Modifying Provider Settings
To enhance the capturing configuration of a Trace Session, you can modify the following aspects of ETW-instrumented providers:
Driver-level filtering — as described in Common Provider Configuration Settings Summary, you can configure various low-level Fast Filters for PEF providers to introduce a selectivity factor to your Trace Sessions for performance improvements, for example, with the Microsoft-PEF-NDIS-PacketCapture provider. You can also configure special stack filters and packet traversal paths at the driver level for Trace Scenarios that use the Microsoft-Windows-NDIS-PacketCapture provider. Filtering at the driver-provider level improves speed, which can rapidly become a critical issue if large numbers of messages do not pass the filtering criteria.
Event filtering — as described in System ETW Provider Configuration Settings, you can specify Keyword and Level filter settings for numerous system ETW Providers to enable selective event logging via ETW, which subsequently focuses the events that Message Analyzer captures.
The indicated provider setting types are accessible from the Trace Scenario Configuration pane in the Message Analyzer Trace Session configuration interface. The available settings enable you to do the following:
Configure Groups of logically chained Fast Filters and assign them to selected adapters by specifying settings in the Microsoft-PEF-NDIS-PacketCapture Advanced Settings dialog for a Local Link Layer trace.
Configure Fast Filters in the PEF WFP Settings for a Firewall trace.
Set the Keyword and/or Level configuration of system ETW providers by specifying settings in the ETW Provider Core Configuration.
Specify the layers on which packets are intercepted in the NDIS filter stack or Hyper-V-Switch extension stack, in Trace Scenarios that use the Microsoft-Windows-NDIS-PacketCapture provider. You can also configure special filters such as Truncation, packet traversal Direction, EtherTypes, IP Protocol Numbers, Mac Addresses, and IP Addresses for this provider.
Note For system ETW Providers, you can only modify the Keyword and Level filtering configurations; however, not all system ETW Providers make keyword settings available for filtering. System ETW Providers, such as the Microsoft-Windows-LDAP-Client, are contained in a searchable library that is located in the Trace Scenario Configuration pane.
To learn more about common provider settings, see the Common Provider Configuration Settings Summary.
To learn more about settings for the Microsoft-PEF-NDIS-PacketCapture provider, see Using the PEF-NDIS Provider Advanced Settings Dialog.
To learn more about settings for the Microsoft-Windows-NDIS-PacketCapture provider, see Using the Windows NDIS Provider Advanced Settings Dialog.