Microsoft-Windows-SruMon
12 events across 1 channel
| Event | Title | Channel | Sample |
|---|---|---|---|
| 2001 | _DebugString. | Diagnostic | N |
| 2002 | _FunctionName Failed with _Status. | Diagnostic | N |
| 2003 | _FunctionName Failed with _HR. | Diagnostic | N |
| 2004 | Accessing database table _TableName. | Diagnostic | N |
| 2005 | _FunctionName Failed with _HR. | Diagnostic | N |
| 2006 | Called at _FunctionName. | Diagnostic | N |
| 2007 | Called at _FunctionName. | Diagnostic | N |
| 2008 | _Status. | Diagnostic | N |
| 2009 | _Reset. | Diagnostic | N |
| 2010 | Called at _FunctionName for Application _ApplicationName over InterfaceLuid … | Diagnostic | N |
| 2011 | Called at _FunctionName. | Diagnostic | N |
| 2012 | InterfaceGUID _InterfaceGuid, InterfaceLuid _InterfaceLuid, App _Application, … | Diagnostic | N |
Event ID 2001: _DebugString.
#Event ID 2002: _FunctionName Failed with _Status.
#Event ID 2003: _FunctionName Failed with _HR.
#Event ID 2004: Accessing database table _TableName.
#Event ID 2005: _FunctionName Failed with _HR.
#Event ID 2006: Called at _FunctionName.
#Event ID 2007: Called at _FunctionName.
#Event ID 2010: Called at _FunctionName for Application _ApplicationName over InterfaceLuid _InterfaceLuid whose cost is _Costed with _BytesSent bytes sent and _BytesReceived bytes received.
#Description
Called at _FunctionName for Application _ApplicationName over InterfaceLuid _InterfaceLuid whose cost is _Costed with _BytesSent bytes sent and _BytesReceived bytes received.
Message #
Fields #
| Name | Description |
|---|---|
_FunctionName UnicodeString | |
_ApplicationName UnicodeString | |
_InterfaceLuid UInt64 | |
_Costed Boolean | |
_BytesSent UInt64 | |
_BytesReceived UInt64 |
Event ID 2011: Called at _FunctionName.
#Event ID 2012: InterfaceGUID _InterfaceGuid, InterfaceLuid _InterfaceLuid, App _Application, ProfileId _ProfileId, ProfileFlags _ProfileFlags, BytesSent _BytesSent, BytesReceived _BytesReceived.
#Description
InterfaceGUID _InterfaceGuid, InterfaceLuid _InterfaceLuid, App _Application, ProfileId _ProfileId, ProfileFlags _ProfileFlags, BytesSent _BytesSent, BytesReceived _BytesReceived.
Message #
Fields #
| Name | Description |
|---|---|
_InterfaceGuid GUID | |
_InterfaceLuid UInt64 | |
_Application UnicodeString | |
_ProfileId UInt64 | |
_ProfileFlags UInt64 | |
_BytesSent UInt64 | |
_BytesReceived UInt64 |
Provenance
Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.
ETW provider GUID c8dbf506-e3d3-4822-930d-84c557eb6247
Defined in srumapi.dll, which carries the event manifest.
Observed on:
- WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.1, captured 2026-06-02
- Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.1, captured 2026-06-02