EtwLogger

final class ntoseye.EtwLogger

Subclass of BaseRecord.

An active ETW trace session, decoded from its _WMI_LOGGER_CONTEXT.

property address: int

The _WMI_LOGGER_CONTEXT.

property buffer_size: int

Bytes per buffer.

property buffers_available: int
property buffers_in_use: int

The buffers taken from the free pool (number_of_buffers - buffers_available). Each of these buffers is current on a processor, full, or in a flush.

property buffers_written: int
property clock: str

The name of what the event timestamps count.

property clock_type: int

ClockType (EVENT_TRACE_CLOCK_*).

property collection_on: bool
property consumers: int
property events_lost: int
property flag_names: list[str]

The Flags bitfields that are set, from the PDB.

property flags: int
property flush_threshold: int
property flush_timer: int
property instance_guid: str
property log_buffers_lost: int
property log_file_name: str | None

LogFileName. None if ntoseye cannot read its buffer.

property logger_id: int
property logger_mode: int
property logger_mode_names: list[str]

The EVENT_TRACE_*_MODE bits that are set in logger_mode.

property logger_status: int
property logger_thread: int
property maximum_buffers: int
property maximum_event_size: int
property maximum_file_size: int
property minimum_buffers: int
property name: str | None

LoggerName. None if ntoseye cannot read its buffer, which can happen when the pool is freed or paged out while a session stops.

property number_of_buffers: int
property peak_buffers: int
property real_time_buffers_delivered: int
property real_time_buffers_lost: int
property start_time: int

StartTime, a FILETIME.

property start_time_utc: str | None

start_time as UTC (YYYY-MM-DD HH:MM:SS.fffffff). None if it is out of range.