--please don't forget to upvote
and Accept as answer
if the reply is helpful--
Kernel-EventTracing Event ID 32
Hi, I have a lot events with id 32 (Kernel-EventTracing/Admin)
I can't find anything about that, any idea?
Detailed event description below:
Log Name: Microsoft-Windows-Kernel-EventTracing/Admin
Source: Microsoft-Windows-Kernel-EventTracing
Date: 10.12.2021 10:42:07
Event ID: 32
Task Category: Provider
Level: Warning
Keywords: Provider,Session
User: SYSTEM
Computer: w2k22
Description:
Failed to look up debug info for provider {c85ab4ed-7f0f-42c7-8421-995da9810fdd} from process 93323264 for session "圼送 fh". Error: Unknown NTSTATUS Error code: 0xb70c3577. Either the debug data could not be found, or the debug data is inaccessible because the image registering the provider is malformed.
Event Xml:
<Event xmlns='http://schemas.microsoft.com/win/2004/08/events/event'><System><Provider Name='Microsoft-Windows-Kernel-EventTracing' Guid='{b675ec37-bdb6-4648-bc92-f3fdc74d3ca2}'/><EventID>32</EventID><Version>0</Version><Level>3</Level><Task>3</Task><Opcode>0</Opcode><Keywords>0x8000000000000030</Keywords><TimeCreated SystemTime='2021-12-10T09:42:07.1171368Z'/><EventRecordID>44120</EventRecordID><Correlation/><Execution ProcessID='3464' ThreadID='11652'/><Channel>Microsoft-Windows-Kernel-EventTracing/Admin</Channel><Computer>w2k22</Computer><Security UserID='S-1-5-18'/></System><EventData><Data Name='ProviderGuid'>{c85ab4ed-7f0f-42c7-8421-995da9810fdd}</Data><Data Name='SessionName'>圼送 fh</Data><Data Name='ProcessId'>93323264</Data><Data Name='Status'>3071030647</Data></EventData></Event>
6 answers
Sort by: Most helpful
-
Anonymous
Dec 10, 2021, 2:23 PM -
Limitless Technology 39,686 Reputation points
Dec 10, 2021, 3:44 PM Hello
Thank you for your question and reaching out.
Event id is 2. Always lots of threads have the same event and it should be harmless and can be safely ignored.
It may be related to your cloud storage. For example One drive. It may have given you this prompt when you started.
So I consider that you could check the information about Onedrive below to check.Also try Disable any third party Antivirus you may have for temporary.
--If the reply is helpful, please Upvote and Accept as answer--
-
ms 11 Reputation points
Dec 13, 2021, 7:13 AM Hi, thx for sugestions.
I didn't find solution yet. This server is RDS terminal, do some chinese signs like ' 圼 送' in log are disturbing. Google translate says that means 'send' what i again disturbing. I tried to track down the source process but without lack, work in progress. -
Gary Nebbett 6,091 Reputation points
Dec 13, 2021, 9:33 AM Hello @ms ,
When a DLL registers an event provider, the event tracing mechanism tries to extract some information from the "debug directory" in the PE header of the DLL. This information is added to the trace data as a ProviderBinaryPath event:
My guess is that some (probably non-Microsoft) DLL is present on the system and a trace provider in that DLL is being started; furthermore, that DLL probably either does not contain a debug directory, or contains a debug directory without an CodeView RSDS format entry.
The Chinese characters are probably harmless too. My guess is that the format string for the event specifies that a Unicode (UTF-16LE) string is required for the SessionName value but a UTF-8/ASCII string is being provided (a bug). UTF-8 encodings, when decoded as UTF-16 normally returns Chinese characters (due to the positions of the various character sets in Unicode).
Gary
-
ms 11 Reputation points
Dec 13, 2021, 12:54 PM Hi,
Event is related with SCOM. In each hour show 24-33 events with id 32, in each time three same warning with different session provider, always the same:c85ab4ed-7f0f-42c7-8421-995da9810fdd
36cd7b6e-631a-42e1-a3c0-d436ac41bc61
c7a7ea08-da1f-4681-bbaa-5522771e0711after tuning on maintenance mode from SCOM console (not service agent on server), event stoped showing, now after more than 1 hours no new logs.
I guess that is related with some healt monitor, mayby it is not compatible with Windows Server 2022 yet? (this server is not only server in my enviroment with w2k22 and scom agent installed, the rest not raport event 32, but each server have diferent roles and apps).