Event Tracing Functions for Kernel Mode Providers
This section describes the Event Tracing for Windows kernel-mode functions to register event providers, to enable events, and to trace events.
In this section
- EtwRegister
- EtwUnregister
- EtwEventEnabled
- EtwProviderEnabled
- EtwActivityIdControl
- EtwActivityIdControlKernel
- EtwWrite
- EtwWriteEx
- EtwWriteTransfer
- EtwWriteString
- SeEtwWriteKMCveEvent
- PETWENABLECALLBACK