Microsoft-Windows-Dism-Api
86 events across 2 channels
Event ID 1: DismInitializeStart
#Event ID 2: DismInitializeStop
#Event ID 3: DismShutdown
#Example Event #
{
"system": {
"provider": "Microsoft-Windows-Dism-Api",
"guid": "{75B0DA21-8B50-42EB-9448-EC48B1729B57}",
"event_source_name": "",
"event_id": 3,
"version": 0,
"level": 4,
"task": 2,
"opcode": 1,
"keywords": "0x0000000000000001",
"time_created": "2026-06-02T05:16:04.241+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{877F78A1-F053-000B-A536-818753F0DC01}"
},
"execution": {
"process_id": 19220,
"thread_id": 18680
},
"channel": "ETW Trace",
"computer": "JD-DC01-2022",
"security": {
"user_id": ""
}
},
"event_data": {},
"message": "DismShutdown"
}
Event ID 4: DismShutdown
#Example Event #
{
"system": {
"provider": "Microsoft-Windows-Dism-Api",
"guid": "{75B0DA21-8B50-42EB-9448-EC48B1729B57}",
"event_source_name": "",
"event_id": 4,
"version": 0,
"level": 4,
"task": 2,
"opcode": 2,
"keywords": "0x0000000000000001",
"time_created": "2026-06-02T05:16:04.246+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{877F78A1-F053-000B-A536-818753F0DC01}"
},
"execution": {
"process_id": 19220,
"thread_id": 18680
},
"channel": "ETW Trace",
"computer": "JD-DC01-2022",
"security": {
"user_id": ""
}
},
"event_data": {},
"message": "DismShutdown"
}
Event ID 6: DismOpenSession
#Fields #
| Name | Description |
|---|---|
SessionId UInt32 | |
String UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Dism-Api",
"guid": "{75B0DA21-8B50-42EB-9448-EC48B1729B57}",
"event_source_name": "",
"event_id": 6,
"version": 0,
"level": 4,
"task": 3,
"opcode": 2,
"keywords": "0x0000000000000001",
"time_created": "2026-06-02T05:16:02.796+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{877F78A1-F053-000B-A536-818753F0DC01}"
},
"execution": {
"process_id": 19220,
"thread_id": 18680
},
"channel": "ETW Trace",
"computer": "JD-DC01-2022",
"security": {
"user_id": ""
}
},
"event_data": {
"SessionId": 2,
"String": "DISM_{53BFAE52-B167-4E2F-A258-0A37B57FF845}"
},
"message": "DismOpenSession"
}
Event ID 7: DismCloseSession
#Fields #
| Name | Description |
|---|---|
SessionId UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Dism-Api",
"guid": "{75B0DA21-8B50-42EB-9448-EC48B1729B57}",
"event_source_name": "",
"event_id": 7,
"version": 0,
"level": 4,
"task": 4,
"opcode": 1,
"keywords": "0x0000000000000001",
"time_created": "2026-06-02T05:16:02.846+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{877F78A1-F053-000B-A536-818753F0DC01}"
},
"execution": {
"process_id": 19220,
"thread_id": 18680
},
"channel": "ETW Trace",
"computer": "JD-DC01-2022",
"security": {
"user_id": ""
}
},
"event_data": {
"SessionId": 2
},
"message": "DismCloseSession"
}
Event ID 8: DismCloseSession
#Fields #
| Name | Description |
|---|---|
SessionId UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Dism-Api",
"guid": "{75B0DA21-8B50-42EB-9448-EC48B1729B57}",
"event_source_name": "",
"event_id": 8,
"version": 0,
"level": 4,
"task": 4,
"opcode": 2,
"keywords": "0x0000000000000001",
"time_created": "2026-06-02T05:16:04.240+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{877F78A1-F053-000B-A536-818753F0DC01}"
},
"execution": {
"process_id": 19220,
"thread_id": 18680
},
"channel": "ETW Trace",
"computer": "JD-DC01-2022",
"security": {
"user_id": ""
}
},
"event_data": {
"SessionId": 2
},
"message": "DismCloseSession"
}
Event ID 13: EnqueueCommandObject
#Fields #
| Name | Description |
|---|---|
SessionId UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Dism-Api",
"guid": "{75B0DA21-8B50-42EB-9448-EC48B1729B57}",
"event_source_name": "",
"event_id": 13,
"version": 0,
"level": 4,
"task": 5,
"opcode": 1,
"keywords": "0x400000000000001A",
"time_created": "2026-06-02T05:16:02.797+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{877F78A1-F053-000B-A536-818753F0DC01}"
},
"execution": {
"process_id": 19220,
"thread_id": 18680
},
"channel": "ETW Trace",
"computer": "JD-DC01-2022",
"security": {
"user_id": ""
}
},
"event_data": {
"SessionId": 2
},
"message": "EnqueueCommandObject"
}
Event ID 14: EnqueueCommandObject
#Fields #
| Name | Description |
|---|---|
SessionId UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Dism-Api",
"guid": "{75B0DA21-8B50-42EB-9448-EC48B1729B57}",
"event_source_name": "",
"event_id": 14,
"version": 0,
"level": 4,
"task": 5,
"opcode": 2,
"keywords": "0x400000000000001A",
"time_created": "2026-06-02T05:16:02.797+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{877F78A1-F053-000B-A536-818753F0DC01}"
},
"execution": {
"process_id": 19220,
"thread_id": 18680
},
"channel": "ETW Trace",
"computer": "JD-DC01-2022",
"security": {
"user_id": ""
}
},
"event_data": {
"SessionId": 2
},
"message": "EnqueueCommandObject"
}
Event ID 15: DequeueCommandObject
#Fields #
| Name | Description |
|---|---|
SessionId UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Dism-Api",
"guid": "{75B0DA21-8B50-42EB-9448-EC48B1729B57}",
"event_source_name": "",
"event_id": 15,
"version": 0,
"level": 4,
"task": 6,
"opcode": 1,
"keywords": "0x400000000000001A",
"time_created": "2026-06-02T05:16:02.797+00:00",
"event_record_id": 0,
"correlation": {},
"execution": {
"process_id": 19220,
"thread_id": 4380
},
"channel": "ETW Trace",
"computer": "JD-DC01-2022",
"security": {
"user_id": ""
}
},
"event_data": {
"SessionId": 2
},
"message": "DequeueCommandObject"
}
Event ID 16: DequeueCommandObject
#Fields #
| Name | Description |
|---|---|
SessionId UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Dism-Api",
"guid": "{75B0DA21-8B50-42EB-9448-EC48B1729B57}",
"event_source_name": "",
"event_id": 16,
"version": 0,
"level": 4,
"task": 6,
"opcode": 2,
"keywords": "0x400000000000001A",
"time_created": "2026-06-02T05:16:02.797+00:00",
"event_record_id": 0,
"correlation": {},
"execution": {
"process_id": 19220,
"thread_id": 4380
},
"channel": "ETW Trace",
"computer": "JD-DC01-2022",
"security": {
"user_id": ""
}
},
"event_data": {
"SessionId": 2
},
"message": "DequeueCommandObject"
}
Event ID 31: DismGetMountedImageInfoStart
#Event ID 32: DismGetMountedImageInfoStop
#Event ID 33: DismCleanupMountpointsStart
#Event ID 34: DismCleanupMountpointsStop
#Event ID 77: DismAddProvisionedAppxPackageStart
#Fields #
| Name | Description |
|---|---|
SessionId UInt32 | |
String UnicodeString |
Event ID 78: DismAddProvisionedAppxPackageStop
#Fields #
| Name | Description |
|---|---|
SessionId UInt32 | |
String UnicodeString |
Event ID 79: DismRemoveProvisionedAppxPackageStart
#Fields #
| Name | Description |
|---|---|
SessionId UInt32 | |
String UnicodeString |
Event ID 80: DismRemoveProvisionedAppxPackageStop
#Fields #
| Name | Description |
|---|---|
SessionId UInt32 | |
String UnicodeString |
Event ID 81: DismGetProvisionedAppxPackages
#Fields #
| Name | Description |
|---|---|
SessionId UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Dism-Api",
"guid": "{75B0DA21-8B50-42EB-9448-EC48B1729B57}",
"event_source_name": "",
"event_id": 81,
"version": 0,
"level": 4,
"task": 41,
"opcode": 1,
"keywords": "0x0000000000000001",
"time_created": "2026-06-02T05:16:02.802+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{877F78A1-F053-000B-A536-818753F0DC01}"
},
"execution": {
"process_id": 19220,
"thread_id": 18680
},
"channel": "ETW Trace",
"computer": "JD-DC01-2022",
"security": {
"user_id": ""
}
},
"event_data": {
"SessionId": 2
},
"message": "DismGetProvisionedAppxPackages"
}
Event ID 82: DismGetProvisionedAppxPackages
#Fields #
| Name | Description |
|---|---|
SessionId UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Dism-Api",
"guid": "{75B0DA21-8B50-42EB-9448-EC48B1729B57}",
"event_source_name": "",
"event_id": 82,
"version": 0,
"level": 4,
"task": 41,
"opcode": 2,
"keywords": "0x0000000000000001",
"time_created": "2026-06-02T05:16:02.842+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{877F78A1-F053-000B-A536-818753F0DC01}"
},
"execution": {
"process_id": 19220,
"thread_id": 18680
},
"channel": "ETW Trace",
"computer": "JD-DC01-2022",
"security": {
"user_id": ""
}
},
"event_data": {
"SessionId": 2
},
"message": "DismGetProvisionedAppxPackages"
}
Event ID 87: DismRemoveProvisionedAppxPackageStart87
#Fields #
| Name | Description |
|---|---|
SessionId UInt32 | |
String UnicodeString |
Event ID 88: DismRemoveProvisionedAppxPackageStop88
#Fields #
| Name | Description |
|---|---|
SessionId UInt32 | |
String UnicodeString |
Provenance
Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.
ETW provider GUID {75B0DA21-8B50-42EB-9448-EC48B1729B57}
Defined in DismApi.dll, which carries the event manifest.
Observed on:
- WS2022-20348.4893, sample captured from a live trace, binary version 10.0.20348.1, captured 2026-06-02
- WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.1, captured 2026-06-02
- Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.4946, captured 2026-06-02