Microsoft-Windows-SruMon

12 events across 1 channel

Event ID 2001: _DebugString.

#
Provider
Microsoft-Windows-SruMon
Channel
Diagnostic
Task
SruMonDebugTrace

Description

_DebugString

Message #

%1

Fields #

NameDescription
_DebugString UnicodeString

Event ID 2002: _FunctionName Failed with _Status.

#
Provider
Microsoft-Windows-SruMon
Channel
Diagnostic
Task
SruMonDebugTrace

Description

_FunctionName Failed with _Status.

Message #

%1 Failed with %2

Fields #

NameDescription
_FunctionName UnicodeString
_Status UInt32

Event ID 2003: _FunctionName Failed with _HR.

#
Provider
Microsoft-Windows-SruMon
Channel
Diagnostic
Task
SruMonDebugTrace

Description

_FunctionName Failed with _HR.

Message #

%1 Failed with %2

Fields #

NameDescription
_FunctionName UnicodeString
_HR Int32

Event ID 2004: Accessing database table _TableName.

#
Provider
Microsoft-Windows-SruMon
Channel
Diagnostic
Task
SruMonDebugTrace

Description

Accessing database table _TableName.

Message #

Accessing database table %1

Fields #

NameDescription
_TableName UnicodeString

Event ID 2005: _FunctionName Failed with _HR.

#
Provider
Microsoft-Windows-SruMon
Channel
Diagnostic
Task
SruMonDebugTrace

Description

_FunctionName Failed with _HR.

Message #

%1 Failed with %2

Fields #

NameDescription
_FunctionName UnicodeString
_HR Int32

Event ID 2006: Called at _FunctionName.

#
Provider
Microsoft-Windows-SruMon
Channel
Diagnostic
Task
SruMonDebugSequenceTrace

Description

Called at _FunctionName.

Message #

Called at %1

Fields #

NameDescription
_FunctionName UnicodeString

Event ID 2007: Called at _FunctionName.

#
Provider
Microsoft-Windows-SruMon
Channel
Diagnostic
Task
SruMonDebugSequenceTrace

Description

Called at _FunctionName.

Message #

Called at %1

Fields #

NameDescription
_FunctionName UnicodeString

Event ID 2008: _Status.

#
Provider
Microsoft-Windows-SruMon
Channel
Diagnostic
Task
SruMonDebugSequenceTrace

Description

_Status

Message #

%1

Fields #

NameDescription
_Status UnicodeString

Event ID 2009: _Reset.

#
Provider
Microsoft-Windows-SruMon
Channel
Diagnostic
Task
SruMonDebugSequenceErrorTrace

Description

_Reset

Message #

%1

Fields #

NameDescription
_Reset UnicodeString

Event ID 2010: Called at _FunctionName for Application _ApplicationName over InterfaceLuid _InterfaceLuid whose cost is _Costed with _BytesSent bytes sent and _BytesReceived bytes received.

#
Provider
Microsoft-Windows-SruMon
Channel
Diagnostic
Task
SruMonNWAggregationTrace

Description

Called at _FunctionName for Application _ApplicationName over InterfaceLuid _InterfaceLuid whose cost is _Costed with _BytesSent bytes sent and _BytesReceived bytes received.

Message #

Called at %1 for Application %2 over InterfaceLuid %3 whose cost is %4 with %5 bytes sent and %6 bytes received

Fields #

NameDescription
_FunctionName UnicodeString
_ApplicationName UnicodeString
_InterfaceLuid UInt64
_Costed Boolean
_BytesSent UInt64
_BytesReceived UInt64

Event ID 2011: Called at _FunctionName.

#
Provider
Microsoft-Windows-SruMon
Channel
Diagnostic
Task
SruMonNWAggregationTrace

Description

Called at _FunctionName.

Message #

Called at %1

Fields #

NameDescription
_FunctionName UnicodeString

Event ID 2012: InterfaceGUID _InterfaceGuid, InterfaceLuid _InterfaceLuid, App _Application, ProfileId _ProfileId, ProfileFlags _ProfileFlags, BytesSent _BytesSent, BytesReceived _BytesReceived.

#
Provider
Microsoft-Windows-SruMon
Channel
Diagnostic
Task
SruMonNWAggregationTrace

Description

InterfaceGUID _InterfaceGuid, InterfaceLuid _InterfaceLuid, App _Application, ProfileId _ProfileId, ProfileFlags _ProfileFlags, BytesSent _BytesSent, BytesReceived _BytesReceived.

Message #

InterfaceGUID %1, InterfaceLuid %2, App %3, ProfileId %4, ProfileFlags %5, BytesSent %6, BytesReceived %7

Fields #

NameDescription
_InterfaceGuid GUID
_InterfaceLuid UInt64
_Application UnicodeString
_ProfileId UInt64
_ProfileFlags UInt64
_BytesSent UInt64
_BytesReceived UInt64

Provenance

Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.

ETW provider GUID c8dbf506-e3d3-4822-930d-84c557eb6247

Defined in srumapi.dll, which carries the event manifest.

Observed on:

  • WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.1, captured 2026-06-02
  • Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.1, captured 2026-06-02

Downloads