Professional Documents
Culture Documents
Source:
Date:
System
Service Control Manager
7/14/2009 10:26:45 AM
Event ID:
7036
Information
Keywords:
User:
Classic
N/A
Computer:
37L4247D28-05
Description:
The Windows Management Instrumentation service entered the stopped state.
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}"
EventSourceName="Service Control Manager" />
<EventID Qualifiers="16384">7036</EventID>
<Version>0</Version>
<Level>4</Level>
<Task>0</Task>
<Opcode>0</Opcode>
<Keywords>0x8080000000000000</Keywords>
<TimeCreated SystemTime="2009-07-14T04:56:45.074339000Z" />
<EventRecordID>6</EventRecordID>
<Correlation />
<Execution ProcessID="488" ThreadID="3012" />
<Channel>System</Channel>
<Computer>37L4247D28-05</Computer>
<Security />
</System>
<EventData>
<Data Name="param1">Windows Management Instrumentation</Data>
<Data Name="param2">stopped</Data>
<Binary>570069006E006D0067006D0074002F0031000000</Binary>
</EventData>
</Event>
Log Name:
Source:
Date:
System
Service Control Manager
9/2/2011 8:08:12 PM
Event ID:
7036
Information
Keywords:
User:
Classic
N/A
Computer:
abc-PC
Description:
The Telephony service entered the running state.
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
<System>
Log Name:
Source:
Date:
System
Microsoft-Windows-Winlogon
9/1/2011 9:22:17 PM
Event ID:
7001
Information
Keywords:
User:
SYSTEM
Computer:
abc-PC
Description:
User Logon Notification for Customer Experience Improvement Program
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="Microsoft-Windows-Winlogon" Guid="{DBE9B383-7CF3-4331-91CCA3CB16A3B538}" />
<EventID>7001</EventID>
<Version>0</Version>
<Level>4</Level>
<Task>1101</Task>
<Opcode>0</Opcode>
<Keywords>0x2000000000000000</Keywords>
<TimeCreated SystemTime="2011-09-01T15:52:17.580400000Z" />
<EventRecordID>1698</EventRecordID>
<Correlation ActivityID="{67144949-5132-4859-8036-A737B43825D8}" />
<Execution ProcessID="588" ThreadID="648" />
<Channel>System</Channel>
<Computer>abc-PC</Computer>
<Security UserID="S-1-5-18" />
</System>
<EventData>
<Data Name="TSId">1</Data>
<Data Name="UserSid">S-1-5-21-2844341564-3896910852-2927903099-1000</Data>
</EventData>
</Event>