Skip to content
Generic ETW manifest file with a "key: value" format for events.
Branch: master
Clone or download
Fetching latest commit…
Cannot retrieve the latest commit at this time.
Permalink
Type Name Latest commit message Commit time
Failed to load latest commit information.
ETWTestCS
ETWTestUapp
disptrace
JyTrace.cs
LICENSE
LICENSE.md
MSG00001.bin
README.md
jytrace.dll
jytrace.h
jytrace.man
jytrace.rc
jytrace.res
jytraceTEMP.BIN
mftrace.zip

README.md

win32-etw-manifest

Generic ETW manifest file with a "key: value" format for events. Check out this blog post for more information.

How to compile the manifest file

mc -um <name>.man

Compile .rc to .res

rc <input>.rc

Create a dll from the .res file

link -dll -noentry -out:<out>.dll <input>.res

Register the manifest to the system

wevtutil im <manifest_file>.man /rf:"<full_path_to_noentry_dll>" /mf:"<full_path_to_noentry_dll>"

Remove the manifest from the system:

wevtutil um <manifest_file>.man

License

The MIT License

You can’t perform that action at this time.