Microsoft-Windows-ESE
140 events across 2 channels
Event ID 103: ESE CacheNewPage Trace
#Description
ESE CacheNewPage Trace.
Message #
Fields #
| Name | Description |
|---|---|
ifmp UInt32 | |
pgno UInt32 | |
LatchFlags UInt32 | |
objid UInt32 | |
PageFlags UInt32 | |
UserId UInt32 | |
OperationId UInt8 | |
OperationType UInt8 | Known values
|
ClientType UInt8 | |
Flags UInt8 | |
CorrelationId UInt32 | |
Iorp UInt8 | |
Iors UInt8 | |
Iort UInt8 | |
Ioru UInt8 | |
Iorf UInt8 | |
ParentObjectClass UInt8 | |
dbtimeDirtied UInt64 | |
itagMicFree UInt16 | |
cbFree UInt16 |
Event ID 104: ESE CacheReadPage Trace
#Description
ESE CacheReadPage Trace.
Message #
Fields #
| Name | Description |
|---|---|
ifmp UInt32 | |
pgno UInt32 | |
LatchFlags UInt32 | |
objid UInt32 | |
PageFlags UInt32 | |
UserId UInt32 | |
OperationId UInt8 | |
OperationType UInt8 | Known values
|
ClientType UInt8 | |
Flags UInt8 | |
CorrelationId UInt32 | |
Iorp UInt8 | |
Iors UInt8 | |
Iort UInt8 | |
Ioru UInt8 | |
Iorf UInt8 | |
ParentObjectClass UInt8 | |
dbtimeDirtied UInt64 | |
itagMicFree UInt16 | |
cbFree UInt16 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-ESE",
"guid": "{478EA8A8-00BE-4BA6-8E75-8B9DC7DB9F78}",
"event_source_name": "",
"event_id": 104,
"version": 0,
"level": 4,
"task": 5,
"opcode": 0,
"keywords": "0x0000000000004022",
"time_created": "2026-06-02T05:23:25.389+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{5FF741DB-F0E3-4F6E-BD7E-A0D869BCBAEE}"
},
"execution": {
"process_id": 1748,
"thread_id": 19708
},
"channel": "ETW Trace",
"computer": "JD-DC01-2022",
"security": {
"user_id": ""
}
},
"event_data": {
"ClientType": 0,
"CorrelationId": 0,
"Flags": 0,
"Iorf": 0,
"Iorp": 33,
"Iors": 3,
"Iort": 1,
"Ioru": 29,
"LatchFlags": 16384,
"OperationId": 0,
"OperationType": 0,
"PageFlags": 75780,
"ParentObjectClass": 0,
"UserId": 2147483648,
"cbFree": 1663,
"dbtimeDirtied": 370534,
"ifmp": 2,
"itagMicFree": 182,
"objid": 8,
"pgno": 11611
},
"message": "ESE_CacheReadPage_Trace"
}
Event ID 105: ESE CachePrereadPage Trace
#Description
ESE CachePrereadPage Trace.
Message #
Fields #
| Name | Description |
|---|---|
ifmp UInt32 | |
pgno UInt32 | |
UserId UInt32 | |
OperationId UInt8 | |
OperationType UInt8 | Known values
|
ClientType UInt8 | |
Flags UInt8 | |
CorrelationId UInt32 | |
Iorp UInt8 | |
Iors UInt8 | |
Iort UInt8 | |
Ioru UInt8 | |
Iorf UInt8 | |
ParentObjectClass UInt8 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-ESE",
"guid": "{478EA8A8-00BE-4BA6-8E75-8B9DC7DB9F78}",
"event_source_name": "",
"event_id": 105,
"version": 0,
"level": 4,
"task": 6,
"opcode": 0,
"keywords": "0x0000000000004022",
"time_created": "2026-06-02T05:23:26.771+00:00",
"event_record_id": 0,
"correlation": {},
"execution": {
"process_id": 12112,
"thread_id": 1804
},
"channel": "ETW Trace",
"computer": "JD-DC01-2022",
"security": {
"user_id": ""
}
},
"event_data": {
"ClientType": 0,
"CorrelationId": 0,
"Flags": 0,
"Iorf": 0,
"Iorp": 34,
"Iors": 0,
"Iort": 1,
"Ioru": 50,
"OperationId": 0,
"OperationType": 0,
"ParentObjectClass": 0,
"UserId": 2147483648,
"ifmp": 1,
"pgno": 3
},
"message": "ESE_CachePrereadPage_Trace"
}
Event ID 106: ESE CacheWritePage Trace
#Description
ESE CacheWritePage Trace.
Message #
Fields #
| Name | Description |
|---|---|
tick UInt32 | |
ifmp UInt32 | |
pgno UInt32 | |
objid UInt32 | |
PageFlags UInt32 | |
DirtyLevel UInt32 | |
UserId UInt32 | |
OperationId UInt8 | |
OperationType UInt8 | Known values
|
ClientType UInt8 | |
Flags UInt8 | |
CorrelationId UInt32 | |
Iorp UInt8 | |
Iors UInt8 | |
Iort UInt8 | |
Ioru UInt8 | |
Iorf UInt8 | |
ParentObjectClass UInt8 |
Event ID 107: ESE CacheEvictPage Trace
#Description
ESE CacheEvictPage Trace.
Message #
Fields #
| Name | Description |
|---|---|
tick UInt32 | |
ifmp UInt32 | |
pgno UInt32 | |
fCurrentVersion UInt32 | |
errBF Int32 | |
bfef UInt32 | |
pctPriority UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-ESE",
"guid": "{478EA8A8-00BE-4BA6-8E75-8B9DC7DB9F78}",
"event_source_name": "",
"event_id": 107,
"version": 0,
"level": 4,
"task": 8,
"opcode": 0,
"keywords": "0x0000000000004420",
"time_created": "2026-06-02T05:23:25.398+00:00",
"event_record_id": 0,
"correlation": {},
"execution": {
"process_id": 1748,
"thread_id": 19708
},
"channel": "ETW Trace",
"computer": "JD-DC01-2022",
"security": {
"user_id": ""
}
},
"event_data": {
"bfef": 1,
"errBF": 0,
"fCurrentVersion": 1,
"ifmp": 2,
"pctPriority": 0,
"pgno": 4858,
"tick": 35249578
},
"message": "ESE_CacheEvictPage_Trace"
}
Event ID 108: ESE CacheRequestPage Trace
#Description
ESE CacheRequestPage Trace.
Message #
Fields #
| Name | Description |
|---|---|
tick UInt32 | |
ifmp UInt32 | |
pgno UInt32 | |
bflf UInt32 | |
objid UInt32 | |
PageFlags UInt32 | |
bflt UInt32 | |
pctPriority UInt32 | |
bfrtf UInt32 | |
ClientType UInt8 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-ESE",
"guid": "{478EA8A8-00BE-4BA6-8E75-8B9DC7DB9F78}",
"event_source_name": "",
"event_id": 108,
"version": 0,
"level": 5,
"task": 9,
"opcode": 0,
"keywords": "0x0000000000000420",
"time_created": "2026-06-02T05:23:25.374+00:00",
"event_record_id": 0,
"correlation": {},
"execution": {
"process_id": 4820,
"thread_id": 7912
},
"channel": "ETW Trace",
"computer": "JD-DC01-2022",
"security": {
"user_id": ""
}
},
"event_data": {
"ClientType": 0,
"PageFlags": 75779,
"bflf": 82176,
"bflt": 0,
"bfrtf": 5,
"ifmp": 1,
"objid": 18,
"pctPriority": 100,
"pgno": 141,
"tick": 35249546
},
"message": "ESE_CacheRequestPage_Trace"
}
Event ID 110: ESE CacheDirtyPage Trace
#Description
ESE CacheDirtyPage Trace.
Message #
Fields #
| Name | Description |
|---|---|
tick UInt32 | |
ifmp UInt32 | |
pgno UInt32 | |
objid UInt32 | |
PageFlags UInt32 | |
DirtyLevel UInt32 | |
LgposModify UInt64 | |
UserId UInt32 | |
OperationId UInt8 | |
OperationType UInt8 | Known values
|
ClientType UInt8 | |
Flags UInt8 | |
CorrelationId UInt32 | |
Iorp UInt8 | |
Iors UInt8 | |
Iort UInt8 | |
Ioru UInt8 | |
Iorf UInt8 | |
ParentObjectClass UInt8 | |
ClientComponent AnsiString | |
ClientAction AnsiString | |
ClientActionContext AnsiString | |
GuidActivityId GUID |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-ESE",
"guid": "{478EA8A8-00BE-4BA6-8E75-8B9DC7DB9F78}",
"event_source_name": "",
"event_id": 110,
"version": 0,
"level": 5,
"task": 11,
"opcode": 0,
"keywords": "0x0000000000000422",
"time_created": "2026-06-02T05:23:25.374+00:00",
"event_record_id": 0,
"correlation": {},
"execution": {
"process_id": 4820,
"thread_id": 7912
},
"channel": "ETW Trace",
"computer": "JD-DC01-2022",
"security": {
"user_id": ""
}
},
"event_data": {
"ClientType": 0,
"CorrelationId": 0,
"DirtyLevel": 2,
"Flags": 0,
"Iorf": 0,
"Iorp": 0,
"Iors": 9,
"Iort": 1,
"Ioru": 22,
"LgposModify": 1816803083663,
"OperationId": 0,
"OperationType": 0,
"PageFlags": 75779,
"ParentObjectClass": 0,
"UserId": 2147483648,
"ifmp": 1,
"objid": 18,
"pgno": 141,
"tick": 35249546
},
"message": "ESE_CacheDirtyPage_Trace"
}
Event ID 111: ESE TransactionBegin Trace
#Description
ESE TransactionBegin Trace.
Message #
Fields #
| Name | Description |
|---|---|
SessionNumber Pointer | |
TransactionNumber Pointer | |
TransactionLevel UInt8 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-ESE",
"guid": "{478EA8A8-00BE-4BA6-8E75-8B9DC7DB9F78}",
"event_source_name": "",
"event_id": 111,
"version": 0,
"level": 5,
"task": 12,
"opcode": 0,
"keywords": "0x0000000000000008",
"time_created": "2026-06-02T05:23:25.374+00:00",
"event_record_id": 0,
"correlation": {},
"execution": {
"process_id": 4820,
"thread_id": 7912
},
"channel": "ETW Trace",
"computer": "JD-DC01-2022",
"security": {
"user_id": ""
}
},
"event_data": {
"SessionNumber": "0x2B467C60C00",
"TransactionLevel": 1,
"TransactionNumber": "0x16CD30C"
},
"message": "ESE_TransactionBegin_Trace"
}
Event ID 112: ESE TransactionCommit Trace
#Description
ESE TransactionCommit Trace.
Message #
Fields #
| Name | Description |
|---|---|
SessionNumber Pointer | |
TransactionNumber Pointer | |
TransactionLevel UInt8 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-ESE",
"guid": "{478EA8A8-00BE-4BA6-8E75-8B9DC7DB9F78}",
"event_source_name": "",
"event_id": 112,
"version": 0,
"level": 5,
"task": 13,
"opcode": 0,
"keywords": "0x0000000000000008",
"time_created": "2026-06-02T05:23:25.374+00:00",
"event_record_id": 0,
"correlation": {},
"execution": {
"process_id": 4820,
"thread_id": 7912
},
"channel": "ETW Trace",
"computer": "JD-DC01-2022",
"security": {
"user_id": ""
}
},
"event_data": {
"SessionNumber": "0x2B467C60C00",
"TransactionLevel": 1,
"TransactionNumber": "0x16CD30C"
},
"message": "ESE_TransactionCommit_Trace"
}
Event ID 113: ESE TransactionRollback Trace
#Description
ESE TransactionRollback Trace.
Message #
Fields #
| Name | Description |
|---|---|
SessionNumber Pointer | |
TransactionNumber Pointer | |
TransactionLevel UInt8 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-ESE",
"guid": "{478EA8A8-00BE-4BA6-8E75-8B9DC7DB9F78}",
"event_source_name": "",
"event_id": 113,
"version": 0,
"level": 5,
"task": 14,
"opcode": 0,
"keywords": "0x0000000000000008",
"time_created": "2026-06-02T05:23:26.775+00:00",
"event_record_id": 0,
"correlation": {},
"execution": {
"process_id": 12112,
"thread_id": 7804
},
"channel": "ETW Trace",
"computer": "JD-DC01-2022",
"security": {
"user_id": ""
}
},
"event_data": {
"SessionNumber": "0x14B5A0110C0",
"TransactionLevel": 2,
"TransactionNumber": "0x65F14"
},
"message": "ESE_TransactionRollback_Trace"
}
Event ID 114: ESE SpaceAllocExt Trace
#Event ID 115: ESE SpaceFreeExt Trace
#Event ID 116: ESE SpaceAllocPage Trace
#Event ID 117: ESE SpaceFreePage Trace
#Event ID 118: ESE IorunEnqueue Trace
#Description
ESE IorunEnqueue Trace.
Message #
Fields #
| Name | Description |
|---|---|
iFile UInt64 | |
ibOffset UInt64 | |
cbData UInt32 | |
tidAlloc UInt32 | |
fHeapA UInt32 | |
fWrite UInt32 | |
EngineFileType UInt32 | |
EngineFileId UInt64 | |
cusecEnqueueLatency UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-ESE",
"guid": "{478EA8A8-00BE-4BA6-8E75-8B9DC7DB9F78}",
"event_source_name": "",
"event_id": 118,
"version": 0,
"level": 4,
"task": 19,
"opcode": 0,
"keywords": "0x4000000000000040",
"time_created": "2026-06-02T05:23:26.757+00:00",
"event_record_id": 0,
"correlation": {},
"execution": {
"process_id": 12112,
"thread_id": 7804
},
"channel": "ETW Trace",
"computer": "JD-DC01-2022",
"security": {
"user_id": ""
}
},
"event_data": {
"EngineFileId": 1,
"EngineFileType": 5,
"cbData": 8192,
"cusecEnqueueLatency": 0,
"fHeapA": 2,
"fWrite": 0,
"iFile": 1284,
"ibOffset": 8192,
"tidAlloc": 7804
},
"message": "ESE_IorunEnqueue_Trace"
}
Event ID 119: ESE IorunDequeue Trace
#Description
ESE IorunDequeue Trace.
Message #
Fields #
| Name | Description |
|---|---|
iFile UInt64 | |
ibOffset UInt64 | |
cbData UInt32 | |
tidAlloc UInt32 | |
fHeapA UInt32 | |
fWrite UInt32 | |
Iorp UInt32 | |
Iors UInt32 | |
Ioru UInt32 | |
Iorf UInt32 | |
grbitQos UInt32 | |
cmsecTimeInQueue UInt64 | |
EngineFileType UInt32 | |
EngineFileId UInt64 | |
cDispatchPass UInt64 | |
cIorunCombined UInt16 | |
cusecDequeueLatency UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-ESE",
"guid": "{478EA8A8-00BE-4BA6-8E75-8B9DC7DB9F78}",
"event_source_name": "",
"event_id": 119,
"version": 0,
"level": 4,
"task": 20,
"opcode": 0,
"keywords": "0x4000000000000040",
"time_created": "2026-06-02T05:23:26.762+00:00",
"event_record_id": 0,
"correlation": {},
"execution": {
"process_id": 12112,
"thread_id": 1804
},
"channel": "ETW Trace",
"computer": "JD-DC01-2022",
"security": {
"user_id": ""
}
},
"event_data": {
"EngineFileId": 1,
"EngineFileType": 5,
"Iorf": 0,
"Iorp": 106,
"Iors": 0,
"Ioru": 50,
"cDispatchPass": 24779,
"cIorunCombined": 1,
"cbData": 8192,
"cmsecTimeInQueue": 4137,
"cusecDequeueLatency": 1,
"fHeapA": 2,
"fWrite": 0,
"grbitQos": 16,
"iFile": 1284,
"ibOffset": 8192,
"tidAlloc": 7804
},
"message": "ESE_IorunDequeue_Trace"
}
Event ID 120: ESE IOCompletion Trace
#Description
ESE IOCompletion Trace.
Message #
Fields #
| Name | Description |
|---|---|
iFile UInt64 | |
fMultiIor UInt32 | |
fWrite UInt8 | |
UserId UInt32 | |
OperationId UInt8 | |
OperationType UInt8 | Known values
|
ClientType UInt8 | |
Flags UInt8 | |
CorrelationId UInt32 | |
Iorp UInt8 | |
Iors UInt8 | |
Iort UInt8 | |
Ioru UInt8 | |
Iorf UInt8 | |
ParentObjectClass UInt8 | |
ibOffset UInt64 | |
cbTransfer UInt32 | |
error UInt32 | |
qosHighestFirst UInt32 | |
cmsecIOElapsed Double | |
dtickQueueDelay UInt32 | |
tidAlloc UInt32 | |
EngineFileType UInt32 | |
EngineFileId UInt64 | |
fmfFile UInt32 | |
DiskNumber UInt32 | |
dwEngineObjid UInt32 | |
qosIOComplete UInt64 | |
dwTraceFlags UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-ESE",
"guid": "{478EA8A8-00BE-4BA6-8E75-8B9DC7DB9F78}",
"event_source_name": "",
"event_id": 120,
"version": 0,
"level": 4,
"task": 21,
"opcode": 0,
"keywords": "0x4000000000000040",
"time_created": "2026-06-02T05:23:26.626+00:00",
"event_record_id": 0,
"correlation": {},
"execution": {
"process_id": 21260,
"thread_id": 12752
},
"channel": "ETW Trace",
"computer": "JD-DC01-2022",
"security": {
"user_id": ""
}
},
"event_data": {
"ClientType": 0,
"CorrelationId": 0,
"DiskNumber": 0,
"EngineFileId": 4611686022722355201,
"EngineFileType": 3,
"Flags": 0,
"Iorf": 0,
"Iorp": 80,
"Iors": 0,
"Iort": 9,
"Ioru": 98,
"OperationId": 0,
"OperationType": 0,
"ParentObjectClass": 0,
"UserId": 4294967295,
"cbTransfer": 0,
"cmsecIOElapsed": 41,
"dtickQueueDelay": 5,
"dwEngineObjid": 0,
"error": 0,
"fMultiIor": 262144,
"fWrite": 1,
"fmfFile": 1,
"iFile": 1204,
"ibOffset": 1048576,
"qosHighestFirst": 16,
"qosIOComplete": 16,
"tidAlloc": 12752
},
"message": "ESE_IOCompletion_Trace"
}
Event ID 122: ESE LogWrite Trace
#Description
ESE LogWrite Trace.
Message #
Fields #
| Name | Description |
|---|---|
lgenData Int32 | |
ibLogData UInt32 | |
cbLogData UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-ESE",
"guid": "{478EA8A8-00BE-4BA6-8E75-8B9DC7DB9F78}",
"event_source_name": "",
"event_id": 122,
"version": 0,
"level": 4,
"task": 23,
"opcode": 0,
"keywords": "0x0000000000000080",
"time_created": "2026-06-02T05:23:26.631+00:00",
"event_record_id": 0,
"correlation": {},
"execution": {
"process_id": 21260,
"thread_id": 12752
},
"channel": "ETW Trace",
"computer": "JD-DC01-2022",
"security": {
"user_id": ""
}
},
"event_data": {
"cbLogData": 4096,
"ibLogData": 0,
"lgenData": 1
},
"message": "ESE_LogWrite_Trace"
}
Event ID 123: ESE EventLogInfo Trace
#Description
ESE EventLogInfo Trace.
Message #
Fields #
| Name | Description |
|---|---|
szTrace UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-ESE",
"guid": "478EA8A8-00BE-4BA6-8E75-8B9DC7DB9F78",
"event_source_name": "",
"event_id": 123,
"version": 0,
"level": 4,
"task": 24,
"opcode": 0,
"keywords": 9223372036854775812,
"time_created": "2026-03-13T20:00:52.072070+00:00",
"event_record_id": 1,
"correlation": {},
"execution": {
"process_id": 7000,
"thread_id": 7520
},
"channel": "Microsoft-Windows-ESE/Operational",
"computer": "LAB-DC01.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"szTrace": "EventLog[ID=102(0x66)@10958217080]: TiWorker (7000,P,98) SoftwareUsageMetrics-Api: The database engine (10.00.20348.0000) is starting a new instance (0). "
},
"message": ""
}
Event ID 124: ESE EventLogWarn Trace
#Description
ESE EventLogWarn Trace.
Message #
Fields #
| Name | Description |
|---|---|
szTrace UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-ESE",
"guid": "478EA8A8-00BE-4BA6-8E75-8B9DC7DB9F78",
"event_source_name": "",
"event_id": 124,
"version": 0,
"level": 3,
"task": 25,
"opcode": 0,
"keywords": 9223372036854775812,
"time_created": "2026-03-13T23:07:16.370107+00:00",
"event_record_id": 237,
"correlation": {},
"execution": {
"process_id": 14016,
"thread_id": 13980
},
"channel": "Microsoft-Windows-ESE/Operational",
"computer": "LAB-DC01.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"szTrace": "EventLog[ID=640(0x280)@47616170117]: certsrv.exe (14016,P,98) Restore0001: Error -1919 validating header page on flush map file \"C:\\Windows\\system32\\CertLog\\EvtGen-Root-CA.jfm\". The flush map file will be invalidated. \r\nAdditional information: [SignDbHdrFromDb:Create time:03/13/2026 23:06:22.503 Rand:3655758382 Computer:] [SignFmHdrFromDb:Create time:03/13/2026 23:06:22.385 Rand:413456288 Computer:] [SignDbHdrFromFm:Create time:03/13/2026 23:06:22.931 Rand:2864051150 Computer:] [SignFmHdrFromFm:Create time:03/13/2026 23:06:22.945 Rand:3852748920 Computer:] "
},
"message": ""
}
Event ID 125: ESE EventLogError Trace
#Description
ESE EventLogError Trace.
Message #
Fields #
| Name | Description |
|---|---|
szTrace UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-ESE",
"guid": "478EA8A8-00BE-4BA6-8E75-8B9DC7DB9F78",
"event_source_name": "",
"event_id": 125,
"version": 0,
"level": 2,
"task": 26,
"opcode": 0,
"keywords": 9223372036854775812,
"time_created": "2026-03-13T20:00:00.026028+00:00",
"event_record_id": 2,
"correlation": {
"ActivityID": "DF92C490-B30B-0001-9AC5-92DF0BB3DC01"
},
"execution": {
"process_id": 3312,
"thread_id": 4008
},
"channel": "Microsoft-Windows-ESE/Operational",
"computer": "LAB-WIN11.ludus.domain",
"security": {
"user_id": "S-1-5-19"
}
},
"event_data": {
"szTrace": "EventLog[ID=412(0x19c)@103513027991]: svchost (3312,R,98) SRUJet: Unable to read the header of logfile C:\\Windows\\system32\\SRU\\SRU.log. Error -501. "
},
"message": ""
}
Event ID 126: ESE TimerQueueScheduleDeprecated Trace
#Description
ESE TimerQueueScheduleDeprecated Trace.
Message #
Event ID 127: ESE TimerQueueRunDeprecated Trace
#Description
ESE TimerQueueRunDeprecated Trace.
Message #
Event ID 128: ESE TimerQueueCancelDeprecated Trace
#Description
ESE TimerQueueCancelDeprecated Trace.
Message #
Event ID 129: ESE TimerTaskSchedule Trace
#Description
ESE TimerTaskSchedule Trace.
Message #
Fields #
| Name | Description |
|---|---|
posttTimerHandle Pointer | |
pfnTask Pointer | |
pvTaskGroupContext Pointer | |
pvRuntimeContext Pointer | |
dtickMinDelay UInt32 | |
dtickSlopDelay UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-ESE",
"guid": "{478EA8A8-00BE-4BA6-8E75-8B9DC7DB9F78}",
"event_source_name": "",
"event_id": 129,
"version": 0,
"level": 5,
"task": 30,
"opcode": 0,
"keywords": "0x0000000000000100",
"time_created": "2026-06-02T05:23:25.389+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{5FF741DB-F0E3-4F6E-BD7E-A0D869BCBAEE}"
},
"execution": {
"process_id": 1748,
"thread_id": 19708
},
"channel": "ETW Trace",
"computer": "JD-DC01-2022",
"security": {
"user_id": ""
}
},
"event_data": {
"dtickMinDelay": 10,
"dtickSlopDelay": 0,
"pfnTask": "0x7FF9F681B0A0",
"posttTimerHandle": "0x2A2B6C57940",
"pvRuntimeContext": "0x0",
"pvTaskGroupContext": "0x7FF9F67E61B0"
},
"message": "ESE_TimerTaskSchedule_Trace"
}
Event ID 130: ESE TimerTaskRun Trace
#Description
ESE TimerTaskRun Trace.
Message #
Fields #
| Name | Description |
|---|---|
posttTimerHandle Pointer | |
pfnTask Pointer | |
pvTaskGroupContext Pointer | |
pvRuntimeContext Pointer | |
cRuns UInt64 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-ESE",
"guid": "{478EA8A8-00BE-4BA6-8E75-8B9DC7DB9F78}",
"event_source_name": "",
"event_id": 130,
"version": 0,
"level": 5,
"task": 31,
"opcode": 0,
"keywords": "0x0000000000000100",
"time_created": "2026-06-02T05:23:25.398+00:00",
"event_record_id": 0,
"correlation": {},
"execution": {
"process_id": 1748,
"thread_id": 19708
},
"channel": "ETW Trace",
"computer": "JD-DC01-2022",
"security": {
"user_id": ""
}
},
"event_data": {
"cRuns": 56841,
"pfnTask": "0x7FF9F681B0A0",
"posttTimerHandle": "0x2A2B6C57940",
"pvRuntimeContext": "0x0",
"pvTaskGroupContext": "0x7FF9F67E61B0"
},
"message": "ESE_TimerTaskRun_Trace"
}
Event ID 131: ESE TimerTaskCancel Trace
#Event ID 132: ESE TaskManagerPost Trace
#Description
ESE TaskManagerPost Trace.
Message #
Fields #
| Name | Description |
|---|---|
ptm Pointer | |
pfnCompletion Pointer | |
dwCompletionKey1 UInt32 | |
dwCompletionKey2 Pointer |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-ESE",
"guid": "{478EA8A8-00BE-4BA6-8E75-8B9DC7DB9F78}",
"event_source_name": "",
"event_id": 132,
"version": 0,
"level": 5,
"task": 33,
"opcode": 0,
"keywords": "0x0000000000000100",
"time_created": "2026-06-02T05:23:26.757+00:00",
"event_record_id": 0,
"correlation": {},
"execution": {
"process_id": 12112,
"thread_id": 7804
},
"channel": "ETW Trace",
"computer": "JD-DC01-2022",
"security": {
"user_id": ""
}
},
"event_data": {
"dwCompletionKey1": 0,
"dwCompletionKey2": "0x0",
"pfnCompletion": "0x7FF9F67BE780",
"ptm": "0x14B1843FEC0"
},
"message": "ESE_TaskManagerPost_Trace"
}
Event ID 133: ESE TaskManagerRun Trace
#Description
ESE TaskManagerRun Trace.
Message #
Fields #
| Name | Description |
|---|---|
ptm Pointer | |
pfnCompletion Pointer | |
dwCompletionKey1 UInt32 | |
dwCompletionKey2 Pointer | |
gle UInt32 | |
dwThreadContext Pointer |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-ESE",
"guid": "{478EA8A8-00BE-4BA6-8E75-8B9DC7DB9F78}",
"event_source_name": "",
"event_id": 133,
"version": 0,
"level": 5,
"task": 34,
"opcode": 0,
"keywords": "0x0000000000000100",
"time_created": "2026-06-02T05:23:26.762+00:00",
"event_record_id": 0,
"correlation": {},
"execution": {
"process_id": 12112,
"thread_id": 1804
},
"channel": "ETW Trace",
"computer": "JD-DC01-2022",
"security": {
"user_id": ""
}
},
"event_data": {
"dwCompletionKey1": 0,
"dwCompletionKey2": "0x0",
"dwThreadContext": "0x0",
"gle": 0,
"pfnCompletion": "0x7FF9F67BE780",
"ptm": "0x14B1843FEC0"
},
"message": "ESE_TaskManagerRun_Trace"
}
Event ID 134: ESE GPTaskManagerPost Trace
#Description
ESE GPTaskManagerPost Trace.
Message #
Fields #
| Name | Description |
|---|---|
pgptm Pointer | |
pfnCompletion Pointer | |
pvParam Pointer | |
pTaskInfo Pointer |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-ESE",
"guid": "{478EA8A8-00BE-4BA6-8E75-8B9DC7DB9F78}",
"event_source_name": "",
"event_id": 134,
"version": 0,
"level": 5,
"task": 35,
"opcode": 0,
"keywords": "0x0000000000000100",
"time_created": "2026-06-02T05:23:25.943+00:00",
"event_record_id": 0,
"correlation": {},
"execution": {
"process_id": 4820,
"thread_id": 7912
},
"channel": "ETW Trace",
"computer": "JD-DC01-2022",
"security": {
"user_id": ""
}
},
"event_data": {
"pTaskInfo": "0x0",
"pfnCompletion": "0x7FF9F6748080",
"pgptm": "0x2B467B101F0",
"pvParam": "0x2B467B50000"
},
"message": "ESE_GPTaskManagerPost_Trace"
}
Event ID 135: ESE GPTaskManagerRun Trace
#Description
ESE GPTaskManagerRun Trace.
Message #
Fields #
| Name | Description |
|---|---|
pgptm Pointer | |
pfnCompletion Pointer | |
pvParam Pointer | |
pTaskInfo Pointer |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-ESE",
"guid": "{478EA8A8-00BE-4BA6-8E75-8B9DC7DB9F78}",
"event_source_name": "",
"event_id": 135,
"version": 0,
"level": 5,
"task": 36,
"opcode": 0,
"keywords": "0x0000000000000100",
"time_created": "2026-06-02T05:23:25.951+00:00",
"event_record_id": 0,
"correlation": {},
"execution": {
"process_id": 4820,
"thread_id": 16212
},
"channel": "ETW Trace",
"computer": "JD-DC01-2022",
"security": {
"user_id": ""
}
},
"event_data": {
"pTaskInfo": "0x0",
"pfnCompletion": "0x7FF9F6748080",
"pgptm": "0x2B467B101F0",
"pvParam": "0x2B467B50000"
},
"message": "ESE_GPTaskManagerRun_Trace"
}
Event ID 136: ESE TestMarker Trace
#Event ID 137: ESE ThreadCreate Trace
#Event ID 138: ESE ThreadStart Trace
#Description
ESE ThreadStart Trace.
Message #
Fields #
| Name | Description |
|---|---|
Thread Pointer | |
pfnStart Pointer | |
dwParam Pointer |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-ESE",
"guid": "{478EA8A8-00BE-4BA6-8E75-8B9DC7DB9F78}",
"event_source_name": "",
"event_id": 138,
"version": 0,
"level": 4,
"task": 39,
"opcode": 0,
"keywords": "0x0000000000000100",
"time_created": "2026-06-02T05:23:26.576+00:00",
"event_record_id": 0,
"correlation": {},
"execution": {
"process_id": 21260,
"thread_id": 4144
},
"channel": "ETW Trace",
"computer": "JD-DC01-2022",
"security": {
"user_id": ""
}
},
"event_data": {
"Thread": "0x1D626213470",
"dwParam": "0x0",
"pfnStart": "0x7FF9F6806360"
},
"message": "ESE_ThreadStart_Trace"
}
Event ID 139: ESE CacheVersionPage Trace
#Event ID 140: ESE CacheVersionCopyPage Trace
#Event ID 141: ESE CacheResize Trace
#Description
ESE CacheResize Trace.
Message #
Fields #
| Name | Description |
|---|---|
cbfCacheAddressableInitial Int64 | |
cbfCacheSizeInitial Int64 | |
cbfCacheAddressableFinal Int64 | |
cbfCacheSizeFinal Int64 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-ESE",
"guid": "{478EA8A8-00BE-4BA6-8E75-8B9DC7DB9F78}",
"event_source_name": "",
"event_id": 141,
"version": 0,
"level": 4,
"task": 42,
"opcode": 0,
"keywords": "0x0000000000000022",
"time_created": "2026-06-02T05:23:26.577+00:00",
"event_record_id": 0,
"correlation": {},
"execution": {
"process_id": 21260,
"thread_id": 12752
},
"channel": "ETW Trace",
"computer": "JD-DC01-2022",
"security": {
"user_id": ""
}
},
"event_data": {
"cbfCacheAddressableFinal": 320,
"cbfCacheAddressableInitial": 0,
"cbfCacheSizeFinal": 320,
"cbfCacheSizeInitial": 0
},
"message": "ESE_CacheResize_Trace"
}
Event ID 142: ESE CacheLimitResize Trace
#Description
ESE CacheLimitResize Trace.
Message #
Fields #
| Name | Description |
|---|---|
cbfCacheSizeLimitInitial Int64 | |
cbfCacheSizeLimitFinal Int64 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-ESE",
"guid": "{478EA8A8-00BE-4BA6-8E75-8B9DC7DB9F78}",
"event_source_name": "",
"event_id": 142,
"version": 0,
"level": 4,
"task": 43,
"opcode": 0,
"keywords": "0x0000000000000022",
"time_created": "2026-06-02T05:23:25.398+00:00",
"event_record_id": 0,
"correlation": {},
"execution": {
"process_id": 1748,
"thread_id": 19708
},
"channel": "ETW Trace",
"computer": "JD-DC01-2022",
"security": {
"user_id": ""
}
},
"event_data": {
"cbfCacheSizeLimitFinal": 64,
"cbfCacheSizeLimitInitial": 64
},
"message": "ESE_CacheLimitResize_Trace"
}
Event ID 143: ESE CacheScavengeProgress Trace
#Description
ESE CacheScavengeProgress Trace.
Message #
Fields #
| Name | Description |
|---|---|
iRun Int64 | |
cbfVisited Int32 | |
cbfCacheSize Int32 | |
cbfCacheTarget Int32 | |
cbfCacheSizeStartShrink Int32 | |
dtickShrinkDuration UInt32 | |
cbfAvail Int32 | |
cbfAvailPoolLow Int32 | |
cbfAvailPoolHigh Int32 | |
cbfFlushPending Int32 | |
cbfFlushPendingSlow Int32 | |
cbfFlushPendingHung Int32 | |
cbfOutOfMemory Int32 | |
cbfPermanentErrs Int32 | |
eStopReason Int32 | |
errRun Int32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-ESE",
"guid": "{478EA8A8-00BE-4BA6-8E75-8B9DC7DB9F78}",
"event_source_name": "",
"event_id": 143,
"version": 0,
"level": 4,
"task": 44,
"opcode": 0,
"keywords": "0x0000000000000022",
"time_created": "2026-06-02T05:23:25.398+00:00",
"event_record_id": 0,
"correlation": {},
"execution": {
"process_id": 1748,
"thread_id": 19708
},
"channel": "ETW Trace",
"computer": "JD-DC01-2022",
"security": {
"user_id": ""
}
},
"event_data": {
"cbfAvail": 8,
"cbfAvailPoolHigh": 8,
"cbfAvailPoolLow": 4,
"cbfCacheSize": 64,
"cbfCacheSizeStartShrink": 0,
"cbfCacheTarget": 64,
"cbfFlushPending": 0,
"cbfFlushPendingHung": 0,
"cbfFlushPendingSlow": 0,
"cbfOutOfMemory": 0,
"cbfPermanentErrs": 0,
"cbfVisited": 2,
"dtickShrinkDuration": 0,
"eStopReason": 1,
"errRun": 0,
"iRun": 69099
},
"message": "ESE_CacheScavengeProgress_Trace"
}
Event ID 144: ESE ApiCall_Start Trace
#Description
ESE ApiCall_Start Trace.
Message #
Fields #
| Name | Description |
|---|---|
opApi UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-ESE",
"guid": "{478EA8A8-00BE-4BA6-8E75-8B9DC7DB9F78}",
"event_source_name": "",
"event_id": 144,
"version": 0,
"level": 4,
"task": 45,
"opcode": 1,
"keywords": "0x0000000000000002",
"time_created": "2026-06-02T05:23:25.374+00:00",
"event_record_id": 0,
"correlation": {},
"execution": {
"process_id": 4820,
"thread_id": 7912
},
"channel": "ETW Trace",
"computer": "JD-DC01-2022",
"security": {
"user_id": ""
}
},
"event_data": {
"opApi": 9
},
"message": "ESE_ApiCall_Trace"
}
Event ID 145: ESE ApiCall_Stop Trace
#Description
ESE ApiCall_Stop Trace.
Message #
Fields #
| Name | Description |
|---|---|
opApi UInt32 | |
err Int32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-ESE",
"guid": "{478EA8A8-00BE-4BA6-8E75-8B9DC7DB9F78}",
"event_source_name": "",
"event_id": 145,
"version": 0,
"level": 4,
"task": 45,
"opcode": 2,
"keywords": "0x0000000000000002",
"time_created": "2026-06-02T05:23:25.374+00:00",
"event_record_id": 0,
"correlation": {},
"execution": {
"process_id": 4820,
"thread_id": 7912
},
"channel": "ETW Trace",
"computer": "JD-DC01-2022",
"security": {
"user_id": ""
}
},
"event_data": {
"err": 0,
"opApi": 9
},
"message": "ESE_ApiCall_Trace"
}
Event ID 146: ESE ResMgrInit Trace
#Description
ESE ResMgrInit Trace.
Message #
Fields #
| Name | Description |
|---|---|
tick UInt32 | |
K Int32 | |
csecCorrelatedTouch Double | |
csecTimeout Double | |
csecUncertainty Double | |
dblHashLoadFactor Double | |
dblHashUniformity Double | |
dblSpeedSizeTradeoff Double |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-ESE",
"guid": "{478EA8A8-00BE-4BA6-8E75-8B9DC7DB9F78}",
"event_source_name": "",
"event_id": 146,
"version": 0,
"level": 4,
"task": 46,
"opcode": 0,
"keywords": "0x0000000000000400",
"time_created": "2026-06-02T05:23:26.576+00:00",
"event_record_id": 0,
"correlation": {},
"execution": {
"process_id": 21260,
"thread_id": 12752
},
"channel": "ETW Trace",
"computer": "JD-DC01-2022",
"security": {
"user_id": ""
}
},
"event_data": {
"K": 2,
"csecCorrelatedTouch": 0.128,
"csecTimeout": 100.0,
"csecUncertainty": 1.0,
"dblHashLoadFactor": 5.0,
"dblHashUniformity": 1.0,
"dblSpeedSizeTradeoff": 0.0,
"tick": 35250750
},
"message": "ESE_ResMgrInit_Trace"
}
Event ID 147: ESE ResMgrTerm Trace
#Event ID 148: ESE CacheCachePage Trace
#Description
ESE CacheCachePage Trace.
Message #
Fields #
| Name | Description |
|---|---|
tick UInt32 | |
ifmp UInt32 | |
pgno UInt32 | |
bflf UInt32 | |
bflt UInt32 | |
pctPriority UInt32 | |
bfrtf UInt32 | |
ClientType UInt8 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-ESE",
"guid": "{478EA8A8-00BE-4BA6-8E75-8B9DC7DB9F78}",
"event_source_name": "",
"event_id": 148,
"version": 0,
"level": 5,
"task": 48,
"opcode": 0,
"keywords": "0x0000000000000420",
"time_created": "2026-06-02T05:23:25.389+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{5FF741DB-F0E3-4F6E-BD7E-A0D869BCBAEE}"
},
"execution": {
"process_id": 1748,
"thread_id": 19708
},
"channel": "ETW Trace",
"computer": "JD-DC01-2022",
"security": {
"user_id": ""
}
},
"event_data": {
"ClientType": 0,
"bflf": 16384,
"bflt": 0,
"bfrtf": 12,
"ifmp": 2,
"pctPriority": 100,
"pgno": 11611,
"tick": 35249562
},
"message": "ESE_CacheCachePage_Trace"
}
Event ID 149: ESE MarkPageAsSuperCold Trace
#Event ID 150: ESE CacheMissLatency Trace
#Description
ESE CacheMissLatency Trace.
Message #
Fields #
| Name | Description |
|---|---|
ifmp UInt32 | |
pgno UInt32 | |
dwUserId UInt32 | |
bOperationId UInt8 | |
bOperationType UInt8 | |
bClientType UInt8 | |
bFlags UInt8 | |
dwCorrelationId UInt32 | |
iorp UInt8 | |
iors UInt8 | |
iort UInt8 | |
ioru UInt8 | |
iorf UInt8 | |
tce UInt8 | |
usecsWait UInt64 | |
bftcmr UInt8 | |
bUserPriorityTag UInt8 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-ESE",
"guid": "{478EA8A8-00BE-4BA6-8E75-8B9DC7DB9F78}",
"event_source_name": "",
"event_id": 150,
"version": 0,
"level": 4,
"task": 50,
"opcode": 0,
"keywords": "0x0000000000002020",
"time_created": "2026-06-02T05:23:25.389+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{5FF741DB-F0E3-4F6E-BD7E-A0D869BCBAEE}"
},
"execution": {
"process_id": 1748,
"thread_id": 19708
},
"channel": "ETW Trace",
"computer": "JD-DC01-2022",
"security": {
"user_id": ""
}
},
"event_data": {
"bClientType": 0,
"bFlags": 0,
"bOperationId": 0,
"bOperationType": 0,
"bUserPriorityTag": 0,
"bftcmr": 5,
"dwCorrelationId": 0,
"dwUserId": 2147483648,
"ifmp": 2,
"iorf": 0,
"iorp": 33,
"iors": 3,
"iort": 1,
"ioru": 29,
"pgno": 11611,
"tce": 0,
"usecsWait": 5
},
"message": "ESE_CacheMissLatency_Trace"
}
Event ID 151: ESE BTreePrereadPageRequest Trace
#Event ID 152: ESE DiskFlushFileBuffers Trace
#Description
ESE DiskFlushFileBuffers Trace.
Message #
Fields #
| Name | Description |
|---|---|
Disk UInt32 | |
wszFileName UnicodeString | |
iofr UInt32 | |
cioreqFileFlushing UInt64 | |
usFfb UInt64 | |
error UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-ESE",
"guid": "{478EA8A8-00BE-4BA6-8E75-8B9DC7DB9F78}",
"event_source_name": "",
"event_id": 152,
"version": 0,
"level": 4,
"task": 52,
"opcode": 0,
"keywords": "0x0000000000000040",
"time_created": "2026-06-02T05:23:26.724+00:00",
"event_record_id": 0,
"correlation": {},
"execution": {
"process_id": 12112,
"thread_id": 7804
},
"channel": "ETW Trace",
"computer": "JD-DC01-2022",
"security": {
"user_id": ""
}
},
"event_data": {
"Disk": 0,
"cioreqFileFlushing": 1,
"error": 0,
"iofr": 2,
"usFfb": 893,
"wszFileName": "Svc.log"
},
"message": "ESE_DiskFlushFileBuffers_Trace"
}
Event ID 153: ESE DiskFlushFileBuffersBegin Trace
#Description
ESE DiskFlushFileBuffersBegin Trace.
Message #
Fields #
| Name | Description |
|---|---|
dwDisk UInt32 | |
hFile UInt64 | |
iofr UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-ESE",
"guid": "{478EA8A8-00BE-4BA6-8E75-8B9DC7DB9F78}",
"event_source_name": "",
"event_id": 153,
"version": 0,
"level": 4,
"task": 53,
"opcode": 0,
"keywords": "0x0000000000000040",
"time_created": "2026-06-02T05:23:26.641+00:00",
"event_record_id": 0,
"correlation": {},
"execution": {
"process_id": 21260,
"thread_id": 12752
},
"channel": "ETW Trace",
"computer": "JD-DC01-2022",
"security": {
"user_id": ""
}
},
"event_data": {
"dwDisk": 0,
"hFile": 1204,
"iofr": 2147483680
},
"message": "ESE_DiskFlushFileBuffersBegin_Trace"
}
Event ID 154: ESE CacheFirstDirtyPage Trace
#Description
ESE CacheFirstDirtyPage Trace.
Message #
Fields #
| Name | Description |
|---|---|
tick UInt32 | |
ifmp UInt32 | |
pgno UInt32 | |
objid UInt32 | |
fFlags UInt32 | |
bfdfNew UInt32 | |
lgposModify UInt64 | |
dwUserId UInt32 | |
bOperationId UInt8 | |
bOperationType UInt8 | |
bClientType UInt8 | |
bFlags UInt8 | |
dwCorrelationId UInt32 | |
iorp UInt8 | |
iors UInt8 | |
iort UInt8 | |
ioru UInt8 | |
iorf UInt8 | |
tce UInt8 |
Event ID 155: ESE SysStationId Trace
#Description
ESE SysStationId Trace.
Message #
Fields #
| Name | Description |
|---|---|
tsidr UInt8 | |
dwImageVerMajor UInt32 | |
dwImageVerMinor UInt32 | |
dwImageBuildMajor UInt32 | |
dwImageBuildMinor UInt32 | |
wszDisplayName UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-ESE",
"guid": "{478EA8A8-00BE-4BA6-8E75-8B9DC7DB9F78}",
"event_source_name": "",
"event_id": 155,
"version": 0,
"level": 4,
"task": 55,
"opcode": 0,
"keywords": "0x0000000000000800",
"time_created": "2026-06-02T05:23:25.389+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{5FF741DB-F0E3-4F6E-BD7E-A0D869BCBAEE}"
},
"execution": {
"process_id": 1748,
"thread_id": 19708
},
"channel": "ETW Trace",
"computer": "JD-DC01-2022",
"security": {
"user_id": ""
}
},
"event_data": {
"dwImageBuildMajor": 20348,
"dwImageBuildMinor": 0,
"dwImageVerMajor": 10,
"dwImageVerMinor": 0,
"tsidr": 1,
"wszDisplayName": "svchost.exe"
},
"message": "ESE_SysStationId_Trace"
}
Event ID 156: ESE InstStationId Trace
#Description
ESE InstStationId Trace.
Message #
Fields #
| Name | Description |
|---|---|
tsidr UInt8 | |
iInstance UInt32 | |
perfstatusEvent UInt8 | |
wszInstanceName UnicodeString | |
wszDisplayName UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-ESE",
"guid": "{478EA8A8-00BE-4BA6-8E75-8B9DC7DB9F78}",
"event_source_name": "",
"event_id": 156,
"version": 0,
"level": 4,
"task": 56,
"opcode": 0,
"keywords": "0x0000000000000800",
"time_created": "2026-06-02T05:23:25.389+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{5FF741DB-F0E3-4F6E-BD7E-A0D869BCBAEE}"
},
"execution": {
"process_id": 1748,
"thread_id": 19708
},
"channel": "ETW Trace",
"computer": "JD-DC01-2022",
"security": {
"user_id": ""
}
},
"event_data": {
"iInstance": 1,
"perfstatusEvent": 3,
"tsidr": 1,
"wszDisplayName": "NULL",
"wszInstanceName": "Catalog Database"
},
"message": "ESE_InstStationId_Trace"
}
Event ID 157: ESE FmpStationId Trace
#Description
ESE FmpStationId Trace.
Message #
Fields #
| Name | Description |
|---|---|
tsidr UInt8 | |
ifmp UInt32 | |
iInstance UInt32 | |
dbid UInt8 | |
wszDatabaseName UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-ESE",
"guid": "{478EA8A8-00BE-4BA6-8E75-8B9DC7DB9F78}",
"event_source_name": "",
"event_id": 157,
"version": 0,
"level": 4,
"task": 57,
"opcode": 0,
"keywords": "0x0000000000000800",
"time_created": "2026-06-02T05:23:25.389+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{5FF741DB-F0E3-4F6E-BD7E-A0D869BCBAEE}"
},
"execution": {
"process_id": 1748,
"thread_id": 19708
},
"channel": "ETW Trace",
"computer": "JD-DC01-2022",
"security": {
"user_id": ""
}
},
"event_data": {
"dbid": 2,
"iInstance": 1,
"ifmp": 2,
"tsidr": 1,
"wszDatabaseName": "C:\\Windows\\system32\\CatRoot2\\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\\catdb"
},
"message": "ESE_FmpStationId_Trace"
}
Event ID 158: ESE DiskStationId Trace
#Description
ESE DiskStationId Trace.
Message #
Fields #
| Name | Description |
|---|---|
tsidr UInt8 | |
dwDiskNumber UInt32 | |
wszDiskPathId UnicodeString | |
szDiskModel AnsiString | |
szDiskFirmwareRev AnsiString | |
szDiskSerialNumber AnsiString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-ESE",
"guid": "{478EA8A8-00BE-4BA6-8E75-8B9DC7DB9F78}",
"event_source_name": "",
"event_id": 158,
"version": 0,
"level": 4,
"task": 58,
"opcode": 0,
"keywords": "0x0000000000000800",
"time_created": "2026-06-02T05:23:26.626+00:00",
"event_record_id": 0,
"correlation": {},
"execution": {
"process_id": 21260,
"thread_id": 12752
},
"channel": "ETW Trace",
"computer": "JD-DC01-2022",
"security": {
"user_id": ""
}
},
"event_data": {
"dwDiskNumber": 0,
"szDiskFirmwareRev": "0001",
"szDiskModel": "VirtIO",
"szDiskSerialNumber": "",
"tsidr": 1,
"wszDiskPathId": "MBR:77AC4D73"
},
"message": "ESE_DiskStationId_Trace"
}
Event ID 159: ESE FileStationId Trace
#Description
ESE FileStationId Trace.
Message #
Fields #
| Name | Description |
|---|---|
tsidr UInt8 | |
hFile UInt64 | |
dwDiskNumber UInt32 | |
dwEngineFileType UInt32 | |
qwEngineFileId UInt64 | |
fmf UInt32 | |
cbFileSize UInt64 | |
wszAbsPath UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-ESE",
"guid": "{478EA8A8-00BE-4BA6-8E75-8B9DC7DB9F78}",
"event_source_name": "",
"event_id": 159,
"version": 0,
"level": 4,
"task": 59,
"opcode": 0,
"keywords": "0x0000000000000800",
"time_created": "2026-06-02T05:23:26.584+00:00",
"event_record_id": 0,
"correlation": {},
"execution": {
"process_id": 21260,
"thread_id": 12752
},
"channel": "ETW Trace",
"computer": "JD-DC01-2022",
"security": {
"user_id": ""
}
},
"event_data": {
"cbFileSize": 0,
"dwDiskNumber": 0,
"dwEngineFileType": 3,
"fmf": 1,
"hFile": 1204,
"qwEngineFileId": 4611686022722355201,
"tsidr": 2,
"wszAbsPath": "C:\\ProgramData\\Microsoft\\Search\\Data\\Applications\\Windows\\edbtmp.jtx"
},
"message": "ESE_FileStationId_Trace"
}
Event ID 160: ESE IsamDbfilehdrInfo Trace
#Description
ESE IsamDbfilehdrInfo Trace.
Message #
Fields #
| Name | Description |
|---|---|
tsidr UInt8 | |
ifmp UInt32 | |
filetype UInt32 | |
ulMagic UInt32 | |
ulChecksum UInt32 | |
cbPageSize UInt32 | |
ulDbFlags UInt32 | |
psignDb Binary |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-ESE",
"guid": "{478EA8A8-00BE-4BA6-8E75-8B9DC7DB9F78}",
"event_source_name": "",
"event_id": 160,
"version": 0,
"level": 4,
"task": 60,
"opcode": 0,
"keywords": "0x0000000000000800",
"time_created": "2026-06-02T05:23:25.389+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{5FF741DB-F0E3-4F6E-BD7E-A0D869BCBAEE}"
},
"execution": {
"process_id": 1748,
"thread_id": 19708
},
"channel": "ETW Trace",
"computer": "JD-DC01-2022",
"security": {
"user_id": ""
}
},
"event_data": {
"cbPageSize": 4096,
"filetype": 1,
"ifmp": 2,
"psignDb": "9D812947341F131F0C7D1F0400000000000000000000000000000000",
"tsidr": 1,
"ulChecksum": 3391831584,
"ulDbFlags": 0,
"ulMagic": 2309737967
},
"message": "ESE_IsamDbfilehdrInfo_Trace"
}
Event ID 161: ESE DiskOsDiskCacheInfo Trace
#Description
ESE DiskOsDiskCacheInfo Trace.
Message #
Fields #
| Name | Description |
|---|---|
tsidr UInt8 | |
posdci Binary |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-ESE",
"guid": "{478EA8A8-00BE-4BA6-8E75-8B9DC7DB9F78}",
"event_source_name": "",
"event_id": 161,
"version": 0,
"level": 4,
"task": 61,
"opcode": 0,
"keywords": "0x0000000000000800",
"time_created": "2026-06-02T05:23:26.626+00:00",
"event_record_id": 0,
"correlation": {},
"execution": {
"process_id": 21260,
"thread_id": 12752
},
"channel": "ETW Trace",
"computer": "JD-DC01-2022",
"security": {
"user_id": ""
}
},
"event_data": {
"posdci": "000101000000000000000000000000000000000000000000",
"tsidr": 1
},
"message": "ESE_DiskOsDiskCacheInfo_Trace"
}
Event ID 162: ESE DiskOsStorageWriteCacheProp Trace
#Event ID 163: ESE DiskOsDeviceSeekPenaltyDesc Trace
#Event ID 165: ESE IOCompletion2 Trace
#Description
ESE IOCompletion2 Trace.
Message #
Fields #
| Name | Description |
|---|---|
wszFilename UnicodeString | |
fMultiIor UInt32 | |
fWrite UInt8 | |
dwUserId UInt32 | |
bOperationId UInt8 | |
bOperationType UInt8 | |
bClientType UInt8 | |
bFlags UInt8 | |
dwCorrelationId UInt32 | |
iorp UInt8 | |
iors UInt8 | |
iort UInt8 | |
ioru UInt8 | |
iorf UInt8 | |
tce UInt8 | |
szClientComponent AnsiString | |
szClientAction AnsiString | |
szClientActionContext AnsiString | |
guidActivityId GUID | |
ibOffset UInt64 | |
cbTransfer UInt32 | |
dwError UInt32 | |
qosHighestFirst UInt32 | |
cmsecIOElapsed Double | |
dtickQueueDelay UInt32 | |
tidAlloc UInt32 | |
dwEngineFileType UInt32 | |
dwEngineFileId UInt64 | |
fmfFile UInt32 | |
dwDiskNumber UInt32 | |
dwEngineObjid UInt32 | |
dwTraceFlags UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-ESE",
"guid": "{478EA8A8-00BE-4BA6-8E75-8B9DC7DB9F78}",
"event_source_name": "",
"event_id": 165,
"version": 0,
"level": 4,
"task": 65,
"opcode": 0,
"keywords": "0x0000000000008000",
"time_created": "2026-06-02T05:23:26.626+00:00",
"event_record_id": 0,
"correlation": {},
"execution": {
"process_id": 21260,
"thread_id": 12752
},
"channel": "ETW Trace",
"computer": "JD-DC01-2022",
"security": {
"user_id": ""
}
},
"event_data": {
"bClientType": 0,
"bFlags": 0,
"bOperationId": 0,
"bOperationType": 0,
"cbTransfer": 0,
"cmsecIOElapsed": 41,
"dtickQueueDelay": 5,
"dwCorrelationId": 0,
"dwDiskNumber": 0,
"dwEngineFileId": 4611686022722355201,
"dwEngineFileType": 3,
"dwEngineObjid": 0,
"dwError": 0,
"dwUserId": 4294967295,
"fMultiIor": 262144,
"fWrite": 1,
"fmfFile": 1,
"guidActivityId": "{00000000-0000-0000-0000-000000000000}",
"ibOffset": 1048576,
"iorf": 0,
"iorp": 80,
"iors": 0,
"iort": 9,
"ioru": 98,
"qosHighestFirst": 16,
"szClientAction": "",
"szClientActionContext": "",
"szClientComponent": "",
"tce": 0,
"tidAlloc": 12752,
"wszFilename": "C:\\ProgramData\\Microsoft\\Search\\Data\\Applications\\Windows\\edbtmp.jtx"
},
"message": "ESE_IOCompletion2_Trace"
}
Event ID 166: ESE FCBPurgeFailure Trace
#Event ID 167: ESE IOLatencySpikeNotice Trace
#Event ID 168: ESE IOCompletion2Sess Trace
#Description
ESE IOCompletion2Sess Trace.
Message #
Fields #
| Name | Description |
|---|---|
wszFilename UnicodeString | |
fMultiIor UInt32 | |
fWrite UInt8 | |
dwUserId UInt32 | |
bOperationId UInt8 | |
bOperationType UInt8 | |
bClientType UInt8 | |
bFlags UInt8 | |
dwCorrelationId UInt32 | |
iorp UInt8 | |
iors UInt8 | |
iort UInt8 | |
ioru UInt8 | |
iorf UInt8 | |
tce UInt8 | |
szClientComponent AnsiString | |
szClientAction AnsiString | |
szClientActionContext AnsiString | |
guidActivityId GUID | |
ibOffset UInt64 | |
cbTransfer UInt32 | |
dwError UInt32 | |
qosHighestFirst UInt32 | |
cmsecIOElapsed Double | |
dtickQueueDelay UInt32 | |
tidAlloc UInt32 | |
dwEngineFileType UInt32 | |
dwEngineFileId UInt64 | |
fmfFile UInt32 | |
dwDiskNumber UInt32 | |
dwEngineObjid UInt32 | |
dwTraceFlags UInt32 |
Event ID 169: ESE IOIssueThreadPost Trace
#Description
ESE IOIssueThreadPost Trace.
Message #
Fields #
| Name | Description |
|---|---|
p_osf Pointer | |
cioDiskEnqueued UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-ESE",
"guid": "{478EA8A8-00BE-4BA6-8E75-8B9DC7DB9F78}",
"event_source_name": "",
"event_id": 169,
"version": 0,
"level": 4,
"task": 69,
"opcode": 0,
"keywords": "0x0000000000000040",
"time_created": "2026-06-02T05:23:26.626+00:00",
"event_record_id": 0,
"correlation": {},
"execution": {
"process_id": 21260,
"thread_id": 12752
},
"channel": "ETW Trace",
"computer": "JD-DC01-2022",
"security": {
"user_id": ""
}
},
"event_data": {
"cioDiskEnqueued": 0,
"p_osf": "0x1D6262A5B90"
},
"message": "ESE_IOIssueThreadPost_Trace"
}
Event ID 170: ESE IOIssueThreadPosted Trace
#Description
ESE IOIssueThreadPosted Trace.
Message #
Fields #
| Name | Description |
|---|---|
p_osf Pointer | |
cDispatchAttempts UInt32 | |
usPosted UInt64 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-ESE",
"guid": "{478EA8A8-00BE-4BA6-8E75-8B9DC7DB9F78}",
"event_source_name": "",
"event_id": 170,
"version": 0,
"level": 4,
"task": 70,
"opcode": 0,
"keywords": "0x0000000000000040",
"time_created": "2026-06-02T05:23:26.626+00:00",
"event_record_id": 0,
"correlation": {},
"execution": {
"process_id": 21260,
"thread_id": 12752
},
"channel": "ETW Trace",
"computer": "JD-DC01-2022",
"security": {
"user_id": ""
}
},
"event_data": {
"cDispatchAttempts": 0,
"p_osf": "0x1D6262A5B90",
"usPosted": 2
},
"message": "ESE_IOIssueThreadPosted_Trace"
}
Event ID 171: ESE IOThreadIssueStart Trace
#Description
ESE IOThreadIssueStart Trace.
Message #
Example Event #
{
"system": {
"provider": "Microsoft-Windows-ESE",
"guid": "{478EA8A8-00BE-4BA6-8E75-8B9DC7DB9F78}",
"event_source_name": "",
"event_id": 171,
"version": 0,
"level": 4,
"task": 71,
"opcode": 0,
"keywords": "0x0000000000000040",
"time_created": "2026-06-02T05:23:26.762+00:00",
"event_record_id": 0,
"correlation": {},
"execution": {
"process_id": 12112,
"thread_id": 1804
},
"channel": "ETW Trace",
"computer": "JD-DC01-2022",
"security": {
"user_id": ""
}
},
"event_data": {},
"message": "ESE_IOThreadIssueStart_Trace"
}
Event ID 172: ESE IOThreadIssuedDisk Trace
#Description
ESE IOThreadIssuedDisk Trace.
Message #
Fields #
| Name | Description |
|---|---|
dwDiskId UInt32 | |
fFromCompletion UInt8 | |
ipass Int64 | |
err Int32 | |
cioProcessed UInt32 | |
usRuntime UInt64 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-ESE",
"guid": "{478EA8A8-00BE-4BA6-8E75-8B9DC7DB9F78}",
"event_source_name": "",
"event_id": 172,
"version": 0,
"level": 4,
"task": 72,
"opcode": 0,
"keywords": "0x0000000000000040",
"time_created": "2026-06-02T05:23:26.762+00:00",
"event_record_id": 0,
"correlation": {},
"execution": {
"process_id": 12112,
"thread_id": 1804
},
"channel": "ETW Trace",
"computer": "JD-DC01-2022",
"security": {
"user_id": ""
}
},
"event_data": {
"cioProcessed": 1,
"dwDiskId": 0,
"err": 0,
"fFromCompletion": 0,
"ipass": 24779,
"usRuntime": 62
},
"message": "ESE_IOThreadIssuedDisk_Trace"
}
Event ID 173: ESE IOThreadIssueProcessedIO Trace
#Description
ESE IOThreadIssueProcessedIO Trace.
Message #
Fields #
| Name | Description |
|---|---|
err Int32 | |
cDisksProcessed UInt32 | |
usRuntime UInt64 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-ESE",
"guid": "{478EA8A8-00BE-4BA6-8E75-8B9DC7DB9F78}",
"event_source_name": "",
"event_id": 173,
"version": 0,
"level": 4,
"task": 73,
"opcode": 0,
"keywords": "0x0000000000000040",
"time_created": "2026-06-02T05:23:26.762+00:00",
"event_record_id": 0,
"correlation": {},
"execution": {
"process_id": 12112,
"thread_id": 1804
},
"channel": "ETW Trace",
"computer": "JD-DC01-2022",
"security": {
"user_id": ""
}
},
"event_data": {
"cDisksProcessed": 1,
"err": 0,
"usRuntime": 65
},
"message": "ESE_IOThreadIssueProcessedIO_Trace"
}
Event ID 174: ESE IOIoreqCompletion Trace
#Event ID 175: ESE CacheMemoryUsage Trace
#Event ID 176: ESE CacheSetLgposModify Trace
#Description
ESE CacheSetLgposModify Trace.
Message #
Fields #
| Name | Description |
|---|---|
tick UInt32 | |
ifmp UInt32 | |
pgno UInt32 | |
lgposModify UInt64 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-ESE",
"guid": "{478EA8A8-00BE-4BA6-8E75-8B9DC7DB9F78}",
"event_source_name": "",
"event_id": 176,
"version": 0,
"level": 5,
"task": 76,
"opcode": 0,
"keywords": "0x0000000000000420",
"time_created": "2026-06-02T05:23:25.374+00:00",
"event_record_id": 0,
"correlation": {},
"execution": {
"process_id": 4820,
"thread_id": 7912
},
"channel": "ETW Trace",
"computer": "JD-DC01-2022",
"security": {
"user_id": ""
}
},
"event_data": {
"ifmp": 1,
"lgposModify": 1816803083672,
"pgno": 141,
"tick": 35249546
},
"message": "ESE_CacheSetLgposModify_Trace"
}
Event ID 177: ESE CacheFirstDirtyPage2 Trace
#Description
ESE CacheFirstDirtyPage2 Trace.
Message #
Fields #
| Name | Description |
|---|---|
tick UInt32 | |
wszFilename UnicodeString | |
ifmp UInt32 | |
iofile UInt32 | |
pgno UInt32 | |
objid UInt32 | |
fFlags UInt32 | |
bfdfNew UInt32 | |
lgposModify UInt64 | |
dwUserId UInt32 | |
bOperationId UInt8 | |
bOperationType UInt8 | |
bClientType UInt8 | |
bFlags UInt8 | |
dwCorrelationId UInt32 | |
iorp UInt8 | |
iors UInt8 | |
iort UInt8 | |
ioru UInt8 | |
iorf UInt8 | |
tce UInt8 | |
szClientComponent AnsiString | |
szClientAction AnsiString | |
szClientActionContext AnsiString | |
guidActivityId GUID |
Event ID 178: ESE DBScanPageSpace Trace
#Event ID 200: ESE tagNull Trace
#Event ID 201: ESE tagInformation Trace
#Event ID 202: ESE tagErrors Trace
#Event ID 203: ESE tagAsserts Trace
#Event ID 204: ESE tagAPI Trace
#Event ID 205: ESE tagInitTerm Trace
#Event ID 206: ESE tagBufferManager Trace
#Event ID 207: ESE tagBufferManagerHashedLatches Trace
#Event ID 208: ESE tagIO Trace
#Event ID 209: ESE tagMemory Trace
#Event ID 210: ESE tagVersionStore Trace
#Event ID 211: ESE tagVersionStoreOOM Trace
#Event ID 212: ESE tagVersionCleanup Trace
#Event ID 213: ESE tagCatalog Trace
#Event ID 214: ESE tagDDLRead Trace
#Event ID 215: ESE tagDDLWrite Trace
#Event ID 216: ESE tagDMLRead Trace
#Event ID 217: ESE tagDMLWrite Trace
#Event ID 218: ESE tagDMLConflicts Trace
#Event ID 219: ESE tagInstances Trace
#Event ID 220: ESE tagDatabases Trace
#Event ID 221: ESE tagSessions Trace
#Event ID 222: ESE tagCursors Trace
#Event ID 223: ESE tagCursorNavigation Trace
#Event ID 224: ESE tagCursorPageRefs Trace
#Event ID 225: ESE tagBtree Trace
#Event ID 226: ESE tagSpace Trace
#Event ID 227: ESE tagFCBs Trace
#Event ID 228: ESE tagTransactions Trace
#Event ID 229: ESE tagLogging Trace
#Event ID 230: ESE tagRecovery Trace
#Event ID 231: ESE tagBackup Trace
#Event ID 232: ESE tagRestore Trace
#Event ID 233: ESE tagOLD Trace
#Event ID 234: ESE tagEventlog Trace
#Event ID 235: ESE tagBufferManagerMaintTasks Trace
#Event ID 236: ESE tagSpaceManagement Trace
#Event ID 237: ESE tagSpaceInternal Trace
#Event ID 238: ESE tagIOQueue Trace
#Event ID 239: ESE tagDiskVolumeManagement Trace
#Event ID 240: ESE tagCallbacks Trace
#Event ID 241: ESE tagIOProblems Trace
#Event ID 242: ESE tagUpgrade Trace
#Event ID 243: ESE tagRecoveryValidation Trace
#Event ID 244: ESE tagBufferManagerBufferCacheState Trace
#Event ID 245: ESE tagBufferManagerBufferDirtyState Trace
#Event ID 246: ESE tagTimerQueue Trace
#Event ID 247: ESE tagSortPerf Trace
#Event ID 248: ESE tagOLDRegistration Trace
#Event ID 249: ESE tagOLDWork Trace
#Event ID 250: ESE tagSysInitTerm Trace
#Event ID 251: ESE tagVersionAndStagingChecks Trace
#Event ID 252: ESE tagFile Trace
#Event ID 253: ESE tagFlushFileBuffers Trace
#Event ID 254: ESE tagCheckpointUpdate Trace
#Event ID 255: ESE tagDiagnostics Trace
#Event ID 256: ESE tagBlockCache Trace
#Event ID 257: ESE tagRBS Trace
#Event ID 258: ESE tagRBSCleaner Trace
#Event ID 259: ESE tagBlockCacheOperations Trace
#Event ID 5000: ESE Compression Experiment Trace
#Provenance
Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.
ETW provider GUID {478EA8A8-00BE-4BA6-8E75-8B9DC7DB9F78}
Defined in ETWESEProviderResources.dll, which carries the event manifest.
Observed on:
- WS2022-20348.4893, sample captured from a live trace, binary version 10.0.20348.1, captured 2026-06-02
- WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.1, captured 2026-06-02
- Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.1, captured 2026-06-02