
Channel
Operational
Task
StandbyPerformanceMonitoring
Opcode
StandbyDegradation

Message #

Preparing the video subsystem for sleep was slower than expected: 

     Name		: %3

     Total Time		: %4ms

     Degradation Time	: %5ms

     Incident Time (UTC)	: %1

Fields #

NameDescription
StartTime FILETIME
NameLength UInt32
Name UnicodeString
TotalTime UInt32
DegradationTime UInt32

Event ID 307: Preparing Winlogon for sleep was slower than expected.

#
Channel
Operational
Task
StandbyPerformanceMonitoring
Opcode
StandbyDegradation

Message #

Preparing Winlogon for sleep was slower than expected: 

     Name		: %3

     Total Time		: %4ms

     Degradation Time	: %5ms

     Incident Time (UTC)	: %1

Fields #

NameDescription
StartTime FILETIME
NameLength UInt32
Name UnicodeString
TotalTime UInt32
DegradationTime UInt32

Event ID 308: Preparing system memory for sleep was slower than expected.

#
Channel
Operational
Task
StandbyPerformanceMonitoring
Opcode
StandbyDegradation

Message #

Preparing system memory for sleep was slower than expected: 

     Name		: %3

     Total Time		: %4ms

     Degradation Time	: %5ms

     Incident Time (UTC)	: %1

Fields #

NameDescription
StartTime FILETIME
NameLength UInt32
Name UnicodeString
TotalTime UInt32
DegradationTime UInt32

Event ID 309: Preparing core system for sleep was slower than expected.

#
Channel
Operational
Task
StandbyPerformanceMonitoring
Opcode
StandbyDegradation

Message #

Preparing core system for sleep was slower than expected: 

     Name		: %3

     Total Time		: %4ms

     Degradation Time	: %5ms

     Incident Time (UTC)	: %1

Fields #

NameDescription
StartTime FILETIME
NameLength UInt32
Name UnicodeString
TotalTime UInt32
DegradationTime UInt32

Event ID 310: Preparing system worker threads for sleep was slower than expected.

#
Channel
Operational
Task
StandbyPerformanceMonitoring
Opcode
StandbyDegradation

Message #

Preparing system worker threads for sleep was slower than expected: 

     Name		: %3

     Total Time		: %4ms

     Degradation Time	: %5ms

     Incident Time (UTC)	: %1

Fields #

NameDescription
StartTime FILETIME
NameLength UInt32
Name UnicodeString
TotalTime UInt32
DegradationTime UInt32

Event ID 350: Bios initialization time was greater than 250ms (logo requirement) during system resume.

#
Channel
Operational
Task
StandbyPerformanceMonitoring
Opcode
StandbyDegradation

Message #

Bios initialization time was greater than 250ms (logo requirement) during system resume: 

     Name		: %3

     Total Time		: %4ms

     Degradation Time	: %5ms

     Incident Time (UTC)	: %1

Fields #

NameDescription
StartTime FILETIME
NameLength UInt32
Name UnicodeString
TotalTime UInt32
DegradationTime UInt32

Event ID 351: This driver responded slower than expected to the resume request while servicing this device.

#
Channel
Operational
Task
StandbyPerformanceMonitoring
Opcode
StandbyDegradation

Message #

This driver responded slower than expected to the resume request while servicing this device: 

     Driver File Name		: %3

     Driver Friendly Name		: %5

     Driver Version			: %7

     Driver Total Time		: %8ms

     Driver Degradation Time	: %9ms

     Incident Time (UTC)		: %1

     Device Name			: %17

     Device Friendly Name		: %19

     Device Total Time		: %20ms

     Device Degradation Time	: %21ms

Fields #

NameDescription
StartTime FILETIME
NameLength UInt32
Name UnicodeString
FriendlyNameLength UInt32
FriendlyName UnicodeString
VersionLength UInt32
Version UnicodeString
TotalTime UInt32
DegradationTime UInt32
PathLength UInt32
Path UnicodeString
ProductNameLength UInt32
ProductName UnicodeString
CompanyNameLength UInt32
CompanyName UnicodeString
DeviceNameLength UInt32
DeviceName UnicodeString
DeviceFriendlyNameLength UInt32
DeviceFriendlyName UnicodeString
DeviceTotalTime UInt32
DeviceDegradationTime UInt32

Event ID 352: Reading the hiber-file was slower than expected.

#
Channel
Operational
Task
StandbyPerformanceMonitoring
Opcode
StandbyDegradation

Message #

Reading the hiber-file was slower than expected: 

     Name		: %3

     Total Time		: %4ms

     Degradation Time	: %5ms

     Incident Time (UTC)	: %1

Fields #

NameDescription
StartTime FILETIME
NameLength UInt32
Name UnicodeString
TotalTime UInt32
DegradationTime UInt32

Event ID 400: Information about the system performance monitoring event.

#
Channel
Operational
Task
SystemPerformanceMonitoring
Opcode
ShellInformation

Message #

Information about the system performance monitoring event: 

     Scenario		: %3

     Analysis result		: %6

     Incident Time (UTC)	: %1

Fields #

NameDescription
ShellScenarioStartTime FILETIME
ShellScenarioEndTime FILETIME
ShellSubScenario UInt32
ShellScenarioDuration UInt32
ShellRootCauseBits UInt32
ShellAnalysisResult UInt32
ShellDegradationType UInt32
ShellTsVersion UInt32
ShellMachineUpTimeHours UInt32
ShellMachineSleepPattern UInt32

Event ID 401: This process is using up processor time and is impacting the performance of Windows.

#
Channel
Operational
Task
SystemPerformanceMonitoring
Opcode
ShellDegradation

Message #

This process is using up processor time and is impacting the performance of Windows: 

     File Name		: %3

     Friendly Name		: %5

     Version		: %7

     Thread time		: %8ms

     Blocked Time		: %9ms

     Incident Time (UTC)	: %1

Fields #

NameDescription
StartTime FILETIME
NameLength UInt32
Name UnicodeString
FriendlyNameLength UInt32
FriendlyName UnicodeString
VersionLength UInt32
Version UnicodeString
ThreadTime UInt32
BlockedTime UInt32
PercentTime Double
PathLength UInt32
Path UnicodeString
ProductNameLength UInt32
ProductName UnicodeString
CompanyNameLength UInt32
CompanyName UnicodeString

Event ID 402: This process is doing excessive disk activities and is impacting the performance of Windows.

#
Channel
Operational
Task
SystemPerformanceMonitoring
Opcode
ShellDegradation

Message #

This process is doing excessive disk activities and is impacting the performance of Windows: 

     File Name		: %3

     Friendly Name		: %5

     Version		: %7

     Thread time		: %8ms

     Blocked Time		: %9ms

     Incident Time (UTC)	: %1

Fields #

NameDescription
StartTime FILETIME
NameLength UInt32
Name UnicodeString
FriendlyNameLength UInt32
FriendlyName UnicodeString
VersionLength UInt32
Version UnicodeString
ThreadTime UInt32
BlockedTime UInt32
PercentTime Double
PathLength UInt32
Path UnicodeString
ProductNameLength UInt32
ProductName UnicodeString
CompanyNameLength UInt32
CompanyName UnicodeString

Event ID 403: This driver is using up too many resources and is impacting the performance of Windows.

#
Channel
Operational
Task
SystemPerformanceMonitoring
Opcode
ShellDegradation

Message #

This driver is using up too many resources and is impacting the performance of Windows: 

     File Name		: %3

     Friendly Name		: %5

     Version		: %7

     Thread time		: %8ms

     Blocked Time		: %9ms

     Incident Time (UTC)	: %1

Fields #

NameDescription
StartTime FILETIME
NameLength UInt32
Name UnicodeString
FriendlyNameLength UInt32
FriendlyName UnicodeString
VersionLength UInt32
Version UnicodeString
ThreadTime UInt32
BlockedTime UInt32
PercentTime Double
PathLength UInt32
Path UnicodeString
ProductNameLength UInt32
ProductName UnicodeString
CompanyNameLength UInt32
CompanyName UnicodeString

Event ID 404: This driver is waiting longer than expected on a device.

#
Channel
Operational
Task
SystemPerformanceMonitoring
Opcode
ShellDegradation

Message #

This driver is waiting longer than expected on a device: 

     File Name		: %3

     Friendly Name		: %5

     Version		: %7

     Thread time		: %8ms

     Blocked Time		: %9ms

     Incident Time (UTC)	: %1

Fields #

NameDescription
StartTime FILETIME
NameLength UInt32
Name UnicodeString
FriendlyNameLength UInt32
FriendlyName UnicodeString
VersionLength UInt32
Version UnicodeString
ThreadTime UInt32
BlockedTime UInt32
PercentTime Double
PathLength UInt32
Path UnicodeString
ProductNameLength UInt32
ProductName UnicodeString
CompanyNameLength UInt32
CompanyName UnicodeString

Event ID 405: This file is fragmented and is impacting the performance of Windows.

#
Channel
Operational
Task
SystemPerformanceMonitoring
Opcode
ShellDegradation

Message #

This file is fragmented and is impacting the performance of Windows: 

     File Name		: %3

     Friendly Name		: %5

     Version		: %7

     Thread time		: %8ms

     Blocked Time		: %9ms

     Incident Time (UTC)	: %1

Fields #

NameDescription
StartTime FILETIME
NameLength UInt32
Name UnicodeString
FriendlyNameLength UInt32
FriendlyName UnicodeString
VersionLength UInt32
Version UnicodeString
ThreadTime UInt32
BlockedTime UInt32
PercentTime Double
PathLength UInt32
Path UnicodeString
ProductNameLength UInt32
ProductName UnicodeString
CompanyNameLength UInt32
CompanyName UnicodeString

Event ID 406: Disk IO to this file is taking longer than expected.

#
Channel
Operational
Task
SystemPerformanceMonitoring
Opcode
ShellDegradation

Message #

Disk IO to this file is taking longer than expected: 

     File Name		: %3

     Friendly Name		: %5

     Version		: %7

     Thread time		: %8ms

     Blocked Time		: %9ms

     Incident Time (UTC)	: %1

Fields #

NameDescription
StartTime FILETIME
NameLength UInt32
Name UnicodeString
FriendlyNameLength UInt32
FriendlyName UnicodeString
VersionLength UInt32
Version UnicodeString
ThreadTime UInt32
BlockedTime UInt32
PercentTime Double
PathLength UInt32
Path UnicodeString
ProductNameLength UInt32
ProductName UnicodeString
CompanyNameLength UInt32
CompanyName UnicodeString

Event ID 407: This process is using up too much system memory.

#
Channel
Operational
Task
SystemPerformanceMonitoring
Opcode
ShellDegradation

Message #

This process is using up too much system memory: 

     File Name		: %3

     Friendly Name		: %5

     Version		: %7

     Workingset size	: %8Kb

     Percent memory	: %11

     Incident Time (UTC)	: %1

Fields #

NameDescription
StartTime FILETIME
NameLength UInt32
Name UnicodeString
FriendlyNameLength UInt32
FriendlyName UnicodeString
VersionLength UInt32
Version UnicodeString
WorkingSetSizeKb UInt32
PeakWorkingSetSizeKb UInt32
ProcessId UInt32
PercentMemory Double
PathLength UInt32
Path UnicodeString
ProductNameLength UInt32
ProductName UnicodeString
CompanyNameLength UInt32
CompanyName UnicodeString

Event ID 408: Many processes are using too much system memory.

#
Channel
Operational
Task
SystemPerformanceMonitoring
Opcode
ShellDegradation

Message #

Many processes are using too much system memory: 

     Workingset size	: %2Kb

     Percent memory	: %3

     Incident Time (UTC)	: %1

Fields #

NameDescription
StartTime FILETIME
WorkingSetSizeKb UInt32
PercentMemory Double

Event ID 500: The Desktop Window Manager is experiencing heavy resource contention.

#
Channel
Operational
Task
DesktopWindowManagerMonitoring
Opcode
VideoMemoryDegradation

Message #

The Desktop Window Manager is experiencing heavy resource contention. 

     Scenario	: %5

Fields #

NameDescription
DisplayDeviceFriendlyNameLength UInt32
DisplayDeviceFriendlyName UnicodeString
MemoryBandwidth UInt32
MemorySize UInt32
Scenario UInt32

Event ID 501: The Desktop Window Manager is experiencing heavy resource contention.

#
Channel
Operational
Task
DesktopWindowManagerMonitoring
Opcode
VideoMemoryResponsiveness

Message #

The Desktop Window Manager is experiencing heavy resource contention.

     Reason	: %1

     Diagnosis	: %2

Fields #

NameDescription
Reason UInt32
Diagnosis UInt32

Event ID 1001: Status

#
Channel
Diagnostic
Task
Boot_DMConfig
Opcode
Failed

Fields #

NameDescription
HResult UInt32

Event ID 1002: Status

#
Channel
Diagnostic
Task
Boot_UnexpectedEvent

Fields #

NameDescription
GUID GUID
EventId UInt16
InternalState UInt32

Event ID 1003: Status

#
Channel
Diagnostic
Task
Boot_ChangedState

Fields #

NameDescription
NewState UInt32

Event ID 1005: Status

#
Channel
Diagnostic
Task
Boot_CapturedDCL

Fields #

NameDescription
HResult UInt32

Event ID 1006: Status

#
Channel
Diagnostic
Task
Boot_DetectedMultipleLogons

Event ID 1007: Status

#
Channel
Diagnostic
Task
Boot_ReceivedEvent

Fields #

NameDescription
GUID GUID
EventId UInt16
InternalState UInt32

Event ID 1010: Status

#
Channel
Diagnostic
Task
Boot_Troubleshooting
Opcode
Start

Event ID 1011: Status

#
Channel
Diagnostic
Task
Boot_Troubleshooting
Opcode
Stop

Fields #

NameDescription
HResult UInt32

Event ID 1012: Status

#
Channel
Diagnostic
Task
Boot_ProcessingSystem
Opcode
Start

Event ID 1013: Status

#
Channel
Diagnostic
Task
Boot_ProcessingSystem
Opcode
Stop

Fields #

NameDescription
HResult UInt32

Event ID 1014: Status

#
Channel
Diagnostic
Task
Boot_ProcessingUser
Opcode
Start

Event ID 1015: Status

#
Channel
Diagnostic
Task
Boot_ProcessingUser
Opcode
Stop

Fields #

NameDescription
HResult UInt32

Event ID 1020: Status

#
Channel
Diagnostic
Task
Boot_ArchiveCorrupt

Fields #

NameDescription
HResult UInt32

Event ID 1022: Status

#
Channel
Diagnostic
Task
Boot_CancelledAnalysisViaRegistry

Event ID 1024: Status

#
Channel
Diagnostic
Task
Boot_RurReadAhead
Opcode
Start

Event ID 1025: Status

#
Channel
Diagnostic
Task
Boot_RurReadAhead
Opcode
Stop

Fields #

NameDescription
HResult UInt32

Event ID 1026: Status

#
Channel
Diagnostic
Task
Boot_RurLegacyResource
Opcode
Start

Event ID 1027: Status

#
Channel
Diagnostic
Task
Boot_RurLegacyResource
Opcode
Stop

Event ID 1028: Status

#
Channel
Diagnostic
Task
Boot_RurAppResourceUsage
Opcode
Start

Event ID 1029: Status

#
Channel
Diagnostic
Task
Boot_RurAppResourceUsage
Opcode
Stop

Fields #

NameDescription
HResult UInt32

Event ID 1030: Status

#
Channel
Diagnostic
Task
Boot_RurPostLogonResourceUsage
Opcode
Start

Event ID 1031: Status

#
Channel
Diagnostic
Task
Boot_RurPostLogonResourceUsage
Opcode
Stop

Fields #

NameDescription
HResult UInt32

Event ID 2001: Status

#
Channel
Diagnostic
Task
Shell_DegradationDetected
Opcode
StepUp

Event ID 2002: Status

#
Channel
Diagnostic
Task
Shell_DegradationDetected
Opcode
StepDown

Event ID 2003: Status

#
Channel
Diagnostic
Task
Shell_DegradationDetected
Opcode
GradualUp

Event ID 2004: Status

#
Channel
Diagnostic
Task
Shell_DegradationDetected
Opcode
GradualDown

Event ID 2005: Status

#
Channel
Diagnostic
Task
Scenario_CapturedCKCL

Fields #

NameDescription
HResult UInt32
SnapshotPath UnicodeString

Event ID 2006: Status

#
Channel
Diagnostic
Task
Scenario_CapturedDCL

Fields #

NameDescription
HResult UInt32
SnapshotPath UnicodeString

Event ID 2007: Status

#
Channel
Diagnostic
Task
Scenario_SimpleEvent
Opcode
Start

Fields #

NameDescription
ProviderId GUID
EventId UInt16
HResult UInt32

Event ID 2008: Status

#
Channel
Diagnostic
Task
Scenario_SimpleEvent
Opcode
Stop

Fields #

NameDescription
ProviderId GUID
EventId UInt16
HResult UInt32

Event ID 2009: Status

#
Channel
Diagnostic
Task
Scenario_StartEvent
Opcode
Start

Fields #

NameDescription
ProviderId GUID
EventId UInt16
HResult UInt32

Event ID 2010: Status

#
Channel
Diagnostic
Task
Scenario_StartEvent
Opcode
Stop

Fields #

NameDescription
ProviderId GUID
EventId UInt16
HResult UInt32

Event ID 2011: Status

#
Channel
Diagnostic
Task
Scenario_StopEvent
Opcode
Start

Fields #

NameDescription
ProviderId GUID
EventId UInt16
HResult UInt32

Event ID 2012: Status

#
Channel
Diagnostic
Task
Scenario_StopEvent
Opcode
Stop

Fields #

NameDescription
ProviderId GUID
EventId UInt16
HResult UInt32

Event ID 2013: Status

#
Channel
Diagnostic
Task
Scenario_ProblemDetection
Opcode
Start

Fields #

NameDescription
ScenarioGUID GUID
HResult UInt32

Event ID 2014: Status

#
Channel
Diagnostic
Task
Scenario_ProblemDetection
Opcode
Stop

Fields #

NameDescription
ScenarioGUID GUID
HResult UInt32

Event ID 2015: Status

#
Channel
Diagnostic
Task
Scenario_TroubleShoot
Opcode
Start

Fields #

NameDescription
ScenarioGUID GUID
HResult UInt32

Event ID 2016: Status

#
Channel
Diagnostic
Task
Scenario_TroubleShoot
Opcode
Stop

Fields #

NameDescription
ScenarioGUID GUID
HResult UInt32

Event ID 7001: Status

#
Channel
Loopback
Task
Boot_Loopback_SnapshotKMScenario

Event ID 7101: Status

#
Channel
Loopback
Task
BootApps_ResolverLoopback

Event ID 7102: Status

#
Channel
Loopback
Task
BootDrivers_ResolverLoopback

Event ID 7103: Status

#
Channel
Loopback
Task
ShutdownApps_ResolverLoopback

Event ID 7104: Status

#
Channel
Loopback
Task
SuspendApps_ResolverLoopback

Event ID 7105: Status

#
Channel
Loopback
Task
SuspendDrivers_ResolverLoopback

Event ID 7106: Status

#
Channel
Loopback
Task
ResumeDrivers_ResolverLoopback

Event ID 8001: Status

#
Channel
Diagnostic
Task
Shutdown_ArchiveCorrupt

Fields #

NameDescription
HResult UInt32

Event ID 8002: Status

#
Channel
Diagnostic
Task
Shutdown_ThreadCreateFailed
Opcode
Failed

Fields #

NameDescription
HResult UInt32

Event ID 8003: Status

#
Channel
Diagnostic
Task
Shutdown_Troubleshooting
Opcode
Start

Event ID 8004: Status

#
Channel
Diagnostic
Task
Shutdown_Troubleshooting
Opcode
Stop

Fields #

NameDescription
HResult UInt32

Event ID 8005: Status

#
Channel
Diagnostic
Task
Shutdown_WaitingForBoot

Event ID 8006: Status

#
Channel
Diagnostic
Task
Shutdown_LocatedCKCL

Fields #

NameDescription
Path UnicodeString

Event ID 8007: Status

#
Channel
Diagnostic
Task
Shutdown_LocatedPossibleDCL

Fields #

NameDescription
Path UnicodeString

Event ID 8008: Status

#
Channel
Diagnostic
Task
Shutdown_RestoringConfig

Event ID 8009: Status

#
Channel
Diagnostic
Task
Shutdown_LoadConfig
Opcode
Failed

Fields #

NameDescription
HResult UInt32

Event ID 8010: Status

#
Channel
Diagnostic
Task
Shutdown_ProxyCallback

Event ID 8011: Status

#
Channel
Diagnostic
Task
Shutdown_StartCKCL
Opcode
Start

Event ID 8012: Status

#
Channel
Diagnostic
Task
Shutdown_StartCKCL
Opcode
Stop

Fields #

NameDescription
HResult UInt32

Event ID 8013: Status

#
Channel
Diagnostic
Task
Shutdown_CancelledAnalysisViaRegistry

Event ID 9001: Status

#
Channel
Diagnostic
Task
SecondaryLogon_DMConfig
Opcode
Failed

Fields #

NameDescription
HResult UInt32

Event ID 9003: Status

#
Channel
Diagnostic
Task
SecondaryLogon_UnexpectedEvent

Fields #

NameDescription
GUID GUID
EventId UInt16
InternalState UInt32

Event ID 9005: Status

#
Channel
Diagnostic
Task
SecondaryLogon_ChangedState

Fields #

NameDescription
NewState UInt32

Event ID 9007: Status

#
Channel
Diagnostic
Task
SecondaryLogon_DetectedMultipleLogons

Event ID 9009: Status

#
Channel
Diagnostic
Task
SecondaryLogon_ReceivedEvent

Fields #

NameDescription
GUID GUID
EventId UInt16
InternalState UInt32

Event ID 9011: Status

#
Channel
Diagnostic
Task
SecondaryLogon_Troubleshooting
Opcode
Start

Event ID 9012: Status

#
Channel
Diagnostic
Task
SecondaryLogon_Troubleshooting
Opcode
Stop

Fields #

NameDescription
HResult UInt32

Event ID 9013: Status

#
Channel
Diagnostic
Task
SecondaryLogon_CancelledAnalysisViaRegistry

Event ID 9015: Status

#
Channel
Diagnostic
Task
SecondaryLogon_CapturedDCL

Fields #

NameDescription
HResult UInt32

Event ID 10001: Status

#
Channel
Loopback
Task
SecondaryLogonScenario_Stop

Event ID 11001: Standby_ReceivedEvent

#
Channel
Diagnostic
Task
Standby_ReceivedEvent

Fields #

NameDescription
GUID GUID
EventId UInt16
InternalState UInt32

Event ID 11002: Standby_ChangedState

#
Channel
Diagnostic
Task
Standby_ChangedState

Fields #

NameDescription
NewState UInt32

Event ID 11003: Standby_FailedTransition

#
Channel
Diagnostic
Task
Standby_FailedTransition

Event ID 11005: Standby_DetectRegressionsStart

#
Channel
Diagnostic
Task
Standby_DetectRegressions
Opcode
Start

Event ID 11006: Standby_DetectRegressionsStop

#
Channel
Diagnostic
Task
Standby_DetectRegressions
Opcode
Stop

Fields #

NameDescription
HResult UInt32

Provenance

ETW provider GUID cfc18ec0-96b1-4eba-961b-622caee05b0a

Defined in diagperf.dll, which carries the event manifest.

  • Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.1, captured 2026-06-02 — Manifest XML pack, 2.0 MB