Enum ferrisetw::native::ExtendedDataItem
source · pub enum ExtendedDataItem {
Unsupported,
RelatedActivityId(GUID),
Sid(SID),
TsId(u32),
InstanceInfo(EVENT_EXTENDED_ITEM_INSTANCE),
StackTrace32(EVENT_EXTENDED_ITEM_STACK_TRACE32),
StackTrace64(EVENT_EXTENDED_ITEM_STACK_TRACE64),
EventKey(u64),
ProcessStartKey(u64),
}
Expand description
A safe representation of an ExtendedDataItem
Variants§
Unsupported
Unexpected or invalid (or not implemented yet in Ferrisetw) extended data type
RelatedActivityId(GUID)
Related activity identifier
Sid(SID)
Security identifier (SID) of the user that logged the event
TsId(u32)
Terminal session identifier
InstanceInfo(EVENT_EXTENDED_ITEM_INSTANCE)
StackTrace32(EVENT_EXTENDED_ITEM_STACK_TRACE32)
Call stack (if the event is captured on a 32-bit computer)
StackTrace64(EVENT_EXTENDED_ITEM_STACK_TRACE64)
Call stack (if the event is captured on a 64-bit computer)
EventKey(u64)
Unique event identifier
ProcessStartKey(u64)
Unique process identifier (unique across the boot session)