We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
EventFilter::ByPids are only effective on kernel mode logger session.
EventFilter::ByPids
see https://learn.microsoft.com/en-us/windows/win32/api/evntprov/ns-evntprov-event_filter_descriptor:
The PIDs based filter-blob is only valid for a kernel mode logger session because the private logger session runs inside a user-mode process
But this does not work for KernelTraces in ferrisetw. This would be good to support it.
KernelTrace
Ideas:
ferrisetw::KernelTrace
If this eventually works, this should be added in an integration test
The text was updated successfully, but these errors were encountered:
[doc] Event filters
a552a2a
* Some filters are not effetive on Win7 * By-PID filters may not work, even for kernel traces See n4r1b#51
d816f2b
No branches or pull requests
EventFilter::ByPids
are only effective on kernel mode logger session.see https://learn.microsoft.com/en-us/windows/win32/api/evntprov/ns-evntprov-event_filter_descriptor:
But this does not work for
KernelTrace
s in ferrisetw. This would be good to support it.Ideas:
ferrisetw::KernelTrace
one of them in the first place?If this eventually works, this should be added in an integration test
The text was updated successfully, but these errors were encountered: