Win32_SystemTrace class

The Win32_SystemTrace event WMI class is the base class for all system trace events. System trace events are fired by the kernel logger, using the Event Tracing application programming interface (API).

The following syntax is simplified from Managed Object Format (MOF) code and includes all of the inherited properties. Properties and methods are in alphabetic order, not MOF order.

Syntax

[AMENDMENT]
class Win32_SystemTrace : __ExtrinsicEvent
{
  uint8  SECURITY_DESCRIPTOR[];
  uint64 TIME_CREATED;
};

Members

The Win32_SystemTrace class has these types of members:

Properties

The Win32_SystemTrace class has these properties.

SECURITY_DESCRIPTOR
Data type: uint8 array
Access type: Read-only

Descriptor used by the event provider to determine which users can receive the event. This property is inherited from __Event. For more information about constants used to set this security descriptor, see WMI Security Constants.

TIME_CREATED
Data type: uint64
Access type: Read-only

Unique value that indicates the time at which the event was generated. This is a 64-bit value that represents the number of 100-nanosecond intervals after January 1, 1601. The information is in the Coordinated Universal Times (UTC) format. This property is inherited from __Event.

For more information about using uint64 values in scripts, see Scripting in WMI.

Remarks

The Win32_SystemTrace class is derived from the WMI __ExtrinsicEvent system class.

Requirements

Minimum supported client

Windows Vista

Minimum supported server

Windows Server 2008

Namespace

Root\CIMV2

MOF

Krnlprov.mof

DLL

Krnlprov.dll

See also

__ExtrinsicEvent
Operating System Classes

 

 

Show: