question

YenMingChiu-7791 avatar image
0 Votes"
YenMingChiu-7791 asked SongZhu-MSFT commented

How to subscribe to all registered valid event channels?

I used EvtOpenChannelEnum to fetch all registered events on the computer, then trying to subscribe to them with EvtSubscribe.
And some of them lead to the error 4201 (The instance name passed was not recognized as valid by a WMI data provider.)

I did filter out those channels which have "/Analytic" and "/Debug" at the end of the name, and those channels are named "Analytic" or "Debug". But it still doesn't work.
Is there have any other limitations with ETW subscriptions?

PS: the following picture shows a part of what I got after fetching and filtering.
81492-etw-channels.png


windows-apic++
etw-channels.png (54.9 KiB)
· 1
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

ERROR_WMI_INSTANCE_NOT_FOUND means "the session from which you are trying to consume events in real time is not running or does not have the real-time trace mode enabled".And you can refer to Why isn't my Event Trace for Windows working?.

1 Vote 1 ·

0 Answers