Source code of Windows XP (NT5)
You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

816 lines
57 KiB

  1. ��<?xml version="1.0" encoding="UTF-16"?>
  2. <!DOCTYPE DCARRIER SYSTEM "Mantis.DTD">
  3. <DCARRIER
  4. CarrierRevision="1"
  5. DTDRevision="16"
  6. >
  7. <TASKS
  8. Context="1"
  9. PlatformGUID="{00000000-0000-0000-0000-000000000000}"
  10. > </TASKS>
  11. <PLATFORMS
  12. Context="1"
  13. > </PLATFORMS>
  14. <REPOSITORIES
  15. Context="1"
  16. PlatformGUID="{00000000-0000-0000-0000-000000000000}"
  17. > </REPOSITORIES>
  18. <GROUPS
  19. Context="1"
  20. PlatformGUID="{00000000-0000-0000-0000-000000000000}"
  21. > </GROUPS>
  22. <COMPONENTS
  23. Context="0"
  24. PlatformGUID="{B784E719-C196-4DDB-B358-D9254426C38D}"
  25. >
  26. <COMPONENT
  27. ComponentVSGUID="{34001539-CDA9-495C-9210-22C2D0BE9423}"
  28. ComponentVIGUID="{83679002-5A67-44ED-BF82-0022B7BFDD55}"
  29. Revision="620"
  30. RepositoryVSGUID="{8E0BE9ED-7649-47F3-810B-232D36C430B4}"
  31. Visibility="200"
  32. MultiInstance="False"
  33. Released="False"
  34. Editable="True"
  35. HTMLFinal="False"
  36. IsMacro="False"
  37. Opaque="False"
  38. Context="1"
  39. PlatformGUID="{B784E719-C196-4DDB-B358-D9254426C38D}"
  40. >
  41. <HELPCONTEXT
  42. src=".\smlogsvc.htm"
  43. ><![CDATA[<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 3.2 Final//EN">
  44. <HTML DIR="LTR"><HEAD>
  45. <META HTTP-EQUIV="Content-Type" Content="text/html; charset=Windows-1252">
  46. <TITLE>Performance Logs and Alerts Service</TITLE>
  47. <STYLE TYPE="text/css">
  48. <!--
  49. BODY { font: normal 8pt Tahoma; background-color: #FFFFFF; }
  50. P { font: normal 8pt Tahoma; }
  51. .showhide { color: blue; text-decoration: underline; cursor: hand; }
  52. .callout { font: normal 8pt Tahoma; background-color: #E0E0E0; padding: 10pt; }
  53. .code { font: normal 8pt Courier New; }
  54. UL { font: normal 8pt Tahoma; list-style: square outside; margin-left: 0.25in; }
  55. OL { font: normal 8pt Tahoma; list-style: decimal outside; margin-left: 0.25in; }
  56. H1 { font: bold 12pt Tahoma; margin-bottom: -12pt; }
  57. H2 { font: bold 10pt Tahoma; margin-bottom: -12pt; }
  58. H3 { font: bold 8pt Tahoma; margin-bottom: -12pt; }
  59. H4 { font: italic 8pt Tahoma; margin-bottom: -12pt; }
  60. TABLE { font: normal 8pt Tahoma; text-align: left; padding: 2px; }
  61. CAPTION { font: bold 8pt Tahoma; text-align: left; padding: 2px; }
  62. THEAD { font: bold 8pt Tahoma; text-align: left; padding: 2px; background-color: #F0F0F0 }
  63. TH { font: bold 8pt Tahoma; text-align: left; padding: 2px; background-color: #F0F0F0 }
  64. TBODY { font: normal 8pt Tahoma; text-align: left; padding: 2px; }
  65. TD { font: normal 8pt Tahoma; text-align: left; padding: 2px; }
  66. TR { font: normal 8pt Tahoma; text-align: left; padding: 2px; }
  67. CODE { font-family: Courier New; }
  68. TT { font-family: Courier New; }
  69. KBD { font-family: Courier New; font-weight: bold; }
  70. VAR { font-family: Courier New; font-style: italic; }
  71. EM { font-style: italic; }
  72. I { font-style: italic; }
  73. STRONG { font-weight: bold; }
  74. B { font-weight: bold; }
  75. -->
  76. </STYLE>
  77. </HEAD>
  78. <BODY TOPMARGIN="0">
  79. The Performance Logs and Alerts Service component provides the scheduled starting and stopping of performance counter and event trace log collections, and the processing of alerts against pre-defined performance counter thresholds. It supports the System Monitor and the Performance Command-Line tool components. </P>
  80. <H3>Component Configuration</H3>
  81. <P>This component is a stand-alone executable file that processes collections that have been configured previously using the System Monitor component or the command-line tool Logman, which is part of the Performance Command Line Tool component.</P>
  82. <H3>For More Information </H3>
  83. <P>For information about configuring performance logs and alerts, see the online Help in the System Monitor component.</P>
  84. </BODY>
  85. </HTML>
  86. ]]></HELPCONTEXT>
  87. <PROPERTIES
  88. Context="1"
  89. PlatformGUID="{00000000-0000-0000-0000-000000000000}"
  90. > </PROPERTIES>
  91. <RESOURCES
  92. Context="1"
  93. PlatformGUID="{B784E719-C196-4DDB-B358-D9254426C38D}"
  94. >
  95. <RESOURCE
  96. Name="File(819):&quot;%11%&quot;,&quot;smlogsvc.exe&quot;"
  97. ResTypeVSGUID="{E66B49F6-4A35-4246-87E8-5C1A468315B5}"
  98. BuildTypeMask="819"
  99. BuildOrder="1000"
  100. Localize="False"
  101. Disabled="False"
  102. Context="1"
  103. PlatformGUID="{B784E719-C196-4DDB-B358-D9254426C38D}"
  104. >
  105. <PROPERTIES
  106. Context="1"
  107. PlatformGUID="{00000000-0000-0000-0000-000000000000}"
  108. >
  109. <PROPERTY
  110. Name="DstPath"
  111. Format="String"
  112. Context="1"
  113. PlatformGUID="{00000000-0000-0000-0000-000000000000}"
  114. >%11%</PROPERTY>
  115. <PROPERTY
  116. Name="DstName"
  117. Format="String"
  118. Context="1"
  119. PlatformGUID="{00000000-0000-0000-0000-000000000000}"
  120. >smlogsvc.exe</PROPERTY>
  121. <PROPERTY
  122. Name="NoExpand"
  123. Format="Boolean"
  124. Context="1"
  125. PlatformGUID="{00000000-0000-0000-0000-000000000000}"
  126. >False</PROPERTY>
  127. </PROPERTIES>
  128. <DISPLAYNAME>Performance Logs and Alerts service</DISPLAYNAME>
  129. <DESCRIPTION>Collects performance data from local or remote computers based on preconfigured schedule parameters, then writes the data to a log or triggers an alert.</DESCRIPTION>
  130. </RESOURCE>
  131. <RESOURCE
  132. Name="RawDep(819):&quot;File&quot;,&quot;ADVAPI32.dll&quot;"
  133. ResTypeVSGUID="{90D8E195-E710-4AF6-B667-B1805FFC9B8F}"
  134. BuildTypeMask="819"
  135. BuildOrder="1000"
  136. Localize="False"
  137. Disabled="False"
  138. Context="1"
  139. PlatformGUID="{B784E719-C196-4DDB-B358-D9254426C38D}"
  140. >
  141. <PROPERTIES
  142. Context="1"
  143. PlatformGUID="{00000000-0000-0000-0000-000000000000}"
  144. >
  145. <PROPERTY
  146. Name="RawType"
  147. Format="String"
  148. Context="1"
  149. PlatformGUID="{00000000-0000-0000-0000-000000000000}"
  150. >File</PROPERTY>
  151. <PROPERTY
  152. Name="Value"
  153. Format="String"
  154. Context="1"
  155. PlatformGUID="{00000000-0000-0000-0000-000000000000}"
  156. >ADVAPI32.dll</PROPERTY>
  157. </PROPERTIES>
  158. </RESOURCE>
  159. <RESOURCE
  160. Name="RawDep(819):&quot;File&quot;,&quot;KERNEL32.dll&quot;"
  161. ResTypeVSGUID="{90D8E195-E710-4AF6-B667-B1805FFC9B8F}"
  162. BuildTypeMask="819"
  163. BuildOrder="1000"
  164. Localize="False"
  165. Disabled="False"
  166. Context="1"
  167. PlatformGUID="{B784E719-C196-4DDB-B358-D9254426C38D}"
  168. >
  169. <PROPERTIES
  170. Context="1"
  171. PlatformGUID="{00000000-0000-0000-0000-000000000000}"
  172. >
  173. <PROPERTY
  174. Name="RawType"
  175. Format="String"
  176. Context="1"
  177. PlatformGUID="{00000000-0000-0000-0000-000000000000}"
  178. >File</PROPERTY>
  179. <PROPERTY
  180. Name="Value"
  181. Format="String"
  182. Context="1"
  183. PlatformGUID="{00000000-0000-0000-0000-000000000000}"
  184. >KERNEL32.dll</PROPERTY>
  185. </PROPERTIES>
  186. </RESOURCE>
  187. <RESOURCE
  188. Name="RawDep(819):&quot;File&quot;,&quot;USER32.dll&quot;"
  189. ResTypeVSGUID="{90D8E195-E710-4AF6-B667-B1805FFC9B8F}"
  190. BuildTypeMask="819"
  191. BuildOrder="1000"
  192. Localize="False"
  193. Disabled="False"
  194. Context="1"
  195. PlatformGUID="{B784E719-C196-4DDB-B358-D9254426C38D}"
  196. >
  197. <PROPERTIES
  198. Context="1"
  199. PlatformGUID="{00000000-0000-0000-0000-000000000000}"
  200. >
  201. <PROPERTY
  202. Name="RawType"
  203. Format="String"
  204. Context="1"
  205. PlatformGUID="{00000000-0000-0000-0000-000000000000}"
  206. >File</PROPERTY>
  207. <PROPERTY
  208. Name="Value"
  209. Format="String"
  210. Context="1"
  211. PlatformGUID="{00000000-0000-0000-0000-000000000000}"
  212. >USER32.dll</PROPERTY>
  213. </PROPERTIES>
  214. </RESOURCE>
  215. <RESOURCE
  216. Name="RawDep(819):&quot;File&quot;,&quot;ntdll.dll&quot;"
  217. ResTypeVSGUID="{90D8E195-E710-4AF6-B667-B1805FFC9B8F}"
  218. BuildTypeMask="819"
  219. BuildOrder="1000"
  220. Localize="False"
  221. Disabled="False"
  222. Context="1"
  223. PlatformGUID="{B784E719-C196-4DDB-B358-D9254426C38D}"
  224. >
  225. <PROPERTIES
  226. Context="1"
  227. PlatformGUID="{00000000-0000-0000-0000-000000000000}"
  228. >
  229. <PROPERTY
  230. Name="RawType"
  231. Format="String"
  232. Context="1"
  233. PlatformGUID="{00000000-0000-0000-0000-000000000000}"
  234. >File</PROPERTY>
  235. <PROPERTY
  236. Name="Value"
  237. Format="String"
  238. Context="1"
  239. PlatformGUID="{00000000-0000-0000-0000-000000000000}"
  240. >ntdll.dll</PROPERTY>
  241. </PROPERTIES>
  242. </RESOURCE>
  243. <RESOURCE
  244. Name="RawDep(819):&quot;File&quot;,&quot;NETAPI32.dll&quot;"
  245. ResTypeVSGUID="{90D8E195-E710-4AF6-B667-B1805FFC9B8F}"
  246. BuildTypeMask="819"
  247. BuildOrder="1000"
  248. Localize="False"
  249. Disabled="False"
  250. Context="1"
  251. PlatformGUID="{B784E719-C196-4DDB-B358-D9254426C38D}"
  252. >
  253. <PROPERTIES
  254. Context="1"
  255. PlatformGUID="{00000000-0000-0000-0000-000000000000}"
  256. >
  257. <PROPERTY
  258. Name="RawType"
  259. Format="String"
  260. Context="1"
  261. PlatformGUID="{00000000-0000-0000-0000-000000000000}"
  262. >File</PROPERTY>
  263. <PROPERTY
  264. Name="Value"
  265. Format="String"
  266. Context="1"
  267. PlatformGUID="{00000000-0000-0000-0000-000000000000}"
  268. >NETAPI32.dll</PROPERTY>
  269. </PROPERTIES>
  270. </RESOURCE>
  271. <RESOURCE
  272. Name="RawDep(819):&quot;File&quot;,&quot;SHLWAPI.dll&quot;"
  273. ResTypeVSGUID="{90D8E195-E710-4AF6-B667-B1805FFC9B8F}"
  274. BuildTypeMask="819"
  275. BuildOrder="1000"
  276. Localize="False"
  277. Disabled="False"
  278. Context="1"
  279. PlatformGUID="{B784E719-C196-4DDB-B358-D9254426C38D}"
  280. >
  281. <PROPERTIES
  282. Context="1"
  283. PlatformGUID="{00000000-0000-0000-0000-000000000000}"
  284. >
  285. <PROPERTY
  286. Name="RawType"
  287. Format="String"
  288. Context="1"
  289. PlatformGUID="{00000000-0000-0000-0000-000000000000}"
  290. >File</PROPERTY>
  291. <PROPERTY
  292. Name="Value"
  293. Format="String"
  294. Context="1"
  295. PlatformGUID="{00000000-0000-0000-0000-000000000000}"
  296. >SHLWAPI.dll</PROPERTY>
  297. </PROPERTIES>
  298. </RESOURCE>
  299. <RESOURCE
  300. Name="RawDep(819):&quot;File&quot;,&quot;pdh.dll&quot;"
  301. ResTypeVSGUID="{90D8E195-E710-4AF6-B667-B1805FFC9B8F}"
  302. BuildTypeMask="819"
  303. BuildOrder="1000"
  304. Localize="False"
  305. Disabled="False"
  306. Context="1"
  307. PlatformGUID="{B784E719-C196-4DDB-B358-D9254426C38D}"
  308. >
  309. <PROPERTIES
  310. Context="1"
  311. PlatformGUID="{00000000-0000-0000-0000-000000000000}"
  312. >
  313. <PROPERTY
  314. Name="RawType"
  315. Format="String"
  316. Context="1"
  317. PlatformGUID="{00000000-0000-0000-0000-000000000000}"
  318. >File</PROPERTY>
  319. <PROPERTY
  320. Name="Value"
  321. Format="String"
  322. Context="1"
  323. PlatformGUID="{00000000-0000-0000-0000-000000000000}"
  324. >pdh.dll</PROPERTY>
  325. </PROPERTIES>
  326. </RESOURCE>
  327. <RESOURCE
  328. Name="RegKey(819):&quot;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SysmonLog\Log Queries&quot;,&quot;Defaults Installed&quot;"
  329. ResTypeVSGUID="{2C10DB69-39AB-48A4-A83F-9AB3ACBA7C45}"
  330. BuildTypeMask="819"
  331. BuildOrder="1000"
  332. Localize="False"
  333. Disabled="False"
  334. Context="1"
  335. PlatformGUID="{B784E719-C196-4DDB-B358-D9254426C38D}"
  336. >
  337. <PROPERTIES
  338. Context="1"
  339. PlatformGUID="{00000000-0000-0000-0000-000000000000}"
  340. >
  341. <PROPERTY
  342. Name="KeyPath"
  343. Format="String"
  344. Context="1"
  345. PlatformGUID="{00000000-0000-0000-0000-000000000000}"
  346. >HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SysmonLog\Log Queries</PROPERTY>
  347. <PROPERTY
  348. Name="ValueName"
  349. Format="String"
  350. Context="1"
  351. PlatformGUID="{00000000-0000-0000-0000-000000000000}"
  352. >Defaults Installed</PROPERTY>
  353. <PROPERTY
  354. Name="RegValue"
  355. Format="Integer"
  356. Context="1"
  357. PlatformGUID="{00000000-0000-0000-0000-000000000000}"
  358. >0</PROPERTY>
  359. <PROPERTY
  360. Name="RegType"
  361. Format="Integer"
  362. Context="1"
  363. PlatformGUID="{00000000-0000-0000-0000-000000000000}"
  364. >4</PROPERTY>
  365. <PROPERTY
  366. Name="RegOp"
  367. Format="Integer"
  368. Context="1"
  369. PlatformGUID="{00000000-0000-0000-0000-000000000000}"
  370. >1</PROPERTY>
  371. <PROPERTY
  372. Name="RegCond"
  373. Format="Integer"
  374. Context="1"
  375. PlatformGUID="{00000000-0000-0000-0000-000000000000}"
  376. >1</PROPERTY>
  377. </PROPERTIES>
  378. </RESOURCE>
  379. <RESOURCE
  380. Name="RegKey(819):&quot;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\SysmonLog&quot;,&quot;EventMessageFile&quot;"
  381. ResTypeVSGUID="{2C10DB69-39AB-48A4-A83F-9AB3ACBA7C45}"
  382. BuildTypeMask="819"
  383. BuildOrder="1000"
  384. Localize="False"
  385. Disabled="False"
  386. Context="1"
  387. PlatformGUID="{B784E719-C196-4DDB-B358-D9254426C38D}"
  388. >
  389. <PROPERTIES
  390. Context="1"
  391. PlatformGUID="{00000000-0000-0000-0000-000000000000}"
  392. >
  393. <PROPERTY
  394. Name="KeyPath"
  395. Format="String"
  396. Context="1"
  397. PlatformGUID="{00000000-0000-0000-0000-000000000000}"
  398. >HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\SysmonLog</PROPERTY>
  399. <PROPERTY
  400. Name="ValueName"
  401. Format="String"
  402. Context="1"
  403. PlatformGUID="{00000000-0000-0000-0000-000000000000}"
  404. >EventMessageFile</PROPERTY>
  405. <PROPERTY
  406. Name="RegValue"
  407. Format="String"
  408. Context="1"
  409. PlatformGUID="{00000000-0000-0000-0000-000000000000}"
  410. >%SystemRoot%\System32\smlogsvc.exe</PROPERTY>
  411. <PROPERTY
  412. Name="RegType"
  413. Format="Integer"
  414. Context="1"
  415. PlatformGUID="{00000000-0000-0000-0000-000000000000}"
  416. >2</PROPERTY>
  417. <PROPERTY
  418. Name="RegOp"
  419. Format="Integer"
  420. Context="1"
  421. PlatformGUID="{00000000-0000-0000-0000-000000000000}"
  422. >1</PROPERTY>
  423. <PROPERTY
  424. Name="RegCond"
  425. Format="Integer"
  426. Context="1"
  427. PlatformGUID="{00000000-0000-0000-0000-000000000000}"
  428. >1</PROPERTY>
  429. </PROPERTIES>
  430. </RESOURCE>
  431. <RESOURCE
  432. Name="RegKey(819):&quot;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\SysmonLog&quot;,&quot;TypesSupported&quot;"
  433. ResTypeVSGUID="{2C10DB69-39AB-48A4-A83F-9AB3ACBA7C45}"
  434. BuildTypeMask="819"
  435. BuildOrder="1000"
  436. Localize="False"
  437. Disabled="False"
  438. Context="1"
  439. PlatformGUID="{B784E719-C196-4DDB-B358-D9254426C38D}"
  440. >
  441. <PROPERTIES
  442. Context="1"
  443. PlatformGUID="{00000000-0000-0000-0000-000000000000}"
  444. >
  445. <PROPERTY
  446. Name="KeyPath"
  447. Format="String"
  448. Context="1"
  449. PlatformGUID="{00000000-0000-0000-0000-000000000000}"
  450. >HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\SysmonLog</PROPERTY>
  451. <PROPERTY
  452. Name="ValueName"
  453. Format="String"
  454. Context="1"
  455. PlatformGUID="{00000000-0000-0000-0000-000000000000}"
  456. >TypesSupported</PROPERTY>
  457. <PROPERTY
  458. Name="RegValue"
  459. Format="Integer"
  460. Context="1"
  461. PlatformGUID="{00000000-0000-0000-0000-000000000000}"
  462. >7</PROPERTY>
  463. <PROPERTY
  464. Name="RegType"
  465. Format="Integer"
  466. Context="1"
  467. PlatformGUID="{00000000-0000-0000-0000-000000000000}"
  468. >4</PROPERTY>
  469. <PROPERTY
  470. Name="RegOp"
  471. Format="Integer"
  472. Context="1"
  473. PlatformGUID="{00000000-0000-0000-0000-000000000000}"
  474. >1</PROPERTY>
  475. <PROPERTY
  476. Name="RegCond"
  477. Format="Integer"
  478. Context="1"
  479. PlatformGUID="{00000000-0000-0000-0000-000000000000}"
  480. >1</PROPERTY>
  481. </PROPERTIES>
  482. </RESOURCE>
  483. <RESOURCE
  484. Name="Service(819):&quot;SysmonLog&quot;"
  485. ResTypeVSGUID="{5C16ED57-3182-4411-8EA7-AC1CE70B96DA}"
  486. BuildTypeMask="819"
  487. BuildOrder="1000"
  488. Localize="True"
  489. Disabled="False"
  490. Context="1"
  491. PlatformGUID="{B784E719-C196-4DDB-B358-D9254426C38D}"
  492. >
  493. <PROPERTIES
  494. Context="1"
  495. PlatformGUID="{00000000-0000-0000-0000-000000000000}"
  496. >
  497. <PROPERTY
  498. Name="ComponentVSGUID"
  499. Format="GUID"
  500. Context="1"
  501. PlatformGUID="{00000000-0000-0000-0000-000000000000}"
  502. >{00000000-0000-0000-0000-000000000000}</PROPERTY>
  503. <PROPERTY
  504. Name="Dependencies"
  505. Format="Multi"
  506. Context="1"
  507. PlatformGUID="{00000000-0000-0000-0000-000000000000}"
  508. ></PROPERTY>
  509. <PROPERTY
  510. Name="ErrorControl"
  511. Format="Integer"
  512. Context="1"
  513. PlatformGUID="{00000000-0000-0000-0000-000000000000}"
  514. >1</PROPERTY>
  515. <PROPERTY
  516. Name="LoadOrderGroup"
  517. Format="String"
  518. Context="1"
  519. PlatformGUID="{00000000-0000-0000-0000-000000000000}"
  520. ></PROPERTY>
  521. <PROPERTY
  522. Name="Password"
  523. Format="String"
  524. Context="1"
  525. PlatformGUID="{00000000-0000-0000-0000-000000000000}"
  526. ></PROPERTY>
  527. <PROPERTY
  528. Name="ServiceBinary"
  529. Format="String"
  530. Context="1"
  531. PlatformGUID="{00000000-0000-0000-0000-000000000000}"
  532. >%SystemRoot%\system32\smlogsvc.exe</PROPERTY>
  533. <PROPERTY
  534. Name="ServiceDescription"
  535. Format="String"
  536. Context="1"
  537. PlatformGUID="{00000000-0000-0000-0000-000000000000}"
  538. >Collects performance data from local or remote computers based on preconfigured schedule parameters, then writes the data to a log or triggers an alert. If this service is stopped, performance information will not be collected. If this service is disabled, any services that explicitly depend on it will fail to start.</PROPERTY>
  539. <PROPERTY
  540. Name="ServiceDisplayName"
  541. Format="String"
  542. Context="1"
  543. PlatformGUID="{00000000-0000-0000-0000-000000000000}"
  544. >Performance Logs and Alerts</PROPERTY>
  545. <PROPERTY
  546. Name="ServiceName"
  547. Format="String"
  548. Context="1"
  549. PlatformGUID="{00000000-0000-0000-0000-000000000000}"
  550. >SysmonLog</PROPERTY>
  551. <PROPERTY
  552. Name="ServiceType"
  553. Format="Integer"
  554. Context="1"
  555. PlatformGUID="{00000000-0000-0000-0000-000000000000}"
  556. >16</PROPERTY>
  557. <PROPERTY
  558. Name="StartName"
  559. Format="String"
  560. Context="1"
  561. PlatformGUID="{00000000-0000-0000-0000-000000000000}"
  562. ></PROPERTY>
  563. <PROPERTY
  564. Name="StartType"
  565. Format="Integer"
  566. Context="1"
  567. PlatformGUID="{00000000-0000-0000-0000-000000000000}"
  568. >3</PROPERTY>
  569. </PROPERTIES>
  570. <DISPLAYNAME>Service(819):&quot;SysmonLog&quot;</DISPLAYNAME>
  571. <DESCRIPTION></DESCRIPTION>
  572. </RESOURCE>
  573. <RESOURCE
  574. Name="RegKey(819):&quot;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SysmonLog&quot;,&quot;ObjectName&quot;"
  575. ResTypeVSGUID="{2C10DB69-39AB-48A4-A83F-9AB3ACBA7C45}"
  576. BuildTypeMask="819"
  577. BuildOrder="1000"
  578. Localize="False"
  579. Disabled="False"
  580. Context="1"
  581. PlatformGUID="{B784E719-C196-4DDB-B358-D9254426C38D}"
  582. >
  583. <PROPERTIES
  584. Context="1"
  585. PlatformGUID="{00000000-0000-0000-0000-000000000000}"
  586. >
  587. <PROPERTY
  588. Name="ComponentVSGUID"
  589. Format="GUID"
  590. Context="1"
  591. PlatformGUID="{00000000-0000-0000-0000-000000000000}"
  592. >{00000000-0000-0000-0000-000000000000}</PROPERTY>
  593. <PROPERTY
  594. Name="KeyPath"
  595. Format="String"
  596. Context="1"
  597. PlatformGUID="{00000000-0000-0000-0000-000000000000}"
  598. >HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SysmonLog</PROPERTY>
  599. <PROPERTY
  600. Name="RegCond"
  601. Format="Integer"
  602. Context="1"
  603. PlatformGUID="{00000000-0000-0000-0000-000000000000}"
  604. >1</PROPERTY>
  605. <PROPERTY
  606. Name="RegOp"
  607. Format="Integer"
  608. Context="1"
  609. PlatformGUID="{00000000-0000-0000-0000-000000000000}"
  610. >1</PROPERTY>
  611. <PROPERTY
  612. Name="RegType"
  613. Format="Integer"
  614. Context="1"
  615. PlatformGUID="{00000000-0000-0000-0000-000000000000}"
  616. >1</PROPERTY>
  617. <PROPERTY
  618. Name="ValueName"
  619. Format="String"
  620. Context="1"
  621. PlatformGUID="{00000000-0000-0000-0000-000000000000}"
  622. >ObjectName</PROPERTY>
  623. <PROPERTY
  624. Name="RegValue"
  625. Format="String"
  626. Context="1"
  627. PlatformGUID="{00000000-0000-0000-0000-000000000000}"
  628. >NT Authority\NetworkService</PROPERTY>
  629. </PROPERTIES>
  630. <DISPLAYNAME>HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SysmonLog\ObjectName</DISPLAYNAME>
  631. <DESCRIPTION></DESCRIPTION>
  632. </RESOURCE>
  633. <RESOURCE
  634. Name="RegKey(819):&quot;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SysmonLog&quot;,&quot;DefaultLogFileFolder&quot;"
  635. ResTypeVSGUID="{2C10DB69-39AB-48A4-A83F-9AB3ACBA7C45}"
  636. BuildTypeMask="819"
  637. BuildOrder="1000"
  638. Localize="False"
  639. Disabled="False"
  640. Context="1"
  641. PlatformGUID="{B784E719-C196-4DDB-B358-D9254426C38D}"
  642. >
  643. <PROPERTIES
  644. Context="1"
  645. PlatformGUID="{00000000-0000-0000-0000-000000000000}"
  646. >
  647. <PROPERTY
  648. Name="ComponentVSGUID"
  649. Format="GUID"
  650. Context="1"
  651. PlatformGUID="{00000000-0000-0000-0000-000000000000}"
  652. >{00000000-0000-0000-0000-000000000000}</PROPERTY>
  653. <PROPERTY
  654. Name="KeyPath"
  655. Format="String"
  656. Context="1"
  657. PlatformGUID="{00000000-0000-0000-0000-000000000000}"
  658. >HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SysmonLog</PROPERTY>
  659. <PROPERTY
  660. Name="RegCond"
  661. Format="Integer"
  662. Context="1"
  663. PlatformGUID="{00000000-0000-0000-0000-000000000000}"
  664. >1</PROPERTY>
  665. <PROPERTY
  666. Name="RegOp"
  667. Format="Integer"
  668. Context="1"
  669. PlatformGUID="{00000000-0000-0000-0000-000000000000}"
  670. >1</PROPERTY>
  671. <PROPERTY
  672. Name="RegType"
  673. Format="Integer"
  674. Context="1"
  675. PlatformGUID="{00000000-0000-0000-0000-000000000000}"
  676. >1</PROPERTY>
  677. <PROPERTY
  678. Name="ValueName"
  679. Format="String"
  680. Context="1"
  681. PlatformGUID="{00000000-0000-0000-0000-000000000000}"
  682. >DefaultLogFileFolder</PROPERTY>
  683. <PROPERTY
  684. Name="RegValue"
  685. Format="String"
  686. Context="1"
  687. PlatformGUID="{00000000-0000-0000-0000-000000000000}"
  688. >%SystemDrive%\PerfLogs</PROPERTY>
  689. </PROPERTIES>
  690. <DISPLAYNAME>HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SysmonLog\DefaultLogFileFolder</DISPLAYNAME>
  691. <DESCRIPTION></DESCRIPTION>
  692. </RESOURCE>
  693. </RESOURCES>
  694. <GROUPMEMBERS
  695. >
  696. <GROUPMEMBER
  697. GroupVSGUID="{E01B4103-3883-4FE8-992F-10566E7B796C}"
  698. ></GROUPMEMBER>
  699. <GROUPMEMBER
  700. GroupVSGUID="{D7523171-4196-45C3-BA4A-46ECD881D49B}"
  701. ></GROUPMEMBER>
  702. </GROUPMEMBERS>
  703. <DEPENDENCIES
  704. Context="1"
  705. PlatformGUID="{B784E719-C196-4DDB-B358-D9254426C38D}"
  706. > </DEPENDENCIES>
  707. <DISPLAYNAME>Performance Logs and Alerts Service</DISPLAYNAME>
  708. <VERSION>1.0</VERSION>
  709. <DESCRIPTION>Collects performance data from local or remote computers based on preconfigured schedule parameters, then writes the data to a log or triggers an alert.</DESCRIPTION>
  710. <COPYRIGHT>2000 Microsoft Corp.</COPYRIGHT>
  711. <VENDOR>Microsoft Corp.</VENDOR>
  712. <OWNERS>kathse</OWNERS>
  713. <AUTHORS>kathse</AUTHORS>
  714. <DATECREATED>7/20/2001</DATECREATED>
  715. <DATEREVISED>10/28/2001 7:34:52 PM</DATEREVISED>
  716. </COMPONENT>
  717. </COMPONENTS>
  718. <RESTYPES
  719. Context="1"
  720. PlatformGUID="{00000000-0000-0000-0000-000000000000}"
  721. > </RESTYPES>
  722. </DCARRIER>