Process Monitor Not Picking Up Any Events When "Drop Filtered Events" is toggeled?

Curtis W. Wright 0 Reputation points
2024-07-18T21:41:49.8366667+00:00

I am trying to troubleshoot an issue with Sever 2022 becoming unable to RDP into it after some time, and I'm trying to use Process Monitor to monitor the key HKLM\SYSTEM\CurrentControlSet\Control\Terminal Server\fDenyTSConnections. However, when I toggle "Drop Filtered Events" it doesn't seem to capture anything. I can confirm that when I manually change the registry key, it displays the events as intended. Screenshot 2024-07-18 143739

But when I drop the events, it stops working.

Screenshot 2024-07-18 143757

I can't just leave it, as the memory quickly fills up and crashes the program with maybe 30 minutes of running, and this issue takes hours to manifest. Am I missing something?

Screenshot 2024-07-18 144229

Server 2022 21H2 20348.2582. Process Monitor 4.01.

Screenshot 2024-07-18 144236

Screenshot 2024-07-18 144241

Sysinternals
Sysinternals
Advanced system utilities to manage, troubleshoot, and diagnose Windows and Linux systems and applications.
1,218 questions
0 comments No comments
{count} votes

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.