Windows Notification Facility Provider

5 events across 1 channel

EventTitleChannelSample
32WNFSubUnsubETW TraceY
33WNFSubUnsubETW TraceY
34WNFCallbackETW TraceY
35WNFPublishETW TraceY
36WNFNameSubRundownETW TraceY

Event ID 32: WNFSubUnsub

#
Provider
Windows Notification Facility Provider
Channel
ETW Trace
Also via
realtime ETW trace
Source
Trace

Fields #

NameDescription
StateName mof:UInt64
Subscription mof:UInt32
NameSub mof:UInt32
Callback mof:UInt32
RefCount mof:UInt32
DeliveryFlags mof:UInt32

Example Event #

{
  "system": {
    "provider": "Windows Notification Facility Provider",
    "guid": "{42695762-EA50-497A-9068-5CBBB35E0B95}",
    "event_source_name": "",
    "event_id": 32,
    "version": 2,
    "level": 0,
    "task": 0,
    "opcode": 32,
    "keywords": "",
    "time_created": "2026-06-02T04:02:19.162+00:00",
    "event_record_id": 0,
    "correlation": {},
    "execution": {
      "process_id": 5388,
      "thread_id": 13968
    },
    "channel": "ETW Trace",
    "computer": "JD-DC01-2022",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Callback": "0x7FF9FAAD7D90",
    "DeliveryFlags": 17,
    "NameSub": "0x2088413B880",
    "RefCount": 1,
    "StateName": 541872588846794869,
    "Subscription": "0x2088413B7D0"
  },
  "message": ""
}

Event ID 33: WNFSubUnsub

#
Provider
Windows Notification Facility Provider
Channel
ETW Trace
Also via
realtime ETW trace
Source
Trace

Fields #

NameDescription
StateName mof:UInt64
Subscription mof:UInt32
NameSub mof:UInt32
Callback mof:UInt32
RefCount mof:UInt32
DeliveryFlags mof:UInt32

Example Event #

{
  "system": {
    "provider": "Windows Notification Facility Provider",
    "guid": "{42695762-EA50-497A-9068-5CBBB35E0B95}",
    "event_source_name": "",
    "event_id": 33,
    "version": 2,
    "level": 0,
    "task": 0,
    "opcode": 33,
    "keywords": "",
    "time_created": "2026-06-02T04:02:19.172+00:00",
    "event_record_id": 0,
    "correlation": {},
    "execution": {
      "process_id": 1400,
      "thread_id": 11792
    },
    "channel": "ETW Trace",
    "computer": "JD-DC01-2022",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Callback": "0x7FF9FBB49DA0",
    "DeliveryFlags": 8,
    "NameSub": "0x20E5C6F43D0",
    "RefCount": 2,
    "StateName": 4739561890658924613,
    "Subscription": "0x20E5B668000"
  },
  "message": ""
}

Event ID 34: WNFCallback

#
Provider
Windows Notification Facility Provider
Channel
ETW Trace
Also via
realtime ETW trace
Source
Trace

Fields #

NameDescription
StateName mof:UInt64
Subscription mof:UInt32
NameSub mof:UInt32
Callback mof:UInt32
ChangeStamp mof:UInt32
DeliveryFlags mof:UInt32
Return mof:UInt32

Example Event #

{
  "system": {
    "provider": "Windows Notification Facility Provider",
    "guid": "{42695762-EA50-497A-9068-5CBBB35E0B95}",
    "event_source_name": "",
    "event_id": 34,
    "version": 2,
    "level": 0,
    "task": 0,
    "opcode": 34,
    "keywords": "",
    "time_created": "2026-06-02T04:02:19.172+00:00",
    "event_record_id": 0,
    "correlation": {},
    "execution": {
      "process_id": 1120,
      "thread_id": 13620
    },
    "channel": "ETW Trace",
    "computer": "JD-DC01-2022",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Callback": "0x7FF9F8CA9BD0",
    "ChangeStamp": 16,
    "DeliveryFlags": 1,
    "NameSub": "0x19E9CC7C270",
    "Return": 0,
    "StateName": 4739561890658924613,
    "Subscription": "0x19E9CC84180"
  },
  "message": ""
}

Event ID 35: WNFPublish

#
Provider
Windows Notification Facility Provider
Channel
ETW Trace
Also via
realtime ETW trace
Source
Trace

Fields #

NameDescription
StateName mof:UInt64
DataLength mof:UInt32

Example Event #

{
  "system": {
    "provider": "Windows Notification Facility Provider",
    "guid": "{42695762-EA50-497A-9068-5CBBB35E0B95}",
    "event_source_name": "",
    "event_id": 35,
    "version": 2,
    "level": 0,
    "task": 0,
    "opcode": 35,
    "keywords": "",
    "time_created": "2026-06-02T04:02:19.171+00:00",
    "event_record_id": 0,
    "correlation": {},
    "execution": {
      "process_id": 1400,
      "thread_id": 10676
    },
    "channel": "ETW Trace",
    "computer": "JD-DC01-2022",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "DataLength": 244,
    "StateName": 4739561890658924613
  },
  "message": ""
}

Event ID 36: WNFNameSubRundown

#
Provider
Windows Notification Facility Provider
Channel
ETW Trace
Also via
realtime ETW trace
Source
Trace

Fields #

NameDescription
StateName mof:UInt64
NameSub mof:UInt32

Example Event #

{
  "system": {
    "provider": "Windows Notification Facility Provider",
    "guid": "{42695762-EA50-497A-9068-5CBBB35E0B95}",
    "event_source_name": "",
    "event_id": 36,
    "version": 2,
    "level": 0,
    "task": 0,
    "opcode": 36,
    "keywords": "",
    "time_created": "2026-06-02T04:02:19.172+00:00",
    "event_record_id": 0,
    "correlation": {},
    "execution": {
      "process_id": 1400,
      "thread_id": 3940
    },
    "channel": "ETW Trace",
    "computer": "JD-DC01-2022",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "NameSub": "0x20E5C6F43D0",
    "StateName": 4739561890658924613
  },
  "message": ""
}

Provenance

Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.

ETW provider GUID {42695762-EA50-497A-9068-5CBBB35E0B95}

Observed on:

  • WS2025-26100.0, schema read from the WMI MOF class, captured 2026-02-26

    Taken from Windows installation media (build 26100.1), not a patched system, so the exact update level is unknown.

  • WS2022-20348.4893, sample captured from a live trace, captured 2026-06-02
  • WS2022-20348.4893, schema read from the WMI MOF class, captured 2026-06-02

    MOF class: WnfProvider

  • Win11-26200.6584, schema read from the WMI MOF class, captured 2026-06-02

    MOF class: WnfProvider