TraceLog Main Topic| Previous

TraceLog Examples


  1. Starts system event tracing. The default log file is c:\logfile.etl.
    tracelog ûstart
    Logger Started...
    Operation Status:       0L
    The operation completed successfully.
    
    Logger Name:            NT Kernel Logger
    Logger Id:              ffff
    Logger Thread Id:       1360
    Buffer Size:            8 Kb
    Maximum Buffers:        25
    Minimum Buffers:        2
    Number of Buffers:      2
    Free Buffers:           1
    Buffers Written:        3
    Events Lost:            0
    Log Buffers Lost:       0
    Real Time Buffers Lost: 0
    Log File Mode:          Sequential
    Enabled tracing:        Process Thread Disk TcpIp
    Log Filename:           C:\LogFile.Etl
  2. Here, directory service (logger name) tracing is started with the log file being mylogfile.etl
    tracelog ûguid control.guid ûstart ds ûf c:\mylogfile
  3. Start directory service tracing.
    tracelog ûstart ds
    Logger Started...
    Operation Status:       0L
    The operation completed successfully.
    
    Logger Name:            ds
    Logger Id:              2
    Logger Thread Id:       1360
    Buffer Size:            8 Kb
    Maximum Buffers:        25
    Minimum Buffers:        2
    Number of Buffers:      2
    Free Buffers:           1
    Buffers Written:        1
    Events Lost:            0
    Log Buffers Lost:       0
    Real Time Buffers Lost: 0
    Log File Mode:          Sequential
    Log Filename:           C:\LogFile.Etl
    tracelog ûstart ds ûguid control.guid ûf c:\dslogfile.etl
    (starts directory service tracing)
  4. Stop tracing.
    tracelog ûstop
    Operation Status:       0L
    The operation completed successfully.
    
    Logger Name:            NT Kernel Logger
    Logger Id:              ffff
    Logger Thread Id:       1360
    Buffer Size:            8 Kb
    Maximum Buffers:        25
    Minimum Buffers:        2
    Number of Buffers:      2
    Free Buffers:           2
    Buffers Written:        7
    Events Lost:            0
    Log Buffers Lost:       0
    Real Time Buffers Lost: 0
    Log File Mode:          Sequential
    Log Filename:           C:\LogFile.Etl
    tracelog ûstop ds
  5. Start tracing to a specific log file.
    tracelog ûstart ûf kernel_log.etl
    Setting log file to: C:\Program Files\Resource Kit\kernel_log.etl
    Logger Started...
    Operation Status:       0L
    The operation completed successfully.
    
    Logger Name:            NT Kernel Logger
    Logger Id:              ffff
    Logger Thread Id:       1360
    Buffer Size:            8 Kb
    Maximum Buffers:        25
    Minimum Buffers:        2
    Number of Buffers:      2
    Free Buffers:           1
    Buffers Written:        3
    Events Lost:            0
    Log Buffers Lost:       0
    Real Time Buffers Lost: 0
    Log File Mode:          Sequential
    Enabled tracing:        Process Thread Disk TcpIp
    Log Filename:           C:\Program Files\Resource Kit\kernel_log.etl
    tracelog ûstart ds ûguid control.guid ûf ds_log.etl
  6. If current logger is a real-time logger, this will switch current logger to non real-time, sequential logger.
    tracelog ûupdate