This shows you the differences between two versions of the page.
Both sides previous revisionPrevious revisionNext revision | Previous revision | ||
ms:win:trace [2019/11/04 15:29] – js | ms:win:trace [2019/11/04 15:39] (current) – js | ||
---|---|---|---|
Line 1: | Line 1: | ||
====== trace with netsh ====== | ====== trace with netsh ====== | ||
- | < | + | < |
+ | |||
+ | You have to load the etl file to " | ||
+ | |||
+ | On the website [[http:// | ||
+ | |||
+ | I found the following powershell code to convert it: | ||
+ | <code powershell> | ||
+ | $s | Add-PefMessageProvider -Provider “C: | ||
+ | $s | Start-PefTraceSession</ | ||
+ | |||
+ | < | ||
You can make it persistent, e.g. if you want to capture the boot: | You can make it persistent, e.g. if you want to capture the boot: | ||
Line 8: | Line 19: | ||
To stop enter | To stop enter | ||
< | < | ||
+ | |||
+ | Capture ICMP traffic: | ||
+ | < | ||
+ | |||
+ | More information: |