[ Mini Kiebo ]
Server: Windows NT AKFAR_SERVER 10.0 build 26200 (Windows 10) AMD64
Path:
D:
/
Data
/
FD Nitip
/
/
support
/
logging
/
[
Home
]
File: microsoft-windows-audit-instrumentation.man
<?xml version='1.0' encoding='utf-8' standalone='yes'?> <assembly xmlns="urn:schemas-microsoft-com:asm.v3" xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" copyright="Copyright (c) Microsoft Corporation. All Rights Reserved." manifestVersion="1.0"> <assemblyIdentity buildType="release" language="neutral" name="Microsoft-Windows-Audit-Instrumentation" processorArchitecture="amd64" publicKeyToken="31bf3856ad364e35" version="10.0.10240.16384" versionScope="nonSxS"/> <registryKeys> <registryKey keyName="HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\AutoLogger\Microsoft-Windows-Setup\{75EBC33E-0936-4a55-9D26-5F298F3180BF}"> <registryValue name="Enabled" value="1" valueType="REG_DWORD"/> <registryValue name="EnableLevel" value="4" valueType="REG_DWORD"/> </registryKey> </registryKeys> <instrumentation xmlns:win="http://manifests.microsoft.com/win/2004/08/windows/events" xmlns:xs="http://www.w3.org/2001/XMLSchema"> <events xmlns="http://schemas.microsoft.com/win/2004/08/events"> <provider guid="{75EBC33E-0936-4a55-9D26-5F298F3180BF}" message="$(string.Audit.ProviderMessage)" messageFileName="%SystemRoot%\system32\oobe\audit.exe" name="Microsoft-Windows-Audit" resourceFileName="%SystemRoot%\system32\oobe\audit.exe" symbol="Microsoft_Windows_Audit"> <channels> <channel chid="chaAuditAnalytic" name="Microsoft-Windows-Audit/Analytic" type="Analytic"/> <importChannel chid="chaSetup" name="Setup"/> </channels> <keywords> <keyword mask="0x00000001" message="$(string.Performance.KeywordMessage)" name="keyPerformance"/> <keyword mask="0x00000002" message="$(string.Diagnostic.KeywordMessage)" name="keyDiagnostic"/> </keywords> <templates> <template tid="tidCommandLine"> <data inType="win:UnicodeString" name="CommandLine"/> </template> <template tid="tidErrorCodeResult"> <data inType="win:UInt32" name="ErrorCode"/> </template> <template tid="tidAuditProcessUnattend"> <data inType="win:UnicodeString" name="Pass"/> </template> <template tid="tidAuditUsingUnattend"> <data inType="win:UnicodeString" name="Pass"/> <data inType="win:UnicodeString" name="FilePath"/> </template> </templates> <tasks> <task eventGUID="{7415972C-BA13-425f-B15B-FC2F9EC9F886}" message="$(string.RunAudit.TaskMessage)" name="tskRunAudit" value="1000"/> <task eventGUID="{38BB09CA-D270-4fc5-A125-D692C5F33D90}" message="$(string.AuditProcessUnattend.TaskMessage)" name="tskAuditProcessUnattend" value="2000"/> </tasks> <events> <event channel="chaAuditAnalytic" keywords="keyPerformance" level="win:Informational" message="$(string.RunAudit.StartMessage)" opcode="win:Start" symbol="RunAuditStart" task="tskRunAudit" template="tidCommandLine" value="1001"/> <event channel="chaAuditAnalytic" keywords="keyPerformance" level="win:Informational" message="$(string.RunAudit.StopMessage)" opcode="win:Stop" symbol="RunAuditStop" task="tskRunAudit" template="tidErrorCodeResult" value="1002"/> <event channel="chaAuditAnalytic" keywords="keyPerformance" level="win:Informational" message="$(string.AuditProcessUnattend.StartMessage)" opcode="win:Start" symbol="AuditProcessUnattendStart" task="tskAuditProcessUnattend" template="tidAuditProcessUnattend" value="2001"/> <event channel="chaAuditAnalytic" keywords="keyPerformance" level="win:Informational" message="$(string.AuditProcessUnattend.StopMessageExecuted)" opcode="win:Stop" symbol="AuditProcessUnattendStopExecuted" task="tskAuditProcessUnattend" template="tidErrorCodeResult" value="2002"/> <event channel="chaAuditAnalytic" keywords="keyPerformance" level="win:Informational" message="$(string.AuditProcessUnattend.StopMessageFailedToExecute)" opcode="win:Stop" symbol="AuditProcessUnattendStopFailedToExecute" task="tskAuditProcessUnattend" template="tidErrorCodeResult" value="2003"/> <event channel="chaAuditAnalytic" keywords="keyDiagnostic" level="win:Informational" message="$(string.AuditProcessUnattend.UsingFile)" opcode="win:Info" symbol="AuditProcessUnattendUsingFile" task="tskAuditProcessUnattend" template="tidAuditUsingUnattend" value="2004"/> </events> </provider> </events> </instrumentation> <localization> <resources culture="en-US"> <stringTable> <string id="Performance.KeywordMessage" value="Performance"/> <string id="Diagnostic.KeywordMessage" value="Diagnostic"/> <string id="Audit.ProviderMessage" value="Microsoft-Windows-Audit"/> <string id="RunAudit.TaskMessage" value="Run Audit"/> <string id="RunAudit.StartMessage" value="Audit.exe launched with command line "%1"."/> <string id="RunAudit.StopMessage" value="Audit.exe exiting with status %1."/> <string id="AuditProcessUnattend.TaskMessage" value="Audit Process Unattend"/> <string id="AuditProcessUnattend.StartMessage" value="Executing unattend settings pass "%1"."/> <string id="AuditProcessUnattend.StopMessageExecuted" value="Finished executing unattend pass with status %1."/> <string id="AuditProcessUnattend.StopMessageFailedToExecute" value="Failed to execute unattend pass with status %1."/> <string id="AuditProcessUnattend.UsingFile" value="Using unattend file "%2" for pass "%1"."/> </stringTable> </resources> </localization> <cbb:debuggingInfo xmlns:cbb="urn:schemas-microsoft-com:asm.internal.v1"> <cbb:sourceManifest sourcePath="%basedir%\base\ntsetup\opktools\audit\src\microsoft-windows-audit-instrumentation.man"/> </cbb:debuggingInfo> </assembly>