Microsoft-Windows-Kernel-EventTracing

Seen on:

  • Windows 2008

  • Windows 7

  • Windows 8.0

Name: Microsoft-Windows-Kernel-EventTracing
Identifier: {b675ec37-bdb6-4648-bc92-f3fdc74d3ca2}
Event message file(s): %SystemRoot%\system32\advapi32.dll

 

Seen on:

  • Windows 2012

  • Windows 8.1

  • Windows 10 (1511, 1607, 1703, 1709, 1803, 1809, 1903, 1909, 2004, 20H2)

  • Windows 2016

  • Windows 2019

  • Windows 11 (21H2)

Name: Microsoft-Windows-Kernel-EventTracing
Identifier: {b675ec37-bdb6-4648-bc92-f3fdc74d3ca2}
Event message file(s): %SystemRoot%\system32\Microsoft-Windows-System-Events.dll