Professional Documents
Culture Documents
README
README
==============================================
http://go.microsoft.com/fwlink/?LinkId=103276
CONTENTS
========
1.b. I cannot decode symbols. Why is that and how can I fix it?
iii. The ETW kernel trace file has been stopped and merged with xperf's
option -d or merged on the same machine it was taken with xperf's
option -merge. (xperf performs a special image identification
process during its custom trace merge.)
vi. _NT_SYMBOL_PATH points to the right files. If the files are from a
different build or architecture they will not work. If you replace
the binary or symbols you will not be able to decode anymore symbols
for traces recording activity of the old binaries.
To rule out a symbol mismatch, use symchk from the Windows Debugging
Tools distribution to ensure the symbols match the binaries on the
machine on which the trace was taken:
fc /b <local_file> <drop_share_file>
vii. The ETW kernel trace was captured with at least PROC_THREAD+LOADER.
These flags provide basic information about process lifetime and
image ranges in process memory, which are instrumental in decoding
virtual addresses to images and symbols.
To verify that these flags have been enabled in the ETW kernel trace,
check that Process events (Create, Delete, Start Rundown, End Rundown)
and Image events (Load, Unload, Start Rundown, End Rundown) are present
in the table generated by "xperf -i kernel.etl -a tracestats -detail".
1.c. I'd like to have ETW log the context stacks for certain events. How
can I do that?