Microsoft-Windows-HttpLog

1 events across 1 channel

EventTitleChannelSample
1HTTP transaction logLogN

Event ID 1: HTTP transaction log

#
Provider
Microsoft-Windows-HttpLog
Channel
Log

Description

HTTP transaction log.

Message #

HTTP transaction log

Fields #

NameDescription
ServerSessionId UInt64
UrlGroupId UInt64
UrlContext UInt64
DateTime FILETIME
RemoteAddrLength UInt32
RemoteAddr Binary
LocalAddrLength UInt32
LocalAddr Binary
KernelCached UInt32
HttpMajorVer UInt16
HttpMinorVer UInt16
BytesSent UInt64
BytesReceived UInt64
TimeTaken UInt64
UserName UnicodeString
Method AnsiString
UriStem UnicodeString
UriQuery AnsiString
ProtocolStatus UInt16
ProtocolSubStatus UInt16
Win32Status UInt32
Host AnsiString
UserAgent AnsiString
Referer AnsiString
AppContext AnsiString

Provenance

Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.

ETW provider GUID c42a2738-2333-40a5-a32f-6acc36449dcc

Defined in HTTP.SYS, the binary that emits these events.

Observed on:

  • WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.3451, captured 2026-06-02
  • Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.4202, captured 2026-06-02

Downloads