Ask Your Question

How to capture etw.* data by Wireshark?

asked 2023-01-22 04:53:04 +0000

Huang gravatar image

I found that there are 3 etw filter at filter reference page: But how to capture etw data/events by Wireshark? If I can't, what does these filters do?

etw: Event Tracing for Windows (3.6.0 to 4.0.3, 25 fields)

etw.ndis: ETW Ndis (2.6.0 to 4.0.3, 95 fields)

etw.wfp_capture: ETW WFP Capture (2.6.0 to 4.0.3, 10 fields)

edit retag flag offensive close merge delete

1 Answer

Sort by ยป oldest newest most voted

answered 2023-01-22 06:01:31 +0000

Chuckc gravatar image

Microsoft example for etwdump external capture interface:
Analyzing Mobile Broadband Logs in Wireshark

A list of providers - logman query providers (e.g. --p=Microsoft-Windows-Kernel-EventTracing) - to make a capture.

edit flag offensive delete link more


Thank you.

Huang gravatar imageHuang ( 2023-01-22 06:29:13 +0000 )edit

Your Answer

Please start posting anonymously - your entry will be published after you log in or create a new account.

Add Answer

Question Tools

1 follower


Asked: 2023-01-22 04:53:04 +0000

Seen: 345 times

Last updated: Jan 22 '23