Microsoft-Windows-HttpLog
1 events across 1 channel
| Event | Title | Channel | Sample |
|---|---|---|---|
| 1 | HTTP transaction log | Log | N |
Event ID 1: HTTP transaction log
#Description
HTTP transaction log.
Message #
Fields #
| Name | Description |
|---|---|
ServerSessionId UInt64 | |
UrlGroupId UInt64 | |
UrlContext UInt64 | |
DateTime FILETIME | |
RemoteAddrLength UInt32 | |
RemoteAddr Binary | |
LocalAddrLength UInt32 | |
LocalAddr Binary | |
KernelCached UInt32 | |
HttpMajorVer UInt16 | |
HttpMinorVer UInt16 | |
BytesSent UInt64 | |
BytesReceived UInt64 | |
TimeTaken UInt64 | |
UserName UnicodeString | |
Method AnsiString | |
UriStem UnicodeString | |
UriQuery AnsiString | |
ProtocolStatus UInt16 | |
ProtocolSubStatus UInt16 | |
Win32Status UInt32 | |
Host AnsiString | |
UserAgent AnsiString | |
Cookie AnsiString | |
Referer AnsiString | |
AppContext AnsiString |
Provenance
Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.
ETW provider GUID c42a2738-2333-40a5-a32f-6acc36449dcc
Defined in HTTP.SYS, the binary that emits these events.
Observed on:
- WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.3451, captured 2026-06-02
- Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.4202, captured 2026-06-02