Microsoft-Windows-Heap-Snapshot

EventTitleChannelSampleRule
100task_0_V1OperationalNN
200task_0200_V1OperationalNN

Event ID 100: task_0_V1

#
Channel
Operational

Fields #

NameDescription
HeapSnapshotInstance UInt32
HeapSnapshotSequence UInt32
HeapSnapshotBufferLen UInt32
HeapSnapshotBuffer Binary

Event ID 200: task_0200_V1

#
Channel
Operational

Fields #

NameDescription
HeapSnapshotInstance UInt32
TotalData UInt32

Provenance

ETW provider GUID 901d2afa-4ff6-46d7-8d0e-53645e1a47f5

Defined in Microsoft-Windows-System-Events.dll, which carries the event manifest.

  • WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.3932, captured 2026-06-02 — Manifest XML pack, 1.9 MB
  • Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.5074, captured 2026-06-02 — Manifest XML pack, 2.0 MB