Microsoft-Windows-HttpLog

EventTitleChannelSampleRule
1HTTP transaction logLogNN

Event ID 1: HTTP transaction log

#
Channel
Log

Fields #

NameDescription
ServerSessionId UInt64
UrlGroupId UInt64
UrlContext UInt64
DateTime FILETIME
RemoteAddrLength UInt32
RemoteAddr Binary
LocalAddrLength UInt32
LocalAddr Binary
KernelCached UInt32
HttpMajorVer UInt16
HttpMinorVer UInt16
BytesSent UInt64
BytesReceived UInt64
TimeTaken UInt64
UserName UnicodeString
Method AnsiString
UriStem UnicodeString
UriQuery AnsiString
ProtocolStatus UInt16
ProtocolSubStatus UInt16
Win32Status UInt32
Host AnsiString
UserAgent AnsiString
Cookie AnsiString
Referer AnsiString
AppContext AnsiString

Provenance

ETW provider GUID c42a2738-2333-40a5-a32f-6acc36449dcc

Defined in HTTP.SYS, the binary that emits these events.

  • WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.3451, captured 2026-06-02 — Manifest XML pack, 1.9 MB
  • Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.4202, captured 2026-06-02 — Manifest XML pack, 2.0 MB