watch_etw

Plugin

ArgDescriptionType
nameA session namestring
guidA Provider GUID to watchstring (required)
anyAny Keywordsuint64
allAll Keywordsuint64
levelLog level (0-5)int64
stopIf provided we stop watching automatically when this lambda returns trueLambda
timeoutIf provided we stop after this much timeuint64

Description

Watch for events from an ETW provider.