Microsoft-Windows-Win32k

358 events across 8 channels

EventTitleChannelSample
1WindowUpdateTracingN
2FocusChangeTracingN
3UIPIMsgErrorUIPIN
4UIPIHookErrorUIPIN
5UIPIEventHookErrorUIPIN
6UIPIHandleValErrorUIPIN
7UIPIInputErrorUIPIN
8UIPIClipboardErrorUIPIN
9UIPISystemErrorUIPIN
10PowerDisplayChangePowerN
11IdleActionExpirationPowerN
12DisplayReqChangePowerN
13DisplayTimeoutResetPowerN
14LockAcquireExclusiveConcurrencyN
15LockAcquireSharedConcurrencyN
16LockAcquireSharedStarveExclusiveConcurrencyN
17LockReleaseConcurrencyN
18SwapChainBindTracingN
19SwapChainUnBindTracingN
20IdleStatusTracingPowerY
21SwapChainSetStatsTracingN
22ScreenSaverProcessPowerN
23WinlogonSleepStartPowerN
24WinlogonSleepEndPowerN
25UserActiveTracingN
26FocusedProcessChangeTracingN
27DwmSpriteCreateTracingN
28DwmSpriteDestroyTracingN
29LogicalSurfCreateTracingN
30LogicalSurfDestroyTracingN
31LogicalSurfPhysSurfBindTracingN
32LogicalSurfPhysSurfUnbindTracingN
33GdiSysMemTokenTracingN
35WaitCursorTracingN
36ThreadInfoRundownTracingN
37InputProcessDelayTracingN
38MessageCheckDelayTracingN
39RenderingNewRenderingRenderN
40RenderingOldToNewRenderingRenderN
41RenderingRenderY
42RenderingAppRenderingTightUpdateRenderN
43RenderingValidateWindowRenderN
44RenderingInvalidateWindowRenderN
45ThreadExitTracingY
46BindLogicalSurfaceTracingN
47UnBindLogicalSurfaceTracingN
48BindLogicalSurfaceRHTracingN
49DwmSpriteLogicalSurfBindTracingN
50DwmSpriteLogicalSurfUnBindTracingN
51LogicalSurfEnableDirtyNotificationTracingN
52PhysicalSurfCreateTracingY
53ModifyRgnTracingY
54SwapChainGetStatsTracingN
55SwapChainBindingOpenTracingN
56SwapChainBindingReleaseTracingN
57SwapChainBindingStatusTracingN
58DesktopResolutionFailureTracingN
59QueuePostMessageMessagesY
60SendMessageStartMessagesN
61RetrievePostMessageMessagesY
62RetrieveSendMessageStartMessagesN
63RetrieveInputMessageMessagesY
64RetrievePseudoMessageMessagesY
65WakePumpMessagesY
66InputQueueLockedMessagesN
67InputQueueLocked67MessagesN
68UserCallbackStartMessagesN
69UserCallbackStopMessagesN
70SendMessageStopMessagesN
71SendMessageTimeOutToBlockingMessagesN
72InputDeviceReadStartMessagesN
73InputDeviceReadStopMessagesN
74MessageInjectionPostGestureInputMessageMessagesN
75MessageInjectionPostGestureMessageMessagesN
76AppMessagePumpMessagesY
77AppMessagePumpMessagesY
78WakeRITMessagesY
79PointerMotionStartMessagesN
80PointerMotionStopMessagesN
81InjectMouseStartMessagesN
82InjectMouseStopMessagesN
83RetrieveSendMessageStopMessagesN
84GUIProcessMessagesY
85GUIProcessMessagesY
86GUIThreadMessagesY
87GUIThreadMessagesY
88QueueInputMessageMessagesY
89TranslateMessageStartMessagesN
91TranslateMessageStopMessagesN
92DispatchMessageMessagesY
93DispatchMessageMessagesY
94TouchTargetingSpeedHitTestStartMessagesN
95TouchTargetingSpeedHitTestStopMessagesN
96TouchTargetingWindowHitTestStartMessagesN
97TouchTargetingWindowHitTestStopMessagesN
98TouchTargetingPointerTargetStartMessagesN
99TouchTargetingPointerTargetStopMessagesN
100MessageInjectionInjectTouchEventMessagesN
102task_0TracingN
103task_0103TracingN
104ContactVisualizationStartTracingN
105ContactVisualizationStopTracingN
106TouchTargetingOffsetMessagesN
107TouchTargetingPointerEventMessagesN
108TouchTargetingPointerEvent108MessagesN
109PointerDeviceReadStartMessagesN
110PointerDeviceReadStopMessagesN
111PointerDeviceMessageStartMessagesN
112PointerDeviceMessageStopMessagesN
113PointerDeviceMessageStart113MessagesN
114PointerDeviceMessageStop114MessagesN
115PointerDeviceTransformationStartMessagesN
116PointerDeviceTransformationStopMessagesN
117RenderingTranslationUpdateRenderN
118TranslationUpdateOffsetRenderN
119RenderingTranslationUpdateRectClipRenderN
120RenderingUpdateDxAccumFromGDIRenderN
121RenderingUpdateDxAccumFromDXRenderN
122RenderingGetDxAccumRenderN
123ModifyDxAccumRgnTracingN
124LogicalSurfRemovedTranslationFromDirtyTracingN
125PointerDeviceDiscoveryStartMessagesN
126PointerDeviceDiscoveryStopMessagesN
127PointerDeviceMessageStart127MessagesN
128PointerDeviceMessageStop128MessagesN
129TouchInjectionEventStartMessagesN
130TouchInjectionEventStopMessagesN
131PointerFrameCreationStartMessagesN
132PointerFrameCreationStopMessagesN
133PointerFrameBuildPartialStartMessagesN
134PointerFrameBuildPartialStopMessagesN
135PointerFrameCommitStartMessagesN
136PointerFrameCommitStopMessagesN
137PointerFrameCoalesceStartMessagesN
138PointerFrameCoalesceStopMessagesN
139PointerFrameMessageGenerationStartMessagesN
140PointerFrameMessageGenerationStopMessagesN
141PointerMessageRetrieveStartMessagesN
142PointerMessageRetrieveStopMessagesN
143PointerUpdateMessageRetrieveStartMessagesN
144PointerUpdateMessageRetrieveStopMessagesN
145PointerSetTargetWindowsStartMessagesN
146PointerSetTargetWindowsStopMessagesN
147PointerUpdateSetTargetWindowsStartMessagesN
148PointerUpdateSetTargetWindowsStopMessagesN
149InputQueueNoRemoveLockerStopMessagesN
150InputQueueLockedPeekRecursionStopMessagesN
151DCompCommitBatchTracingY
152DelegateInputUserCallbackStartMessagesN
153DelegateInputUserCallbackStopMessagesN
154DelegatedInputWorkerStartMessagesN
155DelegatedInputWorkerStopMessagesN
156PointerDeviceMessageMessagesN
157PointerMessageGenerationStartMessagesN
158PointerMessageGenerationStopMessagesN
159PointerFrameCoalesceMessagesN
160SmoothRotationStartTracingN
161SmoothRotationStopTracingN
162DCompGetBatchTracingY
163ExclusiveUserCritContentionN
164ExclusiveUserCritContentionY
165SharedUserCritContentionN
166SharedUserCritContentionY
167ReleaseUserCritContentionY
168SleepInputIdleMessagesY
169WakeInputIdleMessagesY
170EdgyDetectionStartTracingN
171EdgyDetectionStopTracingN
172ImmersiveInputProcessDelayTracingN
173ImmersiveMessageCheckDelayTracingN
174THQAEventStartMessagesN
175THQAEventStopMessagesN
176PointerPredictionStartMessagesN
177PointerPredictionStopMessagesN
178MoveRgnTracingN
179DirtyRgnTracingN
180LogicalSurfRemovedTranslationFromMoveTracingN
181DirtyRectUpdateTracingY
182TranslationUpdateOffsetDWMTracingN
183DwmGetRgnTracingN
184PointerFrameCoalesceStart184MessagesN
185PointerFrameCoalesceStop185MessagesN
186PointerFrameCoalesce186MessagesN
187InternalSetTimerCoalescingTracingY
188InternalSetTimerNoCoalescingTracingN
189KillTimerTracingY
190ProcTimerCoalescingTracingY
191ProcTimerNoCoalescingTracingN
192DrvChangeDisplaySettingsStartTracingN
193DrvChangeDisplaySettingsStopTracingN
194ChangeDisplayModeStartTracingN
195ChangeDisplayModeStopTracingN
196PseudoDevCreationStartMessagesN
197PseudoDevCreationStopMessagesN
198TouchHWTimeStampMessagesN
199PointerFrameCoalesce199MessagesN
200PointerFrameCoalesce200MessagesN
201TokenCompositionSurfaceObject_V1TracingN
202CompositionSurfaceObjectUpdateTracingN
203QueueEventMessageMessagesY
204RetrieveQueueEventMessageMessagesY
205ForegroundWindowFullScreenStartTracingN
206ForegroundWindowFullScreenStopTracingN
207ChangeDisplayModeBroadcastTracingN
213ContactVisualizationTracingN
214ChangeDisplayModeDeferralTracingN
215ConvertibleStateTracingN
216DockStateTracingN
217TouchPadHWTimeStampTracingN
218TransformAgeDecayTracingN
219WakeMITMessagesN
220ArmDitMouseFlushMessagesN
221ProcessQueuedMouseEventsMessagesY
222ProcessQueuedMouseEventsMessagesY
223DITSpeedHitTestFailedRevalidationMessagesN
224InputRedirectionMessagesN
225OnInputXformUpdateMessagesN
226DitWaitForRitDisEngagementMessagesN
227RitDisEngagedMessagesN
228DitEngagedMessagesN
229RitReEngagedMessagesN
230DitDisEngagedMessagesN
231DitTerminatedMessagesN
232DitShutdownMessagesN
233TouchPadAAPTracingN
234MouseInputApcMessagesN
235MouseInputCoalescedMessagesN
236TouchPadTypeDiscoveredTracingN
237TouchPadEnabledStatusChangeStartTracingN
238TouchPadEnabledStatusChangeStopTracingN
239PTPReadThresholdsStartTracingN
240PTPReadThresholdsStopTracingN
241TouchPadConfidenceClearedTracingN
242TouchPadConfidenceUppedTracingN
243PTPElasticDragModeStartTracingN
244PTPElasticDragModeStopTracingN
245LegacyTouchPadDetectionStartTracingN
246LegacyTouchPadDetectionStopTracingN
247LegacyTouchPadDetectionTracingN
248LegacyTouchPadDetection248TracingN
249TouchPadCurtainStateTracingN
250TouchPadCurtainSizeTracingN
251TouchpadStopInertiaTracingN
252TouchpadStopInertia252TracingN
253TouchpadStopInertia253TracingN
254TrappedAppContainerRenderTracingN
255CursorSizeTracingN
256DitMmcssWorkStartMessagesN
257DitMmcssWorkStopMessagesN
258FocusedProcessChangeGainedTracingN
259FocusedProcessChangeLostTracingN
260SourceProcessName attempted loading a font that is restricted by font loading …OperationalN
301TokenStateChanged_V1TracingN
400DCompDeferBatchTracingY
401TouchPadHIDProcessingStartMessagesN
402TouchPadHIDProcessingStopMessagesN
403TouchPadWMPointerProcessingStartMessagesN
404TouchPadWMPointerProcessingStopMessagesN
405TouchPadGestureMessagesN
406CopyPointerInputFrameStartTracingN
407CopyPointerInputFrameStopTracingN
410LatencyModeProcessingStartMessagesN
411LatencyModeProcessingStopMessagesN
412DCompBeginFrameTracingY
413TokenIndependentFlipSkipCompleteTracingN
414DwmManipulationFrameStartTracingN
415DwmManipulationFrameRoutedTracingN
416ExclusiveUserCritTelemetryTracingN
417SharedUserCritTelemetryTracingN
418PowerOnGdiPowerN
419PowerOnGdiPowerN
420UserResetDisplayDevicePowerN
421UserResetDisplayDevicePowerN
422PowerOnMonitorPowerN
423PowerOnMonitorPowerN
424DwmSyncFlushForceRenderAndWaitForBatchPowerN
425DwmSyncFlushForceRenderAndWaitForBatchPowerN
426QueueNullPostMessageMessagesN
427The following win32k syscall is blocked by Win32k Syscall Filter: SyscallName.OperationalN
428The following SystemParametersInfo action was blocked by Win32k Syscall Filter: …OperationalN
429PowerWatchdogPowerN
430PowerWatchdogPowerN
431VideoPortCalloutThreadPowerN
432VideoPortCalloutThreadPowerN
433PowerStateCalloutWorkerPowerN
434PowerStateCalloutWorkerPowerN
435PowerEventCalloutWorkerPowerN
436PowerEventCalloutWorkerPowerN
437InsertPowerN
438RemovePowerN
439CanceledPowerN
440CompletedPowerN
441WaitForVideoPortCalloutReadyPowerN
442WaitForVideoPortCalloutReadyPowerN
443DCompResourceMappingTracingN
444DCompResourcePropertyUpdateTracingN
445DCompCommandTypeTracingY
446DCompCommandsInBatchTracingY
450DCompCreateImplicitInteractionTracingN
451DCompVisualSetInteractionTracingN
452UserHandleOperationTracingY
453UserHandleOperationTracingY
454UserHandleOperationUpdateHandleOwnerTracingN
455GdiHandleOperationTracingY
456GdiHandleOperationTracingY
457GdiHandleOperationTracingY
458GdiHandleOperationTracingY
459WriteClipboardTracingN
460WriteClipboard460TracingN
461DwmVisRgnUpdateTracingN
462DwmVisRgnDirtyTracingN
463ReadClipboardTracingN
500FlipManagerCompleteTokenStartTracingN
501FlipManagerCompleteTokenStopTracingN
502FlipManagerTokenReleaseToFrameStartTracingN
503FlipManagerTokenReleaseToFrameStopTracingN
504FlipManagerSignalPresentRetiredTracingN
505FlipManagerPresentRetiredSignalOverrideTracingN
506FlipManagerPresentPostedTracingN
507FlipManagerProducerSetContentTracingN
508FlipManagerBufferAvailableTracingN
509FlipManagerAddBufferTracingN
510FlipManagerRemoveBufferTracingN
511FlipManagerContentRebindTracingN
512FlipManagerPresentProcessedTracingN
513FlipManagerPresentDeferredTracingN
514FlipManagerPresentCanceledTracingN
515FlipManagerPresentIFlipSubmittedTracingN
516FlipManagerPresentIFlipCompletedTracingN
517FlipManagerPresentQueueDepthTracingN
518FlipManagerBindingStartTracingN
519FlipManagerBindingTracingN
520FlipManagerBindingStopTracingN
521FlipManagerAddContentTracingN
522FlipManagerContentFlipTracingN
523FlipManagerNoOpPresentTracingN
524FlipManagerCancelPostedTracingN
525FlipManagerContentUnbindTracingN
526FlipManagerCreateTracingN
527FlipManagerDestroyTracingN
528TokenManagerDisableScanoutTokenTracingN
529FlipManagerLostTracingN
530FlipManagerCanceledPresentShownTracingN
531FlipManagerUpdateExpectedConsumerPresentIdTracingN
532FlipManagerPresentSkippedTracingN
533FlipManagerRemoveContentTracingN
534FlipManagerPresentIFlipPurgePreviousPresentsTracingN
535FlipManagerDiscardPresentAfterDestroyTracingN
536FlipManagerWaitForFrameRenderingCompleteOperationalN
537FlipManagerWaitForFrameFlipAwayOperationalN
538FlipManagerFlipAwayFenceCreateOperationalN
539FlipManagerFlipAwayFenceDestroyOperationalN
1000task_01000OperationalN
1001RegisterRawInputDevicesOperationalY
1002SetWindowsHookExOperationalY
1003GetAsyncKeyStateOperationalY
2000task_02000OperationalY
10002WindowLayoutChangeStopTracingN

Event ID 1: WindowUpdate

#
Provider
Microsoft-Windows-Win32k
Channel
Tracing
Task
WindowUpdate

Fields #

NameDescription
Hwnd Pointer
Type UInt32

Event ID 2: FocusChange

#
Provider
Microsoft-Windows-Win32k
Channel
Tracing
Task
FocusChange

Fields #

NameDescription
OldThreadId UInt32
NewThreadId UInt32

Event ID 3: UIPIMsgError

#
Provider
Microsoft-Windows-Win32k
Channel
UIPI
Task
UIPIMsgError

Fields #

NameDescription
UIPI_Trace_Header UInt8
Message UInt32
wParam UInt64
lParam UInt64

Event ID 4: UIPIHookError

#
Provider
Microsoft-Windows-Win32k
Channel
UIPI
Task
UIPIHookError

Fields #

NameDescription
UIPI_Trace_Header UInt16
HookID Int32
Flags Int8
nCode Int32
wParam UInt64
lParam UInt64

Event ID 5: UIPIEventHookError

#
Provider
Microsoft-Windows-Win32k
Channel
UIPI
Task
UIPIEventHookError

Fields #

NameDescription
UIPI_Trace_Header UInt32
WinEvent UInt32
WndHandle UInt64
ObjectID UInt32
ChildID UInt32
SenderTID Int32
Time Int32
Flags UInt32

Event ID 6: UIPIHandleValError

#
Provider
Microsoft-Windows-Win32k
Channel
UIPI
Task
UIPIHandleValError

Fields #

NameDescription
UIPI_Trace_Header UInt8
Handle UInt64
HandleType UInt32
Reserved UInt32

Event ID 7: UIPIInputError

#
Provider
Microsoft-Windows-Win32k
Channel
UIPI
Task
UIPIInputError

Fields #

NameDescription
UIPI_Trace_Header UInt8
InputType UInt32
QIL UInt32
QLBN UInt32

Event ID 8: UIPIClipboardError

#
Provider
Microsoft-Windows-Win32k
Channel
UIPI
Task
UIPIClipboardError

Fields #

NameDescription
UIPI_Trace_Header UInt8
ClipFormat UInt32
ClipIL UInt32
ClipLBN UInt32

Event ID 9: UIPISystemError

#
Provider
Microsoft-Windows-Win32k
Channel
UIPI
Task
UIPISystemError

Fields #

NameDescription
UIPI_Trace_Header AnsiString
SysErrorType UInt32

Event ID 10: PowerDisplayChange

#
Provider
Microsoft-Windows-Win32k
Channel
Power
Task
PowerDisplayChange

Fields #

NameDescription
SessionId UInt32
PreviousStateTime UInt32
PreviousState UInt16
NewState UInt16
IsConsoleSession UInt16

Event ID 11: IdleActionExpiration

#
Provider
Microsoft-Windows-Win32k
Channel
Power
Task
IdleActionExpiration

Fields #

NameDescription
SessionId UInt32
IdleAction UInt32
TimeoutValueMs UInt32
IdleStartTime UInt32
IsConsoleSession UInt16

Event ID 12: DisplayReqChange

#
Provider
Microsoft-Windows-Win32k
Channel
Power
Task
DisplayReqChange

Fields #

NameDescription
SessionId UInt32
IsConsoleSession UInt16
NewCount UInt32

Event ID 13: DisplayTimeoutReset

#
Provider
Microsoft-Windows-Win32k
Channel
Power
Task
DisplayTimeoutReset

Fields #

NameDescription
SessionId UInt32
IsConsoleSession UInt16
DisplayTimeoutValueMs UInt32

Event ID 14: LockAcquireExclusive

#
Provider
Microsoft-Windows-Win32k
Channel
Concurrency
Task
LockAcquireExclusive

Fields #

NameDescription
LockId Pointer
LockLevel UInt32
LockName UnicodeString

Event ID 15: LockAcquireShared

#
Provider
Microsoft-Windows-Win32k
Channel
Concurrency
Task
LockAcquireShared

Fields #

NameDescription
LockId Pointer
LockName UnicodeString

Event ID 16: LockAcquireSharedStarveExclusive

#
Provider
Microsoft-Windows-Win32k
Channel
Concurrency
Task
LockAcquireSharedStarveExclusive

Fields #

NameDescription
LockId Pointer
LockName UnicodeString

Event ID 17: LockRelease

#
Provider
Microsoft-Windows-Win32k
Channel
Concurrency
Task
LockRelease

Fields #

NameDescription
LockId Pointer
LockName UnicodeString

Event ID 18: SwapChainBind

#
Provider
Microsoft-Windows-Win32k
Channel
Tracing
Task
SwapChainBind

Fields #

NameDescription
hWnd UInt64
hLogicalSurfSwapChainBind UInt64

Event ID 19: SwapChainUnBind

#
Provider
Microsoft-Windows-Win32k
Channel
Tracing
Task
SwapChainUnBind

Fields #

NameDescription
hWnd UInt64
hLogicalSurfSwapChainBind UInt64

Event ID 20: IdleStatusTracing

#
Provider
Microsoft-Windows-Win32k
Channel
Power
Also via
realtime ETW trace
Level
Informational
Task
IdleStatusTracing
Opcode
win:Info

Fields #

NameDescription
SessionId UInt32
AccruedIdleTime UInt32
DisplayTimeoutValueMs UInt32
ScreenSaverTimeoutValueMs UInt32
DimTimeoutValueMs UInt32
DimBrightnessValue UInt32
NormalBrightnessValue UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Win32k",
    "guid": "{8C416C79-D49B-4F01-A467-E56D3AA8234C}",
    "event_source_name": "",
    "event_id": 20,
    "version": 0,
    "level": 4,
    "task": 21,
    "opcode": 0,
    "keywords": "0x2000000000008000",
    "time_created": "2026-06-02T05:32:25.246+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{8C416C79-D49B-4F01-A467-E56D3AA8234C}"
    },
    "execution": {
      "process_id": 1004,
      "thread_id": 1112
    },
    "channel": "ETW Trace",
    "computer": "JD-DC01-2022",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "AccruedIdleTime": 24078,
    "DimBrightnessValue": 0,
    "DimTimeoutValueMs": 585000,
    "DisplayTimeoutValueMs": 600000,
    "NormalBrightnessValue": 100,
    "ScreenSaverTimeoutValueMs": 900000,
    "SessionId": 1
  },
  "message": "IdleStatusTracing"
}

Event ID 21: SwapChainSetStats

#
Provider
Microsoft-Windows-Win32k
Channel
Tracing
Task
SwapChainSetStats

Fields #

NameDescription
hLogicalSurfSwapChainBind UInt64
ConfirmReason UInt32
LastPresentId UInt32
LastFrameCount UInt32
SyncFrameCount UInt32
LastFrameTime UInt64

Event ID 22: ScreenSaverProcess

#
Provider
Microsoft-Windows-Win32k
Channel
Power
Task
ScreenSaverProcess

Fields #

NameDescription
Action UInt32

Event ID 23: WinlogonSleepStart

#
Provider
Microsoft-Windows-Win32k
Channel
Power
Task
WinlogonSleepStart

Fields #

NameDescription
Action UInt32

Event ID 24: WinlogonSleepEnd

#
Provider
Microsoft-Windows-Win32k
Channel
Power
Task
WinlogonSleepEnd

Fields #

NameDescription
Action UInt32

Event ID 25: UserActive

#
Provider
Microsoft-Windows-Win32k
Channel
Tracing
Task
UserActive

Fields #

NameDescription
SessionId UInt32
ProcessIdOwningFocus UInt32
ProcessCreateTimeOwningFocus FILETIME

Event ID 26: FocusedProcessChange

#
Provider
Microsoft-Windows-Win32k
Channel
Tracing
Task
FocusedProcessChange

Fields #

NameDescription
SessionId UInt32
OldProcessId UInt32
NewProcessId UInt32

Event ID 27: DwmSpriteCreate

#
Provider
Microsoft-Windows-Win32k
Channel
Tracing
Task
DwmSpriteCreate

Fields #

NameDescription
hWnd UInt64
hSprite UInt64

Event ID 28: DwmSpriteDestroy

#
Provider
Microsoft-Windows-Win32k
Channel
Tracing
Task
DwmSpriteDestroy

Fields #

NameDescription
hWnd UInt64
hSprite UInt64

Event ID 29: LogicalSurfCreate

#
Provider
Microsoft-Windows-Win32k
Channel
Tracing
Task
LogicalSurfCreate

Fields #

NameDescription
hLogicalSurf UInt64
Flags UInt32

Event ID 30: LogicalSurfDestroy

#
Provider
Microsoft-Windows-Win32k
Channel
Tracing
Task
LogicalSurfDestroy

Fields #

NameDescription
hLogicalSurf UInt64
Flags UInt32

Event ID 31: LogicalSurfPhysSurfBind

#
Provider
Microsoft-Windows-Win32k
Channel
Tracing
Task
LogicalSurfPhysSurfBind

Fields #

NameDescription
hLogicalSurf UInt64
hPhysicalSurf UInt64

Event ID 32: LogicalSurfPhysSurfUnbind

#
Provider
Microsoft-Windows-Win32k
Channel
Tracing
Task
LogicalSurfPhysSurfUnbind

Fields #

NameDescription
hLogicalSurf UInt64
hPhysicalSurf UInt64

Event ID 33: GdiSysMemToken

#
Provider
Microsoft-Windows-Win32k
Channel
Tracing
Task
GdiSysMemToken

Fields #

NameDescription
Pending UInt32
dwDirtyFlags UInt32
hLogicalSurf UInt64
uiCookie UInt64

Event ID 35: WaitCursor

#
Provider
Microsoft-Windows-Win32k
Channel
Tracing
Task
WaitCursor

Fields #

NameDescription
CursorThreadId UInt32
CursorProcessId UInt32
SessionId UInt32
CursorType UInt32
DisplayTimeMs UInt32

Event ID 36: ThreadInfoRundown

#
Provider
Microsoft-Windows-Win32k
Channel
Tracing
Task
ThreadInfoRundown

Fields #

NameDescription
ThreadId UInt32
Flags UInt32
TimeSinceInputCheckMs UInt32
TimeSinceInputRemoveMs UInt32
TimeSinceOldestInputMs UInt32

Event ID 37: InputProcessDelay

#
Provider
Microsoft-Windows-Win32k
Channel
Tracing
Task
InputProcessDelay

Fields #

NameDescription
Flags UInt32
TimeSinceInputRemoveMs UInt32
TimeSinceOldestInputMs UInt32
ClassName UnicodeString
TopLevelClassName UnicodeString
ImagePath UnicodeString
MessageId UInt32
WParam UInt64

Event ID 38: MessageCheckDelay

#
Provider
Microsoft-Windows-Win32k
Channel
Tracing
Task
MessageCheckDelay

Fields #

NameDescription
Flags UInt32
DelayTimeMs UInt32
TimeSinceInputRemoveMs UInt32
TimeSinceOldestInputMs UInt32
ClassName UnicodeString
TopLevelClassName UnicodeString
ImagePath UnicodeString
MessageId UInt32
WParam UInt64

Event ID 39: RenderingNewRendering

#
Provider
Microsoft-Windows-Win32k
Channel
Render
Task
Rendering
Opcode
NewRendering

Fields #

NameDescription
hwndDst Pointer
hwndDstSprite Pointer
hbmDst Pointer
DstLeft UInt32
DstTop UInt32
DstRight UInt32
DstBottom UInt32
hwndSrc Pointer
hwndSrcSprite Pointer
hbmSrc Pointer
SrcLeft UInt32
SrcTop UInt32
SrcRight UInt32
SrcBottom UInt32

Event ID 40: RenderingOldToNewRendering

#
Provider
Microsoft-Windows-Win32k
Channel
Render
Task
Rendering
Opcode
OldToNewRendering

Fields #

NameDescription
hwndDst Pointer
hwndDstSprite Pointer
hbmDst Pointer
DstLeft UInt32
DstTop UInt32
DstRight UInt32
DstBottom UInt32
hwndSrc Pointer
hwndSrcSprite Pointer
hbmSrc Pointer
SrcLeft UInt32
SrcTop UInt32
SrcRight UInt32
SrcBottom UInt32

Event ID 41: Rendering

#
Provider
Microsoft-Windows-Win32k
Channel
Render
Also via
realtime ETW trace
Level
Informational
Task
Rendering
Opcode
AppRenderingUpdate

Fields #

NameDescription
hwnd Pointer
bitmapCX UInt32
bitmapCY UInt32
DirtyLeft UInt32
DirtyTop UInt32
DirtyRight UInt32
DirtyBottom UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Win32k",
    "guid": "{8C416C79-D49B-4F01-A467-E56D3AA8234C}",
    "event_source_name": "",
    "event_id": 41,
    "version": 0,
    "level": 4,
    "task": 39,
    "opcode": 12,
    "keywords": "0x0800000000100000",
    "time_created": "2026-06-02T04:02:00.030+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{8C416C79-D49B-4F01-A467-E56D3AA8234C}"
    },
    "execution": {
      "process_id": 4304,
      "thread_id": 3088
    },
    "channel": "ETW Trace",
    "computer": "JD-DC01-2022",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "DirtyBottom": 40,
    "DirtyLeft": 907,
    "DirtyRight": 971,
    "DirtyTop": 0,
    "bitmapCX": 1024,
    "bitmapCY": 40,
    "hwnd": "0x20032"
  },
  "message": "Rendering"
}

Event ID 42: RenderingAppRenderingTightUpdate

#
Provider
Microsoft-Windows-Win32k
Channel
Render
Task
Rendering
Opcode
AppRenderingTightUpdate

Fields #

NameDescription
hwnd Pointer
bitmapCX UInt32
bitmapCY UInt32
DirtyLeft UInt32
DirtyTop UInt32
DirtyRight UInt32
DirtyBottom UInt32

Event ID 43: RenderingValidateWindow

#
Provider
Microsoft-Windows-Win32k
Channel
Render
Task
Rendering
Opcode
ValidateWindow

Fields #

NameDescription
hwnd Pointer
FULL UInt32
Left UInt32
Top UInt32
Right UInt32
Bottom UInt32

Event ID 44: RenderingInvalidateWindow

#
Provider
Microsoft-Windows-Win32k
Channel
Render
Task
Rendering
Opcode
InvalidateWindow

Fields #

NameDescription
hwnd Pointer
FULL UInt32
Left UInt32
Top UInt32
Right UInt32
Bottom UInt32

Event ID 45: ThreadExit

#
Provider
Microsoft-Windows-Win32k
Channel
Tracing
Also via
realtime ETW trace
Level
Informational
Task
ThreadExit
Opcode
win:Info

Fields #

NameDescription
ThreadId UInt32
Flags UInt32
TimeSinceInputCheckMs UInt32
TimeSinceInputRemoveMs UInt32
TimeSinceOldestInputMs UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Win32k",
    "guid": "{8C416C79-D49B-4F01-A467-E56D3AA8234C}",
    "event_source_name": "",
    "event_id": 45,
    "version": 0,
    "level": 4,
    "task": 45,
    "opcode": 0,
    "keywords": "0x0000000000200000",
    "time_created": "2026-06-02T04:02:00.577+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{8C416C79-D49B-4F01-A467-E56D3AA8234C}"
    },
    "execution": {
      "process_id": 4872,
      "thread_id": 10316
    },
    "channel": "ETW Trace",
    "computer": "JD-DC01-2022",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Flags": 64,
    "ThreadId": 10316,
    "TimeSinceInputCheckMs": 0,
    "TimeSinceInputRemoveMs": 72438,
    "TimeSinceOldestInputMs": 0
  },
  "message": "ThreadExit"
}

Event ID 46: BindLogicalSurface

#
Provider
Microsoft-Windows-Win32k
Channel
Tracing
Task
BindLogicalSurface

Fields #

NameDescription
hWnd UInt64
hLogicalSurf UInt64

Event ID 47: UnBindLogicalSurface

#
Provider
Microsoft-Windows-Win32k
Channel
Tracing
Task
UnBindLogicalSurface

Fields #

NameDescription
hWnd UInt64
hLogicalSurf UInt64

Event ID 48: BindLogicalSurfaceRH

#
Provider
Microsoft-Windows-Win32k
Channel
Tracing
Task
BindLogicalSurfaceRH

Fields #

NameDescription
hLogicalSurf UInt64
bCreated UInt64

Event ID 49: DwmSpriteLogicalSurfBind

#
Provider
Microsoft-Windows-Win32k
Channel
Tracing
Task
DwmSpriteLogicalSurfBind

Fields #

NameDescription
hDwmSprite UInt64
hLogicalSurf UInt64

Event ID 50: DwmSpriteLogicalSurfUnBind

#
Provider
Microsoft-Windows-Win32k
Channel
Tracing
Task
DwmSpriteLogicalSurfUnBind

Fields #

NameDescription
hDwmSprite UInt64
hLogicalSurf UInt64

Event ID 51: LogicalSurfEnableDirtyNotification

#
Provider
Microsoft-Windows-Win32k
Channel
Tracing
Task
LogicalSurfEnableDirtyNotification

Fields #

NameDescription
hLogicalSurf UInt64
hPhysSurf UInt64

Event ID 52: PhysicalSurfCreate

#
Provider
Microsoft-Windows-Win32k
Channel
Tracing
Also via
realtime ETW trace
Level
Informational
Task
PhysicalSurfCreate
Opcode
win:Info

Fields #

NameDescription
hPhysicalSurf UInt64
Type UInt32
hDxSharedSurface UInt64
Flags UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Win32k",
    "guid": "{8C416C79-D49B-4F01-A467-E56D3AA8234C}",
    "event_source_name": "",
    "event_id": 52,
    "version": 0,
    "level": 4,
    "task": 52,
    "opcode": 0,
    "keywords": "0x0000000000001000",
    "time_created": "2026-06-02T05:32:25.758+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{8C416C79-D49B-4F01-A467-E56D3AA8234C}"
    },
    "execution": {
      "process_id": 14592,
      "thread_id": 10500
    },
    "channel": "ETW Trace",
    "computer": "JD-DC01-2022",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Flags": 0,
    "Type": 0,
    "hDxSharedSurface": 0,
    "hPhysicalSurf": 18446744071763722935
  },
  "message": "PhysicalSurfCreate"
}

Event ID 53: ModifyRgn

#
Provider
Microsoft-Windows-Win32k
Channel
Tracing
Also via
realtime ETW trace
Level
Informational
Task
ModifyRgn
Opcode
win:Info

Fields #

NameDescription
hLogicalSurface UInt64
RgnType UInt32
rcBounds Int16
NumRects UInt32
rcData Int64

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Win32k",
    "guid": "{8C416C79-D49B-4F01-A467-E56D3AA8234C}",
    "event_source_name": "",
    "event_id": 53,
    "version": 0,
    "level": 4,
    "task": 53,
    "opcode": 0,
    "keywords": "0x0000000000001000",
    "time_created": "2026-06-02T04:02:00.030+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{8C416C79-D49B-4F01-A467-E56D3AA8234C}"
    },
    "execution": {
      "process_id": 4304,
      "thread_id": 3088
    },
    "channel": "ETW Trace",
    "computer": "JD-DC01-2022",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "NumRects": 1,
    "RgnType": 1,
    "hLogicalSurface": 68290098,
    "rcBounds": "00000000000000000004000028000000",
    "rcData": "00000000000000000004000028000000"
  },
  "message": "ModifyRgn"
}

Event ID 54: SwapChainGetStats

#
Provider
Microsoft-Windows-Win32k
Channel
Tracing
Task
SwapChainGetStats

Fields #

NameDescription
hLogicalSurfSwapChainBind UInt64
ConfirmReason UInt32
LastPresentId UInt32
LastFrameCount UInt32
SyncFrameCount UInt32
LastFrameTime UInt64

Event ID 55: SwapChainBindingOpen

#
Provider
Microsoft-Windows-Win32k
Channel
Tracing
Task
SwapChainBindingOpen

Fields #

NameDescription
hLogicalSurfSwapChainBinding UInt64
luidAdapter UInt64
nWidth UInt32
nHeight UInt32
DxgiColorFormat UInt32
hmonAssociation UInt64
uiPresentLimitSemaphoreId UInt64
cBuffers UInt32
BindingInfoHandle Int64

Event ID 56: SwapChainBindingRelease

#
Provider
Microsoft-Windows-Win32k
Channel
Tracing
Task
SwapChainBindingRelease

Fields #

NameDescription
hLogicalSurfSwapChainBinding UInt64
DesktopCompositorProcess UInt8
DesktopCompositorError UInt8
DesktopCompositorRef UInt8
DesktopCompositorStatus UInt8
pEventConfirmed UInt64

Event ID 57: SwapChainBindingStatus

#
Provider
Microsoft-Windows-Win32k
Channel
Tracing
Task
SwapChainBindingStatus

Fields #

NameDescription
hLogicalSurfSwapChainBinding UInt64
DesktopCompositorStatus UInt8

Event ID 58: DesktopResolutionFailure

#
Provider
Microsoft-Windows-Win32k
Channel
Tracing
Task
DesktopResolutionFailure

Fields #

NameDescription
ProcessId UInt32
FailureStatus UInt32

Event ID 59: QueuePostMessage

#
Provider
Microsoft-Windows-Win32k
Channel
Messages
Also via
realtime ETW trace
Level
Informational
Task
QueuePostMessage
Opcode
win:Info

Fields #

NameDescription
CallbackCount Int8
pqmsg Pointer
hwnd Pointer
WParam Pointer
LParam Pointer
message UInt32
inputReadyTimeMs UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Win32k",
    "guid": "{8C416C79-D49B-4F01-A467-E56D3AA8234C}",
    "event_source_name": "",
    "event_id": 59,
    "version": 0,
    "level": 4,
    "task": 59,
    "opcode": 0,
    "keywords": "0x0400000000400000",
    "time_created": "2026-06-02T05:32:24.458+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{8C416C79-D49B-4F01-A467-E56D3AA8234C}"
    },
    "execution": {
      "process_id": 6296,
      "thread_id": 3488
    },
    "channel": "ETW Trace",
    "computer": "JD-DC01-2022",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "CallbackCount": 0,
    "LParam": "0x0",
    "WParam": "0x0",
    "hwnd": "0x30048",
    "inputReadyTimeMs": 35788625,
    "message": 0,
    "pqmsg": "0xFFFFC5238079C710"
  },
  "message": "QueuePostMessage"
}

Event ID 60: SendMessageStart

#
Provider
Microsoft-Windows-Win32k
Channel
Messages
Task
SendMessage
Opcode
Start

Fields #

NameDescription
CallbackCount Int8
pqmsg Pointer
hwnd Pointer
WParam Pointer
LParam Pointer
message UInt32
inputReadyTimeMs UInt32
flags UInt32
pidReceiver UInt32
tidReceiver UInt32

Event ID 61: RetrievePostMessage

#
Provider
Microsoft-Windows-Win32k
Channel
Messages
Also via
realtime ETW trace
Level
Informational
Task
RetrievePostMessage
Opcode
win:Info

Fields #

NameDescription
CallbackCount Int8
pqmsg Pointer
hwnd Pointer
WParam Pointer
LParam Pointer
message UInt32
inputReadyTimeMs UInt32
flags UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Win32k",
    "guid": "{8C416C79-D49B-4F01-A467-E56D3AA8234C}",
    "event_source_name": "",
    "event_id": 61,
    "version": 0,
    "level": 4,
    "task": 65,
    "opcode": 0,
    "keywords": "0x0400000000400000",
    "time_created": "2026-06-02T05:32:24.458+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{8C416C79-D49B-4F01-A467-E56D3AA8234C}"
    },
    "execution": {
      "process_id": 6296,
      "thread_id": 6300
    },
    "channel": "ETW Trace",
    "computer": "JD-DC01-2022",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "CallbackCount": 0,
    "LParam": "0x0",
    "WParam": "0x0",
    "flags": 1,
    "hwnd": "0x30048",
    "inputReadyTimeMs": 35788625,
    "message": 0,
    "pqmsg": "0xFFFFC5238079C710"
  },
  "message": "RetrievePostMessage"
}

Event ID 62: RetrieveSendMessageStart

#
Provider
Microsoft-Windows-Win32k
Channel
Messages
Task
RetrieveSendMessage
Opcode
Start

Fields #

NameDescription
CallbackCount Int8
pqmsg Pointer
hwnd Pointer
WParam Pointer
LParam Pointer
message UInt32
inputReadyTimeMs UInt32

Event ID 63: RetrieveInputMessage

#
Provider
Microsoft-Windows-Win32k
Channel
Messages
Also via
realtime ETW trace
Level
Informational
Task
RetrieveInputMessage
Opcode
win:Info

Fields #

NameDescription
CallbackCount Int8
hwnd Pointer
WParam Pointer
LParam Pointer
message UInt32
inputReadyTimeMs UInt32
flags UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Win32k",
    "guid": "{8C416C79-D49B-4F01-A467-E56D3AA8234C}",
    "event_source_name": "",
    "event_id": 63,
    "version": 0,
    "level": 4,
    "task": 67,
    "opcode": 0,
    "keywords": "0x0400000040400000",
    "time_created": "2026-06-02T05:32:25.759+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{8C416C79-D49B-4F01-A467-E56D3AA8234C}"
    },
    "execution": {
      "process_id": 952,
      "thread_id": 1052
    },
    "channel": "ETW Trace",
    "computer": "JD-DC01-2022",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "CallbackCount": 0,
    "LParam": "0x0",
    "WParam": "0x0",
    "flags": 1,
    "hwnd": "0x10004",
    "inputReadyTimeMs": 0,
    "message": 0
  },
  "message": "RetrieveInputMessage"
}

Event ID 64: RetrievePseudoMessage

#
Provider
Microsoft-Windows-Win32k
Channel
Messages
Also via
realtime ETW trace
Task
RetrievePseudoMessage
Opcode
win:Info

Fields #

NameDescription
CallbackCount Int8
pqmsg Pointer
hwnd Pointer
WParam Pointer
LParam Pointer
message UInt32
inputReadyTimeMs UInt32
flags UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Win32k",
    "guid": "{8C416C79-D49B-4F01-A467-E56D3AA8234C}",
    "event_source_name": "",
    "event_id": 64,
    "version": 0,
    "level": 0,
    "task": 68,
    "opcode": 0,
    "keywords": "0x0400000000400000",
    "time_created": "2026-06-02T05:32:25.771+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{8C416C79-D49B-4F01-A467-E56D3AA8234C}"
    },
    "execution": {
      "process_id": 14592,
      "thread_id": 10500
    },
    "channel": "ETW Trace",
    "computer": "JD-DC01-2022",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "CallbackCount": 0,
    "LParam": "0x0",
    "WParam": "0x0",
    "flags": 1,
    "hwnd": "0x4F006C",
    "inputReadyTimeMs": 35789937,
    "message": 0,
    "pqmsg": "0x0"
  },
  "message": "RetrievePseudoMessage"
}

Event ID 65: WakePump

#
Provider
Microsoft-Windows-Win32k
Channel
Messages
Also via
realtime ETW trace
Level
Informational
Task
WakePump
Opcode
win:Info

Fields #

NameDescription
CallbackCount Int8
pqmsg Pointer
hwnd Pointer
WParam Pointer
LParam Pointer
message UInt32
inputReadyTimeMs UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Win32k",
    "guid": "{8C416C79-D49B-4F01-A467-E56D3AA8234C}",
    "event_source_name": "",
    "event_id": 65,
    "version": 0,
    "level": 4,
    "task": 61,
    "opcode": 0,
    "keywords": "0x0400000000400000",
    "time_created": "2026-06-02T05:32:25.758+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{8C416C79-D49B-4F01-A467-E56D3AA8234C}"
    },
    "execution": {
      "process_id": 14592,
      "thread_id": 10500
    },
    "channel": "ETW Trace",
    "computer": "JD-DC01-2022",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "CallbackCount": 0,
    "LParam": "0x0",
    "WParam": "0x0",
    "hwnd": "0x4F006C",
    "inputReadyTimeMs": 0,
    "message": 15,
    "pqmsg": "0xFFFFC52384489010"
  },
  "message": "WakePump"
}

Event ID 66: InputQueueLocked

#
Provider
Microsoft-Windows-Win32k
Channel
Messages
Task
InputQueueLocked

Fields #

NameDescription
CallbackCount Int8
pQueue Pointer
ownerThread UInt32

Event ID 67: InputQueueLocked67

#
Provider
Microsoft-Windows-Win32k
Channel
Messages
Task
InputQueueLocked

Fields #

NameDescription
CallbackCount Int8
pQueue Pointer
ownerThread UInt32

Event ID 68: UserCallbackStart

#
Provider
Microsoft-Windows-Win32k
Channel
Messages
Task
UserCallback
Opcode
Start

Fields #

NameDescription
CallbackCount Int8
api Int32

Event ID 69: UserCallbackStop

#
Provider
Microsoft-Windows-Win32k
Channel
Messages
Task
UserCallback
Opcode
Stop

Fields #

NameDescription
CallbackCount Int8
api Int32

Event ID 70: SendMessageStop

#
Provider
Microsoft-Windows-Win32k
Channel
Messages
Task
SendMessage
Opcode
Stop

Fields #

NameDescription
CallbackCount Int8
pqmsg Pointer

Event ID 71: SendMessageTimeOutToBlocking

#
Provider
Microsoft-Windows-Win32k
Channel
Messages
Task
SendMessageTimeOutToBlocking

Fields #

NameDescription
CallbackCount Int8

Event ID 72: InputDeviceReadStart

#
Provider
Microsoft-Windows-Win32k
Channel
Messages
Task
InputDeviceRead
Opcode
Start

Fields #

NameDescription
DeviceType Int32
dwFlags UInt32

Event ID 73: InputDeviceReadStop

#
Provider
Microsoft-Windows-Win32k
Channel
Messages
Task
InputDeviceRead
Opcode
Stop

Fields #

NameDescription
DeviceType Int32
dwFlags UInt32

Event ID 74: MessageInjectionPostGestureInputMessage

#
Provider
Microsoft-Windows-Win32k
Channel
Messages
Task
MessageInjection
Opcode
PostGestureInputMessage

Fields #

NameDescription
CallbackCount Int8
hwnd Pointer
hGestureInfo Pointer

Event ID 75: MessageInjectionPostGestureMessage

#
Provider
Microsoft-Windows-Win32k
Channel
Messages
Task
MessageInjection
Opcode
PostGestureMessage

Fields #

NameDescription
CallbackCount Int8
hwnd Pointer
hGestureInfo Pointer

Event ID 76: AppMessagePump

#
Provider
Microsoft-Windows-Win32k
Channel
Messages
Also via
realtime ETW trace
Level
Informational
Task
AppMessagePump
Opcode
Start

Fields #

NameDescription
CallbackCount Int8
fGetMessage Int32
dwFlags UInt32
Message UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Win32k",
    "guid": "{8C416C79-D49B-4F01-A467-E56D3AA8234C}",
    "event_source_name": "",
    "event_id": 76,
    "version": 0,
    "level": 4,
    "task": 69,
    "opcode": 1,
    "keywords": "0x0400000000800000",
    "time_created": "2026-06-02T05:32:24.458+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{8C416C79-D49B-4F01-A467-E56D3AA8234C}"
    },
    "execution": {
      "process_id": 6296,
      "thread_id": 6300
    },
    "channel": "ETW Trace",
    "computer": "JD-DC01-2022",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "CallbackCount": 0,
    "Message": 1024,
    "dwFlags": 1,
    "fGetMessage": 1
  },
  "message": "AppMessagePump"
}

Event ID 77: AppMessagePump

#
Provider
Microsoft-Windows-Win32k
Channel
Messages
Also via
realtime ETW trace
Level
Informational
Task
AppMessagePump
Opcode
Stop

Fields #

NameDescription
CallbackCount Int8
fGetMessage Int32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Win32k",
    "guid": "{8C416C79-D49B-4F01-A467-E56D3AA8234C}",
    "event_source_name": "",
    "event_id": 77,
    "version": 0,
    "level": 4,
    "task": 69,
    "opcode": 2,
    "keywords": "0x0400000000800000",
    "time_created": "2026-06-02T05:32:24.458+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{8C416C79-D49B-4F01-A467-E56D3AA8234C}"
    },
    "execution": {
      "process_id": 6296,
      "thread_id": 6300
    },
    "channel": "ETW Trace",
    "computer": "JD-DC01-2022",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "CallbackCount": 0,
    "fGetMessage": 1
  },
  "message": "AppMessagePump"
}

Event ID 78: WakeRIT

#
Provider
Microsoft-Windows-Win32k
Channel
Messages
Also via
realtime ETW trace
Level
Informational
Task
WakeRIT
Opcode
win:Info

Fields #

NameDescription
CallbackCount Int8
WakeReason Int32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Win32k",
    "guid": "{8C416C79-D49B-4F01-A467-E56D3AA8234C}",
    "event_source_name": "",
    "event_id": 78,
    "version": 0,
    "level": 4,
    "task": 72,
    "opcode": 0,
    "keywords": "0x0400000000800000",
    "time_created": "2026-06-02T05:32:25.759+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{8C416C79-D49B-4F01-A467-E56D3AA8234C}"
    },
    "execution": {
      "process_id": 14592,
      "thread_id": 10500
    },
    "channel": "ETW Trace",
    "computer": "JD-DC01-2022",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "CallbackCount": 0,
    "WakeReason": 1
  },
  "message": "WakeRIT"
}

Event ID 79: PointerMotionStart

#
Provider
Microsoft-Windows-Win32k
Channel
Messages
Task
PointerMotion
Opcode
Start

Fields #

NameDescription
Time Int32
X Int32
Y Int32

Event ID 80: PointerMotionStop

#
Provider
Microsoft-Windows-Win32k
Channel
Messages
Task
PointerMotion
Opcode
Stop

Fields #

NameDescription
Time Int32
X Int32
Y Int32

Event ID 81: InjectMouseStart

#
Provider
Microsoft-Windows-Win32k
Channel
Messages
Task
InjectMouse
Opcode
Start

Fields #

NameDescription
CallbackCount Int8
Time Int32
X Int32
Y Int32

Event ID 82: InjectMouseStop

#
Provider
Microsoft-Windows-Win32k
Channel
Messages
Task
InjectMouse
Opcode
Stop

Fields #

NameDescription
CallbackCount Int8
Time Int32
X Int32
Y Int32

Event ID 83: RetrieveSendMessageStop

#
Provider
Microsoft-Windows-Win32k
Channel
Messages
Task
RetrieveSendMessage
Opcode
Stop

Fields #

NameDescription
CallbackCount Int8
pqmsg Pointer

Event ID 84: GUIProcess

#
Provider
Microsoft-Windows-Win32k
Channel
Messages
Level
Informational
Task
GUIProcess
Opcode
Start

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Win32k",
    "guid": "{8C416C79-D49B-4F01-A467-E56D3AA8234C}",
    "event_source_name": "",
    "event_id": 84,
    "version": 0,
    "level": 4,
    "task": 76,
    "opcode": 1,
    "keywords": "0x0400000000200000",
    "time_created": "2026-06-02T05:32:25.745+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{8C416C79-D49B-4F01-A467-E56D3AA8234C}"
    },
    "execution": {
      "process_id": 14592,
      "thread_id": 12892
    },
    "channel": "ETW Trace",
    "computer": "JD-DC01-2022",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": "GUIProcess"
}

Event ID 85: GUIProcess

#
Provider
Microsoft-Windows-Win32k
Channel
Messages
Level
Informational
Task
GUIProcess
Opcode
Stop

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Win32k",
    "guid": "{8C416C79-D49B-4F01-A467-E56D3AA8234C}",
    "event_source_name": "",
    "event_id": 85,
    "version": 0,
    "level": 4,
    "task": 76,
    "opcode": 2,
    "keywords": "0x0400000000200000",
    "time_created": "2026-06-02T06:07:54.630+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{8C416C79-D49B-4F01-A467-E56D3AA8234C}"
    },
    "execution": {
      "process_id": 11204,
      "thread_id": 4120
    },
    "channel": "ETW Trace",
    "computer": "DESKTOP-FF3N5XK",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": "GUIProcess"
}

Event ID 86: GUIThread

#
Provider
Microsoft-Windows-Win32k
Channel
Messages
Level
Informational
Task
GUIThread
Opcode
Start

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Win32k",
    "guid": "{8C416C79-D49B-4F01-A467-E56D3AA8234C}",
    "event_source_name": "",
    "event_id": 86,
    "version": 0,
    "level": 4,
    "task": 77,
    "opcode": 1,
    "keywords": "0x0400000000200000",
    "time_created": "2026-06-02T05:32:24.730+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{8C416C79-D49B-4F01-A467-E56D3AA8234C}"
    },
    "execution": {
      "process_id": 21572,
      "thread_id": 12732
    },
    "channel": "ETW Trace",
    "computer": "JD-DC01-2022",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": "GUIThread"
}

Event ID 87: GUIThread

#
Provider
Microsoft-Windows-Win32k
Channel
Messages
Level
Informational
Task
GUIThread
Opcode
Stop

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Win32k",
    "guid": "{8C416C79-D49B-4F01-A467-E56D3AA8234C}",
    "event_source_name": "",
    "event_id": 87,
    "version": 0,
    "level": 4,
    "task": 77,
    "opcode": 2,
    "keywords": "0x0400000000200000",
    "time_created": "2026-06-02T04:02:00.577+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{8C416C79-D49B-4F01-A467-E56D3AA8234C}"
    },
    "execution": {
      "process_id": 4872,
      "thread_id": 10316
    },
    "channel": "ETW Trace",
    "computer": "JD-DC01-2022",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": "GUIThread"
}

Event ID 88: QueueInputMessage

#
Provider
Microsoft-Windows-Win32k
Channel
Messages
Also via
realtime ETW trace
Level
Informational
Task
QueueInputMessage
Opcode
win:Info

Fields #

NameDescription
CallbackCount Int8
pqmsg Pointer
WindowDelegated Boolean
WasWindowDelegated Boolean
Delegated Boolean
WasDelegated Boolean
Processed Boolean
fDelayedFree Boolean
hwnd Pointer
WParam Pointer
LParam Pointer
message UInt32
inputReadyTimeMs UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Win32k",
    "guid": "{8C416C79-D49B-4F01-A467-E56D3AA8234C}",
    "event_source_name": "",
    "event_id": 88,
    "version": 0,
    "level": 4,
    "task": 79,
    "opcode": 0,
    "keywords": "0x0400000040400000",
    "time_created": "2026-06-02T05:32:25.759+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{8C416C79-D49B-4F01-A467-E56D3AA8234C}"
    },
    "execution": {
      "process_id": 952,
      "thread_id": 1052
    },
    "channel": "ETW Trace",
    "computer": "JD-DC01-2022",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "CallbackCount": 0,
    "Delegated": false,
    "LParam": "0x0",
    "Processed": false,
    "WParam": "0x0",
    "WasDelegated": false,
    "WasWindowDelegated": false,
    "WindowDelegated": false,
    "fDelayedFree": false,
    "hwnd": "0x0",
    "inputReadyTimeMs": 35789921,
    "message": 0,
    "pqmsg": "0xFFFFC5238079C710"
  },
  "message": "QueueInputMessage"
}

Event ID 89: TranslateMessageStart

#
Provider
Microsoft-Windows-Win32k
Channel
Messages
Task
TranslateMessage
Opcode
Start

Fields #

NameDescription
CallbackCount Int8
message UInt32

Event ID 91: TranslateMessageStop

#
Provider
Microsoft-Windows-Win32k
Channel
Messages
Task
TranslateMessage
Opcode
Stop

Fields #

NameDescription
CallbackCount Int8
message UInt32

Event ID 92: DispatchMessage

#
Provider
Microsoft-Windows-Win32k
Channel
Messages
Also via
realtime ETW trace
Level
Informational
Task
DispatchMessage
Opcode
Start

Fields #

NameDescription
CallbackCount Int8
message UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Win32k",
    "guid": "{8C416C79-D49B-4F01-A467-E56D3AA8234C}",
    "event_source_name": "",
    "event_id": 92,
    "version": 0,
    "level": 4,
    "task": 81,
    "opcode": 1,
    "keywords": "0x0400000000400000",
    "time_created": "2026-06-02T05:32:25.759+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{8C416C79-D49B-4F01-A467-E56D3AA8234C}"
    },
    "execution": {
      "process_id": 952,
      "thread_id": 1052
    },
    "channel": "ETW Trace",
    "computer": "JD-DC01-2022",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "CallbackCount": 0,
    "message": 512
  },
  "message": "DispatchMessage"
}

Event ID 93: DispatchMessage

#
Provider
Microsoft-Windows-Win32k
Channel
Messages
Also via
realtime ETW trace
Level
Informational
Task
DispatchMessage
Opcode
Stop

Fields #

NameDescription
CallbackCount Int8
message UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Win32k",
    "guid": "{8C416C79-D49B-4F01-A467-E56D3AA8234C}",
    "event_source_name": "",
    "event_id": 93,
    "version": 0,
    "level": 4,
    "task": 81,
    "opcode": 2,
    "keywords": "0x0400000000400000",
    "time_created": "2026-06-02T05:32:25.759+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{8C416C79-D49B-4F01-A467-E56D3AA8234C}"
    },
    "execution": {
      "process_id": 952,
      "thread_id": 1052
    },
    "channel": "ETW Trace",
    "computer": "JD-DC01-2022",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "CallbackCount": 0,
    "message": 512
  },
  "message": "DispatchMessage"
}

Event ID 94: TouchTargetingSpeedHitTestStart

#
Provider
Microsoft-Windows-Win32k
Channel
Messages
Task
TouchTargetingSpeedHitTest
Opcode
Start

Event ID 95: TouchTargetingSpeedHitTestStop

#
Provider
Microsoft-Windows-Win32k
Channel
Messages
Task
TouchTargetingSpeedHitTest
Opcode
Stop

Event ID 96: TouchTargetingWindowHitTestStart

#
Provider
Microsoft-Windows-Win32k
Channel
Messages
Task
TouchTargetingWindowHitTest
Opcode
Start

Event ID 97: TouchTargetingWindowHitTestStop

#
Provider
Microsoft-Windows-Win32k
Channel
Messages
Task
TouchTargetingWindowHitTest
Opcode
Stop

Event ID 98: TouchTargetingPointerTargetStart

#
Provider
Microsoft-Windows-Win32k
Channel
Messages
Task
TouchTargetingPointerTarget
Opcode
Start

Event ID 99: TouchTargetingPointerTargetStop

#
Provider
Microsoft-Windows-Win32k
Channel
Messages
Task
TouchTargetingPointerTarget
Opcode
Stop

Event ID 100: MessageInjectionInjectTouchEvent

#
Provider
Microsoft-Windows-Win32k
Channel
Messages
Task
MessageInjection
Opcode
InjectTouchEvent

Fields #

NameDescription
CallbackCount Int8

Event ID 102: task_0

#
Provider
Microsoft-Windows-Win32k
Channel
Tracing
Opcode
Info

Fields #

NameDescription
SessionId UInt32
cLineWidth UInt32
cElements UInt32

Event ID 103: task_0103

#
Provider
Microsoft-Windows-Win32k
Channel
Tracing
Opcode
Info

Fields #

NameDescription
ProcName AnsiString
ClassName UnicodeString
WindowName UnicodeString
uId UInt32
uElapse UInt32
uType UInt32

Event ID 104: ContactVisualizationStart

#
Provider
Microsoft-Windows-Win32k
Channel
Tracing
Task
ContactVisualization
Opcode
Start

Event ID 105: ContactVisualizationStop

#
Provider
Microsoft-Windows-Win32k
Channel
Tracing
Task
ContactVisualization
Opcode
Stop

Event ID 106: TouchTargetingOffset

#
Provider
Microsoft-Windows-Win32k
Channel
Messages
Task
TouchTargetingOffset

Fields #

NameDescription
ptOffsetX Int32
ptOffsetY Int32
pointerId Int32
cursorId Int32

Event ID 107: TouchTargetingPointerEvent

#
Provider
Microsoft-Windows-Win32k
Channel
Messages
Task
TouchTargetingPointerEvent

Fields #

NameDescription
pointerId Int32
cursorId Int32
pointerType Int32
pointerFlags Int32
touchMask Int32
ptLocationX Int32
ptLocationY Int32
rcContactLeft Int32
rcContactRight Int32
rcContactTop Int32
rcContactBottom Int32
orientation Int32

Event ID 108: TouchTargetingPointerEvent108

#
Provider
Microsoft-Windows-Win32k
Channel
Messages
Task
TouchTargetingPointerEvent

Fields #

NameDescription
pointerId Int32
cursorId Int32
pointerType Int32
pointerFlags Int32
touchMask Int32
ptLocationX Int32
ptLocationY Int32
rcContactLeft Int32
rcContactRight Int32
rcContactTop Int32
rcContactBottom Int32
orientation Int32

Event ID 109: PointerDeviceReadStart

#
Provider
Microsoft-Windows-Win32k
Channel
Messages
Task
PointerDeviceRead
Opcode
Start

Event ID 110: PointerDeviceReadStop

#
Provider
Microsoft-Windows-Win32k
Channel
Messages
Task
PointerDeviceRead
Opcode
Stop

Event ID 111: PointerDeviceMessageStart

#
Provider
Microsoft-Windows-Win32k
Channel
Messages
Task
PointerDeviceMessage
Opcode
Start

Event ID 112: PointerDeviceMessageStop

#
Provider
Microsoft-Windows-Win32k
Channel
Messages
Task
PointerDeviceMessage
Opcode
Stop

Event ID 113: PointerDeviceMessageStart113

#
Provider
Microsoft-Windows-Win32k
Channel
Messages
Task
PointerDeviceMessage
Opcode
Start

Event ID 114: PointerDeviceMessageStop114

#
Provider
Microsoft-Windows-Win32k
Channel
Messages
Task
PointerDeviceMessage
Opcode
Stop

Event ID 115: PointerDeviceTransformationStart

#
Provider
Microsoft-Windows-Win32k
Channel
Messages
Task
PointerDeviceTransformation
Opcode
Start

Fields #

NameDescription
ulContactId UInt32

Event ID 116: PointerDeviceTransformationStop

#
Provider
Microsoft-Windows-Win32k
Channel
Messages
Task
PointerDeviceTransformation
Opcode
Stop

Fields #

NameDescription
ulContactId UInt32

Event ID 117: RenderingTranslationUpdate

#
Provider
Microsoft-Windows-Win32k
Channel
Render
Task
Rendering
Opcode
TranslationUpdate

Fields #

NameDescription
hwnd Pointer
DirtyLeft UInt32
DirtyTop UInt32
DirtyRight UInt32
DirtyBottom UInt32

Event ID 118: TranslationUpdateOffset

#
Provider
Microsoft-Windows-Win32k
Channel
Render
Task
TranslationUpdateOffset

Fields #

NameDescription
hwnd Pointer
Offsetx Int32
Offsety Int32

Event ID 119: RenderingTranslationUpdateRectClip

#
Provider
Microsoft-Windows-Win32k
Channel
Render
Task
Rendering
Opcode
TranslationUpdateRectClip

Fields #

NameDescription
hwnd Pointer
DirtyLeft UInt32
DirtyTop UInt32
DirtyRight UInt32
DirtyBottom UInt32

Event ID 120: RenderingUpdateDxAccumFromGDI

#
Provider
Microsoft-Windows-Win32k
Channel
Render
Task
Rendering
Opcode
UpdateDxAccumFromGDI

Fields #

NameDescription
hwnd Pointer
DirtyLeft UInt32
DirtyTop UInt32
DirtyRight UInt32
DirtyBottom UInt32

Event ID 121: RenderingUpdateDxAccumFromDX

#
Provider
Microsoft-Windows-Win32k
Channel
Render
Task
Rendering
Opcode
UpdateDxAccumFromDX

Fields #

NameDescription
hwnd Pointer
DirtyLeft UInt32
DirtyTop UInt32
DirtyRight UInt32
DirtyBottom UInt32

Event ID 122: RenderingGetDxAccum

#
Provider
Microsoft-Windows-Win32k
Channel
Render
Task
Rendering
Opcode
GetDxAccum

Fields #

NameDescription
hSprite UInt64
hWnd Pointer

Event ID 123: ModifyDxAccumRgn

#
Provider
Microsoft-Windows-Win32k
Channel
Tracing
Task
ModifyDxAccumRgn

Fields #

NameDescription
hLogicalSurface UInt64
RgnType UInt32
rcBounds Int16
NumRects UInt32
rcData Int64

Event ID 124: LogicalSurfRemovedTranslationFromDirty

#
Provider
Microsoft-Windows-Win32k
Channel
Tracing
Task
LogicalSurfRemovedTranslationFromDirty

Fields #

NameDescription
hwnd Pointer
DirtyLeft UInt32
DirtyTop UInt32
DirtyRight UInt32
DirtyBottom UInt32

Event ID 125: PointerDeviceDiscoveryStart

#
Provider
Microsoft-Windows-Win32k
Channel
Messages
Task
PointerDeviceDiscovery
Opcode
Start

Event ID 126: PointerDeviceDiscoveryStop

#
Provider
Microsoft-Windows-Win32k
Channel
Messages
Task
PointerDeviceDiscovery
Opcode
Stop

Event ID 127: PointerDeviceMessageStart127

#
Provider
Microsoft-Windows-Win32k
Channel
Messages
Task
PointerDeviceMessage
Opcode
Start

Event ID 128: PointerDeviceMessageStop128

#
Provider
Microsoft-Windows-Win32k
Channel
Messages
Task
PointerDeviceMessage
Opcode
Stop

Event ID 129: TouchInjectionEventStart

#
Provider
Microsoft-Windows-Win32k
Channel
Messages
Task
TouchInjectionEvent
Opcode
Start

Event ID 130: TouchInjectionEventStop

#
Provider
Microsoft-Windows-Win32k
Channel
Messages
Task
TouchInjectionEvent
Opcode
Stop

Event ID 131: PointerFrameCreationStart

#
Provider
Microsoft-Windows-Win32k
Channel
Messages
Task
PointerFrameCreation
Opcode
Start

Fields #

NameDescription
FrameId UInt32
PointerCount UInt32
PendingPointerCount UInt32

Event ID 132: PointerFrameCreationStop

#
Provider
Microsoft-Windows-Win32k
Channel
Messages
Task
PointerFrameCreation
Opcode
Stop

Fields #

NameDescription
FrameId UInt32
PointerCount UInt32
PendingPointerCount UInt32

Event ID 133: PointerFrameBuildPartialStart

#
Provider
Microsoft-Windows-Win32k
Channel
Messages
Task
PointerFrameBuildPartial
Opcode
Start

Fields #

NameDescription
FrameId UInt32
PointerCount UInt32
PendingPointerCount UInt32

Event ID 134: PointerFrameBuildPartialStop

#
Provider
Microsoft-Windows-Win32k
Channel
Messages
Task
PointerFrameBuildPartial
Opcode
Stop

Fields #

NameDescription
FrameId UInt32
PointerCount UInt32
PendingPointerCount UInt32

Event ID 135: PointerFrameCommitStart

#
Provider
Microsoft-Windows-Win32k
Channel
Messages
Task
PointerFrameCommit
Opcode
Start

Fields #

NameDescription
FrameId UInt32
PointerCount UInt32
PendingPointerCount UInt32

Event ID 136: PointerFrameCommitStop

#
Provider
Microsoft-Windows-Win32k
Channel
Messages
Task
PointerFrameCommit
Opcode
Stop

Fields #

NameDescription
FrameId UInt32
PointerCount UInt32
PendingPointerCount UInt32

Event ID 137: PointerFrameCoalesceStart

#
Provider
Microsoft-Windows-Win32k
Channel
Messages
Task
PointerFrameCoalesce
Opcode
Start

Fields #

NameDescription
FrameId UInt32
PointerCount UInt32
PendingPointerCount UInt32

Event ID 138: PointerFrameCoalesceStop

#
Provider
Microsoft-Windows-Win32k
Channel
Messages
Task
PointerFrameCoalesce
Opcode
Stop

Fields #

NameDescription
FrameId UInt32
PointerCount UInt32
PendingPointerCount UInt32

Event ID 139: PointerFrameMessageGenerationStart

#
Provider
Microsoft-Windows-Win32k
Channel
Messages
Task
PointerFrameMessageGeneration
Opcode
Start

Fields #

NameDescription
FrameId UInt32
PointerCount UInt32
PendingPointerCount UInt32

Event ID 140: PointerFrameMessageGenerationStop

#
Provider
Microsoft-Windows-Win32k
Channel
Messages
Task
PointerFrameMessageGeneration
Opcode
Stop

Fields #

NameDescription
FrameId UInt32
PointerCount UInt32
PendingPointerCount UInt32

Event ID 141: PointerMessageRetrieveStart

#
Provider
Microsoft-Windows-Win32k
Channel
Messages
Task
PointerMessageRetrieve
Opcode
Start

Fields #

NameDescription
pqmsg Pointer
PointerId UInt32
Message UInt32

Event ID 142: PointerMessageRetrieveStop

#
Provider
Microsoft-Windows-Win32k
Channel
Messages
Task
PointerMessageRetrieve
Opcode
Stop

Fields #

NameDescription
pqmsg Pointer
PointerId UInt32
Message UInt32

Event ID 143: PointerUpdateMessageRetrieveStart

#
Provider
Microsoft-Windows-Win32k
Channel
Messages
Task
PointerUpdateMessageRetrieve
Opcode
Start

Fields #

NameDescription
pqmsg Pointer
PointerId UInt32
Message UInt32

Event ID 144: PointerUpdateMessageRetrieveStop

#
Provider
Microsoft-Windows-Win32k
Channel
Messages
Task
PointerUpdateMessageRetrieve
Opcode
Stop

Fields #

NameDescription
pqmsg Pointer
PointerId UInt32
Message UInt32

Event ID 145: PointerSetTargetWindowsStart

#
Provider
Microsoft-Windows-Win32k
Channel
Messages
Task
PointerSetTargetWindows
Opcode
Start

Event ID 146: PointerSetTargetWindowsStop

#
Provider
Microsoft-Windows-Win32k
Channel
Messages
Task
PointerSetTargetWindows
Opcode
Stop

Event ID 147: PointerUpdateSetTargetWindowsStart

#
Provider
Microsoft-Windows-Win32k
Channel
Messages
Task
PointerUpdateSetTargetWindows
Opcode
Start

Event ID 148: PointerUpdateSetTargetWindowsStop

#
Provider
Microsoft-Windows-Win32k
Channel
Messages
Task
PointerUpdateSetTargetWindows
Opcode
Stop

Event ID 149: InputQueueNoRemoveLockerStop

#
Provider
Microsoft-Windows-Win32k
Channel
Messages
Task
InputQueueNoRemoveLocker
Opcode
Stop

Fields #

NameDescription
CallbackCount Int8
pQueue Pointer
ownerThread UInt32

Event ID 150: InputQueueLockedPeekRecursionStop

#
Provider
Microsoft-Windows-Win32k
Channel
Messages
Task
InputQueueLockedPeekRecursion
Opcode
Stop

Fields #

NameDescription
CallbackCount Int8
pQueue Pointer
ownerThread UInt32

Event ID 151: DCompCommitBatch

#
Provider
Microsoft-Windows-Win32k
Channel
Tracing
Also via
realtime ETW trace
Level
Informational
Task
DCompCommitBatch
Opcode
win:Info

Fields #

NameDescription
channelHandle UInt32
pBatch Pointer
batchID UInt32
isNinja Boolean

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Win32k",
    "guid": "{8C416C79-D49B-4F01-A467-E56D3AA8234C}",
    "event_source_name": "",
    "event_id": 151,
    "version": 0,
    "level": 4,
    "task": 107,
    "opcode": 0,
    "keywords": "0x0000000400001000",
    "time_created": "2026-06-02T06:08:00.231+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{8C416C79-D49B-4F01-A467-E56D3AA8234C}"
    },
    "execution": {
      "process_id": 5396,
      "thread_id": 3744
    },
    "channel": "ETW Trace",
    "computer": "DESKTOP-FF3N5XK",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "batchID": 24923,
    "channelHandle": 15,
    "isNinja": false,
    "pBatch": "0xFFFF990EE77329B0"
  },
  "message": "DCompCommitBatch"
}

Event ID 152: DelegateInputUserCallbackStart

#
Provider
Microsoft-Windows-Win32k
Channel
Messages
Task
DelegateInputUserCallback
Opcode
Start

Fields #

NameDescription
CallbackCount Int8
pqmsg Pointer
WindowDelegated Boolean
WasWindowDelegated Boolean
Delegated Boolean
WasDelegated Boolean
Processed Boolean
fDelayedFree Boolean
hwnd Pointer
WParam Pointer
LParam Pointer
message UInt32
inputReadyTimeMs UInt32

Event ID 153: DelegateInputUserCallbackStop

#
Provider
Microsoft-Windows-Win32k
Channel
Messages
Task
DelegateInputUserCallback
Opcode
Stop

Fields #

NameDescription
CallbackCount Int8
pqmsg Pointer
WindowDelegated Boolean
WasWindowDelegated Boolean
Delegated Boolean
WasDelegated Boolean
Processed Boolean
fDelayedFree Boolean
hwnd Pointer
WParam Pointer
LParam Pointer
message UInt32
inputReadyTimeMs UInt32

Event ID 154: DelegatedInputWorkerStart

#
Provider
Microsoft-Windows-Win32k
Channel
Messages
Task
DelegatedInputWorker
Opcode
Start

Fields #

NameDescription
CallbackCount Int8
pqmsg Pointer
WindowDelegated Boolean
WasWindowDelegated Boolean
Delegated Boolean
WasDelegated Boolean
Processed Boolean
fDelayedFree Boolean
hwnd Pointer
WParam Pointer
LParam Pointer
message UInt32
inputReadyTimeMs UInt32
hdfResponse UInt32

Event ID 155: DelegatedInputWorkerStop

#
Provider
Microsoft-Windows-Win32k
Channel
Messages
Task
DelegatedInputWorker
Opcode
Stop

Fields #

NameDescription
CallbackCount Int8
pqmsg Pointer
WindowDelegated Boolean
WasWindowDelegated Boolean
Delegated Boolean
WasDelegated Boolean
Processed Boolean
fDelayedFree Boolean
hwnd Pointer
WParam Pointer
LParam Pointer
message UInt32
inputReadyTimeMs UInt32
hdfResponse UInt32

Event ID 156: PointerDeviceMessage

#
Provider
Microsoft-Windows-Win32k
Channel
Messages
Task
PointerDeviceMessage

Fields #

NameDescription
bNew UInt32
ulContactId UInt32
dwCursorId UInt32
X Int32
Y Int32

Event ID 157: PointerMessageGenerationStart

#
Provider
Microsoft-Windows-Win32k
Channel
Messages
Task
PointerMessageGeneration
Opcode
Start

Fields #

NameDescription
wCursorId UInt16
wPointerId UInt16

Event ID 158: PointerMessageGenerationStop

#
Provider
Microsoft-Windows-Win32k
Channel
Messages
Task
PointerMessageGeneration
Opcode
Stop

Fields #

NameDescription
wCursorId UInt16
wPointerId UInt16

Event ID 159: PointerFrameCoalesce

#
Provider
Microsoft-Windows-Win32k
Channel
Messages
Task
PointerFrameCoalesce

Fields #

NameDescription
wCursorId UInt16
wPointerId UInt16
dwReason UInt32

Event ID 160: SmoothRotationStart

#
Provider
Microsoft-Windows-Win32k
Channel
Tracing
Task
SmoothRotation
Opcode
Start

Fields #

NameDescription
Orientation UInt32
SensorOriginated Boolean
ActiveProcessId UInt32

Event ID 161: SmoothRotationStop

#
Provider
Microsoft-Windows-Win32k
Channel
Tracing
Task
SmoothRotation
Opcode
Stop

Fields #

NameDescription
Orientation UInt32
SensorOriginated Boolean

Event ID 162: DCompGetBatch

#
Provider
Microsoft-Windows-Win32k
Channel
Tracing
Also via
realtime ETW trace
Level
Informational
Task
DCompGetBatch
Opcode
win:Info

Fields #

NameDescription
pBatch Pointer

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Win32k",
    "guid": "{8C416C79-D49B-4F01-A467-E56D3AA8234C}",
    "event_source_name": "",
    "event_id": 162,
    "version": 0,
    "level": 4,
    "task": 111,
    "opcode": 0,
    "keywords": "0x0000000400001000",
    "time_created": "2026-06-02T06:08:00.242+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{8C416C79-D49B-4F01-A467-E56D3AA8234C}"
    },
    "execution": {
      "process_id": 1168,
      "thread_id": 1236
    },
    "channel": "ETW Trace",
    "computer": "DESKTOP-FF3N5XK",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "pBatch": "0xFFFF990EE77329B0"
  },
  "message": "DCompGetBatch"
}

Event ID 163: ExclusiveUserCrit

#
Provider
Microsoft-Windows-Win32k
Channel
Contention
Task
ExclusiveUserCrit

Fields #

NameDescription
AcquireQpcCounts UInt64
AcquireTimeUs UInt32
Token UInt64

Event ID 164: ExclusiveUserCrit

#
Provider
Microsoft-Windows-Win32k
Channel
Contention
Also via
realtime ETW trace
Level
Informational
Task
ExclusiveUserCrit
Opcode
win:Info

Fields #

NameDescription
AcquireQpcCounts UInt64
AcquireTimeUs UInt32
Token UInt64

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Win32k",
    "guid": "{8C416C79-D49B-4F01-A467-E56D3AA8234C}",
    "event_source_name": "",
    "event_id": 164,
    "version": 0,
    "level": 4,
    "task": 113,
    "opcode": 0,
    "keywords": "0x0200000010000000",
    "time_created": "2026-06-02T05:32:24.458+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{8C416C79-D49B-4F01-A467-E56D3AA8234C}"
    },
    "execution": {
      "process_id": 6296,
      "thread_id": 3488
    },
    "channel": "ETW Trace",
    "computer": "JD-DC01-2022",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "AcquireQpcCounts": 5,
    "AcquireTimeUs": 0,
    "Token": 267
  },
  "message": "ExclusiveUserCrit"
}

Event ID 165: SharedUserCrit

#
Provider
Microsoft-Windows-Win32k
Channel
Contention
Task
SharedUserCrit

Fields #

NameDescription
AcquireQpcCounts UInt64
AcquireTimeUs UInt32
Token UInt64

Event ID 166: SharedUserCrit

#
Provider
Microsoft-Windows-Win32k
Channel
Contention
Also via
realtime ETW trace
Level
Informational
Task
SharedUserCrit
Opcode
win:Info

Fields #

NameDescription
AcquireQpcCounts UInt64
AcquireTimeUs UInt32
Token UInt64

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Win32k",
    "guid": "{8C416C79-D49B-4F01-A467-E56D3AA8234C}",
    "event_source_name": "",
    "event_id": 166,
    "version": 0,
    "level": 4,
    "task": 114,
    "opcode": 0,
    "keywords": "0x0200000010000000",
    "time_created": "2026-06-02T05:32:24.458+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{8C416C79-D49B-4F01-A467-E56D3AA8234C}"
    },
    "execution": {
      "process_id": 6296,
      "thread_id": 6300
    },
    "channel": "ETW Trace",
    "computer": "JD-DC01-2022",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "AcquireQpcCounts": 4,
    "AcquireTimeUs": 0,
    "Token": 270
  },
  "message": "SharedUserCrit"
}

Event ID 167: ReleaseUserCrit

#
Provider
Microsoft-Windows-Win32k
Channel
Contention
Also via
realtime ETW trace
Level
Informational
Task
ReleaseUserCrit
Opcode
win:Info

Fields #

NameDescription
HoldQpcCounts UInt64
HoldTimeMs UInt32
Token UInt64

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Win32k",
    "guid": "{8C416C79-D49B-4F01-A467-E56D3AA8234C}",
    "event_source_name": "",
    "event_id": 167,
    "version": 0,
    "level": 4,
    "task": 115,
    "opcode": 0,
    "keywords": "0x0200000010000000",
    "time_created": "2026-06-02T05:32:24.458+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{8C416C79-D49B-4F01-A467-E56D3AA8234C}"
    },
    "execution": {
      "process_id": 6296,
      "thread_id": 3488
    },
    "channel": "ETW Trace",
    "computer": "JD-DC01-2022",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "HoldQpcCounts": 1895,
    "HoldTimeMs": 0,
    "Token": 268
  },
  "message": "ReleaseUserCrit"
}

Event ID 168: SleepInputIdle

#
Provider
Microsoft-Windows-Win32k
Channel
Messages
Also via
realtime ETW trace
Level
Informational
Task
SleepInputIdle
Opcode
win:Info

Fields #

NameDescription
pti Pointer

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Win32k",
    "guid": "{8C416C79-D49B-4F01-A467-E56D3AA8234C}",
    "event_source_name": "",
    "event_id": 168,
    "version": 0,
    "level": 4,
    "task": 116,
    "opcode": 0,
    "keywords": "0x0400000000800000",
    "time_created": "2026-06-02T05:32:24.458+00:00",
    "event_record_id": 0,
    "correlation": {},
    "execution": {
      "process_id": 6296,
      "thread_id": 6300
    },
    "channel": "ETW Trace",
    "computer": "JD-DC01-2022",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "pti": "0xFFFFC5238447A010"
  },
  "message": "SleepInputIdle"
}

Event ID 169: WakeInputIdle

#
Provider
Microsoft-Windows-Win32k
Channel
Messages
Also via
realtime ETW trace
Level
Informational
Task
WakeInputIdle
Opcode
win:Info

Fields #

NameDescription
pti Pointer

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Win32k",
    "guid": "{8C416C79-D49B-4F01-A467-E56D3AA8234C}",
    "event_source_name": "",
    "event_id": 169,
    "version": 0,
    "level": 4,
    "task": 117,
    "opcode": 0,
    "keywords": "0x0400000000800000",
    "time_created": "2026-06-02T05:32:24.458+00:00",
    "event_record_id": 0,
    "correlation": {},
    "execution": {
      "process_id": 6296,
      "thread_id": 6300
    },
    "channel": "ETW Trace",
    "computer": "JD-DC01-2022",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "pti": "0xFFFFC5238447A010"
  },
  "message": "WakeInputIdle"
}

Event ID 170: EdgyDetectionStart

#
Provider
Microsoft-Windows-Win32k
Channel
Tracing
Task
EdgyDetection
Opcode
Start

Event ID 171: EdgyDetectionStop

#
Provider
Microsoft-Windows-Win32k
Channel
Tracing
Task
EdgyDetection
Opcode
Stop

Fields #

NameDescription
Info UInt32

Event ID 172: ImmersiveInputProcessDelay

#
Provider
Microsoft-Windows-Win32k
Channel
Tracing
Task
ImmersiveInputProcessDelay

Fields #

NameDescription
Flags UInt32
TimeSinceInputRemoveMs UInt32
TimeSinceOldestInputMs UInt32
ClassName UnicodeString
TopLevelClassName UnicodeString
PackageMoniker UnicodeString
AppUserModelId UnicodeString
MessageId UInt32
WParam UInt64

Event ID 173: ImmersiveMessageCheckDelay

#
Provider
Microsoft-Windows-Win32k
Channel
Tracing
Task
ImmersiveMessageCheckDelay

Fields #

NameDescription
Flags UInt32
DelayTimeMs UInt32
TimeSinceInputRemoveMs UInt32
TimeSinceOldestInputMs UInt32
ClassName UnicodeString
TopLevelClassName UnicodeString
PackageMoniker UnicodeString
AppUserModelId UnicodeString
MessageId UInt32
WParam UInt64

Event ID 174: THQAEventStart

#
Provider
Microsoft-Windows-Win32k
Channel
Messages
Task
THQAEvent
Opcode
Start

Event ID 175: THQAEventStop

#
Provider
Microsoft-Windows-Win32k
Channel
Messages
Task
THQAEvent
Opcode
Stop

Event ID 176: PointerPredictionStart

#
Provider
Microsoft-Windows-Win32k
Channel
Messages
Task
PointerPrediction
Opcode
Start

Fields #

NameDescription
ulContactId UInt32

Event ID 177: PointerPredictionStop

#
Provider
Microsoft-Windows-Win32k
Channel
Messages
Task
PointerPrediction
Opcode
Stop

Fields #

NameDescription
ulContactId UInt32

Event ID 178: MoveRgn

#
Provider
Microsoft-Windows-Win32k
Channel
Tracing
Task
MoveRgn

Fields #

NameDescription
hLogicalSurface UInt64
RgnType UInt32
rcBounds Int16
NumRects UInt32
rcData Int64

Event ID 179: DirtyRgn

#
Provider
Microsoft-Windows-Win32k
Channel
Tracing
Task
DirtyRgn

Fields #

NameDescription
hLogicalSurface UInt64
RgnType UInt32
rcBounds Int16
NumRects UInt32
rcData Int64

Event ID 180: LogicalSurfRemovedTranslationFromMove

#
Provider
Microsoft-Windows-Win32k
Channel
Tracing
Task
LogicalSurfRemovedTranslationFromMove

Fields #

NameDescription
hwnd Pointer
DirtyLeft UInt32
DirtyTop UInt32
DirtyRight UInt32
DirtyBottom UInt32

Event ID 181: DirtyRectUpdate

#
Provider
Microsoft-Windows-Win32k
Channel
Tracing
Also via
realtime ETW trace
Level
Informational
Task
DirtyRectUpdate
Opcode
win:Info

Fields #

NameDescription
hwnd Pointer
DirtyLeft UInt32
DirtyTop UInt32
DirtyRight UInt32
DirtyBottom UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Win32k",
    "guid": "{8C416C79-D49B-4F01-A467-E56D3AA8234C}",
    "event_source_name": "",
    "event_id": 181,
    "version": 0,
    "level": 4,
    "task": 127,
    "opcode": 0,
    "keywords": "0x0000000000001000",
    "time_created": "2026-06-02T04:02:00.030+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{8C416C79-D49B-4F01-A467-E56D3AA8234C}"
    },
    "execution": {
      "process_id": 4304,
      "thread_id": 3088
    },
    "channel": "ETW Trace",
    "computer": "JD-DC01-2022",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "DirtyBottom": 40,
    "DirtyLeft": 907,
    "DirtyRight": 971,
    "DirtyTop": 0,
    "hwnd": "0x4120632"
  },
  "message": "DirtyRectUpdate"
}

Event ID 182: TranslationUpdateOffsetDWM

#
Provider
Microsoft-Windows-Win32k
Channel
Tracing
Task
TranslationUpdateOffsetDWM

Fields #

NameDescription
hwnd Pointer
Offsetx Int32
Offsety Int32

Event ID 183: DwmGetRgn

#
Provider
Microsoft-Windows-Win32k
Channel
Tracing
Task
DwmGetRgn

Fields #

NameDescription
hLogicalSurface UInt64
RgnType UInt32
rcBounds Int16
NumRects UInt32
rcData Int64

Event ID 184: PointerFrameCoalesceStart184

#
Provider
Microsoft-Windows-Win32k
Channel
Messages
Task
PointerFrameCoalesce
Opcode
Start

Fields #

NameDescription
FrameId UInt32
PointerCount UInt32
PendingPointerCount UInt32

Event ID 185: PointerFrameCoalesceStop185

#
Provider
Microsoft-Windows-Win32k
Channel
Messages
Task
PointerFrameCoalesce
Opcode
Stop

Fields #

NameDescription
FrameId UInt32
PointerCount UInt32
PendingPointerCount UInt32

Event ID 186: PointerFrameCoalesce186

#
Provider
Microsoft-Windows-Win32k
Channel
Messages
Task
PointerFrameCoalesce

Fields #

NameDescription
wCursorId UInt16
wPointerId UInt16
dwReason UInt32

Event ID 187: InternalSetTimerCoalescing

#
Provider
Microsoft-Windows-Win32k
Channel
Tracing
Also via
realtime ETW trace
Level
Informational
Task
InternalSetTimerCoalescing
Opcode
win:Info

Fields #

NameDescription
Hwnd Pointer
uId UInt32
uElapse UInt32
uCoalescingTolerance UInt32
uType UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Win32k",
    "guid": "{8C416C79-D49B-4F01-A467-E56D3AA8234C}",
    "event_source_name": "",
    "event_id": 187,
    "version": 0,
    "level": 4,
    "task": 130,
    "opcode": 0,
    "keywords": "0x0000000020000000",
    "time_created": "2026-06-02T05:32:25.745+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{8C416C79-D49B-4F01-A467-E56D3AA8234C}"
    },
    "execution": {
      "process_id": 14592,
      "thread_id": 12892
    },
    "channel": "ETW Trace",
    "computer": "JD-DC01-2022",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Hwnd": "0x0",
    "uCoalescingTolerance": 0,
    "uElapse": 35000,
    "uId": 32766,
    "uType": 540
  },
  "message": "InternalSetTimerCoalescing"
}

Event ID 188: InternalSetTimerNoCoalescing

#
Provider
Microsoft-Windows-Win32k
Channel
Tracing
Task
InternalSetTimerNoCoalescing

Fields #

NameDescription
Hwnd Pointer
uId UInt32
uElapse UInt32
uType UInt32

Event ID 189: KillTimer

#
Provider
Microsoft-Windows-Win32k
Channel
Tracing
Also via
realtime ETW trace
Level
Informational
Task
KillTimer
Opcode
win:Info

Fields #

NameDescription
Hwnd Pointer
uId UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Win32k",
    "guid": "{8C416C79-D49B-4F01-A467-E56D3AA8234C}",
    "event_source_name": "",
    "event_id": 189,
    "version": 0,
    "level": 4,
    "task": 132,
    "opcode": 0,
    "keywords": "0x0000000020000000",
    "time_created": "2026-06-02T04:02:01.046+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{8C416C79-D49B-4F01-A467-E56D3AA8234C}"
    },
    "execution": {
      "process_id": 4304,
      "thread_id": 3088
    },
    "channel": "ETW Trace",
    "computer": "JD-DC01-2022",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Hwnd": "0x0",
    "uId": 23933
  },
  "message": "KillTimer"
}

Event ID 190: ProcTimerCoalescing

#
Provider
Microsoft-Windows-Win32k
Channel
Tracing
Also via
realtime ETW trace
Level
Informational
Task
ProcTimerCoalescing
Opcode
win:Info

Fields #

NameDescription
Hwnd Pointer
uId UInt32
uElapse UInt32
uCoalescingTolerance UInt32
uType UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Win32k",
    "guid": "{8C416C79-D49B-4F01-A467-E56D3AA8234C}",
    "event_source_name": "",
    "event_id": 190,
    "version": 0,
    "level": 4,
    "task": 133,
    "opcode": 0,
    "keywords": "0x0000000020000000",
    "time_created": "2026-06-02T05:32:25.246+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{8C416C79-D49B-4F01-A467-E56D3AA8234C}"
    },
    "execution": {
      "process_id": 1004,
      "thread_id": 1112
    },
    "channel": "ETW Trace",
    "computer": "JD-DC01-2022",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Hwnd": "0x0",
    "uCoalescingTolerance": 0,
    "uElapse": 1000,
    "uId": 32766,
    "uType": 516
  },
  "message": "ProcTimerCoalescing"
}

Event ID 191: ProcTimerNoCoalescing

#
Provider
Microsoft-Windows-Win32k
Channel
Tracing
Task
ProcTimerNoCoalescing

Fields #

NameDescription
Hwnd Pointer
uId UInt32
uElapse UInt32
uType UInt32

Event ID 192: DrvChangeDisplaySettingsStart

#
Provider
Microsoft-Windows-Win32k
Channel
Tracing
Task
DrvChangeDisplaySettings
Opcode
Start

Event ID 193: DrvChangeDisplaySettingsStop

#
Provider
Microsoft-Windows-Win32k
Channel
Tracing
Task
DrvChangeDisplaySettings
Opcode
Stop

Event ID 194: ChangeDisplayModeStart

#
Provider
Microsoft-Windows-Win32k
Channel
Tracing
Task
ChangeDisplayMode
Opcode
Start

Event ID 195: ChangeDisplayModeStop

#
Provider
Microsoft-Windows-Win32k
Channel
Tracing
Task
ChangeDisplayMode
Opcode
Stop

Event ID 196: PseudoDevCreationStart

#
Provider
Microsoft-Windows-Win32k
Channel
Messages
Task
PseudoDevCreation
Opcode
Start

Event ID 197: PseudoDevCreationStop

#
Provider
Microsoft-Windows-Win32k
Channel
Messages
Task
PseudoDevCreation
Opcode
Stop

Event ID 198: TouchHWTimeStamp

#
Provider
Microsoft-Windows-Win32k
Channel
Messages
Task
TouchHWTimeStamp

Fields #

NameDescription
ScanTime Int32
dwTime Int32
QPC UInt64
XRawPosition Int32
YRawPosition Int32
XPredictedPosition Int32
YPredictedPosition Int32

Event ID 199: PointerFrameCoalesce199

#
Provider
Microsoft-Windows-Win32k
Channel
Messages
Task
PointerFrameCoalesce

Fields #

NameDescription
wCursorId UInt16
wPointerId UInt16
dwReason UInt32

Event ID 200: PointerFrameCoalesce200

#
Provider
Microsoft-Windows-Win32k
Channel
Messages
Task
PointerFrameCoalesce

Fields #

NameDescription
wCursorId UInt16
wPointerId UInt16
dwReason UInt32

Event ID 201: TokenCompositionSurfaceObject_V1

#
Provider
Microsoft-Windows-Win32k
Channel
Tracing
Task
TokenCompositionSurfaceObject

Fields #

NameDescription
pToken Pointer
pCompositionSurfaceObject Pointer
SwapChainIndex UInt32
PresentCount UInt64
CompositionSurfaceLuid UInt64
BindId UInt64
FlipInterval UInt32
DestWidth UInt32
DestHeight UInt32

Event ID 202: CompositionSurfaceObjectUpdate

#
Provider
Microsoft-Windows-Win32k
Channel
Tracing
Task
CompositionSurfaceObjectUpdate

Fields #

NameDescription
pCompositionSurfaceObject Pointer
SwapChainIndex UInt32

Event ID 203: QueueEventMessage

#
Provider
Microsoft-Windows-Win32k
Channel
Messages
Also via
realtime ETW trace
Level
Informational
Task
QueueEventMessage
Opcode
win:Info

Fields #

NameDescription
CallbackCount Int8
pqmsg Pointer
pti Pointer
dwQEvent UInt32
hwnd Pointer

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Win32k",
    "guid": "{8C416C79-D49B-4F01-A467-E56D3AA8234C}",
    "event_source_name": "",
    "event_id": 203,
    "version": 0,
    "level": 4,
    "task": 140,
    "opcode": 0,
    "keywords": "0x0400000000800000",
    "time_created": "2026-06-02T06:08:00.227+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{8C416C79-D49B-4F01-A467-E56D3AA8234C}"
    },
    "execution": {
      "process_id": 5396,
      "thread_id": 3744
    },
    "channel": "ETW Trace",
    "computer": "DESKTOP-FF3N5XK",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "CallbackCount": 1,
    "dwQEvent": 9,
    "hwnd": "0x200D2",
    "pqmsg": "0xFFFF990F043BDD00",
    "pti": "0x0"
  },
  "message": "QueueEventMessage"
}

Event ID 204: RetrieveQueueEventMessage

#
Provider
Microsoft-Windows-Win32k
Channel
Messages
Also via
realtime ETW trace
Level
Informational
Task
RetrieveQueueEventMessage
Opcode
win:Info

Fields #

NameDescription
CallbackCount Int8
pqmsg Pointer
pti Pointer
dwQEvent UInt32
hwnd Pointer

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Win32k",
    "guid": "{8C416C79-D49B-4F01-A467-E56D3AA8234C}",
    "event_source_name": "",
    "event_id": 204,
    "version": 0,
    "level": 4,
    "task": 141,
    "opcode": 0,
    "keywords": "0x0400000000800000",
    "time_created": "2026-06-02T06:08:00.228+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{8C416C79-D49B-4F01-A467-E56D3AA8234C}"
    },
    "execution": {
      "process_id": 5396,
      "thread_id": 3744
    },
    "channel": "ETW Trace",
    "computer": "DESKTOP-FF3N5XK",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "CallbackCount": 0,
    "dwQEvent": 9,
    "hwnd": "0x200D2",
    "pqmsg": "0xFFFF990F043BDD00",
    "pti": "0xFFFF990EFF42E720"
  },
  "message": "RetrieveQueueEventMessage"
}

Event ID 205: ForegroundWindowFullScreenStart

#
Provider
Microsoft-Windows-Win32k
Channel
Tracing
Task
ForegroundWindowFullScreen
Opcode
Start

Event ID 206: ForegroundWindowFullScreenStop

#
Provider
Microsoft-Windows-Win32k
Channel
Tracing
Task
ForegroundWindowFullScreen
Opcode
Stop

Event ID 207: ChangeDisplayModeBroadcast

#
Provider
Microsoft-Windows-Win32k
Channel
Tracing
Task
ChangeDisplayModeBroadcast

Event ID 213: ContactVisualization

#
Provider
Microsoft-Windows-Win32k
Channel
Tracing
Task
ContactVisualization

Fields #

NameDescription
data UInt32

Event ID 214: ChangeDisplayModeDeferral

#
Provider
Microsoft-Windows-Win32k
Channel
Tracing
Task
ChangeDisplayModeDeferral

Event ID 215: ConvertibleState

#
Provider
Microsoft-Windows-Win32k
Channel
Tracing
Task
ConvertibleState

Fields #

NameDescription
ConvertibleState UInt32

Event ID 216: DockState

#
Provider
Microsoft-Windows-Win32k
Channel
Tracing
Task
DockState

Fields #

NameDescription
DockState UInt32

Event ID 217: TouchPadHWTimeStamp

#
Provider
Microsoft-Windows-Win32k
Channel
Tracing
Task
TouchPadHWTimeStamp

Fields #

NameDescription
ScanTime UInt32
dwTime UInt32
QPCTime UInt64
XLogicalT UInt32
YLogicalT UInt32
XLogicalC UInt32
YLogicalC UInt32
XHimetricT UInt32
YHimetricT UInt32
Button Boolean
Count UInt32
Identifier UInt32
Width UInt32
Height UInt32
Confidence Boolean
Pressure UInt32
DeviceType UInt32

Event ID 218: TransformAgeDecay

#
Provider
Microsoft-Windows-Win32k
Channel
Tracing
Task
TransformAgeDecay

Fields #

NameDescription
InputTransformList Pointer
PerformanceCount UInt64

Event ID 219: WakeMIT

#
Provider
Microsoft-Windows-Win32k
Channel
Messages
Task
WakeMIT

Fields #

NameDescription
CallbackCount Int8
WakeReason Int32

Event ID 220: ArmDitMouseFlush

#
Provider
Microsoft-Windows-Win32k
Channel
Messages
Task
ArmDitMouseFlush

Event ID 221: ProcessQueuedMouseEvents

#
Provider
Microsoft-Windows-Win32k
Channel
Messages
Level
Informational
Task
ProcessQueuedMouseEvents
Opcode
Start

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Win32k",
    "guid": "{8C416C79-D49B-4F01-A467-E56D3AA8234C}",
    "event_source_name": "",
    "event_id": 221,
    "version": 0,
    "level": 4,
    "task": 216,
    "opcode": 1,
    "keywords": "0x0400000040800000",
    "time_created": "2026-06-02T05:32:25.759+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{8C416C79-D49B-4F01-A467-E56D3AA8234C}"
    },
    "execution": {
      "process_id": 952,
      "thread_id": 1048
    },
    "channel": "ETW Trace",
    "computer": "JD-DC01-2022",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": "ProcessQueuedMouseEvents"
}

Event ID 222: ProcessQueuedMouseEvents

#
Provider
Microsoft-Windows-Win32k
Channel
Messages
Level
Informational
Task
ProcessQueuedMouseEvents
Opcode
Stop

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Win32k",
    "guid": "{8C416C79-D49B-4F01-A467-E56D3AA8234C}",
    "event_source_name": "",
    "event_id": 222,
    "version": 0,
    "level": 4,
    "task": 216,
    "opcode": 2,
    "keywords": "0x0400000040800000",
    "time_created": "2026-06-02T05:32:25.759+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{8C416C79-D49B-4F01-A467-E56D3AA8234C}"
    },
    "execution": {
      "process_id": 952,
      "thread_id": 1048
    },
    "channel": "ETW Trace",
    "computer": "JD-DC01-2022",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": "ProcessQueuedMouseEvents"
}

Event ID 223: DITSpeedHitTestFailedRevalidation

#
Provider
Microsoft-Windows-Win32k
Channel
Messages
Task
DITSpeedHitTestFailedRevalidation

Fields #

NameDescription
Hwnd Pointer

Event ID 224: InputRedirection

#
Provider
Microsoft-Windows-Win32k
Channel
Messages
Task
InputRedirection

Fields #

NameDescription
hDCompInputHandle Pointer
Hwnd Pointer
XformQPCTime UInt64
XformStored UInt32

Event ID 225: OnInputXformUpdate

#
Provider
Microsoft-Windows-Win32k
Channel
Messages
Task
OnInputXformUpdate

Fields #

NameDescription
Hwnd Pointer
XformQPCTime UInt64
XformUpdated UInt32

Event ID 226: DitWaitForRitDisEngagement

#
Provider
Microsoft-Windows-Win32k
Channel
Messages
Task
DitWaitForRitDisEngagement

Event ID 227: RitDisEngaged

#
Provider
Microsoft-Windows-Win32k
Channel
Messages
Task
RitDisEngaged

Event ID 228: DitEngaged

#
Provider
Microsoft-Windows-Win32k
Channel
Messages
Task
DitEngaged

Event ID 229: RitReEngaged

#
Provider
Microsoft-Windows-Win32k
Channel
Messages
Task
RitReEngaged

Event ID 230: DitDisEngaged

#
Provider
Microsoft-Windows-Win32k
Channel
Messages
Task
DitDisEngaged

Event ID 231: DitTerminated

#
Provider
Microsoft-Windows-Win32k
Channel
Messages
Task
DitTerminated

Event ID 232: DitShutdown

#
Provider
Microsoft-Windows-Win32k
Channel
Messages
Task
DitShutdown

Event ID 233: TouchPadAAP

#
Provider
Microsoft-Windows-Win32k
Channel
Tracing
Task
TouchPadAAP

Fields #

NameDescription
LastKeyDownTime UInt32
LastKeyUpTime UInt32
TapTime UInt32
Blocked Boolean
Feature UInt32

Event ID 234: MouseInputApc

#
Provider
Microsoft-Windows-Win32k
Channel
Messages
Task
MouseInputApc

Event ID 235: MouseInputCoalesced

#
Provider
Microsoft-Windows-Win32k
Channel
Messages
Task
MouseInputCoalesced

Event ID 236: TouchPadTypeDiscovered

#
Provider
Microsoft-Windows-Win32k
Channel
Tracing
Task
TouchPadTypeDiscovered

Fields #

NameDescription
deviceType UInt32

Event ID 237: TouchPadEnabledStatusChangeStart

#
Provider
Microsoft-Windows-Win32k
Channel
Tracing
Task
TouchPadEnabledStatusChange
Opcode
Start

Event ID 238: TouchPadEnabledStatusChangeStop

#
Provider
Microsoft-Windows-Win32k
Channel
Tracing
Task
TouchPadEnabledStatusChange
Opcode
Stop

Event ID 239: PTPReadThresholdsStart

#
Provider
Microsoft-Windows-Win32k
Channel
Tracing
Task
PTPReadThresholds
Opcode
Start

Event ID 240: PTPReadThresholdsStop

#
Provider
Microsoft-Windows-Win32k
Channel
Tracing
Task
PTPReadThresholds
Opcode
Stop

Event ID 241: TouchPadConfidenceCleared

#
Provider
Microsoft-Windows-Win32k
Channel
Tracing
Task
TouchPadConfidenceCleared

Fields #

NameDescription
ContactId UInt32
OnUp Boolean
NeedsUp Boolean

Event ID 242: TouchPadConfidenceUpped

#
Provider
Microsoft-Windows-Win32k
Channel
Tracing
Task
TouchPadConfidenceUpped

Fields #

NameDescription
ContactId UInt32

Event ID 243: PTPElasticDragModeStart

#
Provider
Microsoft-Windows-Win32k
Channel
Tracing
Task
PTPElasticDragMode
Opcode
Start

Event ID 244: PTPElasticDragModeStop

#
Provider
Microsoft-Windows-Win32k
Channel
Tracing
Task
PTPElasticDragMode
Opcode
Stop

Event ID 245: LegacyTouchPadDetectionStart

#
Provider
Microsoft-Windows-Win32k
Channel
Tracing
Task
LegacyTouchPadDetection
Opcode
Start

Event ID 246: LegacyTouchPadDetectionStop

#
Provider
Microsoft-Windows-Win32k
Channel
Tracing
Task
LegacyTouchPadDetection
Opcode
Stop

Event ID 247: LegacyTouchPadDetection

#
Provider
Microsoft-Windows-Win32k
Channel
Tracing
Task
LegacyTouchPadDetection

Event ID 248: LegacyTouchPadDetection248

#
Provider
Microsoft-Windows-Win32k
Channel
Tracing
Task
LegacyTouchPadDetection

Event ID 249: TouchPadCurtainState

#
Provider
Microsoft-Windows-Win32k
Channel
Tracing
Task
TouchPadCurtainState

Fields #

NameDescription
CurtainsOn Boolean

Event ID 250: TouchPadCurtainSize

#
Provider
Microsoft-Windows-Win32k
Channel
Tracing
Task
TouchPadCurtainSize

Fields #

NameDescription
Top UInt32
Left UInt32
Right UInt32
Enabled Boolean

Event ID 251: TouchpadStopInertia

#
Provider
Microsoft-Windows-Win32k
Channel
Tracing
Task
TouchpadStopInertia

Event ID 252: TouchpadStopInertia252

#
Provider
Microsoft-Windows-Win32k
Channel
Tracing
Task
TouchpadStopInertia

Event ID 253: TouchpadStopInertia253

#
Provider
Microsoft-Windows-Win32k
Channel
Tracing
Task
TouchpadStopInertia

Event ID 254: TrappedAppContainerRender

#
Provider
Microsoft-Windows-Win32k
Channel
Tracing
Task
TrappedAppContainerRender

Fields #

NameDescription
RenderSourceProcessName AnsiString
RenderSourcePackageName UnicodeString
RenderTargetProcessName AnsiString
RenderTargetPackageName UnicodeString

Event ID 255: CursorSize

#
Provider
Microsoft-Windows-Win32k
Channel
Tracing
Task
CursorSize

Fields #

NameDescription
iCursorDim UInt32
cx UInt32
cy UInt32

Event ID 256: DitMmcssWorkStart

#
Provider
Microsoft-Windows-Win32k
Channel
Messages
Task
DitMmcssWork
Opcode
Start

Event ID 257: DitMmcssWorkStop

#
Provider
Microsoft-Windows-Win32k
Channel
Messages
Task
DitMmcssWork
Opcode
Stop

Event ID 258: FocusedProcessChangeGained

#
Provider
Microsoft-Windows-Win32k
Channel
Tracing
Task
FocusedProcessChangeGained

Fields #

NameDescription
SessionId UInt32
NewProcessId UInt32
NewProcessCreateTime FILETIME

Event ID 259: FocusedProcessChangeLost

#
Provider
Microsoft-Windows-Win32k
Channel
Tracing
Task
FocusedProcessChangeLost

Fields #

NameDescription
SessionId UInt32
OldProcessId UInt32
OldProcessCreateTime FILETIME

Event ID 260: SourceProcessName attempted loading a font that is restricted by font loading policy.

#
Provider
Microsoft-Windows-Win32k
Channel
Operational
Collection Priority
Recommended (JSCU-NL)
Task
FontLoadAttempt

Description

SourceProcessName attempted loading a font that is restricted by font loading policy.

Message #

%1 attempted loading a font that is restricted by font loading policy.
FontType: %2
FontPath: %3
Blocked: %4

Fields #

NameDescription
SourceProcessName UnicodeString
SourceType UInt32
FontSourcePath UnicodeString
Blocked Boolean

Event ID 301: TokenStateChanged_V1

#
Provider
Microsoft-Windows-Win32k
Channel
Tracing
Task
TokenStateChanged

Fields #

NameDescription
pCompositionSurfaceObject Pointer
SwapChainIndex UInt32
PresentCount UInt32
FenceValue UInt64
NewState UInt32
IndependentFlip Boolean
SkipIndependentFlip Boolean
CompositionSurfaceLuid UInt64
BindId UInt64
EarlyComposition Boolean

Event ID 400: DCompDeferBatch

#
Provider
Microsoft-Windows-Win32k
Channel
Tracing
Also via
realtime ETW trace
Level
Informational
Task
DCompDeferBatch
Opcode
win:Info

Fields #

NameDescription
channelHandle UInt32
pBatch Pointer
batchID UInt32
submissionTime UInt64
submissionDeadline UInt64
deferReason UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Win32k",
    "guid": "{8C416C79-D49B-4F01-A467-E56D3AA8234C}",
    "event_source_name": "",
    "event_id": 400,
    "version": 0,
    "level": 4,
    "task": 400,
    "opcode": 0,
    "keywords": "0x0000000000001000",
    "time_created": "2026-06-02T06:08:00.231+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{8C416C79-D49B-4F01-A467-E56D3AA8234C}"
    },
    "execution": {
      "process_id": 1168,
      "thread_id": 1236
    },
    "channel": "ETW Trace",
    "computer": "DESKTOP-FF3N5XK",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "batchID": 24923,
    "channelHandle": 15,
    "deferReason": 3,
    "pBatch": "0xFFFF990EE77329B0",
    "submissionDeadline": 1236898750000,
    "submissionTime": 1236898856077
  },
  "message": "DCompDeferBatch"
}

Event ID 401: TouchPadHIDProcessingStart

#
Provider
Microsoft-Windows-Win32k
Channel
Messages
Task
TouchPadHIDProcessing
Opcode
Start

Event ID 402: TouchPadHIDProcessingStop

#
Provider
Microsoft-Windows-Win32k
Channel
Messages
Task
TouchPadHIDProcessing
Opcode
Stop

Event ID 403: TouchPadWMPointerProcessingStart

#
Provider
Microsoft-Windows-Win32k
Channel
Messages
Task
TouchPadWMPointerProcessing
Opcode
Start

Event ID 404: TouchPadWMPointerProcessingStop

#
Provider
Microsoft-Windows-Win32k
Channel
Messages
Task
TouchPadWMPointerProcessing
Opcode
Stop

Event ID 405: TouchPadGesture

#
Provider
Microsoft-Windows-Win32k
Channel
Messages
Task
TouchPadGesture

Event ID 406: CopyPointerInputFrameStart

#
Provider
Microsoft-Windows-Win32k
Channel
Tracing
Task
CopyPointerInputFrame
Opcode
Start

Event ID 407: CopyPointerInputFrameStop

#
Provider
Microsoft-Windows-Win32k
Channel
Tracing
Task
CopyPointerInputFrame
Opcode
Stop

Event ID 410: LatencyModeProcessingStart

#
Provider
Microsoft-Windows-Win32k
Channel
Messages
Task
LatencyModeProcessing
Opcode
Start

Event ID 411: LatencyModeProcessingStop

#
Provider
Microsoft-Windows-Win32k
Channel
Messages
Task
LatencyModeProcessing
Opcode
Stop

Event ID 412: DCompBeginFrame

#
Provider
Microsoft-Windows-Win32k
Channel
Tracing
Also via
realtime ETW trace
Level
Informational
Task
DCompBeginFrame
Opcode
win:Info

Fields #

NameDescription
hConnection UInt64
targetTime UInt64

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Win32k",
    "guid": "{8C416C79-D49B-4F01-A467-E56D3AA8234C}",
    "event_source_name": "",
    "event_id": 412,
    "version": 0,
    "level": 4,
    "task": 412,
    "opcode": 0,
    "keywords": "0x0000000000001000",
    "time_created": "2026-06-02T04:02:00.060+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{8C416C79-D49B-4F01-A467-E56D3AA8234C}"
    },
    "execution": {
      "process_id": 1648,
      "thread_id": 1712
    },
    "channel": "ETW Trace",
    "computer": "JD-DC01-2022",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "SyncRefreshCount": 1943314,
    "hConnection": 4
  },
  "message": "DCompBeginFrame"
}

Event ID 413: TokenIndependentFlipSkipComplete

#
Provider
Microsoft-Windows-Win32k
Channel
Tracing
Task
TokenIndependentFlipSkipComplete

Fields #

NameDescription
SyncRefreshCount UInt32
PresentCount UInt32
CompositionSurfaceLuid UInt64
BindId UInt64

Event ID 414: DwmManipulationFrameStart

#
Provider
Microsoft-Windows-Win32k
Channel
Tracing
Task
DwmManipulationFrameStart

Fields #

NameDescription
FrameId UInt32
PointerCount UInt32

Event ID 415: DwmManipulationFrameRouted

#
Provider
Microsoft-Windows-Win32k
Channel
Tracing
Task
DwmManipulationFrameRouted

Fields #

NameDescription
FrameId UInt32
PointerCount UInt32

Event ID 416: ExclusiveUserCritTelemetry

#
Provider
Microsoft-Windows-Win32k
Channel
Tracing
Task
ExclusiveUserCritTelemetry

Fields #

NameDescription
AcquireQpcCounts UInt64
AcquireTimeMs UInt32
Token UInt64

Event ID 417: SharedUserCritTelemetry

#
Provider
Microsoft-Windows-Win32k
Channel
Tracing
Task
SharedUserCritTelemetry

Fields #

NameDescription
AcquireQpcCounts UInt64
AcquireTimeMs UInt32
Token UInt64

Event ID 418: PowerOnGdi

#
Provider
Microsoft-Windows-Win32k
Channel
Power
Task
PowerDisplayChange
Opcode
Start

Description

PowerOnGdi.

Message #

PowerOnGdi

Fields #

NameDescription
Location Int32

Event ID 419: PowerOnGdi

#
Provider
Microsoft-Windows-Win32k
Channel
Power
Task
PowerDisplayChange
Opcode
Stop

Description

PowerOnGdi.

Message #

PowerOnGdi

Fields #

NameDescription
Location Int32

Event ID 420: UserResetDisplayDevice

#
Provider
Microsoft-Windows-Win32k
Channel
Power
Task
PowerDisplayChange
Opcode
Start

Description

UserResetDisplayDevice.

Message #

UserResetDisplayDevice

Fields #

NameDescription
Location Int32

Event ID 421: UserResetDisplayDevice

#
Provider
Microsoft-Windows-Win32k
Channel
Power
Task
PowerDisplayChange
Opcode
Stop

Description

UserResetDisplayDevice.

Message #

UserResetDisplayDevice

Fields #

NameDescription
Location Int32

Event ID 422: PowerOnMonitor

#
Provider
Microsoft-Windows-Win32k
Channel
Power
Task
PowerDisplayChange
Opcode
Start

Description

PowerOnMonitor.

Message #

PowerOnMonitor

Fields #

NameDescription
Location Int32

Event ID 423: PowerOnMonitor

#
Provider
Microsoft-Windows-Win32k
Channel
Power
Task
PowerDisplayChange
Opcode
Stop

Description

PowerOnMonitor.

Message #

PowerOnMonitor

Fields #

NameDescription
Location Int32

Event ID 424: DwmSyncFlushForceRenderAndWaitForBatch

#
Provider
Microsoft-Windows-Win32k
Channel
Power
Task
PowerDisplayChange
Opcode
Start

Description

DwmSyncFlushForceRenderAndWaitForBatch.

Message #

DwmSyncFlushForceRenderAndWaitForBatch

Fields #

NameDescription
Location Int32

Event ID 425: DwmSyncFlushForceRenderAndWaitForBatch

#
Provider
Microsoft-Windows-Win32k
Channel
Power
Task
PowerDisplayChange
Opcode
Stop

Description

DwmSyncFlushForceRenderAndWaitForBatch.

Message #

DwmSyncFlushForceRenderAndWaitForBatch

Fields #

NameDescription
Location Int32

Event ID 426: QueueNullPostMessage

#
Provider
Microsoft-Windows-Win32k
Channel
Messages
Task
QueueNullPostMessage

Fields #

NameDescription
SourceProcessId UInt32
SourceThreadId UInt32
SourceProcessName AnsiString
DestinationHwnd Pointer

Event ID 427: The following win32k syscall is blocked by Win32k Syscall Filter: SyscallName.

#
Provider
Microsoft-Windows-Win32k
Channel
Operational
Task
SyscallFilterMessage

Description

The following win32k syscall is blocked by Win32k Syscall Filter: SyscallName.

Message #

The following win32k syscall is blocked by Win32k Syscall Filter: %1
Process Command Line: %3

Fields #

NameDescription
SyscallName AnsiString
AppContainerSid UnicodeString
ProcessCommandLine UnicodeString
FilterSetId UInt32

Event ID 428: The following SystemParametersInfo action was blocked by Win32k Syscall Filter: SPIAction.

#
Provider
Microsoft-Windows-Win32k
Channel
Operational
Task
SPIBlockedByFiltering

Description

The following SystemParametersInfo action was blocked by Win32k Syscall Filter: SPIAction.

Message #

The following SystemParametersInfo action was blocked by Win32k Syscall Filter: %1

Fields #

NameDescription
SPIAction UInt32

Event ID 429: PowerWatchdog

#
Provider
Microsoft-Windows-Win32k
Channel
Power
Task
PowerWatchdog
Opcode
Start

Description

PowerWatchdog.

Message #

PowerWatchdog

Fields #

NameDescription
Instance UInt64
WatchdogType UInt32

Event ID 430: PowerWatchdog

#
Provider
Microsoft-Windows-Win32k
Channel
Power
Task
PowerWatchdog
Opcode
Stop

Description

PowerWatchdog.

Message #

PowerWatchdog

Fields #

NameDescription
Instance UInt64

Event ID 431: VideoPortCalloutThread

#
Provider
Microsoft-Windows-Win32k
Channel
Power
Task
PowerRequest
Opcode
Start

Description

VideoPortCalloutThread.

Message #

VideoPortCalloutThread

Fields #

NameDescription
CalloutType Int32
Status UInt32NTSTATUS reference

Event ID 432: VideoPortCalloutThread

#
Provider
Microsoft-Windows-Win32k
Channel
Power
Task
PowerRequest
Opcode
Stop

Description

VideoPortCalloutThread.

Message #

VideoPortCalloutThread

Fields #

NameDescription
CalloutType Int32
Status UInt32NTSTATUS reference

Event ID 433: PowerStateCalloutWorker

#
Provider
Microsoft-Windows-Win32k
Channel
Power
Task
PowerRequest
Opcode
Start

Description

PowerStateCalloutWorker.

Message #

PowerStateCalloutWorker

Fields #

NameDescription
PowerTaskState Int32
Status UInt32NTSTATUS reference

Event ID 434: PowerStateCalloutWorker

#
Provider
Microsoft-Windows-Win32k
Channel
Power
Task
PowerRequest
Opcode
Stop

Description

PowerStateCalloutWorker.

Message #

PowerStateCalloutWorker

Fields #

NameDescription
PowerTaskState Int32
Status UInt32NTSTATUS reference

Event ID 435: PowerEventCalloutWorker

#
Provider
Microsoft-Windows-Win32k
Channel
Power
Task
PowerRequest
Opcode
Start

Description

PowerEventCalloutWorker.

Message #

PowerEventCalloutWorker

Fields #

NameDescription
EventNumber Int32
Code UInt64
Status UInt32NTSTATUS reference

Event ID 436: PowerEventCalloutWorker

#
Provider
Microsoft-Windows-Win32k
Channel
Power
Task
PowerRequest
Opcode
Stop

Description

PowerEventCalloutWorker.

Message #

PowerEventCalloutWorker

Fields #

NameDescription
EventNumber Int32
Code UInt64
Status UInt32NTSTATUS reference

Event ID 437: Insert

#
Provider
Microsoft-Windows-Win32k
Channel
Power
Task
PowerRequest
Opcode
Start

Description

Insert

Message #

Insert

Fields #

NameDescription
Address UInt64
EventNumber Int32
Code UInt64

Event ID 438: Remove

#
Provider
Microsoft-Windows-Win32k
Channel
Power
Task
PowerRequest

Description

Remove

Message #

Remove

Fields #

NameDescription
Address UInt64
Status UInt32NTSTATUS reference

Event ID 439: Canceled

#
Provider
Microsoft-Windows-Win32k
Channel
Power
Task
PowerRequest

Description

Canceled

Message #

Canceled

Fields #

NameDescription
Address UInt64
Status UInt32NTSTATUS reference

Event ID 440: Completed

#
Provider
Microsoft-Windows-Win32k
Channel
Power
Task
PowerRequest
Opcode
Stop

Description

Completed.

Message #

Completed

Fields #

NameDescription
Address UInt64
Status UInt32NTSTATUS reference

Event ID 441: WaitForVideoPortCalloutReady

#
Provider
Microsoft-Windows-Win32k
Channel
Power
Task
PowerRequest
Opcode
Start

Description

WaitForVideoPortCalloutReady.

Message #

WaitForVideoPortCalloutReady

Fields #

NameDescription
NeedWaitForRit Boolean
NeedPowerOnGdi Boolean

Event ID 442: WaitForVideoPortCalloutReady

#
Provider
Microsoft-Windows-Win32k
Channel
Power
Task
PowerRequest
Opcode
Stop

Description

WaitForVideoPortCalloutReady.

Message #

WaitForVideoPortCalloutReady

Event ID 443: DCompResourceMapping

#
Provider
Microsoft-Windows-Win32k
Channel
Tracing
Task
DCompResourceMapping

Fields #

NameDescription
Channel UInt32
InternalHandle UInt32
ExternalHandle UInt32
InternalHandleAndChannel UInt64
ExternalHandleAndChannel UInt64
ResourceType UInt32
CreateShared Boolean
OpenShared Boolean

Event ID 444: DCompResourcePropertyUpdate

#
Provider
Microsoft-Windows-Win32k
Channel
Tracing
Task
DCompResourcePropertyUpdate

Fields #

NameDescription
Channel UInt32
InternalHandle UInt32
ExternalHandle UInt32
ResourceType UInt32
PropertyId UInt32

Event ID 445: DCompCommandType

#
Provider
Microsoft-Windows-Win32k
Channel
Tracing
Also via
realtime ETW trace
Level
Informational
Task
DCompCommandType
Opcode
win:Info

Fields #

NameDescription
CommandType UInt32
status UInt64NTSTATUS reference

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Win32k",
    "guid": "{8C416C79-D49B-4F01-A467-E56D3AA8234C}",
    "event_source_name": "",
    "event_id": 445,
    "version": 0,
    "level": 4,
    "task": 433,
    "opcode": 0,
    "keywords": "0x0000000400001000",
    "time_created": "2026-06-02T06:08:00.231+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{8C416C79-D49B-4F01-A467-E56D3AA8234C}"
    },
    "execution": {
      "process_id": 5396,
      "thread_id": 3744
    },
    "channel": "ETW Trace",
    "computer": "DESKTOP-FF3N5XK",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "CommandType": 11,
    "status": 0
  },
  "message": "DCompCommandType"
}

Event ID 446: DCompCommandsInBatch

#
Provider
Microsoft-Windows-Win32k
Channel
Tracing
Also via
realtime ETW trace
Level
Informational
Task
DCompCommandsInBatch
Opcode
win:Info

Fields #

NameDescription
CommandsCount UInt64

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Win32k",
    "guid": "{8C416C79-D49B-4F01-A467-E56D3AA8234C}",
    "event_source_name": "",
    "event_id": 446,
    "version": 0,
    "level": 4,
    "task": 434,
    "opcode": 0,
    "keywords": "0x0000000400001000",
    "time_created": "2026-06-02T06:08:00.231+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{8C416C79-D49B-4F01-A467-E56D3AA8234C}"
    },
    "execution": {
      "process_id": 5396,
      "thread_id": 3744
    },
    "channel": "ETW Trace",
    "computer": "DESKTOP-FF3N5XK",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "CommandsCount": 18
  },
  "message": "DCompCommandsInBatch"
}

Event ID 450: DCompCreateImplicitInteraction

#
Provider
Microsoft-Windows-Win32k
Channel
Tracing
Task
DCompCreateImplicitInteraction

Fields #

NameDescription
Channel UInt32
VisualInternalHandle UInt32
InteractionInternalHandle UInt32
VisualInternalHandleAndChannel UInt64
InteractionInternalHandleAndChannel UInt64
ResourceType UInt32
DefaultInteraction Boolean
Reason UnicodeString

Event ID 451: DCompVisualSetInteraction

#
Provider
Microsoft-Windows-Win32k
Channel
Tracing
Task
DCompVisualSetInteraction

Fields #

NameDescription
Channel UInt32
VisualInternalHandle UInt32
InteractionInternalHandle UInt32
VisualInternalHandleAndChannel UInt64
InteractionInternalHandleAndChannel UInt64

Event ID 452: UserHandleOperation

#
Provider
Microsoft-Windows-Win32k
Channel
Tracing
Also via
realtime ETW trace
Level
Informational
Task
UserHandleOperation
Opcode
CreateHandle

Fields #

NameDescription
HandleValue Pointer
HandleType UInt32
SessionId UInt32
OwnerProcessId UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Win32k",
    "guid": "{8C416C79-D49B-4F01-A467-E56D3AA8234C}",
    "event_source_name": "",
    "event_id": 452,
    "version": 0,
    "level": 4,
    "task": 443,
    "opcode": 28,
    "keywords": "0x0000020000000000",
    "time_created": "2026-06-02T05:32:25.757+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{8C416C79-D49B-4F01-A467-E56D3AA8234C}"
    },
    "execution": {
      "process_id": 14592,
      "thread_id": 10500
    },
    "channel": "ETW Trace",
    "computer": "JD-DC01-2022",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "HandleType": 1,
    "HandleValue": "0x4F006C",
    "OwnerProcessId": 14592,
    "SessionId": 0
  },
  "message": "UserHandleOperation"
}

Event ID 453: UserHandleOperation

#
Provider
Microsoft-Windows-Win32k
Channel
Tracing
Also via
realtime ETW trace
Level
Informational
Task
UserHandleOperation
Opcode
DestroyHandle

Fields #

NameDescription
HandleValue Pointer
HandleType UInt32
SessionId UInt32
OwnerProcessId UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Win32k",
    "guid": "{8C416C79-D49B-4F01-A467-E56D3AA8234C}",
    "event_source_name": "",
    "event_id": 453,
    "version": 0,
    "level": 4,
    "task": 443,
    "opcode": 29,
    "keywords": "0x0000020000000000",
    "time_created": "2026-06-02T05:32:25.759+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{8C416C79-D49B-4F01-A467-E56D3AA8234C}"
    },
    "execution": {
      "process_id": 14592,
      "thread_id": 10500
    },
    "channel": "ETW Trace",
    "computer": "JD-DC01-2022",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "HandleType": 3,
    "HandleValue": "0x8902DD",
    "OwnerProcessId": 14592,
    "SessionId": 0
  },
  "message": "UserHandleOperation"
}

Event ID 454: UserHandleOperationUpdateHandleOwner

#
Provider
Microsoft-Windows-Win32k
Channel
Tracing
Task
UserHandleOperation
Opcode
UpdateHandleOwner

Fields #

NameDescription
HandleValue Pointer
HandleType UInt32
SessionId UInt32
OwnerProcessId UInt32

Event ID 455: GdiHandleOperation

#
Provider
Microsoft-Windows-Win32k
Channel
Tracing
Also via
realtime ETW trace
Level
Informational
Task
GdiHandleOperation
Opcode
CreateHandle

Fields #

NameDescription
HandleValue Pointer
HandleType UInt32
SessionId UInt32
OwnerProcessId UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Win32k",
    "guid": "{8C416C79-D49B-4F01-A467-E56D3AA8234C}",
    "event_source_name": "",
    "event_id": 455,
    "version": 0,
    "level": 4,
    "task": 442,
    "opcode": 28,
    "keywords": "0x0000010000000000",
    "time_created": "2026-06-02T05:32:25.757+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{8C416C79-D49B-4F01-A467-E56D3AA8234C}"
    },
    "execution": {
      "process_id": 14592,
      "thread_id": 10500
    },
    "channel": "ETW Trace",
    "computer": "JD-DC01-2022",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "HandleType": 1,
    "HandleValue": "0xFFFFFFFF8B0102B7",
    "OwnerProcessId": 14592,
    "SessionId": 0
  },
  "message": "GdiHandleOperation"
}

Event ID 456: GdiHandleOperation

#
Provider
Microsoft-Windows-Win32k
Channel
Tracing
Also via
realtime ETW trace
Level
Informational
Task
GdiHandleOperation
Opcode
DestroyHandle

Fields #

NameDescription
HandleValue Pointer
HandleType UInt32
SessionId UInt32
OwnerProcessId UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Win32k",
    "guid": "{8C416C79-D49B-4F01-A467-E56D3AA8234C}",
    "event_source_name": "",
    "event_id": 456,
    "version": 0,
    "level": 4,
    "task": 442,
    "opcode": 29,
    "keywords": "0x0000010000000000",
    "time_created": "2026-06-02T05:32:25.757+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{8C416C79-D49B-4F01-A467-E56D3AA8234C}"
    },
    "execution": {
      "process_id": 14592,
      "thread_id": 10500
    },
    "channel": "ETW Trace",
    "computer": "JD-DC01-2022",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "HandleType": 1,
    "HandleValue": "0xFFFFFFFF92010287",
    "OwnerProcessId": 14592,
    "SessionId": 0
  },
  "message": "GdiHandleOperation"
}

Event ID 457: GdiHandleOperation

#
Provider
Microsoft-Windows-Win32k
Channel
Tracing
Also via
realtime ETW trace
Level
Informational
Task
GdiHandleOperation
Opcode
UpdateHandleOwner

Fields #

NameDescription
HandleValue Pointer
HandleType UInt32
SessionId UInt32
OwnerProcessId UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Win32k",
    "guid": "{8C416C79-D49B-4F01-A467-E56D3AA8234C}",
    "event_source_name": "",
    "event_id": 457,
    "version": 0,
    "level": 4,
    "task": 442,
    "opcode": 30,
    "keywords": "0x0000010000000000",
    "time_created": "2026-06-02T05:32:25.757+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{8C416C79-D49B-4F01-A467-E56D3AA8234C}"
    },
    "execution": {
      "process_id": 14592,
      "thread_id": 10500
    },
    "channel": "ETW Trace",
    "computer": "JD-DC01-2022",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "HandleType": 4,
    "HandleValue": "0xFFFFFFFF93040287",
    "OwnerProcessId": 0,
    "SessionId": 0
  },
  "message": "GdiHandleOperation"
}

Event ID 458: GdiHandleOperation

#
Provider
Microsoft-Windows-Win32k
Channel
Tracing
Also via
realtime ETW trace
Level
Informational
Task
GdiHandleOperation
Opcode
TransformHandle

Fields #

NameDescription
PreviousHandleValue Pointer
NewHandleValue Pointer
HandleType UInt32
SessionId UInt32
OwnerProcessId UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Win32k",
    "guid": "{8C416C79-D49B-4F01-A467-E56D3AA8234C}",
    "event_source_name": "",
    "event_id": 458,
    "version": 0,
    "level": 4,
    "task": 442,
    "opcode": 31,
    "keywords": "0x0000010000000000",
    "time_created": "2026-06-02T04:02:00.029+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{8C416C79-D49B-4F01-A467-E56D3AA8234C}"
    },
    "execution": {
      "process_id": 4304,
      "thread_id": 3088
    },
    "channel": "ETW Trace",
    "computer": "JD-DC01-2022",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "HandleType": 4,
    "NewHandleValue": "0xD8041846",
    "OwnerProcessId": 4304,
    "PreviousHandleValue": "0xD7041846",
    "SessionId": 1
  },
  "message": "GdiHandleOperation"
}

Event ID 459: WriteClipboard

#
Provider
Microsoft-Windows-Win32k
Channel
Tracing
Task
WriteClipboard

Fields #

NameDescription
Pid UInt32
ProcessCreateTime FILETIME

Event ID 460: WriteClipboard460

#
Provider
Microsoft-Windows-Win32k
Channel
Tracing
Task
WriteClipboard

Fields #

NameDescription
Pid UInt32
ProcessCreateTime FILETIME

Event ID 461: DwmVisRgnUpdate

#
Provider
Microsoft-Windows-Win32k
Channel
Tracing
Task
DwmVisRgnUpdate

Fields #

NameDescription
hwnd Pointer
hwndParent Pointer
visRgnType UInt32
changed Boolean

Event ID 462: DwmVisRgnDirty

#
Provider
Microsoft-Windows-Win32k
Channel
Tracing
Task
DwmVisRgnDirty

Fields #

NameDescription
hwnd Pointer
hwndParent Pointer

Event ID 463: ReadClipboard

#
Provider
Microsoft-Windows-Win32k
Channel
Tracing
Task
ReadClipboard

Fields #

NameDescription
CallerPid UInt32
CallerProcessCreateTime FILETIME
OwnerPid UInt32
OwnerProcessCreateTime FILETIME
ClipboardSequenceNumber UInt32

Event ID 500: FlipManagerCompleteTokenStart

#
Provider
Microsoft-Windows-Win32k
Channel
Tracing
Task
FlipManagerCompleteToken
Opcode
Start

Fields #

NameDescription
FlipManagerId UInt32
PresentId UInt64
IFlip Boolean
IFlipCompleted Boolean
ConvertedToNonIflip Boolean
RequestDwmConfirm Boolean
RequestDwmExit Boolean
IndependentFlipCandidate Boolean

Event ID 501: FlipManagerCompleteTokenStop

#
Provider
Microsoft-Windows-Win32k
Channel
Tracing
Task
FlipManagerCompleteToken
Opcode
Stop

Fields #

NameDescription
PresentId UInt64

Event ID 502: FlipManagerTokenReleaseToFrameStart

#
Provider
Microsoft-Windows-Win32k
Channel
Tracing
Task
FlipManagerTokenReleaseToFrame
Opcode
Start

Fields #

NameDescription
FlipManagerId UInt32
PresentId UInt64

Event ID 503: FlipManagerTokenReleaseToFrameStop

#
Provider
Microsoft-Windows-Win32k
Channel
Tracing
Task
FlipManagerTokenReleaseToFrame
Opcode
Stop

Fields #

NameDescription
FlipManagerId UInt32
PresentId UInt64

Event ID 504: FlipManagerSignalPresentRetired

#
Provider
Microsoft-Windows-Win32k
Channel
Tracing
Task
FlipManagerPresentConfirmed

Fields #

NameDescription
FlipManagerId UInt32
PresentId UInt64

Event ID 505: FlipManagerPresentRetiredSignalOverride

#
Provider
Microsoft-Windows-Win32k
Channel
Tracing
Task
FlipManagerPresentSignaled

Fields #

NameDescription
FlipManagerId UInt32
SignalValue UInt64
Skipped Boolean
Status UInt32NTSTATUS reference

Event ID 506: FlipManagerPresentPosted

#
Provider
Microsoft-Windows-Win32k
Channel
Tracing
Task
FlipManagerPresentPosted

Fields #

NameDescription
FlipManagerId UInt32
PresentId UInt64
PresentAtTimeHns UInt64
CurrentTimeHns UInt64
PresentAtTimeMinusCurrentTimeHns Int64

Event ID 507: FlipManagerProducerSetContent

#
Provider
Microsoft-Windows-Win32k
Channel
Tracing
Task
FlipManagerProducerSetContent

Fields #

NameDescription
FlipManagerId UInt32
ContentResource Pointer
BufferResource Pointer
BufferIndex UInt32

Event ID 508: FlipManagerBufferAvailable

#
Provider
Microsoft-Windows-Win32k
Channel
Tracing
Task
FlipManagerBufferAvailable

Fields #

NameDescription
FlipManagerId UInt32
BufferResource Pointer
available Boolean

Event ID 509: FlipManagerAddBuffer

#
Provider
Microsoft-Windows-Win32k
Channel
Tracing
Task
FlipManagerAddBuffer

Fields #

NameDescription
FlipManagerId UInt32
BufferResource Pointer
hVidMmGlobalAlloc Pointer

Event ID 510: FlipManagerRemoveBuffer

#
Provider
Microsoft-Windows-Win32k
Channel
Tracing
Task
FlipManagerRemoveBuffer

Fields #

NameDescription
FlipManagerId UInt32
BufferResource Pointer

Event ID 511: FlipManagerContentRebind

#
Provider
Microsoft-Windows-Win32k
Channel
Tracing
Task
FlipManagerContentRebind

Fields #

NameDescription
Content Pointer
LUID UInt64
BindId UInt64
Displayable Boolean
BufferCount UInt32

Event ID 512: FlipManagerPresentProcessed

#
Provider
Microsoft-Windows-Win32k
Channel
Tracing
Task
FlipManagerPresentProcessed

Fields #

NameDescription
FlipManagerId UInt32
PresentId UInt64
FrameId UInt64
PresentAtTimeHns UInt64
FrameTimeHns UInt64
MaxAcceptableTargetTimeHns UInt64
PresentTimeMinusFrameTimeHns Int64

Event ID 513: FlipManagerPresentDeferred

#
Provider
Microsoft-Windows-Win32k
Channel
Tracing
Task
FlipManagerPresentDeferred

Fields #

NameDescription
FlipManagerId UInt32
PresentId UInt64
FrameId UInt64
PresentAtTimeHns UInt64
FrameTimeHns UInt64
MaxAcceptableTargetTimeHns UInt64
PresentTimeMinusFrameTimeHns Int64

Event ID 514: FlipManagerPresentCanceled

#
Provider
Microsoft-Windows-Win32k
Channel
Tracing
Task
FlipManagerPresentCanceled

Fields #

NameDescription
FlipManagerId UInt32
PresentId UInt64
FrameId UInt64
PresentAtTimeHns UInt64
FrameTimeHns UInt64
MaxAcceptableTargetTimeHns UInt64
PresentTimeMinusFrameTimeHns Int64

Event ID 515: FlipManagerPresentIFlipSubmitted

#
Provider
Microsoft-Windows-Win32k
Channel
Tracing
Task
FlipManagerPresentIFlipSubmitted

Fields #

NameDescription
FlipManagerId UInt32
PresentId UInt64
WasCanceled Boolean

Event ID 516: FlipManagerPresentIFlipCompleted

#
Provider
Microsoft-Windows-Win32k
Channel
Tracing
Task
FlipManagerPresentIFlipCompleted

Fields #

NameDescription
FlipManagerId UInt32
PresentId UInt64
Notify Boolean
WasCanceled Boolean
CompletedQpc UInt64
DurationQpc UInt64

Event ID 517: FlipManagerPresentQueueDepth

#
Provider
Microsoft-Windows-Win32k
Channel
Tracing
Task
FlipManagerPresentQueueDepth

Fields #

NameDescription
FlipManagerId UInt32
PresentQueueDepth UInt64

Event ID 518: FlipManagerBindingStart

#
Provider
Microsoft-Windows-Win32k
Channel
Tracing
Task
FlipManagerBinding
Opcode
Start

Fields #

NameDescription
ContentResource Pointer

Event ID 519: FlipManagerBinding

#
Provider
Microsoft-Windows-Win32k
Channel
Tracing
Task
FlipManagerBinding

Fields #

NameDescription
BufferResource Pointer
Index UInt32

Event ID 520: FlipManagerBindingStop

#
Provider
Microsoft-Windows-Win32k
Channel
Tracing
Task
FlipManagerBinding
Opcode
Stop

Event ID 521: FlipManagerAddContent

#
Provider
Microsoft-Windows-Win32k
Channel
Tracing
Task
FlipManagerAddContent

Fields #

NameDescription
FlipManagerId UInt32
ContentResource Pointer

Event ID 522: FlipManagerContentFlip

#
Provider
Microsoft-Windows-Win32k
Channel
Tracing
Task
FlipManagerContentFlip

Fields #

NameDescription
ContentResource Pointer
LUID UInt64
BindId UInt64
FlipIndex UInt32

Event ID 523: FlipManagerNoOpPresent

#
Provider
Microsoft-Windows-Win32k
Channel
Tracing
Task
FlipManagerNoOpPresent

Fields #

NameDescription
FlipManagerId UInt32
PresentId UInt64

Event ID 524: FlipManagerCancelPosted

#
Provider
Microsoft-Windows-Win32k
Channel
Tracing
Task
FlipManagerCancelPosted

Fields #

NameDescription
FlipManagerId UInt32
PresentId UInt64

Event ID 525: FlipManagerContentUnbind

#
Provider
Microsoft-Windows-Win32k
Channel
Tracing
Task
FlipManagerContentUnbind

Fields #

NameDescription
Content Pointer
LUID UInt64

Event ID 526: FlipManagerCreate

#
Provider
Microsoft-Windows-Win32k
Channel
Tracing
Task
FlipManagerCreate

Fields #

NameDescription
FlipManagerId UInt32

Event ID 527: FlipManagerDestroy

#
Provider
Microsoft-Windows-Win32k
Channel
Tracing
Task
FlipManagerDestroy

Fields #

NameDescription
FlipManagerId UInt32

Event ID 528: TokenManagerDisableScanoutToken

#
Provider
Microsoft-Windows-Win32k
Channel
Tracing
Task
TokenManagerDisableScanoutToken

Fields #

NameDescription
LUID UInt64
BindId UInt64

Event ID 529: FlipManagerLost

#
Provider
Microsoft-Windows-Win32k
Channel
Tracing
Task
FlipManagerLost

Fields #

NameDescription
FlipManagerId UInt32

Event ID 530: FlipManagerCanceledPresentShown

#
Provider
Microsoft-Windows-Win32k
Channel
Tracing
Task
FlipManagerCanceledPresentShown

Fields #

NameDescription
FlipManagerId UInt32
PresentId UInt64
Reason UInt32

Event ID 531: FlipManagerUpdateExpectedConsumerPresentId

#
Provider
Microsoft-Windows-Win32k
Channel
Tracing
Task
FlipManagerUpdateExpectedConsumerPresentId

Fields #

NameDescription
FlipManagerId UInt32
PresentId UInt64
Reason UInt32

Event ID 532: FlipManagerPresentSkipped

#
Provider
Microsoft-Windows-Win32k
Channel
Tracing
Task
FlipManagerPresentSkipped

Fields #

NameDescription
FlipManagerId UInt32
PresentId UInt64
FrameId UInt64
PresentAtTimeHns UInt64
FrameTimeHns UInt64
MaxAcceptableTargetTimeHns UInt64
PresentTimeMinusFrameTimeHns Int64

Event ID 533: FlipManagerRemoveContent

#
Provider
Microsoft-Windows-Win32k
Channel
Tracing
Task
FlipManagerRemoveContent

Fields #

NameDescription
FlipManagerId UInt32
ContentResource Pointer

Event ID 534: FlipManagerPresentIFlipPurgePreviousPresents

#
Provider
Microsoft-Windows-Win32k
Channel
Tracing
Task
FlipManagerPresentIFlipPurgePreviousPresents

Fields #

NameDescription
FlipManagerId UInt32
PresentId UInt64

Event ID 535: FlipManagerDiscardPresentAfterDestroy

#
Provider
Microsoft-Windows-Win32k
Channel
Tracing
Task
FlipManagerDiscardPresentAfterDestroy

Fields #

NameDescription
FlipManagerId UInt32
PresentId UInt64

Event ID 536: FlipManagerWaitForFrameRenderingComplete

#
Provider
Microsoft-Windows-Win32k
Channel
Operational
Task
FlipManagerWaitForFrameRenderingComplete

Fields #

NameDescription
FlipManagerId UInt32
PresentId UInt64
FrameId UInt64
Status UInt32NTSTATUS reference

Event ID 537: FlipManagerWaitForFrameFlipAway

#
Provider
Microsoft-Windows-Win32k
Channel
Operational
Task
FlipManagerWaitForFrameFlipAway

Fields #

NameDescription
FlipManagerId UInt32
adapterLuid UInt64
fenceValue UInt64
Status UInt32NTSTATUS reference

Event ID 538: FlipManagerFlipAwayFenceCreate

#
Provider
Microsoft-Windows-Win32k
Channel
Operational
Task
FlipManagerFlipAwayFenceCreate

Fields #

NameDescription
fenceId UInt64
displayAdapterLuid UInt64

Event ID 539: FlipManagerFlipAwayFenceDestroy

#
Provider
Microsoft-Windows-Win32k
Channel
Operational
Task
FlipManagerFlipAwayFenceDestroy

Fields #

NameDescription
fenceId UInt64
displayAdapterLuid UInt64

Event ID 1000: task_01000

#
Provider
Microsoft-Windows-Win32k
Channel
Operational
Opcode
Info

Fields #

NameDescription
eventMin UInt32
eventMax UInt32
idEventProcess UInt32
idEventThread UInt32
Flags UInt32
HookInstance Pointer

Event ID 1001: RegisterRawInputDevices

#
Provider
Microsoft-Windows-Win32k
Channel
Operational
Also via
realtime ETW trace
Level
Informational
Opcode
Info

Description

Fires when RegisterRawInputDevices is called. The Flags field indicates registration mode; RIDEV_INPUTSINK (0x100) enables background capture. Captured via the AuditApiCalls ETW keyword (0x400) on the Microsoft-Windows-Win32k provider.

Fields #

NameDescription
ReturnValue UInt32Return value of RegisterRawInputDevices (1=success)
UsagePage UInt16HID usage page (1 = Generic Desktop)
Usage UInt16HID usage (2=Mouse, 6=Keyboard)
Flags UInt32Registration flags; RIDEV_INPUTSINK=0x100 indicates background input capture
hwndTarget PointerTarget window handle (required when RIDEV_INPUTSINK is set)
ThreadStartAddress Pointer
ThreadCreateTime FILETIME
ThreadId UInt32
cWindows UInt32
cVisWindows UInt32
ThreadInfoFlags UInt64
ProcessId UInt32
ProcessCreateTime FILETIME
ProcessStartKey UInt64
ThreadStartAddressMappedModuleName UnicodeStringMapped module at the calling thread's start address
ThreadStartAddressQueryResult UInt32
ThreadStartAddressVadAllocationBase Pointer
ThreadStartAddressVadAllocationProtect UInt32
ThreadStartAddressVadRegionType UInt32
ThreadStartAddressVadRegionSize Pointer
ThreadStartAddressVadProtect UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Win32k",
    "guid": "{8C416C79-D49B-4F01-A467-E56D3AA8234C}",
    "event_source_name": "",
    "event_id": 1001,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": "0x0000000000000400",
    "time_created": "2026-06-08T20:01:29.588+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{8C416C79-D49B-4F01-A467-E56D3AA8234C}"
    },
    "execution": {
      "process_id": 6504,
      "thread_id": 556
    },
    "channel": "ETW Trace",
    "computer": "DESKTOP-FF3N5XK",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "ReturnValue": 1,
    "UsagePage": 1,
    "Usage": 6,
    "Flags": 0,
    "hwndTarget": "0x0",
    "ThreadStartAddress": "0x7FF97E3DDCB0",
    "ThreadId": 556,
    "cWindows": 0,
    "cVisWindows": 0,
    "ThreadInfoFlags": 0,
    "ProcessId": 6504,
    "ThreadStartAddressMappedModuleName": "\\Device\\HarddiskVolume4\\Windows\\System32\\ntdll.dll",
    "ThreadStartAddressQueryResult": 0,
    "ThreadStartAddressVadAllocationBase": "0x7FF97E360000",
    "ThreadStartAddressVadAllocationProtect": 128,
    "ThreadStartAddressVadRegionType": 16777216,
    "ThreadStartAddressVadRegionSize": "0xF8000",
    "ThreadStartAddressVadProtect": 32
  },
  "message": ""
}

Event ID 1002: SetWindowsHookEx

#
Provider
Microsoft-Windows-Win32k
Channel
Operational
Also via
realtime ETW trace
Level
Informational
Opcode
Info

Description

Fires when SetWindowsHookEx is called. FilterType carries the hook identifier; WH_KEYBOARD_LL (0xD) is the low-level keyboard hook used by keyloggers. pfnFilterProc is the callback address — unbacked or shellcode-range values indicate injection. Captured via the AuditApiCalls ETW keyword (0x400) on the Microsoft-Windows-Win32k provider.

Fields #

NameDescription
FilterType UInt32Windows hook type (WH_KEYBOARD_LL=0xD, WH_MOUSE_LL=0xE, WH_KEYBOARD=0x2). 0xFFFFFFFF seen for internal system hooks.
pstrLib UnicodeStringDLL path when hook is loaded from a remote DLL; NULL for in-process hooks
hmod PointerModule handle of the hook DLL (0x0 for in-process hooks)
pfnFilterProc PointerAddress of the hook callback procedure; unbacked addresses indicate reflectively-loaded code
ReturnValue UInt32Hook handle returned by SetWindowsHookEx (HHOOK)

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Win32k",
    "guid": "{8C416C79-D49B-4F01-A467-E56D3AA8234C}",
    "event_source_name": "",
    "event_id": 1002,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": "0x0000000000000400",
    "time_created": "2026-06-08T20:01:29.617+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{8C416C79-D49B-4F01-A467-E56D3AA8234C}"
    },
    "execution": {
      "process_id": 6504,
      "thread_id": 556
    },
    "channel": "ETW Trace",
    "computer": "DESKTOP-FF3N5XK",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "FilterType": 13,
    "pstrLib": "NULL",
    "hmod": "0x0",
    "pfnFilterProc": "0x1EC341D6C0C",
    "ReturnValue": 3408085
  },
  "message": ""
}

Event ID 1003: GetAsyncKeyState

#
Provider
Microsoft-Windows-Win32k
Channel
Operational
Also via
realtime ETW trace
Level
Informational
Opcode
Info

Description

Fires when a background process calls GetAsyncKeyState while another process holds the foreground. BackgroundCallCount accumulates calls since the last key event; MsSinceLastKeyEvent is the interval since the previous key press. Captured via the AuditApiCalls ETW keyword (0x400) on the Microsoft-Windows-Win32k provider. Requires an interactive desktop session with active keyboard input.

Fields #

NameDescription
PID UInt32Process ID of the background caller polling keyboard state
MsSinceLastKeyEvent UInt32Milliseconds elapsed since the last key press event in the session
BackgroundCallCount UInt32Number of GetAsyncKeyState calls made by this background process since the last key event

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Win32k",
    "guid": "{8C416C79-D49B-4F01-A467-E56D3AA8234C}",
    "event_source_name": "",
    "event_id": 1003,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": "0x0000000000000400",
    "time_created": "2026-06-08T21:12:41.337+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{8C416C79-D49B-4F01-A467-E56D3AA8234C}"
    },
    "execution": {
      "process_id": 808,
      "thread_id": 928
    },
    "channel": "ETW Trace",
    "computer": "DESKTOP-FF3N5XK",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "PID": 11716,
    "MsSinceLastKeyEvent": 0,
    "BackgroundCallCount": 2
  },
  "message": ""
}

Event ID 2000: task_02000

#
Provider
Microsoft-Windows-Win32k
Channel
Operational
Also via
realtime ETW trace
Level
Informational
Opcode
Info

Fields #

NameDescription
Flags UInt32
ProcessId UInt32
ProcessCreateTime FILETIME
ProcessStartKey UInt64

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Win32k",
    "guid": "{8C416C79-D49B-4F01-A467-E56D3AA8234C}",
    "event_source_name": "",
    "event_id": 2000,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": "0x0000004000000000",
    "time_created": "2026-06-02T05:32:25.771+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{8C416C79-D49B-4F01-A467-E56D3AA8234C}"
    },
    "execution": {
      "process_id": 14592,
      "thread_id": 10500
    },
    "channel": "ETW Trace",
    "computer": "JD-DC01-2022",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Flags": 26,
    "ProcessCreateTime": "2026-06-02 05:32:25.725Z",
    "ProcessId": 14592,
    "ProcessStartKey": 6755399441100732
  },
  "message": ""
}

Event ID 10002: WindowLayoutChangeStop

#
Provider
Microsoft-Windows-Win32k
Channel
Tracing
Task
WindowLayoutChange
Opcode
Stop

Fields #

NameDescription
hWnd UInt32
Packed_High_Height_Low_Width UInt32
PRAID UnicodeString
PackageFullName UnicodeString

Provenance

Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.

ETW provider GUID {8C416C79-D49B-4F01-A467-E56D3AA8234C}

Defined in win32kbase.sys, the binary that emits these events.

Observed on:

  • WS2022-20348.4893, sample captured from a live trace, binary version 10.0.20348.4893, captured 2026-06-02
  • Win11-26200.6584, sample captured from a live trace, binary version 10.0.26100.1000, captured 2026-06-02
  • WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.4893, captured 2026-06-02
  • Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.1000, captured 2026-06-02

Downloads