General Check if Last Boot was from Fast Startup, Hibernate, Restart or Shutdown in Windows 11

  • Thread starter Thread starter Brink
  • Start date Published: Start date Updated Updated:

Power_banner.webp

This tutorial will show you how to check if the last boot was from a hybrid shutdown (fast startup), full shutdown or restart, or resume from hibernate in Windows 10 and Windows 11.

Fast startup (aka: hiberboot, hybrid boot, or hybrid shutdown) is turned on by default in Windows and is a setting that helps your PC start up faster after shutdown. Even faster than hibernate.

Hibernate is a power-saving state designed primarily for laptops, and might not be available for all PCs. Hibernate uses less power than sleep and when you start up the PC again, you’re back to where you left off (though not as fast as sleep). Use hibernation when you know that you won't use your laptop or tablet for an extended period and won't have an opportunity to charge the battery during that time.

A restart will sign out all users, shut down the computer, and then automatically reboot the computer. If you have Automatically save my restartable apps and restart them when I sign back in turned on, it will restore open apps that have registered for application restart after you restart or shutdown.

A full shutdown will close all apps, sign out all users, and completely turn off the PC. A full shutdown is good to use if you don't plan to use your PC for an extended period and wanted to completely power off the PC. If you have Automatically save my restartable apps and restart them when I sign back in turned on, it will restore open apps that have registered for application restart after you restart or shutdown.



Here's How:

1 Open Windows Terminal, and select either Windows PowerShell or Command Prompt.

2 Copy and paste the appropriate command below into Windows Terminal, and press Enter. (see screenshots below)

Windows PowerShell
Get-WinEvent -ProviderName Microsoft-Windows-Kernel-boot -MaxEvents 10 | where-object -Property id -eq "27"

OR​

Command Prompt
powershell -command "Get-WinEvent -ProviderName Microsoft-Windows-Kernel-boot -MaxEvents 10 | where-object -Property id -eq "27""


3 Look for The boot type was under the shutdown time period you want, and compare it with the table below.

Boot Type​
Description​
0x0restart OR cold boot from full shutdown
0x1hybrid boot (fast startup)
0x2resume from hibernation

PowerShell.webp


Command_Prompt.webp



That's it,
Shawn Brink

 
Last edited:
Doesn't work with powershell 7.6, bu this does:

Get-WinEvent -ProviderName Microsoft-Windows-Kernel-boot -MaxEvents 10 | where-object -Property id -like "27"


Screenshot 2026-03-24 171003.webp
 

My Computers

System One System Two

  • OS
    Windows 11 Pro x64
    Computer type
    PC/Desktop
    Manufacturer/Model
    📷🔈🎧 🪛 DIY Photoshop/Audio/Game/tinker
    CPU
    i9 14900K P/E 5.8/4.5 GHz, cache 5.0 GHz
    Motherboard
    Asus ROG Maximus Z790 Dark Hero
    Memory
    🐏 96GB (2x48) G.skill Ripjaws 6800 MT/s
    Graphics Card(s)
    Asus ROG Strix 4070 Ti OC
    Sound Card
    🔊Bowers & Wilkins 606 S3 speakers; Audiolabs 7000a integrated amp; RSL 10S Mk2 sub; Creative Pebble Pro Minimilist
    Monitor(s) Displays
    🖥️🖥️ Eizo CG2730 ColorEdge, ViewSonic VP2768
    Screen Resolution
    🖥️🖥️ 2560 x 1440p x 2
    Hard Drives
    💾 WDC SN850X 4TB nvme, SN850 1TB nvme, SK-Hynix 2 TB P41 nvme,. Sabrent USB-C DS-SC5B 5-bay docking station: 6TB WDC Black, 6TB Ironwolf Pro; 2x 2TB WDC Black HDD
    PSU
    ⚡️ 850W Seasonic Vertex PX-850 ATX 3.0/PCI-E 5.0
    Case
    Fractal Design North XL Mesh, Black Walnut
    Cooling
    ❄️ EK Nucleus black 360 AIO w/Phanteks T30-120 fans, 2 Noctua NF-A14 Chromax case fan, 1 T30-120 fan cooling memory
    Keyboard
    ⌨️ Keychron Q3 Max TKL with custom GMK Redsuns Red Samuri keycaps, TX Stabs
    Mouse
    🖱️ Logitech G305 wireless gaming
    Internet Speed
    ⬇️ 500 Mb/s ⬆️ 12 Mb/s
    Browser
    🔥🦊 Firefox
    Antivirus
    🦺 Defender, Macrium Reflect X 🏆
    Other Info
    Phangkey Amaterasu V2 Desk Mat
  • Computer type
    Laptop
    Manufacturer/Model
    💻 Apple 13" Macbook Pro 2020 (m1)
    CPU
    Apple M1
    Screen Resolution
    2560x1600
    Browser
    Firefox
I don't understand the need for -like, the matching Event ID is 27.

This command returns the last 10 boot events.
Code:
Get-WinEvent -ProviderName Microsoft-Windows-Kernel-boot | Where-Object { $_.Id -eq 27 } | ForEach-Object { '{0}  {1}' -f $_.TimeCreated.ToString("MM/dd/yyyy hh:mm:ss tt"), $(switch -regex ($_.Message) { "0x0" {'Restart or Cold Boot'} "0x1" {'Fast Startup'} "0x2" {'Resume from Hibernation'} })} | select -First 10

Code:
PS C:\Users\GARLIN\Downloads> Get-WinEvent -ProviderName Microsoft-Windows-Kernel-boot | Where-Object { $_.Id -eq 27 } | ForEach-Object { '{0}  {1}' -f $_.TimeCreated.ToString("MM/dd/yyyy hh:mm:ss tt"), $(switch -regex ($_.Message) { "0x0" {'Restart or Cold Boot'} "0x1" {'Fast Startup'} "0x2" {'Resume from Hibernation'} })} | select -First 10
03/12/2026 12:38:05 PM  Restart or Cold Boot
03/12/2026 12:32:32 PM  Restart or Cold Boot
03/11/2026 06:33:55 PM  Restart or Cold Boot
03/11/2026 06:23:37 PM  Restart or Cold Boot
01/13/2026 05:23:03 PM  Restart or Cold Boot
01/13/2026 02:04:48 PM  Restart or Cold Boot
01/13/2026 01:14:29 PM  Restart or Cold Boot
01/13/2026 01:02:39 PM  Restart or Cold Boot
 

My Computer

System One

  • OS
    Windows 7
I don't understand the need for -like, the matching Event ID is 27.

This command returns the last 10 boot events.
Code:
Get-WinEvent -ProviderName Microsoft-Windows-Kernel-boot | Where-Object { $_.Id -eq 27 } | ForEach-Object { '{0}  {1}' -f $_.TimeCreated.ToString("MM/dd/yyyy hh:mm:ss tt"), $(switch -regex ($_.Message) { "0x0" {'Restart or Cold Boot'} "0x1" {'Fast Startup'} "0x2" {'Resume from Hibernation'} })} | select -First 10

Code:
PS C:\Users\GARLIN\Downloads> Get-WinEvent -ProviderName Microsoft-Windows-Kernel-boot | Where-Object { $_.Id -eq 27 } | ForEach-Object { '{0}  {1}' -f $_.TimeCreated.ToString("MM/dd/yyyy hh:mm:ss tt"), $(switch -regex ($_.Message) { "0x0" {'Restart or Cold Boot'} "0x1" {'Fast Startup'} "0x2" {'Resume from Hibernation'} })} | select -First 10
03/12/2026 12:38:05 PM  Restart or Cold Boot
03/12/2026 12:32:32 PM  Restart or Cold Boot
03/11/2026 06:33:55 PM  Restart or Cold Boot
03/11/2026 06:23:37 PM  Restart or Cold Boot
01/13/2026 05:23:03 PM  Restart or Cold Boot
01/13/2026 02:04:48 PM  Restart or Cold Boot
01/13/2026 01:14:29 PM  Restart or Cold Boot
01/13/2026 01:02:39 PM  Restart or Cold Boot

What version of powershell are you using. I agree, -eq, but the { $.id -eq "27"} did mnot work for me.
 

My Computers

System One System Two

  • OS
    Windows 11 Pro x64
    Computer type
    PC/Desktop
    Manufacturer/Model
    📷🔈🎧 🪛 DIY Photoshop/Audio/Game/tinker
    CPU
    i9 14900K P/E 5.8/4.5 GHz, cache 5.0 GHz
    Motherboard
    Asus ROG Maximus Z790 Dark Hero
    Memory
    🐏 96GB (2x48) G.skill Ripjaws 6800 MT/s
    Graphics Card(s)
    Asus ROG Strix 4070 Ti OC
    Sound Card
    🔊Bowers & Wilkins 606 S3 speakers; Audiolabs 7000a integrated amp; RSL 10S Mk2 sub; Creative Pebble Pro Minimilist
    Monitor(s) Displays
    🖥️🖥️ Eizo CG2730 ColorEdge, ViewSonic VP2768
    Screen Resolution
    🖥️🖥️ 2560 x 1440p x 2
    Hard Drives
    💾 WDC SN850X 4TB nvme, SN850 1TB nvme, SK-Hynix 2 TB P41 nvme,. Sabrent USB-C DS-SC5B 5-bay docking station: 6TB WDC Black, 6TB Ironwolf Pro; 2x 2TB WDC Black HDD
    PSU
    ⚡️ 850W Seasonic Vertex PX-850 ATX 3.0/PCI-E 5.0
    Case
    Fractal Design North XL Mesh, Black Walnut
    Cooling
    ❄️ EK Nucleus black 360 AIO w/Phanteks T30-120 fans, 2 Noctua NF-A14 Chromax case fan, 1 T30-120 fan cooling memory
    Keyboard
    ⌨️ Keychron Q3 Max TKL with custom GMK Redsuns Red Samuri keycaps, TX Stabs
    Mouse
    🖱️ Logitech G305 wireless gaming
    Internet Speed
    ⬇️ 500 Mb/s ⬆️ 12 Mb/s
    Browser
    🔥🦊 Firefox
    Antivirus
    🦺 Defender, Macrium Reflect X 🏆
    Other Info
    Phangkey Amaterasu V2 Desk Mat
  • Computer type
    Laptop
    Manufacturer/Model
    💻 Apple 13" Macbook Pro 2020 (m1)
    CPU
    Apple M1
    Screen Resolution
    2560x1600
    Browser
    Firefox

My Computer

System One

  • OS
    Windows 11 Pro 25H2
    Computer type
    PC/Desktop
    Manufacturer/Model
    Intel NUC12WSHi7
    CPU
    12th Gen Core i7-1260P
    Motherboard
    NUC12WSBi7
    Memory
    64 GB Micron PC4-25600
    Graphics Card(s)
    Intel Iris Xe Graphics
    Sound Card
    on-board Realtek HD Audio
    Monitor(s) Displays
    Dell U3219Q
    Screen Resolution
    3840 x 2160
    Hard Drives
    Samsung SSD 990 PRO 1TB
    Crucial MX500 2 TB
    Antivirus
    Microsoft Defender

My Computers

System One System Two

  • OS
    Windows 11 Pro x64
    Computer type
    PC/Desktop
    Manufacturer/Model
    📷🔈🎧 🪛 DIY Photoshop/Audio/Game/tinker
    CPU
    i9 14900K P/E 5.8/4.5 GHz, cache 5.0 GHz
    Motherboard
    Asus ROG Maximus Z790 Dark Hero
    Memory
    🐏 96GB (2x48) G.skill Ripjaws 6800 MT/s
    Graphics Card(s)
    Asus ROG Strix 4070 Ti OC
    Sound Card
    🔊Bowers & Wilkins 606 S3 speakers; Audiolabs 7000a integrated amp; RSL 10S Mk2 sub; Creative Pebble Pro Minimilist
    Monitor(s) Displays
    🖥️🖥️ Eizo CG2730 ColorEdge, ViewSonic VP2768
    Screen Resolution
    🖥️🖥️ 2560 x 1440p x 2
    Hard Drives
    💾 WDC SN850X 4TB nvme, SN850 1TB nvme, SK-Hynix 2 TB P41 nvme,. Sabrent USB-C DS-SC5B 5-bay docking station: 6TB WDC Black, 6TB Ironwolf Pro; 2x 2TB WDC Black HDD
    PSU
    ⚡️ 850W Seasonic Vertex PX-850 ATX 3.0/PCI-E 5.0
    Case
    Fractal Design North XL Mesh, Black Walnut
    Cooling
    ❄️ EK Nucleus black 360 AIO w/Phanteks T30-120 fans, 2 Noctua NF-A14 Chromax case fan, 1 T30-120 fan cooling memory
    Keyboard
    ⌨️ Keychron Q3 Max TKL with custom GMK Redsuns Red Samuri keycaps, TX Stabs
    Mouse
    🖱️ Logitech G305 wireless gaming
    Internet Speed
    ⬇️ 500 Mb/s ⬆️ 12 Mb/s
    Browser
    🔥🦊 Firefox
    Antivirus
    🦺 Defender, Macrium Reflect X 🏆
    Other Info
    Phangkey Amaterasu V2 Desk Mat
  • Computer type
    Laptop
    Manufacturer/Model
    💻 Apple 13" Macbook Pro 2020 (m1)
    CPU
    Apple M1
    Screen Resolution
    2560x1600
    Browser
    Firefox
If I remember correctly, the original PowerShell version was something like

Get-WinEvent -ProviderName Microsoft-Windows-Kernel-boot -MaxEvents 10 | Where-Object { $_.Id -eq 27 }.

That would get the first 10 events, regardless of event ID, and then filter to only show event 27. If you had no event 27s in that first 10, you would get no results. You have to do it garlin's way if you mean "give me 10 events with an ID of 27," or use a hideous XPath query.

Powershell:
> Get-WinEvent -ProviderName Microsoft-Windows-Kernel-boot -MaxEvents 10 | Where-Object { $_.Id -eq 27 }

   ProviderName: Microsoft-Windows-Kernel-Boot

TimeCreated                     Id LevelDisplayName Message
-----------                     -- ---------------- -------
3/24/2026 5:02:13 PM            27 Information      The boot type was 0x0.


> Get-WinEvent -ProviderName Microsoft-Windows-Kernel-boot | Where-Object { $_.Id -eq 27 } | Select-Object -First 10

   ProviderName: Microsoft-Windows-Kernel-Boot

TimeCreated                     Id LevelDisplayName Message
-----------                     -- ---------------- -------
3/24/2026 5:02:13 PM            27 Information      The boot type was 0x0.
3/24/2026 7:17:12 AM            27 Information      The boot type was 0x0.
3/23/2026 7:51:21 PM            27 Information      The boot type was 0x0.
3/23/2026 5:57:26 PM            27 Information      The boot type was 0x0.
3/23/2026 4:10:32 PM            27 Information      The boot type was 0x0.
3/23/2026 12:19:46 PM           27 Information      The boot type was 0x0.
3/23/2026 1:59:20 AM            27 Information      The boot type was 0x0.
3/22/2026 10:09:36 PM           27 Information      The boot type was 0x0.
3/22/2026 9:52:02 PM            27 Information      The boot type was 0x0.
3/22/2026 9:23:00 PM            27 Information      The boot type was 0x0.
 

My Computer

System One

  • OS
    Windows 11 Pro 25H2
    Computer type
    PC/Desktop
    Manufacturer/Model
    Intel NUC12WSHi7
    CPU
    12th Gen Core i7-1260P
    Motherboard
    NUC12WSBi7
    Memory
    64 GB Micron PC4-25600
    Graphics Card(s)
    Intel Iris Xe Graphics
    Sound Card
    on-board Realtek HD Audio
    Monitor(s) Displays
    Dell U3219Q
    Screen Resolution
    3840 x 2160
    Hard Drives
    Samsung SSD 990 PRO 1TB
    Crucial MX500 2 TB
    Antivirus
    Microsoft Defender
This command returns the last 10 boot events
That's great. Many thanks.

I keep my version in a ps1 for convenience of use.
- I've merely altered the date-time format to a 24 hour clock with all elements in 'significance' order [20260325 092539].
- I've stuck a pause line at the end so I can look at the output. I don't expect to want to save the output to a file.
revised version.webp


ListBootDates-Times.ps1

### adapted from garlins version in www.elevenforum.com/t/check-if-last-boot-was-from-fast-startup-hibernate-restart-or-shutdown-in-windows-11.45563/#post-723337
### I merely made it display date-time in descending format with a 24 hour clock yyyyMMdd HHmmss

Get-WinEvent -ProviderName Microsoft-Windows-Kernel-boot | Where-Object { $_.Id -eq 27 } | ForEach-Object { '{0} {1}' -f $_.TimeCreated.ToString("yyyyMMdd HHmmss"), $(switch -regex ($_.Message) { "0x0" {'Restart or Cold Boot'} "0x1" {'Fast Startup'} "0x2" {'Resume from Hibernation'} })} | select -First 10

Pause



Thanks,
Denis
 

Attachments

Last edited:

My Computer

System One

  • OS
    Windows 11 Home x64 Version 25H2 Build 26200.8037
I just realized you can get pedantic, and move up the select -First N for slightly better performance.
Code:
Get-WinEvent -ProviderName Microsoft-Windows-Kernel-boot | Where-Object { $_.Id -eq 27 } | select -First 10 | ForEach-Object { '{0}  {1}' -f $_.TimeCreated.ToString("MM/dd/yyyy hh:mm:ss tt"), $(switch -regex ($_.Message) { "0x0" {'Restart or Cold Boot'} "0x1" {'Fast Startup'} "0x2" {'Resume from Hibernation'} })}
 

My Computer

System One

  • OS
    Windows 7
Does the script scan event viewer for entries and if there are none does it not comment?


Code:
Windows PowerShell
Copyright (C) Microsoft Corporation. All rights reserved.

Try the new cross-platform PowerShell https://aka.ms/pscore6

PS C:\WINDOWS\system32> ### adapted from garlins version in www.elevenforum.com/t/check-if-last-boot-was-from-fast-startup-hibernate-restart-or-shutdown-in-windows-11.45563/#post-723337
>> ### I merely made it display date-time in descending format with a 24 hour clock [yyyyMMdd HHmmss].
>>
>> Get-WinEvent -ProviderName Microsoft-Windows-Kernel-boot | Where-Object { $_.Id -eq 27 } | ForEach-Object { '{0}  {1}' -f $_.TimeCreated.ToString("yyyyMMdd HHmmss"), $(switch -regex ($_.Message) { "0x0" {'Restart or Cold Boot'} "0x1" {'Fast Startup'} "0x2" {'Resume from Hibernation'} })} | select -First 10
>>
>> Pause
Press Enter to continue...:
PS C:\WINDOWS\system32>
 

My Computer

System One

  • OS
    Windows 10
    Computer type
    Laptop
    Manufacturer/Model
    HP
    CPU
    Intel(R) Core(TM) i7-4800MQ CPU @ 2.70GHz
    Motherboard
    Product : 190A Version : KBC Version 94.56
    Memory
    16 GB Total: Manufacturer : Samsung MemoryType : DDR3 FormFactor : SODIMM Capacity : 8GB Speed : 1600
    Graphics Card(s)
    NVIDIA Quadro K3100M; Intel(R) HD Graphics 4600
    Sound Card
    IDT High Definition Audio CODEC; PNP Device ID HDAUDIO\FUNC_01&VEN_111D&DEV_76E0
    Hard Drives
    Model Hitachi HTS727575A9E364
    Antivirus
    Microsoft Defender
    Other Info
    Mobile Workstation
Does the script scan event viewer for entries and if there are none does it not comment?
Yes & yes.
Except that it scans event logs rather than Event viewer.


All the best,
Denis
 

My Computer

System One

  • OS
    Windows 11 Home x64 Version 25H2 Build 26200.8037
This was from AI:


Log Overwriting (FIFO): Event Viewer logs have a maximum size (default is usually 20 MB). Once a log file is full, Windows uses a "First In, First Out" (FIFO) method, meaning it overwrites the oldest events to make room for new ones. If your system generates many logs, older boot records will naturally be pushed out over time.


Increase Log Size: If your logs are disappearing too quickly due to overwriting, you can right-click the System log in Event Viewer, go to Properties, and increase the Maximum log size


the default size was 20480
 

My Computer

System One

  • OS
    Windows 10
    Computer type
    Laptop
    Manufacturer/Model
    HP
    CPU
    Intel(R) Core(TM) i7-4800MQ CPU @ 2.70GHz
    Motherboard
    Product : 190A Version : KBC Version 94.56
    Memory
    16 GB Total: Manufacturer : Samsung MemoryType : DDR3 FormFactor : SODIMM Capacity : 8GB Speed : 1600
    Graphics Card(s)
    NVIDIA Quadro K3100M; Intel(R) HD Graphics 4600
    Sound Card
    IDT High Definition Audio CODEC; PNP Device ID HDAUDIO\FUNC_01&VEN_111D&DEV_76E0
    Hard Drives
    Model Hitachi HTS727575A9E364
    Antivirus
    Microsoft Defender
    Other Info
    Mobile Workstation
Does the script scan event viewer for entries and if there are none does it not comment?

Code:
$Events = (Get-WinEvent -ProviderName Microsoft-Windows-Kernel-boot | Where-Object { $_.Id -eq 27 } | select -First 10); if ($Events -ne $null) { $Events | ForEach-Object { '{0}  {1}' -f $_.TimeCreated.ToString("MM/dd/yyyy hh:mm:ss tt"), $(switch -regex ($_.Message) { "0x0" {'Restart or Cold Boot'} "0x1" {'Fast Startup'} "0x2" {'Resume from Hibernation'} })} } else { 'No Event ID 27 found.' }
 

My Computer

System One

  • OS
    Windows 7
This was from AI:


Log Overwriting (FIFO): Event Viewer logs have a maximum size (default is usually 20 MB). Once a log file is full, Windows uses a "First In, First Out" (FIFO) method, meaning it overwrites the oldest events to make room for new ones. If your system generates many logs, older boot records will naturally be pushed out over time.


Increase Log Size: If your logs are disappearing too quickly due to overwriting, you can right-click the System log in Event Viewer, go to Properties, and increase the Maximum log size


the default size was 20480

There's multiple log files, one for each event channel.
Code:
Get-WinEvent -ListLog * | Select-Object LogName,@{Name="FileSizeMB"; Expression={$_.FileSize / 1MB}}, @{Name="MaxSizeMB"; Expression={$_.MaximumSizeInBytes / 1MB}} | Sort-Object LogName

Code:
Get-WinEvent -ListLog Microsoft-Windows-Kernel-Boot/Operational | Select-Object LogName,@{Name="FileSizeMB"; Expression={$_.FileSize / 1MB}}, @{Name="MaxSizeMB"; Expression={$_.MaximumSizeInBytes / 1MB}}

LogName                                   FileSizeMB MaxSizeMB
-------                                   ---------- ---------
Microsoft-Windows-Kernel-Boot/Operational       0.07      1.00
 

My Computer

System One

  • OS
    Windows 7
These were the results from posts 14 and 15:


Code:
Windows PowerShell
Copyright (C) Microsoft Corporation. All rights reserved.

Try the new cross-platform PowerShell https://aka.ms/pscore6

PS C:\WINDOWS\system32> Get-WinEvent -ProviderName Microsoft-Windows-Kernel-boot | Where-Object { $_.Id -eq 27 } | ForEach-Object { '{0}  {1}' -f $_.TimeCreated.ToString("yyyyMMdd HHmmss"), $(switch -regex ($_.Message) { "0x0" {'Restart or Cold Boot'} "0x1" {'Fast Startup'} "0x2" {'Resume from Hibernation'} })} | select -First 10
>>
>> Pause
Press Enter to continue...:
PS C:\WINDOWS\system32> $Events = (Get-WinEvent -ProviderName Microsoft-Windows-Kernel-boot | Where-Object { $_.Id -eq 27 } | select -First 10); if ($Events -ne $null) { $Events | ForEach-Object { '{0}  {1}' -f $_.TimeCreated.ToString("MM/dd/yyyy hh:mm:ss tt"), $(switch -regex ($_.Message) { "0x0" {'Restart or Cold Boot'} "0x1" {'Fast Startup'} "0x2" {'Resume from Hibernation'} })} } else { 'No Event ID 27 found.' }
No Event ID 27 found.
PS C:\WINDOWS\system32> Get-WinEvent -ListLog * | Select-Object LogName,@{Name="FileSizeMB"; Expression={$_.FileSize / 1MB}}, @{Name="MaxSizeMB"; Expression={$_.MaximumSizeInBytes / 1MB}} | Sort-Object LogName

LogName                                                                                 FileSizeMB       MaxSizeMB
-------                                                                                 ----------       ---------
AMSI/Operational                                                                        0.06640625      1.00390625
Application                                                                             2.06640625              20
ForwardedEvents                                                                                  0              20
HardwareEvents                                                                          0.06640625              20
Hewlett-Packard                                                                         0.06640625      1.00390625
HP CASL Framework                                                                       0.06640625               4
HP Diagnostics                                                                          0.06640625               4
HP HotKey Support                                                                       0.06640625               4
Internet Explorer                                                                       0.06640625      1.00390625
Key Management Service                                                                  0.06640625              20
Microsoft-AppV-Client/Admin                                                             0.06640625              10
Microsoft-AppV-Client/Operational                                                       0.06640625              10
Microsoft-AppV-Client/Virtual Applications                                              0.06640625              10
Microsoft-Client-License-ESU/Admin                                                      0.06640625      1.00390625
Microsoft-Client-License-Flexible-Platform/Admin                                        0.06640625      1.00390625
Microsoft-Client-Licensing-Platform/Admin                                               1.00390625      1.00390625
Microsoft-User Experience Virtualization-Agent Driver/Operational                       0.06640625      1.00390625
Microsoft-User Experience Virtualization-App Agent/Operational                          0.06640625      1.00390625
Microsoft-User Experience Virtualization-IPC/Operational                                0.06640625      1.00390625
Microsoft-User Experience Virtualization-SQM Uploader/Operational                       0.06640625      1.00390625
Microsoft-Windows-AAD/Operational                                                       0.06640625      1.00390625
Microsoft-Windows-AllJoyn/Operational                                                   0.06640625      1.00390625
Microsoft-Windows-All-User-Install-Agent/Admin                                          0.06640625      1.00390625
Microsoft-Windows-AppHost/Admin                                                         0.06640625      1.00390625
Microsoft-Windows-AppID/Operational                                                     0.06640625      1.00390625
Microsoft-Windows-ApplicabilityEngine/Operational                                       0.06640625      1.00390625
Microsoft-Windows-Application Server-Applications/Admin                                 0.06640625      1.00390625
Microsoft-Windows-Application Server-Applications/Operational                           0.06640625      1.00390625
Microsoft-Windows-Application-Experience/Program-Compatibility-Assistant                0.06640625      1.00390625
Microsoft-Windows-Application-Experience/Program-Compatibility-Troubleshooter           0.06640625      1.00390625
Microsoft-Windows-Application-Experience/Program-Inventory                              0.06640625      1.00390625
Microsoft-Windows-Application-Experience/Program-Telemetry                              1.00390625      1.00390625
Microsoft-Windows-Application-Experience/Steps-Recorder                                 0.06640625      1.00390625
Microsoft-Windows-ApplicationResourceManagementSystem/Operational                       0.06640625      1.00390625
Microsoft-Windows-AppLocker/EXE and DLL                                                 0.06640625      1.00390625
Microsoft-Windows-AppLocker/MSI and Script                                              0.06640625      1.00390625
Microsoft-Windows-AppLocker/Packaged app-Deployment                                     0.06640625      1.00390625
Microsoft-Windows-AppLocker/Packaged app-Execution                                      0.06640625      1.00390625
Microsoft-Windows-AppModel-Runtime/Admin                                                1.00390625      1.00390625
Microsoft-Windows-AppReadiness/Admin                                                    1.06640625               5
Microsoft-Windows-AppReadiness/Operational                                              1.06640625               5
Microsoft-Windows-AppXDeployment/Operational                                            1.00390625      1.00390625
Microsoft-Windows-AppXDeploymentServer/Operational                                      5.00390625               5
Microsoft-Windows-AppXDeployment-Server/Operational                                     1.06640625               5
Microsoft-Windows-AppXDeploymentServer/Restricted                                       0.06640625      1.00390625
Microsoft-Windows-AppxPackaging/Operational                                             1.00390625      1.00390625
Microsoft-Windows-ASN1/Operational                                                               0      1.00390625
Microsoft-Windows-AssignedAccess/Admin                                                  0.06640625      1.00390625
Microsoft-Windows-AssignedAccess/Operational                                                     0      1.00390625
Microsoft-Windows-AssignedAccessBroker/Admin                                            0.06640625      1.00390625
Microsoft-Windows-AssignedAccessBroker/Operational                                               0      1.00390625
Microsoft-Windows-Audio/CaptureMonitor                                                  0.06640625      1.00390625
Microsoft-Windows-Audio/GlitchDetection                                                          0      1.00390625
Microsoft-Windows-Audio/Informational                                                            0      1.00390625
Microsoft-Windows-Audio/Operational                                                     0.06640625      1.00390625
Microsoft-Windows-Audio/PlaybackManager                                                 0.06640625      1.00390625
Microsoft-Windows-Authentication User Interface/Operational                             0.06640625      1.00390625
Microsoft-Windows-Authentication/AuthenticationPolicyFailures-DomainController                   0      1.00390625
Microsoft-Windows-Authentication/ProtectedUser-Client                                            0      1.00390625
Microsoft-Windows-Authentication/ProtectedUserFailures-DomainController                          0      1.00390625
Microsoft-Windows-Authentication/ProtectedUserSuccesses-DomainController                         0      1.00390625
Microsoft-Windows-AzureCheck/Admin                                                      0.06640625      1.00390625
Microsoft-Windows-BackgroundTaskInfrastructure/Operational                              0.06640625      1.00390625
Microsoft-Windows-BackgroundTransfer-ContentPrefetcher/Operational                               0      1.00390625
Microsoft-Windows-Backup                                                                0.06640625      1.00390625
Microsoft-Windows-Base-Filtering-Engine-Connections/Operational                                  0      1.00390625
Microsoft-Windows-Base-Filtering-Engine-Resource-Flows/Operational                               0      1.00390625
Microsoft-Windows-Biometrics/Operational                                                1.00390625      1.00390625
Microsoft-Windows-BitLocker/BitLocker Management                                        1.00390625      1.00390625
Microsoft-Windows-BitLocker/BitLocker Operational                                                0      1.00390625
Microsoft-Windows-BitLocker-DrivePreparationTool/Admin                                  0.06640625      1.00390625
Microsoft-Windows-BitLocker-DrivePreparationTool/Operational                            0.06640625      1.00390625
Microsoft-Windows-Bits-Client/Analytic                                                           0      1.00390625
Microsoft-Windows-Bits-Client/Operational                                               1.00390625      1.00390625
Microsoft-Windows-Bluetooth-BthLEEnum/Operational                                       0.06640625      1.00390625
Microsoft-Windows-Bluetooth-BthLEPrepairing/Operational                                 0.06640625      1.00390625
Microsoft-Windows-Bluetooth-Bthmini/Operational                                                  0      1.00390625
Microsoft-Windows-Bluetooth-MTPEnum/Operational                                         0.06640625      1.00390625
Microsoft-Windows-Bluetooth-Policy/Operational                                                   0      1.00390625
Microsoft-Windows-BranchCache/Operational                                               0.06640625      1.00390625
Microsoft-Windows-BranchCacheSMB/Operational                                            0.06640625      1.00390625
Microsoft-Windows-CAPI2/Operational                                                              0      1.00390625
Microsoft-Windows-CertificateServicesClient-CredentialRoaming/Operational                        0      1.00390625
Microsoft-Windows-CertificateServicesClient-Lifecycle-System/Operational                0.06640625      1.00390625
Microsoft-Windows-CertificateServicesClient-Lifecycle-User/Operational                  0.06640625      1.00390625
Microsoft-Windows-CertPoleEng/Operational                                                        0      1.00390625
Microsoft-Windows-Cleanmgr/Diagnostic                                                   4.06640625               8
Microsoft-Windows-CloudRestoreLauncher/Operational                                      1.00390625      1.00390625
Microsoft-Windows-CloudStorageWizard/Operational                                        0.06640625      1.00390625
Microsoft-Windows-CloudStore/Debug                                                               0              10
Microsoft-Windows-CloudStore/Initialization                                             0.06640625      1.00390625
Microsoft-Windows-CloudStore/Operational                                                1.00390625      1.00390625
Microsoft-Windows-CodeIntegrity/Operational                                             1.00390625      1.00390625
Microsoft-Windows-Compat-Appraiser/Operational                                          0.06640625      1.00390625
Microsoft-Windows-Containers-BindFlt/Operational                                        0.06640625      1.00390625
Microsoft-Windows-Containers-Wcifs/Operational                                          0.06640625      1.00390625
Microsoft-Windows-Containers-Wcnfs/Operational                                          0.06640625      1.00390625
Microsoft-Windows-CoreApplication/Operational                                           0.06640625      1.00390625
Microsoft-Windows-CoreSystem-SmsRouter-Events/Operational                               0.06640625      1.00390625
Microsoft-Windows-CorruptedFileRecovery-Client/Operational                              0.06640625      1.00390625
Microsoft-Windows-CorruptedFileRecovery-Server/Operational                              0.06640625      1.00390625
Microsoft-Windows-Crypto-DPAPI/BackUpKeySvc                                             0.06640625      1.00390625
Microsoft-Windows-Crypto-DPAPI/Debug                                                             0      1.00390625
Microsoft-Windows-Crypto-DPAPI/Operational                                              1.00390625      1.00390625
Microsoft-Windows-Crypto-NCrypt/Operational                                             1.00390625      1.00390625
Microsoft-Windows-DAL-Provider/Operational                                              0.06640625      1.00390625
Microsoft-Windows-DataIntegrityScan/Admin                                               0.06640625      1.00390625
Microsoft-Windows-DataIntegrityScan/CrashRecovery                                       0.06640625      1.00390625
Microsoft-Windows-DateTimeControlPanel/Operational                                      0.06640625      1.00390625
Microsoft-Windows-Deduplication/Diagnostic                                              0.06640625             100
Microsoft-Windows-Deduplication/Operational                                             0.06640625              10
Microsoft-Windows-Deduplication/Scrubbing                                               0.06640625              10
Microsoft-Windows-DeviceGuard/Operational                                               0.06640625      1.00390625
Microsoft-Windows-DeviceManagement-Enterprise-Diagnostics-Provider/Admin                1.00390625      1.00390625
Microsoft-Windows-DeviceManagement-Enterprise-Diagnostics-Provider/Enrollment           0.06640625      1.00390625
Microsoft-Windows-DeviceManagement-Enterprise-Diagnostics-Provider/Operational          1.00390625      1.00390625
Microsoft-Windows-DeviceManagement-Enterprise-Diagnostics-Provider/Sync                 0.06640625      1.00390625
Microsoft-Windows-Devices-Background/Operational                                        0.06640625      1.00390625
Microsoft-Windows-DeviceSetupManager/Admin                                              1.00390625      1.00390625
Microsoft-Windows-DeviceSetupManager/Operational                                        0.06640625      1.00390625
Microsoft-Windows-DeviceSync/Operational                                                0.06640625      1.00390625
Microsoft-Windows-DeviceUpdateAgent/Operational                                         0.06640625      1.00390625
Microsoft-Windows-Dhcp-Client/Admin                                                     0.06640625      1.00390625
Microsoft-Windows-Dhcp-Client/Operational                                                        0      1.00390625
Microsoft-Windows-Dhcpv6-Client/Admin                                                   0.06640625      1.00390625
Microsoft-Windows-Dhcpv6-Client/Operational                                                      0      1.00390625
Microsoft-Windows-Diagnosis-DPS/Operational                                             1.00390625      1.00390625
Microsoft-Windows-Diagnosis-PCW/Operational                                             1.00390625      1.00390625
Microsoft-Windows-Diagnosis-PLA/Operational                                             0.06640625      1.00390625
Microsoft-Windows-Diagnosis-Scheduled/Operational                                       1.00390625      1.00390625
Microsoft-Windows-Diagnosis-Scripted/Admin                                              1.00390625      1.00390625
Microsoft-Windows-Diagnosis-Scripted/Operational                                        1.00390625      1.00390625
Microsoft-Windows-Diagnosis-ScriptedDiagnosticsProvider/Operational                     1.00390625      1.00390625
Microsoft-Windows-Diagnostics-Networking/Operational                                    0.06640625      1.00390625
Microsoft-Windows-Diagnostics-Performance/Operational                                   1.00390625      1.00390625
Microsoft-Windows-DiskDiagnostic/Operational                                            0.06640625      1.00390625
Microsoft-Windows-DiskDiagnosticDataCollector/Operational                               0.06640625      1.00390625
Microsoft-Windows-DiskDiagnosticResolver/Operational                                    0.06640625      1.00390625
Microsoft-Windows-DisplayColorCalibration/Operational                                            0      1.00390625
Microsoft-Windows-DNS-Client/Operational                                                         0      1.00390625
Microsoft-Windows-DriverFrameworks-UserMode/Operational                                          0      1.00390625
Microsoft-Windows-DSC/Admin                                                             0.06640625      1.00390625
Microsoft-Windows-DSC/Operational                                                       0.06640625      1.00390625
Microsoft-Windows-DucUpdateAgent/Operational                                            0.06640625      1.00390625
Microsoft-Windows-DxgKrnl-Admin                                                         0.06640625      1.00390625
Microsoft-Windows-DxgKrnl-Operational                                                   0.06640625      1.00390625
Microsoft-Windows-EapHost/Operational                                                   0.06640625      1.00390625
Microsoft-Windows-EapMethods-RasChap/Operational                                        0.06640625      1.00390625
Microsoft-Windows-EapMethods-RasTls/Operational                                         0.06640625      1.00390625
Microsoft-Windows-EapMethods-Sim/Operational                                            0.06640625      1.00390625
Microsoft-Windows-EapMethods-Ttls/Operational                                           0.06640625      1.00390625
Microsoft-Windows-EDP-Application-Learning/Admin                                        0.06640625      1.00390625
Microsoft-Windows-EDP-Audit-Regular/Admin                                               0.06640625      1.00390625
Microsoft-Windows-EDP-Audit-TCB/Admin                                                   0.06640625      1.00390625
Microsoft-Windows-EmbeddedAppLauncher/Admin                                             0.06640625      1.00390625
Microsoft-Windows-EmbeddedAppLauncher/Operational                                                0      1.00390625
Microsoft-Windows-Energy-Estimation-Engine/EventLog                                              0      1.00390625
Microsoft-Windows-ESE/Operational                                                                0      1.00390625
Microsoft-Windows-EventCollector/Operational                                            0.06640625      1.00390625
Microsoft-Windows-Fault-Tolerant-Heap/Operational                                       0.06640625      1.00390625
Microsoft-Windows-FeatureConfiguration/Operational                                      0.06640625      1.00390625
Microsoft-Windows-FileHistory-Core/WHC                                                  0.06640625      1.00390625
Microsoft-Windows-FileHistory-Engine/BackupLog                                          0.06640625      1.00390625
Microsoft-Windows-FMS/Operational                                                       0.06640625      1.00390625
Microsoft-Windows-Folder Redirection/Operational                                        0.06640625               4
Microsoft-Windows-Forwarding/Operational                                                0.06640625      1.00390625
Microsoft-Windows-GenericRoaming/Admin                                                  0.06640625      1.00390625
Microsoft-Windows-glcnd/Admin                                                                    0      1.00390625
Microsoft-Windows-GroupPolicy/Operational                                               4.00390625               4
Microsoft-Windows-HelloForBusiness/Operational                                          1.00390625      1.00390625
Microsoft-Windows-Help/Operational                                                      0.06640625      1.00390625
Microsoft-Windows-HomeGroup Control Panel/Operational                                   0.06640625      1.00390625
Microsoft-Windows-HomeGroup Listener Service/Operational                                0.06640625      1.00390625
Microsoft-Windows-HomeGroup Provider Service/Operational                                0.06640625      1.00390625
Microsoft-Windows-HotspotAuth/Operational                                               0.06640625      1.00390625
Microsoft-Windows-HttpService/Log                                                                0      1.00390625
Microsoft-Windows-HttpService/Trace                                                              0      1.00390625
Microsoft-Windows-Hyper-V-Guest-Drivers/Admin                                           0.06640625      1.00390625
Microsoft-Windows-Hyper-V-Guest-Drivers/Operational                                              0      1.00390625
Microsoft-Windows-Hyper-V-Hypervisor-Admin                                              0.06640625      1.00390625
Microsoft-Windows-Hyper-V-Hypervisor-Operational                                        0.06640625      1.00390625
Microsoft-Windows-Hyper-V-VID-Admin                                                     0.06640625      1.00390625
Microsoft-Windows-IdCtrls/Operational                                                   0.06640625      1.00390625
Microsoft-Windows-IKE/Operational                                                       0.06640625      1.00390625
Microsoft-Windows-International/Operational                                             0.06640625      1.00390625
Microsoft-Windows-International-RegionalOptionsControlPanel/Operational                 0.06640625      1.00390625
Microsoft-Windows-Iphlpsvc/Operational                                                  0.06640625      1.00390625
Microsoft-Windows-IPxlatCfg/Operational                                                 0.06640625      1.00390625
Microsoft-Windows-KdsSvc/Operational                                                    0.06640625      1.00390625
Microsoft-Windows-Kerberos/Operational                                                           0      1.00390625
Microsoft-Windows-Kernel-ApphelpCache/Operational                                       0.06640625      1.00390625
Microsoft-Windows-Kernel-Boot/Operational                                               0.06640625      1.00390625
Microsoft-Windows-Kernel-EventTracing/Admin                                             1.00390625      1.00390625
Microsoft-Windows-Kernel-IO/Operational                                                 0.06640625      1.00390625
Microsoft-Windows-Kernel-LiveDump/Operational                                           0.06640625      1.00390625
Microsoft-Windows-Kernel-PnP/Configuration                                              1.00390625      1.00390625
Microsoft-Windows-Kernel-PnP/Driver Watchdog                                            0.06640625      1.00390625
Microsoft-Windows-Kernel-Power/Thermal-Operational                                      0.06640625      1.00390625
Microsoft-Windows-Kernel-ShimEngine/Operational                                         1.00390625      1.00390625
Microsoft-Windows-Kernel-StoreMgr/Operational                                           0.06640625      1.00390625
Microsoft-Windows-Kernel-WDI/Operational                                                0.06640625      1.00390625
Microsoft-Windows-Kernel-WHEA/Errors                                                    0.06640625              32
Microsoft-Windows-Kernel-WHEA/Operational                                               1.06640625              32
Microsoft-Windows-KeyboardFilter/Admin                                                  0.06640625      1.00390625
Microsoft-Windows-KeyboardFilter/Operational                                                     0      1.00390625
Microsoft-Windows-KeyboardFilter/Performance                                                     0      1.00390625
Microsoft-Windows-Known Folders API Service                                             1.00390625      1.00390625
Microsoft-Windows-LanguagePackSetup/Operational                                         1.00390625      1.00390625
Microsoft-Windows-LAPS/Operational                                                      0.06640625              50
Microsoft-Windows-LinkLayerDiscoveryProtocol/Operational                                         0      1.00390625
Microsoft-Windows-LiveId/Operational                                                    1.00390625      1.00390625
Microsoft-Windows-LSA/Operational                                                                0      1.00390625
Microsoft-Windows-MediaFoundation-Performance/SARStreamResource                                  0      1.00390625
Microsoft-Windows-MemoryDiagnostics-Results/Debug                                       0.06640625      1.00390625
Microsoft-Windows-Mobile-Broadband-Experience-Parser-Task/Operational                   0.06640625      1.00390625
Microsoft-Windows-Mobile-Broadband-Experience-SmsRouter/Admin                           0.06640625      1.00390625
Microsoft-Windows-ModernDeployment-Diagnostics-Provider/Admin                           0.06640625      1.00390625
Microsoft-Windows-ModernDeployment-Diagnostics-Provider/Autopilot                       0.06640625      1.00390625
Microsoft-Windows-ModernDeployment-Diagnostics-Provider/Diagnostics                     0.06640625      1.00390625
Microsoft-Windows-ModernDeployment-Diagnostics-Provider/ManagementService               0.06640625      1.00390625
Microsoft-Windows-Mprddm/Operational                                                    0.06640625      1.00390625
Microsoft-Windows-MSPaint/Admin                                                                  0      1.00390625
Microsoft-Windows-MUI/Admin                                                             0.06640625      1.00390625
Microsoft-Windows-MUI/Operational                                                       0.06640625      1.00390625
Microsoft-Windows-Ncasvc/Operational                                                             0      1.00390625
Microsoft-Windows-NcdAutoSetup/Operational                                              0.06640625      1.00390625
Microsoft-Windows-NCSI/Operational                                                      1.00390625      1.00390625
Microsoft-Windows-NDIS/Operational                                                               0      1.00390625
Microsoft-Windows-NdisImPlatform/Operational                                            0.06640625      1.00390625
Microsoft-Windows-NetworkLocationWizard/Operational                                     0.06640625      1.00390625
Microsoft-Windows-NetworkProfile/Operational                                            1.00390625      1.00390625
Microsoft-Windows-NetworkProvider/Operational                                           0.06640625      1.00390625
Microsoft-Windows-NetworkProvisioning/Operational                                       0.06640625      1.00390625
Microsoft-Windows-NlaSvc/Operational                                                    0.06640625      1.00390625
Microsoft-Windows-Ntfs/Operational                                                      1.06640625              32
Microsoft-Windows-Ntfs/WHC                                                              0.06640625      1.00390625
Microsoft-Windows-NTLM/Operational                                                      0.06640625      1.00390625
Microsoft-Windows-NvdimmN/Operational                                                   0.06640625      1.00390625
Microsoft-Windows-OcpUpdateAgent/Operational                                            0.06640625      1.00390625
Microsoft-Windows-OfflineFiles/Operational                                              0.06640625      1.00390625
Microsoft-Windows-OneBackup/Debug                                                       0.06640625      1.00390625
Microsoft-Windows-OneX/Operational                                                               0      1.00390625
Microsoft-Windows-OOBE-Machine-DUI/Operational                                          0.06640625      1.00390625
Microsoft-Windows-OtpCredentialProvider/Operational                                              0      1.00390625
Microsoft-Windows-PackageStateRoaming/Operational                                       0.06640625      1.00390625
Microsoft-Windows-ParentalControls/Operational                                          0.06640625      1.00390625
Microsoft-Windows-Partition/Diagnostic                                                  1.06640625              16
Microsoft-Windows-PerceptionRuntime/Operational                                         0.06640625      1.00390625
Microsoft-Windows-PerceptionSensorDataService/Operational                               0.06640625      1.00390625
Microsoft-Windows-PersistentMemory-Nvdimm/Operational                                   0.06640625               6
Microsoft-Windows-PersistentMemory-PmemDisk/Operational                                 0.06640625               6
Microsoft-Windows-PersistentMemory-ScmBus/Certification                                 0.06640625      1.00390625
Microsoft-Windows-PersistentMemory-ScmBus/Operational                                   0.06640625               6
Microsoft-WindowsPhone-Connectivity-WiFiConnSvc-Channel                                 0.06640625      1.00390625
Microsoft-Windows-PmemDisk/Operational                                                  0.06640625      1.00390625
Microsoft-Windows-Policy/Operational                                                    0.06640625      1.00390625
Microsoft-Windows-PowerShell/Admin                                                      0.06640625     1000.390625
Microsoft-Windows-PowerShell/Operational                                               15.00390625              15
Microsoft-Windows-PowerShell-DesiredStateConfiguration-FileDownloadManager/Operational  0.06640625      1.00390625
Microsoft-Windows-PrintBRM/Admin                                                        0.06640625      1.00390625
Microsoft-Windows-PrintService/Admin                                                    0.06640625      1.00390625
Microsoft-Windows-PrintService/Operational                                                       0      1.00390625
Microsoft-Windows-PriResources-Deployment/Operational                                   0.06640625      1.00390625
Microsoft-Windows-Privacy-Auditing/Operational                                          0.06640625             100
Microsoft-Windows-Program-Compatibility-Assistant/Analytic                                       0      1.00390625
Microsoft-Windows-Program-Compatibility-Assistant/CompatAfterUpgrade                    0.06640625      1.00390625
Microsoft-Windows-Provisioning-Diagnostics-Provider/Admin                               1.00390625      1.00390625
Microsoft-Windows-Provisioning-Diagnostics-Provider/AutoPilot                           0.06640625      1.00390625
Microsoft-Windows-Provisioning-Diagnostics-Provider/ManagementService                   0.06640625      1.00390625
Microsoft-Windows-Proximity-Common/Diagnostic                                                    0      1.00390625
Microsoft-Windows-PushNotification-Platform/Admin                                       0.06640625      1.00390625
Microsoft-Windows-PushNotification-Platform/Operational                                 1.00390625      1.00390625
Microsoft-Windows-RasAgileVpn/Operational                                                        0      1.00390625
Microsoft-Windows-ReadyBoost/Operational                                                0.06640625      1.00390625
Microsoft-Windows-ReadyBoostDriver/Operational                                          0.06640625      1.00390625
Microsoft-Windows-ReFS/Operational                                                      0.06640625      1.00390625
Microsoft-Windows-Regsvr32/Operational                                                  0.06640625      1.00390625
Microsoft-Windows-RemoteApp and Desktop Connections/Admin                               0.06640625      1.00390625
Microsoft-Windows-RemoteApp and Desktop Connections/Operational                         0.06640625      1.00390625
Microsoft-Windows-RemoteAssistance/Admin                                                0.06640625      1.00390625
Microsoft-Windows-RemoteAssistance/Operational                                          0.06640625      1.00390625
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS/Admin                                 0.06640625      1.00390625
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS/Operational                           0.06640625      1.00390625
Microsoft-Windows-RemoteDesktopServices-RemoteFX-Synth3dvsc/Admin                       0.06640625      1.00390625
Microsoft-Windows-RemoteDesktopServices-SessionServices/Operational                     0.06640625      1.00390625
Microsoft-Windows-Remotefs-Rdbss/Operational                                                     0      1.00390625
Microsoft-Windows-Resource-Exhaustion-Detector/Operational                              1.00390625      1.00390625
Microsoft-Windows-Resource-Exhaustion-Resolver/Operational                              1.00390625      1.00390625
Microsoft-Windows-RestartManager/Operational                                            0.06640625      1.00390625
Microsoft-Windows-RetailDemo/Admin                                                      0.06640625      1.00390625
Microsoft-Windows-RetailDemo/Operational                                                0.06640625      1.00390625
Microsoft-Windows-RRAS/Operational                                                               0      1.00390625
Microsoft-Windows-ScmBus/Certification                                                  0.06640625      1.00390625
Microsoft-Windows-ScmBus/Operational                                                             0      1.00390625
Microsoft-Windows-SearchUI/Operational                                                  0.06640625      1.00390625
Microsoft-Windows-SecureAssessment/Operational                                                   0      1.00390625
Microsoft-Windows-Security-Adminless/Operational                                        0.06640625      1.00390625
Microsoft-Windows-Security-Audit-Configuration-Client/Operational                       0.06640625      1.00390625
Microsoft-Windows-Security-EnterpriseData-FileRevocationManager/Operational             0.06640625      1.00390625
Microsoft-Windows-Security-ExchangeActiveSyncProvisioning/Operational                            0      1.00390625
Microsoft-Windows-Security-IdentityListener/Operational                                          0      1.00390625
Microsoft-Windows-Security-LessPrivilegedAppContainer/Operational                       1.00390625      1.00390625
Microsoft-Windows-Security-Mitigations/KernelMode                                       1.00390625      1.00390625
Microsoft-Windows-Security-Mitigations/UserMode                                         0.06640625      1.00390625
Microsoft-Windows-SecurityMitigationsBroker/Admin                                                0      1.00390625
Microsoft-Windows-SecurityMitigationsBroker/Operational                                 0.06640625      1.00390625
Microsoft-Windows-Security-Netlogon/Operational                                         0.06640625      1.00390625
Microsoft-Windows-Security-SPP-UX-GenuineCenter-Logging/Operational                     0.06640625      1.00390625
Microsoft-Windows-Security-SPP-UX-Notifications/ActionCenter                            0.06640625      1.00390625
Microsoft-Windows-Security-UserConsentVerifier/Audit                                    0.06640625      1.00390625
Microsoft-Windows-SENSE/Operational                                                     0.06640625      1.00390625
Microsoft-Windows-SenseIR/Operational                                                   0.06640625      1.00390625
Microsoft-Windows-ServiceReportingApi/Debug                                                      0      1.00390625
Microsoft-Windows-SettingSync/Debug                                                     3.06640625               5
Microsoft-Windows-SettingSync/Operational                                               0.06640625      1.00390625
Microsoft-Windows-SettingSync-Azure/Debug                                               0.06640625      1.00390625
Microsoft-Windows-SettingSync-Azure/Operational                                         0.06640625      1.00390625
Microsoft-Windows-SettingSync-OneDrive/Debug                                            0.06640625      1.00390625
Microsoft-Windows-SettingSync-OneDrive/Operational                                      0.06640625      1.00390625
Microsoft-Windows-ShellCommon-StartLayoutPopulation/Operational                         1.00390625      1.00390625
Microsoft-Windows-Shell-ConnectedAccountState/ActionCenter                              0.06640625      1.00390625
Microsoft-Windows-Shell-Core/ActionCenter                                               0.06640625      1.00390625
Microsoft-Windows-Shell-Core/AppDefaults                                                1.00390625      1.00390625
Microsoft-Windows-Shell-Core/LogonTasksChannel                                          0.06640625      1.00390625
Microsoft-Windows-Shell-Core/Operational                                                1.00390625      1.00390625
Microsoft-Windows-SmartCard-Audit/Authentication                                        0.06640625      1.00390625
Microsoft-Windows-SmartCard-DeviceEnum/Operational                                      0.06640625      1.00390625
Microsoft-Windows-SmartCard-TPM-VCard-Module/Admin                                      0.06640625      1.00390625
Microsoft-Windows-SmartCard-TPM-VCard-Module/Operational                                0.06640625      1.00390625
Microsoft-Windows-SmartScreen/Debug                                                              0      1.00390625
Microsoft-Windows-SmbClient/Audit                                                       0.06640625               8
Microsoft-Windows-SmbClient/Connectivity                                                5.06640625               8
Microsoft-Windows-SMBClient/Operational                                                 0.06640625               8
Microsoft-Windows-SmbClient/Security                                                    0.06640625               8
Microsoft-Windows-SMBServer/Audit                                                       0.06640625               8
Microsoft-Windows-SMBServer/Connectivity                                                0.06640625               8
Microsoft-Windows-SMBServer/Operational                                                 1.06640625               8
Microsoft-Windows-SMBServer/Security                                                    0.06640625               8
Microsoft-Windows-SMBWitnessClient/Admin                                                0.06640625      1.00390625
Microsoft-Windows-SMBWitnessClient/Informational                                        0.06640625      1.00390625
Microsoft-Windows-StateRepository/Operational                                           5.00390625               5
Microsoft-Windows-StateRepository/Restricted                                            0.06640625      1.00390625
Microsoft-Windows-Storage-ATAPort/Admin                                                          0      1.00390625
Microsoft-Windows-Storage-ATAPort/Operational                                                    0      1.00390625
Microsoft-Windows-Storage-ClassPnP/Admin                                                         0      1.00390625
Microsoft-Windows-Storage-ClassPnP/Operational                                          0.06640625               6
Microsoft-Windows-Storage-Disk/Admin                                                             0      1.00390625
Microsoft-Windows-Storage-Disk/Operational                                                       0      1.00390625
Microsoft-Windows-StorageManagement/Operational                                         0.06640625              32
Microsoft-Windows-StorageManagement-PartUtil/Operational                                0.06640625      1.00390625
Microsoft-Windows-StorageSettings/Diagnostic                                            1.06640625              64
Microsoft-Windows-StorageSpaces-Api/Operational                                         0.06640625      1.00390625
Microsoft-Windows-StorageSpaces-Driver/Diagnostic                                       0.06640625              16
Microsoft-Windows-StorageSpaces-Driver/Operational                                      0.06640625      1.00390625
Microsoft-Windows-StorageSpaces-ManagementAgent/WHC                                     0.06640625      1.00390625
Microsoft-Windows-StorageSpaces-SpaceManager/Diagnostic                                 0.06640625              16
Microsoft-Windows-StorageSpaces-SpaceManager/Operational                                0.06640625      1.00390625
Microsoft-Windows-Storage-Storport/Admin                                                         0      1.00390625
Microsoft-Windows-Storage-Storport/Health                                               6.00390625               6
Microsoft-Windows-Storage-Storport/Operational                                         22.06640625              32
Microsoft-Windows-Storage-Tiering/Admin                                                 0.06640625      1.00390625
Microsoft-Windows-Store/Operational                                                    19.12890625 19.073486328125
Microsoft-Windows-Storsvc/Diagnostic                                                    1.06640625              16
Microsoft-Windows-SystemSettingsThreshold/Operational                                   0.06640625      1.00390625
Microsoft-Windows-TaskScheduler/Maintenance                                             1.00390625      1.00390625
Microsoft-Windows-TaskScheduler/Operational                                                      0              10
Microsoft-Windows-TCPIP/Operational                                                     0.06640625      1.00390625
Microsoft-Windows-TenantRestrictions/Operational                                        0.06640625      1.00390625
Microsoft-Windows-TerminalServices-ClientUSBDevices/Admin                               0.06640625      1.00390625
Microsoft-Windows-TerminalServices-ClientUSBDevices/Operational                         0.06640625      1.00390625
Microsoft-Windows-TerminalServices-LocalSessionManager/Admin                            0.06640625      1.00390625
Microsoft-Windows-TerminalServices-LocalSessionManager/Operational                      1.00390625      1.00390625
Microsoft-Windows-TerminalServices-PnPDevices/Admin                                     0.06640625      1.00390625
Microsoft-Windows-TerminalServices-PnPDevices/Operational                               0.06640625      1.00390625
Microsoft-Windows-TerminalServices-Printers/Admin                                       0.06640625      1.00390625
Microsoft-Windows-TerminalServices-Printers/Operational                                 0.06640625      1.00390625
Microsoft-Windows-TerminalServices-RDPClient/Operational                                0.06640625      1.00390625
Microsoft-Windows-TerminalServices-RemoteConnectionManager/Admin                        0.06640625      1.00390625
Microsoft-Windows-TerminalServices-RemoteConnectionManager/Operational                  0.06640625      1.00390625
Microsoft-Windows-TerminalServices-ServerUSBDevices/Admin                               0.06640625      1.00390625
Microsoft-Windows-TerminalServices-ServerUSBDevices/Operational                         0.06640625      1.00390625
Microsoft-Windows-Time-Service/Operational                                              1.00390625      1.00390625
Microsoft-Windows-Time-Service-PTP-Provider/PTP-Operational                             0.06640625      1.00390625
Microsoft-Windows-Troubleshooting-Recommended/Admin                                     0.06640625      1.00390625
Microsoft-Windows-Troubleshooting-Recommended/Operational                               0.06640625      1.00390625
Microsoft-Windows-TWinUI/Operational                                                    1.00390625      1.00390625
Microsoft-Windows-TZSync/Operational                                                    0.06640625      1.00390625
Microsoft-Windows-TZUtil/Operational                                                    0.06640625      1.00390625
Microsoft-Windows-UAC/Operational                                                       0.06640625      1.00390625
Microsoft-Windows-UAC-FileVirtualization/Operational                                    0.06640625      1.00390625
Microsoft-Windows-UniversalTelemetryClient/Operational                                  1.00390625      1.00390625
Microsoft-Windows-User Control Panel/Operational                                        0.06640625      1.00390625
Microsoft-Windows-User Device Registration/Admin                                        1.00390625      1.00390625
Microsoft-Windows-User Profile Service/Operational                                      1.06640625               4
Microsoft-Windows-User-Loader/Operational                                               0.06640625      1.00390625
Microsoft-Windows-UserPnp/ActionCenter                                                  0.06640625      1.00390625
Microsoft-Windows-UserPnp/DeviceInstall                                                 0.06640625      1.00390625
Microsoft-Windows-UserSettingsBackup-BackupUnitProcessor/Operational                    0.06640625      1.00390625
Microsoft-Windows-UserSettingsBackup-Orchestrator/Operational                           0.06640625      1.00390625
Microsoft-Windows-VDRVROOT/Operational                                                  0.06640625      1.00390625
Microsoft-Windows-VerifyHardwareSecurity/Admin                                          0.06640625      1.00390625
Microsoft-Windows-VerifyHardwareSecurity/Operational                                             0      1.00390625
Microsoft-Windows-VHDMP-Operational                                                     0.06640625      1.00390625
Microsoft-Windows-VIRTDISK/Operational                                                  0.06640625      1.00390625
Microsoft-Windows-Volume/Diagnostic                                                     0.06640625      1.00390625
Microsoft-Windows-VolumeSnapshot-Driver/Operational                                     1.00390625      1.00390625
Microsoft-Windows-VPN/Operational                                                       0.06640625      1.00390625
Microsoft-Windows-VPN-Client/Operational                                                0.06640625      1.00390625
Microsoft-Windows-Wcmsvc/Operational                                                    1.00390625      1.00390625
Microsoft-Windows-WDAG-PolicyEvaluator-CSP/Operational                                  0.06640625      1.00390625
Microsoft-Windows-WDAG-PolicyEvaluator-GP/Operational                                   0.06640625      1.00390625
Microsoft-Windows-WDAG-Service/Operational                                              0.06640625      1.00390625
Microsoft-Windows-WebAuth/Operational                                                            0      1.00390625
Microsoft-Windows-WebAuthN/Operational                                                  3.06640625               5
Microsoft-Windows-WebIO-NDF/Diagnostic                                                           0      1.00390625
Microsoft-Windows-WEPHOSTSVC/Operational                                                         0      1.00390625
Microsoft-Windows-WER-PayloadHealth/Operational                                         1.00390625      1.00390625
Microsoft-Windows-WFP/Operational                                                       0.06640625      1.00390625
Microsoft-Windows-Win32k/Operational                                                    0.06640625      1.00390625
Microsoft-Windows-Windows Defender/Operational                                         16.00390625      1.00390625
Microsoft-Windows-Windows Defender/WHC                                                  0.06640625      1.00390625
Microsoft-Windows-Windows Firewall With Advanced Security/ConnectionSecurity            0.06640625      1.00390625
Microsoft-Windows-Windows Firewall With Advanced Security/ConnectionSecurityVerbose              0      1.00390625
Microsoft-Windows-Windows Firewall With Advanced Security/Firewall                      1.00390625      1.00390625
Microsoft-Windows-Windows Firewall With Advanced Security/FirewallDiagnostics           0.06640625      1.00390625
Microsoft-Windows-Windows Firewall With Advanced Security/FirewallVerbose                        0      1.00390625
Microsoft-Windows-WindowsBackup/ActionCenter                                            0.06640625      1.00390625
Microsoft-Windows-WindowsColorSystem/Operational                                                 0      1.00390625
Microsoft-Windows-WindowsSystemAssessmentTool/Operational                               1.00390625      1.00390625
Microsoft-Windows-WindowsUIImmersive/Operational                                                 0      1.00390625
Microsoft-Windows-WindowsUpdateClient/Operational                                       1.00390625      1.00390625
Microsoft-Windows-WinHttp/Operational                                                   0.06640625      1.00390625
Microsoft-Windows-WinHTTP-NDF/Diagnostic                                                         0      1.00390625
Microsoft-Windows-WinINet/Operational                                                   0.06640625      1.00390625
Microsoft-Windows-WinINet-Capture/Analytic                                                       0      1.00390625
Microsoft-Windows-WinINet-Config/ProxyConfigChanged                                     0.06640625      1.00390625
Microsoft-Windows-Winlogon/Operational                                                  1.00390625      1.00390625
Microsoft-Windows-WinNat/Oper                                                                    0      1.00390625
Microsoft-Windows-WinRM/Operational                                                     1.00390625      1.00390625
Microsoft-Windows-Winsock-AFD/Operational                                                        0      1.00390625
Microsoft-Windows-Winsock-NameResolution/Operational                                             0      1.00390625
Microsoft-Windows-Winsock-WS2HELP/Operational                                           0.06640625      1.00390625
Microsoft-Windows-Wired-AutoConfig/Operational                                          0.06640625      1.00390625
Microsoft-Windows-WLAN-AutoConfig/Operational                                           0.06640625      1.00390625
Microsoft-Windows-wmbclass/Trace                                                                 0      1.00390625
Microsoft-Windows-WMI-Activity/Operational                                              1.00390625      1.00390625
Microsoft-Windows-WMPNSS-Service/Operational                                            0.06640625      1.00390625
Microsoft-Windows-Wordpad/Admin                                                                  0      1.00390625
Microsoft-Windows-WorkFolders/Operational                                               0.06640625      1.00390625
Microsoft-Windows-WorkFolders/WHC                                                       0.06640625      1.00390625
Microsoft-Windows-Workplace Join/Admin                                                  0.06640625      1.00390625
Microsoft-Windows-WPD-ClassInstaller/Operational                                        0.06640625      1.00390625
Microsoft-Windows-WPD-CompositeClassDriver/Operational                                  0.06640625      1.00390625
Microsoft-Windows-WPD-MTPClassDriver/Operational                                        0.06640625      1.00390625
Microsoft-Windows-WWAN-SVC-Events/Operational                                           0.06640625      1.00390625
Network Isolation Operational                                                                    0      1.00390625
OpenSSH/Admin                                                                           0.06640625      1.00390625
OpenSSH/Operational                                                                     0.06640625      1.00390625
Security                                                                               20.00390625              20
Setup                                                                                   1.00390625      1.00390625
SMSApi                                                                                  0.06640625      1.00390625
System                                                                                  1.06640625              20
Windows Networking Vpn Plugin Platform/Operational                                               0      1.00390625
Windows Networking Vpn Plugin Platform/OperationalVerbose                                        0      1.00390625
Windows PowerShell                                                                      1.06640625              15


PS C:\WINDOWS\system32> Get-WinEvent -ListLog Microsoft-Windows-Kernel-Boot/Operational | Select-Object LogName,@{Name="FileSizeMB"; Expression={$_.FileSize / 1MB}}, @{Name="MaxSizeMB"; Expression={$_.MaximumSizeInBytes / 1MB}}

LogName                                   FileSizeMB  MaxSizeMB
-------                                   ----------  ---------
Microsoft-Windows-Kernel-Boot/Operational 0.06640625 1.00390625


PS C:\WINDOWS\system32>
 

My Computer

System One

  • OS
    Windows 10
    Computer type
    Laptop
    Manufacturer/Model
    HP
    CPU
    Intel(R) Core(TM) i7-4800MQ CPU @ 2.70GHz
    Motherboard
    Product : 190A Version : KBC Version 94.56
    Memory
    16 GB Total: Manufacturer : Samsung MemoryType : DDR3 FormFactor : SODIMM Capacity : 8GB Speed : 1600
    Graphics Card(s)
    NVIDIA Quadro K3100M; Intel(R) HD Graphics 4600
    Sound Card
    IDT High Definition Audio CODEC; PNP Device ID HDAUDIO\FUNC_01&VEN_111D&DEV_76E0
    Hard Drives
    Model Hitachi HTS727575A9E364
    Antivirus
    Microsoft Defender
    Other Info
    Mobile Workstation
You'd have to check whether you have any "boot type" events. Here's another query which doesn't use the Id.
Code:
PS C:\Users\GARLIN> Get-WinEvent -ProviderName Microsoft-Windows-Kernel-boot | where-object { $_.Message -match 'boot type' }

   ProviderName: Microsoft-Windows-Kernel-Boot

TimeCreated                     Id LevelDisplayName Message
-----------                     -- ---------------- -------
3/12/2026 12:38:05 PM           27 Information      The boot type was 0x0.
3/12/2026 12:32:32 PM           27 Information      The boot type was 0x0.
3/11/2026 6:33:55 PM            27 Information      The boot type was 0x0.
3/11/2026 6:23:37 PM            27 Information      The boot type was 0x0.
1/13/2026 5:23:03 PM            27 Information      The boot type was 0x0.
1/13/2026 2:04:48 PM            27 Information      The boot type was 0x0.
1/13/2026 1:14:29 PM            27 Information      The boot type was 0x0.
1/13/2026 1:02:39 PM            27 Information      The boot type was 0x0.
 

My Computer

System One

  • OS
    Windows 7
The current and max had one or more with current > max

Microsoft-Windows-Windows Defender/Operational 16.00390625 1.00390625




Code:
PS C:\WINDOWS\system32> Get-WinEvent -ProviderName Microsoft-Windows-Kernel-boot | where-object { $_.Message -match 'boot type' }
PS C:\WINDOWS\system32>

It was empty/blank.
 

My Computer

System One

  • OS
    Windows 10
    Computer type
    Laptop
    Manufacturer/Model
    HP
    CPU
    Intel(R) Core(TM) i7-4800MQ CPU @ 2.70GHz
    Motherboard
    Product : 190A Version : KBC Version 94.56
    Memory
    16 GB Total: Manufacturer : Samsung MemoryType : DDR3 FormFactor : SODIMM Capacity : 8GB Speed : 1600
    Graphics Card(s)
    NVIDIA Quadro K3100M; Intel(R) HD Graphics 4600
    Sound Card
    IDT High Definition Audio CODEC; PNP Device ID HDAUDIO\FUNC_01&VEN_111D&DEV_76E0
    Hard Drives
    Model Hitachi HTS727575A9E364
    Antivirus
    Microsoft Defender
    Other Info
    Mobile Workstation
Either the system hasn't rebooted, or something has cleaned the logs. Some people want to tamper with system performance by disabling most of the event channels. Not saying in your case, but it's been known that some people do that.
 

My Computer

System One

  • OS
    Windows 7
Today is 03/25/26.

Code:
PS C:\WINDOWS\system32> (Get-CimInstance -ClassName Win32_OperatingSystem).LastBootUpTime

Tuesday, January 27, 2026 10:02:31 PM


PS C:\WINDOWS\system32>
 

My Computer

System One

  • OS
    Windows 10
    Computer type
    Laptop
    Manufacturer/Model
    HP
    CPU
    Intel(R) Core(TM) i7-4800MQ CPU @ 2.70GHz
    Motherboard
    Product : 190A Version : KBC Version 94.56
    Memory
    16 GB Total: Manufacturer : Samsung MemoryType : DDR3 FormFactor : SODIMM Capacity : 8GB Speed : 1600
    Graphics Card(s)
    NVIDIA Quadro K3100M; Intel(R) HD Graphics 4600
    Sound Card
    IDT High Definition Audio CODEC; PNP Device ID HDAUDIO\FUNC_01&VEN_111D&DEV_76E0
    Hard Drives
    Model Hitachi HTS727575A9E364
    Antivirus
    Microsoft Defender
    Other Info
    Mobile Workstation

Latest Support Threads

Back
Top Bottom