start_etw_trace
Initiate a kernel-level ETW trace session to capture Windows kernel events for diagnostics and troubleshooting.
Instructions
Start a kernel ETW trace via logman (requires elevation). providers are Microsoft-Windows-Kernel-* names or GUID strings.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| session_name | Yes | Trace session name | |
| providers | No | ||
| output_dir | No | Directory for ETL output |