Elastic Windows Event Explorer


Publisher - Microsoft-Windows-DotNETRuntime

Event ID 151 v1

Message:

ModuleID=%{ModuleID};
AssemblyID=%{AssemblyID};
AppDomainID=%{AppDomainID};
ModuleFlags=%{ModuleFlags};
ModuleILPath=%{Reserved1};ModuleNativePath=%{ModuleILPath};
ClrInstanceID=%{ModuleNativePath}

Event Data:

# Name In Type
Out Type
1 ModuleID win:UInt64 win:HexInt64
2 AssemblyID win:UInt64 win:HexInt64
3 AppDomainID win:UInt64 win:HexInt64
4 ModuleFlags win:UInt32 xs:unsignedInt
5 Reserved1 win:UInt32 xs:unsignedInt
6 ModuleILPath win:UnicodeString xs:string
7 ModuleNativePath win:UnicodeString xs:string
8 ClrInstanceID win:UInt16 xs:unsignedShort

Observed Windows Versions:

Version: 1

Fingerprint: RAHIMXKIELVT6