Was this page helpful?
Your feedback about this content is important. Let us know what you think.
Additional feedback?
1500 characters remaining
Export (0) Print
Expand All

Win32_ProcessStartTrace class

The Win32_ProcessStartTrace event WMI classindicates that a new process has started.

The following syntax is simplified from Managed Object Format (MOF) code and includes all of the inherited properties. Properties and methods are in alphabetic order, not MOF order.

Syntax

[AMENDMENT]
class Win32_ProcessStartTrace : Win32_ProcessTrace
{
  uint32 ParentProcessID;
  uint4  PageDirectoryBase;
  string ProcessName;
  uint32 SessionID;
};

Members

The Win32_ProcessStartTrace class has these types of members:

Properties

The Win32_ProcessStartTrace class has these properties.

PageDirectoryBase
Data type: uint4
Access type: Read-only

Identifies the process page directory base. Beginning with Windows Vista, this property is not available.

Windows Server 2003:  This property is available, but does not contain data that is useful outside of the operating system.

ParentProcessID
Data type: uint32
Access type: Read-only

Process that starts an event.

This property is inherited from Win32_ProcessTrace.

ProcessName
Data type: string
Access type: Read-only

Name of the process. You can use this name to get the instance of the Win32_Process for same process.

SessionID
Data type: uint32
Access type: Read-only

Session under which the process exists.

Remarks

The Win32_ProcessStartTrace class is derived from Win32_ProcessTrace.

Requirements

Minimum supported client

Windows Vista

Minimum supported server

Windows Server 2003

Namespace

Root\CIMV2

MOF

Krnlprov.mof

DLL

Krnlprov.dll

See also

Win32_ProcessTrace
Operating System Classes
Win32_Process

 

 

Show:
© 2015 Microsoft