Microsoft-Windows-Watchdog-Events

11 events across 1 channel

EventTitleChannelSample
100LogAssertWdLogN
101LogErrorWdLogN
102LogWarningWdLogN
103LogEventWdLogY
104LogTraceWdLogN
105LogLowResourceWdLogN
106LogDmmEventWdLogN
107LogPresentTokenEventWdLogY
108LogPowerWdLogN
109LogDebugWdLogN
110LogUnknownWdLogN

Event ID 100: LogAssert

#
Provider
Microsoft-Windows-Watchdog-Events
Channel
WdLog
Task
LogAssert

Fields #

NameDescription
ReturnAddress Pointer
LogEntry UInt32
Level UInt32
Param1 UInt64
Param2 UInt64
Param3 UInt64
Param4 UInt64
Param5 UInt64

Event ID 101: LogError

#
Provider
Microsoft-Windows-Watchdog-Events
Channel
WdLog
Task
LogError

Fields #

NameDescription
ReturnAddress Pointer
LogEntry UInt32
Level UInt32
Param1 UInt64
Param2 UInt64
Param3 UInt64
Param4 UInt64
Param5 UInt64

Event ID 102: LogWarning

#
Provider
Microsoft-Windows-Watchdog-Events
Channel
WdLog
Task
LogWarning

Fields #

NameDescription
ReturnAddress Pointer
LogEntry UInt32
Level UInt32
Param1 UInt64
Param2 UInt64
Param3 UInt64
Param4 UInt64
Param5 UInt64

Event ID 103: LogEvent

#
Provider
Microsoft-Windows-Watchdog-Events
Channel
WdLog
Also via
realtime ETW trace
Task
LogEvent
Opcode
win:Info

Fields #

NameDescription
ReturnAddress Pointer
LogEntry UInt32
Level UInt32
Param1 UInt64
Param2 UInt64
Param3 UInt64
Param4 UInt64
Param5 UInt64

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Watchdog-Events",
    "guid": "{70E74DD8-39DB-5F6F-6FD1-F5581B29E834}",
    "event_source_name": "",
    "event_id": 103,
    "version": 0,
    "level": 0,
    "task": 4,
    "opcode": 0,
    "keywords": "0x0000000000000008",
    "time_created": "2026-06-02T06:06:08.408+00:00",
    "event_record_id": 0,
    "correlation": {},
    "execution": {
      "process_id": 4,
      "thread_id": 728
    },
    "channel": "ETW Trace",
    "computer": "DESKTOP-FF3N5XK",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Level": 4,
    "LogEntry": 11785281,
    "Param1": 18446670449002553360,
    "Param2": 270376,
    "Param3": 270374,
    "Param4": 0,
    "Param5": 0,
    "Return Address": "0xFFFFF80068C0EB25"
  },
  "message": "LogEvent"
}

Event ID 104: LogTrace

#
Provider
Microsoft-Windows-Watchdog-Events
Channel
WdLog
Task
LogTrace

Fields #

NameDescription
ReturnAddress Pointer
LogEntry UInt32
Level UInt32
Param1 UInt64
Param2 UInt64
Param3 UInt64
Param4 UInt64
Param5 UInt64

Event ID 105: LogLowResource

#
Provider
Microsoft-Windows-Watchdog-Events
Channel
WdLog
Task
LogLowResource

Fields #

NameDescription
ReturnAddress Pointer
LogEntry UInt32
Level UInt32
Param1 UInt64
Param2 UInt64
Param3 UInt64
Param4 UInt64
Param5 UInt64

Event ID 106: LogDmmEvent

#
Provider
Microsoft-Windows-Watchdog-Events
Channel
WdLog
Task
LogDmmEvent

Fields #

NameDescription
ReturnAddress Pointer
LogEntry UInt32
Level UInt32
Param1 UInt64
Param2 UInt64
Param3 UInt64
Param4 UInt64
Param5 UInt64

Event ID 107: LogPresentTokenEvent

#
Provider
Microsoft-Windows-Watchdog-Events
Channel
WdLog
Also via
realtime ETW trace
Task
LogPresentTokenEvent
Opcode
win:Info

Fields #

NameDescription
ReturnAddress Pointer
LogEntry UInt32
Level UInt32
Param1 UInt64
Param2 UInt64
Param3 UInt64
Param4 UInt64
Param5 UInt64

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Watchdog-Events",
    "guid": "{70E74DD8-39DB-5F6F-6FD1-F5581B29E834}",
    "event_source_name": "",
    "event_id": 107,
    "version": 0,
    "level": 0,
    "task": 7,
    "opcode": 0,
    "keywords": "0x0000000000000080",
    "time_created": "2026-06-02T06:06:08.408+00:00",
    "event_record_id": 0,
    "correlation": {},
    "execution": {
      "process_id": 4,
      "thread_id": 728
    },
    "channel": "ETW Trace",
    "computer": "DESKTOP-FF3N5XK",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Level": 8,
    "LogEntry": 11785285,
    "Param1": 18446630888022925664,
    "Param2": 54086,
    "Param3": 5722749,
    "Param4": 1,
    "Param5": 0,
    "Return Address": "0xFFFFF80068C1434C"
  },
  "message": "LogPresentTokenEvent"
}

Event ID 108: LogPower

#
Provider
Microsoft-Windows-Watchdog-Events
Channel
WdLog
Task
LogPower

Fields #

NameDescription
ReturnAddress Pointer
LogEntry UInt32
Level UInt32
Param1 UInt64
Param2 UInt64
Param3 UInt64
Param4 UInt64
Param5 UInt64

Event ID 109: LogDebug

#
Provider
Microsoft-Windows-Watchdog-Events
Channel
WdLog
Task
LogDebug

Fields #

NameDescription
ReturnAddress Pointer
LogEntry UInt32
Level UInt32
Param1 UInt64
Param2 UInt64
Param3 UInt64
Param4 UInt64
Param5 UInt64

Event ID 110: LogUnknown

#
Provider
Microsoft-Windows-Watchdog-Events
Channel
WdLog
Task
LogUnknown

Fields #

NameDescription
ReturnAddress Pointer
LogEntry UInt32
Level UInt32
Param1 UInt64
Param2 UInt64
Param3 UInt64
Param4 UInt64
Param5 UInt64

Provenance

Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.

ETW provider GUID {70E74DD8-39DB-5F6F-6FD1-F5581B29E834}

Defined in watchdog.sys, the binary that emits these events.

Observed on:

  • Win11-26200.6584, sample captured from a live trace, binary version 10.0.26100.5074, captured 2026-06-02
  • Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.5074, captured 2026-06-02

Downloads