Microsoft-Windows-SruMon
| Event | Title | Channel | Sample | Rule |
|---|---|---|---|---|
| 2001 | _DebugString. | Diagnostic | Y | N |
| 2002 | _FunctionName Failed with _Status. | Diagnostic | Y | N |
| 2003 | _FunctionName Failed with _HR. | Diagnostic | N | N |
| 2004 | Accessing database table _TableName. | Diagnostic | N | N |
| 2005 | _FunctionName Failed with _HR. | Diagnostic | Y | N |
| 2006 | Called at _FunctionName. | Diagnostic | N | N |
| 2007 | Called at _FunctionName. | Diagnostic | Y | N |
| 2008 | _Status. | Diagnostic | N | N |
| 2009 | _Reset. | Diagnostic | Y | N |
| 2010 | Called at _FunctionName for Application _ApplicationName over InterfaceLuid … | Diagnostic | N | N |
| 2011 | Called at _FunctionName. | Diagnostic | N | N |
| 2012 | InterfaceGUID _InterfaceGuid, InterfaceLuid _InterfaceLuid, App _Application, … | Diagnostic | N | N |
Event ID 2001: _DebugString.
#Message #
Fields #
| Name | Description |
|---|---|
_DebugString UnicodeString |
Example Event #
{
"system": {
"channel": "Microsoft-Windows-SruMon/Diagnostic",
"computer": "10.2.10.21",
"correlation": {},
"event_id": 2001,
"event_record_id": 0,
"event_source_name": "",
"execution": {
"process_id": 3184,
"thread_id": 4988
},
"guid": "",
"keywords": 0,
"level": 4,
"opcode": 0,
"provider": "Microsoft-Windows-SruMon",
"security": {
"user_id": ""
},
"task": 0,
"time_created": "2026-07-22 00:42:00.003Z",
"version": 0
},
"event_data": {
"_DebugString": "==> SruStatsStoreUpdateAll"
},
"message": ""
}
Event ID 2002: _FunctionName Failed with _Status.
#Message #
Fields #
| Name | Description |
|---|---|
_FunctionName UnicodeString | |
_Status UInt32 |
Example Event #
{
"system": {
"channel": "Microsoft-Windows-SruMon/Diagnostic",
"computer": "10.2.10.21",
"correlation": {},
"event_id": 2002,
"event_record_id": 0,
"event_source_name": "",
"execution": {
"process_id": 3184,
"thread_id": 2312
},
"guid": "",
"keywords": 0,
"level": 4,
"opcode": 0,
"provider": "Microsoft-Windows-SruMon",
"security": {
"user_id": ""
},
"task": 0,
"time_created": "2026-07-22 00:42:00.004Z",
"version": 0
},
"event_data": {
"_FunctionName": "SruTier1StoreRolloverEntries(Tier2)",
"_Status": 21
},
"message": ""
}
Event ID 2003: _FunctionName Failed with _HR.
#Event ID 2004: Accessing database table _TableName.
#Event ID 2005: _FunctionName Failed with _HR.
#Message #
Fields #
| Name | Description |
|---|---|
_FunctionName UnicodeString | |
_HR Int32 |
Example Event #
{
"system": {
"channel": "Microsoft-Windows-SruMon/Diagnostic",
"computer": "10.2.10.21",
"correlation": {},
"event_id": 2005,
"event_record_id": 0,
"event_source_name": "",
"execution": {
"process_id": 3184,
"thread_id": 5276
},
"guid": "",
"keywords": 0,
"level": 4,
"opcode": 0,
"provider": "Microsoft-Windows-SruMon",
"security": {
"user_id": ""
},
"task": 0,
"time_created": "2026-07-22 00:42:00.055Z",
"version": 0
},
"event_data": {
"_FunctionName": "JetInit",
"_HR": -501
},
"message": ""
}
Event ID 2007: Called at _FunctionName.
#Message #
Fields #
| Name | Description |
|---|---|
_FunctionName UnicodeString |
Example Event #
{
"system": {
"channel": "Microsoft-Windows-SruMon/Diagnostic",
"computer": "10.2.10.21",
"correlation": {},
"event_id": 2007,
"event_record_id": 0,
"event_source_name": "",
"execution": {
"process_id": 3184,
"thread_id": 5368
},
"guid": "",
"keywords": 0,
"level": 4,
"opcode": 0,
"provider": "Microsoft-Windows-SruMon",
"security": {
"user_id": ""
},
"task": 0,
"time_created": "2026-07-22 00:42:00.003Z",
"version": 0
},
"event_data": {
"_FunctionName": "UpdateStore"
},
"message": ""
}
Event ID 2009: _Reset.
#Message #
Fields #
| Name | Description |
|---|---|
_Reset UnicodeString |
Example Event #
{
"system": {
"channel": "Microsoft-Windows-SruMon/Diagnostic",
"computer": "10.2.10.21",
"correlation": {},
"event_id": 2009,
"event_record_id": 0,
"event_source_name": "",
"execution": {
"process_id": 3184,
"thread_id": 5276
},
"guid": "",
"keywords": 0,
"level": 4,
"opcode": 0,
"provider": "Microsoft-Windows-SruMon",
"security": {
"user_id": ""
},
"task": 0,
"time_created": "2026-07-22 00:42:00.063Z",
"version": 0
},
"event_data": {
"_Reset": "SruDbHandleDbOpenError"
},
"message": ""
}
Event ID 2010: Called at _FunctionName for Application _ApplicationName over InterfaceLuid _InterfaceLuid whose cost is _Costed with _BytesSent bytes sent and _BytesReceived bytes received.
#Event ID 2012: InterfaceGUID _InterfaceGuid, InterfaceLuid _InterfaceLuid, App _Application, ProfileId _ProfileId, ProfileFlags _ProfileFlags, BytesSent _BytesSent, BytesReceived _BytesReceived.
#Provenance
ETW provider GUID c8dbf506-e3d3-4822-930d-84c557eb6247
Defined in srumapi.dll, which carries the event manifest.
- WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.1, captured 2026-06-02 — Manifest XML pack, 1.9 MB
- Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.1, captured 2026-06-02 — Manifest XML pack, 2.0 MB