Microsoft-Windows-ServiceTriggerPerfEventProvider
5 events across 1 channel
| Event | Title | Channel | Sample |
|---|---|---|---|
| 1 | task_0 | Operational | Y |
| 2 | task_02 | Operational | Y |
| 3 | task_03 | Operational | N |
| 4 | task_04 | Operational | N |
| 5 | task_05 | Operational | N |
Event ID 1: task_0
#Fields #
| Name | Description |
|---|---|
TriggerSubType UnicodeString | |
TriggerData UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-ServiceTriggerPerfEventProvider",
"guid": "{6545939F-3398-411A-88B7-6A8914B8CEC7}",
"event_source_name": "",
"event_id": 1,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": "0x0000000000000000",
"time_created": "2026-06-02T04:01:27.357+00:00",
"event_record_id": 0,
"correlation": {},
"execution": {
"process_id": 1028,
"thread_id": 6340
},
"channel": "ETW Trace",
"computer": "DESKTOP-FF3N5XK",
"security": {
"user_id": ""
}
},
"event_data": {
"TriggerData": "2eb08e3e-639f-4fba-97b1-14f878961076",
"TriggerSubType": "bc90d167-9470-4139-a9ba-be0bbbf5b74d"
},
"message": ""
}
Event ID 2: task_02
#Fields #
| Name | Description |
|---|---|
TriggerSubType UnicodeString | An attempt to retrieve firewall filter with key |
TriggerData UnicodeString | has failed with error |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-ServiceTriggerPerfEventProvider",
"guid": "{6545939F-3398-411A-88B7-6A8914B8CEC7}",
"event_source_name": "",
"event_id": 2,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": "0x0000000000000000",
"time_created": "2026-06-02T04:01:27.424+00:00",
"event_record_id": 0,
"correlation": {},
"execution": {
"process_id": 1028,
"thread_id": 6340
},
"channel": "ETW Trace",
"computer": "DESKTOP-FF3N5XK",
"security": {
"user_id": ""
}
},
"event_data": {
"TriggerData": "c9ac6db5-82b7-4e55-ae8a-e464ed7b4277",
"TriggerSubType": "bc90d167-9470-4139-a9ba-be0bbbf5b74d"
},
"message": ""
}
Event ID 3: task_03
#Fields #
| Name | Description |
|---|---|
TriggerSubType UnicodeString | DetectionLocation |
TriggerData UnicodeString | Status |
Event ID 4: task_04
#Fields #
| Name | Description |
|---|---|
TriggerSubType UnicodeString | An attempt to delete firewall filter with key |
TriggerData UnicodeString | has failed with error |
Provenance
Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.
ETW provider GUID {6545939F-3398-411A-88B7-6A8914B8CEC7}
Defined in RpcEpMap.dll, which carries the event manifest.
Observed on:
- Win11-26200.6584, sample captured from a live trace, binary version 10.0.26100.1, captured 2026-06-02
- WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.1, captured 2026-06-02
- Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.1, captured 2026-06-02