MSNT_SystemTrace, ROOT\WMI

Class | Childs (56) | Methods | Properties (1) | Qualifiers (4) | Instances | Namespaces (2)
Samples: VB Script | C# | VB.Net | Search on:Microsoft

Description

Windows Kernel Trace

MSNT_SystemTrace - child subclasses in ROOT\WMI

Number of classes:56
Class nameChildsPropertiesMethodsClass
Instances
Child
Instances
AbstractSingleton
ALPC510----
Debugger110----
DiskIo310----
DiskIo_V0110----
DiskIo_V1510----
DiskIo_V2810----
EventTraceEvent610----
EventTraceEvent_V0310----
EventTraceEvent_V1310----
FileIo1110----
FileIo_V0110----
FileIo_V1110----
FileIo_V2810----
Image410----
Image_V0110----
Image_V1110----
Image_V2610----
Lost_Event110----
MMCSSTrace310----
ObTrace610----
PageFault110----
PageFault_V21110----
PerfInfo210----
PerfInfo_V0110----
PerfInfo_V1310----
PerfInfo_V21610----
PoolTrace310----
PowerEvents110----
Process110----
Process_V0110----
Process_V1110----
Process_V2610----
Process_V3110----
Process_V4110----
Registry1010----
Registry_V0110----
Registry_V1110----
SplitIo110----
StackWalk310----
SystemConfig110----
SystemConfig_V0910----
SystemConfig_V1910----
SystemConfig_V21810----
SystemConfig_V3410----
SystemConfig_V4110----
TcpIp710----
TcpIp_V0110----
TcpIp_V1610----
Thread210----
Thread_V0110----
Thread_V1410----
Thread_V21510----
UdpIp310----
UdpIp_V0110----
UdpIp_V1110----
UmsEvent510----

MSNT_SystemTrace properties

MSNT_SystemTrace has 1 properties (1 Local)

NameOriginCIMType
FlagsMSNT_SystemTrace19 [uint32]

Detailed description of MSNT_SystemTrace properties

Local properties (1) of MSNT_SystemTrace class

Flags property
CIMTYPE'uint32'
DefineValues['EVENT_TRACE_FLAG_PROCESS', 'EVENT_TRACE_FLAG_THREAD', 'EVENT_TRACE_FLAG_IMAGE_LOAD', 'EVENT_TRACE_FLAG_PROCESS_COUNTERS', 'EVENT_TRACE_FLAG_CSWITCH', 'EVENT_TRACE_FLAG_DPC', 'EVENT_TRACE_FLAG_INTERRUPT', 'EVENT_TRACE_FLAG_SYSTEMCALL', 'EVENT_TRACE_FLAG_DISK_IO', 'EVENT_TRACE_FLAG_DISK_FILE_IO', 'EVENT_TRACE_FLAG_DISK_IO_INIT', 'EVENT_TRACE_FLAG_DISPATCHER', 'EVENT_TRACE_FLAG_MEMORY_PAGE_FAULTS', 'EVENT_TRACE_FLAG_MEMORY_HARD_FAULTS', 'EVENT_TRACE_FLAG_VIRTUAL_ALLOC', 'EVENT_TRACE_FLAG_NETWORK_TCPIP', 'EVENT_TRACE_FLAG_REGISTRY', 'EVENT_TRACE_FLAG_ALPC', 'EVENT_TRACE_FLAG_SPLIT_IO', 'EVENT_TRACE_FLAG_DRIVER', 'EVENT_TRACE_FLAG_PROFILE', 'EVENT_TRACE_FLAG_FILE_IO', 'EVENT_TRACE_FLAG_FILE_IO_INIT']
Description'Enable Flags'
ValueDescriptions['Process creations/deletions', 'Thread creations/deletions', 'Image load', 'Process counters', 'Context switches', 'Deferred procedure calls', 'Interrupts', 'System calls', 'Disk IO', 'File details', 'Disk IO entry', 'Dispatcher operations', 'Page faults', 'Hard page faults', 'Virtual memory allocations', 'Network TCP/IP', 'Registry details', 'ALPC', 'Split IO', 'Driver delays', 'Sample based profiling', 'File IO completion', 'File IO']
ValueMap['0x00000001', '0x00000002', '0x00000004', '0x00000008', '0x00000010', '0x00000020', '0x00000040', '0x00000080', '0x00000100', '0x00000200', '0x00000400', '0x00000800', '0x00001000', '0x00002000', '0x00004000', '0x00010000', '0x00020000', '0x00100000', '0x00200000', '0x00800000', '0x01000000', '0x02000000', '0x04000000']
Values['process', 'thread', 'img', 'proccntr', 'cswitch', 'dpc', 'isr', 'syscall', 'disk', 'file', 'diskinit', 'dispatcher', 'pf', 'hf', 'virtalloc', 'net', 'registry', 'alpc', 'splitio', 'driver', 'profile', 'fileiocompletion', 'fileio']
Flags property is in 2953 classes of ROOT\WMI and in 142 namespaces

MSNT_SystemTrace Qualifiers

NameValueToInstanceToSubclassOverridableAmendedLocal
Description'Windows Kernel Trace'
dynamicTrue
Guid'{9e814aad-3204-11d2-9a82-006008a86939}'
LOCALE'ms_409'

MSNT_SystemTrace System properties

NameValueOriginCIMTypeLocalArray
__PATH'\\.\ROOT\WMI:MSNT_SystemTrace'___SYSTEM8
__NAMESPACE'ROOT\WMI'___SYSTEM8
__SERVER'.'___SYSTEM8
__DERIVATION['EventTrace']___SYSTEM8
__PROPERTY_COUNT1___SYSTEM3
__RELPATH'MSNT_SystemTrace'___SYSTEM8
__DYNASTY'EventTrace'___SYSTEM8
__SUPERCLASS'EventTrace'___SYSTEM8
__CLASS'MSNT_SystemTrace'___SYSTEM8
__GENUS1___SYSTEM3
comments powered by Disqus
WUtils.com