Windows platform event channels
Kernel, boot, power, device and driver, hardware, clock and performance channels, bound as one feed. Disks, volumes and the filesystem have their own feed, win.eventlog.storage. Light curation: every event keeps the severity the provider stated, capped at Warning, and one measured flood (WHEA corrected-error 20) is dropped by event id. No reasons yet; the fleet data this feed produces is what the curated rules will be written from.
Feed id: win.eventlog.platform.
Channels
This feed binds 44 Windows Event Log channels as one reporting axis. A channel that a given Windows edition, role or OEM does not provide is absent on that endpoint; the rest still collect.
The ticket class is the subject area an event on the channel is evidence for, and it is what fleet-wide questions group by. A channel that records across every subject area at once ships unlabeled rather than mislabeled.
| Channel | Ticket class |
|---|---|
Dell | hardware |
Intel Graphics Software | hardware |
Intel-GFX-Info/Application | hardware |
Lenovo-Power-BaseModule/Operational | hardware |
Lenovo-Power-SmartStandby/Operational | hardware |
Lenovo-Sif-Core/Operational | hardware |
Microsoft-Windows-DeviceSetupManager/Admin | hardware |
Microsoft-Windows-DeviceSetupManager/Operational | hardware |
Microsoft-Windows-Diagnosis-DPS/Operational | |
Microsoft-Windows-Diagnosis-Scheduled/Operational | |
Microsoft-Windows-Diagnosis-Scripted/Admin | |
Microsoft-Windows-Diagnosis-Scripted/Operational | |
Microsoft-Windows-Diagnosis-ScriptedDiagnosticsProvider/Operational | |
Microsoft-Windows-Diagnostics-Performance/Operational | performance |
Microsoft-Windows-DxgKrnl-Admin | hardware |
Microsoft-Windows-DxgKrnl-Operational | hardware |
Microsoft-Windows-Kernel-Boot/Operational | os_stability |
Microsoft-Windows-Kernel-Cache/Operational | os_stability |
Microsoft-Windows-Kernel-Dump/Operational | os_stability |
Microsoft-Windows-Kernel-EventTracing/Admin | os_stability |
Microsoft-Windows-Kernel-LiveDump/Operational | os_stability |
Microsoft-Windows-Kernel-PnP/Configuration | hardware |
Microsoft-Windows-Kernel-PnP/Device Management | hardware |
Microsoft-Windows-Kernel-PnP/Driver Watchdog | hardware |
Microsoft-Windows-Kernel-PnPConfig/Configuration | hardware |
Microsoft-Windows-Kernel-Power/Thermal-Operational | hardware |
Microsoft-Windows-Kernel-WHEA/Errors | hardware |
Microsoft-Windows-Kernel-WHEA/Operational | hardware |
Microsoft-Windows-PCI/Operational | hardware |
Microsoft-Windows-PerceptionSensorDataService/Operational | hardware |
Microsoft-Windows-Perflib/Operational | performance |
Microsoft-Windows-Resource-Exhaustion-Detector/Operational | performance |
Microsoft-Windows-Resource-Exhaustion-Resolver/Operational | performance |
Microsoft-Windows-Time-Service/Operational | time_sync |
Microsoft-Windows-TZSync/Operational | time_sync |
Microsoft-Windows-USB-UCMUCSICX/Operational | hardware |
Microsoft-Windows-USB-USBXHCI-Operational | hardware |
Microsoft-Windows-UserPnp/DeviceInstall | hardware |
Microsoft-Windows-WerKernel/Operational | os_stability |
Microsoft-Windows-Win32k/Operational | os_stability |
Microsoft-Windows-WindowsSystemAssessmentTool/Operational | performance |
Microsoft-Windows-WPD-ClassInstaller/Operational | hardware |
Microsoft-Windows-WPD-MTPClassDriver/Operational | hardware |
OneApp_IGCC | hardware |
Severity
This feed is bound for collection but is not yet curated per event. Every event keeps the severity its own provider stated, capped at Warning.
Ask this feed a question
Every reason code, token and field on this page is queryable across the endpoints you manage. Connect your AI and ask in plain language, or open the same evidence in Explore.