Microsoft-Windows-FunctionDiscovery
58 events across 1 channel
Event ID 1000: Begin IFunctionDiscovery::GetInstanceCollection().
#Event ID 1001: End IFunctionDiscovery::GetInstanceCollection().
#Event ID 1002: Begin IFunctionDiscovery::GetInstance().
#Event ID 1003: End IFunctionDiscovery::GetInstance().
#Event ID 1004: Begin IFunctionDiscovery::CreateInstanceCollectionQuery().
#Event ID 1005: End IFunctionDiscovery::CreateInstanceCollectionQuery().
#Event ID 1006: Begin IFunctionDiscovery::CreateInstanceQuery().
#Event ID 1007: End IFunctionDiscovery::CreateInstanceQuery().
#Event ID 1008: Begin IFunctionDiscovery::AddInstance().
#Event ID 1009: End IFunctionDiscovery::AddInstance().
#Event ID 1010: Begin IFunctionDiscovery::RemoveInstance().
#Event ID 1011: End IFunctionDiscovery::RemoveInstance().
#Event ID 1012: Begin IFunctionInstanceCollectionQuery::Execute().
#Event ID 1013: End IFunctionInstanceCollectionQuery::Execute().
#Event ID 1014: Begin IFunctionInstanceCollectionQuery2::Advise().
#Event ID 1015: End IFunctionInstanceCollectionQuery2::Advise().
#Event ID 1016: Begin IFunctionInstanceCollectionQuery2::Unadvise().
#Event ID 1017: End IFunctionInstanceCollectionQuery2::Unadvise().
#Event ID 1018: Begin IFunctionInstanceCollectionQuery2::Start().
#Event ID 1019: End IFunctionInstanceCollectionQuery2::Start().
#Event ID 1020: Begin IFunctionInstanceCollectionQuery2::Stop().
#Event ID 1021: End IFunctionInstanceCollectionQuery2::Stop().
#Event ID 1022: Begin IFunctionInstanceCollectionQuery2::QueryService().
#Event ID 1023: End IFunctionInstanceCollectionQuery2::QueryService().
#Event ID 1024: Begin IFunctionInstanceQuery::Execute().
#Event ID 1025: End IFunctionInstanceQuery::Execute().
#Event ID 1026: Begin IFunctionDiscoveryProvider::Initialize().
#Event ID 1027: End IFunctionDiscoveryProvider::Initialize().
#Event ID 1028: Begin IFunctionDiscoveryProvider::Query().
#Event ID 1029: End IFunctionDiscoveryProvider::Query().
#Event ID 1030: Begin IFunctionDiscoveryProvider::EndQuery().
#Event ID 1031: End IFunctionDiscoveryProvider::EndQuery().
#Event ID 1032: Begin IFunctionDiscoveryProvider::InstancePropertyStoreValidateAccess().
#Event ID 1033: End IFunctionDiscoveryProvider::InstancePropertyStoreValidateAccess().
#Event ID 1034: Begin IFunctionDiscoveryProvider::InstancePropertyStoreOpen().
#Event ID 1035: End IFunctionDiscoveryProvider::InstancePropertyStoreOpen().
#Event ID 1036: Begin IFunctionDiscoveryProvider::InstancePropertyStoreFlush().
#Event ID 1037: End IFunctionDiscoveryProvider::InstancePropertyStoreFlush().
#Event ID 1038: Begin IFunctionDiscoveryProvider::InstanceQueryService().
#Event ID 1039: End IFunctionDiscoveryProvider::InstanceQueryService().
#Event ID 1040: Begin IFunctionDiscoveryProvider::InstanceReleased().
#Event ID 1041: End IFunctionDiscoveryProvider::InstanceReleased().
#Event ID 1042: Begin IProviderPublishing::CreateInstance().
#Event ID 1043: End IProviderPublishing::CreateInstance().
#Event ID 1044: Begin IProviderPublishing::RemoveInstance().
#Event ID 1045: End IProviderPublishing::RemoveInstance().
#Event ID 1046: Begin Provider IServiceProvider::QueryService().
#Event ID 1047: End Provider IServiceProvider::QueryService().
#Event ID 1048: Begin Provider IProviderProperties::GetCount().
#Event ID 1049: End Provider IProviderProperties::GetCount().
#Event ID 1050: Begin Provider IProviderProperties::GetAt().
#Event ID 1051: End Provider IProviderProperties::GetAt().
#Event ID 1052: Begin Provider IProviderProperties::GetValue().
#Event ID 1053: End Provider IProviderProperties::GetValue().
#Event ID 1054: Begin Provider IProviderProperties::SetValue().
#Event ID 1055: End Provider IProviderProperties::SetValue().
#Event ID 1056: Begin asyncronous query.
#Event ID 1057: Asynchronous query complete.
#Provenance
Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.
ETW provider GUID 9db0fdb5-3b21-440e-a94b-63738a4be5de
Defined in fundisc.dll, which carries the event manifest.
Observed on:
- WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.1, captured 2026-06-02
- Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.1, captured 2026-06-02