Microsoft-Windows-Websocket-Protocol-Component
| Event | Title | Channel | Sample | Rule |
|---|---|---|---|---|
| 1 | TraceMessage. | Tracing | N | N |
| 2 | Operation of 'OperationType' type queued with ID 'Id'. | Tracing | N | N |
| 3 | Operation 'Id' is executing action 'ActionType'. | Tracing | N | N |
| 4 | Operation 'Id' finished. | Tracing | N | N |
Event ID 2: Operation of 'OperationType' type queued with ID 'Id'.
#Message #
Fields #
| Name | Description |
|---|---|
Id UInt32 | |
OperationType UInt32 | Known values
|
Event ID 3: Operation 'Id' is executing action 'ActionType'.
#Provenance
ETW provider GUID cba5f63c-e2cf-4b36-8305-bde1311924fc
Defined in websocket.dll, which carries the event manifest.
- WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.1, captured 2026-06-02 — Manifest XML pack, 1.9 MB
- Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.1, captured 2026-06-02 — Manifest XML pack, 2.0 MB