EtwEvent

final class ntoseye.EtwEvent

Subclass of BaseRecord.

An event record that ntoseye decoded from a trace buffer. A field is None if the header kind of the event does not have it.

property activity_id: str | None
property buffer: int

The buffer that the event came from.

property descriptor: EtwEventDescriptor | None
property event_class: EtwEventClass | None

The class of a classic event. The JSON key is class.

property event_flags: int | None

EVENT_HEADER.Flags.

property extended: list[EtwExtendedData]
property group: str | None

The EVENT_TRACE_GROUP_* name of the hook id, if it is known.

property guid: str | None

The provider GUID (EVENT_HEADER), event class GUID (EVENT_TRACE_HEADER), or message GUID (MESSAGE_TRACE_HEADER).

property header: str

The trace header at the start of the record (EVENT_HEADER, …).

property header_type: int
property hook_id: int | None

The kernel hook id (group << 8 | type) of system and perfinfo events.

property message: EtwEventMessage | None
property offset: int

The offset of the record in its buffer.

property payload: str

The user data of the event, as hex.

property process_id: int | None
property processor: int
property size: int

The record size, with the header included (unaligned).

property system_time: int | None

The FILETIME, if the clock of the logger converts to one.

property system_time_utc: str | None

system_time as UTC (YYYY-MM-DD HH:MM:SS.fffffff).

property thread_id: int | None
property timestamp: int | None

The raw timestamp in the clock of the logger. A WPP message without TRACE_MESSAGE_TIMESTAMP has no timestamp.