Microsoft-Windows-DirectShow-KernelSupport

13 events across 1 channel

Event ID 1: PluginCreation_Start

#
Provider
Microsoft-Windows-DirectShow-KernelSupport
Channel
Performance
Task
KSProxyInfo
Opcode
Enter

Description

PluginCreation_Start.

Message #

PluginCreation_Start

Event ID 2: PluginCreation_Complete

#
Provider
Microsoft-Windows-DirectShow-KernelSupport
Channel
Performance
Task
KSProxyInfo
Opcode
Exit

Description

PluginCreation_Complete.

Message #

PluginCreation_Complete

Event ID 3: SetMediaType_Enter

#
Provider
Microsoft-Windows-DirectShow-KernelSupport
Channel
Performance
Task
KSProxyInfo
Opcode
Enter

Description

SetMediaType_Enter.

Message #

SetMediaType_Enter

Event ID 4: SetMediaType_Exit

#
Provider
Microsoft-Windows-DirectShow-KernelSupport
Channel
Performance
Task
KSProxyInfo
Opcode
Exit

Description

SetMediaType_Exit.

Message #

SetMediaType_Exit

Event ID 5: SetFormat_Enter

#
Provider
Microsoft-Windows-DirectShow-KernelSupport
Channel
Performance
Task
KSProxyInfo
Opcode
Enter

Description

SetFormat_Enter.

Message #

SetFormat_Enter

Event ID 6: SetFormat_Exit

#
Provider
Microsoft-Windows-DirectShow-KernelSupport
Channel
Performance
Task
KSProxyInfo
Opcode
Exit

Description

SetFormat_Exit.

Message #

SetFormat_Exit

Event ID 7: InputPin_Receive: Pointer = Buffer, Timestamp = TimeStamp.

#
Provider
Microsoft-Windows-DirectShow-KernelSupport
Channel
Performance
Task
KSProxyBuffer

Description

InputPin_Receive: Pointer = Buffer, Timestamp = TimeStamp.

Message #

InputPin_Receive: Pointer = %1, Timestamp = %2

Fields #

NameDescription
Buffer Pointer
TimeStamp Int64

Event ID 8: ProcessInput_Start: Pointer = Buffer, Timestamp = TimeStamp.

#
Provider
Microsoft-Windows-DirectShow-KernelSupport
Channel
Performance
Task
KSProxyBuffer

Description

ProcessInput_Start: Pointer = Buffer, Timestamp = TimeStamp.

Message #

ProcessInput_Start: Pointer = %1, Timestamp = %2

Fields #

NameDescription
Buffer Pointer
TimeStamp Int64

Event ID 9: ProcessInput_Complete: Pointer = Buffer, Timestamp = TimeStamp.

#
Provider
Microsoft-Windows-DirectShow-KernelSupport
Channel
Performance
Task
KSProxyBuffer

Description

ProcessInput_Complete: Pointer = Buffer, Timestamp = TimeStamp.

Message #

ProcessInput_Complete: Pointer = %1, Timestamp = %2

Fields #

NameDescription
Buffer Pointer
TimeStamp Int64

Event ID 10: ProcessOutput_Start: Pointer = Buffer, Timestamp = TimeStamp.

#
Provider
Microsoft-Windows-DirectShow-KernelSupport
Channel
Performance
Task
KSProxyBuffer

Description

ProcessOutput_Start: Pointer = Buffer, Timestamp = TimeStamp.

Message #

ProcessOutput_Start: Pointer = %1, Timestamp = %2

Fields #

NameDescription
Buffer Pointer
TimeStamp Int64

Event ID 11: ProcessOutput_Complete: Pointer = Buffer, Timestamp = TimeStamp.

#
Provider
Microsoft-Windows-DirectShow-KernelSupport
Channel
Performance
Task
KSProxyBuffer

Description

ProcessOutput_Complete: Pointer = Buffer, Timestamp = TimeStamp.

Message #

ProcessOutput_Complete: Pointer = %1, Timestamp = %2

Fields #

NameDescription
Buffer Pointer
TimeStamp Int64

Event ID 12: DeviceIo_Start: Pointer = Buffer, Timestamp = TimeStamp.

#
Provider
Microsoft-Windows-DirectShow-KernelSupport
Channel
Performance
Task
KSProxyBuffer

Description

DeviceIo_Start: Pointer = Buffer, Timestamp = TimeStamp.

Message #

DeviceIo_Start: Pointer = %1, Timestamp = %2

Fields #

NameDescription
Buffer Pointer
TimeStamp Int64

Event ID 13: DeviceIo_Complete: Pointer = Buffer, Timestamp = TimeStamp.

#
Provider
Microsoft-Windows-DirectShow-KernelSupport
Channel
Performance
Task
KSProxyBuffer

Description

DeviceIo_Complete: Pointer = Buffer, Timestamp = TimeStamp.

Message #

DeviceIo_Complete: Pointer = %1, Timestamp = %2

Fields #

NameDescription
Buffer Pointer
TimeStamp Int64

Provenance

Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.

ETW provider GUID 3cc2d4af-da5e-4ed4-bcbe-3cf995940483

Defined in ksproxy.ax, which carries the event manifest.

Observed on:

  • WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.1, captured 2026-06-02
  • Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.1, captured 2026-06-02

Downloads