Huge thanks to our Platinum Members Endace and LiveAction,
and our Silver Member Veeam, for supporting the Wireshark Foundation and project.

Display Filter Reference: Event Tracing for Windows

Protocol field name: etw

Versions: 3.6.0 to 4.2.4

Back to Display Filter Reference

Field name Description Type Versions
etw.activity_idActivity IDGlobally Unique Identifier3.6.0 to 4.2.4
etw.buffer_context.alignmentAlignmentUnsigned integer (8 bits)3.6.0 to 4.2.4
etw.buffer_context.logger_idIDUnsigned integer (16 bits)3.6.0 to 4.2.4
etw.buffer_context.processor_numberProcessor NumberUnsigned integer (8 bits)3.6.0 to 4.2.4
etw.descriptor.channelChannelUnsigned integer (8 bits)3.6.0 to 4.2.4
etw.descriptor.idIDUnsigned integer (16 bits)3.6.0 to 4.2.4
etw.descriptor.keywordsKeywordsUnsigned integer (64 bits)3.6.0 to 4.2.4
etw.descriptor.levelLevelUnsigned integer (8 bits)3.6.0 to 4.2.4
etw.descriptor.opcodeOpcodeUnsigned integer (8 bits)3.6.0 to 4.2.4
etw.descriptor.taskTaskUnsigned integer (16 bits)3.6.0 to 4.2.4
etw.descriptor.versionVersionUnsigned integer (8 bits)3.6.0 to 4.2.4
etw.event_propertyEvent PropertyUnsigned integer (16 bits)3.6.0 to 4.2.4
etw.flagsFlagsUnsigned integer (16 bits)3.6.0 to 4.2.4
etw.header_typeHeader TypeUnsigned integer (16 bits)3.6.0 to 4.2.4
etw.messageEvent MessageCharacter string3.6.0 to 4.2.4
etw.message_lengthMessage LengthUnsigned integer (32 bits)3.6.0 to 4.2.4
etw.process_idProcess IDUnsigned integer (32 bits)3.6.0 to 4.2.4
etw.processor_timeProcessor TimeUnsigned integer (64 bits)3.6.0 to 4.2.4
etw.provider_idProvider IDGlobally Unique Identifier3.6.0 to 4.2.4
etw.provider_nameProvider NameCharacter string3.6.0 to 4.2.4
etw.provider_name_lengthProvider Name LengthUnsigned integer (32 bits)3.6.0 to 4.2.4
etw.sizeSizeUnsigned integer (16 bits)3.6.0 to 4.2.4
etw.thread_idThread IDUnsigned integer (32 bits)3.6.0 to 4.2.4
etw.time_stampTime StampUnsigned integer (64 bits)3.6.0 to 4.2.4
etw.user_data_lengthUser Data LengthUnsigned integer (32 bits)3.6.0 to 4.2.4