|
121 | 121 | value="0x3002" |
122 | 122 | version="1" |
123 | 123 | /> |
| 124 | + <!--Telemetry events--> |
| 125 | + <event |
| 126 | + channel="C_OPERATIONAL" |
| 127 | + level="win:Error" |
| 128 | + message="$(string.PS_PROVIDER.event.E_O_TelemetrySettingError.message)" |
| 129 | + opcode="Exception" |
| 130 | + symbol="TelemetrySettingError" |
| 131 | + task="Telemetry" |
| 132 | + template="T_TelemetrySettingError" |
| 133 | + value="0x3011" |
| 134 | + version="1" |
| 135 | + /> |
124 | 136 | <!--M3P events--> |
125 | 137 | <event |
126 | 138 | channel="C_ANALYTIC" |
|
2208 | 2220 | value="0x6017" |
2209 | 2221 | version="1" |
2210 | 2222 | /> |
2211 | | - <event |
2212 | | - channel="C_ANALYTIC" |
2213 | | - keywords="AmsiState" |
2214 | | - level="win:Verbose" |
2215 | | - message="$(string.PS_PROVIDER.event.E_A_AmsiState.message)" |
2216 | | - opcode="Method" |
2217 | | - symbol="AmsiState" |
2218 | | - task="Amsi" |
2219 | | - template="T_AmsiState" |
2220 | | - value="0x4001" |
2221 | | - version="1" |
| 2223 | + <event |
| 2224 | + channel="C_ANALYTIC" |
| 2225 | + keywords="AmsiState" |
| 2226 | + level="win:Verbose" |
| 2227 | + message="$(string.PS_PROVIDER.event.E_A_AmsiState.message)" |
| 2228 | + opcode="Method" |
| 2229 | + symbol="AmsiState" |
| 2230 | + task="Amsi" |
| 2231 | + template="T_AmsiState" |
| 2232 | + value="0x4001" |
| 2233 | + version="1" |
| 2234 | + /> |
| 2235 | + <event |
| 2236 | + channel="C_ANALYTIC" |
| 2237 | + keywords="WDACQuery" |
| 2238 | + level="win:Verbose" |
| 2239 | + message="$(string.PS_PROVIDER.event.E_A_WDACQuery.message)" |
| 2240 | + opcode="Method" |
| 2241 | + symbol="WDACQuery" |
| 2242 | + task="WDAC" |
| 2243 | + template="T_WDACQuery" |
| 2244 | + value="0x4002" |
| 2245 | + version="1" |
| 2246 | + /> |
| 2247 | + <event |
| 2248 | + channel="C_ANALYTIC" |
| 2249 | + keywords="WDACAudit" |
| 2250 | + level="win:Verbose" |
| 2251 | + message = "$(string.PS_PROVIDER.event.E_A_WDACAudit.message)" |
| 2252 | + opcode="Method" |
| 2253 | + symbol="WDACAudit" |
| 2254 | + task="WDACAudit" |
| 2255 | + template="T_WDACAudit" |
| 2256 | + value="0x4003" |
| 2257 | + version="1" |
2222 | 2258 | /> |
2223 | 2259 | </events> |
2224 | 2260 | <channels> |
|
2409 | 2445 | symbol="T_EXPERIMENTALFEATURE" |
2410 | 2446 | value="107" |
2411 | 2447 | /> |
| 2448 | + <task |
| 2449 | + message="$(string.PS_PROVIDER.task.T_Telemetry.message)" |
| 2450 | + name="Telemetry" |
| 2451 | + symbol="T_TELEMETRY" |
| 2452 | + value="108" |
| 2453 | + /> |
2412 | 2454 | <task |
2413 | 2455 | message="$(string.PS_PROVIDER.task.T_ScheduledJob.message)" |
2414 | 2456 | name="ScheduledJob" |
|
2427 | 2469 | symbol="T_ISEOperation" |
2428 | 2470 | value="120" |
2429 | 2471 | /> |
2430 | | - <task |
2431 | | - message="$(string.PS_PROVIDER.task.T_AmsiState.message)" |
2432 | | - name="Amsi" |
2433 | | - symbol="T_Amsi" |
2434 | | - value="130" |
| 2472 | + <task |
| 2473 | + message="$(string.PS_PROVIDER.task.T_AmsiState.message)" |
| 2474 | + name="Amsi" |
| 2475 | + symbol="T_Amsi" |
| 2476 | + value="130" |
| 2477 | + /> |
| 2478 | + <task |
| 2479 | + message="$(string.PS_PROVIDER.task.T_WDACQuery.message)" |
| 2480 | + name="WDAC" |
| 2481 | + symbol="T_WDAC" |
| 2482 | + value="131" |
| 2483 | + /> |
| 2484 | + <task |
| 2485 | + message="$(string.PS_PROVIDER.task.T_WDACAudit.message)" |
| 2486 | + name="WDACAudit" |
| 2487 | + symbol="T_WDACAudit" |
| 2488 | + value="132" |
2435 | 2489 | /> |
2436 | 2490 | </tasks> |
2437 | 2491 | <opcodes> |
|
2593 | 2647 | name="PSWorkflow" |
2594 | 2648 | symbol="K_PSWORKFLOW" |
2595 | 2649 | /> |
2596 | | - <keyword |
2597 | | - mask="0x400" |
2598 | | - message="$(string.PS_PROVIDER.keyword.K_AmsiState.message)" |
2599 | | - name="AmsiState" |
2600 | | - symbol="K_AmsiState" |
| 2650 | + <keyword |
| 2651 | + mask="0x400" |
| 2652 | + message="$(string.PS_PROVIDER.keyword.K_AmsiState.message)" |
| 2653 | + name="AmsiState" |
| 2654 | + symbol="K_AmsiState" |
| 2655 | + /> |
| 2656 | + <keyword |
| 2657 | + mask="0x800" |
| 2658 | + message="$(string.PS_PROVIDER.keyword.K_WDACQuery.message)" |
| 2659 | + name="WDACQuery" |
| 2660 | + symbol="K_WDACQuery" |
| 2661 | + /> |
| 2662 | + <keyword |
| 2663 | + mask="0x1000" |
| 2664 | + message="$(string.PS_PROVIDER.keyword.K_WDACAudit.message)" |
| 2665 | + name="WDACAudit" |
| 2666 | + symbol="K_WDACAudit" |
2601 | 2667 | /> |
2602 | 2668 | </keywords> |
2603 | 2669 | <maps> |
|
4004 | 4070 | name="StackTrace" |
4005 | 4071 | /> |
4006 | 4072 | </template> |
| 4073 | + <template tid="T_TelemetrySettingError"> |
| 4074 | + <data |
| 4075 | + inType="win:UnicodeString" |
| 4076 | + name="Name" |
| 4077 | + /> |
| 4078 | + <data |
| 4079 | + inType="win:UnicodeString" |
| 4080 | + name="Message" |
| 4081 | + /> |
| 4082 | + <data |
| 4083 | + inType="win:UnicodeString" |
| 4084 | + name="StackTrace" |
| 4085 | + /> |
| 4086 | + </template> |
4007 | 4087 | <template tid="T_TrackingGuid"> |
4008 | 4088 | <data |
4009 | 4089 | inType="win:GUID" |
|
4080 | 4160 | name="FileName" |
4081 | 4161 | /> |
4082 | 4162 | </template> |
4083 | | - <template tid="T_AmsiState"> |
4084 | | - <data |
4085 | | - inType="win:UnicodeString" |
4086 | | - name="Action" |
| 4163 | + <template tid="T_AmsiState"> |
| 4164 | + <data |
| 4165 | + inType="win:UnicodeString" |
| 4166 | + name="Action" |
4087 | 4167 | /> |
4088 | | - <data |
4089 | | - inType="win:UnicodeString" |
4090 | | - name="AmsiContext" |
| 4168 | + <data |
| 4169 | + inType="win:UnicodeString" |
| 4170 | + name="AmsiContext" |
4091 | 4171 | /> |
4092 | | - </template> |
| 4172 | + </template> |
| 4173 | + <template tid="T_WDACQuery"> |
| 4174 | + <data |
| 4175 | + inType="win:UnicodeString" |
| 4176 | + name="QueryName" |
| 4177 | + /> |
| 4178 | + <data |
| 4179 | + inType="win:UnicodeString" |
| 4180 | + name="FileName" |
| 4181 | + /> |
| 4182 | + <data |
| 4183 | + inType="win:Int32" |
| 4184 | + name="QuerySuccess" |
| 4185 | + /> |
| 4186 | + <data |
| 4187 | + inType="win:Int32" |
| 4188 | + name="QuerySResult" |
| 4189 | + /> |
| 4190 | + </template> |
| 4191 | + <template tid="T_WDACAudit"> |
| 4192 | + <data |
| 4193 | + inType="win:UnicodeString" |
| 4194 | + name="Title" |
| 4195 | + /> |
| 4196 | + <data |
| 4197 | + inType="win:UnicodeString" |
| 4198 | + name="Message" |
| 4199 | + /> |
| 4200 | + <data |
| 4201 | + inType="win:UnicodeString" |
| 4202 | + name="FullyQualifiedId" |
| 4203 | + /> |
| 4204 | + </template> |
4093 | 4205 | </templates> |
4094 | 4206 | </provider> |
4095 | 4207 | </events> |
|
5535 | 5647 | id="PS_PROVIDER.task.T_ExperimentalFeature.message" |
5536 | 5648 | value="PowerShell Experimental Features" |
5537 | 5649 | /> |
| 5650 | + <string |
| 5651 | + id="PS_PROVIDER.event.E_O_TelemetrySettingError.message" |
| 5652 | + value="Failed to retrieve diagnostics and feedback setting from Windows.%n Exception: %1 %n Message: %2 %n StackTrace: %3 %n" |
| 5653 | + /> |
| 5654 | + <string |
| 5655 | + id="PS_PROVIDER.task.T_Telemetry.message" |
| 5656 | + value="PowerShell Telemetry" |
| 5657 | + /> |
5538 | 5658 | <string |
5539 | 5659 | id="PS_PROVIDER.task.T_NamedPipe.message" |
5540 | 5660 | value="PowerShell Named Pipe IPC" |
|
5719 | 5839 | id="PS_PROVIDER.event.E_O_REMOTE_NAMEDPIPE_DISCONNECT.message" |
5720 | 5840 | value="PowerShell IPC disconnect on process: %1 in AppDomain: %2 for User: %3." |
5721 | 5841 | /> |
| 5842 | + <string |
| 5843 | + id="PS_PROVIDER.event.E_A_WDACQuery.message" |
| 5844 | + value="WDAC Query. %n %t Query: %1 %n %t File: %2 %n %t SuccessCode: %3 %n %t ResultCode: %4" |
| 5845 | + /> |
| 5846 | + <string |
| 5847 | + id="PS_PROVIDER.keyword.K_WDACQuery.message" |
| 5848 | + value="WDAC Query" |
| 5849 | + /> |
| 5850 | + <string |
| 5851 | + id="PS_PROVIDER.task.T_WDACQuery.message" |
| 5852 | + value="WDAC Query" |
| 5853 | + /> |
| 5854 | + <string |
| 5855 | + id="PS_PROVIDER.event.E_A_WDACAudit.message" |
| 5856 | + value="WDAC Audit. %n %t Title: %1 %n %t Message: %2 %n %t FullyQualifiedId: %3" |
| 5857 | + /> |
| 5858 | + <string |
| 5859 | + id="PS_PROVIDER.keyword.K_WDACAudit.message" |
| 5860 | + value="WDAC Audit" |
| 5861 | + /> |
| 5862 | + <string |
| 5863 | + id="PS_PROVIDER.task.T_WDACAudit.message" |
| 5864 | + value="WDAC Audit" |
| 5865 | + /> |
5722 | 5866 | </stringTable> |
5723 | 5867 | </resources> |
5724 | 5868 | </localization> |
|
0 commit comments