Process Monitor - how to capture process creation/termination?

empleat 131 Reputation points
2021-03-24T20:53:17.807+00:00

81210-procmon.png
I have enabled show "process and thread activity" pressed "Ctrl+L" and added "Operation" "contains" "Process" "Include". In File -> Capture Events is enabled. Yet no process creation, or termination is logged!!! Why it doesn't work? I was able to google only 1 article, in which it said: the way to do it is this and yet it doesn't work... Tried launch as admin, doesn't work also!

Sysinternals
Sysinternals
Advanced system utilities to manage, troubleshoot, and diagnose Windows and Linux systems and applications.
0 comments No comments
{count} votes

6 answers

Sort by: Most helpful
  1. Castorix31 91,281 Reputation points
    2021-03-24T21:24:47.493+00:00

    This test with Notepad works for me (version 3.60) =>

    81227-procmon-notepad.jpg

    0 comments No comments

  2. empleat 131 Reputation points
    2021-03-25T17:55:20.777+00:00

    Yeah but I didn't say notepad, I want to monitor every process creation. I just downloaded it from MS, it says version 3.61. Also tried 32 bit version - didn't work.


  3. empleat 131 Reputation points
    2021-03-26T17:00:15.203+00:00

    LOL I still get nothing! Everything is bugged for me. Doing that literally same as you and nothing! LOL wat, you 2nd answer just disappeared! 81939-procmon-bug.png

    **EDIT:**Today tried again and now it works, maybe I needed to enter all 3 entries, but it does not make sense that all 3 would be needed. It happens to me in other programs too. First 2 times I launch them it doesn't work and trird times something works. Everything is so bugged... Dude so bugged. Your answer from -3 days showed when I opened browser and after I edited my post I wanted to select your answer as solution, now it is missing again... And it is not addons! I disable them and still... On other MS forums when I click to write text - nothing happens and text already written flashes LOL... SO BUGGED SO STUPID...

    THANKS FOR HELP BTW!

    0 comments No comments

  4. empleat 131 Reputation points
    2021-04-19T22:29:26.393+00:00

    Again it doesn't work, this time I Am trying to monitor changes done by programs in a folder. Using Path contains {path} and again nothing is showing... It is pretty simple, I don't know why it doesn't work. And no idea why it started to work all of the sudden previously. Show filesystem activity is enabled, as well capture. I tried to restart program 2 times, or launch as admin, didn't help!

    EDIT: I did it same as in some video and it worked for him. It doesn't work for me - similarly like before! No idea why!

    0 comments No comments

  5. Steven Whiting 101 Reputation points
    2021-04-28T08:57:23.027+00:00

    Have you clicked reset on your filter then tried again? I've had it at times where I've forgotten to reset the filter and its trying to look for an app that is no longer running.

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.