Foundations
Diagnostics & logging
Where Windows records what happened — turning 'it's acting weird' into an actual, inspectable trail of evidence.
Every level in this course describes a mechanism operating correctly. Real troubleshooting starts from the opposite direction: something went wrong, and you need evidence, not theory, to figure out what. This is the diagnostics toolkit — a cross-cutting track, not a layer of the OS itself, because these tools observe every level above rather than belonging to any one of them.
Different tools for different diagnostic goals
Windows doesn't have one universal logging mechanism — it has several, deliberately shaped for different needs:
- The Event Log (covered next) — durable, structured history: what happened, when, recorded to disk in a form you can review long after the fact.
- ETW (ETW tracing) — high-volume, real-time tracing, built for capturing far more detail than durable logging could reasonably persist, at the cost of generally not being kept around indefinitely.
- WMI (WMI & CIM) — a management and instrumentation layer for querying current system state (what's running right now, what a service's configuration is right now), rather than historical events.
Why "Event Log" and "ETW" aren't the same thing
A specific, common point of confusion worth resolving early: Event Log and ETW are related — the Event Log service is, in fact, built on ETW infrastructure underneath — but they answer different questions. Event Log is curated, durable history: a relatively small set of significant events, kept around specifically so you can review them well after they occurred. ETW is a much higher-volume, configurable tracing bus, capable of capturing vastly more detail (near every function call in a hot path, if a provider is configured to emit that much), but generally consumed live or captured to a trace file for near-term analysis, not treated as permanent history the way Event Log records are.
A worked example: troubleshooting a failed login or a driver issue
A practical, representative diagnostic path: start with the Event Log for durable, already-recorded history — did something log an explicit failure around the time in question? If that's not enough resolution — if you need to see the precise sequence and timing of what happened, not just a summary record — ETW is the next step, letting you capture a live, high-resolution trace of exactly what occurred, in what order, and how long each step took. Event Log tells you that something happened; ETW can tell you how, moment by moment.
A common mistake
Treating every Windows diagnostic question as solvable through Event Log alone undersells what ETW specifically exists for — sequence, timing, and volume that durable event logging was never designed to capture. Equally, assuming ETW is "just another kind of log file" misses that it's a fundamentally different, configurable tracing mechanism with real tradeoffs around retention and performance that ordinary logging doesn't have to make.
Where this connects
- The Windows Event Log covers the durable-history side of this toolkit in full, including the on-disk EVTX format.
- Every level in this course — processes, memory, security, networking — is something these tools can be pointed at to observe directly, rather than reasoning about only in theory.