Display Filter Reference: Network Monitor Event

Protocol field name: netmon_event

Versions: 2.6.0 to 4.4.1

Back to Display Filter Reference

Field name Description Type Versions
netmon_event.activity_idActivity IDGlobally Unique Identifier2.6.0 to 4.4.1
netmon_event.alignmentAlignmentUnsigned integer (8 bits)2.6.0 to 4.4.1
netmon_event.event_desc.channelChannelUnsigned integer (8 bits)2.6.0 to 4.4.1
netmon_event.event_desc.idIDUnsigned integer (16 bits)2.6.0 to 4.4.1
netmon_event.event_desc.keywordKeywordUnsigned integer (64 bits)2.6.0 to 4.4.1
netmon_event.event_desc.levelLevelUnsigned integer (8 bits)2.6.0 to 4.4.1
netmon_event.event_desc.opcodeOpcodeUnsigned integer (8 bits)2.6.0 to 4.4.1
netmon_event.event_desc.taskTaskUnsigned integer (16 bits)2.6.0 to 4.4.1
netmon_event.event_desc.versionVersionUnsigned integer (8 bits)2.6.0 to 4.4.1
netmon_event.event_propertyEvent propertyUnsigned integer (16 bits)2.6.0 to 4.4.1
netmon_event.event_property.forwarded_xmlEvent data contains fully-rendered XMLBoolean2.6.0 to 4.4.1
netmon_event.event_property.legacy_eventlogNeed WMI MOF classBoolean2.6.0 to 4.4.1
netmon_event.event_property.xmlNeed manifestBoolean2.6.0 to 4.4.1
netmon_event.extended_dataExtended dataByte sequence2.6.0 to 4.4.1
netmon_event.extended_data.linkageAdditional extended dataBoolean2.6.0 to 4.4.1
netmon_event.extended_data.reservedReservedUnsigned integer (16 bits)2.6.0 to 4.4.1
netmon_event.extended_data.reserved2ReservedUnsigned integer (16 bits)2.6.0 to 4.4.1
netmon_event.extended_data.sizeExtended data sizeUnsigned integer (16 bits)2.6.0 to 4.4.1
netmon_event.extended_data.typeExtended info typeUnsigned integer (16 bits)2.6.0 to 4.4.1
netmon_event.extended_data_countExtended data countUnsigned integer (16 bits)2.6.0 to 4.4.1
netmon_event.flagsFlagsUnsigned integer (16 bits)2.6.0 to 4.4.1
netmon_event.flags.32bit_headerProvider running on 32-bit computerBoolean2.6.0 to 4.4.1
netmon_event.flags.64bit_headerProvider running on 64-bit computerBoolean2.6.0 to 4.4.1
netmon_event.flags.classic_headerUse TraceEventBoolean2.6.0 to 4.4.1
netmon_event.flags.extended_infoExtended InfoBoolean2.6.0 to 4.4.1
netmon_event.flags.no_cputimeUse ProcessorTimeBoolean2.6.0 to 4.4.1
netmon_event.flags.private_sessionPrivate SessionsBoolean2.6.0 to 4.4.1
netmon_event.flags.string_onlyNull-terminated Unicode stringBoolean2.6.0 to 4.4.1
netmon_event.flags.trace_messageTraceMessage loggedBoolean2.6.0 to 4.4.1
netmon_event.header_typeHeader typeUnsigned integer (16 bits)2.6.0 to 4.4.1
netmon_event.kernel_timeKernel timeUnsigned integer (32 bits)2.6.0 to 4.4.1
netmon_event.logger_idLogger IDUnsigned integer (16 bits)2.6.0 to 4.4.1
netmon_event.process_idProcess IDUnsigned integer (32 bits)2.6.0 to 4.4.1
netmon_event.processor_numberProcessor numberUnsigned integer (8 bits)2.6.0 to 4.4.1
netmon_event.processor_timeProcessor timeUnsigned integer (64 bits)2.6.0 to 4.4.1
netmon_event.provider_idProvider IDGlobally Unique Identifier2.6.0 to 4.4.1
netmon_event.reassembledReassembledUnsigned integer (16 bits)2.6.0 to 4.4.1
netmon_event.sizeSizeUnsigned integer (16 bits)2.6.0 to 4.4.1
netmon_event.thread_idThread IDUnsigned integer (32 bits)2.6.0 to 4.4.1
netmon_event.timestampTimestampDate and time2.6.0 to 4.4.1
netmon_event.user_dataUser dataByte sequence2.6.0 to 4.4.1
netmon_event.user_data_lengthUser data lengthUnsigned integer (16 bits)2.6.0 to 4.4.1
netmon_event.user_timeUser timeUnsigned integer (32 bits)2.6.0 to 4.4.1