Microsoft-Windows-PCI
5 events across 2 channels
| Event | Title | Channel | Sample |
|---|---|---|---|
| 1 | Message. | Operational | Y |
| 2 | Message. | Operational | N |
| 3 | Message. | Operational | N |
| 10 | AspmErrataRundown | Diagnostic | N |
| 10 | AspmErrataRundown | Operational | N |
Event ID 1: Message.
#Description
Message
Message #
Fields #
| Name | Description |
|---|---|
Category HexInt64 | |
Rid HexInt32 | |
Secondary UInt8 | |
PreciseTime UInt64 | |
Qpc UInt64 | |
Message UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-PCI",
"event_id": 1,
"level": 4,
"task": 1,
"opcode": 0,
"time_created": "2026-04-18T03:03:26.4685233+00:00",
"computer": "DESKTOP-FF3N5XK.ludus.domain",
"channel": "Microsoft-Windows-PCI"
},
"event_data": {
"Category": "0x22",
"Qpc": "53286791",
"Rid": "0x90",
"PreciseTime": "53061780",
"Secondary": "255",
"Message": "[PDO] (0x0000.0x12.0x00): Finish state transition to STARTED"
}
}
Event ID 2: Message.
#Event ID 3: Message.
#Event ID 10: AspmErrataRundown
#Event ID 10: AspmErrataRundown
#Provenance
Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.
ETW provider GUID 1a9443d4-b099-44d6-8eb1-829b9c2fe290
Defined in Microsoft-Windows-System-Events.dll, which carries the event manifest.
Observed on:
- WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.3932, captured 2026-06-02
- Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.5074, captured 2026-06-02