This thread's last reply is from May 18, 2017, 3:36 AM UTC. Software, malware, and removal-tool
advice below may be out of date — treat specific steps and download links with caution.
No issue other than the fact that when I tried to click on the Please go HERE link in your post to the eset online scanner link, my browser converted it to some other site.
Thank you for this information - we will work against it.
You didn't say to clean the threats so I didn't.
Very well!
Step 1. Search using FRST64
Double click Frst64.exe to launch it. FRST will start to run.
When the tool opens click Yes to the disclaimer.
Copy/Paste the following line into the Search: box.
When finished searching a log will open on your Desktop ... SearchReg.txt
Please post it in your next reply.
Step 2. TDSSKiller - Rootkit Removal Tool
Please download the TDSSKiller.exe by Kaspersky... save it to your Desktop. <-Important!!!
Right-click on TDSSKiller.exe and select "Run As Administrator...".
If TDSSKiller does not run... rename it. Right-click on TDSSKiller.exe, select Rename and give it a random name with the .com file extension (i.e. ektfhtw.com).
If you don't see file extensions, please see: How to change the file extension.
Click the Start Scan button. Do not use the computer during the scan!
Click Change parameters
Under Additional Options CHECKVerify file digital signatures
IMPORTANT: Ensure Detect TDLFS file system remains UNCHECKED.
Click OK if changes were made.
Click Start scan and allow it to scan for Malicious objects.
If Malicious objects are detected, the default action will be Cure, ensure SKIP is selected... then click Continue
If suspicious objects are detected, the default action will be Skip, ensure Skip is selected... then click Continue
If Unsigned files are detected, the default action will be Skip, ensure Skip is selected... then click Continue
DO NOT change the default actions, other than CURE to SKIP.
You may be asked to reboot the computer to complete the process. Click on Reboot Now and allow the computer to reboot.
A log will be created on your root drive (usually C:) drive. The log will have a name like Name.Version_Date_Time_log.txt.
for example, C:\TDSSKiller.2.4.1.2_20.04.2010_15.31.43_log.txt.
If no reboot is required, click on Report. A log file should appear.
Please post the contents of the log file in your next reply
Please post each log separately to prevent it being cut off by the forum post size limiter.
Check each after you've posted it to make sure it's all present, if any log is cut off you'll have to post it in sections....
Please include in your next reply:
Do you have any problems executing the instructions?
Contents of the SearchReg.txt file
Contents of the TDSSKiller_version_dd.mm.yyyy_hh.mm.ss_log.txt log file
Do you see any changes in computer behavior?
Thanks,
pgmigg
Failure to post replies within 72 hours will result in this thread being closed
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Installer\Components\8F622368F04F7B849A7B2021EE668F21]
"1033\PaymentType.accft"="zn=BVJ(8A$4!!!!MKKSkAccessTemplatesIntl_1033>Y)0pQJQZq?U(,Zb1u9Yv
[HKEY_USERS\S-1-5-21-914517813-2310829996-1314125057-1000\SOFTWARE\Adobe\Acrobat Distiller\PrinterJobControl]
"C:\Users\Doug\Dropbox\Tax Info\2017\Reminder Enter State Tax Payment for 2017 Taxes.pdf"="6"
24792
Max Request Processing Time
24794
iSCSI Sessions
24796
Bytes Received
24798
Bytes Sent
24800
ConnectionTimeout Errors
24802
Digest Errors
24804
Format Errors
24806
PDUs Sent
24808
PDUs Received
24810
Processor Performance
24812
Processor Frequency
24814
% of Maximum Frequency
24816
Processor State Flags
24818
WMI Objects
24820
HiPerf Classes
24822
HiPerf Validity
24824
iSCSI Connections
24826
Bytes Received
24828
Bytes Sent
24830
PDUs Sent
24832
PDUs Received
24834
iSCSI Initiator Instance
24836
Session Cxn Timeout Errors
24838
Session Digest Errors
24840
Sessions Failed
24842
Session Format Errors
24844
iSCSI Initiator Login statistics
24846
Login Accept Responses
24848
Logins Failed
24850
Login Authentication Failed Responses
24852
Failed Logins
24854
Login Negotiation Failed
24856
Login Other Failed Responses
24858
Login Redirect Responses
24860
Logout Normal
24862
Logout Other Codes
24864
iSCSI HBA Main Mode IPSEC Statistics
24866
AcquireFailures
24868
AcquireHeapSize
24870
ActiveAcquire
24872
ActiveReceive
24874
AuthenticationFailures
24876
ConnectionListSize
24878
GetSPIFailures
24880
InvalidCookiesReceived
24882
InvalidPackets
24884
KeyAdditionFailures
24886
KeyAdditions
24888
KeyUpdateFailures
24890
KeyUpdates
24892
NegotiationFailures
24894
OakleyMainMode
24896
OakleyQuickMode
24898
ReceiveFailures
24900
ReceiveHeapSize
24902
SendFailures
24904
SoftAssociations
24906
TotalGetSPI
24908
MSiSCSI_NICPerformance
24910
BytesReceived
24912
BytesTransmitted
24914
PDUReceived
24916
PDUTransmitted
24918
iSCSI HBA Quick Mode IPSEC Statistics
24920
ActiveSA
24922
ActiveTunnels
24924
AuthenticatedBytesReceived
24926
AuthenticatedBytesSent
24928
BadSPIPackets
24930
ConfidentialBytesReceived
24932
ConfidentialBytesSent
24934
KeyAdditions
24936
KeyDeletions
24938
PacketsNotAuthenticated
24940
PacketsNotDecrypted
24942
PacketsWithReplayDetection
24944
PendingKeyOperations
24946
ReKeys
24948
TransportBytesReceived
24950
TransportBytesSent
24952
TunnelBytesReceived
24954
TunnelBytesSent
24956
iSCSI Request Processing Time
24958
Average Request Processing Time
24960
Max Request Processing Time
24962
iSCSI Sessions
24964
Bytes Received
24966
Bytes Sent
24968
ConnectionTimeout Errors
24970
Digest Errors
24972
Format Errors
24974
PDUs Sent
24976
PDUs Received
24978
Processor Performance
24980
Processor Frequency
24982
% of Maximum Frequency
24984
Processor State Flags
7428
RemoteFX Synth3D VSC VM Transport Channel
7430
Number of space available signals received
7432
Number of space available signals received per second
7434
Number of data available signals received
7436
Number of data available signals received per second
7438
Number of space available signals sent
7440
Number of space available signals sent per second
7442
Number of data available signals sent
7444
Number of data available signals sent per second
7446
Number of data available event was reset
7448
Number of data available event was reset per second
7450
Number of space available event was reset
7452
Number of space available event was reset per second
7414
RemoteFX Synth3D VSC VM Device
7416
Number of created VMT channels
7418
Number of waiting VMT channels
7420
Number of connected VMT channels
7422
Number of disconnected VMT channels
7424
Total number of created VMT channels
7426
Number of RDVGM restarted notifications
7336
WorkflowServiceHost 4.0.0.0
7338
Workflows Created
7340
Workflows Created Per Second
7342
Workflows Executing
7344
Workflows Completed
7346
Workflows Completed Per Second
7348
Workflows Aborted
7350
Workflows Aborted Per Second
7352
Workflows In Memory
7354
Workflows Persisted
7356
Workflows Persisted Per Second
7358
Workflows Terminated
7360
Workflows Terminated Per Second
7362
Workflows Loaded
7364
Workflows Loaded Per Second
7366
Workflows Unloaded
7368
Workflows Unloaded Per Second
7370
Workflows Suspended
7372
Workflows Suspended Per Second
7374
Workflows Idle Per Second
7376
Average Workflow Load Time
7378
Average Workflow Load Time Base
7380
Average Workflow Persist Time
7382
Average Workflow Persist Time Base
2038
Terminal Services
2040
Active Sessions
2042
Inactive Sessions
2044
Total Sessions
6634
Hyper-V Hypervisor Logical Processor
6636
Global Time
6638
Total Run Time
6640
Hypervisor Run Time
6642
Hardware Interrupts/sec
6644
Context Switches/sec
6646
Inter-Processor Interrupts/sec
6648
Scheduler Interrupts/sec
6650
Timer Interrupts/sec
6652
Inter-Processor Interrupts Sent/sec
6654
Processor Halts/sec
6656
Monitor Transition Cost
6658
Context Switch Time
6660
C1 Transitions/sec
6662
% C1 Time
6664
C2 Transitions/sec
6666
% C2 Time
6668
C3 Transitions/sec
6670
% C3 Time
6672
Frequency
6674
% of Max Frequency
6676
Parking Status
6678
Processor State Flags
6680
Root Vp Index
6682
Idle Sequence Number
6684
Global TSC Count
6686
Active TSC Count
6688
Idle Accumulation
6690
Reference Cycle Count 0
6692
Actual Cycle Count 0
6694
Reference Cycle Count 1
6696
Actual Cycle Count 1
6698
Proximity Domain Id
6700
Guest Run Time
6702
Idle Time
6704
% Total Run Time
6706
% Hypervisor Run Time
6708
% Guest Run Time
6710
% Idle Time
6712
Total Interrupts/sec
6616
Hyper-V Hypervisor
6618
Logical Processors
6620
Partitions
6622
Total Pages
6624
Virtual Processors
6626
Monitored Notifications
6628
Modern Standby Entries
6630
Platform Idle Transitions
6632
HypervisorStartupCost
6714
Hyper-V Hypervisor Root Partition
6716
Virtual Processors
6718
Virtual TLB Pages
6720
Address Spaces
6722
Deposited Pages
6724
GPA Pages
6726
GPA Space Modifications/sec
6728
Virtual TLB Flush Entires/sec
6730
Recommended Virtual TLB Size
6732
4K GPA pages
6734
2M GPA pages
6736
1G GPA pages
6738
512G GPA pages
6740
4K device pages
6742
2M device pages
6744
1G device pages
6746
512G device pages
6748
Attached Devices
6750
Device Interrupt Mappings
6752
I/O TLB Flushes/sec
6754
I/O TLB Flush Cost
6756
Device Interrupt Errors
6758
Device DMA Errors
6760
Device Interrupt Throttle Events
6762
Skipped Timer Ticks
6764
Partition Id
6766
Nested TLB Size
6768
Recommended Nested TLB Size
6770
Nested TLB Free List Size
6772
Nested TLB Trimmed Pages/sec
6774
I/O TLB Flushes Base
6776
Hyper-V Hypervisor Root Virtual Processor
6778
Total Run Time
6780
Hypervisor Run Time
6782
Remote Node Run Time
6784
Normalized Run Time
6786
Hypercalls/sec
6788
Hypercalls Cost
6790
Page Invalidations/sec
6792
Page Invalidations Cost
6794
Control Register Accesses/sec
6796
Control Register Accesses Cost
6798
IO Instructions/sec
6800
IO Instructions Cost
6802
HLT Instructions/sec
6804
HLT Instructions Cost
6806
MWAIT Instructions/sec
6808
MWAIT Instructions Cost
6810
CPUID Instructions/sec
6812
CPUID Instructions Cost
6814
MSR Accesses/sec
6816
MSR Accesses Cost
6818
Other Intercepts/sec
6820
Other Intercepts Cost
6822
External Interrupts/sec
6824
External Interrupts Cost
6826
Pending Interrupts/sec
6828
Pending Interrupts Cost
6830
Emulated Instructions/sec
6832
Emulated Instructions Cost
6834
Debug Register Accesses/sec
6836
Debug Register Accesses Cost
6838
Page Fault Intercepts/sec
6840
Page Fault Intercepts Cost
6842
Guest Page Table Maps/sec
6844
Large Page TLB Fills/sec
6846
Small Page TLB Fills/sec
6848
Reflected Guest Page Faults/sec
6850
APIC MMIO Accesses/sec
6852
IO Intercept Messages/sec
6854
Memory Intercept Messages/sec
6856
APIC EOI Accesses/sec
6858
Other Messages/sec
6860
Page Table Allocations/sec
6862
Logical Processor Migrations/sec
6864
Address Space Evictions/sec
6866
Address Space Switches/sec
6868
Address Domain Flushes/sec
6870
Address Space Flushes/sec
6872
Global GVA Range Flushes/sec
6874
Local Flushed GVA Ranges/sec
6876
Page Table Evictions/sec
6878
Page Table Reclamations/sec
6880
Page Table Resets/sec
6882
Page Table Validations/sec
6884
APIC TPR Accesses/sec
6886
Page Table Write Intercepts/sec
6888
Synthetic Interrupts/sec
6890
Virtual Interrupts/sec
6892
APIC IPIs Sent/sec
6894
APIC Self IPIs Sent/sec
6896
GPA Space Hypercalls/sec
6898
Logical Processor Hypercalls/sec
6900
Long Spin Wait Hypercalls/sec
6902
Other Hypercalls/sec
6904
Synthetic Interrupt Hypercalls/sec
6906
Virtual Interrupt Hypercalls/sec
6908
Virtual MMU Hypercalls/sec
6910
Virtual Processor Hypercalls/sec
6912
Hardware Interrupts/sec
6914
Nested Page Fault Intercepts/sec
6916
Nested Page Fault Intercepts Cost
6918
Logical Processor Dispatches/sec
6920
CPU Wait Time Per Dispatch
6922
Extended Hypercalls/sec
6924
Extended Hypercall Intercept Messages/sec
6926
MBEC Nested Page Table Switches/sec
6928
Other Reflected Guest Exceptions/sec
6930
Global I/O TLB Flushes/sec
6932
Global I/O TLB Flush Cost
6934
Local I/O TLB Flushes/sec
6936
Local I/O TLB Flush Cost
6938
Hypercalls Forwarded/sec
6940
Hypercalls Forwarding Cost
6942
Page Invalidations Forwarded/sec
6944
Page Invalidations Forwarding Cost
6946
Control Register Accesses Forwarded/sec
6948
Control Register Accesses Forwarding Cost
6950
IO Instructions Forwarded/sec
6952
IO Instructions Forwarding Cost
6954
HLT Instructions Forwarded/sec
6956
HLT Instructions Forwarding Cost
6958
MWAIT Instructions Forwarded/sec
6960
MWAIT Instructions Forwarding Cost
6962
CPUID Instructions Forwarded/sec
6964
CPUID Instructions Forwarding Cost
6966
MSR Accesses Forwarded/sec
6968
MSR Accesses Forwarding Cost
6970
Other Intercepts Forwarded/sec
6972
Other Intercepts Forwarding Cost
6974
External Interrupts Forwarded/sec
6976
External Interrupts Forwarding Cost
6978
Pending Interrupts Forwarded/sec
6980
Pending Interrupts Forwarding Cost
6982
Emulated Instructions Forwarded/sec
6984
Emulated Instructions Forwarding Cost
6986
Debug Register Accesses Forwarded/sec
6988
Debug Register Accesses Forwarding Cost
6990
Page Fault Intercepts Forwarded/sec
6992
Page Fault Intercepts Forwarding Cost
6994
VMCLEAR Emulation Intercepts/sec
6996
VMCLEAR Instruction Emulation Cost
6998
VMPTRLD Emulation Intercepts/sec
7000
VMPTRLD Instruction Emulation Cost
7002
VMPTRST Emulation Intercepts/sec
7004
VMPTRST Instruction Emulation Cost
7006
VMREAD Emulation Intercepts/sec
7008
VMREAD Instruction Emulation Cost
7010
VMWRITE Emulation Intercepts/sec
7012
VMWRITE Instruction Emulation Cost
7014
VMXOFF Emulation Intercepts/sec
7016
VMXOFF Instruction Emulation Cost
7018
VMXON Emulation Intercepts/sec
7020
VMXON Instruction Emulation Cost
7022
Nested VM Entries/sec
7024
Nested VM Entries Cost
7026
Nested SLAT Soft Page Faults/sec
7028
Nested SLAT Soft Page Faults Cost
7030
Nested SLAT Hard Page Faults/sec
7032
Nested SLAT Hard Page Faults Cost
7034
InvEpt All Context Emulation Intercepts/sec
7036
InvEpt All Context Instruction Emulation Cost
7038
InvEpt Single Context Emulation Intercepts/sec
7040
InvEpt Single Context Instruction Emulation Cost
7042
InvVpid All Context Emulation Intercepts/sec
7044
InvVpid All Context Instruction Emulation Cost
7046
InvVpid Single Context Emulation Intercepts/sec
7048
InvVpid Single Context Instruction Emulation Cost
7050
InvVpid Single Address Emulation Intercepts/sec
7052
InvVpid Single Address Instruction Emulation Cost
7054
Nested TLB Page Table Reclamations/sec
7056
Nested TLB Page Table Evictions/sec
7058
Flush Physical Address Space Hypercalls/sec
7060
Flush Physical Address List Hypercalls/sec
7062
Guest Run Time
7064
% Total Run Time
7066
% Hypervisor Run Time
7068
% Guest Run Time
7070
Total Messages/sec
7072
Total Intercepts Base
7074
Total Intercepts/sec
7076
Total Intercepts Cost
7078
% Remote Run Time
7080
Total Virtualization Instructions Emulated Base
7082
Total Virtualization Instructions Emulated/sec
7084
Total Virtualization Instructions Emulation Cost
7086
Global Reference Time
7088
Hypercalls Base
7090
Page Invalidations Base
7092
Control Register Accesses Base
7094
IO Instructions Base
7096
HLT Instructions Base
7098
MWAIT Instructions Base
7100
CPUID Instructions Base
7102
MSR Accesses Base
7104
Other Intercepts Base
7106
External Interrupts Base
7108
Pending Interrupts Base
7110
Emulated Instructions Base
7112
Debug Register Accesses Base
7114
Page Fault Intercepts Base
7116
Nested Page Fault Intercepts Base
7118
Logical Processor Dispatches Base
7120
Global I/O TLB Flushes Base
7122
Local I/O TLB Flushes Base
7124
Hypercalls Forwarded Base
7126
Page Invalidations Forwarded Base
7128
Control Register Accesses Forwarded Base
7130
IO Instructions Forwarded Base
7132
HLT Instructions Forwarded Base
7134
MWAIT Instructions Forwarded Base
7136
CPUID Instructions Forwarded Base
7138
MSR Accesses Forwarded Base
7140
Other Intercepts Forwarded Base
7142
External Interrupts Forwarded Base
7144
Pending Interrupts Forwarded Base
7146
Emulated Instructions Forwarded Base
7148
Debug Register Accesses Forwarded Base
7150
Page Fault Intercepts Forwarded Base
7152
VMCLEAR Emulation Intercepts Base
7154
VMPTRLD Emulation Intercepts Base
7156
VMPTRST Emulation Intercepts Base
7158
VMREAD Emulation Intercepts Base
7160
VMWRITE Emulation Intercepts Base
7162
VMXOFF Emulation Intercepts Base
7164
VMXON Emulation Intercepts Base
7166
Nested VM Entries Base
7168
Nested SLAT Soft Page Faults Base
7170
Nested SLAT Hard Page Faults Base
7172
InvEpt All Context Emulation Intercepts Base
7174
InvEpt Single Context Emulation Intercepts Base
7176
InvVpid All Context Emulation Intercepts Base
7178
InvVpid Single Context Emulation Intercepts Base
7180
InvVpid Single Address Emulation Intercepts Base
5174
Pacer Flow
5176
Packets dropped
5178
Packets scheduled
5180
Packets transmitted
5182
Bytes scheduled
5184
Bytes transmitted
5186
Bytes transmitted/sec
5188
Bytes scheduled/sec
5190
Packets transmitted/sec
5192
Packets scheduled/sec
5194
Packets dropped/sec
5196
Nonconforming packets scheduled
5198
Nonconforming packets scheduled/sec
5200
Average packets in shaper
5202
Max packets in shaper
5204
Average packets in sequencer
5206
Max packets in sequencer
5208
Maximum packets in netcard
5210
Average packets in netcard
5212
Nonconforming packets transmitted
5214
Nonconforming packets transmitted/sec
5216
Pacer Pipe
5218
Out of packets
5220
Flows opened
5222
Flows closed
5224
Flows rejected
5226
Flows modified
5228
Flow mods rejected
5230
Max simultaneous flows
5232
Nonconforming packets scheduled
5234
Nonconforming packets scheduled/sec
5236
Average packets in shaper
5238
Max packets in shaper
5240
Average packets in sequencer
5242
Max packets in sequencer
5244
Max packets in netcard
5246
Average packets in netcard
5248
Nonconforming packets transmitted
5250
Nonconforming packets transmitted/sec
7968
Generic IKEv1, AuthIP, and IKEv2
7970
IKEv1 Main Mode Negotiation Time
7972
AuthIP Main Mode Negotiation Time
7974
IKEv1 Quick Mode Negotiation Time
7976
AuthIP Quick Mode Negotiation Time
7978
Extended Mode Negotiation Time
7980
Packets Received/sec
7982
Invalid Packets Received/sec
7984
Successful Negotiations
7986
Successful Negotiations/sec
7988
Failed Negotiations
7990
Failed Negotiations/sec
7992
IKEv2 Main Mode Negotiation Time
7994
IKEv2 Quick Mode Negotiation Time
7996
IPsec IKEv2 IPv4
7998
Active Main Mode SAs
8000
Pending Main Mode Negotiations
8002
Main Mode Negotiations
8004
Main Mode Negotiations/sec
8006
Successful Main Mode Negotiations
8008
Successful Main Mode Negotiations/sec
8010
Failed Main Mode Negotiations
8012
Failed Main Mode Negotiations/sec
8014
Main Mode Negotiation Requests Received
8016
Main Mode Negotiation Requests Received/sec
8018
Active Quick Mode SAs
8020
Pending Quick Mode Negotiations
8022
Quick Mode Negotiations
8024
Quick Mode Negotiations/sec
8026
Successful Quick Mode Negotiations
8028
Successful Quick Mode Negotiations/sec
8030
Failed Quick Mode Negotiations
8032
Failed Quick Mode Negotiations/sec
7848
IPsec AuthIP IPv4
7850
Active Main Mode SAs
7852
Pending Main Mode Negotiations
7854
Main Mode Negotiations
7856
Main Mode Negotiations/sec
7858
Successful Main Mode Negotiations
7860
Successful Main Mode Negotiations/sec
7862
Failed Main Mode Negotiations
7864
Failed Main Mode Negotiations/sec
7866
Main Mode Negotiation Requests Received
7868
Main Mode Negotiation Requests Received/sec
7870
Main Mode SAs That Used Impersonation
7872
Main Mode SAs That Used Impersonation/sec
7874
Active Quick Mode SAs
7876
Pending Quick Mode Negotiations
7878
Quick Mode Negotiations
7880
Quick Mode Negotiations/sec
7882
Successful Quick Mode Negotiations
7884
Successful Quick Mode Negotiations/sec
7886
Failed Quick Mode Negotiations
7888
Failed Quick Mode Negotiations/sec
7890
Active Extended Mode SAs
7892
Pending Extended Mode Negotiations
7894
Extended Mode Negotiations
7896
Extended Mode Negotiations/sec
7898
Successful Extended Mode Negotiations
7900
Successful Extended Mode Negotiations/sec
7902
Failed Extended Mode Negotiations
7904
Failed Extended Mode Negotiations/sec
7906
Extended Mode SAs That Used Impersonation
8072
IPsec Connections
8074
Total Number current Connections
8076
Total number of cumulative connections since boot
8078
Max number of connections since boot
8080
Total Bytes In since start
8082
Total Bytes Out since start
8084
Number of failed authentications
7908
IPsec AuthIP IPv6
7910
Active Main Mode SAs
7912
Pending Main Mode Negotiations
7914
Main Mode Negotiations
7916
Main Mode Negotiations/sec
7918
Successful Main Mode Negotiations
7920
Successful Main Mode Negotiations/sec
7922
Failed Main Mode Negotiations
7924
Failed Main Mode Negotiations/sec
7926
Main Mode Negotiation Requests Received
7928
Main Mode Negotiation Requests Received/sec
7930
Main Mode SAs That Used Impersonation
7932
Main Mode SAs That Used Impersonation/sec
7934
Active Quick Mode SAs
7936
Pending Quick Mode Negotiations
7938
Quick Mode Negotiations
7940
Quick Mode Negotiations/sec
7942
Successful Quick Mode Negotiations
7944
Successful Quick Mode Negotiations/sec
7946
Failed Quick Mode Negotiations
7948
Failed Quick Mode Negotiations/sec
7950
Active Extended Mode SAs
7952
Pending Extended Mode Negotiations
7954
Extended Mode Negotiations
7956
Extended Mode Negotiations/sec
7958
Successful Extended Mode Negotiations
7960
Successful Extended Mode Negotiations/sec
7962
Failed Extended Mode Negotiations
7964
Failed Extended Mode Negotiations/sec
7966
Extended Mode SAs That Used Impersonation
8034
IPsec IKEv2 IPv6
8036
Active Main Mode SAs
8038
Pending Main Mode Negotiations
8040
Main Mode Negotiations
8042
Main Mode Negotiations/sec
8044
Successful Main Mode Negotiations
8046
Successful Main Mode Negotiations/sec
8048
Failed Main Mode Negotiations
8050
Failed Main Mode Negotiations/sec
8052
Main Mode Negotiation Requests Received
8054
Main Mode Negotiation Requests Received/sec
8056
Active Quick Mode SAs
8058
Pending Quick Mode Negotiations
8060
Quick Mode Negotiations
8062
Quick Mode Negotiations/sec
8064
Successful Quick Mode Negotiations
8066
Successful Quick Mode Negotiations/sec
8068
Failed Quick Mode Negotiations
8070
Failed Quick Mode Negotiations/sec
7648
WFPv4
7650
Inbound Packets Discarded/sec
7652
Outbound Packets Discarded/sec
7654
Packets Discarded/sec
7656
Blocked Binds
7658
Inbound Connections Blocked/sec
7660
Outbound Connections Blocked/sec
7662
Inbound Connections Allowed/sec
7664
Outbound Connections Allowed/sec
7666
Inbound Connections
7668
Outbound Connections
7670
Active Inbound Connections
7672
Active Outbound Connections
7674
Allowed Classifies/sec
7772
IPsec IKEv1 IPv4
7774
Active Main Mode SAs
7776
Pending Main Mode Negotiations
7778
Main Mode Negotiations
7780
Main Mode Negotiations/sec
7782
Successful Main Mode Negotiations
7784
Successful Main Mode Negotiations/sec
7786
Failed Main Mode Negotiations
7788
Failed Main Mode Negotiations/sec
7790
Main Mode Negotiation Requests Received
7792
Main Mode Negotiation Requests Received/sec
7794
Active Quick Mode SAs
7796
Pending Quick Mode Negotiations
7798
Quick Mode Negotiations
7800
Quick Mode Negotiations/sec
7802
Successful Quick Mode Negotiations
7804
Successful Quick Mode Negotiations/sec
7806
Failed Quick Mode Negotiations
7808
Failed Quick Mode Negotiations/sec
7810
IPsec IKEv1 IPv6
7812
Active Main Mode SAs
7814
Pending Main Mode Negotiations
7816
Main Mode Negotiations
7818
Main Mode Negotiations/sec
7820
Successful Main Mode Negotiations
7822
Successful Main Mode Negotiations/sec
7824
Failed Main Mode Negotiations
7826
Failed Main Mode Negotiations/sec
7828
Main Mode Negotiation Requests Received
7830
Main Mode Negotiation Requests Received/sec
7832
Active Quick Mode SAs
7834
Pending Quick Mode Negotiations
7836
Quick Mode Negotiations
7838
Quick Mode Negotiations/sec
7840
Successful Quick Mode Negotiations
7842
Successful Quick Mode Negotiations/sec
7844
Failed Quick Mode Negotiations
7846
Failed Quick Mode Negotiations/sec
7708
IPsec Driver
7710
Active Security Associations
7712
Pending Security Associations
7714
Incorrect SPI Packets
7716
Incorrect SPI Packets/sec
7718
Bytes Received in Tunnel Mode/sec
7720
Bytes Sent in Tunnel Mode/sec
7722
Bytes Received in Transport Mode/sec
7724
Bytes Sent in Transport Mode/sec
7726
Offloaded Security Associations
7728
Offloaded Bytes Received/sec
7730
Offloaded Bytes Sent/sec
7732
Packets That Failed Replay Detection
7734
Packets That Failed Replay Detection/sec
7736
Packets Not Authenticated
7738
Packets Not Authenticated/sec
7740
Packets Not Decrypted
7742
Packets Not Decrypted/sec
7744
SA Rekeys
7746
Security Associations Added
7748
Packets That Failed ESP Validation
7750
Packets That Failed ESP Validation/sec
7752
Packets That Failed UDP-ESP Validation
7754
Packets That Failed UDP-ESP Validation/sec
7756
Packets Received Over Wrong SA
7758
Packets Received Over Wrong SA/sec
7760
Plaintext Packets Received
7762
Plaintext Packets Received/sec
7764
Total Inbound Packets Received
7766
Inbound Packets Received/sec
7768
Total Inbound Packets Dropped
7770
Inbound Packets Dropped/sec
7704
WFP
7706
Provider Count
7676
WFPv6
7678
Inbound Packets Discarded/sec
7680
Outbound Packets Discarded/sec
7682
Packets Discarded/sec
7684
Blocked Binds
7686
Inbound Connections Blocked/sec
7688
Outbound Connections Blocked/sec
7690
Inbound Connections Allowed/sec
7692
Outbound Connections Allowed/sec
7694
Inbound Connections
7696
Outbound Connections
7698
Active Inbound Connections
7700
Active Outbound Connections
7702
Allowed Classifies/sec
8086
Peer Name Resolution Protocol
8088
Registration
8090
Resolve
8092
Cache Entry
8094
Average bytes sent
8096
Average bytes received
8098
Estimated cloud size
8100
Stale cache entry
8102
Send failures
8104
Receive failures
8106
Solicit sent per second
8108
Solicit received per second
8110
Advertise sent per second
8112
Advertise received per second
8114
Request sent per second
8116
Request received per second
8118
Flood sent per second
8120
Flood received per second
8122
Inquire sent per second
8124
Inquire received per second
8126
Authority sent per second
8128
Authority received per second
8130
Ack sent per second
8132
Ack received per second
8134
Lookup sent per second
8136
Lookup received per second
8138
Unknown message type received
4290
Authorization Manager Applications
4292
Total number of scopes
4294
Number of Scopes loaded in memory
4756
Fax Service
4758
Total minutes sending and receiving
4760
Total pages
4762
Total faxes sent and received
4764
Total bytes
4766
Failed faxes transmissions
4768
Failed outgoing connections
4770
Minutes sending
4772
Pages sent
4774
Faxes sent
4776
Bytes sent
4778
Failed receptions
4780
Minutes receiving
4782
Received pages
4784
Received faxes
4786
Bytes received
6098
Microsoft Winsock BSP
6100
Dropped Datagrams/sec
6102
Dropped Datagrams
6104
Rejected Connections/sec
6106
Rejected Connections
4680
BitLocker
4682
Min Read Split Size
4684
Max Read Split Size
4686
Min Write Split Size
4688
Max Write Split Size
4690
Read Requests/sec
4692
Read Subrequests/sec
4694
Write Requests/sec
4696
Write Subrequests/sec
13414
Storage Spaces Virtual Disk
13416
Virtual Disk Active
13418
Virtual Disk Active Bytes
13420
Virtual Disk Missing
13422
Virtual Disk Missing Bytes
13424
Virtual Disk Stale
13426
Virtual Disk Stale Bytes
13428
Virtual Disk Need Reallocation
13430
Virtual Disk Need Reallocation Bytes
13432
Virtual Disk Need Regeneration
13434
Virtual Disk Need Regeneration Bytes
13436
Virtual Disk Regenerating
13438
Virtual Disk Regenerating Bytes
13440
Virtual Disk Pending Deletion
13442
Virtual Disk Pending Deletion Bytes
13444
Virtual Disk Total
13446
Virtual Disk Total Bytes
13488
Storage Spaces Write Cache
13490
Cache Writes/sec
13492
Cache Write Bytes/sec
13494
Avg. Cache Bytes/Write
13496
Cache Overwrites/sec
13498
Cache Overwrite Bytes/sec
13500
Avg. Cache Bytes/Overwrite
13502
Cache Evicts/sec
13504
Cache Evict Bytes/sec
13506
Avg. Cache Bytes/Evict
13508
Current Destage Queue Length
13510
Destage Operations/sec
13512
Avg. Destage sec/Operation
13514
Avg. Destage Queue Length
13516
Destage Optimized Operations/sec
13518
Destage Evicts/sec
13520
Avg. Destage Evicts/Operation
13522
Destage Evict Bytes/sec
13524
Avg. Destage Bytes/Evict
13526
Avg. Destage Evict Bytes/Operation
13528
Destage Transfers/sec
13530
Avg. Destage Transfers/Operation
13532
Avg. Destage Transfers/Evict
13534
Destage Transfer Bytes/sec
13536
Avg. Destage Bytes/Transfer
13538
Avg. Destage Transfer Bytes/Operation
13540
Bytes Cached
13542
Bytes Reserved
13544
Bytes Reclaimable
13546
Bytes Used
13548
Cache Size
13550
Cache Writes
13552
Cache Overwrites
13554
Cache Evicts
13556
Destage Operations
13558
Destage Evicts
13560
Destage Transfers
13448
Storage Spaces Tier
13450
Tier Reads/sec
13452
Avg. Tier sec/Read
13454
Avg. Tier Read Queue Length
13456
Tier Read Bytes/sec
13458
Avg. Tier Bytes/Read
13460
Tier Writes/sec
13462
Avg. Tier sec/Write
13464
Avg. Tier Write Queue Length
13466
Tier Write Bytes/sec
13468
Avg. Tier Bytes/Write
13470
Current Tier Queue Length
13472
Tier Transfers/sec
13474
Avg. Tier sec/Transfer
13476
Avg. Tier Queue Length
13478
Tier Transfer Bytes/sec
13480
Avg. Tier Bytes/Transfer
13482
Tier Reads
13484
Tier Writes
13486
Tier Transfers
6606
Hyper-V Virtual Machine Bus Pipes
6608
Reads/sec
6610
Writes/sec
6612
Bytes Read/sec
6614
Bytes Written/sec
8140
Offline Files
8142
Bytes Received
8144
Bytes Transmitted
8146
Bytes Transmitted/sec
8150
Bytes Received/sec
8154
Client Side Caching
8156
SMB BranchCache Bytes Requested
8158
SMB BranchCache Bytes Received
8160
SMB BranchCache Bytes Published
8162
SMB BranchCache Bytes Requested From Server
8164
SMB BranchCache Hashes Requested
8166
SMB BranchCache Hashes Received
8168
SMB BranchCache Hash Bytes Received
8170
Prefetch Operations Queued
8172
Prefetch Bytes Read From Cache
8174
Prefetch Bytes Read From Server
8176
Application Bytes Read From Cache
8178
Application Bytes Read From Server
8180
Application Bytes Read From Server (Not Cached)
4358
Teredo Relay
4360
In - Teredo Relay Total Packets: Success + Error
4362
In - Teredo Relay Success Packets: Total
4364
In - Teredo Relay Success Packets: Bubbles
4366
In - Teredo Relay Success Packets: Data Packets
4368
In - Teredo Relay Error Packets: Total
4370
In - Teredo Relay Error Packets: Header Error
4372
In - Teredo Relay Error Packets: Source Error
4374
In - Teredo Relay Error Packets: Destination Error
4376
Out - Teredo Relay Total Packets: Success + Error
4378
Out - Teredo Relay Success Packets
4380
Out - Teredo Relay Success Packets: Bubbles
4382
Out - Teredo Relay Success Packets: Data Packets
4384
Out - Teredo Relay Error Packets
4386
Out - Teredo Relay Error Packets: Header Error
4388
Out - Teredo Relay Error Packets: Source Error
4390
Out - Teredo Relay Error Packets: Destination Error
4392
In - Teredo Relay Total Packets: Success + Error / sec
4394
Out - Teredo Relay Total Packets: Success + Error / sec
4396
In - Teredo Relay Success Packets: Data Packets User Mode
4398
In - Teredo Relay Success Packets: Data Packets Kernel Mode
4400
Out - Teredo Relay Success Packets: Data Packets User Mode
4402
Out - Teredo Relay Success Packets: Data Packets Kernel Mode
4404
IPHTTPS Session
4406
Packets received on this session
4408
Packets sent on this session
4410
Bytes received on this session
4412
Bytes sent on this session
4414
Errors - Transmit errors on this session
4416
Errors - Receive errors on this session
4418
Duration - Duration of the session (Seconds)
4442
DNS64 Global
4444
AAAA queries - Successful
4446
AAAA queries - Failed
4448
IP6.ARPA queries - Matched
4450
Other queries - Successful
4452
Other queries - Failed
4454
AAAA - Synthesized records
4420
IPHTTPS Global
4422
In - Total bytes received
4424
Out - Total bytes sent
4426
Drops - Neighbor resolution timeouts
4428
Errors - Authentication Errors
4430
Out - Total bytes forwarded
4432
Errors - Transmit errors on the server
4434
Errors - Receive errors on the server
4436
In - Total packets received
4438
Out - Total packets sent
4440
Sessions - Total sessions
4328
Teredo Server
4330
In - Teredo Server Total Packets: Success + Error
4332
In - Teredo Server Success Packets: Total
4334
In - Teredo Server Success Packets: Bubbles
4336
In - Teredo Server Success Packets: Echo
4338
In - Teredo Server Success Packets: RS-Primary
4340
In - Teredo Server Success Packets: RS-Secondary
4342
In - Teredo Server Error Packets: Total
4344
In - Teredo Server Error Packets: Header Error
4346
In - Teredo Server Error Packets: Source Error
4348
In - Teredo Server Error Packets: Destination Error
4350
In - Teredo Server Error Packets: Authentication Error
4352
Out - Teredo Server: RA-Primary
4354
Out - Teredo Server: RA-Secondary
4356
In - Teredo Server Total Packets: Success + Error / sec
4304
Teredo Client
4306
In - Teredo Router Advertisement
4308
In - Teredo Bubble
4310
In - Teredo Data
4312
In - Teredo Invalid
4314
Out - Teredo Router Solicitation
4316
Out - Teredo Bubble
4318
Out - Teredo Data
4320
In - Teredo Data User Mode
4322
In - Teredo Data Kernel Mode
4324
Out - Teredo Data User Mode
4326
Out - Teredo Data Kernel Mode
6108
Hyper-V Dynamic Memory Integration Service
6110
Maximum Memory, Mbytes
6400
ServiceModelService 4.0.0.0
6402
Calls
6404
Calls Per Second
6406
Calls Outstanding
6408
Calls Failed
6410
Calls Failed Per Second
6412
Calls Faulted
6414
Calls Faulted Per Second
6416
Calls Duration
6418
Security Validation and Authentication Failures
6420
Security Validation and Authentication Failures Per Second
6422
Security Calls Not Authorized
6424
Security Calls Not Authorized Per Second
6426
Instances
6428
Instances Created Per Second
6430
Reliable Messaging Sessions Faulted
6432
Reliable Messaging Sessions Faulted Per Second
6434
Reliable Messaging Messages Dropped
6436
Reliable Messaging Messages Dropped Per Second
6438
Transactions Flowed
6440
Transactions Flowed Per Second
6442
Transacted Operations Committed
6444
Transacted Operations Committed Per Second
6446
Transacted Operations Aborted
6448
Transacted Operations Aborted Per Second
6450
Transacted Operations In Doubt
6452
Transacted Operations In Doubt Per Second
6454
Queued Poison Messages
6456
Queued Poison Messages Per Second
6458
Queued Messages Rejected
6460
Queued Messages Rejected Per Second
6462
Queued Messages Dropped
6464
Queued Messages Dropped Per Second
6466
Percent Of Max Concurrent Calls
6468
Percent Of Max Concurrent Instances
6470
Percent Of Max Concurrent Sessions
6472
CallDurationBase
6474
CallsPercentMaxConcurrentCallsBase
6476
InstancesPercentMaxConcurrentInstancesBase
6478
SessionsPercentMaxConcurrentSessionsBase
6520
ServiceModelOperation 4.0.0.0
6522
Calls
6524
Calls Per Second
6526
Calls Outstanding
6528
Calls Failed
6530
Call Failed Per Second
6532
Calls Faulted
6534
Calls Faulted Per Second
6536
Calls Duration
6538
Security Validation and Authentication Failures
6540
Security Validation and Authentication Failures Per Second
6542
Security Calls Not Authorized
6544
Security Calls Not Authorized Per Second
6546
Transactions Flowed
6548
Transactions Flowed Per Second
6550
CallsDurationBase
6480
ServiceModelEndpoint 4.0.0.0
6482
Calls
6484
Calls Per Second
6486
Calls Outstanding
6488
Calls Failed
6490
Calls Failed Per Second
6492
Calls Faulted
6494
Calls Faulted Per Second
6496
Calls Duration
6498
Security Validation and Authentication Failures
6500
Security Validation and Authentication Failures Per Second
6502
Security Calls Not Authorized
6504
Security Calls Not Authorized Per Second
6506
Reliable Messaging Sessions Faulted
6508
Reliable Messaging Sessions Faulted Per Second
6510
Reliable Messaging Messages Dropped
6512
Reliable Messaging Messages Dropped Per Second
6514
Transactions Flowed
6516
Transactions Flowed Per Second
6518
CallDurationBase
7490
Power Meter
7492
Power
7494
Power Budget
7496
Energy Meter
7498
Time
7500
Energy
7502
Power
7506
TCPIP Performance Diagnostics
7508
IPv4 NBLs indicated with low-resource flag
7510
IPv4 NBLs/sec indicated with low-resource flag
7512
IPv6 NBLs indicated with low-resource flag
7514
IPv6 NBLs/sec indicated with low-resource flag
7516
IPv4 NBLs indicated without prevalidation
7518
IPv4 NBLs/sec indicated without prevalidation
7520
IPv6 NBLs indicated without prevalidation
7522
IPv6 NBLs/sec indicated without prevalidation
7524
IPv4 NBLs treated as non-prevalidated
7526
IPv4 NBLs/sec treated as non-prevalidated
7528
IPv6 NBLs treated as non-prevalidated
7530
IPv6 NBLs/sec treated as non-prevalidated
7532
IPv4 outbound NBLs not processed via fast path
7534
IPv4 outbound NBLs/sec not processed via fast path
7536
IPv6 outbound NBLs not processed via fast path
7538
IPv6 outbound NBLs/sec not processed via fast path
7540
TCP inbound segments not processed via fast path
7542
TCP inbound segments/sec not processed via fast path
7544
TCP connect requests fallen off loopback fast path
7546
TCP connect requests/sec fallen off loopback fast path
7548
Denied connect or send requests in low-power mode
6382
HTTP Service Request Queues
6384
CurrentQueueSize
6386
MaxQueueItemAge
6388
ArrivalRate
6390
RejectionRate
6392
RejectedRequests
6394
CacheHitRate
6362
HTTP Service Url Groups
6364
BytesSentRate
6366
BytesReceivedRate
6368
BytesTransferredRate
6370
CurrentConnections
6372
MaxConnections
6374
ConnectionAttempts
6376
GetRequests
6378
HeadRequests
6380
AllRequests
6348
HTTP Service
6350
CurrentUrisCached
6352
TotalUrisCached
6354
UriCacheHits
6356
UriCacheMisses
6358
UriCacheFlushes
6360
TotalFlushedUris
5114
PowerShell Workflow
5116
# of failed workflow jobs
5118
# of failed workflow jobs/sec
5120
# of resumed workflow jobs
5122
# of resumed workflow jobs/sec
5124
# of running workflow jobs
5126
# of running workflow jobs / sec
5128
# of stopped workflow jobs
5130
# of stopped workflow jobs / sec
5132
# of succeeded workflow jobs
5134
# of succeeded workflow jobs/sec
5136
# of suspended workflow jobs
5138
# of suspended workflow jobs/sec
5140
# of terminated workflow jobs
5142
# of terminated workflow jobs / sec
5144
# of waiting workflow jobs
5146
Activity Host Manager: # of busy host processes
5148
Activity Host Manager: # of failed requests/sec
5150
Activity Host Manager: # of failed requests in queue
5152
Activity Host Manager: # of incoming requests/sec
5154
Activity Host Manager: # of pending requests in queue
5156
Activity Host Manager: # of created host processes
5158
Activity Host Manager: # of disposed host processes
5160
Activity Host Manager: host processes pool size
5162
PowerShell Remoting: # of pending requests in queue
5164
PowerShell Remoting: # of requests being serviced
5166
PowerShell Remoting: # of forced to wait requests in queue
5168
PowerShell Remoting: # of created connections
5170
PowerShell Remoting: # of disposed connections
5172
PowerShell Remoting: # of connections closed-reopened
1946
Windows Media Player Metadata
1948
Files Scanned/Minute
1952
Monitored Folder Updates/Second
1956
Groveler Service Routine Executions/Second
1960
Library Description Updates/Second
1964
Library Description Change Notifications/Second
1968
File Scanning Thread Prioirty
1970
Directory Change Queue Length
1972
Scanning State
1974
Dirty Directory Hit Count
1976
Timestamp Directory Hit Count
1978
AFTS Execution Time (ms)
1980
URL Classification Time (ms)
1982
Property Extraction Time (ms)
1984
Art Extraction Time (ms)
1986
Reorganize Time (ms)
1988
Commit Time (ms)
1990
Normalization Time (ms)
8234
RemoteFX Graphics
8236
Input Frames/Second
8238
Graphics Compression ratio
8240
Output Frames/Second
8242
Frames Skipped/Second - Insufficient Client Resources
8244
Frames Skipped/Second - Insufficient Network Resources
8246
Frames Skipped/Second - Insufficient Server Resources
8248
Frame Quality
8250
Average Encoding Time
8252
Source Frames/Second
8254
RemoteFX Network
8256
Base TCP RTT
8258
Current TCP RTT
8260
Current TCP Bandwidth
8262
Total Received Rate
8264
TCP Received Rate
8266
UDP Received Rate
8268
UDP Packets Received/sec
8270
Total Sent Rate
8272
TCP Sent Rate
8274
UDP Sent Rate
8276
UDP Packets Sent/sec
8278
Sent Rate P0
8280
Sent Rate P1
8282
Sent Rate P2
8284
Sent Rate P3
8286
Loss Rate
8288
Retransmission Rate
8290
FEC Rate
8294
Base UDP RTT
8296
Current UDP RTT
8298
Current UDP Bandwidth
8300
Total Sent Bytes
8302
Total Received Bytes
4852
SMB Server Shares
4854
Received Bytes/sec
4856
Requests/sec
4858
Tree Connect Count
4860
Current Open File Count
4862
Sent Bytes/sec
4864
Transferred Bytes/sec
4866
Current Pending Requests
4868
Avg. sec/Request
4872
Write Requests/sec
4874
Avg. sec/Write
4878
Write Bytes/sec
4880
Read Requests/sec
4882
Avg. sec/Read
4886
Read Bytes/sec
4888
Total File Open Count
4890
Files Opened/sec
4892
Current Durable Open File Count
4894
Total Durable Handle Reopen Count
4896
Total Failed Durable Handle Reopen Count
4898
% Resilient Handles
4902
Total Resilient Handle Reopen Count
4904
Total Failed Resilient Handle Reopen Count
4906
% Persistent Handles
4910
Total Persistent Handle Reopen Count
4912
Total Failed Persistent Handle Reopen Count
4914
Metadata Requests/sec
4916
Avg. sec/Data Request
4920
Avg. Data Bytes/Request
4924
Avg. Bytes/Read
4928
Avg. Bytes/Write
4932
Avg. Read Queue Length
4934
Avg. Write Queue Length
4936
Avg. Data Queue Length
4938
Data Bytes/sec
4940
Data Requests/sec
4942
Current Data Queue Length
4944
SMB Server Sessions
4946
Received Bytes/sec
4948
Requests/sec
4950
Tree Connect Count
4952
Current Open File Count
4954
Sent Bytes/sec
4956
Transferred Bytes/sec
4958
Current Pending Requests
4960
Avg. sec/Request
4964
Write Requests/sec
4966
Avg. sec/Write
4970
Write Bytes/sec
4972
Read Requests/sec
4974
Avg. sec/Read
4978
Read Bytes/sec
4980
Total File Open Count
4982
Files Opened/sec
4984
Current Durable Open File Count
4986
Total Durable Handle Reopen Count
4988
Total Failed Durable Handle Reopen Count
4990
% Resilient Handles
4994
Total Resilient Handle Reopen Count
4996
Total Failed Resilient Handle Reopen Count
4998
% Persistent Handles
5002
Total Persistent Handle Reopen Count
5004
Total Failed Persistent Handle Reopen Count
5006
Metadata Requests/sec
5008
Avg. sec/Data Request
5012
Avg. Data Bytes/Request
5016
Avg. Bytes/Read
5020
Avg. Bytes/Write
5024
Avg. Read Queue Length
5026
Avg. Write Queue Length
5028
Avg. Data Queue Length
5030
Data Bytes/sec
5032
Data Requests/sec
5034
Current Data Queue Length
5036
SMB Server
5038
Read Bytes/sec
5040
Read Requests/sec
5042
Write Bytes/sec
5044
Write Requests/sec
5046
Send Bytes/sec
5048
Receive Bytes/sec
1848
Netlogon
1850
Semaphore Waiters
1852
Semaphore Holders
1854
Semaphore Acquires
1856
Semaphore Timeouts
1858
Average Semaphore Hold Time
1860
Semaphore Hold Time Base
1862
LDAP Bind Time
1864
Last Authentication Time
1866
Trusted Domain Controller Count
7296
XHCI Interrupter
7298
Interrupts/sec
7300
DPCs/sec
7302
Events processed/DPC
7304
DPC count
7306
EventRingFullCount
7308
DpcRequeueCount
7320
XHCI TransferRing
7322
Transfers/sec
7324
Failed Transfer Count
7326
Bytes/Sec
7328
Isoch TD/sec
7330
Isoch TD Failures/sec
7332
Missed Service Error Count
7334
Underrun Overrun count
7310
XHCI CommonBuffer
7312
PagesTotal
7314
PagesInUse
7316
AllocationCount
7318
FreeCount
7550
Distributed Routing Table
7552
Registrations
7554
Searches
7556
Cache Entries
7558
Average Bytes/second Sent
7560
Average Bytes/second Received
7562
Estimated cloud size
7564
Stale Cache Entries
7566
Send Failures
7568
Receive Failures
7570
Solicit Messages Sent/second
7572
Solicit Messages Received/second
7574
Advertise Messages Sent/second
7576
Advertise Messages Received/second
7578
Request Messages Sent/second
7580
Request Messages Received/second
7582
Flood Messages Sent/second
7584
Flood Messages Received/second
7586
Inquire Messages Sent/second
7588
Inquire Messages Received/second
7590
Authority Sent/second
7592
Authority Messages Received/second
7594
Ack Messages Sent/second
7596
Ack Messages Received/second
7598
Lookup Messages Sent/second
7600
Lookup Messages Received/second
7602
Unrecognized Messages Received
5748
PacketDirect Receive Filters
5750
Packets Matched
5752
Packets Matched/sec
5754
Bytes Matched
5756
Bytes Matched/sec
5724
PacketDirect Transmit Counters
5726
Packets Transmitted
5728
Packets Transmitted/sec
5730
Bytes Transmitted
5732
Bytes Transmitted/sec
5712
Physical Network Interface Card Activity
5714
Device Power State
5716
% Time Suspended (Instantaneous)
5718
% Time Suspended (Lifetime)
5720
Low Power Transitions (Lifetime)
5610
Per Processor Network Interface Card Activity
5612
DPCs Queued/sec
5614
Interrupts/sec
5616
Receive Indications/sec
5618
Return Packet Calls/sec
5620
Passive Return Packet Calls/sec
5622
Received Packets/sec
5624
Returned Packets/sec
5626
Passive Returned Packets/sec
5628
DPCs Queued on Other CPUs/sec
5630
Send Request Calls/sec
5632
Passive Send Request Calls/sec
5634
Send Complete Calls/sec
5636
Sent Packets/sec
5638
Passive Sent Packets/sec
5640
Sent Complete Packets/sec
5642
Build Scatter Gather List Calls/sec
5644
RSS Indirection Table Change Calls/sec
5646
Low Resource Receive Indications/sec
5648
Low Resource Received Packets/sec
5650
Tcp Offload Receive Indications/sec
5652
Tcp Offload Send Request Calls/sec
5654
Tcp Offload Receive bytes/sec
5656
Tcp Offload Send bytes/sec
5658
DPCs Deferred/sec
5660
Packets Coalesced/sec
5662
Per Processor Network Activity Cycles
5664
Interrupt DPC Cycles/sec
5666
Interrupt Cycles/sec
5668
NDIS Receive Indication Cycles/sec
5670
Stack Receive Indication Cycles/sec
5672
NDIS Return Packet Cycles/sec
5674
Miniport Return Packet Cycles/sec
5676
NDIS Send Cycles/sec
5678
Miniport Send Cycles/sec
5680
NDIS Send Complete Cycles/sec
5682
Build Scatter Gather Cycles/sec
5684
Miniport RSS Indirection Table Change Cycles
5686
Stack Send Complete Cycles/sec
5688
Interrupt DPC Latency Cycles/sec
5786
PacketDirect Queue Depth
5788
Average Queue Depth
5790
% Average Queue Utilization
5734
PacketDirect Receive Counters
5736
Packets Received
5738
Packets Received/sec
5740
Bytes Received
5742
Bytes Received/sec
5744
Packets Dropped
5746
Packets Dropped/sec
5690
RDMA Activity
5692
RDMA Initiated Connections
5694
RDMA Accepted Connections
5696
RDMA Failed Connection Attempts
5698
RDMA Connection Errors
5700
RDMA Active Connections
5702
RDMA Completion Queue Errors
5704
RDMA Inbound Bytes/sec
5706
RDMA Outbound Bytes/sec
5708
RDMA Inbound Frames/sec
5710
RDMA Outbound Frames/sec
5758
PacketDirect EC Utilization
5760
Processor Number
5762
Total Iterations
5764
Iterations/sec
5766
Total Busy Wait Iterations
5768
Busy Wait Iterations/sec
5772
% Busy Wait Iterations
5776
% Idle Time
5778
% Busy Waiting Time
5780
% Processing Time
5782
TX Queue Count
5784
RX Queue Count
5518
FileSystem Disk Activity
5520
FileSystem Bytes Read
5522
FileSystem Bytes Written
5420
Event Tracing for Windows Session
5422
Buffer Memory Usage -- Paged Pool
5424
Buffer Memory Usage -- Non-Paged Pool
5426
Events Logged per sec
5428
Events Lost
5430
Number of Real-Time Consumers
5252
Processor Information
5254
% Processor Time
5256
% User Time
5258
% Privileged Time
5260
Interrupts/sec
5262
% DPC Time
5264
% Interrupt Time
5266
DPCs Queued/sec
5268
DPC Rate
5270
% Idle Time
5272
% C1 Time
5274
% C2 Time
5276
% C3 Time
5278
C1 Transitions/sec
5280
C2 Transitions/sec
5282
C3 Transitions/sec
5284
% Priority Time
5286
Parking Status
5288
Processor Frequency
5290
% of Maximum Frequency
5292
Processor State Flags
5294
Clock Interrupts/sec
5296
Average Idle Time
5300
Idle Break Events/sec
5302
% Processor Performance
5306
% Processor Utility
5310
% Privileged Utility
5314
% Performance Limit
5316
Performance Limit Flags
5524
Thermal Zone Information
5526
Temperature
5528
% Passive Limit
5530
Throttle Reasons
5406
Event Tracing for Windows
5408
Total Number of Distinct Enabled Providers
5410
Total Number of Distinct Pre-Enabled Providers
5412
Total Number of Distinct Disabled Providers
5414
Total Number of Active Sessions
5416
Total Memory Usage --- Paged Pool
5418
Total Memory Usage --- Non-Paged Pool
5320
Synchronization
5322
Spinlock Acquires/sec
5324
Spinlock Contentions/sec
5326
Spinlock Spins/sec
5328
IPI Send Broadcast Requests/sec
5330
IPI Send Routine Requests/sec
5332
IPI Send Software Interrupts/sec
5334
Exec. Resource Total Initialize/sec
5336
Exec. Resource Total Re-Initialize/sec
5338
Exec. Resource Total Delete/sec
5340
Exec. Resource Total Acquires/sec
5342
Exec. Resource Total Contentions/sec
5344
Exec. Resource Total Exclusive Releases/sec
5346
Exec. Resource Total Shared Releases/sec
5348
Exec. Resource Total Conv. Exclusive To Shared/sec
5350
Exec. Resource Attempts AcqExclLite/sec
5352
Exec. Resource Acquires AcqExclLite/sec
5354
Exec. Resource Recursive Excl. Acquires AcqExclLite/sec
5356
Exec. Resource Contention AcqExclLite/sec
5358
Exec. Resource no-Waits AcqExclLite/sec
5360
Exec. Resource Attempts AcqShrdLite/sec
5362
Exec. Resource Recursive Excl. Acquires AcqShrdLite/sec
5364
Exec. Resource Acquires AcqShrdLite/sec
5366
Exec. Resource Recursive Sh. Acquires AcqShrdLite/sec
5368
Exec. Resource Contention AcqShrdLite/sec
5370
Exec. Resource no-Waits AcqShrdLite/sec
5372
Exec. Resource Attempts AcqShrdStarveExcl/sec
5374
Exec. Resource Recursive Excl. Acquires AcqShrdStarveExcl/sec
5376
Exec. Resource Acquires AcqShrdStarveExcl/sec
5378
Exec. Resource Recursive Sh. Acquires AcqShrdStarveExcl/sec
5380
Exec. Resource Contention AcqShrdStarveExcl/sec
5382
Exec. Resource no-Waits AcqShrdStarveExcl/sec
5384
Exec. Resource Attempts AcqShrdWaitForExcl/sec
5386
Exec. Resource Recursive Excl. Acquires AcqShrdWaitForExcl/sec
5388
Exec. Resource Acquires AcqShrdWaitForExcl/sec
5390
Exec. Resource Recursive Sh. Acquires AcqShrdWaitForExcl/sec
5392
Exec. Resource Contention AcqShrdWaitForExcl/sec
5394
Exec. Resource no-Waits AcqShrdWaitForExcl/sec
5396
Exec. Resource Set Owner Pointer Exclusive/sec
5398
Exec. Resource Set Owner Pointer Shared (New Owner)/sec
5400
Exec. Resource Set Owner Pointer Shared (Existing Owner)/sec
5402
Exec. Resource Boost Excl. Owner/sec
5404
Exec. Resource Boost Shared Owners/sec
5432
SynchronizationNuma
5434
Spinlock Acquires/sec
5436
Spinlock Contentions/sec
5438
Spinlock Spins/sec
5440
IPI Send Broadcast Requests/sec
5442
IPI Send Routine Requests/sec
5444
IPI Send Software Interrupts/sec
5446
Exec. Resource Total Initialize/sec
5448
Exec. Resource Total Re-Initialize/sec
5450
Exec. Resource Total Delete/sec
5452
Exec. Resource Total Acquires/sec
5454
Exec. Resource Total Contentions/sec
5456
Exec. Resource Total Exclusive Releases/sec
5458
Exec. Resource Total Shared Releases/sec
5460
Exec. Resource Total Conv. Exclusive To Shared/sec
5462
Exec. Resource Attempts AcqExclLite/sec
5464
Exec. Resource Acquires AcqExclLite/sec
5466
Exec. Resource Recursive Excl. Acquires AcqExclLite/sec
5468
Exec. Resource Contention AcqExclLite/sec
5470
Exec. Resource no-Waits AcqExclLite/sec
5472
Exec. Resource Attempts AcqShrdLite/sec
5474
Exec. Resource Recursive Excl. Acquires AcqShrdLite/sec
5476
Exec. Resource Acquires AcqShrdLite/sec
5478
Exec. Resource Recursive Sh. Acquires AcqShrdLite/sec
5480
Exec. Resource Contention AcqShrdLite/sec
5482
Exec. Resource no-Waits AcqShrdLite/sec
5484
Exec. Resource Attempts AcqShrdStarveExcl/sec
5486
Exec. Resource Recursive Excl. Acquires AcqShrdStarveExcl/sec
5488
Exec. Resource Acquires AcqShrdStarveExcl/sec
5490
Exec. Resource Recursive Sh. Acquires AcqShrdStarveExcl/sec
5492
Exec. Resource Contention AcqShrdStarveExcl/sec
5494
Exec. Resource no-Waits AcqShrdStarveExcl/sec
5496
Exec. Resource Attempts AcqShrdWaitForExcl/sec
5498
Exec. Resource Recursive Excl. Acquires AcqShrdWaitForExcl/sec
5500
Exec. Resource Acquires AcqShrdWaitForExcl/sec
5502
Exec. Resource Recursive Sh. Acquires AcqShrdWaitForExcl/sec
5504
Exec. Resource Contention AcqShrdWaitForExcl/sec
5506
Exec. Resource no-Waits AcqShrdWaitForExcl/sec
5508
Exec. Resource Set Owner Pointer Exclusive/sec
5510
Exec. Resource Set Owner Pointer Shared (New Owner)/sec
5512
Exec. Resource Set Owner Pointer Shared (Existing Owner)/sec
5514
Exec. Resource Boost Excl. Owner/sec
5516
Exec. Resource Boost Shared Owners/sec
10070
Windows Time Service
10072
Computed Time Offset
10074
Clock Frequency Adjustment
10076
NTP Roundtrip Delay
10078
NTP Client Time Source Count
10080
NTP Server Incoming Requests
10082
NTP Server Outgoing Responses
4608
SMB Client Shares
4610
Read Bytes/sec
4612
Write Bytes/sec
4614
Read Requests/sec
4616
Write Requests/sec
4618
Avg. Bytes/Read
4622
Avg. Bytes/Write
4626
Avg. sec/Read
4630
Avg. sec/Write
4634
Data Bytes/sec
4636
Data Requests/sec
4638
Avg. Data Bytes/Request
4642
Avg. sec/Data Request
4646
Current Data Queue Length
4648
Avg. Read Queue Length
4650
Avg. Write Queue Length
4652
Avg. Data Queue Length
4654
Metadata Requests/sec
4656
Credit Stalls/sec
8230
AppV Client Streamed Data Percentage
8232
Primary Feature % Streamed
6084
Network QoS Policy
6086
Packets transmitted
6088
Packets transmitted/sec
6090
Bytes transmitted
6092
Bytes transmitted/sec
6094
Packets dropped
6096
Packets dropped/sec
8182
BranchCache
8184
Retrieval: Bytes from server
8186
Retrieval: Bytes from cache
8188
Retrieval: Bytes served
8190
Discovery: Weighted average discovery time
8192
SMB: Bytes from cache
8194
SMB: Bytes from server
8196
BITS: Bytes from cache
8198
BITS: Bytes from server
8200
WININET: Bytes from cache
8202
WININET: Bytes from server
8204
WINHTTP: Bytes from cache
8206
WINHTTP: Bytes from server
8208
OTHER: Bytes from cache
8210
OTHER: Bytes from server
8212
Discovery: Attempted discoveries
8214
Local Cache: Cache complete file segments
8216
Local Cache: Cache partial file segments
8218
Hosted Cache: Client file segment offers made
8220
Retrieval: Average branch rate
8222
Discovery: Successful discoveries
8224
Hosted Cache: Segment offers queue size
8226
Publication Cache: Published contents
8228
Local Cache: Average access time
4820
WSMan Quota Statistics
4822
Total Requests/Second
4824
User Quota Violations/Second
4826
System Quota Violations/Second
4828
Active Shells
4830
Active Operations
4832
Active Users
4834
Process ID
1888
RAS
1890
Total Clients
1892
Max Clients
1894
Failed Authentications
1896
Bytes Received By Disconnected Clients
1898
Bytes Transmitted By Disconnected Clients
"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Perflib\009]
"Help"="3
The System performance object consists of counters that apply to more than one instance of a component processors on the computer.
5
The Memory performance object consists of counters that describe the behavior of physical and virtual memory on the computer. Physical memory is the amount of random access memory on the computer. Virtual memory consists of the space in physical memory and on disk. Many of the memory counters monitor paging, which is the movement of pages of code and data between disk and physical memory. Excessive paging, a symptom of a memory shortage, can cause delays which interfere with all system processes.
7
% Processor Time is the percentage of elapsed time that the processor spends to execute a non-Idle thread. It is calculated by measuring the percentage of time that the processor spends executing the idle thread and then subtracting that value from 100%. (Each processor has an idle thread that consumes cycles when no other threads are ready to run). This counter is the primary indicator of processor activity, and displays the average percentage of busy time observed during the sample interval. It should be noted that the accounting calculation of whether the processor is idle is performed at an internal sampling interval of the system clock (10ms). On todays fast processors, % Processor Time can therefore underestimate the processor utilization as the processor may be spending a lot of time servicing threads between the system clock sampling interval. Workload based timer applications are one example of applications which are more likely to be measured inaccurately as timers are signaled just after the sample is taken.
9
% Total DPC Time is the average percentage of time that all processors spend receiving and servicing deferred procedure calls (DPCs). (DPCs are interrupts that run at a lower priority than the standard interrupts). It is the sum of Processor: % DPC Time for all processors on the computer, divided by the number of processors. System: % Total DPC Time is a component of System: % Total Privileged Time because DPCs are executed in privileged mode. DPCs are counted separately and are not a component of the interrupt count. This counter displays the average busy time as a percentage of the sample time.
11
File Read Operations/sec is the combined rate of file system read requests to all devices on the computer, including requests to read from the file system cache. It is measured in numbers of reads. This counter displays the difference between the values observed in the last two samples, divided by the duration of the sample interval.
13
File Write Operations/sec is the combined rate of the file system write requests to all devices on the computer, including requests to write to data in the file system cache. It is measured in numbers of writes. This counter displays the difference between the values observed in the last two samples, divided by the duration of the sample interval.
15
File Control Operations/sec is the combined rate of file system operations that are neither reads nor writes, such as file system control requests and requests for information about device characteristics or status. This is the inverse of System: File Data Operations/sec and is measured in number of operations perf second. This counter displays the difference between the values observed in the last two samples, divided by the duration of the sample interval.
17
File Read Bytes/sec is the overall rate at which bytes are read to satisfy file system read requests to all devices on the computer, including reads from the file system cache. It is measured in number of bytes per second. This counter displays the difference between the values observed in the last two samples, divided by the duration of the sample interval.
19
File Write Bytes/sec is the overall rate at which bytes are written to satisfy file system write requests to all devices on the computer, including writes to the file system cache. It is measured in number of bytes per second. This counter displays the difference between the values observed in the last two samples, divided by the duration of the sample interval.
21
File Control Bytes/sec is the overall rate at which bytes are transferred for all file system operations that are neither reads nor writes, including file system control requests and requests for information about device characteristics or status. It is measured in numbers of bytes. This counter displays the difference between the values observed in the last two samples, divided by the duration of the sample interval.
23
% Total Interrupt Time is the average percentage of time that all processors spend receiving and servicing hardware interrupts during sample intervals, where the value is an indirect indicator of the activity of devices that generate interrupts. It is the sum of Processor: % Interrupt Time for of all processors on the computer, divided by the number of processors. DPCs are counted separately and are not a component of the interrupt count. This value is an indirect indicator of the activity of devices that generate interrupts, such as the system timer, the mouse, disk drivers, data communication lines, network interface cards and other peripheral devices.
25
Available Bytes is the amount of physical memory, in bytes, immediately available for allocation to a process or for system use. It is equal to the sum of memory assigned to the standby (cached), free and zero page lists.
27
Committed Bytes is the amount of committed virtual memory, in bytes. Committed memory is the physical memory which has space reserved on the disk paging file(s). There can be one or more paging files on each physical drive. This counter displays the last observed value only; it is not an average.
29
Page Faults/sec is the average number of pages faulted per second. It is measured in number of pages faulted per second because only one page is faulted in each fault operation, hence this is also equal to the number of page fault operations. This counter includes both hard faults (those that require disk access) and soft faults (where the faulted page is found elsewhere in physical memory.) Most processors can handle large numbers of soft faults without significant consequence. However, hard faults, which require disk access, can cause significant delays.
31
Commit Limit is the amount of virtual memory that can be committed without having to extend the paging file(s). It is measured in bytes. Committed memory is the physical memory which has space reserved on the disk paging files. There can be one paging file on each logical drive). If the paging file(s) are be expanded, this limit increases accordingly. This counter displays the last observed value only; it is not an average.
33
Write Copies/sec is the rate at which page faults are caused by attempts to write that have been satisfied by coping of the page from elsewhere in physical memory. This is an economical way of sharing data since pages are only copied when they are written to; otherwise, the page is shared. This counter shows the number of copies, without regard for the number of pages copied in each operation.
35
Transition Faults/sec is the rate at which page faults are resolved by recovering pages that were being used by another process sharing the page, or were on the modified page list or the standby list, or were being written to disk at the time of the page fault. The pages were recovered without additional disk activity. Transition faults are counted in numbers of faults; because only one page is faulted in each operation, it is also equal to the number of pages faulted.
37
Cache Faults/sec is the rate at which faults occur when a page sought in the file system cache is not found and must be retrieved from elsewhere in memory (a soft fault) or from disk (a hard fault). The file system cache is an area of physical memory that stores recently used pages of data for applications. Cache activity is a reliable indicator of most application I/O operations. This counter shows the number of faults, without regard for the number of pages faulted in each operation.
39
Demand Zero Faults/sec is the rate at which a zeroed page is required to satisfy the fault. Zeroed pages, pages emptied of previously stored data and filled with zeros, are a security feature of Windows that prevent processes from seeing data stored by earlier processes that used the memory space. Windows maintains a list of zeroed pages to accelerate this process. This counter shows the number of faults, without regard to the number of pages retrieved to satisfy the fault. This counter displays the difference between the values observed in the last two samples, divided by the duration of the sample interval.
41
Pages/sec is the rate at which pages are read from or written to disk to resolve hard page faults. This counter is a primary indicator of the kinds of faults that cause system-wide delays. It is the sum of Memory\\Pages Input/sec and Memory\\Pages Output/sec. It is counted in numbers of pages, so it can be compared to other counts of pages, such as Memory\\Page Faults/sec, without conversion. It includes pages retrieved to satisfy faults in the file system cache (usually requested by applications) non-cached mapped memory files.
43
Page Reads/sec is the rate at which the disk was read to resolve hard page faults. It shows the number of reads operations, without regard to the number of pages retrieved in each operation. Hard page faults occur when a process references a page in virtual memory that is not in working set or elsewhere in physical memory, and must be retrieved from disk. This counter is a primary indicator of the kinds of faults that cause system-wide delays. It includes read operations to satisfy faults in the file system cache (usually requested by applications) and in non-cached mapped memory files. Compare the value of Memory\\Pages Reads/sec to the value of Memory\\Pages Input/sec to determine the average number of pages read during each operation.
45
Processor Queue Length is the number of threads in the processor queue. Unlike the disk counters, this counter counters, this counter shows ready threads only, not threads that are running. There is a single queue for processor time even on computers with multiple processors. Therefore, if a computer has multiple processors, you need to divide this value by the number of processors servicing the workload. A sustained processor queue of less than 10 threads per processor is normally acceptable, dependent of the workload.
47
Thread State is the current state of the thread. It is 0 for Initialized, 1 for Ready, 2 for Running, 3 for Standby, 4 for Terminated, 5 for Wait, 6 for Transition, 7 for Unknown. A Running thread is using a processor; a Standby thread is about to use one. A Ready thread wants to use a processor, but is waiting for a processor because none are free. A thread in Transition is waiting for a resource in order to execute, such as waiting for its execution stack to be paged in from disk. A Waiting thread has no use for the processor because it is waiting for a peripheral operation to complete or a resource to become free.
49
Pages Output/sec is the rate at which pages are written to disk to free up space in physical memory. Pages are written back to disk only if they are changed in physical memory, so they are likely to hold data, not code. A high rate of pages output might indicate a memory shortage. Windows writes more pages back to disk to free up space when physical memory is in short supply. This counter shows the number of pages, and can be compared to other counts of pages, without conversion.
51
Page Writes/sec is the rate at which pages are written to disk to free up space in physical memory. Pages are written to disk only if they are changed while in physical memory, so they are likely to hold data, not code. This counter shows write operations, without regard to the number of pages written in each operation. This counter displays the difference between the values observed in the last two samples, divided by the duration of the sample interval.
53
The Browser performance object consists of counters that measure the rates of announcements, enumerations, and other Browser transmissions.
55
Announcements Server/sec is the rate at which the servers in this domain have announced themselves to this server.
57
Pool Paged Bytes is the size, in bytes, of the paged pool, an area of the system virtual memory that is used for objects that can be written to disk when they are not being used. Memory\\Pool Paged Bytes is calculated differently than Process\\Pool Paged Bytes, so it might not equal Process(_Total)\\Pool Paged Bytes. This counter displays the last observed value only; it is not an average.
59
Pool Nonpaged Bytes is the size, in bytes, of the nonpaged pool, an area of the system virtual memory that is used for objects that cannot be written to disk, but must remain in physical memory as long as they are allocated. Memory\\Pool Nonpaged Bytes is calculated differently than Process\\Pool Nonpaged Bytes, so it might not equal Process(_Total)\\Pool Nonpaged Bytes. This counter displays the last observed value only; it is not an average.
61
Pool Paged Allocs is the number of calls to allocate space in the paged pool. The paged pool is an area of the system virtual memory that is used for objects that can be written to disk when they are not being used. It is measured in numbers of calls to allocate space, regardless of the amount of space allocated in each call. This counter displays the last observed value only; it is not an average.
63
Pool Paged Resident Bytes is the size, in bytes, of the portion of the paged pool that is currently resident and active in physical memory. The paged pool is an area of the system virtual memory that is used for objects that can be written to disk when they are not being used. This counter displays the last observed value only; it is not an average.
65
Pool Nonpaged Allocs is the number of calls to allocate space in the nonpaged pool. The nonpaged pool is an area of system memory area for objects that cannot be written to disk, and must remain in physical memory as long as they are allocated. It is measured in numbers of calls to allocate space, regardless of the amount of space allocated in each call. This counter displays the last observed value only; it is not an average.
67
Bytes Total/sec is the total rate of bytes sent to or received from the network by the protocol, but only for the frames (packets) which carry data. This is the sum of Frame Bytes/sec and Datagram Bytes/sec.
69
System Code Total Bytes is the size, in bytes, of the pageable operating system code currently mapped into the system virtual address space. This value is calculated by summing the bytes in Ntoskrnl.exe, Hal.dll, the boot drivers, and file systems loaded by Ntldr/osloader. This counter does not include code that must remain in physical memory and cannot be written to disk. This counter displays the last observed value only; it is not an average.
71
System Code Resident Bytes is the size, in bytes, of the pageable operating system code that is currently resident and active in physical memory. This value is a component of Memory\\System Code Total Bytes. Memory\\System Code Resident Bytes (and Memory\\System Code Total Bytes) does not include code that must remain in physical memory and cannot be written to disk. This counter displays the last observed value only; it is not an average.
73
System Driver Total Bytes is the size, in bytes, of the pageable virtual memory currently being used by device drivers. Pageable memory can be written to disk when it is not being used. It includes both physical memory (Memory\\System Driver Resident Bytes) and code and data paged to disk. It is a component of Memory\\System Code Total Bytes. This counter displays the last observed value only; it is not an average.
75
System Driver Resident Bytes is the size, in bytes, of the pageable physical memory being used by device drivers. It is the working set (physical memory area) of the drivers. This value is a component of Memory\\System Driver Total Bytes, which also includes driver memory that has been written to disk. Neither Memory\\System Driver Resident Bytes nor Memory\\System Driver Total Bytes includes memory that cannot be written to disk.
77
System Cache Resident Bytes is the size, in bytes, of the portion of the system file cache which is currently resident and active in physical memory. The System Cache Resident Bytes and Memory\\Cache Bytes counters are equivalent. This counter displays the last observed value only; it is not an average.
79
Announcements Domain/sec is the rate at which a domain has announced itself to the network.
81
Election Packets/sec is the rate at which browser election packets have been received by this workstation.
83
Mailslot Writes/sec is the rate at which mailslot messages have been successfully received.
85
Server List Requests/sec is the rate at which requests to retrieve a list of browser servers have been processed by this workstation.
87
The Cache performance object consists of counters that monitor the file system cache, an area of physical memory that stores recently used data as long as possible to permit access to the data without having to read from the disk. Because applications typically use the cache, the cache is monitored as an indicator of application I/O operations. When memory is plentiful, the cache can grow, but when memory is scarce, the cache can become too small to be effective.
89
Data Maps/sec is the frequency that a file system such as NTFS, maps a page of a file into the file system cache to read the page.
91
Sync Data Maps/sec counts the frequency that a file system, such as NTFS, maps a page of a file into the file system cache to read the page, and wishes to wait for the page to be retrieved if it is not in main memory.
93
Async Data Maps/sec is the frequency that an application using a file system, such as NTFS, to map a page of a file into the file system cache to read the page, and does not wait for the page to be retrieved if it is not in main memory.
95
Data Map Hits is the percentage of data maps in the file system cache that could be resolved without having to retrieve a page from the disk, because the page was already in physical memory.
97
Data Map Pins/sec is the frequency of data maps in the file system cache that resulted in pinning a page in main memory, an action usually preparatory to writing to the file on disk. While pinned, a page's physical address in main memory and virtual address in the file system cache will not be altered.
99
Pin Reads/sec is the frequency of reading data into the file system cache preparatory to writing the data back to disk. Pages read in this fashion are pinned in memory at the completion of the read. While pinned, a page's physical address in the file system cache will not be altered.
101
Sync Pin Reads/sec is the frequency of reading data into the file system cache preparatory to writing the data back to disk. Pages read in this fashion are pinned in memory at the completion of the read. The file system will not regain control until the page is pinned in the file system cache, in particular if the disk must be accessed to retrieve the page. While pinned, a page's physical address in the file system cache will not be altered.
103
Async Pin Reads/sec is the frequency of reading data into the file system cache preparatory to writing the data back to disk. Pages read in this fashion are pinned in memory at the completion of the read. The file system will regain control immediately even if the disk must be accessed to retrieve the page. While pinned, a page's physical address will not be altered.
105
Pin Read Hits is the percentage of pin read requests that hit the file system cache, i.e., did not require a disk read in order to provide access to the page in the file system cache. While pinned, a page's physical address in the file system cache will not be altered. The LAN Redirector uses this method for retrieving data from the cache, as does the LAN Server for small transfers. This is usually the method used by the disk file systems as well.
107
Copy Reads/sec is the frequency of reads from pages of the file system cache that involve a memory copy of the data from the cache to the application's buffer. The LAN Redirector uses this method for retrieving information from the file system cache, as does the LAN Server for small transfers. This is a method used by the disk file systems as well.
109
Sync Copy Reads/sec is the frequency of reads from pages of the file system cache that involve a memory copy of the data from the cache to the application's buffer. The file system will not regain control until the copy operation is complete, even if the disk must be accessed to retrieve the page.
111
Async Copy Reads/sec is the frequency of reads from pages of the file system cache that involve a memory copy of the data from the cache to the application's buffer. The application will regain control immediately even if the disk must be accessed to retrieve the page.
113
Copy Read Hits is the percentage of cache copy read requests that hit the cache, that is, they did not require a disk read in order to provide access to the page in the cache. A copy read is a file read operation that is satisfied by a memory copy from a page in the cache to the application's buffer. The LAN Redirector uses this method for retrieving information from the cache, as does the LAN Server for small transfers. This is a method used by the disk file systems as well.
115
MDL Reads/sec is the frequency of reads from the file system cache that use a Memory Descriptor List (MDL) to access the data. The MDL contains the physical address of each page involved in the transfer, and thus can employ a hardware Direct Memory Access (DMA) device to effect the copy. The LAN Server uses this method for large transfers out of the server.
117
Sync MDL Reads/sec is the frequency of reads from the file system cache that use a Memory Descriptor List (MDL) to access the pages. The MDL contains the physical address of each page in the transfer, thus permitting Direct Memory Access (DMA) of the pages. If the accessed page(s) are not in main memory, the caller will wait for the pages to fault in from the disk.
119
Async MDL Reads/sec is the frequency of reads from the file system cache that use a Memory Descriptor List (MDL) to access the pages. The MDL contains the physical address of each page in the transfer, thus permitting Direct Memory Access (DMA) of the pages. If the accessed page(s) are not in main memory, the calling application program will not wait for the pages to fault in from disk.
121
MDL Read Hits is the percentage of Memory Descriptor List (MDL) Read requests to the file system cache that hit the cache, i.e., did not require disk accesses in order to provide memory access to the page(s) in the cache.
123
Read Aheads/sec is the frequency of reads from the file system cache in which the Cache detects sequential access to a file. The read aheads permit the data to be transferred in larger blocks than those being requested by the application, reducing the overhead per access.
125
Fast Reads/sec is the frequency of reads from the file system cache that bypass the installed file system and retrieve the data directly from the cache. Normally, file I/O requests invoke the appropriate file system to retrieve data from a file, but this path permits direct retrieval of data from the cache without file system involvement if the data is in the cache. Even if the data is not in the cache, one invocation of the file system is avoided.
127
Sync Fast Reads/sec is the frequency of reads from the file system cache that bypass the installed file system and retrieve the data directly from the cache. Normally, file I/O requests invoke the appropriate file system to retrieve data from a file, but this path permits direct retrieval of data from the cache without file system involvement if the data is in the cache. Even if the data is not in the cache, one invocation of the file system is avoided. If the data is not in the cache, the request (application program call) will wait until the data has been retrieved from disk.
129
Async Fast Reads/sec is the frequency of reads from the file system cache that bypass the installed file system and retrieve the data directly from the cache. Normally, file I/O requests will invoke the appropriate file system to retrieve data from a file, but this path permits data to be retrieved from the cache directly (without file system involvement) if the data is in the cache. Even if the data is not in the cache, one invocation of the file system is avoided. If the data is not in the cache, the request (application program call) will not wait until the data has been retrieved from disk, but will get control immediately.
131
Fast Read Resource Misses/sec is the frequency of cache misses necessitated by the lack of available resources to satisfy the request.
133
Fast Read Not Possibles/sec is the frequency of attempts by an Application Program Interface (API) function call to bypass the file system to get to data in the file system cache that could not be honored without invoking the file system.
135
Lazy Write Flushes/sec is the rate at which the Lazy Writer thread has written to disk. Lazy Writing is the process of updating the disk after the page has been changed in memory, so that the application that changed the file does not have to wait for the disk write to be complete before proceeding. More than one page can be transferred by each write operation.
137
Lazy Write Pages/sec is the rate at which the Lazy Writer thread has written to disk. Lazy Writing is the process of updating the disk after the page has been changed in memory, so that the application that changed the file does not have to wait for the disk write to be complete before proceeding. More than one page can be transferred on a single disk write operation.
139
Data Flushes/sec is the rate at which the file system cache has flushed its contents to disk as the result of a request to flush or to satisfy a write-through file write request. More than one page can be transferred on each flush operation.
141
Data Flush Pages/sec is the number of pages the file system cache has flushed to disk as a result of a request to flush or to satisfy a write-through file write request. More than one page can be transferred on each flush operation.
143
% User Time is the percentage of elapsed time the processor spends in the user mode. User mode is a restricted processing mode designed for applications, environment subsystems, and integral subsystems. The alternative, privileged mode, is designed for operating system components and allows direct access to hardware and all memory. The operating system switches application threads to privileged mode to access operating system services. This counter displays the average busy time as a percentage of the sample time.
145
% Privileged Time is the percentage of elapsed time that the process threads spent executing code in privileged mode. When a Windows system service in called, the service will often run in privileged mode to gain access to system-private data. Such data is protected from access by threads executing in user mode. Calls to the system can be explicit or implicit, such as page faults or interrupts. Unlike some early operating systems, Windows uses process boundaries for subsystem protection in addition to the traditional protection of user and privileged modes. Some work done by Windows on behalf of the application might appear in other subsystem processes in addition to the privileged time in the process.
147
Context Switches/sec is the combined rate at which all processors on the computer are switched from one thread to another. Context switches occur when a running thread voluntarily relinquishes the processor, is preempted by a higher priority ready thread, or switches between user-mode and privileged (kernel) mode to use an Executive or subsystem service. It is the sum of Thread\\Context Switches/sec for all threads running on all processors in the computer and is measured in numbers of switches. There are context switch counters on the System and Thread objects. This counter displays the difference between the values observed in the last two samples, divided by the duration of the sample interval.
149
Interrupts/sec is the average rate, in incidents per second, at which the processor received and serviced hardware interrupts. It does not include deferred procedure calls (DPCs), which are counted separately. This value is an indirect indicator of the activity of devices that generate interrupts, such as the system clock, the mouse, disk drivers, data communication lines, network interface cards, and other peripheral devices. These devices normally interrupt the processor when they have completed a task or require attention. Normal thread execution is suspended. The system clock typically interrupts the processor every 10 milliseconds, creating a background of interrupt activity. This counter displays the difference between the values observed in the last two samples, divided by the duration of the sample interval.
151
System Calls/sec is the combined rate of calls to operating system service routines by all processes running on the computer. These routines perform all of the basic scheduling and synchronization of activities on the computer, and provide access to non-graphic devices, memory management, and name space management. This counter displays the difference between the values observed in the last two samples, divided by the duration of the sample interval.
153
Level 1 TLB Fills/sec is the frequency of faults that occur when reference is made to memory whose Page Table Entry (PTE) is not in the Translation Lookaside Buffer (TLB). On some computers this fault is handled by software loading the PTE into the TLB, and this counter is incremented.
155
Level 2 TLB Fills/sec is the frequency of faults that occur when reference is made to memory whose Page Table Entry (PTE) is not in the Translation Lookaside Buffer (TLB), nor is the page containing the PTE. On some computers this fault is handled by software loading the PTE into the TLB, and this counter is incremented.
157
% User Time is the percentage of elapsed time that the process threads spent executing code in user mode. Applications, environment subsystems, and integral subsystems execute in user mode. Code executing in user mode cannot damage the integrity of the Windows executive, kernel, and device drivers. Unlike some early operating systems, Windows uses process boundaries for subsystem protection in addition to the traditional protection of user and privileged modes. Some work done by Windows on behalf of the application might appear in other subsystem processes in addition to the privileged time in the process.
159
% Privileged Time is the percentage of elapsed time that the process threads spent executing code in privileged mode. When a Windows system service is called, the service will often run in privileged mode to gain access to system-private data. Such data is protected from access by threads executing in user mode. Calls to the system can be explicit or implicit, such as page faults or interrupts. Unlike some early operating systems, Windows uses process boundaries for subsystem protection in addition to the traditional protection of user and privileged modes. Some work done by Windows on behalf of the application might appear in other subsystem processes in addition to the privileged time in the process.
161
Enumerations Server/sec is the rate at which server browse requests have been processed by this workstation.
163
Enumerations Domain/sec is the rate at which domain browse requests have been processed by this workstation.
165
Enumerations Other/sec is the rate at which browse requests processed by this workstation are not domain or server browse requests.
167
Missed Server Announcements is the number of server announcements that have been missed due to configuration or allocation limits.
169
Missed Mailslot Datagrams is the number of Mailslot Datagrams that have been discarded due to configuration or allocation limits.
171
Missed Server List Requests is the number of requests to retrieve a list of browser servers that were received by this workstation, but could not be processed.
173
Virtual Bytes Peak is the maximum size, in bytes, of virtual address space the process has used at any one time. Use of virtual address space does not necessarily imply corresponding use of either disk or main memory pages. However, virtual space is finite, and the process might limit its ability to load libraries.
175
Virtual Bytes is the current size, in bytes, of the virtual address space the process is using. Use of virtual address space does not necessarily imply corresponding use of either disk or main memory pages. Virtual space is finite, and the process can limit its ability to load libraries.
177
Page Faults/sec is the rate at which page faults by the threads executing in this process are occurring. A page fault occurs when a thread refers to a virtual memory page that is not in its working set in main memory. This may not cause the page to be fetched from disk if it is on the standby list and hence already in main memory, or if it is in use by another process with whom the page is shared.
179
Working Set Peak is the maximum size, in bytes, of the Working Set of this process at any point in time. The Working Set is the set of memory pages touched recently by the threads in the process. If free memory in the computer is above a threshold, pages are left in the Working Set of a process even if they are not in use. When free memory falls below a threshold, pages are trimmed from Working Sets. If they are needed they will then be soft-faulted back into the Working Set before they leave main memory.
181
Working Set is the current size, in bytes, of the Working Set of this process. The Working Set is the set of memory pages touched recently by the threads in the process. If free memory in the computer is above a threshold, pages are left in the Working Set of a process even if they are not in use. When free memory falls below a threshold, pages are trimmed from Working Sets. If they are needed they will then be soft-faulted back into the Working Set before leaving main memory.
183
Page File Bytes Peak is the maximum amount of virtual memory, in bytes, that this process has reserved for use in the paging file(s). Paging files are used to store pages of memory used by the process that are not contained in other files. Paging files are shared by all processes, and the lack of space in paging files can prevent other processes from allocating memory. If there is no paging file, this counter reflects the maximum amount of virtual memory that the process has reserved for use in physical memory.
185
Page File Bytes is the current amount of virtual memory, in bytes, that this process has reserved for use in the paging file(s). Paging files are used to store pages of memory used by the process that are not contained in other files. Paging files are shared by all processes, and the lack of space in paging files can prevent other processes from allocating memory. If there is no paging file, this counter reflects the current amount of virtual memory that the process has reserved for use in physical memory.
187
Private Bytes is the current size, in bytes, of memory that this process has allocated that cannot be shared with other processes.
189
% Processor Time is the percentage of elapsed time that all of process threads used the processor to execution instructions. An instruction is the basic unit of execution in a computer, a thread is the object that executes instructions, and a process is the object created when a program is run. Code executed to handle some hardware interrupts and trap conditions are included in this count.
191
% Processor Time is the percentage of elapsed time that all of process threads used the processor to execution instructions. An instruction is the basic unit of execution in a computer, a thread is the object that executes instructions, and a process is the object created when a program is run. Code executed to handle some hardware interrupts and trap conditions are included in this count.
193
% User Time is the percentage of elapsed time that this thread has spent executing code in user mode. Applications, environment subsystems, and integral subsystems execute in user mode. Code executing in user mode cannot damage the integrity of the Windows NT Executive, Kernel, and device drivers. Unlike some early operating systems, Windows NT uses process boundaries for subsystem protection in addition to the traditional protection of user and privileged modes. These subsystem processes provide additional protection. Therefore, some work done by Windows NT on behalf of your application might appear in other subsystem processes in addition to the privileged time in your process.
195
% Privileged Time is the percentage of elapsed time that the process threads spent executing code in privileged mode. When a Windows system service in called, the service will often run in privileged mode to gain access to system-private data. Such data is protected from access by threads executing in user mode. Calls to the system can be explicit or implicit, such as page faults or interrupts. Unlike some early operating systems, Windows uses process boundaries for subsystem protection in addition to the traditional protection of user and privileged modes. Some work done by Windows on behalf of the application might appear in other subsystem processes in addition to the privileged time in the process.
197
Context Switches/sec is the rate of switches from one thread to another. Thread switches can occur either inside of a single process or across processes. A thread switch can be caused either by one thread asking another for information, or by a thread being preempted by another, higher priority thread becoming ready to run. Unlike some early operating systems, Windows NT uses process boundaries for subsystem protection in addition to the traditional protection of user and privileged modes. These subsystem processes provide additional protection. Therefore, some work done by Windows NT on behalf of an application appear in other subsystem processes in addition to the privileged time in the application. Switching to the subsystem process causes one Context Switch in the application thread. Switching back causes another Context Switch in the subsystem thread.
199
Current Disk Queue Length is the number of requests outstanding on the disk at the time the performance data is collected. It also includes requests in service at the time of the collection. This is a instantaneous snapshot, not an average over the time interval. Multi-spindle disk devices can have multiple requests that are active at one time, but other concurrent requests are awaiting service. This counter might reflect a transitory high or low queue length, but if there is a sustained load on the disk drive, it is likely that this will be consistently high. Requests experience delays proportional to the length of this queue minus the number of spindles on the disks. For good performance, this difference should average less than two.
201
% Disk Time is the percentage of elapsed time that the selected disk drive was busy servicing read or write requests.
203
% Disk Read Time is the percentage of elapsed time that the selected disk drive was busy servicing read requests.
205
% Disk Write Time is the percentage of elapsed time that the selected disk drive was busy servicing write requests.
207
Avg. Disk sec/Transfer is the time, in seconds, of the average disk transfer.
209
Avg. Disk sec/Read is the average time, in seconds, of a read of data from the disk.
211
Avg. Disk sec/Write is the average time, in seconds, of a write of data to the disk.
213
Disk Transfers/sec is the rate of read and write operations on the disk.
215
Disk Reads/sec is the rate of read operations on the disk.
217
Disk Writes/sec is the rate of write operations on the disk.
219
Disk Bytes/sec is the rate bytes are transferred to or from the disk during write or read operations.
221
Disk Read Bytes/sec is the rate at which bytes are transferred from the disk during read operations.
223
Disk Write Bytes/sec is rate at which bytes are transferred to the disk during write operations.
225
Avg. Disk Bytes/Transfer is the average number of bytes transferred to or from the disk during write or read operations.
227
Avg. Disk Bytes/Read is the average number of bytes transferred from the disk during read operations.
229
Avg. Disk Bytes/Write is the average number of bytes transferred to the disk during write operations.
231
The Process performance object consists of counters that monitor running application program and system processes. All the threads in a process share the same address space and have access to the same data.
233
The Thread performance object consists of counters that measure aspects of thread behavior. A thread is the basic object that executes instructions on a processor. All running processes have at least one thread.
235
The Physical Disk performance object consists of counters that monitor hard or fixed disk drive on a computer. Disks are used to store file, program, and paging data and are read to retrieve these items, and written to record changes to them. The values of physical disk counters are sums of the values of the logical disks (or partitions) into which they are divided.
237
The Logical Disk performance object consists of counters that monitor logical partitions of a hard or fixed disk drives. Performance Monitor identifies logical disks by their a drive letter, such as C.
239
The Processor performance object consists of counters that measure aspects of processor activity. The processor is the part of the computer that performs arithmetic and logical computations, initiates operations on peripherals, and runs the threads of processes. A computer can have multiple processors. The processor object represents each processor as an instance of the object.
241
% Total Processor Time is the average percentage of time that all processors on the computer are executing non-idle threads. This counter was designed as the primary indicator of processor activity on multiprocessor computers. It is equal to the sum of Process: % Processor Time for all processors, divided by the number of processors. It is calculated by summing the time that all processors spend executing the thread of the Idle process in each sample interval, subtracting that value from 100%, and dividing the difference by the number of processors on the computer. (Each processor has an Idle thread which consumes cycles when no other threads are ready to run). For example, on a multiprocessor computer, a value of 50% means that all processors are busy for half of the sample interval, or that half of the processors are busy for all of the sample interval. This counter displays the average percentage of busy time observed during the sample interval. It is calculated by monitoring the time the service was inactive, and then subtracting that value from 100%.
243
% Total User Time is the average percentage of non-idle time all processors spend in user mode. It is the sum of Processor: % User Time for all processors on the computer, divided by the number of processors. System: % Total User Time and System: % Total Privileged Time sum to % Total Processor Time, but not always to 100%. (User mode is a restricted processing mode designed for applications, environment subsystems, and integral subsystems. The alternative, privileged mode, is designed for operating system components and allows direct access to hardware and all memory. The operating system switches application threads to privileged mode to access operating system services). This counter displays the average busy time as a percentage of the sample time.
245
% Total Privileged Time is the average percentage of non-idle time all processors spend in privileged (kernel) mode. It is the sum of Processor: % Privileged Time for all processors on the computer, divided by the number of processors. System: % Total User Time and System: % Total Privileged Time sum to % Total Processor Time, but not always to 100%. (Privileged mode is an processing mode designed for operating system components which allows direct access to hardware and all memory. The operating system switches application threads to privileged mode to access operating system services. The alternative, user mode, is a restricted processing mode designed for applications and environment subsystems). This counter displays the average busy time as a percentage of the sample time.
247
Total Interrupts/sec is the combined rate of hardware interrupts received and serviced by all processors on the computer It is the sum of Processor: Interrupts/sec for all processors, and divided by the number of processors, and is measured in numbers of interrupts. It does not include DPCs, which are counted separately. This value is an indirect indicator of the activity of devices that generate interrupts, such as the system timer, the mouse, disk drivers, data communication lines, network interface cards and other peripheral devices. These devices normally interrupt the processor when they have completed a task or require attention. Normal thread execution is suspended during interrupts. Most system clocks interrupt the processor every 10 milliseconds, creating a background of interrupt activity. This counter displays the difference between the values observed in the last two samples, divided by the duration of the sample interval.
249
Processes is the number of processes in the computer at the time of data collection. This is an instantaneous count, not an average over the time interval. Each process represents the running of a program.
251
Threads is the number of threads in the computer at the time of data collection. This is an instantaneous count, not an average over the time interval. A thread is the basic executable entity that can execute instructions in a processor.
253
Events is the number of events in the computer at the time of data collection. This is an instantaneous count, not an average over the time interval. An event is used when two or more threads try to synchronize execution.
255
Semaphores is the number of semaphores in the computer at the time of data collection. This is an instantaneous count, not an average over the time interval. Threads use semaphores to obtain exclusive access to data structures that they share with other threads.
257
Mutexes counts the number of mutexes in the computer at the time of data collection. This is an instantaneous count, not an average over the time interval. Mutexes are used by threads to assure only one thread is executing a particular section of code.
259
Sections is the number of sections in the computer at the time of data collection. This is an instantaneous count, not an average over the time interval. A section is a portion of virtual memory created by a process for storing data. A process can share sections with other processes.
261
The Object performance object consists of counters that monitor logical objects in the system, such as processes, threads, mutexes, and semaphores. This information can be used to detect the unnecessary consumption of computer resources. Each object requires memory to store basic information about the object.
263
The Redirector performance object consists of counter that monitor network connections originating at the local computer.
265
Bytes Received/sec is the rate of bytes coming in to the Redirector from the network. It includes all application data as well as network protocol information (such as packet headers).
267
Packets Received/sec is the rate at which the Redirector is receiving packets (also called SMBs or Server Message Blocks). Network transmissions are divided into packets. The average number of bytes received in a packet can be obtained by dividing Bytes Received/sec by this counter. Some packets received might not contain incoming data (for example an acknowledgment to a write made by the Redirector would count as an incoming packet).
269
Read Bytes Paging/sec is the rate at which the Redirector is attempting to read bytes in response to page faults. Page faults are caused by loading of modules (such as programs and libraries), by a miss in the Cache (see Read Bytes Cache/sec), or by files directly mapped into the address space of applications (a high-performance feature of Windows NT).
271
Read Bytes Non-Paging/sec are those bytes read by the Redirector in response to normal file requests by an application when they are redirected to come from another computer. In addition to file requests, this counter includes other methods of reading across the network such as Named Pipes and Transactions. This counter does not count network protocol information, just application data.
273
Read Bytes Cache/sec is the rate at which applications are accessing the file system cache by using the Redirector. Some of these data requests are satisfied by retrieving the data from the cache. Requests that miss the Cache cause a page fault (see Read Bytes Paging/sec).
275
Read Bytes Network/sec is the rate at which applications are reading data across the network. This occurs when data sought in the file system cache is not found there and must be retrieved from the network. Dividing this value by Bytes Received/sec indicates the proportion of application data traveling across the network. (see Bytes Received/sec).
277
Bytes Transmitted/sec is the rate at which bytes are leaving the Redirector to the network. It includes all application data as well as network protocol information (such as packet headers and the like).
279
Packets Transmitted/sec is the rate at which the Redirector is sending packets (also called SMBs or Server Message Blocks). Network transmissions are divided into packets. The average number of bytes transmitted in a packet can be obtained by dividing Bytes Transmitted/sec by this counter.
281
Write Bytes Paging/sec is the rate at which the Redirector is attempting to write bytes changed in the pages being used by applications. The program data changed by modules (such as programs and libraries) that were loaded over the network are 'paged out' when no longer needed. Other output pages come from the file system cache (see Write Bytes Cache/sec).
283
Write Bytes Non-Paging/sec is the rate at which bytes are written by the Redirector in response to normal file outputs by an application when they are redirected to another computer. In addition to file requests, this count includes other methods of writing across the network, such as Named Pipes and Transactions. This counter does not count network protocol information, just application data.
285
Write Bytes Cache/sec is the rate at which applications on your computer are writing to the file system cache by using the Redirector. The data might not leave your computer immediately; it can be retained in the cache for further modification before being written to the network. This saves network traffic. Each write of a byte into the cache is counted here.
287
Write Bytes Network/sec is the rate at which applications are writing data across the network. This occurs when the file system cache is bypassed, such as for Named Pipes or Transactions, or when the cache writes the bytes to disk to make room for other data. Dividing this counter by Bytes Transmitted/sec will indicate the proportion of application data being to the network (see Transmitted Bytes/sec).
289
File Read Operations/sec is the rate at which applications are asking the Redirector for data. Each call to a file system or similar Application Program Interface (API) call counts as one operation.
291
Read Operations Random/sec counts the rate at which, on a file-by-file basis, reads are made that are not sequential. If a read is made using a particular file handle, and then is followed by another read that is not immediately the contiguous next byte, this counter is incremented by one.
293
Read Packets/sec is the rate at which read packets are being placed on the network. Each time a single packet is sent with a request to read data remotely, this counter is incremented by one.
295
Reads Large/sec is the rate at which reads over 2 times the server's negotiated buffer size are made by applications. Too many of these could place a strain on server resources. This counter is incremented once for each read. It does not count packets.
297
Read Packets Small/sec is the rate at which reads less than one-fourth of the server's negotiated buffer size are made by applications. Too many of these could indicate a waste of buffers on the server. This counter is incremented once for each read. It does not count packets.
299
File Write Operations/sec is the rate at which applications are sending data to the Redirector. Each call to a file system or similar Application Program Interface (API) call counts as one operation.
301
Write Operations Random/sec is the rate at which, on a file-by-file basis, writes are made that are not sequential. If a write is made using a particular file handle, and then is followed by another write that is not immediately the next contiguous byte, this counter is incremented by one.
303
Write Packets/sec is the rate at which writes are being sent to the network. Each time a single packet is sent with a request to write remote data, this counter is incremented by one.
305
Writes Large/sec is the rate at which writes are made by applications that are over 2 times the server's negotiated buffer size. Too many of these could place a strain on server resources. This counter is incremented once for each write: it counts writes, not packets.
307
Write Packets Small/sec is the rate at which writes are made by applications that are less than one-fourth of the server's negotiated buffer size. Too many of these could indicate a waste of buffers on the server. This counter is incremented once for each write: it counts writes, not packets.
309
Reads Denied/sec is the rate at which the server is unable to accommodate requests for Raw Reads. When a read is much larger than the server's negotiated buffer size, the Redirector requests a Raw Read which, if granted, would permit the transfer of the data without lots of protocol overhead on each packet. To accomplish this the server must lock out other requests, so the request is denied if the server is really busy.
311
Writes Denied/sec is the rate at which the server is unable to accommodate requests for Raw Writes. When a write is much larger than the server's negotiated buffer size, the Redirector requests a Raw Write which, if granted, would permit the transfer of the data without lots of protocol overhead on each packet. To accomplish this the server must lock out other requests, so the request is denied if the server is really busy.
313
Network Errors/sec is the rate at which serious unexpected errors are occurring. Such errors generally indicate that the Redirector and one or more Servers are having serious communication difficulties. For example an SMB (Server Message Block) protocol error is a Network Error. An entry is written to the System Event Log and provide details.
315
Server Sessions counts the total number of security objects the Redirector has managed. For example, a logon to a server followed by a network access to the same server will establish one connection, but two sessions.
317
Server Reconnects counts the number of times your Redirector has had to reconnect to a server in order to complete a new active request. You can be disconnected by the Server if you remain inactive for too long. Locally even if all your remote files are closed, the Redirector will keep your connections intact for (nominally) ten minutes. Such inactive connections are called Dormant Connections. Reconnecting is expensive in time.
319
Connects Core counts the number of connections you have to servers running the original MS-Net SMB protocol, including MS-Net itself and Xenix and VAX's.
321
Connects LAN Manager 2.0 counts connections to LAN Manager 2.0 servers, including LMX servers.
323
Connects LAN Manager 2.1 counts connections to LAN Manager 2.1 servers, including LMX servers.
325
Connects Windows NT counts the connections to Windows 2000 or earlier computers.
327
Server Disconnects counts the number of times a Server has disconnected your Redirector. See also Server Reconnects.
329
Server Sessions Hung counts the number of active sessions that are timed out and unable to proceed due to a lack of response from the remote server.
331
The Server performance object consists of counters that measure communication between the local computer and the network.
333
The number of bytes the server has received from the network. Indicates how busy the server is.
335
The number of bytes the server has sent on the network. Indicates how busy the server is.
337
Thread Wait Reason is only applicable when the thread is in the Wait state (see Thread State). It is 0 or 7 when the thread is waiting for the Executive, 1 or 8 for a Free Page, 2 or 9 for a Page In, 3 or 10 for a Pool Allocation, 4 or 11 for an Execution Delay, 5 or 12 for a Suspended condition, 6 or 13 for a User Request, 14 for an Event Pair High, 15 for an Event Pair Low, 16 for an LPC Receive, 17 for an LPC Reply, 18 for Virtual Memory, 19 for a Page Out; 20 and higher are not assigned at the time of this writing. Event Pairs are used to communicate with protected subsystems (see Context Switches).
339
% DPC Time is the percentage of time that the processor spent receiving and servicing deferred procedure calls (DPCs) during the sample interval. DPCs are interrupts that run at a lower priority than standard interrupts. % DPC Time is a component of % Privileged Time because DPCs are executed in privileged mode. They are counted separately and are not a component of the interrupt counters. This counter displays the average busy time as a percentage of the sample time.
341
The number of sessions that have been closed due to their idle time exceeding the AutoDisconnect parameter for the server. Shows whether the AutoDisconnect setting is helping to conserve resources.
343
The number of sessions that have been closed due to unexpected error conditions or sessions that have reached the autodisconnect timeout and have been disconnected normally. The autodisconnect timeout value represents the number of seconds that idle connections with no session attached to have before being disconnected automatically by a server. The default value is 30 seconds. This counter increments as a result of normal server operation, not as an indication of network problems or unexpected error condition.
345
The number of sessions that have terminated normally. Useful in interpreting the Sessions Times Out and Sessions Errored Out statistics--allows percentage calculations.
347
The number of sessions that have been forced to logoff. Can indicate how many sessions were forced to logoff due to logon time constraints.
349
The number of failed logon attempts to the server. Can indicate whether password guessing programs are being used to crack the security on the server.
351
The number of times opens on behalf of clients have failed with STATUS_ACCESS_DENIED. Can indicate whether somebody is randomly attempting to access files in hopes of getting at something that was not properly protected.
353
The number of times accesses to files opened successfully were denied. Can indicate attempts to access files without proper access authorization.
355
The number of times an internal Server Error was detected. Unexpected errors usually indicate a problem with the Server.
357
The number of times the server has rejected blocking SMBs due to insufficient count of free work items. Indicates whether the MaxWorkItem or MinFreeWorkItems server parameters might need to be adjusted.
359
The number of times STATUS_DATA_NOT_ACCEPTED was returned at receive indication time. This occurs when no work item is available or can be allocated to service the incoming request. Indicates whether the InitWorkItems or MaxWorkItems parameters might need to be adjusted.
361
The number of successful open attempts performed by the server of behalf of clients. Useful in determining the amount of file I/O, determining overhead for path-based operations, and for determining the effectiveness of open locks.
363
The number of files currently opened in the server. Indicates current server activity.
365
The number of sessions currently active in the server. Indicates current server activity.
367
The number of searches for files currently active in the server. Indicates current server activity.
369
The number of bytes of non-pageable computer memory the server is using. This value is useful for determining the values of the MaxNonpagedMemoryUsage value entry in the Windows NT Registry.
371
The number of times allocations from nonpaged pool have failed. Indicates that the computer's physical memory is too small.
373
The maximum number of bytes of nonpaged pool the server has had in use at any one point. Indicates how much physical memory the computer should have.
375
The number of bytes of pageable computer memory the server is currently using. Can help in determining good values for the MaxPagedMemoryUsage parameter.
377
The number of times allocations from paged pool have failed. Indicates that the computer's physical memory or paging file are too small.
379
The maximum number of bytes of paged pool the server has had allocated. Indicates the proper sizes of the Page File(s) and physical memory.
381
Server Announce Allocations Failed/sec is the rate at which server (or domain) announcements have failed due to lack of memory.
383
Mailslot Allocations Failed is the number of times the datagram receiver has failed to allocate a buffer to hold a user mailslot write.
385
Mailslot Receives Failed indicates the number of mailslot messages that could not be received due to transport failures.
387
Mailslot Writes Failed is the total number of mailslot messages that have been successfully received, but that could not be written to the mailslot.
389
Bytes Total/sec is the rate the Redirector is processing data bytes. This includes all application and file data in addition to protocol information such as packet headers.
391
File Data Operations/sec is the rate at which the Redirector is processing data operations. One operation should include many bytes, since each operation has overhead. The efficiency of this path can be determined by dividing the Bytes/sec by this counter to obtain the average number of bytes transferred per operation.
393
Current Commands counter indicates the number of pending commands from the local computer to all destination servers. If the Current Commands counter shows a high number and the local computer is idle, this may indicate a network-related problem or a redirector bottleneck on the local computer.
395
The number of bytes the server has sent to and received from the network. This value provides an overall indication of how busy the server is.
397
% Interrupt Time is the time the processor spends receiving and servicing hardware interrupts during sample intervals. This value is an indirect indicator of the activity of devices that generate interrupts, such as the system clock, the mouse, disk drivers, data communication lines, network interface cards and other peripheral devices. These devices normally interrupt the processor when they have completed a task or require attention. Normal thread execution is suspended during interrupts. Most system clocks interrupt the processor every 10 milliseconds, creating a background of interrupt activity. suspends normal thread execution during interrupts. This counter displays the average busy time as a percentage of the sample time.
399
The NWLink NetBIOS performance object consists of counters that monitor IPX transport rates and connections.
401
Packets/sec is the rate the Redirector is processing data packets. One packet includes (hopefully) many bytes. We say hopefully here because each packet has protocol overhead. You can determine the efficiency of this path by dividing the Bytes/sec by this counter to determine the average number of bytes transferred/packet. You can also divide this counter by Operations/sec to determine the average number of packets per operation, another measure of efficiency.
405
Context Blocks Queued per second is the rate at which work context blocks had to be placed on the server's FSP queue to await server action.
407
File Data Operations/ sec is the combined rate of read and write operations on all logical disks on the computer. This is the inverse of System: File Control Operations/sec. This counter displays the difference between the values observed in the last two samples, divided by the duration of the sample interval.
409
% Free Space is the percentage of total usable space on the selected logical disk drive that was free.
411
Free Megabytes displays the unallocated space, in megabytes, on the disk drive in megabytes. One megabyte is equal to 1,048,576 bytes.
413
Connections Open is the number of connections currently open for this protocol. This counter shows the current count only and does not accumulate over time.
415
Connections No Retries is the total count of connections that were successfully made on the first try. This number is an accumulator and shows a running total.
417
Connections With Retries is the total count of connections that were made after retrying the attempt. A retry occurs when the first connection attempt failed. This number is an accumulator and shows a running total.
419
Disconnects Local is the number of session disconnections that were initiated by the local computer. This number is an accumulator and shows a running total.
421
Disconnects Remote is the number of session disconnections that were initiated by the remote computer. This number is an accumulator and shows a running total.
423
Failures Link is the number of connections that were dropped due to a link failure. This number is an accumulator and shows a running total.
425
Failures Adapter is the number of connections that were dropped due to an adapter failure. This number is an accumulator and shows a running total.
427
Connection Session Timeouts is the number of connections that were dropped due to a session timeout. This number is an accumulator and shows a running total.
429
Connections Canceled is the number of connections that were canceled. This number is an accumulator and shows a running total.
431
Failures Resource Remote is the number of connections that failed because of resource problems or shortages on the remote computer. This number is an accumulator and shows a running total.
433
Failures Resource Local is the number of connections that failed because of resource problems or shortages on the local computer. This number is an accumulator and shows a running total.
435
Failures Not Found is the number of connection attempts that failed because the remote computer could not be found. This number is an accumulator and shows a running total.
437
Failures No Listen is the number of connections that were rejected because the remote computer was not listening for connection requests.
439
Datagrams/sec is the rate at which datagrams are processed by the computer. This counter displays the sum of datagrams sent and datagrams received. A datagram is a connectionless packet whose delivery to a remote is not guaranteed.
441
Datagram Bytes/sec is the rate at which datagram bytes are processed by the computer. This counter is the sum of datagram bytes that are sent as well as received. A datagram is a connectionless packet whose delivery to a remote is not guaranteed.
443
Datagrams Sent/sec is the rate at which datagrams are sent from the computer. A datagram is a connectionless packet whose delivery to a remote computer is not guaranteed.
445
Datagram Bytes Sent/sec is the rate at which datagram bytes are sent from the computer. A datagram is a connectionless packet whose delivery to a remote computer is not guaranteed.
447
Datagrams Received/sec is the rate at which datagrams are received by the computer. A datagram is a connectionless packet whose delivery to a remote computer is not guaranteed.
449
Datagram Bytes Received/sec is the rate at which datagram bytes are received by the computer. A datagram is a connectionless packet whose delivery to a remote computer is not guaranteed.
451
Packets/sec is the rate at which packets are processed by the computer. This count is the sum of Packets Sent and Packets Received per second. This counter includes all packets processed: control as well as data packets.
453
Packets Sent/sec is the rate at which packets are sent by the computer. This counter counts all packets sent by the computer, i.e. control as well as data packets.
455
Packets Received/sec is the rate at which packets are received by the computer. This counter counts all packets processed: control as well as data packets.
457
Frames/sec is the rate at which data frames (or packets) are processed by the computer. This counter is the sum of data frames sent and data frames received. This counter only counts those frames (packets) that carry data.
459
Frame Bytes/sec is the rate at which data bytes are processed by the computer. This counter is the sum of data frame bytes sent and received. This counter only counts the byte in frames (packets) that carry data.
461
Frames Sent/sec is the rate at which data frames are sent by the computer. This counter only counts the frames (packets) that carry data.
463
Frame Bytes Sent/sec is the rate at which data bytes are sent by the computer. This counter only counts the bytes in frames (packets) that carry data.
465
Frames Received/sec is the rate at which data frames are received by the computer. This counter only counts the frames (packets) that carry data.
467
Frame Bytes Received/sec is the rate at which data bytes are received by the computer. This counter only counts the frames (packets) that carry data.
469
Frames Re-Sent/sec is the rate at which data frames (packets) are re-sent by the computer. This counter only counts the frames or packets that carry data.
471
Frame Bytes Re-Sent/sec is the rate at which data bytes are re-sent by the computer. This counter only counts the bytes in frames that carry data.
473
Frames Rejected/sec is the rate at which data frames are rejected. This counter only counts the frames (packets) that carry data.
475
Frame Bytes Rejected/sec is the rate at which data bytes are rejected. This counter only counts the bytes in data frames (packets) that carry data.
477
Expirations Response is the count of T1 timer expirations.
479
Expirations Ack is the count of T2 timer expirations.
481
Window Send Maximum is the maximum number of bytes of data that will be sent before waiting for an acknowledgment from the remote computer.
483
Window Send Average is the running average number of data bytes that were sent before waiting for an acknowledgment from the remote computer.
485
Piggyback Ack Queued/sec is the rate at which piggybacked acknowledgments are queued. Piggyback acknowledgments are acknowledgments to received packets that are to be included in the next outgoing packet to the remote computer.
487
Piggyback Ack Timeouts is the number of times that a piggyback acknowledgment could not be sent because there was no outgoing packet to the remote on which to piggyback. A piggyback ack is an acknowledgment to a received packet that is sent along in an outgoing data packet to the remote computer. If no outgoing packet is sent within the timeout period, then an ack packet is sent and this counter is incremented.
489
The NWLink IPX performance object consists of counters that measure datagram transmission to and from computers using the IPX protocol.
491
The NWLink SPX performance object consist of counters that measure data transmission and session connections for computers using the SPX protocol.
493
The NetBEUI performance object consists of counters that measure data transmission for network activity which conforms to the NetBIOS End User Interface standard.
495
The NetBEUI Resource performance object consists of counters that track the use of buffers by the NetBEUI protocol.
497
Used Maximum is the maximum number of NetBEUI resources (buffers) in use at any point in time. This value is useful in sizing the maximum resources provided. The number in parentheses following the resource name is used to identify the resource in Event Log messages.
499
Used Average is the current number of resources (buffers) in use at this time. The number in parentheses following the resource name is used to identify the resource in Event Log messages.
501
Times Exhausted is the number of times all the resources (buffers) were in use. The number in parentheses following the resource name is used to identify the resource in Event Log messages.
503
The NBT Connection performance object consists of counters that measure the rates at which bytes are sent and received over the NBT connection between the local computer and a remote computer. The connection is identified by the name of the remote computer.
505
Bytes Received/sec is the rate at which bytes are received by the local computer over an NBT connection to some remote computer. All the bytes received by the local computer over the particular NBT connection are counted.
507
Bytes Sent/sec is the rate at which bytes are sent by the local computer over an NBT connection to some remote computer. All the bytes sent by the local computer over the particular NBT connection are counted.
509
Bytes Total/sec is the rate at which bytes are sent or received by the local computer over an NBT connection to some remote computer. All the bytes sent or received by the local computer over the particular NBT connection are counted.
511
The Network Interface performance object consists of counters that measure the rates at which bytes and packets are sent and received over a network connection. It includes counters that monitor connection errors.
513
Bytes Total/sec is the rate at which bytes are sent and received over each network adapter, including framing characters. Network Interface\Bytes Total/sec is a sum of Network Interface\Bytes Received/sec and Network Interface\Bytes Sent/sec.
515
Packets/sec is the rate at which packets are sent and received on the network interface.
517
Packets Received/sec is the rate at which packets are received on the network interface.
519
Packets Sent/sec is the rate at which packets are sent on the network interface.
521
Current Bandwidth is an estimate of the current bandwidth of the network interface in bits per second (BPS). For interfaces that do not vary in bandwidth or for those where no accurate estimation can be made, this value is the nominal bandwidth.
523
Bytes Received/sec is the rate at which bytes are received over each network adapter, including framing characters. Network Interface\Bytes Received/sec is a subset of Network Interface\Bytes Total/sec.
525
Packets Received Unicast/sec is the rate at which (subnet) unicast packets are delivered to a higher-layer protocol.
527
Packets Received Non-Unicast/sec is the rate at which non-unicast (subnet broadcast or subnet multicast) packets are delivered to a higher-layer protocol.
529
Packets Received Discarded is the number of inbound packets that were chosen to be discarded even though no errors had been detected to prevent their delivery to a higher-layer protocol. One possible reason for discarding packets could be to free up buffer space.
531
Packets Received Errors is the number of inbound packets that contained errors preventing them from being deliverable to a higher-layer protocol.
533
Packets Received Unknown is the number of packets received through the interface that were discarded because of an unknown or unsupported protocol.
535
Bytes Sent/sec is the rate at which bytes are sent over each network adapter, including framing characters. Network Interface\Bytes Sent/sec is a subset of Network Interface\Bytes Total/sec.
537
Packets Sent Unicast/sec is the rate at which packets are requested to be transmitted to subnet-unicast addresses by higher-level protocols. The rate includes the packets that were discarded or not sent.
539
Packets Sent Non-Unicast/sec is the rate at which packets are requested to be transmitted to non-unicast (subnet broadcast or subnet multicast) addresses by higher-level protocols. The rate includes the packets that were discarded or not sent.
541
Packets Outbound Discarded is the number of outbound packets that were chosen to be discarded even though no errors had been detected to prevent transmission. One possible reason for discarding packets could be to free up buffer space.
543
Packets Outbound Errors is the number of outbound packets that could not be transmitted because of errors.
545
Output Queue Length is the length of the output packet queue (in packets). If this is longer than two, there are delays and the bottleneck should be found and eliminated, if possible. Since the requests are queued by the Network Driver Interface Specification (NDIS) in this implementation, this will always be 0.
547
The IP performance object consists of counters that measure the rates at which IP datagrams are sent and received by using IP protocols. It also includes counters that monitor IP protocol errors.
549
Datagrams/sec is the rate, in incidents per second, at which IP datagrams were received from or sent to the interfaces, including those in error. Forwarded datagrams are not included in this rate.
551
Datagrams Received/sec is the rate, in incidents per second, at which IP datagrams are received from the interfaces, including those in error. Datagrams Received/sec is a subset of Datagrams/sec.
553
Datagrams Received Header Errors is the number of input datagrams that were discarded due to errors in the IP headers, including bad checksums, version number mismatch, other format errors, time-to-live exceeded, errors discovered in processing their IP options, etc.
555
Datagrams Received Address Errors is the number of input datagrams that were discarded because the IP address in their IP header destination field was not valid for the computer. This count includes invalid addresses (for example, 0.0. 0.0) and addresses of unsupported Classes (for example, Class E). For entities that are not IP gateways and do not forward datagrams, this counter includes datagrams that were discarded because the destination address was not a local address.
557
Datagrams Forwarded/sec is the rate, in incidents per second, at which attemps were made to find routes to forward input datagrams their final destination, because the local server was not the final IP destination. In servers that do not act as IP Gateways, this rate includes only packets that were source-routed via this entity, where the source-route option processing was successful.
559
Datagrams Received Unknown Protocol is the number of locally-addressed datagrams that were successfully received but were discarded because of an unknown or unsupported protocol.
561
Datagrams Received Discarded is the number of input IP datagrams that were discarded even though problems prevented their continued processing (for example, lack of buffer space). This counter does not include any datagrams discarded while awaiting re-assembly.
563
Datagrams Received Delivered/sec is the rate, in incidents per second, at which input datagrams were successfully delivered to IP user-protocols, including Internet Control Message Protocol (ICMP).
565
Datagrams Sent/sec is the rate, in incidents per second, at which IP datagrams were supplied for transmission by local IP user-protocols (including ICMP). This counter does not include any datagrams counted in Datagrams Forwarded/sec. Datagrams Sent/sec is a subset of Datagrams/sec.
567
Datagrams Outbound Discarded is the number of output IP datagrams that were discarded even though no problems were encountered to prevent their transmission to their destination (for example, lack of buffer space). This counter includes datagrams counted in Datagrams Forwarded/sec that meet this criterion.
569
Datagrams Outbound No Route is the number of IP datagrams that were discarded because no route could be found to transmit them to their destination. This counter includes any packets counted in Datagrams Forwarded/sec that meet this `no route' criterion.
571
Fragments Received/sec is the rate, in incidents per second, at which IP fragments that need to be reassembled at this entity are received.
573
Fragments Re-assembled/sec is the rate, in incidents per second, at which IP fragments were successfully reassembled.
575
Fragment Re-assembly Failures is the number of failures detected by the IP reassembly algorithm, such as time outs, errors, etc. This is not necessarily a count of discarded IP fragments since some algorithms (notably RFC 815) lose track of the number of fragments by combining them as they are received.
577
Fragmented Datagrams/sec is the rate, in incidents per second, at which datagrams are successfully fragmented.
579
Fragmentation Failures is the number of IP datagrams that were discarded because they needed to be fragmented at but could not be (for example, because the `Don't Fragment' flag was set).
581
Fragments Created/sec is the rate, in incidents per second, at which IP datagram fragments were generated as a result of fragmentation.
583
The ICMP performance object consists of counters that measure the rates at which messages are sent and received by using ICMP protocols. It also includes counters that monitor ICMP protocol errors.
585
Messages/sec is the total rate, in incidents per second, at which ICMP messages were sent and received by the entity. The rate includes messages received or sent in error.
587
Messages Received/sec is the rate, in incidents per second at which ICMP messages were received. The rate includes messages received in error.
589
Messages Received Errors is the number of ICMP messages that the entity received but had errors, such as bad ICMP checksums, bad length, etc.
591
Received Destination Unreachable is the number of ICMP Destination Unreachable messages received.
593
Received Time Exceeded is the number of ICMP Time Exceeded messages received.
595
Received Parameter Problem is the number of ICMP Parameter Problem messages received.
597
Received Source Quench is the number of ICMP Source Quench messages received.
599
Received Redirect/sec is the rate, in incidents per second, at which ICMP Redirect messages were received.
601
Received Echo/sec is the rate, in incidents per second, at which ICMP Echo messages were received.
603
Received Echo Reply/sec is the rate, in incidents per second, at which ICMP Echo Reply messages were received.
605
Received Timestamp/sec is the rate, in incidents per second at which ICMP Timestamp Request messages were received.
607
Received Timestamp Reply/sec is the rate of ICMP Timestamp Reply messages received.
609
Received Address Mask is the number of ICMP Address Mask Request messages received.
611
Received Address Mask Reply is the number of ICMP Address Mask Reply messages received.
613
Messages Sent/sec is the rate, in incidents per second, at which the server attempted to send. The rate includes those messages sent in error.
615
Messages Outbound Errors is the number of ICMP messages that were not send due to problems within ICMP, such as lack of buffers. This value does not include errors discovered outside the ICMP layer, such as those recording the failure of IP to route the resultant datagram. In some implementations, none of the error types are included in the value of this counter.
617
Sent Destination Unreachable is the number of ICMP Destination Unreachable messages sent.
619
Sent Time Exceeded is the number of ICMP Time Exceeded messages sent.
621
Sent Parameter Problem is the number of ICMP Parameter Problem messages sent.
623
Sent Source Quench is the number of ICMP Source Quench messages sent.
625
Sent Redirect/sec is the rate, in incidents per second, at which ICMP Redirect messages were sent.
627
Sent Echo/sec is the rate of ICMP Echo messages sent.
629
Sent Echo Reply/sec is the rate, in incidents per second, at which ICMP Echo Reply messages were sent.
631
Sent Timestamp/sec is the rate, in incidents per second, at which ICMP Timestamp Request messages were sent.
633
Sent Timestamp Reply/sec is the rate, in incidents per second, at which ICMP Timestamp Reply messages were sent.
635
Sent Address Mask is the number of ICMP Address Mask Request messages sent.
637
Sent Address Mask Reply is the number of ICMP Address Mask Reply messages sent.
639
The TCP performance object consists of counters that measure the rates at which TCP Segments are sent and received by using the TCP protocol. It includes counters that monitor the number of TCP connections in each TCP connection state.
641
Segments/sec is the rate at which TCP segments are sent or received using the TCP protocol.
643
Connections Established is the number of TCP connections for which the current state is either ESTABLISHED or CLOSE-WAIT.
645
Connections Active is the number of times TCP connections have made a direct transition to the SYN-SENT state from the CLOSED state. In other words, it shows a number of connections which are initiated by the local computer. The value is a cumulative total.
647
Connections Passive is the number of times TCP connections have made a direct transition to the SYN-RCVD state from the LISTEN state. In other words, it shows a number of connections to the local computer, which are initiated by remote computers. The value is a cumulative total.
649
Connection Failures is the number of times TCP connections have made a direct transition to the CLOSED state from the SYN-SENT state or the SYN-RCVD state, plus the number of times TCP connections have made a direct transition to the LISTEN state from the SYN-RCVD state.
651
Connections Reset is the number of times TCP connections have made a direct transition to the CLOSED state from either the ESTABLISHED state or the CLOSE-WAIT state.
653
Segments Received/sec is the rate at which segments are received, including those received in error. This count includes segments received on currently established connections.
655
Segments Sent/sec is the rate at which segments are sent, including those on current connections, but excluding those containing only retransmitted bytes.
657
Segments Retransmitted/sec is the rate at which segments are retransmitted, that is, segments transmitted containing one or more previously transmitted bytes.
659
The UDP performance object consists of counters that measure the rates at which UDP datagrams are sent and received by using the UDP protocol. It includes counters that monitor UDP protocol errors.
661
Datagrams/sec is the rate at which UDP datagrams are sent or received by the entity.
663
Datagrams Received/sec is the rate at which UDP datagrams are delivered to UDP users.
665
Datagrams No Port/sec is the rate of received UDP datagrams for which there was no application at the destination port.
667
Datagrams Received Errors is the number of received UDP datagrams that could not be delivered for reasons other than the lack of an application at the destination port.
669
Datagrams Sent/sec is the rate at which UDP datagrams are sent from the entity.
671
Disk Storage device statistics from the foreign computer
673
The number of allocation failures reported by the disk storage device
675
System Up Time is the elapsed time (in seconds) that the computer has been running since it was last started. This counter displays the difference between the start time and the current time.
677
The current number of system handles in use.
679
Free System Page Table Entries is the number of page table entries not currently in used by the system. This counter displays the last observed value only; it is not an average.
681
The number of threads currently active in this process. An instruction is the basic unit of execution in a processor, and a thread is the object that executes instructions. Every running process has at least one thread.
683
The current base priority of this process. Threads within a process can raise and lower their own base priority relative to the process' base priority.
685
The total elapsed time, in seconds, that this process has been running.
687
Alignment Fixups/sec is the rate, in incidents per seconds, at alignment faults were fixed by the system.
689
Exception Dispatches/sec is the rate, in incidents per second, at which exceptions were dispatched by the system.
691
Floating Emulations/sec is the rate of floating emulations performed by the system. This counter displays the difference between the values observed in the last two samples, divided by the duration of the sample interval.
693
Logon/sec is the rate of all server logons.
695
The current dynamic priority of this thread. The system can raise the thread's dynamic priority above the base priority if the thread is handling user input, or lower it towards the base priority if the thread becomes compute bound.
697
The current base priority of this thread. The system can raise the thread's dynamic priority above the base priority if the thread is handling user input, or lower it towards the base priority if the thread becomes compute bound.
699
The total elapsed time (in seconds) this thread has been running.
701
The Paging File performance object consists of counters that monitor the paging file(s) on the computer. The paging file is a reserved space on disk that backs up committed physical memory on the computer.
703
The amount of the Page File instance in use in percent. See also Process\\Page File Bytes.
705
The peak usage of the Page File instance in percent. See also Process\\Page File Bytes Peak.
707
Starting virtual address for this thread.
709
Current User Program Counter for this thread.
711
Mapped Space is virtual memory that has been mapped to a specific virtual address (or range of virtual addresses) in the process' virtual address space. No Access protection prevents a process from writing to or reading from these pages and will generate an access violation if either is attempted.
713
Mapped Space is virtual memory that has been mapped to a specific virtual address (or range of virtual addresses) in the process' virtual address space. Read Only protection prevents the contents of these pages from being modified. Any attempts to write or modify these pages will generate an access violation.
715
Mapped Space is virtual memory that has been mapped to a specific virtual address (or range of virtual addresses) in the process' virtual address space. Read/Write protection allows a process to read, modify and write to these pages.
717
Mapped Space is virtual memory that has been mapped to a specific virtual address (or range of virtual addresses) in the process' virtual address space. Write Copy protection is used when memory is shared for reading but not for writing. When processes are reading this memory, they can share the same memory, however, when a sharing process wants to have write access to this shared memory, a copy of that memory is made.
719
Mapped Space is virtual memory that has been mapped to a specific virtual address (or range of virtual addresses) in the process' virtual address space. Executable memory is memory that can be executed by programs, but cannot be read or written. This type of protection is not supported by all processor types.
721
Mapped Space is virtual memory that has been mapped to a specific virtual address (or range of virtual addresses) in the process' virtual address space. Execute/Read Only memory is memory that can be executed as well as read.
723
Mapped Space is virtual memory that has been mapped to a specific virtual address (or range of virtual addresses) in the process' virtual address space. Execute/Read/Write memory is memory that can be executed by programs as well as read and modified.
725
Mapped Space is virtual memory that has been mapped to a specific virtual address (or range of virtual addresses) in the process' virtual address space. Execute Write Copy is memory that can be executed by programs as well as read and written. This type of protection is used when memory needs to be shared between processes. If the sharing processes only read the memory, then they will all use the same memory. If a sharing process desires write access, then a copy of this memory will be made for that process.
727
Reserved Space is virtual memory that has been reserved for future use by a process, but has not been mapped or committed. No Access protection prevents a process from writing to or reading from these pages and will generate an access violation if either is attempted.
729
Reserved Space is virtual memory that has been reserved for future use by a process, but has not been mapped or committed. Read Only protection prevents the contents of these pages from being modified. Any attempts to write or modify these pages will generate an access violation.
731
Reserved Space is virtual memory that has been reserved for future use by a process, but has not been mapped or committed. Read/Write protection allows a process to read, modify and write to these pages.
733
Reserved Space is virtual memory that has been reserved for future use by a process, but has not been mapped or committed. Write Copy protection is used when memory is shared for reading but not for writing. When processes are reading this memory, they can share the same memory, however, when a sharing process wants to have read/write access to this shared memory, a copy of that memory is made.
735
Reserved Space is virtual memory that has been reserved for future use by a process, but has not been mapped or committed. Executable memory is memory that can be executed by programs, but cannot be read or written. This type of protection is not supported by all processor types.
737
Reserved Space is virtual memory that has been reserved for future use by a process, but has not been mapped or committed. Execute/Read Only memory is memory that can be executed as well as read.
739
Reserved Space is virtual memory that has been reserved for future use by a process, but has not been mapped or committed. Execute/Read/Write memory is memory that can be executed by programs as well as read and modified.
741
The Image performance object consists of counters that monitor the virtual address usage of images executed by processes on the computer.
743
Reserved Space is virtual memory that has been reserved for future use by a process, but has not been mapped or committed. Execute Write Copy is memory that can be executed by programs as well as read and written. This type of protection is used when memory needs to be shared between processes. If the sharing processes only read the memory, then they will all use the same memory. If a sharing process desires write access, then a copy of this memory will be made for that process.
745
Unassigned Space is mapped and committed virtual memory in use by the process that is not attributable to any particular image being executed by that process. No Access protection prevents a process from writing to or reading from these pages and will generate an access violation if either is attempted.
747
Unassigned Space is mapped and committed virtual memory in use by the process that is not attributable to any particular image being executed by that process. Read Only protection prevents the contents of these pages from being modified. Any attempts to write or modify these pages will generate an access violation.
749
Unassigned Space is mapped and committed virtual memory in use by the process that is not attributable to any particular image being executed by that process. Read/Write protection allows a process to read, modify and write to these pages.
751
Unassigned Space is mapped and committed virtual memory in use by the process that is not attributable to any particular image being executed by that process. Write Copy protection is used when memory is shared for reading but not for writing. When processes are reading this memory, they can share the same memory, however, when a sharing process wants to have read/write access to this shared memory, a copy of that memory is made for writing to.
753
Unassigned Space is mapped and committed virtual memory in use by the process that is not attributable to any particular image being executed by that process. Executable memory is memory that can be executed by programs, but cannot be read or written. This type of protection is not supported by all processor types.
755
Unassigned Space is mapped and committed virtual memory in use by the process that is not attributable to any particular image being executed by that process. Execute/Read Only memory is memory that can be executed as well as read.
757
Unassigned Space is mapped and committed virtual memory in use by the process that is not attributable to any particular image being executed by that process. Execute/Read/Write memory is memory that can be executed by programs as well as read and written.
759
Unassigned Space is mapped and committed virtual memory in use by the process that is not attributable to any particular image being executed by that process. Execute Write Copy is memory that can be executed by programs as well as read and written. This type of protection is used when memory needs to be shared between processes. If the sharing processes only read the memory, then they will all use the same memory. If a sharing process desires write access, then a copy of this memory will be made for that process.
761
Image Space is the virtual address space in use by the images being executed by the process. This is the sum of all the address space with this protection allocated by images run by the selected process No Access protection prevents a process from writing to or reading from these pages and will generate an access violation if either is attempted.
763
Image Space is the virtual address space in use by the images being executed by the process. This is the sum of all the address space with this protection allocated by images run by the selected process Read Only protection prevents the contents of these pages from being modified. Any attempts to write or modify these pages will generate an access violation.
765
Image Space is the virtual address space in use by the images being executed by the process. This is the sum of all the address space with this protection allocated by images run by the selected process Read/Write protection allows a process to read, modify and write to these pages.
767
Image Space is the virtual address space in use by the images being executed by the process. This is the sum of all the address space with this protection allocated by images run by the selected process Write Copy protection is used when memory is shared for reading but not for writing. When processes are reading this memory, they can share the same memory, however, when a sharing process wants to have read/write access to this shared memory, a copy of that memory is made for writing to.
769
Image Space is the virtual address space in use by the images being executed by the process. This is the sum of all the address space with this protection allocated by images run by the selected process Executable memory is memory that can be executed by programs, but cannot be read or written. This type of protection is not supported by all processor types.
771
Image Space is the virtual address space in use by the images being executed by the process. This is the sum of all the address space with this protection allocated by images run by the selected process Execute/Read-Only memory is memory that can be executed as well as read.
773
Image Space is the virtual address space in use by the images being executed by the process. This is the sum of all the address space with this protection allocated by images run by the selected process Execute/Read/Write memory is memory that can be executed by programs as well as read and written and modified.
775
Image Space is the virtual address space in use by the images being executed by the process. This is the sum of all the address space with this protection allocated by images run by the selected process Execute Write Copy is memory that can be executed by programs as well as read and written. This type of protection is used when memory needs to be shared between processes. If the sharing processes only read the memory, then they will all use the same memory. If a sharing process desires write access, then a copy of this memory will be made for that process.
777
Bytes Image Reserved is the sum of all virtual memory reserved by images within this process.
779
Bytes Image Free is the amount of virtual address space that is not in use or reserved by images within this process.
781
Bytes Reserved is the total amount of virtual memory reserved for future use by this process.
783
Bytes Free is the total unused virtual address space of this process.
785
ID Process is the unique identifier of this process. ID Process numbers are reused, so they only identify a process for the lifetime of that process.
787
The Process Address Space performance object consists of counters that monitor memory allocation and use for a selected process.
789
Image Space is the virtual address space in use by the selected image with this protection. No Access protection prevents a process from writing or reading these pages and will generate an access violation if either is attempted.
791
Image Space is the virtual address space in use by the selected image with this protection. Read Only protection prevents the contents of these pages from being modified. Any attempts to write or modify these pages will generate an access violation.
793
Image Space is the virtual address space in use by the selected image with this protection. Read/Write protection allows a process to read, modify and write to these pages.
795
Image Space is the virtual address space in use by the selected image with this protection. Write Copy protection is used when memory is shared for reading but not for writing. When processes are reading this memory, they can share the same memory, however, when a sharing process wants to have read/write access to this shared memory, a copy of that memory is made for writing to.
797
Image Space is the virtual address space in use by the selected image with this protection. Executable memory is memory that can be executed by programs, but cannot be read or written. This type of protection is not supported by all processor types.
799
Image Space is the virtual address space in use by the selected image with this protection. Execute/Read Only memory is memory that can be executed as well as read.
801
Image Space is the virtual address space in use by the selected image with this protection. Execute/Read/Write memory is memory that can be executed by programs as well as read and written.
803
Image Space is the virtual address space in use by the selected image with this protection. Execute Write Copy is memory that can be executed by programs as well as read and written. This type of protection is used when memory needs to be shared between processes. If the sharing processes only read the memory, then they will all use the same memory. If a sharing process desires write access, then a copy of this memory will be made for that process.
805
ID Thread is the unique identifier of this thread. ID Thread numbers are reused, so they only identify a thread for the lifetime of that thread.
807
Mailslot Opens Failed/sec indicates the rate at which mailslot messages to be delivered to mailslots that are not present are received by this workstation.
809
Duplicate Master Announcements indicates the number of times that the master browser has detected another master browser on the same domain.
811
Illegal Datagrams/sec is the rate at which incorrectly formatted datagrams have been received by the workstation.
813
Announcements Total/sec is the sum of Announcements Server/sec and Announcements Domain/sec.
815
Enumerations Total/sec is the rate at which browse requests have been processed by this workstation. This is the sum of Enumerations Server/sec, Enumerations Domain/sec, and Enumerations Other/sec.
817
The Thread Details performance object consists of counters that measure aspects of thread behavior that are difficult or time-consuming or collect. These counters are distinguished from those in the Thread object by their high overhead.
819
Cache Bytes the size, in bytes, of the portion of the system file cache which is currently resident and active in physical memory. The Cache Bytes and Memory\\System Cache Resident Bytes counters are equivalent. This counter displays the last observed value only; it is not an average.
821
Cache Bytes Peak is the maximum number of bytes used by the system file cache since the system was last restarted. This might be larger than the current size of the cache. This counter displays the last observed value only; it is not an average.
823
Pages Input/sec is the rate at which pages are read from disk to resolve hard page faults. Hard page faults occur when a process refers to a page in virtual memory that is not in its working set or elsewhere in physical memory, and must be retrieved from disk. When a page is faulted, the system tries to read multiple contiguous pages into memory to maximize the benefit of the read operation. Compare the value of Memory\\Pages Input/sec to the value of Memory\\Page Reads/sec to determine the average number of pages read into memory during each read operation.
825
Transition Pages RePurposed is the rate at which the number of transition cache pages were reused for a different purpose. These pages would have otherwise remained in the page cache to provide a (fast) soft fault (instead of retrieving it from backing store) in the event the page was accessed in the future. Note these pages can contain private or sharable memory.
873
The number of bytes transmitted total for this connection.
875
The number of bytes received total for this connection.
877
The number of data frames transmitted total for this connection.
879
The number of data frames received total for this connection.
881
The compression ratio for bytes being transmitted.
883
The compression ratio for bytes being received.
885
The total number of CRC Errors for this connection. CRC Errors occur when the frame received contains erroneous data.
887
The total number of Timeout Errors for this connection. Timeout Errors occur when an expected is not received in time.
889
The total number of Serial Overrun Errors for this connection. Serial Overrun Errors occur when the hardware cannot handle the rate at which data is received.
891
The total number of Alignment Errors for this connection. Alignment Errors occur when a byte received is different from the byte expected.
893
The total number of Buffer Overrun Errors for this connection. Buffer Overrun Errors when the software cannot handle the rate at which data is received.
895
The total number of CRC, Timeout, Serial Overrun, Alignment, and Buffer Overrun Errors for this connection.
897
The number of bytes transmitted per second.
899
The number of bytes received per second.
901
The number of frames transmitted per second.
903
The number of frames received per second.
905
The total number of CRC, Timeout, Serial Overrun, Alignment, and Buffer Overrun Errors per second.
909
The total number of Remote Access connections.
921
The WINS Server performance object consists of counters that monitor communications using the WINS Server service.
923
Unique Registrations/sec is the rate at which unique registration are received by the WINS server.
925
Group Registrations/sec is the rate at which group registration are received by the WINS server.
927
Total Number of Registrations/sec is the sum of the Unique and Group registrations per sec. This is the total rate at which registration are received by the WINS server.
929
Unique Renewals/sec is the rate at which unique renewals are received by the WINS server.
931
Group Renewals/sec is the rate at which group renewals are received by the WINS server.
933
Total Number of Renewals/sec is the sum of the Unique and Group renewals per sec. This is the total rate at which renewals are received by the WINS server.
935
Total Number of Releases/sec is the rate at which releases are received by the WINS server.
937
Total Number of Queries/sec is the rate at which queries are received by the WINS server.
939
Unique Conflicts/sec is the rate at which unique registrations/renewals received by the WINS server resulted in conflicts with records in the database.
941
Group Conflicts/sec is the rate at which group registration received by the WINS server resulted in conflicts with records in the database.
943
Total Number of Conflicts/sec is the sum of the Unique and Group conflicts per sec. This is the total rate at which conflicts were seen by the WINS server.
945
Total Number of Successful Releases/sec
947
Total Number of Failed Releases/sec
949
Total Number of Successful Queries/sec
951
Total Number of Failed Queries/sec
953
The total number of handles currently open by this process. This number is equal to the sum of the handles currently open by each thread in this process.
1001
Services for Macintosh AFP File Server.
1003
The maximum amount of paged memory resources used by the MacFile Server.
1005
The current amount of paged memory resources used by the MacFile Server.
1007
The maximum amount of nonpaged memory resources use by the MacFile Server.
1009
The current amount of nonpaged memory resources used by the MacFile Server.
1011
The number of sessions currently connected to the MacFile server. Indicates current server activity.
1013
The maximum number of sessions connected at one time to the MacFile server. Indicates usage level of server.
1015
The number of internal files currently open in the MacFile server. This count does not include files opened on behalf of Macintosh clients.
1017
The maximum number of internal files open at one time in the MacFile server. This count does not include files opened on behalf of Macintosh clients.
1019
The number of failed logon attempts to the MacFile server. Can indicate whether password guessing programs are being used to crack the security on the server.
1021
The number of bytes read from disk per second.
1023
The number of bytes written to disk per second.
1025
The number of bytes received from the network per second. Indicates how busy the server is.
1027
The number of bytes sent on the network per second. Indicates how busy the server is.
1029
The number of outstanding work items waiting to be processed.
1031
The maximum number of outstanding work items waiting at one time.
1033
The current number of threads used by MacFile server. Indicates how busy the server is.
1035
The maximum number of threads used by MacFile server. Indicates peak usage level of server.
1051
AppleTalk Protocol
1053
Number of packets received per second by Appletalk on this port.
1055
Number of packets sent per second by Appletalk on this port.
1057
Number of bytes received per second by Appletalk on this port.
1059
Number of bytes sent per second by Appletalk on this port.
1061
Average time in milliseconds to process a DDP packet on this port.
1063
Number of DDP packets per second received by Appletalk on this port.
1065
Average time in milliseconds to process an AARP packet on this port.
1067
Number of AARP packets per second received by Appletalk on this port.
1069
Average time in milliseconds to process an ATP packet on this port.
1071
Number of ATP packets per second received by Appletalk on this port.
1073
Average time in milliseconds to process an NBP packet on this port.
1075
Number of NBP packets per second received by Appletalk on this port.
1077
Average time in milliseconds to process a ZIP packet on this port.
1079
Number of ZIP packets per second received by Appletalk on this port.
1081
Average time in milliseconds to process an RTMP packet on this port.
1083
Number of RTMP packets per second received by Appletalk on this port.
1085
Number of ATP requests retransmitted on this port.
1087
Number of ATP release timers that have expired on this port.
1089
Number of ATP Exactly-once transaction responses per second on this port.
1091
Number of ATP At-least-once transaction responses per second on this port.
1093
Number of ATP transaction release packets per second received on this port.
1095
The current amount of nonpaged memory resources used by AppleTalk.
1097
Number of packets routed in on this port.
1099
Number of packets dropped due to resource limitations on this port.
1101
Number of ATP requests retransmitted to this port.
1103
Number of packets routed out on this port.
1111
Provides Network Statistics for the local network segment via the Network Monitor Service.
1113
The total number of frames received per second on this network segment.
1115
The number of bytes received per second on this network segment.
1117
The number of Broadcast frames received per second on this network segment.
1119
The number of Multicast frames received per second on this network segment.
1121
Percentage of network bandwidth in use on this network segment.
1125
Percentage of network bandwidth which is made up of broadcast traffic on this network segment.
1127
Percentage of network bandwidth which is made up of multicast traffic on this network segment.
1151
The Telephony System
1153
The number of telephone lines serviced by this computer.
1155
The number of telephone devices serviced by this computer.
1157
The number of telephone lines serviced by this computer that are currently active.
1159
The number of telephone devices that are currently being monitored.
1161
The rate of outgoing calls made by this computer.
1163
The rate of incoming calls answered by this computer.
1165
The number of applications that are currently using telephony services.
1167
Current outgoing calls being serviced by this computer.
1169
Current incoming calls being serviced by this computer.
1233
Packet Burst Read NCP Count/sec is the rate of NetWare Core Protocol requests for Packet Burst Read. Packet Burst is a windowing protocol that improves performance.
1235
Packet Burst Read Timeouts/sec is the rate the NetWare Service needs to retransmit a Burst Read Request because the NetWare server took too long to respond.
1237
Packet Burst Write NCP Count/sec is the rate of NetWare Core Protocol requests for Packet Burst Write. Packet Burst is a windowing protocol that improves performance.
1239
Packet Burst Write Timeouts/sec is the rate the NetWare Service needs to retransmit a Burst Write Request because the NetWare server took too long to respond.
1241
Packet Burst IO/sec is the sum of Packet Burst Read NCPs/sec and Packet Burst Write NCPs/sec.
1261
Logon Total indicates the total session setup attempts, including all successful logon and failed logons since the server service is started.
1263
The total number of durable handle disconnects that have occurred.
1265
The total number of durable handles that are successfully reconnected. The ratio of "reconnected durable handles"/"total durable handles" indicates the stability gain from reconnect durable handles.
1267
The number of SMB BranchCache hash requests that were for the header only received by the server. This indicates how many requests are being done to validate hashes that are already cached by the client.
1269
The number of SMB BranchCache hash generation requests that were sent by SRV2 to the SMB Hash Generation service because a client requested hashes for the file and there was either no hash content for the file or the existing hashes were out of date.
1271
The number of SMB BranchCache hash requests that were received by the server.
1273
The number of SMB BranchCache hash responses that have been sent from the server.
1275
The amount of SMB BranchCache hash data sent from the server. This includes bytes transferred for both hash header requests and full hash data requests.
1277
The total number of resilient handle disconnect that have occurred.
1279
The total number of resilient handles that are successfully reconnected. The ratio of "reconnected resilient handles"/"total resilient handles" indicates the stability gain from reconnect resilient handles.
1301
The Server Work Queues performance object consists of counters that monitor the length of the queues and objects in the queues.
1303
Queue length is the current number of workitem in Blocking queues and Nonblocking queues, which indicates how busy the server is to process outstanding workitems for this CPU. A sustained queue length greater than four might indicate processor congestion. This is an instantaneous count, not an average over time.
1305
Active Threads is the number of threads currently working on a request from the server client for this CPU. The system keeps this number as low as possible to minimize unnecessary context switching. This is an instantaneous count for the CPU, not an average over time.
1307
Available Threads is the number of server threads on this CPU not currently working on requests from a client. The server dynamically adjusts the number of threads to maximize server performance.
1309
Every request from a client is represented in the server as a 'work item,' and the server maintains a pool of available work items per CPU to speed processing. This is the instantaneous number of available work items for this CPU. A sustained near-zero value indicates the need to increase the MinFreeWorkItems registry value for the Server service. This value will always be 0 in the SMB1 Blocking Queue instance.
1311
Every request from a client is represented in the server as a 'work item,' and the server maintains a pool of available work items per CPU to speed processing. When a CPU runs out of work items, it borrows a free work item from another CPU. An increasing value of this running counter might indicate the need to increase the 'MaxWorkItems' or 'MinFreeWorkItems' registry values for the Server service. This value will always be 0 in the Blocking Queue and SMB2 Queue instances.
1313
Every request from a client is represented in the server as a 'work item,' and the server maintains a pool of available work items per CPU to speed processing. A sustained value greater than zero indicates the need to increase the 'MaxWorkItems' registry value for the Server service. This value will always be 0 in the Blocking Queue and SMB2 Queue instances.
1315
Current Clients is the instantaneous count of the clients being serviced by this CPU. The server actively balances the client load across all of the CPU's in the system. This value will always be 0 in the Blocking Queue instance.
1317
The rate at which the Server is receiving bytes from the network clients on this CPU. This value is a measure of how busy the Server is.
1319
The rate at which the Server is sending bytes to the network clients on this CPU. This value is a measure of how busy the Server is.
1321
The rate at which the Server is sending and receiving bytes with the network clients on this CPU. This value is a measure of how busy the Server is.
1323
Read Operations/sec is the rate the server is performing file read operations for the clients on this CPU. This value is a measure of how busy the Server is. This value will always be 0 in the Blocking Queue instance.
1325
Read Bytes/sec is the rate the server is reading data from files for the clients on this CPU. This value is a measure of how busy the Server is.
1327
Write Operations/sec is the rate the server is performing file write operations for the clients on this CPU. This value is a measure of how busy the Server is. This value will always be 0 in the Blocking Queue instance.
1329
Write Bytes/sec is the rate the server is writing data to files for the clients on this CPU. This value is a measure of how busy the Server is.
1331
Total Bytes/sec is the rate the Server is reading and writing data to and from the files for the clients on this CPU. This value is a measure of how busy the Server is.
1333
Total Operations/sec is the rate the Server is performing file read and file write operations for the clients on this CPU. This value is a measure of how busy the Server is. This value will always be 0 in the Blocking Queue instance.
1335
DPCs Queued/sec is the average rate, in incidents per second, at which deferred procedure calls (DPCs) were added to the processor's DPC queue. DPCs are interrupts that run at a lower priority than standard interrupts. Each processor has its own DPC queue. This counter measures the rate that DPCs are added to the queue, not the number of DPCs in the queue. This counter displays the difference between the values observed in the last two samples, divided by the duration of the sample interval.
1337
DPC Rate is the rate at which deferred procedure calls (DPCs) were added to the processors DPC queues between the timer ticks of the processor clock. DPCs are interrupts that run at alower priority than standard interrupts. Each processor has its own DPC queue. This counter measures the rate that DPCs were added to the queue, not the number of DPCs in the queue. This counter displays the last observed value only; it is not an average.
1343
Total DPCs Queued/sec is the combined rate at which deferred procedure calls (DPCs) are added to the DPC queue of all processors on the computer. (DPCs are interrupts that run at a lower priority than standard interrupts). Each processor has its own DPC queue. This counter measures the rate at which DPCs are added to the queue, not the number of DPCs in the queue. It is the sum of Processor: DPCs Queued/sec for all processors on the computer, divided by the number of processors. This counter displays the difference between the values observed in the last two samples, divided by the duration of the sample interval.
1345
Total DPC Rate is the combined rate at which deferred procedure calls (DPCs) are added to the DPC queues of all processors between timer ticks of each processor's system clock. (DPCs are interrupts that run at a lower priority than standard interrupts). Each processor has its own DPC queue. This counter measures the rate at which DPCs are added to the queue, not the number of DPCs in the queue. It is the sum of Processor: DPC Rate for all processors on the computer, divided by the number of processors. This counter displays the last observed value only; it is not an average.
1351
% Registry Quota In Use is the percentage of the Total Registry Quota Allowed that is currently being used by the system. This counter displays the current percentage value only; it is not an average.
1361
Counters that indicate the status of local and system Very Large memory allocations.
1363
VLM % Virtual Size In Use
1365
Current size of the process VLM Virtual memory space in bytes.
1367
The peak size of the process VLM virtual memory space in bytes. This value indicates the maximum size of the process VLM virtual memory since the process started.
1369
The current size of the process VLM virtual memory space in bytes that may be allocated. Note that the maximum allocation allowed may be smaller than this value due to fragmentation of the memory space.
1371
The current size of committed VLM memory space for the current process in bytes.
1373
The peak size of the committed VLM memory space in bytes for the current process since the process started.
1375
The current size of all committed VLM memory space in bytes for the system.
1377
The peak size of all committed VLM memory space in bytes since the system was started.
1379
The current size of all committed shared VLM memory space in bytes for the system.
1381
Available KBytes is the amount of physical memory, in Kilobytes, immediately available for allocation to a process or for system use. It is equal to the sum of memory assigned to the standby (cached), free and zero page lists.
1383
Available MBytes is the amount of physical memory, in Megabytes, immediately available for allocation to a process or for system use. It is equal to the sum of memory assigned to the standby (cached), free and zero page lists.
1401
Avg. Disk Queue Length is the average number of both read and write requests that were queued for the selected disk during the sample interval.
1403
Avg. Disk Read Queue Length is the average number of read requests that were queued for the selected disk during the sample interval.
1405
Avg. Disk Write Queue Length is the average number of write requests that were queued for the selected disk during the sample interval.
1407
% Committed Bytes In Use is the ratio of Memory\\Committed Bytes to the Memory\\Commit Limit. Committed memory is the physical memory in use for which space has been reserved in the paging file should it need to be written to disk. The commit limit is determined by the size of the paging file. If the paging file is enlarged, the commit limit increases, and the ratio is reduced). This counter displays the current percentage value only; it is not an average.
1409
The Full Image performance object consists of counters that monitor the virtual address usage of images executed by processes on the computer. Full Image counters are the same counters as contained in Image object with the only difference being the instance name. In the Full Image object, the instance name includes the full file path name of the loaded modules, while in the Image object only the filename is displayed.
1411
The Creating Process ID value is the Process ID of the process that created the process. The creating process may have terminated, so this value may no longer identify a running process.
1413
The rate at which the process is issuing read I/O operations. This counter counts all I/O activity generated by the process to include file, network and device I/Os.
1415
The rate at which the process is issuing write I/O operations. This counter counts all I/O activity generated by the process to include file, network and device I/Os.
1417
The rate at which the process is issuing read and write I/O operations. This counter counts all I/O activity generated by the process to include file, network and device I/Os.
1419
The rate at which the process is issuing I/O operations that are neither read nor write operations (for example, a control function). This counter counts all I/O activity generated by the process to include file, network and device I/Os.
1421
The rate at which the process is reading bytes from I/O operations. This counter counts all I/O activity generated by the process to include file, network and device I/Os.
1423
The rate at which the process is writing bytes to I/O operations. This counter counts all I/O activity generated by the process to include file, network and device I/Os.
1425
The rate at which the process is reading and writing bytes in I/O operations. This counter counts all I/O activity generated by the process to include file, network and device I/Os.
1427
The rate at which the process is issuing bytes to I/O operations that do not involve data such as control operations. This counter counts all I/O activity generated by the process to include file, network and device I/Os.
1451
Displays performance statistics about a Print Queue.
1453
Total number of jobs printed on a print queue since the last restart.
1455
Number of bytes per second printed on a print queue.
1457
Total number of pages printed through GDI on a print queue since the last restart.
1459
Current number of jobs in a print queue.
1461
Current number of references (open handles) to this printer.
1463
Peak number of references (open handles) to this printer.
1465
Current number of spooling jobs in a print queue.
1467
Maximum number of spooling jobs in a print queue since last restart.
1469
Total number of out of paper errors in a print queue since the last restart.
1471
Total number of printer not ready errors in a print queue since the last restart.
1473
Total number of job errors in a print queue since last restart.
1475
Total number of calls from browse clients to this print server to request network browse lists since last restart.
1477
Total number of calls from other print servers to add shared network printers to this server since last restart.
1479
Working Set - Private displays the size of the working set, in bytes, that is use for this process only and not shared nor sharable by other processes.
1481
Working Set - Shared displays the size of the working set, in bytes, that is sharable and may be used by other processes. Because a portion of a process' working set is shareable, does not necessarily mean that other processes are using it.
1483
% Idle Time reports the percentage of time during the sample interval that the disk was idle.
1485
Split IO/Sec reports the rate at which I/Os to the disk were split into multiple I/Os. A split I/O may result from requesting data of a size that is too large to fit into a single I/O or that the disk is fragmented.
1501
Reports the accounting and processor usage data collected by each active named Job object.
1503
Current % Processor Time shows the percentage of the sample interval that the processes in the Job object spent executing code.
1505
Current % User mode Time shows the percentage of the sample interval that the processes in the Job object spent executing code in user mode.
1507
Current % Kernel mode Time shows the percentage of the sample interval that the processes in the Job object spent executing code in kernel or privileged mode.
1509
This Period mSec - Processor shows the time, in milliseconds, of processor time used by all the processes in the Job object, including those that have terminated or that are no longer associated with the Job object, since a time limit on the Job was established.
1511
This Period mSec - User mode shows the time, in milliseconds, of user mode processor time used by all the processes in the Job object, including those that have terminated or that are no longer associated with the Job object, since a time limit on the Job was established.
1513
This Period mSec - Kernel mode shows the time, in milliseconds, of kernel mode processor time used by all the processes in the Job object, including those that have terminated or that are no longer associated with the Job object, since a time limit on the Job was established.
1515
Pages/Sec shows the page fault rate of all the processes in the Job object.
1517
Process Count - Total shows the number of processes, both active and terminated, that are or have been associated with the Job object.
1519
Process Count - Active shows the number of processes that are currently associated with the Job object.
1521
Process Count - Terminated shows the number of processes that have been terminated because of a limit violation.
1523
Total mSec - Processor shows the time, in milliseconds, of processor time used by all the processes in the Job object, including those that have terminated or that are no longer associated with the Job object, since the Job object was created.
1525
Total mSec - User mode shows the time, in milliseconds, of user mode processor time used by all the processes in the Job object, including those that have terminated or that are no longer associated with the Job object, since the Job object was created.
1527
Total mSec - Kernel mode shows the time, in milliseconds, of kernel mode processor time used by all the processes in the Job object, including those that have terminated or that are no longer associated with the Job object, since the Job object was created.
1537
Received Packet Too Big is the number of received packets thatare larger than anticipated.
1539
Received Membership Query is the number of packets received thatquery their membership to a group.
1541
Received Membership Report is the number of packets received thatreport their membership to a group.
1543
Received Membership Reduction is the number of packets received thatcancelled their membership to a group.
1545
Received Router Solicit is the number of packets received thatsolicit the router.
1547
Received Router Advert is the number of packets received thatadvert the router.
1549
% Job object Details shows detailed performance information about the active processes that make up a Job object.
1551
Received Neighbor Solicit is the number of packets received thatsolicit a neighbor.
1553
Received Neighbor Advert is the number of packets received thatadvert a neighbor.
1555
Sent Packet Too Big is the number of sent packets thatare larger than anticipated.
1557
Sent Membership Query is the number of packets sent thatquery their membership to a group.
1559
Sent Membership Report is the number of packets sent thatreport their membership to a group.
1561
Sent Membership Reduction is the number of packets sent thatcancelled their membership to a group.
1563
Sent Router Solicit is the number of packets sent thatsolicit the router.
1565
Sent Router Advert is the number of packets sent thatadvert the router.
1567
Sent Neighbor Solicit is the number of packets sent thatsolicit a neighbor.
1569
Sent Neighbor Advert is the number of packets sent thatadvert a neighbor.
1571
These counters track authentication performance on a per second basis.
1573
This counter tracks the number of NTLM authentications processed per second for the AD on this DC or for local accounts on this member server.
1575
This counter tracks the number of times that clients use a ticket to authenticate to this computer per second.
1577
This counter tracks the number of Authentication Service (AS) requests that are being processed by the Key Distribution Center (KDC) per second. Clients use AS requests to obtain a ticket-granting ticket.
1579
This counter tracks the number of ticket-granting service (TGS) requests that are being processed by the Key Distribution Center (KDC) per second. Clients use these TGS requests to obtain a service ticket, which allows a client to access resources on other computers.
1581
This counter tracks the number of Secure Sockets Layer (SSL) entries that are currently stored in the secure channel (Schannel) session cache. The Schannel session cache stores information about successfully established sessions, such as SSL session IDs. Clients can use this information to reconnect to a server without performing a full SSL handshake.
1583
This counter tracks the number of Secure Sockets Layer (SSL) entries that are currently stored in the secure channel (Schannel) session cache and that are currently in use. The Schannel session cache stores information about successfully established sessions, such as SSL session IDs. Clients can use this information to reconnect to a server without performaing a full SSL handshake.
1585
This counter tracks the number of Secure Sockets Layer (SSL) full client-side handshakes that are being processed per second. During a handshake, signals are exchanged to acknowledge that communication can occur between computers or other devices.
1587
This counter tracks the number of Secure Sockets Layer (SSL) client-side reconnect handshakes that are being processed per second. Reconnect handshakes allow session keys from previous SSL sessions to be used to resume a client/server connection, and they require less memory to process than full handshakes.
1589
This counter tracks the number of Secure Sockets Layer (SSL) full server-side handshakes that are being processed per second. During a handshake, signals are exchanged to acknowledge that communication can occur between computers or other devices.
1591
This counter tracks the number of Secure Sockets Layer (SSL) server-side reconnect handshakes that are being processed per second. Reconnect handshakes allow session keys from previous SSL sessions to be used to resume a client/server connection, and they require less memory to process than full handshakes.
1593
This counter tracks the number of Digest authentications that are being processed per second.
1595
This counter tracks the number of Kerberos requests that a read-only domain controller (RODC) forwards to its hub, per second. This counter is tracked only on a RODC.
1597
Offloaded Connections is the number of TCP connections (over both IPv4 and IPv6) that are currently handled by the TCP chimney offload capable network adapter.
1599
TCP Active RSC Connections is the number of TCP connections (over both IPv4 and IPv6) that are currently receiving large packets from the RSC capable network adapter on this network interface.
1601
TCP RSC Coalesced Packets/sec shows the large packet receive rate across all TCP connections on this network interface.
1603
TCP RSC Exceptions/sec shows the RSC exception rate for receive packets across all TCP connections on this network interface.
1605
TCP RSC Average Packet Size is the average size in bytes of received packets across all TCP connections on this network interface.
1621
This counter tracks the number of armored Authentication Service (AS) requests that are being processed by the Key Distribution Center (KDC) per second.
1623
This counter tracks the number of armored ticket-granting service (TGS) requests that are being processed by the Key Distribution Center (KDC) per second.
1625
This counter tracks the number of Authentication Service (AS) requests explicitly requesting claims that are being processed by the Key Distribution Center (KDC) per second.
1627
This counter tracks the number of service asserted identity (S4U2Self) TGS requests that are explicitly requesting claims. These requests are being processed by the Key Distribution Center (KDC) per second.
1629
This counter tracks the number of constrained delegation (S4U2Proxy) TGS requests that are being processed by the Key Distribution Center (KDC) by checking classic type constrained delegation configuration per second. The classic type constrained delegation is restricted to a single domain and configures the backend services SPN on the middle-tier serviceÂ’s account object.
1631
This counter tracks the number of constrained delegation (S4U2Proxy) TGS requests that are being processed by the Key Distribution Center (KDC) by checking the resource type constrained delegation per second. The resource type constrained delegation can cross domain boundaries and configures the middle-tierÂ’s account on the backend serviceÂ’s account object.
1633
This counter tracks the number of claims-aware ticket-granting service (TGS) requests that are being processed by the Key Distribution Center (KDC) per second. A claims-aware Kerberos client will always request claims during Authentication Service (AS) exchanges.
1671
These counters track the number of security resources and handles used per process.
1673
This counter tracks the number of credential handles in use by a given process. Credential handles are handles to pre-existing credentials, such as a password, that are associated with a user and are established through a system logon.
1675
This counter tracks the number of context handles in use by a given process. Context handles are associated with security contexts established between a client application and a remote peer.
1677
Free & Zero Page List Bytes is the amount of physical memory, in bytes, that is assigned to the free and zero page lists. This memory does not contain cached data. It is immediately available for allocation to a process or for system use.
1679
Modified Page List Bytes is the amount of physical memory, in bytes, that is assigned to the modified page list. This memory contains cached data and code that is not actively in use by processes, the system and the system cache. This memory needs to be written out before it will be available for allocation to a process or for system use.
1681
Standby Cache Reserve Bytes is the amount of physical memory, in bytes, that is assigned to the reserve standby cache page lists. This memory contains cached data and code that is not actively in use by processes, the system and the system cache. It is immediately available for allocation to a process or for system use. If the system runs out of available free and zero memory, memory on lower priority standby cache page lists will be repurposed before memory on higher priority standby cache page lists.
1683
Standby Cache Normal Priority Bytes is the amount of physical memory, in bytes, that is assigned to the normal priority standby cache page lists. This memory contains cached data and code that is not actively in use by processes, the system and the system cache. It is immediately available for allocation to a process or for system use. If the system runs out of available free and zero memory, memory on lower priority standby cache page lists will be repurposed before memory on higher priority standby cache page lists.
1685
Standby Cache Core Bytes is the amount of physical memory, in bytes, that is assigned to the core standby cache page lists. This memory contains cached data and code that is not actively in use by processes, the system and the system cache. It is immediately available for allocation to a process or for system use. If the system runs out of available free and zero memory, memory on lower priority standby cache page lists will be repurposed before memory on higher priority standby cache page lists.
1687
Long-Term Average Standby Cache Lifetime, in seconds. The average lifetime of data in the standby cache over a long interval is measured.
1747
% Idle Time is the percentage of time the processor is idle during the sample interval
1749
% C1 Time is the percentage of time the processor spends in the C1 low-power idle state. % C1 Time is a subset of the total processor idle time. C1 low-power idle state enables the processor to maintain its entire context and quickly return to the running state. Not all systems support the % C1 state.
1751
% C2 Time is the percentage of time the processor spends in the C2 low-power idle state. % C2 Time is a subset of the total processor idle time. C2 low-power idle state enables the processor to maintain the context of the system caches. The C2 power state is a lower power and higher exit latency state than C1. Not all systems support the C2 state.
1753
% C3 Time is the percentage of time the processor spends in the C3 low-power idle state. % C3 Time is a subset of the total processor idle time. When the processor is in the C3 low-power idle state it is unable to maintain the coherency of its caches. The C3 power state is a lower power and higher exit latency state than C2. Not all systems support the C3 state.
1755
Page Fault Intercepts Forwarded/sec
6992
Page Fault Intercepts Forwarding Cost
6994
VMCLEAR Emulation Intercepts/sec
6996
VMCLEAR Instruction Emulation Cost
6998
VMPTRLD Emulation Intercepts/sec
7000
VMPTRLD Instruction Emulation Cost
7002
VMPTRST Emulation Intercepts/sec
7004
VMPTRST Instruction Emulation Cost
7006
VMREAD Emulation Intercepts/sec
7008
VMREAD Instruction Emulation Cost
7010
VMWRITE Emulation Intercepts/sec
7012
VMWRITE Instruction Emulation Cost
7014
VMXOFF Emulation Intercepts/sec
7016
VMXOFF Instruction Emulation Cost
7018
VMXON Emulation Intercepts/sec
7020
VMXON Instruction Emulation Cost
7022
Nested VM Entries/sec
7024
Nested VM Entries Cost
7026
Nested SLAT Soft Page Faults/sec
7028
Nested SLAT Soft Page Faults Cost
7030
Nested SLAT Hard Page Faults/sec
7032
Nested SLAT Hard Page Faults Cost
7034
InvEpt All Context Emulation Intercepts/sec
7036
InvEpt All Context Instruction Emulation Cost
7038
InvEpt Single Context Emulation Intercepts/sec
7040
InvEpt Single Context Instruction Emulation Cost
7042
InvVpid All Context Emulation Intercepts/sec
7044
InvVpid All Context Instruction Emulation Cost
7046
InvVpid Single Context Emulation Intercepts/sec
7048
InvVpid Single Context Instruction Emulation Cost
7050
InvVpid Single Address Emulation Intercepts/sec
7052
InvVpid Single Address Instruction Emulation Cost
7054
Nested TLB Page Table Reclamations/sec
7056
Nested TLB Page Table Evictions/sec
7058
Flush Physical Address Space Hypercalls/sec
7060
Flush Physical Address List Hypercalls/sec
7062
Guest Run Time
7064
% Total Run Time
7066
% Hypervisor Run Time
7068
% Guest Run Time
7070
Total Messages/sec
7072
Total Intercepts Base
7074
Total Intercepts/sec
7076
Total Intercepts Cost
7078
% Remote Run Time
7080
Total Virtualization Instructions Emulated Base
7082
Total Virtualization Instructions Emulated/sec
7084
Total Virtualization Instructions Emulation Cost
7086
Global Reference Time
7088
Hypercalls Base
7090
Page Invalidations Base
7092
Control Register Accesses Base
7094
IO Instructions Base
7096
HLT Instructions Base
7098
MWAIT Instructions Base
7100
CPUID Instructions Base
7102
MSR Accesses Base
7104
Other Intercepts Base
7106
External Interrupts Base
7108
Pending Interrupts Base
7110
Emulated Instructions Base
7112
Debug Register Accesses Base
7114
Page Fault Intercepts Base
7116
Nested Page Fault Intercepts Base
7118
Logical Processor Dispatches Base
7120
Global I/O TLB Flushes Base
7122
Local I/O TLB Flushes Base
7124
Hypercalls Forwarded Base
7126
Page Invalidations Forwarded Base
7128
Control Register Accesses Forwarded Base
7130
IO Instructions Forwarded Base
7132
HLT Instructions Forwarded Base
7134
MWAIT Instructions Forwarded Base
7136
CPUID Instructions Forwarded Base
7138
MSR Accesses Forwarded Base
7140
Other Intercepts Forwarded Base
7142
External Interrupts Forwarded Base
7144
Pending Interrupts Forwarded Base
7146
Emulated Instructions Forwarded Base
7148
Debug Register Accesses Forwarded Base
7150
Page Fault Intercepts Forwarded Base
7152
VMCLEAR Emulation Intercepts Base
7154
VMPTRLD Emulation Intercepts Base
7156
VMPTRST Emulation Intercepts Base
7158
VMREAD Emulation Intercepts Base
7160
VMWRITE Emulation Intercepts Base
7162
VMXOFF Emulation Intercepts Base
7164
VMXON Emulation Intercepts Base
7166
Nested VM Entries Base
7168
Nested SLAT Soft Page Faults Base
7170
Nested SLAT Hard Page Faults Base
7172
InvEpt All Context Emulation Intercepts Base
7174
InvEpt Single Context Emulation Intercepts Base
7176
InvVpid All Context Emulation Intercepts Base
7178
InvVpid Single Context Emulation Intercepts Base
7180
InvVpid Single Address Emulation Intercepts Base
5174
Pacer Flow
5176
Packets dropped
5178
Packets scheduled
5180
Packets transmitted
5182
Bytes scheduled
5184
Bytes transmitted
5186
Bytes transmitted/sec
5188
Bytes scheduled/sec
5190
Packets transmitted/sec
5192
Packets scheduled/sec
5194
Packets dropped/sec
5196
Nonconforming packets scheduled
5198
Nonconforming packets scheduled/sec
5200
Average packets in shaper
5202
Max packets in shaper
5204
Average packets in sequencer
5206
Max packets in sequencer
5208
Maximum packets in netcard
5210
Average packets in netcard
5212
Nonconforming packets transmitted
5214
Nonconforming packets transmitted/sec
5216
Pacer Pipe
5218
Out of packets
5220
Flows opened
5222
Flows closed
5224
Flows rejected
5226
Flows modified
5228
Flow mods rejected
5230
Max simultaneous flows
5232
Nonconforming packets scheduled
5234
Nonconforming packets scheduled/sec
5236
Average packets in shaper
5238
Max packets in shaper
5240
Average packets in sequencer
5242
Max packets in sequencer
5244
Max packets in netcard
5246
Average packets in netcard
5248
Nonconforming packets transmitted
5250
Nonconforming packets transmitted/sec
7968
Generic IKEv1, AuthIP, and IKEv2
7970
IKEv1 Main Mode Negotiation Time
7972
AuthIP Main Mode Negotiation Time
7974
IKEv1 Quick Mode Negotiation Time
7976
AuthIP Quick Mode Negotiation Time
7978
Extended Mode Negotiation Time
7980
Packets Received/sec
7982
Invalid Packets Received/sec
7984
Successful Negotiations
7986
Successful Negotiations/sec
7988
Failed Negotiations
7990
Failed Negotiations/sec
7992
IKEv2 Main Mode Negotiation Time
7994
IKEv2 Quick Mode Negotiation Time
7996
IPsec IKEv2 IPv4
7998
Active Main Mode SAs
8000
Pending Main Mode Negotiations
8002
Main Mode Negotiations
8004
Main Mode Negotiations/sec
8006
Successful Main Mode Negotiations
8008
Successful Main Mode Negotiations/sec
8010
Failed Main Mode Negotiations
8012
Failed Main Mode Negotiations/sec
8014
Main Mode Negotiation Requests Received
8016
Main Mode Negotiation Requests Received/sec
8018
Active Quick Mode SAs
8020
Pending Quick Mode Negotiations
8022
Quick Mode Negotiations
8024
Quick Mode Negotiations/sec
8026
Successful Quick Mode Negotiations
8028
Successful Quick Mode Negotiations/sec
8030
Failed Quick Mode Negotiations
8032
Failed Quick Mode Negotiations/sec
7848
IPsec AuthIP IPv4
7850
Active Main Mode SAs
7852
Pending Main Mode Negotiations
7854
Main Mode Negotiations
7856
Main Mode Negotiations/sec
7858
Successful Main Mode Negotiations
7860
Successful Main Mode Negotiations/sec
7862
Failed Main Mode Negotiations
7864
Failed Main Mode Negotiations/sec
7866
Main Mode Negotiation Requests Received
7868
Main Mode Negotiation Requests Received/sec
7870
Main Mode SAs That Used Impersonation
7872
Main Mode SAs That Used Impersonation/sec
7874
Active Quick Mode SAs
7876
Pending Quick Mode Negotiations
7878
Quick Mode Negotiations
7880
Quick Mode Negotiations/sec
7882
Successful Quick Mode Negotiations
7884
Successful Quick Mode Negotiations/sec
7886
Failed Quick Mode Negotiations
7888
Failed Quick Mode Negotiations/sec
7890
Active Extended Mode SAs
7892
Pending Extended Mode Negotiations
7894
Extended Mode Negotiations
7896
Extended Mode Negotiations/sec
7898
Successful Extended Mode Negotiations
7900
Successful Extended Mode Negotiations/sec
7902
Failed Extended Mode Negotiations
7904
Failed Extended Mode Negotiations/sec
7906
Extended Mode SAs That Used Impersonation
8072
IPsec Connections
8074
Total Number current Connections
8076
Total number of cumulative connections since boot
8078
Max number of connections since boot
8080
Total Bytes In since start
8082
Total Bytes Out since start
8084
Number of failed authentications
7908
IPsec AuthIP IPv6
7910
Active Main Mode SAs
7912
Pending Main Mode Negotiations
7914
Main Mode Negotiations
7916
Main Mode Negotiations/sec
7918
Successful Main Mode Negotiations
7920
Successful Main Mode Negotiations/sec
7922
Failed Main Mode Negotiations
7924
Failed Main Mode Negotiations/sec
7926
Main Mode Negotiation Requests Received
7928
Main Mode Negotiation Requests Received/sec
7930
Main Mode SAs That Used Impersonation
7932
Main Mode SAs That Used Impersonation/sec
7934
Active Quick Mode SAs
7936
Pending Quick Mode Negotiations
7938
Quick Mode Negotiations
7940
Quick Mode Negotiations/sec
7942
Successful Quick Mode Negotiations
7944
Successful Quick Mode Negotiations/sec
7946
Failed Quick Mode Negotiations
7948
Failed Quick Mode Negotiations/sec
7950
Active Extended Mode SAs
7952
Pending Extended Mode Negotiations
7954
Extended Mode Negotiations
7956
Extended Mode Negotiations/sec
7958
Successful Extended Mode Negotiations
7960
Successful Extended Mode Negotiations/sec
7962
Failed Extended Mode Negotiations
7964
Failed Extended Mode Negotiations/sec
7966
Extended Mode SAs That Used Impersonation
8034
IPsec IKEv2 IPv6
8036
Active Main Mode SAs
8038
Pending Main Mode Negotiations
8040
Main Mode Negotiations
8042
Main Mode Negotiations/sec
8044
Successful Main Mode Negotiations
8046
Successful Main Mode Negotiations/sec
8048
Failed Main Mode Negotiations
8050
Failed Main Mode Negotiations/sec
8052
Main Mode Negotiation Requests Received
8054
Main Mode Negotiation Requests Received/sec
8056
Active Quick Mode SAs
8058
Pending Quick Mode Negotiations
8060
Quick Mode Negotiations
8062
Quick Mode Negotiations/sec
8064
Successful Quick Mode Negotiations
8066
Successful Quick Mode Negotiations/sec
8068
Failed Quick Mode Negotiations
8070
Failed Quick Mode Negotiations/sec
7648
WFPv4
7650
Inbound Packets Discarded/sec
7652
Outbound Packets Discarded/sec
7654
Packets Discarded/sec
7656
Blocked Binds
7658
Inbound Connections Blocked/sec
7660
Outbound Connections Blocked/sec
7662
Inbound Connections Allowed/sec
7664
Outbound Connections Allowed/sec
7666
Inbound Connections
7668
Outbound Connections
7670
Active Inbound Connections
7672
Active Outbound Connections
7674
Allowed Classifies/sec
7772
IPsec IKEv1 IPv4
7774
Active Main Mode SAs
7776
Pending Main Mode Negotiations
7778
Main Mode Negotiations
7780
Main Mode Negotiations/sec
7782
Successful Main Mode Negotiations
7784
Successful Main Mode Negotiations/sec
7786
Failed Main Mode Negotiations
7788
Failed Main Mode Negotiations/sec
7790
Main Mode Negotiation Requests Received
7792
Main Mode Negotiation Requests Received/sec
7794
Active Quick Mode SAs
7796
Pending Quick Mode Negotiations
7798
Quick Mode Negotiations
7800
Quick Mode Negotiations/sec
7802
Successful Quick Mode Negotiations
7804
Successful Quick Mode Negotiations/sec
7806
Failed Quick Mode Negotiations
7808
Failed Quick Mode Negotiations/sec
7810
IPsec IKEv1 IPv6
7812
Active Main Mode SAs
7814
Pending Main Mode Negotiations
7816
Main Mode Negotiations
7818
Main Mode Negotiations/sec
7820
Successful Main Mode Negotiations
7822
Successful Main Mode Negotiations/sec
7824
Failed Main Mode Negotiations
7826
Failed Main Mode Negotiations/sec
7828
Main Mode Negotiation Requests Received
7830
Main Mode Negotiation Requests Received/sec
7832
Active Quick Mode SAs
7834
Pending Quick Mode Negotiations
7836
Quick Mode Negotiations
7838
Quick Mode Negotiations/sec
7840
Successful Quick Mode Negotiations
7842
Successful Quick Mode Negotiations/sec
7844
Failed Quick Mode Negotiations
7846
Failed Quick Mode Negotiations/sec
7708
IPsec Driver
7710
Active Security Associations
7712
Pending Security Associations
7714
Incorrect SPI Packets
7716
Incorrect SPI Packets/sec
7718
Bytes Received in Tunnel Mode/sec
7720
Bytes Sent in Tunnel Mode/sec
7722
Bytes Received in Transport Mode/sec
7724
Bytes Sent in Transport Mode/sec
7726
Offloaded Security Associations
7728
Offloaded Bytes Received/sec
7730
Offloaded Bytes Sent/sec
7732
Packets That Failed Replay Detection
7734
Packets That Failed Replay Detection/sec
7736
Packets Not Authenticated
7738
Packets Not Authenticated/sec
7740
Packets Not Decrypted
7742
Packets Not Decrypted/sec
7744
SA Rekeys
7746
Security Associations Added
7748
Packets That Failed ESP Validation
7750
Packets That Failed ESP Validation/sec
7752
Packets That Failed UDP-ESP Validation
7754
Packets That Failed UDP-ESP Validation/sec
7756
Packets Received Over Wrong SA
7758
Packets Received Over Wrong SA/sec
7760
Plaintext Packets Received
7762
Plaintext Packets Received/sec
7764
Total Inbound Packets Received
7766
Inbound Packets Received/sec
7768
Total Inbound Packets Dropped
7770
Inbound Packets Dropped/sec
7704
WFP
7706
Provider Count
7676
WFPv6
7678
Inbound Packets Discarded/sec
7680
Outbound Packets Discarded/sec
7682
Packets Discarded/sec
7684
Blocked Binds
7686
Inbound Connections Blocked/sec
7688
Outbound Connections Blocked/sec
7690
Inbound Connections Allowed/sec
7692
Outbound Connections Allowed/sec
7694
Inbound Connections
7696
Outbound Connections
7698
Active Inbound Connections
7700
Active Outbound Connections
7702
Allowed Classifies/sec
8086
Peer Name Resolution Protocol
8088
Registration
8090
Resolve
8092
Cache Entry
8094
Average bytes sent
8096
Average bytes received
8098
Estimated cloud size
8100
Stale cache entry
8102
Send failures
8104
Receive failures
8106
Solicit sent per second
8108
Solicit received per second
8110
Advertise sent per second
8112
Advertise received per second
8114
Request sent per second
8116
Request received per second
8118
Flood sent per second
8120
Flood received per second
8122
Inquire sent per second
8124
Inquire received per second
8126
Authority sent per second
8128
Authority received per second
8130
Ack sent per second
8132
Ack received per second
8134
Lookup sent per second
8136
Lookup received per second
8138
Unknown message type received
4290
Authorization Manager Applications
4292
Total number of scopes
4294
Number of Scopes loaded in memory
4756
Fax Service
4758
Total minutes sending and receiving
4760
Total pages
4762
Total faxes sent and received
4764
Total bytes
4766
Failed faxes transmissions
4768
Failed outgoing connections
4770
Minutes sending
4772
Pages sent
4774
Faxes sent
4776
Bytes sent
4778
Failed receptions
4780
Minutes receiving
4782
Received pages
4784
Received faxes
4786
Bytes received
6098
Microsoft Winsock BSP
6100
Dropped Datagrams/sec
6102
Dropped Datagrams
6104
Rejected Connections/sec
6106
Rejected Connections
4680
BitLocker
4682
Min Read Split Size
4684
Max Read Split Size
4686
Min Write Split Size
4688
Max Write Split Size
4690
Read Requests/sec
4692
Read Subrequests/sec
4694
Write Requests/sec
4696
Write Subrequests/sec
13414
Storage Spaces Virtual Disk
13416
Virtual Disk Active
13418
Virtual Disk Active Bytes
13420
Virtual Disk Missing
13422
Virtual Disk Missing Bytes
13424
Virtual Disk Stale
13426
Virtual Disk Stale Bytes
13428
Virtual Disk Need Reallocation
13430
Virtual Disk Need Reallocation Bytes
13432
Virtual Disk Need Regeneration
13434
Virtual Disk Need Regeneration Bytes
13436
Virtual Disk Regenerating
13438
Virtual Disk Regenerating Bytes
13440
Virtual Disk Pending Deletion
13442
Virtual Disk Pending Deletion Bytes
13444
Virtual Disk Total
13446
Virtual Disk Total Bytes
13488
Storage Spaces Write Cache
13490
Cache Writes/sec
13492
Cache Write Bytes/sec
13494
Avg. Cache Bytes/Write
13496
Cache Overwrites/sec
13498
Cache Overwrite Bytes/sec
13500
Avg. Cache Bytes/Overwrite
13502
Cache Evicts/sec
13504
Cache Evict Bytes/sec
13506
Avg. Cache Bytes/Evict
13508
Current Destage Queue Length
13510
Destage Operations/sec
13512
Avg. Destage sec/Operation
13514
Avg. Destage Queue Length
13516
Destage Optimized Operations/sec
13518
Destage Evicts/sec
13520
Avg. Destage Evicts/Operation
13522
Destage Evict Bytes/sec
13524
Avg. Destage Bytes/Evict
13526
Avg. Destage Evict Bytes/Operation
13528
Destage Transfers/sec
13530
Avg. Destage Transfers/Operation
13532
Avg. Destage Transfers/Evict
13534
Destage Transfer Bytes/sec
13536
Avg. Destage Bytes/Transfer
13538
Avg. Destage Transfer Bytes/Operation
13540
Bytes Cached
13542
Bytes Reserved
13544
Bytes Reclaimable
13546
Bytes Used
13548
Cache Size
13550
Cache Writes
13552
Cache Overwrites
13554
Cache Evicts
13556
Destage Operations
13558
Destage Evicts
13560
Destage Transfers
13448
Storage Spaces Tier
13450
Tier Reads/sec
13452
Avg. Tier sec/Read
13454
Avg. Tier Read Queue Length
13456
Tier Read Bytes/sec
13458
Avg. Tier Bytes/Read
13460
Tier Writes/sec
13462
Avg. Tier sec/Write
13464
Avg. Tier Write Queue Length
13466
Tier Write Bytes/sec
13468
Avg. Tier Bytes/Write
13470
Current Tier Queue Length
13472
Tier Transfers/sec
13474
Avg. Tier sec/Transfer
13476
Avg. Tier Queue Length
13478
Tier Transfer Bytes/sec
13480
Avg. Tier Bytes/Transfer
13482
Tier Reads
13484
Tier Writes
13486
Tier Transfers
6606
Hyper-V Virtual Machine Bus Pipes
6608
Reads/sec
6610
Writes/sec
6612
Bytes Read/sec
6614
Bytes Written/sec
8140
Offline Files
8142
Bytes Received
8144
Bytes Transmitted
8146
Bytes Transmitted/sec
8150
Bytes Received/sec
8154
Client Side Caching
8156
SMB BranchCache Bytes Requested
8158
SMB BranchCache Bytes Received
8160
SMB BranchCache Bytes Published
8162
SMB BranchCache Bytes Requested From Server
8164
SMB BranchCache Hashes Requested
8166
SMB BranchCache Hashes Received
8168
SMB BranchCache Hash Bytes Received
8170
Prefetch Operations Queued
8172
Prefetch Bytes Read From Cache
8174
Prefetch Bytes Read From Server
8176
Application Bytes Read From Cache
8178
Application Bytes Read From Server
8180
Application Bytes Read From Server (Not Cached)
4358
Teredo Relay
4360
In - Teredo Relay Total Packets: Success + Error
4362
In - Teredo Relay Success Packets: Total
4364
In - Teredo Relay Success Packets: Bubbles
4366
In - Teredo Relay Success Packets: Data Packets
4368
In - Teredo Relay Error Packets: Total
4370
In - Teredo Relay Error Packets: Header Error
4372
In - Teredo Relay Error Packets: Source Error
4374
In - Teredo Relay Error Packets: Destination Error
4376
Out - Teredo Relay Total Packets: Success + Error
4378
Out - Teredo Relay Success Packets
4380
Out - Teredo Relay Success Packets: Bubbles
4382
Out - Teredo Relay Success Packets: Data Packets
4384
Out - Teredo Relay Error Packets
4386
Out - Teredo Relay Error Packets: Header Error
4388
Out - Teredo Relay Error Packets: Source Error
4390
Out - Teredo Relay Error Packets: Destination Error
4392
In - Teredo Relay Total Packets: Success + Error / sec
4394
Out - Teredo Relay Total Packets: Success + Error / sec
4396
In - Teredo Relay Success Packets: Data Packets User Mode
4398
In - Teredo Relay Success Packets: Data Packets Kernel Mode
4400
Out - Teredo Relay Success Packets: Data Packets User Mode
4402
Out - Teredo Relay Success Packets: Data Packets Kernel Mode
4404
IPHTTPS Session
4406
Packets received on this session
4408
Packets sent on this session
4410
Bytes received on this session
4412
Bytes sent on this session
4414
Errors - Transmit errors on this session
4416
Errors - Receive errors on this session
4418
Duration - Duration of the session (Seconds)
4442
DNS64 Global
4444
AAAA queries - Successful
4446
AAAA queries - Failed
4448
IP6.ARPA queries - Matched
4450
Other queries - Successful
4452
Other queries - Failed
4454
AAAA - Synthesized records
4420
IPHTTPS Global
4422
In - Total bytes received
4424
Out - Total bytes sent
4426
Drops - Neighbor resolution timeouts
4428
Errors - Authentication Errors
4430
Out - Total bytes forwarded
4432
Errors - Transmit errors on the server
4434
Errors - Receive errors on the server
4436
In - Total packets received
4438
Out - Total packets sent
4440
Sessions - Total sessions
4328
Teredo Server
4330
In - Teredo Server Total Packets: Success + Error
4332
In - Teredo Server Success Packets: Total
4334
In - Teredo Server Success Packets: Bubbles
4336
In - Teredo Server Success Packets: Echo
4338
In - Teredo Server Success Packets: RS-Primary
4340
In - Teredo Server Success Packets: RS-Secondary
4342
In - Teredo Server Error Packets: Total
4344
In - Teredo Server Error Packets: Header Error
4346
In - Teredo Server Error Packets: Source Error
4348
In - Teredo Server Error Packets: Destination Error
4350
In - Teredo Server Error Packets: Authentication Error
4352
Out - Teredo Server: RA-Primary
4354
Out - Teredo Server: RA-Secondary
4356
In - Teredo Server Total Packets: Success + Error / sec
4304
Teredo Client
4306
In - Teredo Router Advertisement
4308
In - Teredo Bubble
4310
In - Teredo Data
4312
In - Teredo Invalid
4314
Out - Teredo Router Solicitation
4316
Out - Teredo Bubble
4318
Out - Teredo Data
4320
In - Teredo Data User Mode
4322
In - Teredo Data Kernel Mode
4324
Out - Teredo Data User Mode
4326
Out - Teredo Data Kernel Mode
6108
Hyper-V Dynamic Memory Integration Service
6110
Maximum Memory, Mbytes
6400
ServiceModelService 4.0.0.0
6402
Calls
6404
Calls Per Second
6406
Calls Outstanding
6408
Calls Failed
6410
Calls Failed Per Second
6412
Calls Faulted
6414
Calls Faulted Per Second
6416
Calls Duration
6418
Security Validation and Authentication Failures
6420
Security Validation and Authentication Failures Per Second
6422
Security Calls Not Authorized
6424
Security Calls Not Authorized Per Second
6426
Instances
6428
Instances Created Per Second
6430
Reliable Messaging Sessions Faulted
6432
Reliable Messaging Sessions Faulted Per Second
6434
Reliable Messaging Messages Dropped
6436
Reliable Messaging Messages Dropped Per Second
6438
Transactions Flowed
6440
Transactions Flowed Per Second
6442
Transacted Operations Committed
6444
Transacted Operations Committed Per Second
6446
Transacted Operations Aborted
6448
Transacted Operations Aborted Per Second
6450
Transacted Operations In Doubt
6452
Transacted Operations In Doubt Per Second
6454
Queued Poison Messages
6456
Queued Poison Messages Per Second
6458
Queued Messages Rejected
6460
Queued Messages Rejected Per Second
6462
Queued Messages Dropped
6464
Queued Messages Dropped Per Second
6466
Percent Of Max Concurrent Calls
6468
Percent Of Max Concurrent Instances
6470
Percent Of Max Concurrent Sessions
6472
CallDurationBase
6474
CallsPercentMaxConcurrentCallsBase
6476
InstancesPercentMaxConcurrentInstancesBase
6478
SessionsPercentMaxConcurrentSessionsBase
6520
ServiceModelOperation 4.0.0.0
6522
Calls
6524
Calls Per Second
6526
Calls Outstanding
6528
Calls Failed
6530
Call Failed Per Second
6532
Calls Faulted
6534
Calls Faulted Per Second
6536
Calls Duration
6538
Security Validation and Authentication Failures
6540
Security Validation and Authentication Failures Per Second
6542
Security Calls Not Authorized
6544
Security Calls Not Authorized Per Second
6546
Transactions Flowed
6548
Transactions Flowed Per Second
6550
CallsDurationBase
6480
ServiceModelEndpoint 4.0.0.0
6482
Calls
6484
Calls Per Second
6486
Calls Outstanding
6488
Calls Failed
6490
Calls Failed Per Second
6492
Calls Faulted
6494
Calls Faulted Per Second
6496
Calls Duration
6498
Security Validation and Authentication Failures
6500
Security Validation and Authentication Failures Per Second
6502
Security Calls Not Authorized
6504
Security Calls Not Authorized Per Second
6506
Reliable Messaging Sessions Faulted
6508
Reliable Messaging Sessions Faulted Per Second
6510
Reliable Messaging Messages Dropped
6512
Reliable Messaging Messages Dropped Per Second
6514
Transactions Flowed
6516
Transactions Flowed Per Second
6518
CallDurationBase
7490
Power Meter
7492
Power
7494
Power Budget
7496
Energy Meter
7498
Time
7500
Energy
7502
Power
7506
TCPIP Performance Diagnostics
7508
IPv4 NBLs indicated with low-resource flag
7510
IPv4 NBLs/sec indicated with low-resource flag
7512
IPv6 NBLs indicated with low-resource flag
7514
IPv6 NBLs/sec indicated with low-resource flag
7516
IPv4 NBLs indicated without prevalidation
7518
IPv4 NBLs/sec indicated without prevalidation
7520
IPv6 NBLs indicated without prevalidation
7522
IPv6 NBLs/sec indicated without prevalidation
7524
IPv4 NBLs treated as non-prevalidated
7526
IPv4 NBLs/sec treated as non-prevalidated
7528
IPv6 NBLs treated as non-prevalidated
7530
IPv6 NBLs/sec treated as non-prevalidated
7532
IPv4 outbound NBLs not processed via fast path
7534
IPv4 outbound NBLs/sec not processed via fast path
7536
IPv6 outbound NBLs not processed via fast path
7538
IPv6 outbound NBLs/sec not processed via fast path
7540
TCP inbound segments not processed via fast path
7542
TCP inbound segments/sec not processed via fast path
7544
TCP connect requests fallen off loopback fast path
7546
TCP connect requests/sec fallen off loopback fast path
7548
Denied connect or send requests in low-power mode
6382
HTTP Service Request Queues
6384
CurrentQueueSize
6386
MaxQueueItemAge
6388
ArrivalRate
6390
RejectionRate
6392
RejectedRequests
6394
CacheHitRate
6362
HTTP Service Url Groups
6364
BytesSentRate
6366
BytesReceivedRate
6368
BytesTransferredRate
6370
CurrentConnections
6372
MaxConnections
6374
ConnectionAttempts
6376
GetRequests
6378
HeadRequests
6380
AllRequests
6348
HTTP Service
6350
CurrentUrisCached
6352
TotalUrisCached
6354
UriCacheHits
6356
UriCacheMisses
6358
UriCacheFlushes
6360
TotalFlushedUris
5114
PowerShell Workflow
5116
# of failed workflow jobs
5118
# of failed workflow jobs/sec
5120
# of resumed workflow jobs
5122
# of resumed workflow jobs/sec
5124
# of running workflow jobs
5126
# of running workflow jobs / sec
5128
# of stopped workflow jobs
5130
# of stopped workflow jobs / sec
5132
# of succeeded workflow jobs
5134
# of succeeded workflow jobs/sec
5136
# of suspended workflow jobs
5138
# of suspended workflow jobs/sec
5140
# of terminated workflow jobs
5142
# of terminated workflow jobs / sec
5144
# of waiting workflow jobs
5146
Activity Host Manager: # of busy host processes
5148
Activity Host Manager: # of failed requests/sec
5150
Activity Host Manager: # of failed requests in queue
5152
Activity Host Manager: # of incoming requests/sec
5154
Activity Host Manager: # of pending requests in queue
5156
Activity Host Manager: # of created host processes
5158
Activity Host Manager: # of disposed host processes
5160
Activity Host Manager: host processes pool size
5162
PowerShell Remoting: # of pending requests in queue
5164
PowerShell Remoting: # of requests being serviced
5166
PowerShell Remoting: # of forced to wait requests in queue
5168
PowerShell Remoting: # of created connections
5170
PowerShell Remoting: # of disposed connections
5172
PowerShell Remoting: # of connections closed-reopened
1946
Windows Media Player Metadata
1948
Files Scanned/Minute
1952
Monitored Folder Updates/Second
1956
Groveler Service Routine Executions/Second
1960
Library Description Updates/Second
1964
Library Description Change Notifications/Second
1968
File Scanning Thread Prioirty
1970
Directory Change Queue Length
1972
Scanning State
1974
Dirty Directory Hit Count
1976
Timestamp Directory Hit Count
1978
AFTS Execution Time (ms)
1980
URL Classification Time (ms)
1982
Property Extraction Time (ms)
1984
Art Extraction Time (ms)
1986
Reorganize Time (ms)
1988
Commit Time (ms)
1990
Normalization Time (ms)
8234
RemoteFX Graphics
8236
Input Frames/Second
8238
Graphics Compression ratio
8240
Output Frames/Second
8242
Frames Skipped/Second - Insufficient Client Resources
8244
Frames Skipped/Second - Insufficient Network Resources
8246
Frames Skipped/Second - Insufficient Server Resources
8248
Frame Quality
8250
Average Encoding Time
8252
Source Frames/Second
8254
RemoteFX Network
8256
Base TCP RTT
8258
Current TCP RTT
8260
Current TCP Bandwidth
8262
Total Received Rate
8264
TCP Received Rate
8266
UDP Received Rate
8268
UDP Packets Received/sec
8270
Total Sent Rate
8272
TCP Sent Rate
8274
UDP Sent Rate
8276
UDP Packets Sent/sec
8278
Sent Rate P0
8280
Sent Rate P1
8282
Sent Rate P2
8284
Sent Rate P3
8286
Loss Rate
8288
Retransmission Rate
8290
FEC Rate
8294
Base UDP RTT
8296
Current UDP RTT
8298
Current UDP Bandwidth
8300
Total Sent Bytes
8302
Total Received Bytes
4852
SMB Server Shares
4854
Received Bytes/sec
4856
Requests/sec
4858
Tree Connect Count
4860
Current Open File Count
4862
Sent Bytes/sec
4864
Transferred Bytes/sec
4866
Current Pending Requests
4868
Avg. sec/Request
4872
Write Requests/sec
4874
Avg. sec/Write
4878
Write Bytes/sec
4880
Read Requests/sec
4882
Avg. sec/Read
4886
Read Bytes/sec
4888
Total File Open Count
4890
Files Opened/sec
4892
Current Durable Open File Count
4894
Total Durable Handle Reopen Count
4896
Total Failed Durable Handle Reopen Count
4898
% Resilient Handles
4902
Total Resilient Handle Reopen Count
4904
Total Failed Resilient Handle Reopen Count
4906
% Persistent Handles
4910
Total Persistent Handle Reopen Count
4912
Total Failed Persistent Handle Reopen Count
4914
Metadata Requests/sec
4916
Avg. sec/Data Request
4920
Avg. Data Bytes/Request
4924
Avg. Bytes/Read
4928
Avg. Bytes/Write
4932
Avg. Read Queue Length
4934
Avg. Write Queue Length
4936
Avg. Data Queue Length
4938
Data Bytes/sec
4940
Data Requests/sec
4942
Current Data Queue Length
4944
SMB Server Sessions
4946
Received Bytes/sec
4948
Requests/sec
4950
Tree Connect Count
4952
Current Open File Count
4954
Sent Bytes/sec
4956
Transferred Bytes/sec
4958
Current Pending Requests
4960
Avg. sec/Request
4964
Write Requests/sec
4966
Avg. sec/Write
4970
Write Bytes/sec
4972
Read Requests/sec
4974
Avg. sec/Read
4978
Read Bytes/sec
4980
Total File Open Count
4982
Files Opened/sec
4984
Current Durable Open File Count
4986
Total Durable Handle Reopen Count
4988
Total Failed Durable Handle Reopen Count
4990
% Resilient Handles
4994
Total Resilient Handle Reopen Count
4996
Total Failed Resilient Handle Reopen Count
4998
% Persistent Handles
5002
Total Persistent Handle Reopen Count
5004
Total Failed Persistent Handle Reopen Count
5006
Metadata Requests/sec
5008
Avg. sec/Data Request
5012
Avg. Data Bytes/Request
5016
Avg. Bytes/Read
5020
Avg. Bytes/Write
5024
Avg. Read Queue Length
5026
Avg. Write Queue Length
5028
Avg. Data Queue Length
5030
Data Bytes/sec
5032
Data Requests/sec
5034
Current Data Queue Length
5036
SMB Server
5038
Read Bytes/sec
5040
Read Requests/sec
5042
Write Bytes/sec
5044
Write Requests/sec
5046
Send Bytes/sec
5048
Receive Bytes/sec
1848
Netlogon
1850
Semaphore Waiters
1852
Semaphore Holders
1854
Semaphore Acquires
1856
Semaphore Timeouts
1858
Average Semaphore Hold Time
1860
Semaphore Hold Time Base
1862
LDAP Bind Time
1864
Last Authentication Time
1866
Trusted Domain Controller Count
7296
XHCI Interrupter
7298
Interrupts/sec
7300
DPCs/sec
7302
Events processed/DPC
7304
DPC count
7306
EventRingFullCount
7308
DpcRequeueCount
7320
XHCI TransferRing
7322
Transfers/sec
7324
Failed Transfer Count
7326
Bytes/Sec
7328
Isoch TD/sec
7330
Isoch TD Failures/sec
7332
Missed Service Error Count
7334
Underrun Overrun count
7310
XHCI CommonBuffer
7312
PagesTotal
7314
PagesInUse
7316
AllocationCount
7318
FreeCount
7550
Distributed Routing Table
7552
Registrations
7554
Searches
7556
Cache Entries
7558
Average Bytes/second Sent
7560
Average Bytes/second Received
7562
Estimated cloud size
7564
Stale Cache Entries
7566
Send Failures
7568
Receive Failures
7570
Solicit Messages Sent/second
7572
Solicit Messages Received/second
7574
Advertise Messages Sent/second
7576
Advertise Messages Received/second
7578
Request Messages Sent/second
7580
Request Messages Received/second
7582
Flood Messages Sent/second
7584
Flood Messages Received/second
7586
Inquire Messages Sent/second
7588
Inquire Messages Received/second
7590
Authority Sent/second
7592
Authority Messages Received/second
7594
Ack Messages Sent/second
7596
Ack Messages Received/second
7598
Lookup Messages Sent/second
7600
Lookup Messages Received/second
7602
Unrecognized Messages Received
5748
PacketDirect Receive Filters
5750
Packets Matched
5752
Packets Matched/sec
5754
Bytes Matched
5756
Bytes Matched/sec
5724
PacketDirect Transmit Counters
5726
Packets Transmitted
5728
Packets Transmitted/sec
5730
Bytes Transmitted
5732
Bytes Transmitted/sec
5712
Physical Network Interface Card Activity
5714
Device Power State
5716
% Time Suspended (Instantaneous)
5718
% Time Suspended (Lifetime)
5720
Low Power Transitions (Lifetime)
5610
Per Processor Network Interface Card Activity
5612
DPCs Queued/sec
5614
Interrupts/sec
5616
Receive Indications/sec
5618
Return Packet Calls/sec
5620
Passive Return Packet Calls/sec
5622
Received Packets/sec
5624
Returned Packets/sec
5626
Passive Returned Packets/sec
5628
DPCs Queued on Other CPUs/sec
5630
Send Request Calls/sec
5632
Passive Send Request Calls/sec
5634
Send Complete Calls/sec
5636
Sent Packets/sec
5638
Passive Sent Packets/sec
5640
Sent Complete Packets/sec
5642
Build Scatter Gather List Calls/sec
5644
RSS Indirection Table Change Calls/sec
5646
Low Resource Receive Indications/sec
5648
Low Resource Received Packets/sec
5650
Tcp Offload Receive Indications/sec
5652
Tcp Offload Send Request Calls/sec
5654
Tcp Offload Receive bytes/sec
5656
Tcp Offload Send bytes/sec
5658
DPCs Deferred/sec
5660
Packets Coalesced/sec
5662
Per Processor Network Activity Cycles
5664
Interrupt DPC Cycles/sec
5666
Interrupt Cycles/sec
5668
NDIS Receive Indication Cycles/sec
5670
Stack Receive Indication Cycles/sec
5672
NDIS Return Packet Cycles/sec
5674
Miniport Return Packet Cycles/sec
5676
NDIS Send Cycles/sec
5678
Miniport Send Cycles/sec
5680
NDIS Send Complete Cycles/sec
5682
Build Scatter Gather Cycles/sec
5684
Miniport RSS Indirection Table Change Cycles
5686
Stack Send Complete Cycles/sec
5688
Interrupt DPC Latency Cycles/sec
5786
PacketDirect Queue Depth
5788
Average Queue Depth
5790
% Average Queue Utilization
5734
PacketDirect Receive Counters
5736
Packets Received
5738
Packets Received/sec
5740
Bytes Received
5742
Bytes Received/sec
5744
Packets Dropped
5746
Packets Dropped/sec
5690
RDMA Activity
5692
RDMA Initiated Connections
5694
RDMA Accepted Connections
5696
RDMA Failed Connection Attempts
5698
RDMA Connection Errors
5700
RDMA Active Connections
5702
RDMA Completion Queue Errors
5704
RDMA Inbound Bytes/sec
5706
RDMA Outbound Bytes/sec
5708
RDMA Inbound Frames/sec
5710
RDMA Outbound Frames/sec
5758
PacketDirect EC Utilization
5760
Processor Number
5762
Total Iterations
5764
Iterations/sec
5766
Total Busy Wait Iterations
5768
Busy Wait Iterations/sec
5772
% Busy Wait Iterations
5776
% Idle Time
5778
% Busy Waiting Time
5780
% Processing Time
5782
TX Queue Count
5784
RX Queue Count
5518
FileSystem Disk Activity
5520
FileSystem Bytes Read
5522
FileSystem Bytes Written
5420
Event Tracing for Windows Session
5422
Buffer Memory Usage -- Paged Pool
5424
Buffer Memory Usage -- Non-Paged Pool
5426
Events Logged per sec
5428
Events Lost
5430
Number of Real-Time Consumers
5252
Processor Information
5254
% Processor Time
5256
% User Time
5258
% Privileged Time
5260
Interrupts/sec
5262
% DPC Time
5264
% Interrupt Time
5266
DPCs Queued/sec
5268
DPC Rate
5270
% Idle Time
5272
% C1 Time
5274
% C2 Time
5276
% C3 Time
5278
C1 Transitions/sec
5280
C2 Transitions/sec
5282
C3 Transitions/sec
5284
% Priority Time
5286
Parking Status
5288
Processor Frequency
5290
% of Maximum Frequency
5292
Processor State Flags
5294
Clock Interrupts/sec
5296
Average Idle Time
5300
Idle Break Events/sec
5302
% Processor Performance
5306
% Processor Utility
5310
% Privileged Utility
5314
% Performance Limit
5316
Performance Limit Flags
5524
Thermal Zone Information
5526
Temperature
5528
% Passive Limit
5530
Throttle Reasons
5406
Event Tracing for Windows
5408
Total Number of Distinct Enabled Providers
5410
Total Number of Distinct Pre-Enabled Providers
5412
Total Number of Distinct Disabled Providers
5414
Total Number of Active Sessions
5416
Total Memory Usage --- Paged Pool
5418
Total Memory Usage --- Non-Paged Pool
5320
Synchronization
5322
Spinlock Acquires/sec
5324
Spinlock Contentions/sec
5326
Spinlock Spins/sec
5328
IPI Send Broadcast Requests/sec
5330
IPI Send Routine Requests/sec
5332
IPI Send Software Interrupts/sec
5334
Exec. Resource Total Initialize/sec
5336
Exec. Resource Total Re-Initialize/sec
5338
Exec. Resource Total Delete/sec
5340
Exec. Resource Total Acquires/sec
5342
Exec. Resource Total Contentions/sec
5344
Exec. Resource Total Exclusive Releases/sec
5346
Exec. Resource Total Shared Releases/sec
5348
Exec. Resource Total Conv. Exclusive To Shared/sec
5350
Exec. Resource Attempts AcqExclLite/sec
5352
Exec. Resource Acquires AcqExclLite/sec
5354
Exec. Resource Recursive Excl. Acquires AcqExclLite/sec
5356
Exec. Resource Contention AcqExclLite/sec
5358
Exec. Resource no-Waits AcqExclLite/sec
5360
Exec. Resource Attempts AcqShrdLite/sec
5362
Exec. Resource Recursive Excl. Acquires AcqShrdLite/sec
5364
Exec. Resource Acquires AcqShrdLite/sec
5366
Exec. Resource Recursive Sh. Acquires AcqShrdLite/sec
5368
Exec. Resource Contention AcqShrdLite/sec
5370
Exec. Resource no-Waits AcqShrdLite/sec
5372
Exec. Resource Attempts AcqShrdStarveExcl/sec
5374
Exec. Resource Recursive Excl. Acquires AcqShrdStarveExcl/sec
5376
Exec. Resource Acquires AcqShrdStarveExcl/sec
5378
Exec. Resource Recursive Sh. Acquires AcqShrdStarveExcl/sec
5380
Exec. Resource Contention AcqShrdStarveExcl/sec
5382
Exec. Resource no-Waits AcqShrdStarveExcl/sec
5384
Exec. Resource Attempts AcqShrdWaitForExcl/sec
5386
Exec. Resource Recursive Excl. Acquires AcqShrdWaitForExcl/sec
5388
Exec. Resource Acquires AcqShrdWaitForExcl/sec
5390
Exec. Resource Recursive Sh. Acquires AcqShrdWaitForExcl/sec
5392
Exec. Resource Contention AcqShrdWaitForExcl/sec
5394
Exec. Resource no-Waits AcqShrdWaitForExcl/sec
5396
Exec. Resource Set Owner Pointer Exclusive/sec
5398
Exec. Resource Set Owner Pointer Shared (New Owner)/sec
5400
Exec. Resource Set Owner Pointer Shared (Existing Owner)/sec
5402
Exec. Resource Boost Excl. Owner/sec
5404
Exec. Resource Boost Shared Owners/sec
5432
SynchronizationNuma
5434
Spinlock Acquires/sec
5436
Spinlock Contentions/sec
5438
Spinlock Spins/sec
5440
IPI Send Broadcast Requests/sec
5442
IPI Send Routine Requests/sec
5444
IPI Send Software Interrupts/sec
5446
Exec. Resource Total Initialize/sec
5448
Exec. Resource Total Re-Initialize/sec
5450
Exec. Resource Total Delete/sec
5452
Exec. Resource Total Acquires/sec
5454
Exec. Resource Total Contentions/sec
5456
Exec. Resource Total Exclusive Releases/sec
5458
Exec. Resource Total Shared Releases/sec
5460
Exec. Resource Total Conv. Exclusive To Shared/sec
5462
Exec. Resource Attempts AcqExclLite/sec
5464
Exec. Resource Acquires AcqExclLite/sec
5466
Exec. Resource Recursive Excl. Acquires AcqExclLite/sec
5468
Exec. Resource Contention AcqExclLite/sec
5470
Exec. Resource no-Waits AcqExclLite/sec
5472
Exec. Resource Attempts AcqShrdLite/sec
5474
Exec. Resource Recursive Excl. Acquires AcqShrdLite/sec
5476
Exec. Resource Acquires AcqShrdLite/sec
5478
Exec. Resource Recursive Sh. Acquires AcqShrdLite/sec
5480
Exec. Resource Contention AcqShrdLite/sec
5482
Exec. Resource no-Waits AcqShrdLite/sec
5484
Exec. Resource Attempts AcqShrdStarveExcl/sec
5486
Exec. Resource Recursive Excl. Acquires AcqShrdStarveExcl/sec
5488
Exec. Resource Acquires AcqShrdStarveExcl/sec
5490
Exec. Resource Recursive Sh. Acquires AcqShrdStarveExcl/sec
5492
Exec. Resource Contention AcqShrdStarveExcl/sec
5494
Exec. Resource no-Waits AcqShrdStarveExcl/sec
5496
Exec. Resource Attempts AcqShrdWaitForExcl/sec
5498
Exec. Resource Recursive Excl. Acquires AcqShrdWaitForExcl/sec
5500
Exec. Resource Acquires AcqShrdWaitForExcl/sec
5502
Exec. Resource Recursive Sh. Acquires AcqShrdWaitForExcl/sec
5504
Exec. Resource Contention AcqShrdWaitForExcl/sec
5506
Exec. Resource no-Waits AcqShrdWaitForExcl/sec
5508
Exec. Resource Set Owner Pointer Exclusive/sec
5510
Exec. Resource Set Owner Pointer Shared (New Owner)/sec
5512
Exec. Resource Set Owner Pointer Shared (Existing Owner)/sec
5514
Exec. Resource Boost Excl. Owner/sec
5516
Exec. Resource Boost Shared Owners/sec
10070
Windows Time Service
10072
Computed Time Offset
10074
Clock Frequency Adjustment
10076
NTP Roundtrip Delay
10078
NTP Client Time Source Count
10080
NTP Server Incoming Requests
10082
NTP Server Outgoing Responses
4608
SMB Client Shares
4610
Read Bytes/sec
4612
Write Bytes/sec
4614
Read Requests/sec
4616
Write Requests/sec
4618
Avg. Bytes/Read
4622
Avg. Bytes/Write
4626
Avg. sec/Read
4630
Avg. sec/Write
4634
Data Bytes/sec
4636
Data Requests/sec
4638
Avg. Data Bytes/Request
4642
Avg. sec/Data Request
4646
Current Data Queue Length
4648
Avg. Read Queue Length
4650
Avg. Write Queue Length
4652
Avg. Data Queue Length
4654
Metadata Requests/sec
4656
Credit Stalls/sec
8230
AppV Client Streamed Data Percentage
8232
Primary Feature % Streamed
6084
Network QoS Policy
6086
Packets transmitted
6088
Packets transmitted/sec
6090
Bytes transmitted
6092
Bytes transmitted/sec
6094
Packets dropped
6096
Packets dropped/sec
8182
BranchCache
8184
Retrieval: Bytes from server
8186
Retrieval: Bytes from cache
8188
Retrieval: Bytes served
8190
Discovery: Weighted average discovery time
8192
SMB: Bytes from cache
8194
SMB: Bytes from server
8196
BITS: Bytes from cache
8198
BITS: Bytes from server
8200
WININET: Bytes from cache
8202
WININET: Bytes from server
8204
WINHTTP: Bytes from cache
8206
WINHTTP: Bytes from server
8208
OTHER: Bytes from cache
8210
OTHER: Bytes from server
8212
Discovery: Attempted discoveries
8214
Local Cache: Cache complete file segments
8216
Local Cache: Cache partial file segments
8218
Hosted Cache: Client file segment offers made
8220
Retrieval: Average branch rate
8222
Discovery: Successful discoveries
8224
Hosted Cache: Segment offers queue size
8226
Publication Cache: Published contents
8228
Local Cache: Average access time
4820
WSMan Quota Statistics
4822
Total Requests/Second
4824
User Quota Violations/Second
4826
System Quota Violations/Second
4828
Active Shells
4830
Active Operations
4832
Active Users
4834
Process ID
1888
RAS
1890
Total Clients
1892
Max Clients
1894
Failed Authentications
1896
Bytes Received By Disconnected Clients
1898
Bytes Transmitted By Disconnected Clients
o"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Perflib\CurrentLanguage]
"Help"="3
The System performance object consists of counters that apply to more than one instance of a component processors on the computer.
5
The Memory performance object consists of counters that describe the behavior of physical and virtual memory on the computer. Physical memory is the amount of random access memory on the computer. Virtual memory consists of the space in physical memory and on disk. Many of the memory counters monitor paging, which is the movement of pages of code and data between disk and physical memory. Excessive paging, a symptom of a memory shortage, can cause delays which interfere with all system processes.
7
% Processor Time is the percentage of elapsed time that the processor spends to execute a non-Idle thread. It is calculated by measuring the percentage of time that the processor spends executing the idle thread and then subtracting that value from 100%. (Each processor has an idle thread that consumes cycles when no other threads are ready to run). This counter is the primary indicator of processor activity, and displays the average percentage of busy time observed during the sample interval. It should be noted that the accounting calculation of whether the processor is idle is performed at an internal sampling interval of the system clock (10ms). On todays fast processors, % Processor Time can therefore underestimate the processor utilization as the processor may be spending a lot of time servicing threads between the system clock sampling interval. Workload based timer applications are one example of applications which are more likely to be measured inaccurately as timers are signaled just after the sample is taken.
9
% Total DPC Time is the average percentage of time that all processors spend receiving and servicing deferred procedure calls (DPCs). (DPCs are interrupts that run at a lower priority than the standard interrupts). It is the sum of Processor: % DPC Time for all processors on the computer, divided by the number of processors. System: % Total DPC Time is a component of System: % Total Privileged Time because DPCs are executed in privileged mode. DPCs are counted separately and are not a component of the interrupt count. This counter displays the average busy time as a percentage of the sample time.
11
File Read Operations/sec is the combined rate of file system read requests to all devices on the computer, including requests to read from the file system cache. It is measured in numbers of reads. This counter displays the difference between the values observed in the last two samples, divided by the duration of the sample interval.
13
File Write Operations/sec is the combined rate of the file system write requests to all devices on the computer, including requests to write to data in the file system cache. It is measured in numbers of writes. This counter displays the difference between the values observed in the last two samples, divided by the duration of the sample interval.
15
File Control Operations/sec is the combined rate of file system operations that are neither reads nor writes, such as file system control requests and requests for information about device characteristics or status. This is the inverse of System: File Data Operations/sec and is measured in number of operations perf second. This counter displays the difference between the values observed in the last two samples, divided by the duration of the sample interval.
17
File Read Bytes/sec is the overall rate at which bytes are read to satisfy file system read requests to all devices on the computer, including reads from the file system cache. It is measured in number of bytes per second. This counter displays the difference between the values observed in the last two samples, divided by the duration of the sample interval.
19
File Write Bytes/sec is the overall rate at which bytes are written to satisfy file system write requests to all devices on the computer, including writes to the file system cache. It is measured in number of bytes per second. This counter displays the difference between the values observed in the last two samples, divided by the duration of the sample interval.
21
File Control Bytes/sec is the overall rate at which bytes are transferred for all file system operations that are neither reads nor writes, including file system control requests and requests for information about device characteristics or status. It is measured in numbers of bytes. This counter displays the difference between the values observed in the last two samples, divided by the duration of the sample interval.
23
% Total Interrupt Time is the average percentage of time that all processors spend receiving and servicing hardware interrupts during sample intervals, where the value is an indirect indicator of the activity of devices that generate interrupts. It is the sum of Processor: % Interrupt Time for of all processors on the computer, divided by the number of processors. DPCs are counted separately and are not a component of the interrupt count. This value is an indirect indicator of the activity of devices that generate interrupts, such as the system timer, the mouse, disk drivers, data communication lines, network interface cards and other peripheral devices.
25
Available Bytes is the amount of physical memory, in bytes, immediately available for allocation to a process or for system use. It is equal to the sum of memory assigned to the standby (cached), free and zero page lists.
27
Committed Bytes is the amount of committed virtual memory, in bytes. Committed memory is the physical memory which has space reserved on the disk paging file(s). There can be one or more paging files on each physical drive. This counter displays the last observed value only; it is not an average.
29
Page Faults/sec is the average number of pages faulted per second. It is measured in number of pages faulted per second because only one page is faulted in each fault operation, hence this is also equal to the number of page fault operations. This counter includes both hard faults (those that require disk access) and soft faults (where the faulted page is found elsewhere in physical memory.) Most processors can handle large numbers of soft faults without significant consequence. However, hard faults, which require disk access, can cause significant delays.
31
Commit Limit is the amount of virtual memory that can be committed without having to extend the paging file(s). It is measured in bytes. Committed memory is the physical memory which has space reserved on the disk paging files. There can be one paging file on each logical drive). If the paging file(s) are be expanded, this limit increases accordingly. This counter displays the last observed value only; it is not an average.
33
Write Copies/sec is the rate at which page faults are caused by attempts to write that have been satisfied by coping of the page from elsewhere in physical memory. This is an economical way of sharing data since pages are only copied when they are written to; otherwise, the page is shared. This counter shows the number of copies, without regard for the number of pages copied in each operation.
35
Transition Faults/sec is the rate at which page faults are resolved by recovering pages that were being used by another process sharing the page, or were on the modified page list or the standby list, or were being written to disk at the time of the page fault. The pages were recovered without additional disk activity. Transition faults are counted in numbers of faults; because only one page is faulted in each operation, it is also equal to the number of pages faulted.
37
Cache Faults/sec is the rate at which faults occur when a page sought in the file system cache is not found and must be retrieved from elsewhere in memory (a soft fault) or from disk (a hard fault). The file system cache is an area of physical memory that stores recently used pages of data for applications. Cache activity is a reliable indicator of most application I/O operations. This counter shows the number of faults, without regard for the number of pages faulted in each operation.
39
Demand Zero Faults/sec is the rate at which a zeroed page is required to satisfy the fault. Zeroed pages, pages emptied of previously stored data and filled with zeros, are a security feature of Windows that prevent processes from seeing data stored by earlier processes that used the memory space. Windows maintains a list of zeroed pages to accelerate this process. This counter shows the number of faults, without regard to the number of pages retrieved to satisfy the fault. This counter displays the difference between the values observed in the last two samples, divided by the duration of the sample interval.
41
Pages/sec is the rate at which pages are read from or written to disk to resolve hard page faults. This counter is a primary indicator of the kinds of faults that cause system-wide delays. It is the sum of Memory\\Pages Input/sec and Memory\\Pages Output/sec. It is counted in numbers of pages, so it can be compared to other counts of pages, such as Memory\\Page Faults/sec, without conversion. It includes pages retrieved to satisfy faults in the file system cache (usually requested by applications) non-cached mapped memory files.
43
Page Reads/sec is the rate at which the disk was read to resolve hard page faults. It shows the number of reads operations, without regard to the number of pages retrieved in each operation. Hard page faults occur when a process references a page in virtual memory that is not in working set or elsewhere in physical memory, and must be retrieved from disk. This counter is a primary indicator of the kinds of faults that cause system-wide delays. It includes read operations to satisfy faults in the file system cache (usually requested by applications) and in non-cached mapped memory files. Compare the value of Memory\\Pages Reads/sec to the value of Memory\\Pages Input/sec to determine the average number of pages read during each operation.
45
Processor Queue Length is the number of threads in the processor queue. Unlike the disk counters, this counter counters, this counter shows ready threads only, not threads that are running. There is a single queue for processor time even on computers with multiple processors. Therefore, if a computer has multiple processors, you need to divide this value by the number of processors servicing the workload. A sustained processor queue of less than 10 threads per processor is normally acceptable, dependent of the workload.
47
Thread State is the current state of the thread. It is 0 for Initialized, 1 for Ready, 2 for Running, 3 for Standby, 4 for Terminated, 5 for Wait, 6 for Transition, 7 for Unknown. A Running thread is using a processor; a Standby thread is about to use one. A Ready thread wants to use a processor, but is waiting for a processor because none are free. A thread in Transition is waiting for a resource in order to execute, such as waiting for its execution stack to be paged in from disk. A Waiting thread has no use for the processor because it is waiting for a peripheral operation to complete or a resource to become free.
49
Pages Output/sec is the rate at which pages are written to disk to free up space in physical memory. Pages are written back to disk only if they are changed in physical memory, so they are likely to hold data, not code. A high rate of pages output might indicate a memory shortage. Windows writes more pages back to disk to free up space when physical memory is in short supply. This counter shows the number of pages, and can be compared to other counts of pages, without conversion.
51
Page Writes/sec is the rate at which pages are written to disk to free up space in physical memory. Pages are written to disk only if they are changed while in physical memory, so they are likely to hold data, not code. This counter shows write operations, without regard to the number of pages written in each operation. This counter displays the difference between the values observed in the last two samples, divided by the duration of the sample interval.
53
The Browser performance object consists of counters that measure the rates of announcements, enumerations, and other Browser transmissions.
55
Announcements Server/sec is the rate at which the servers in this domain have announced themselves to this server.
57
Pool Paged Bytes is the size, in bytes, of the paged pool, an area of the system virtual memory that is used for objects that can be written to disk when they are not being used. Memory\\Pool Paged Bytes is calculated differently than Process\\Pool Paged Bytes, so it might not equal Process(_Total)\\Pool Paged Bytes. This counter displays the last observed value only; it is not an average.
59
Pool Nonpaged Bytes is the size, in bytes, of the nonpaged pool, an area of the system virtual memory that is used for objects that cannot be written to disk, but must remain in physical memory as long as they are allocated. Memory\\Pool Nonpaged Bytes is calculated differently than Process\\Pool Nonpaged Bytes, so it might not equal Process(_Total)\\Pool Nonpaged Bytes. This counter displays the last observed value only; it is not an average.
61
Pool Paged Allocs is the number of calls to allocate space in the paged pool. The paged pool is an area of the system virtual memory that is used for objects that can be written to disk when they are not being used. It is measured in numbers of calls to allocate space, regardless of the amount of space allocated in each call. This counter displays the last observed value only; it is not an average.
63
Pool Paged Resident Bytes is the size, in bytes, of the portion of the paged pool that is currently resident and active in physical memory. The paged pool is an area of the system virtual memory that is used for objects that can be written to disk when they are not being used. This counter displays the last observed value only; it is not an average.
65
Pool Nonpaged Allocs is the number of calls to allocate space in the nonpaged pool. The nonpaged pool is an area of system memory area for objects that cannot be written to disk, and must remain in physical memory as long as they are allocated. It is measured in numbers of calls to allocate space, regardless of the amount of space allocated in each call. This counter displays the last observed value only; it is not an average.
67
Bytes Total/sec is the total rate of bytes sent to or received from the network by the protocol, but only for the frames (packets) which carry data. This is the sum of Frame Bytes/sec and Datagram Bytes/sec.
69
System Code Total Bytes is the size, in bytes, of the pageable operating system code currently mapped into the system virtual address space. This value is calculated by summing the bytes in Ntoskrnl.exe, Hal.dll, the boot drivers, and file systems loaded by Ntldr/osloader. This counter does not include code that must remain in physical memory and cannot be written to disk. This counter displays the last observed value only; it is not an average.
71
System Code Resident Bytes is the size, in bytes, of the pageable operating system code that is currently resident and active in physical memory. This value is a component of Memory\\System Code Total Bytes. Memory\\System Code Resident Bytes (and Memory\\System Code Total Bytes) does not include code that must remain in physical memory and cannot be written to disk. This counter displays the last observed value only; it is not an average.
73
System Driver Total Bytes is the size, in bytes, of the pageable virtual memory currently being used by device drivers. Pageable memory can be written to disk when it is not being used. It includes both physical memory (Memory\\System Driver Resident Bytes) and code and data paged to disk. It is a component of Memory\\System Code Total Bytes. This counter displays the last observed value only; it is not an average.
75
System Driver Resident Bytes is the size, in bytes, of the pageable physical memory being used by device drivers. It is the working set (physical memory area) of the drivers. This value is a component of Memory\\System Driver Total Bytes, which also includes driver memory that has been written to disk. Neither Memory\\System Driver Resident Bytes nor Memory\\System Driver Total Bytes includes memory that cannot be written to disk.
77
System Cache Resident Bytes is the size, in bytes, of the portion of the system file cache which is currently resident and active in physical memory. The System Cache Resident Bytes and Memory\\Cache Bytes counters are equivalent. This counter displays the last observed value only; it is not an average.
79
Announcements Domain/sec is the rate at which a domain has announced itself to the network.
81
Election Packets/sec is the rate at which browser election packets have been received by this workstation.
83
Mailslot Writes/sec is the rate at which mailslot messages have been successfully received.
85
Server List Requests/sec is the rate at which requests to retrieve a list of browser servers have been processed by this workstation.
87
The Cache performance object consists of counters that monitor the file system cache, an area of physical memory that stores recently used data as long as possible to permit access to the data without having to read from the disk. Because applications typically use the cache, the cache is monitored as an indicator of application I/O operations. When memory is plentiful, the cache can grow, but when memory is scarce, the cache can become too small to be effective.
89
Data Maps/sec is the frequency that a file system such as NTFS, maps a page of a file into the file system cache to read the page.
91
Sync Data Maps/sec counts the frequency that a file system, such as NTFS, maps a page of a file into the file system cache to read the page, and wishes to wait for the page to be retrieved if it is not in main memory.
93
Async Data Maps/sec is the frequency that an application using a file system, such as NTFS, to map a page of a file into the file system cache to read the page, and does not wait for the page to be retrieved if it is not in main memory.
95
Data Map Hits is the percentage of data maps in the file system cache that could be resolved without having to retrieve a page from the disk, because the page was already in physical memory.
97
Data Map Pins/sec is the frequency of data maps in the file system cache that resulted in pinning a page in main memory, an action usually preparatory to writing to the file on disk. While pinned, a page's physical address in main memory and virtual address in the file system cache will not be altered.
99
Pin Reads/sec is the frequency of reading data into the file system cache preparatory to writing the data back to disk. Pages read in this fashion are pinned in memory at the completion of the read. While pinned, a page's physical address in the file system cache will not be altered.
101
Sync Pin Reads/sec is the frequency of reading data into the file system cache preparatory to writing the data back to disk. Pages read in this fashion are pinned in memory at the completion of the read. The file system will not regain control until the page is pinned in the file system cache, in particular if the disk must be accessed to retrieve the page. While pinned, a page's physical address in the file system cache will not be altered.
103
Async Pin Reads/sec is the frequency of reading data into the file system cache preparatory to writing the data back to disk. Pages read in this fashion are pinned in memory at the completion of the read. The file system will regain control immediately even if the disk must be accessed to retrieve the page. While pinned, a page's physical address will not be altered.
105
Pin Read Hits is the percentage of pin read requests that hit the file system cache, i.e., did not require a disk read in order to provide access to the page in the file system cache. While pinned, a page's physical address in the file system cache will not be altered. The LAN Redirector uses this method for retrieving data from the cache, as does the LAN Server for small transfers. This is usually the method used by the disk file systems as well.
107
Copy Reads/sec is the frequency of reads from pages of the file system cache that involve a memory copy of the data from the cache to the application's buffer. The LAN Redirector uses this method for retrieving information from the file system cache, as does the LAN Server for small transfers. This is a method used by the disk file systems as well.
109
Sync Copy Reads/sec is the frequency of reads from pages of the file system cache that involve a memory copy of the data from the cache to the application's buffer. The file system will not regain control until the copy operation is complete, even if the disk must be accessed to retrieve the page.
111
Async Copy Reads/sec is the frequency of reads from pages of the file system cache that involve a memory copy of the data from the cache to the application's buffer. The application will regain control immediately even if the disk must be accessed to retrieve the page.
113
Copy Read Hits is the percentage of cache copy read requests that hit the cache, that is, they did not require a disk read in order to provide access to the page in the cache. A copy read is a file read operation that is satisfied by a memory copy from a page in the cache to the application's buffer. The LAN Redirector uses this method for retrieving information from the cache, as does the LAN Server for small transfers. This is a method used by the disk file systems as well.
115
MDL Reads/sec is the frequency of reads from the file system cache that use a Memory Descriptor List (MDL) to access the data. The MDL contains the physical address of each page involved in the transfer, and thus can employ a hardware Direct Memory Access (DMA) device to effect the copy. The LAN Server uses this method for large transfers out of the server.
117
Sync MDL Reads/sec is the frequency of reads from the file system cache that use a Memory Descriptor List (MDL) to access the pages. The MDL contains the physical address of each page in the transfer, thus permitting Direct Memory Access (DMA) of the pages. If the accessed page(s) are not in main memory, the caller will wait for the pages to fault in from the disk.
119
Async MDL Reads/sec is the frequency of reads from the file system cache that use a Memory Descriptor List (MDL) to access the pages. The MDL contains the physical address of each page in the transfer, thus permitting Direct Memory Access (DMA) of the pages. If the accessed page(s) are not in main memory, the calling application program will not wait for the pages to fault in from disk.
121
MDL Read Hits is the percentage of Memory Descriptor List (MDL) Read requests to the file system cache that hit the cache, i.e., did not require disk accesses in order to provide memory access to the page(s) in the cache.
123
Read Aheads/sec is the frequency of reads from the file system cache in which the Cache detects sequential access to a file. The read aheads permit the data to be transferred in larger blocks than those being requested by the application, reducing the overhead per access.
125
Fast Reads/sec is the frequency of reads from the file system cache that bypass the installed file system and retrieve the data directly from the cache. Normally, file I/O requests invoke the appropriate file system to retrieve data from a file, but this path permits direct retrieval of data from the cache without file system involvement if the data is in the cache. Even if the data is not in the cache, one invocation of the file system is avoided.
127
Sync Fast Reads/sec is the frequency of reads from the file system cache that bypass the installed file system and retrieve the data directly from the cache. Normally, file I/O requests invoke the appropriate file system to retrieve data from a file, but this path permits direct retrieval of data from the cache without file system involvement if the data is in the cache. Even if the data is not in the cache, one invocation of the file system is avoided. If the data is not in the cache, the request (application program call) will wait until the data has been retrieved from disk.
129
Async Fast Reads/sec is the frequency of reads from the file system cache that bypass the installed file system and retrieve the data directly from the cache. Normally, file I/O requests will invoke the appropriate file system to retrieve data from a file, but this path permits data to be retrieved from the cache directly (without file system involvement) if the data is in the cache. Even if the data is not in the cache, one invocation of the file system is avoided. If the data is not in the cache, the request (application program call) will not wait until the data has been retrieved from disk, but will get control immediately.
131
Fast Read Resource Misses/sec is the frequency of cache misses necessitated by the lack of available resources to satisfy the request.
133
Fast Read Not Possibles/sec is the frequency of attempts by an Application Program Interface (API) function call to bypass the file system to get to data in the file system cache that could not be honored without invoking the file system.
135
Lazy Write Flushes/sec is the rate at which the Lazy Writer thread has written to disk. Lazy Writing is the process of updating the disk after the page has been changed in memory, so that the application that changed the file does not have to wait for the disk write to be complete before proceeding. More than one page can be transferred by each write operation.
137
Lazy Write Pages/sec is the rate at which the Lazy Writer thread has written to disk. Lazy Writing is the process of updating the disk after the page has been changed in memory, so that the application that changed the file does not have to wait for the disk write to be complete before proceeding. More than one page can be transferred on a single disk write operation.
139
Data Flushes/sec is the rate at which the file system cache has flushed its contents to disk as the result of a request to flush or to satisfy a write-through file write request. More than one page can be transferred on each flush operation.
141
Data Flush Pages/sec is the number of pages the file system cache has flushed to disk as a result of a request to flush or to satisfy a write-through file write request. More than one page can be transferred on each flush operation.
143
% User Time is the percentage of elapsed time the processor spends in the user mode. User mode is a restricted processing mode designed for applications, environment subsystems, and integral subsystems. The alternative, privileged mode, is designed for operating system components and allows direct access to hardware and all memory. The operating system switches application threads to privileged mode to access operating system services. This counter displays the average busy time as a percentage of the sample time.
145
% Privileged Time is the percentage of elapsed time that the process threads spent executing code in privileged mode. When a Windows system service in called, the service will often run in privileged mode to gain access to system-private data. Such data is protected from access by threads executing in user mode. Calls to the system can be explicit or implicit, such as page faults or interrupts. Unlike some early operating systems, Windows uses process boundaries for subsystem protection in addition to the traditional protection of user and privileged modes. Some work done by Windows on behalf of the application might appear in other subsystem processes in addition to the privileged time in the process.
147
Context Switches/sec is the combined rate at which all processors on the computer are switched from one thread to another. Context switches occur when a running thread voluntarily relinquishes the processor, is preempted by a higher priority ready thread, or switches between user-mode and privileged (kernel) mode to use an Executive or subsystem service. It is the sum of Thread\\Context Switches/sec for all threads running on all processors in the computer and is measured in numbers of switches. There are context switch counters on the System and Thread objects. This counter displays the difference between the values observed in the last two samples, divided by the duration of the sample interval.
149
Interrupts/sec is the average rate, in incidents per second, at which the processor received and serviced hardware interrupts. It does not include deferred procedure calls (DPCs), which are counted separately. This value is an indirect indicator of the activity of devices that generate interrupts, such as the system clock, the mouse, disk drivers, data communication lines, network interface cards, and other peripheral devices. These devices normally interrupt the processor when they have completed a task or require attention. Normal thread execution is suspended. The system clock typically interrupts the processor every 10 milliseconds, creating a background of interrupt activity. This counter displays the difference between the values observed in the last two samples, divided by the duration of the sample interval.
151
System Calls/sec is the combined rate of calls to operating system service routines by all processes running on the computer. These routines perform all of the basic scheduling and synchronization of activities on the computer, and provide access to non-graphic devices, memory management, and name space management. This counter displays the difference between the values observed in the last two samples, divided by the duration of the sample interval.
153
Level 1 TLB Fills/sec is the frequency of faults that occur when reference is made to memory whose Page Table Entry (PTE) is not in the Translation Lookaside Buffer (TLB). On some computers this fault is handled by software loading the PTE into the TLB, and this counter is incremented.
155
Level 2 TLB Fills/sec is the frequency of faults that occur when reference is made to memory whose Page Table Entry (PTE) is not in the Translation Lookaside Buffer (TLB), nor is the page containing the PTE. On some computers this fault is handled by software loading the PTE into the TLB, and this counter is incremented.
157
% User Time is the percentage of elapsed time that the process threads spent executing code in user mode. Applications, environment subsystems, and integral subsystems execute in user mode. Code executing in user mode cannot damage the integrity of the Windows executive, kernel, and device drivers. Unlike some early operating systems, Windows uses process boundaries for subsystem protection in addition to the traditional protection of user and privileged modes. Some work done by Windows on behalf of the application might appear in other subsystem processes in addition to the privileged time in the process.
159
% Privileged Time is the percentage of elapsed time that the process threads spent executing code in privileged mode. When a Windows system service is called, the service will often run in privileged mode to gain access to system-private data. Such data is protected from access by threads executing in user mode. Calls to the system can be explicit or implicit, such as page faults or interrupts. Unlike some early operating systems, Windows uses process boundaries for subsystem protection in addition to the traditional protection of user and privileged modes. Some work done by Windows on behalf of the application might appear in other subsystem processes in addition to the privileged time in the process.
161
Enumerations Server/sec is the rate at which server browse requests have been processed by this workstation.
163
Enumerations Domain/sec is the rate at which domain browse requests have been processed by this workstation.
165
Enumerations Other/sec is the rate at which browse requests processed by this workstation are not domain or server browse requests.
167
Missed Server Announcements is the number of server announcements that have been missed due to configuration or allocation limits.
169
Missed Mailslot Datagrams is the number of Mailslot Datagrams that have been discarded due to configuration or allocation limits.
171
Missed Server List Requests is the number of requests to retrieve a list of browser servers that were received by this workstation, but could not be processed.
173
Virtual Bytes Peak is the maximum size, in bytes, of virtual address space the process has used at any one time. Use of virtual address space does not necessarily imply corresponding use of either disk or main memory pages. However, virtual space is finite, and the process might limit its ability to load libraries.
175
Virtual Bytes is the current size, in bytes, of the virtual address space the process is using. Use of virtual address space does not necessarily imply corresponding use of either disk or main memory pages. Virtual space is finite, and the process can limit its ability to load libraries.
177
Page Faults/sec is the rate at which page faults by the threads executing in this process are occurring. A page fault occurs when a thread refers to a virtual memory page that is not in its working set in main memory. This may not cause the page to be fetched from disk if it is on the standby list and hence already in main memory, or if it is in use by another process with whom the page is shared.
179
Working Set Peak is the maximum size, in bytes, of the Working Set of this process at any point in time. The Working Set is the set of memory pages touched recently by the threads in the process. If free memory in the computer is above a threshold, pages are left in the Working Set of a process even if they are not in use. When free memory falls below a threshold, pages are trimmed from Working Sets. If they are needed they will then be soft-faulted back into the Working Set before they leave main memory.
181
Working Set is the current size, in bytes, of the Working Set of this process. The Working Set is the set of memory pages touched recently by the threads in the process. If free memory in the computer is above a threshold, pages are left in the Working Set of a process even if they are not in use. When free memory falls below a threshold, pages are trimmed from Working Sets. If they are needed they will then be soft-faulted back into the Working Set before leaving main memory.
183
Page File Bytes Peak is the maximum amount of virtual memory, in bytes, that this process has reserved for use in the paging file(s). Paging files are used to store pages of memory used by the process that are not contained in other files. Paging files are shared by all processes, and the lack of space in paging files can prevent other processes from allocating memory. If there is no paging file, this counter reflects the maximum amount of virtual memory that the process has reserved for use in physical memory.
185
Page File Bytes is the current amount of virtual memory, in bytes, that this process has reserved for use in the paging file(s). Paging files are used to store pages of memory used by the process that are not contained in other files. Paging files are shared by all processes, and the lack of space in paging files can prevent other processes from allocating memory. If there is no paging file, this counter reflects the current amount of virtual memory that the process has reserved for use in physical memory.
187
Private Bytes is the current size, in bytes, of memory that this process has allocated that cannot be shared with other processes.
189
% Processor Time is the percentage of elapsed time that all of process threads used the processor to execution instructions. An instruction is the basic unit of execution in a computer, a thread is the object that executes instructions, and a process is the object created when a program is run. Code executed to handle some hardware interrupts and trap conditions are included in this count.
191
% Processor Time is the percentage of elapsed time that all of process threads used the processor to execution instructions. An instruction is the basic unit of execution in a computer, a thread is the object that executes instructions, and a process is the object created when a program is run. Code executed to handle some hardware interrupts and trap conditions are included in this count.
193
% User Time is the percentage of elapsed time that this thread has spent executing code in user mode. Applications, environment subsystems, and integral subsystems execute in user mode. Code executing in user mode cannot damage the integrity of the Windows NT Executive, Kernel, and device drivers. Unlike some early operating systems, Windows NT uses process boundaries for subsystem protection in addition to the traditional protection of user and privileged modes. These subsystem processes provide additional protection. Therefore, some work done by Windows NT on behalf of your application might appear in other subsystem processes in addition to the privileged time in your process.
195
% Privileged Time is the percentage of elapsed time that the process threads spent executing code in privileged mode. When a Windows system service in called, the service will often run in privileged mode to gain access to system-private data. Such data is protected from access by threads executing in user mode. Calls to the system can be explicit or implicit, such as page faults or interrupts. Unlike some early operating systems, Windows uses process boundaries for subsystem protection in addition to the traditional protection of user and privileged modes. Some work done by Windows on behalf of the application might appear in other subsystem processes in addition to the privileged time in the process.
197
Context Switches/sec is the rate of switches from one thread to another. Thread switches can occur either inside of a single process or across processes. A thread switch can be caused either by one thread asking another for information, or by a thread being preempted by another, higher priority thread becoming ready to run. Unlike some early operating systems, Windows NT uses process boundaries for subsystem protection in addition to the traditional protection of user and privileged modes. These subsystem processes provide additional protection. Therefore, some work done by Windows NT on behalf of an application appear in other subsystem processes in addition to the privileged time in the application. Switching to the subsystem process causes one Context Switch in the application thread. Switching back causes another Context Switch in the subsystem thread.
199
Current Disk Queue Length is the number of requests outstanding on the disk at the time the performance data is collected. It also includes requests in service at the time of the collection. This is a instantaneous snapshot, not an average over the time interval. Multi-spindle disk devices can have multiple requests that are active at one time, but other concurrent requests are awaiting service. This counter might reflect a transitory high or low queue length, but if there is a sustained load on the disk drive, it is likely that this will be consistently high. Requests experience delays proportional to the length of this queue minus the number of spindles on the disks. For good performance, this difference should average less than two.
201
% Disk Time is the percentage of elapsed time that the selected disk drive was busy servicing read or write requests.
203
% Disk Read Time is the percentage of elapsed time that the selected disk drive was busy servicing read requests.
205
% Disk Write Time is the percentage of elapsed time that the selected disk drive was busy servicing write requests.
207
Avg. Disk sec/Transfer is the time, in seconds, of the average disk transfer.
209
Avg. Disk sec/Read is the average time, in seconds, of a read of data from the disk.
211
Avg. Disk sec/Write is the average time, in seconds, of a write of data to the disk.
213
Disk Transfers/sec is the rate of read and write operations on the disk.
215
Disk Reads/sec is the rate of read operations on the disk.
217
Disk Writes/sec is the rate of write operations on the disk.
219
Disk Bytes/sec is the rate bytes are transferred to or from the disk during write or read operations.
221
Disk Read Bytes/sec is the rate at which bytes are transferred from the disk during read operations.
223
Disk Write Bytes/sec is rate at which bytes are transferred to the disk during write operations.
225
Avg. Disk Bytes/Transfer is the average number of bytes transferred to or from the disk during write or read operations.
227
Avg. Disk Bytes/Read is the average number of bytes transferred from the disk during read operations.
229
Avg. Disk Bytes/Write is the average number of bytes transferred to the disk during write operations.
231
The Process performance object consists of counters that monitor running application program and system processes. All the threads in a process share the same address space and have access to the same data.
233
The Thread performance object consists of counters that measure aspects of thread behavior. A thread is the basic object that executes instructions on a processor. All running processes have at least one thread.
235
The Physical Disk performance object consists of counters that monitor hard or fixed disk drive on a computer. Disks are used to store file, program, and paging data and are read to retrieve these items, and written to record changes to them. The values of physical disk counters are sums of the values of the logical disks (or partitions) into which they are divided.
237
The Logical Disk performance object consists of counters that monitor logical partitions of a hard or fixed disk drives. Performance Monitor identifies logical disks by their a drive letter, such as C.
239
The Processor performance object consists of counters that measure aspects of processor activity. The processor is the part of the computer that performs arithmetic and logical computations, initiates operations on peripherals, and runs the threads of processes. A computer can have multiple processors. The processor object represents each processor as an instance of the object.
241
% Total Processor Time is the average percentage of time that all processors on the computer are executing non-idle threads. This counter was designed as the primary indicator of processor activity on multiprocessor computers. It is equal to the sum of Process: % Processor Time for all processors, divided by the number of processors. It is calculated by summing the time that all processors spend executing the thread of the Idle process in each sample interval, subtracting that value from 100%, and dividing the difference by the number of processors on the computer. (Each processor has an Idle thread which consumes cycles when no other threads are ready to run). For example, on a multiprocessor computer, a value of 50% means that all processors are busy for half of the sample interval, or that half of the processors are busy for all of the sample interval. This counter displays the average percentage of busy time observed during the sample interval. It is calculated by monitoring the time the service was inactive, and then subtracting that value from 100%.
243
% Total User Time is the average percentage of non-idle time all processors spend in user mode. It is the sum of Processor: % User Time for all processors on the computer, divided by the number of processors. System: % Total User Time and System: % Total Privileged Time sum to % Total Processor Time, but not always to 100%. (User mode is a restricted processing mode designed for applications, environment subsystems, and integral subsystems. The alternative, privileged mode, is designed for operating system components and allows direct access to hardware and all memory. The operating system switches application threads to privileged mode to access operating system services). This counter displays the average busy time as a percentage of the sample time.
245
% Total Privileged Time is the average percentage of non-idle time all processors spend in privileged (kernel) mode. It is the sum of Processor: % Privileged Time for all processors on the computer, divided by the number of processors. System: % Total User Time and System: % Total Privileged Time sum to % Total Processor Time, but not always to 100%. (Privileged mode is an processing mode designed for operating system components which allows direct access to hardware and all memory. The operating system switches application threads to privileged mode to access operating system services. The alternative, user mode, is a restricted processing mode designed for applications and environment subsystems). This counter displays the average busy time as a percentage of the sample time.
247
Total Interrupts/sec is the combined rate of hardware interrupts received and serviced by all processors on the computer It is the sum of Processor: Interrupts/sec for all processors, and divided by the number of processors, and is measured in numbers of interrupts. It does not include DPCs, which are counted separately. This value is an indirect indicator of the activity of devices that generate interrupts, such as the system timer, the mouse, disk drivers, data communication lines, network interface cards and other peripheral devices. These devices normally interrupt the processor when they have completed a task or require attention. Normal thread execution is suspended during interrupts. Most system clocks interrupt the processor every 10 milliseconds, creating a background of interrupt activity. This counter displays the difference between the values observed in the last two samples, divided by the duration of the sample interval.
249
Processes is the number of processes in the computer at the time of data collection. This is an instantaneous count, not an average over the time interval. Each process represents the running of a program.
251
Threads is the number of threads in the computer at the time of data collection. This is an instantaneous count, not an average over the time interval. A thread is the basic executable entity that can execute instructions in a processor.
253
Events is the number of events in the computer at the time of data collection. This is an instantaneous count, not an average over the time interval. An event is used when two or more threads try to synchronize execution.
255
Semaphores is the number of semaphores in the computer at the time of data collection. This is an instantaneous count, not an average over the time interval. Threads use semaphores to obtain exclusive access to data structures that they share with other threads.
257
Mutexes counts the number of mutexes in the computer at the time of data collection. This is an instantaneous count, not an average over the time interval. Mutexes are used by threads to assure only one thread is executing a particular section of code.
259
Sections is the number of sections in the computer at the time of data collection. This is an instantaneous count, not an average over the time interval. A section is a portion of virtual memory created by a process for storing data. A process can share sections with other processes.
261
The Object performance object consists of counters that monitor logical objects in the system, such as processes, threads, mutexes, and semaphores. This information can be used to detect the unnecessary consumption of computer resources. Each object requires memory to store basic information about the object.
263
The Redirector performance object consists of counter that monitor network connections originating at the local computer.
265
Bytes Received/sec is the rate of bytes coming in to the Redirector from the network. It includes all application data as well as network protocol information (such as packet headers).
267
Packets Received/sec is the rate at which the Redirector is receiving packets (also called SMBs or Server Message Blocks). Network transmissions are divided into packets. The average number of bytes received in a packet can be obtained by dividing Bytes Received/sec by this counter. Some packets received might not contain incoming data (for example an acknowledgment to a write made by the Redirector would count as an incoming packet).
269
Read Bytes Paging/sec is the rate at which the Redirector is attempting to read bytes in response to page faults. Page faults are caused by loading of modules (such as programs and libraries), by a miss in the Cache (see Read Bytes Cache/sec), or by files directly mapped into the address space of applications (a high-performance feature of Windows NT).
271
Read Bytes Non-Paging/sec are those bytes read by the Redirector in response to normal file requests by an application when they are redirected to come from another computer. In addition to file requests, this counter includes other methods of reading across the network such as Named Pipes and Transactions. This counter does not count network protocol information, just application data.
273
Read Bytes Cache/sec is the rate at which applications are accessing the file system cache by using the Redirector. Some of these data requests are satisfied by retrieving the data from the cache. Requests that miss the Cache cause a page fault (see Read Bytes Paging/sec).
275
Read Bytes Network/sec is the rate at which applications are reading data across the network. This occurs when data sought in the file system cache is not found there and must be retrieved from the network. Dividing this value by Bytes Received/sec indicates the proportion of application data traveling across the network. (see Bytes Received/sec).
277
Bytes Transmitted/sec is the rate at which bytes are leaving the Redirector to the network. It includes all application data as well as network protocol information (such as packet headers and the like).
279
Packets Transmitted/sec is the rate at which the Redirector is sending packets (also called SMBs or Server Message Blocks). Network transmissions are divided into packets. The average number of bytes transmitted in a packet can be obtained by dividing Bytes Transmitted/sec by this counter.
281
Write Bytes Paging/sec is the rate at which the Redirector is attempting to write bytes changed in the pages being used by applications. The program data changed by modules (such as programs and libraries) that were loaded over the network are 'paged out' when no longer needed. Other output pages come from the file system cache (see Write Bytes Cache/sec).
283
Write Bytes Non-Paging/sec is the rate at which bytes are written by the Redirector in response to normal file outputs by an application when they are redirected to another computer. In addition to file requests, this count includes other methods of writing across the network, such as Named Pipes and Transactions. This counter does not count network protocol information, just application data.
285
Write Bytes Cache/sec is the rate at which applications on your computer are writing to the file system cache by using the Redirector. The data might not leave your computer immediately; it can be retained in the cache for further modification before being written to the network. This saves network traffic. Each write of a byte into the cache is counted here.
287
Write Bytes Network/sec is the rate at which applications are writing data across the network. This occurs when the file system cache is bypassed, such as for Named Pipes or Transactions, or when the cache writes the bytes to disk to make room for other data. Dividing this counter by Bytes Transmitted/sec will indicate the proportion of application data being to the network (see Transmitted Bytes/sec).
289
File Read Operations/sec is the rate at which applications are asking the Redirector for data. Each call to a file system or similar Application Program Interface (API) call counts as one operation.
291
Read Operations Random/sec counts the rate at which, on a file-by-file basis, reads are made that are not sequential. If a read is made using a particular file handle, and then is followed by another read that is not immediately the contiguous next byte, this counter is incremented by one.
293
Read Packets/sec is the rate at which read packets are being placed on the network. Each time a single packet is sent with a request to read data remotely, this counter is incremented by one.
295
Reads Large/sec is the rate at which reads over 2 times the server's negotiated buffer size are made by applications. Too many of these could place a strain on server resources. This counter is incremented once for each read. It does not count packets.
297
Read Packets Small/sec is the rate at which reads less than one-fourth of the server's negotiated buffer size are made by applications. Too many of these could indicate a waste of buffers on the server. This counter is incremented once for each read. It does not count packets.
299
File Write Operations/sec is the rate at which applications are sending data to the Redirector. Each call to a file system or similar Application Program Interface (API) call counts as one operation.
301
Write Operations Random/sec is the rate at which, on a file-by-file basis, writes are made that are not sequential. If a write is made using a particular file handle, and then is followed by another write that is not immediately the next contiguous byte, this counter is incremented by one.
303
Write Packets/sec is the rate at which writes are being sent to the network. Each time a single packet is sent with a request to write remote data, this counter is incremented by one.
305
Writes Large/sec is the rate at which writes are made by applications that are over 2 times the server's negotiated buffer size. Too many of these could place a strain on server resources. This counter is incremented once for each write: it counts writes, not packets.
307
Write Packets Small/sec is the rate at which writes are made by applications that are less than one-fourth of the server's negotiated buffer size. Too many of these could indicate a waste of buffers on the server. This counter is incremented once for each write: it counts writes, not packets.
309
Reads Denied/sec is the rate at which the server is unable to accommodate requests for Raw Reads. When a read is much larger than the server's negotiated buffer size, the Redirector requests a Raw Read which, if granted, would permit the transfer of the data without lots of protocol overhead on each packet. To accomplish this the server must lock out other requests, so the request is denied if the server is really busy.
311
Writes Denied/sec is the rate at which the server is unable to accommodate requests for Raw Writes. When a write is much larger than the server's negotiated buffer size, the Redirector requests a Raw Write which, if granted, would permit the transfer of the data without lots of protocol overhead on each packet. To accomplish this the server must lock out other requests, so the request is denied if the server is really busy.
313
Network Errors/sec is the rate at which serious unexpected errors are occurring. Such errors generally indicate that the Redirector and one or more Servers are having serious communication difficulties. For example an SMB (Server Message Block) protocol error is a Network Error. An entry is written to the System Event Log and provide details.
315
Server Sessions counts the total number of security objects the Redirector has managed. For example, a logon to a server followed by a network access to the same server will establish one connection, but two sessions.
317
Server Reconnects counts the number of times your Redirector has had to reconnect to a server in order to complete a new active request. You can be disconnected by the Server if you remain inactive for too long. Locally even if all your remote files are closed, the Redirector will keep your connections intact for (nominally) ten minutes. Such inactive connections are called Dormant Connections. Reconnecting is expensive in time.
319
Connects Core counts the number of connections you have to servers running the original MS-Net SMB protocol, including MS-Net itself and Xenix and VAX's.
321
Connects LAN Manager 2.0 counts connections to LAN Manager 2.0 servers, including LMX servers.
323
Connects LAN Manager 2.1 counts connections to LAN Manager 2.1 servers, including LMX servers.
325
Connects Windows NT counts the connections to Windows 2000 or earlier computers.
327
Server Disconnects counts the number of times a Server has disconnected your Redirector. See also Server Reconnects.
329
Server Sessions Hung counts the number of active sessions that are timed out and unable to proceed due to a lack of response from the remote server.
331
The Server performance object consists of counters that measure communication between the local computer and the network.
333
The number of bytes the server has received from the network. Indicates how busy the server is.
335
The number of bytes the server has sent on the network. Indicates how busy the server is.
337
Thread Wait Reason is only applicable when the thread is in the Wait state (see Thread State). It is 0 or 7 when the thread is waiting for the Executive, 1 or 8 for a Free Page, 2 or 9 for a Page In, 3 or 10 for a Pool Allocation, 4 or 11 for an Execution Delay, 5 or 12 for a Suspended condition, 6 or 13 for a User Request, 14 for an Event Pair High, 15 for an Event Pair Low, 16 for an LPC Receive, 17 for an LPC Reply, 18 for Virtual Memory, 19 for a Page Out; 20 and higher are not assigned at the time of this writing. Event Pairs are used to communicate with protected subsystems (see Context Switches).
339
% DPC Time is the percentage of time that the processor spent receiving and servicing deferred procedure calls (DPCs) during the sample interval. DPCs are interrupts that run at a lower priority than standard interrupts. % DPC Time is a component of % Privileged Time because DPCs are executed in privileged mode. They are counted separately and are not a component of the interrupt counters. This counter displays the average busy time as a percentage of the sample time.
341
The number of sessions that have been closed due to their idle time exceeding the AutoDisconnect parameter for the server. Shows whether the AutoDisconnect setting is helping to conserve resources.
343
The number of sessions that have been closed due to unexpected error conditions or sessions that have reached the autodisconnect timeout and have been disconnected normally. The autodisconnect timeout value represents the number of seconds that idle connections with no session attached to have before being disconnected automatically by a server. The default value is 30 seconds. This counter increments as a result of normal server operation, not as an indication of network problems or unexpected error condition.
345
The number of sessions that have terminated normally. Useful in interpreting the Sessions Times Out and Sessions Errored Out statistics--allows percentage calculations.
347
The number of sessions that have been forced to logoff. Can indicate how many sessions were forced to logoff due to logon time constraints.
349
The number of failed logon attempts to the server. Can indicate whether password guessing programs are being used to crack the security on the server.
351
The number of times opens on behalf of clients have failed with STATUS_ACCESS_DENIED. Can indicate whether somebody is randomly attempting to access files in hopes of getting at something that was not properly protected.
353
The number of times accesses to files opened successfully were denied. Can indicate attempts to access files without proper access authorization.
355
The number of times an internal Server Error was detected. Unexpected errors usually indicate a problem with the Server.
357
The number of times the server has rejected blocking SMBs due to insufficient count of free work items. Indicates whether the MaxWorkItem or MinFreeWorkItems server parameters might need to be adjusted.
359
The number of times STATUS_DATA_NOT_ACCEPTED was returned at receive indication time. This occurs when no work item is available or can be allocated to service the incoming request. Indicates whether the InitWorkItems or MaxWorkItems parameters might need to be adjusted.
361
The number of successful open attempts performed by the server of behalf of clients. Useful in determining the amount of file I/O, determining overhead for path-based operations, and for determining the effectiveness of open locks.
363
The number of files currently opened in the server. Indicates current server activity.
365
The number of sessions currently active in the server. Indicates current server activity.
367
The number of searches for files currently active in the server. Indicates current server activity.
369
The number of bytes of non-pageable computer memory the server is using. This value is useful for determining the values of the MaxNonpagedMemoryUsage value entry in the Windows NT Registry.
371
The number of times allocations from nonpaged pool have failed. Indicates that the computer's physical memory is too small.
373
The maximum number of bytes of nonpaged pool the server has had in use at any one point. Indicates how much physical memory the computer should have.
375
The number of bytes of pageable computer memory the server is currently using. Can help in determining good values for the MaxPagedMemoryUsage parameter.
377
The number of times allocations from paged pool have failed. Indicates that the computer's physical memory or paging file are too small.
379
The maximum number of bytes of paged pool the server has had allocated. Indicates the proper sizes of the Page File(s) and physical memory.
381
Server Announce Allocations Failed/sec is the rate at which server (or domain) announcements have failed due to lack of memory.
383
Mailslot Allocations Failed is the number of times the datagram receiver has failed to allocate a buffer to hold a user mailslot write.
385
Mailslot Receives Failed indicates the number of mailslot messages that could not be received due to transport failures.
387
Mailslot Writes Failed is the total number of mailslot messages that have been successfully received, but that could not be written to the mailslot.
389
Bytes Total/sec is the rate the Redirector is processing data bytes. This includes all application and file data in addition to protocol information such as packet headers.
391
File Data Operations/sec is the rate at which the Redirector is processing data operations. One operation should include many bytes, since each operation has overhead. The efficiency of this path can be determined by dividing the Bytes/sec by this counter to obtain the average number of bytes transferred per operation.
393
Current Commands counter indicates the number of pending commands from the local computer to all destination servers. If the Current Commands counter shows a high number and the local computer is idle, this may indicate a network-related problem or a redirector bottleneck on the local computer.
395
The number of bytes the server has sent to and received from the network. This value provides an overall indication of how busy the server is.
397
% Interrupt Time is the time the processor spends receiving and servicing hardware interrupts during sample intervals. This value is an indirect indicator of the activity of devices that generate interrupts, such as the system clock, the mouse, disk drivers, data communication lines, network interface cards and other peripheral devices. These devices normally interrupt the processor when they have completed a task or require attention. Normal thread execution is suspended during interrupts. Most system clocks interrupt the processor every 10 milliseconds, creating a background of interrupt activity. suspends normal thread execution during interrupts. This counter displays the average busy time as a percentage of the sample time.
399
The NWLink NetBIOS performance object consists of counters that monitor IPX transport rates and connections.
401
Packets/sec is the rate the Redirector is processing data packets. One packet includes (hopefully) many bytes. We say hopefully here because each packet has protocol overhead. You can determine the efficiency of this path by dividing the Bytes/sec by this counter to determine the average number of bytes transferred/packet. You can also divide this counter by Operations/sec to determine the average number of packets per operation, another measure of efficiency.
405
Context Blocks Queued per second is the rate at which work context blocks had to be placed on the server's FSP queue to await server action.
407
File Data Operations/ sec is the combined rate of read and write operations on all logical disks on the computer. This is the inverse of System: File Control Operations/sec. This counter displays the difference between the values observed in the last two samples, divided by the duration of the sample interval.
409
% Free Space is the percentage of total usable space on the selected logical disk drive that was free.
411
Free Megabytes displays the unallocated space, in megabytes, on the disk drive in megabytes. One megabyte is equal to 1,048,576 bytes.
413
Connections Open is the number of connections currently open for this protocol. This counter shows the current count only and does not accumulate over time.
415
Connections No Retries is the total count of connections that were successfully made on the first try. This number is an accumulator and shows a running total.
417
Connections With Retries is the total count of connections that were made after retrying the attempt. A retry occurs when the first connection attempt failed. This number is an accumulator and shows a running total.
419
Disconnects Local is the number of session disconnections that were initiated by the local computer. This number is an accumulator and shows a running total.
421
Disconnects Remote is the number of session disconnections that were initiated by the remote computer. This number is an accumulator and shows a running total.
423
Failures Link is the number of connections that were dropped due to a link failure. This number is an accumulator and shows a running total.
425
Failures Adapter is the number of connections that were dropped due to an adapter failure. This number is an accumulator and shows a running total.
427
Connection Session Timeouts is the number of connections that were dropped due to a session timeout. This number is an accumulator and shows a running total.
429
Connections Canceled is the number of connections that were canceled. This number is an accumulator and shows a running total.
431
Failures Resource Remote is the number of connections that failed because of resource problems or shortages on the remote computer. This number is an accumulator and shows a running total.
433
Failures Resource Local is the number of connections that failed because of resource problems or shortages on the local computer. This number is an accumulator and shows a running total.
435
Failures Not Found is the number of connection attempts that failed because the remote computer could not be found. This number is an accumulator and shows a running total.
437
Failures No Listen is the number of connections that were rejected because the remote computer was not listening for connection requests.
439
Datagrams/sec is the rate at which datagrams are processed by the computer. This counter displays the sum of datagrams sent and datagrams received. A datagram is a connectionless packet whose delivery to a remote is not guaranteed.
441
Datagram Bytes/sec is the rate at which datagram bytes are processed by the computer. This counter is the sum of datagram bytes that are sent as well as received. A datagram is a connectionless packet whose delivery to a remote is not guaranteed.
443
Datagrams Sent/sec is the rate at which datagrams are sent from the computer. A datagram is a connectionless packet whose delivery to a remote computer is not guaranteed.
445
Datagram Bytes Sent/sec is the rate at which datagram bytes are sent from the computer. A datagram is a connectionless packet whose delivery to a remote computer is not guaranteed.
447
Datagrams Received/sec is the rate at which datagrams are received by the computer. A datagram is a connectionless packet whose delivery to a remote computer is not guaranteed.
449
Datagram Bytes Received/sec is the rate at which datagram bytes are received by the computer. A datagram is a connectionless packet whose delivery to a remote computer is not guaranteed.
451
Packets/sec is the rate at which packets are processed by the computer. This count is the sum of Packets Sent and Packets Received per second. This counter includes all packets processed: control as well as data packets.
453
Packets Sent/sec is the rate at which packets are sent by the computer. This counter counts all packets sent by the computer, i.e. control as well as data packets.
455
Packets Received/sec is the rate at which packets are received by the computer. This counter counts all packets processed: control as well as data packets.
457
Frames/sec is the rate at which data frames (or packets) are processed by the computer. This counter is the sum of data frames sent and data frames received. This counter only counts those frames (packets) that carry data.
459
Frame Bytes/sec is the rate at which data bytes are processed by the computer. This counter is the sum of data frame bytes sent and received. This counter only counts the byte in frames (packets) that carry data.
461
Frames Sent/sec is the rate at which data frames are sent by the computer. This counter only counts the frames (packets) that carry data.
463
Frame Bytes Sent/sec is the rate at which data bytes are sent by the computer. This counter only counts the bytes in frames (packets) that carry data.
465
Frames Received/sec is the rate at which data frames are received by the computer. This counter only counts the frames (packets) that carry data.
467
Frame Bytes Received/sec is the rate at which data bytes are received by the computer. This counter only counts the frames (packets) that carry data.
469
Frames Re-Sent/sec is the rate at which data frames (packets) are re-sent by the computer. This counter only counts the frames or packets that carry data.
471
Frame Bytes Re-Sent/sec is the rate at which data bytes are re-sent by the computer. This counter only counts the bytes in frames that carry data.
473
Frames Rejected/sec is the rate at which data frames are rejected. This counter only counts the frames (packets) that carry data.
475
Frame Bytes Rejected/sec is the rate at which data bytes are rejected. This counter only counts the bytes in data frames (packets) that carry data.
477
Expirations Response is the count of T1 timer expirations.
479
Expirations Ack is the count of T2 timer expirations.
481
Window Send Maximum is the maximum number of bytes of data that will be sent before waiting for an acknowledgment from the remote computer.
483
Window Send Average is the running average number of data bytes that were sent before waiting for an acknowledgment from the remote computer.
485
Piggyback Ack Queued/sec is the rate at which piggybacked acknowledgments are queued. Piggyback acknowledgments are acknowledgments to received packets that are to be included in the next outgoing packet to the remote computer.
487
Piggyback Ack Timeouts is the number of times that a piggyback acknowledgment could not be sent because there was no outgoing packet to the remote on which to piggyback. A piggyback ack is an acknowledgment to a received packet that is sent along in an outgoing data packet to the remote computer. If no outgoing packet is sent within the timeout period, then an ack packet is sent and this counter is incremented.
489
The NWLink IPX performance object consists of counters that measure datagram transmission to and from computers using the IPX protocol.
491
The NWLink SPX performance object consist of counters that measure data transmission and session connections for computers using the SPX protocol.
493
The NetBEUI performance object consists of counters that measure data transmission for network activity which conforms to the NetBIOS End User Interface standard.
495
The NetBEUI Resource performance object consists of counters that track the use of buffers by the NetBEUI protocol.
497
Used Maximum is the maximum number of NetBEUI resources (buffers) in use at any point in time. This value is useful in sizing the maximum resources provided. The number in parentheses following the resource name is used to identify the resource in Event Log messages.
499
Used Average is the current number of resources (buffers) in use at this time. The number in parentheses following the resource name is used to identify the resource in Event Log messages.
501
Times Exhausted is the number of times all the resources (buffers) were in use. The number in parentheses following the resource name is used to identify the resource in Event Log messages.
503
The NBT Connection performance object consists of counters that measure the rates at which bytes are sent and received over the NBT connection between the local computer and a remote computer. The connection is identified by the name of the remote computer.
505
Bytes Received/sec is the rate at which bytes are received by the local computer over an NBT connection to some remote computer. All the bytes received by the local computer over the particular NBT connection are counted.
507
Bytes Sent/sec is the rate at which bytes are sent by the local computer over an NBT connection to some remote computer. All the bytes sent by the local computer over the particular NBT connection are counted.
509
Bytes Total/sec is the rate at which bytes are sent or received by the local computer over an NBT connection to some remote computer. All the bytes sent or received by the local computer over the particular NBT connection are counted.
511
The Network Interface performance object consists of counters that measure the rates at which bytes and packets are sent and received over a network connection. It includes counters that monitor connection errors.
513
Bytes Total/sec is the rate at which bytes are sent and received over each network adapter, including framing characters. Network Interface\Bytes Total/sec is a sum of Network Interface\Bytes Received/sec and Network Interface\Bytes Sent/sec.
515
Packets/sec is the rate at which packets are sent and received on the network interface.
517
Packets Received/sec is the rate at which packets are received on the network interface.
519
Packets Sent/sec is the rate at which packets are sent on the network interface.
521
Current Bandwidth is an estimate of the current bandwidth of the network interface in bits per second (BPS). For interfaces that do not vary in bandwidth or for those where no accurate estimation can be made, this value is the nominal bandwidth.
523
Bytes Received/sec is the rate at which bytes are received over each network adapter, including framing characters. Network Interface\Bytes Received/sec is a subset of Network Interface\Bytes Total/sec.
525
Packets Received Unicast/sec is the rate at which (subnet) unicast packets are delivered to a higher-layer protocol.
527
Packets Received Non-Unicast/sec is the rate at which non-unicast (subnet broadcast or subnet multicast) packets are delivered to a higher-layer protocol.
529
Packets Received Discarded is the number of inbound packets that were chosen to be discarded even though no errors had been detected to prevent their delivery to a higher-layer protocol. One possible reason for discarding packets could be to free up buffer space.
531
Packets Received Errors is the number of inbound packets that contained errors preventing them from being deliverable to a higher-layer protocol.
533
Packets Received Unknown is the number of packets received through the interface that were discarded because of an unknown or unsupported protocol.
535
Bytes Sent/sec is the rate at which bytes are sent over each network adapter, including framing characters. Network Interface\Bytes Sent/sec is a subset of Network Interface\Bytes Total/sec.
537
Packets Sent Unicast/sec is the rate at which packets are requested to be transmitted to subnet-unicast addresses by higher-level protocols. The rate includes the packets that were discarded or not sent.
539
Packets Sent Non-Unicast/sec is the rate at which packets are requested to be transmitted to non-unicast (subnet broadcast or subnet multicast) addresses by higher-level protocols. The rate includes the packets that were discarded or not sent.
541
Packets Outbound Discarded is the number of outbound packets that were chosen to be discarded even though no errors had been detected to prevent transmission. One possible reason for discarding packets could be to free up buffer space.
543
Packets Outbound Errors is the number of outbound packets that could not be transmitted because of errors.
545
Output Queue Length is the length of the output packet queue (in packets). If this is longer than two, there are delays and the bottleneck should be found and eliminated, if possible. Since the requests are queued by the Network Driver Interface Specification (NDIS) in this implementation, this will always be 0.
547
The IP performance object consists of counters that measure the rates at which IP datagrams are sent and received by using IP protocols. It also includes counters that monitor IP protocol errors.
549
Datagrams/sec is the rate, in incidents per second, at which IP datagrams were received from or sent to the interfaces, including those in error. Forwarded datagrams are not included in this rate.
551
Datagrams Received/sec is the rate, in incidents per second, at which IP datagrams are received from the interfaces, including those in error. Datagrams Received/sec is a subset of Datagrams/sec.
553
Datagrams Received Header Errors is the number of input datagrams that were discarded due to errors in the IP headers, including bad checksums, version number mismatch, other format errors, time-to-live exceeded, errors discovered in processing their IP options, etc.
555
Datagrams Received Address Errors is the number of input datagrams that were discarded because the IP address in their IP header destination field was not valid for the computer. This count includes invalid addresses (for example, 0.0. 0.0) and addresses of unsupported Classes (for example, Class E). For entities that are not IP gateways and do not forward datagrams, this counter includes datagrams that were discarded because the destination address was not a local address.
557
Datagrams Forwarded/sec is the rate, in incidents per second, at which attemps were made to find routes to forward input datagrams their final destination, because the local server was not the final IP destination. In servers that do not act as IP Gateways, this rate includes only packets that were source-routed via this entity, where the source-route option processing was successful.
559
Datagrams Received Unknown Protocol is the number of locally-addressed datagrams that were successfully received but were discarded because of an unknown or unsupported protocol.
561
Datagrams Received Discarded is the number of input IP datagrams that were discarded even though problems prevented their continued processing (for example, lack of buffer space). This counter does not include any datagrams discarded while awaiting re-assembly.
563
Datagrams Received Delivered/sec is the rate, in incidents per second, at which input datagrams were successfully delivered to IP user-protocols, including Internet Control Message Protocol (ICMP).
565
Datagrams Sent/sec is the rate, in incidents per second, at which IP datagrams were supplied for transmission by local IP user-protocols (including ICMP). This counter does not include any datagrams counted in Datagrams Forwarded/sec. Datagrams Sent/sec is a subset of Datagrams/sec.
567
Datagrams Outbound Discarded is the number of output IP datagrams that were discarded even though no problems were encountered to prevent their transmission to their destination (for example, lack of buffer space). This counter includes datagrams counted in Datagrams Forwarded/sec that meet this criterion.
569
Datagrams Outbound No Route is the number of IP datagrams that were discarded because no route could be found to transmit them to their destination. This counter includes any packets counted in Datagrams Forwarded/sec that meet this `no route' criterion.
571
Fragments Received/sec is the rate, in incidents per second, at which IP fragments that need to be reassembled at this entity are received.
573
Fragments Re-assembled/sec is the rate, in incidents per second, at which IP fragments were successfully reassembled.
575
Fragment Re-assembly Failures is the number of failures detected by the IP reassembly algorithm, such as time outs, errors, etc. This is not necessarily a count of discarded IP fragments since some algorithms (notably RFC 815) lose track of the number of fragments by combining them as they are received.
577
Fragmented Datagrams/sec is the rate, in incidents per second, at which datagrams are successfully fragmented.
579
Fragmentation Failures is the number of IP datagrams that were discarded because they needed to be fragmented at but could not be (for example, because the `Don't Fragment' flag was set).
581
Fragments Created/sec is the rate, in incidents per second, at which IP datagram fragments were generated as a result of fragmentation.
583
The ICMP performance object consists of counters that measure the rates at which messages are sent and received by using ICMP protocols. It also includes counters that monitor ICMP protocol errors.
585
Messages/sec is the total rate, in incidents per second, at which ICMP messages were sent and received by the entity. The rate includes messages received or sent in error.
587
Messages Received/sec is the rate, in incidents per second at which ICMP messages were received. The rate includes messages received in error.
589
Messages Received Errors is the number of ICMP messages that the entity received but had errors, such as bad ICMP checksums, bad length, etc.
591
Received Destination Unreachable is the number of ICMP Destination Unreachable messages received.
593
Received Time Exceeded is the number of ICMP Time Exceeded messages received.
595
Received Parameter Problem is the number of ICMP Parameter Problem messages received.
597
Received Source Quench is the number of ICMP Source Quench messages received.
599
Received Redirect/sec is the rate, in incidents per second, at which ICMP Redirect messages were received.
601
Received Echo/sec is the rate, in incidents per second, at which ICMP Echo messages were received.
603
Received Echo Reply/sec is the rate, in incidents per second, at which ICMP Echo Reply messages were received.
605
Received Timestamp/sec is the rate, in incidents per second at which ICMP Timestamp Request messages were received.
607
Received Timestamp Reply/sec is the rate of ICMP Timestamp Reply messages received.
609
Received Address Mask is the number of ICMP Address Mask Request messages received.
611
Received Address Mask Reply is the number of ICMP Address Mask Reply messages received.
613
Messages Sent/sec is the rate, in incidents per second, at which the server attempted to send. The rate includes those messages sent in error.
615
Messages Outbound Errors is the number of ICMP messages that were not send due to problems within ICMP, such as lack of buffers. This value does not include errors discovered outside the ICMP layer, such as those recording the failure of IP to route the resultant datagram. In some implementations, none of the error types are included in the value of this counter.
617
Sent Destination Unreachable is the number of ICMP Destination Unreachable messages sent.
619
Sent Time Exceeded is the number of ICMP Time Exceeded messages sent.
621
Sent Parameter Problem is the number of ICMP Parameter Problem messages sent.
623
Sent Source Quench is the number of ICMP Source Quench messages sent.
625
Sent Redirect/sec is the rate, in incidents per second, at which ICMP Redirect messages were sent.
627
Sent Echo/sec is the rate of ICMP Echo messages sent.
629
Sent Echo Reply/sec is the rate, in incidents per second, at which ICMP Echo Reply messages were sent.
631
Sent Timestamp/sec is the rate, in incidents per second, at which ICMP Timestamp Request messages were sent.
633
Sent Timestamp Reply/sec is the rate, in incidents per second, at which ICMP Timestamp Reply messages were sent.
635
Sent Address Mask is the number of ICMP Address Mask Request messages sent.
637
Sent Address Mask Reply is the number of ICMP Address Mask Reply messages sent.
639
The TCP performance object consists of counters that measure the rates at which TCP Segments are sent and received by using the TCP protocol. It includes counters that monitor the number of TCP connections in each TCP connection state.
641
Segments/sec is the rate at which TCP segments are sent or received using the TCP protocol.
643
Connections Established is the number of TCP connections for which the current state is either ESTABLISHED or CLOSE-WAIT.
645
Connections Active is the number of times TCP connections have made a direct transition to the SYN-SENT state from the CLOSED state. In other words, it shows a number of connections which are initiated by the local computer. The value is a cumulative total.
647
Connections Passive is the number of times TCP connections have made a direct transition to the SYN-RCVD state from the LISTEN state. In other words, it shows a number of connections to the local computer, which are initiated by remote computers. The value is a cumulative total.
649
Connection Failures is the number of times TCP connections have made a direct transition to the CLOSED state from the SYN-SENT state or the SYN-RCVD state, plus the number of times TCP connections have made a direct transition to the LISTEN state from the SYN-RCVD state.
651
Connections Reset is the number of times TCP connections have made a direct transition to the CLOSED state from either the ESTABLISHED state or the CLOSE-WAIT state.
653
Segments Received/sec is the rate at which segments are received, including those received in error. This count includes segments received on currently established connections.
655
Segments Sent/sec is the rate at which segments are sent, including those on current connections, but excluding those containing only retransmitted bytes.
657
Segments Retransmitted/sec is the rate at which segments are retransmitted, that is, segments transmitted containing one or more previously transmitted bytes.
659
The UDP performance object consists of counters that measure the rates at which UDP datagrams are sent and received by using the UDP protocol. It includes counters that monitor UDP protocol errors.
661
Datagrams/sec is the rate at which UDP datagrams are sent or received by the entity.
663
Datagrams Received/sec is the rate at which UDP datagrams are delivered to UDP users.
665
Datagrams No Port/sec is the rate of received UDP datagrams for which there was no application at the destination port.
667
Datagrams Received Errors is the number of received UDP datagrams that could not be delivered for reasons other than the lack of an application at the destination port.
669
Datagrams Sent/sec is the rate at which UDP datagrams are sent from the entity.
671
Disk Storage device statistics from the foreign computer
673
The number of allocation failures reported by the disk storage device
675
System Up Time is the elapsed time (in seconds) that the computer has been running since it was last started. This counter displays the difference between the start time and the current time.
677
The current number of system handles in use.
679
Free System Page Table Entries is the number of page table entries not currently in used by the system. This counter displays the last observed value only; it is not an average.
681
The number of threads currently active in this process. An instruction is the basic unit of execution in a processor, and a thread is the object that executes instructions. Every running process has at least one thread.
683
The current base priority of this process. Threads within a process can raise and lower their own base priority relative to the process' base priority.
685
The total elapsed time, in seconds, that this process has been running.
687
Alignment Fixups/sec is the rate, in incidents per seconds, at alignment faults were fixed by the system.
689
Exception Dispatches/sec is the rate, in incidents per second, at which exceptions were dispatched by the system.
691
Floating Emulations/sec is the rate of floating emulations performed by the system. This counter displays the difference between the values observed in the last two samples, divided by the duration of the sample interval.
693
Logon/sec is the rate of all server logons.
695
The current dynamic priority of this thread. The system can raise the thread's dynamic priority above the base priority if the thread is handling user input, or lower it towards the base priority if the thread becomes compute bound.
697
The current base priority of this thread. The system can raise the thread's dynamic priority above the base priority if the thread is handling user input, or lower it towards the base priority if the thread becomes compute bound.
699
The total elapsed time (in seconds) this thread has been running.
701
The Paging File performance object consists of counters that monitor the paging file(s) on the computer. The paging file is a reserved space on disk that backs up committed physical memory on the computer.
703
The amount of the Page File instance in use in percent. See also Process\\Page File Bytes.
705
The peak usage of the Page File instance in percent. See also Process\\Page File Bytes Peak.
707
Starting virtual address for this thread.
709
Current User Program Counter for this thread.
711
Mapped Space is virtual memory that has been mapped to a specific virtual address (or range of virtual addresses) in the process' virtual address space. No Access protection prevents a process from writing to or reading from these pages and will generate an access violation if either is attempted.
713
Mapped Space is virtual memory that has been mapped to a specific virtual address (or range of virtual addresses) in the process' virtual address space. Read Only protection prevents the contents of these pages from being modified. Any attempts to write or modify these pages will generate an access violation.
715
Mapped Space is virtual memory that has been mapped to a specific virtual address (or range of virtual addresses) in the process' virtual address space. Read/Write protection allows a process to read, modify and write to these pages.
717
Mapped Space is virtual memory that has been mapped to a specific virtual address (or range of virtual addresses) in the process' virtual address space. Write Copy protection is used when memory is shared for reading but not for writing. When processes are reading this memory, they can share the same memory, however, when a sharing process wants to have write access to this shared memory, a copy of that memory is made.
719
Mapped Space is virtual memory that has been mapped to a specific virtual address (or range of virtual addresses) in the process' virtual address space. Executable memory is memory that can be executed by programs, but cannot be read or written. This type of protection is not supported by all processor types.
721
Mapped Space is virtual memory that has been mapped to a specific virtual address (or range of virtual addresses) in the process' virtual address space. Execute/Read Only memory is memory that can be executed as well as read.
723
Mapped Space is virtual memory that has been mapped to a specific virtual address (or range of virtual addresses) in the process' virtual address space. Execute/Read/Write memory is memory that can be executed by programs as well as read and modified.
725
Mapped Space is virtual memory that has been mapped to a specific virtual address (or range of virtual addresses) in the process' virtual address space. Execute Write Copy is memory that can be executed by programs as well as read and written. This type of protection is used when memory needs to be shared between processes. If the sharing processes only read the memory, then they will all use the same memory. If a sharing process desires write access, then a copy of this memory will be made for that process.
727
Reserved Space is virtual memory that has been reserved for future use by a process, but has not been mapped or committed. No Access protection prevents a process from writing to or reading from these pages and will generate an access violation if either is attempted.
729
Reserved Space is virtual memory that has been reserved for future use by a process, but has not been mapped or committed. Read Only protection prevents the contents of these pages from being modified. Any attempts to write or modify these pages will generate an access violation.
731
Reserved Space is virtual memory that has been reserved for future use by a process, but has not been mapped or committed. Read/Write protection allows a process to read, modify and write to these pages.
733
Reserved Space is virtual memory that has been reserved for future use by a process, but has not been mapped or committed. Write Copy protection is used when memory is shared for reading but not for writing. When processes are reading this memory, they can share the same memory, however, when a sharing process wants to have read/write access to this shared memory, a copy of that memory is made.
735
Reserved Space is virtual memory that has been reserved for future use by a process, but has not been mapped or committed. Executable memory is memory that can be executed by programs, but cannot be read or written. This type of protection is not supported by all processor types.
737
Reserved Space is virtual memory that has been reserved for future use by a process, but has not been mapped or committed. Execute/Read Only memory is memory that can be executed as well as read.
739
Reserved Space is virtual memory that has been reserved for future use by a process, but has not been mapped or committed. Execute/Read/Write memory is memory that can be executed by programs as well as read and modified.
741
The Image performance object consists of counters that monitor the virtual address usage of images executed by processes on the computer.
743
Reserved Space is virtual memory that has been reserved for future use by a process, but has not been mapped or committed. Execute Write Copy is memory that can be executed by programs as well as read and written. This type of protection is used when memory needs to be shared between processes. If the sharing processes only read the memory, then they will all use the same memory. If a sharing process desires write access, then a copy of this memory will be made for that process.
745
Unassigned Space is mapped and committed virtual memory in use by the process that is not attributable to any particular image being executed by that process. No Access protection prevents a process from writing to or reading from these pages and will generate an access violation if either is attempted.
747
Unassigned Space is mapped and committed virtual memory in use by the process that is not attributable to any particular image being executed by that process. Read Only protection prevents the contents of these pages from being modified. Any attempts to write or modify these pages will generate an access violation.
749
Unassigned Space is mapped and committed virtual memory in use by the process that is not attributable to any particular image being executed by that process. Read/Write protection allows a process to read, modify and write to these pages.
751
Unassigned Space is mapped and committed virtual memory in use by the process that is not attributable to any particular image being executed by that process. Write Copy protection is used when memory is shared for reading but not for writing. When processes are reading this memory, they can share the same memory, however, when a sharing process wants to have read/write access to this shared memory, a copy of that memory is made for writing to.
753
Unassigned Space is mapped and committed virtual memory in use by the process that is not attributable to any particular image being executed by that process. Executable memory is memory that can be executed by programs, but cannot be read or written. This type of protection is not supported by all processor types.
755
Unassigned Space is mapped and committed virtual memory in use by the process that is not attributable to any particular image being executed by that process. Execute/Read Only memory is memory that can be executed as well as read.
757
Unassigned Space is mapped and committed virtual memory in use by the process that is not attributable to any particular image being executed by that process. Execute/Read/Write memory is memory that can be executed by programs as well as read and written.
759
Unassigned Space is mapped and committed virtual memory in use by the process that is not attributable to any particular image being executed by that process. Execute Write Copy is memory that can be executed by programs as well as read and written. This type of protection is used when memory needs to be shared between processes. If the sharing processes only read the memory, then they will all use the same memory. If a sharing process desires write access, then a copy of this memory will be made for that process.
761
Image Space is the virtual address space in use by the images being executed by the process. This is the sum of all the address space with this protection allocated by images run by the selected process No Access protection prevents a process from writing to or reading from these pages and will generate an access violation if either is attempted.
763
Image Space is the virtual address space in use by the images being executed by the process. This is the sum of all the address space with this protection allocated by images run by the selected process Read Only protection prevents the contents of these pages from being modified. Any attempts to write or modify these pages will generate an access violation.
765
Image Space is the virtual address space in use by the images being executed by the process. This is the sum of all the address space with this protection allocated by images run by the selected process Read/Write protection allows a process to read, modify and write to these pages.
767
Image Space is the virtual address space in use by the images being executed by the process. This is the sum of all the address space with this protection allocated by images run by the selected process Write Copy protection is used when memory is shared for reading but not for writing. When processes are reading this memory, they can share the same memory, however, when a sharing process wants to have read/write access to this shared memory, a copy of that memory is made for writing to.
769
Image Space is the virtual address space in use by the images being executed by the process. This is the sum of all the address space with this protection allocated by images run by the selected process Executable memory is memory that can be executed by programs, but cannot be read or written. This type of protection is not supported by all processor types.
771
Image Space is the virtual address space in use by the images being executed by the process. This is the sum of all the address space with this protection allocated by images run by the selected process Execute/Read-Only memory is memory that can be executed as well as read.
773
Image Space is the virtual address space in use by the images being executed by the process. This is the sum of all the address space with this protection allocated by images run by the selected process Execute/Read/Write memory is memory that can be executed by programs as well as read and written and modified.
775
Image Space is the virtual address space in use by the images being executed by the process. This is the sum of all the address space with this protection allocated by images run by the selected process Execute Write Copy is memory that can be executed by programs as well as read and written. This type of protection is used when memory needs to be shared between processes. If the sharing processes only read the memory, then they will all use the same memory. If a sharing process desires write access, then a copy of this memory will be made for that process.
777
Bytes Image Reserved is the sum of all virtual memory reserved by images within this process.
779
Bytes Image Free is the amount of virtual address space that is not in use or reserved by images within this process.
781
Bytes Reserved is the total amount of virtual memory reserved for future use by this process.
783
Bytes Free is the total unused virtual address space of this process.
785
ID Process is the unique identifier of this process. ID Process numbers are reused, so they only identify a process for the lifetime of that process.
787
The Process Address Space performance object consists of counters that monitor memory allocation and use for a selected process.
789
Image Space is the virtual address space in use by the selected image with this protection. No Access protection prevents a process from writing or reading these pages and will generate an access violation if either is attempted.
791
Image Space is the virtual address space in use by the selected image with this protection. Read Only protection prevents the contents of these pages from being modified. Any attempts to write or modify these pages will generate an access violation.
793
Image Space is the virtual address space in use by the selected image with this protection. Read/Write protection allows a process to read, modify and write to these pages.
795
Image Space is the virtual address space in use by the selected image with this protection. Write Copy protection is used when memory is shared for reading but not for writing. When processes are reading this memory, they can share the same memory, however, when a sharing process wants to have read/write access to this shared memory, a copy of that memory is made for writing to.
797
Image Space is the virtual address space in use by the selected image with this protection. Executable memory is memory that can be executed by programs, but cannot be read or written. This type of protection is not supported by all processor types.
799
Image Space is the virtual address space in use by the selected image with this protection. Execute/Read Only memory is memory that can be executed as well as read.
801
Image Space is the virtual address space in use by the selected image with this protection. Execute/Read/Write memory is memory that can be executed by programs as well as read and written.
803
Image Space is the virtual address space in use by the selected image with this protection. Execute Write Copy is memory that can be executed by programs as well as read and written. This type of protection is used when memory needs to be shared between processes. If the sharing processes only read the memory, then they will all use the same memory. If a sharing process desires write access, then a copy of this memory will be made for that process.
805
ID Thread is the unique identifier of this thread. ID Thread numbers are reused, so they only identify a thread for the lifetime of that thread.
807
Mailslot Opens Failed/sec indicates the rate at which mailslot messages to be delivered to mailslots that are not present are received by this workstation.
809
Duplicate Master Announcements indicates the number of times that the master browser has detected another master browser on the same domain.
811
Illegal Datagrams/sec is the rate at which incorrectly formatted datagrams have been received by the workstation.
813
Announcements Total/sec is the sum of Announcements Server/sec and Announcements Domain/sec.
815
Enumerations Total/sec is the rate at which browse requests have been processed by this workstation. This is the sum of Enumerations Server/sec, Enumerations Domain/sec, and Enumerations Other/sec.
817
The Thread Details performance object consists of counters that measure aspects of thread behavior that are difficult or time-consuming or collect. These counters are distinguished from those in the Thread object by their high overhead.
819
Cache Bytes the size, in bytes, of the portion of the system file cache which is currently resident and active in physical memory. The Cache Bytes and Memory\\System Cache Resident Bytes counters are equivalent. This counter displays the last observed value only; it is not an average.
821
Cache Bytes Peak is the maximum number of bytes used by the system file cache since the system was last restarted. This might be larger than the current size of the cache. This counter displays the last observed value only; it is not an average.
823
Pages Input/sec is the rate at which pages are read from disk to resolve hard page faults. Hard page faults occur when a process refers to a page in virtual memory that is not in its working set or elsewhere in physical memory, and must be retrieved from disk. When a page is faulted, the system tries to read multiple contiguous pages into memory to maximize the benefit of the read operation. Compare the value of Memory\\Pages Input/sec to the value of Memory\\Page Reads/sec to determine the average number of pages read into memory during each read operation.
825
Transition Pages RePurposed is the rate at which the number of transition cache pages were reused for a different purpose. These pages would have otherwise remained in the page cache to provide a (fast) soft fault (instead of retrieving it from backing store) in the event the page was accessed in the future. Note these pages can contain private or sharable memory.
873
The number of bytes transmitted total for this connection.
875
The number of bytes received total for this connection.
877
The number of data frames transmitted total for this connection.
879
The number of data frames received total for this connection.
881
The compression ratio for bytes being transmitted.
883
The compression ratio for bytes being received.
885
The total number of CRC Errors for this connection. CRC Errors occur when the frame received contains erroneous data.
887
The total number of Timeout Errors for this connection. Timeout Errors occur when an expected is not received in time.
889
The total number of Serial Overrun Errors for this connection. Serial Overrun Errors occur when the hardware cannot handle the rate at which data is received.
891
The total number of Alignment Errors for this connection. Alignment Errors occur when a byte received is different from the byte expected.
893
The total number of Buffer Overrun Errors for this connection. Buffer Overrun Errors when the software cannot handle the rate at which data is received.
895
The total number of CRC, Timeout, Serial Overrun, Alignment, and Buffer Overrun Errors for this connection.
897
The number of bytes transmitted per second.
899
The number of bytes received per second.
901
The number of frames transmitted per second.
903
The number of frames received per second.
905
The total number of CRC, Timeout, Serial Overrun, Alignment, and Buffer Overrun Errors per second.
909
The total number of Remote Access connections.
921
The WINS Server performance object consists of counters that monitor communications using the WINS Server service.
923
Unique Registrations/sec is the rate at which unique registration are received by the WINS server.
925
Group Registrations/sec is the rate at which group registration are received by the WINS server.
927
Total Number of Registrations/sec is the sum of the Unique and Group registrations per sec. This is the total rate at which registration are received by the WINS server.
929
Unique Renewals/sec is the rate at which unique renewals are received by the WINS server.
931
Group Renewals/sec is the rate at which group renewals are received by the WINS server.
933
Total Number of Renewals/sec is the sum of the Unique and Group renewals per sec. This is the total rate at which renewals are received by the WINS server.
935
Total Number of Releases/sec is the rate at which releases are received by the WINS server.
937
Total Number of Queries/sec is the rate at which queries are received by the WINS server.
939
Unique Conflicts/sec is the rate at which unique registrations/renewals received by the WINS server resulted in conflicts with records in the database.
941
Group Conflicts/sec is the rate at which group registration received by the WINS server resulted in conflicts with records in the database.
943
Total Number of Conflicts/sec is the sum of the Unique and Group conflicts per sec. This is the total rate at which conflicts were seen by the WINS server.
945
Total Number of Successful Releases/sec
947
Total Number of Failed Releases/sec
949
Total Number of Successful Queries/sec
951
Total Number of Failed Queries/sec
953
The total number of handles currently open by this process. This number is equal to the sum of the handles currently open by each thread in this process.
1001
Services for Macintosh AFP File Server.
1003
The maximum amount of paged memory resources used by the MacFile Server.
1005
The current amount of paged memory resources used by the MacFile Server.
1007
The maximum amount of nonpaged memory resources use by the MacFile Server.
1009
The current amount of nonpaged memory resources used by the MacFile Server.
1011
The number of sessions currently connected to the MacFile server. Indicates current server activity.
1013
The maximum number of sessions connected at one time to the MacFile server. Indicates usage level of server.
1015
The number of internal files currently open in the MacFile server. This count does not include files opened on behalf of Macintosh clients.
1017
The maximum number of internal files open at one time in the MacFile server. This count does not include files opened on behalf of Macintosh clients.
1019
The number of failed logon attempts to the MacFile server. Can indicate whether password guessing programs are being used to crack the security on the server.
1021
The number of bytes read from disk per second.
1023
The number of bytes written to disk per second.
1025
The number of bytes received from the network per second. Indicates how busy the server is.
1027
The number of bytes sent on the network per second. Indicates how busy the server is.
1029
The number of outstanding work items waiting to be processed.
1031
The maximum number of outstanding work items waiting at one time.
1033
The current number of threads used by MacFile server. Indicates how busy the server is.
1035
The maximum number of threads used by MacFile server. Indicates peak usage level of server.
1051
AppleTalk Protocol
1053
Number of packets received per second by Appletalk on this port.
1055
Number of packets sent per second by Appletalk on this port.
1057
Number of bytes received per second by Appletalk on this port.
1059
Number of bytes sent per second by Appletalk on this port.
1061
Average time in milliseconds to process a DDP packet on this port.
1063
Number of DDP packets per second received by Appletalk on this port.
1065
Average time in milliseconds to process an AARP packet on this port.
1067
Number of AARP packets per second received by Appletalk on this port.
1069
Average time in milliseconds to process an ATP packet on this port.
1071
Number of ATP packets per second received by Appletalk on this port.
1073
Average time in milliseconds to process an NBP packet on this port.
1075
Number of NBP packets per second received by Appletalk on this port.
1077
Average time in milliseconds to process a ZIP packet on this port.
1079
Number of ZIP packets per second received by Appletalk on this port.
1081
Average time in milliseconds to process an RTMP packet on this port.
1083
Number of RTMP packets per second received by Appletalk on this port.
1085
Number of ATP requests retransmitted on this port.
1087
Number of ATP release timers that have expired on this port.
1089
Number of ATP Exactly-once transaction responses per second on this port.
1091
Number of ATP At-least-once transaction responses per second on this port.
1093
Number of ATP transaction release packets per second received on this port.
1095
The current amount of nonpaged memory resources used by AppleTalk.
1097
Number of packets routed in on this port.
1099
Number of packets dropped due to resource limitations on this port.
1101
Number of ATP requests retransmitted to this port.
1103
Number of packets routed out on this port.
1111
Provides Network Statistics for the local network segment via the Network Monitor Service.
1113
The total number of frames received per second on this network segment.
1115
The number of bytes received per second on this network segment.
1117
The number of Broadcast frames received per second on this network segment.
1119
The number of Multicast frames received per second on this network segment.
1121
Percentage of network bandwidth in use on this network segment.
1125
Percentage of network bandwidth which is made up of broadcast traffic on this network segment.
1127
Percentage of network bandwidth which is made up of multicast traffic on this network segment.
1151
The Telephony System
1153
The number of telephone lines serviced by this computer.
1155
The number of telephone devices serviced by this computer.
1157
The number of telephone lines serviced by this computer that are currently active.
1159
The number of telephone devices that are currently being monitored.
1161
The rate of outgoing calls made by this computer.
1163
The rate of incoming calls answered by this computer.
1165
The number of applications that are currently using telephony services.
1167
Current outgoing calls being serviced by this computer.
1169
Current incoming calls being serviced by this computer.
1233
Packet Burst Read NCP Count/sec is the rate of NetWare Core Protocol requests for Packet Burst Read. Packet Burst is a windowing protocol that improves performance.
1235
Packet Burst Read Timeouts/sec is the rate the NetWare Service needs to retransmit a Burst Read Request because the NetWare server took too long to respond.
1237
Packet Burst Write NCP Count/sec is the rate of NetWare Core Protocol requests for Packet Burst Write. Packet Burst is a windowing protocol that improves performance.
1239
Packet Burst Write Timeouts/sec is the rate the NetWare Service needs to retransmit a Burst Write Request because the NetWare server took too long to respond.
1241
Packet Burst IO/sec is the sum of Packet Burst Read NCPs/sec and Packet Burst Write NCPs/sec.
1261
Logon Total indicates the total session setup attempts, including all successful logon and failed logons since the server service is started.
1263
The total number of durable handle disconnects that have occurred.
1265
The total number of durable handles that are successfully reconnected. The ratio of "reconnected durable handles"/"total durable handles" indicates the stability gain from reconnect durable handles.
1267
The number of SMB BranchCache hash requests that were for the header only received by the server. This indicates how many requests are being done to validate hashes that are already cached by the client.
1269
The number of SMB BranchCache hash generation requests that were sent by SRV2 to the SMB Hash Generation service because a client requested hashes for the file and there was either no hash content for the file or the existing hashes were out of date.
1271
The number of SMB BranchCache hash requests that were received by the server.
1273
The number of SMB BranchCache hash responses that have been sent from the server.
1275
The amount of SMB BranchCache hash data sent from the server. This includes bytes transferred for both hash header requests and full hash data requests.
1277
The total number of resilient handle disconnect that have occurred.
1279
The total number of resilient handles that are successfully reconnected. The ratio of "reconnected resilient handles"/"total resilient handles" indicates the stability gain from reconnect resilient handles.
1301
The Server Work Queues performance object consists of counters that monitor the length of the queues and objects in the queues.
1303
Queue length is the current number of workitem in Blocking queues and Nonblocking queues, which indicates how busy the server is to process outstanding workitems for this CPU. A sustained queue length greater than four might indicate processor congestion. This is an instantaneous count, not an average over time.
1305
Active Threads is the number of threads currently working on a request from the server client for this CPU. The system keeps this number as low as possible to minimize unnecessary context switching. This is an instantaneous count for the CPU, not an average over time.
1307
Available Threads is the number of server threads on this CPU not currently working on requests from a client. The server dynamically adjusts the number of threads to maximize server performance.
1309
Every request from a client is represented in the server as a 'work item,' and the server maintains a pool of available work items per CPU to speed processing. This is the instantaneous number of available work items for this CPU. A sustained near-zero value indicates the need to increase the MinFreeWorkItems registry value for the Server service. This value will always be 0 in the SMB1 Blocking Queue instance.
1311
Every request from a client is represented in the server as a 'work item,' and the server maintains a pool of available work items per CPU to speed processing. When a CPU runs out of work items, it borrows a free work item from another CPU. An increasing value of this running counter might indicate the need to increase the 'MaxWorkItems' or 'MinFreeWorkItems' registry values for the Server service. This value will always be 0 in the Blocking Queue and SMB2 Queue instances.
1313
Every request from a client is represented in the server as a 'work item,' and the server maintains a pool of available work items per CPU to speed processing. A sustained value greater than zero indicates the need to increase the 'MaxWorkItems' registry value for the Server service. This value will always be 0 in the Blocking Queue and SMB2 Queue instances.
1315
Current Clients is the instantaneous count of the clients being serviced by this CPU. The server actively balances the client load across all of the CPU's in the system. This value will always be 0 in the Blocking Queue instance.
1317
The rate at which the Server is receiving bytes from the network clients on this CPU. This value is a measure of how busy the Server is.
1319
The rate at which the Server is sending bytes to the network clients on this CPU. This value is a measure of how busy the Server is.
1321
The rate at which the Server is sending and receiving bytes with the network clients on this CPU. This value is a measure of how busy the Server is.
1323
Read Operations/sec is the rate the server is performing file read operations for the clients on this CPU. This value is a measure of how busy the Server is. This value will always be 0 in the Blocking Queue instance.
1325
Read Bytes/sec is the rate the server is reading data from files for the clients on this CPU. This value is a measure of how busy the Server is.
1327
Write Operations/sec is the rate the server is performing file write operations for the clients on this CPU. This value is a measure of how busy the Server is. This value will always be 0 in the Blocking Queue instance.
1329
Write Bytes/sec is the rate the server is writing data to files for the clients on this CPU. This value is a measure of how busy the Server is.
1331
Total Bytes/sec is the rate the Server is reading and writing data to and from the files for the clients on this CPU. This value is a measure of how busy the Server is.
1333
Total Operations/sec is the rate the Server is performing file read and file write operations for the clients on this CPU. This value is a measure of how busy the Server is. This value will always be 0 in the Blocking Queue instance.
1335
DPCs Queued/sec is the average rate, in incidents per second, at which deferred procedure calls (DPCs) were added to the processor's DPC queue. DPCs are interrupts that run at a lower priority than standard interrupts. Each processor has its own DPC queue. This counter measures the rate that DPCs are added to the queue, not the number of DPCs in the queue. This counter displays the difference between the values observed in the last two samples, divided by the duration of the sample interval.
1337
DPC Rate is the rate at which deferred procedure calls (DPCs) were added to the processors DPC queues between the timer ticks of the processor clock. DPCs are interrupts that run at alower priority than standard interrupts. Each processor has its own DPC queue. This counter measures the rate that DPCs were added to the queue, not the number of DPCs in the queue. This counter displays the last observed value only; it is not an average.
1343
Total DPCs Queued/sec is the combined rate at which deferred procedure calls (DPCs) are added to the DPC queue of all processors on the computer. (DPCs are interrupts that run at a lower priority than standard interrupts). Each processor has its own DPC queue. This counter measures the rate at which DPCs are added to the queue, not the number of DPCs in the queue. It is the sum of Processor: DPCs Queued/sec for all processors on the computer, divided by the number of processors. This counter displays the difference between the values observed in the last two samples, divided by the duration of the sample interval.
1345
Total DPC Rate is the combined rate at which deferred procedure calls (DPCs) are added to the DPC queues of all processors between timer ticks of each processor's system clock. (DPCs are interrupts that run at a lower priority than standard interrupts). Each processor has its own DPC queue. This counter measures the rate at which DPCs are added to the queue, not the number of DPCs in the queue. It is the sum of Processor: DPC Rate for all processors on the computer, divided by the number of processors. This counter displays the last observed value only; it is not an average.
1351
% Registry Quota In Use is the percentage of the Total Registry Quota Allowed that is currently being used by the system. This counter displays the current percentage value only; it is not an average.
1361
Counters that indicate the status of local and system Very Large memory allocations.
1363
VLM % Virtual Size In Use
1365
Current size of the process VLM Virtual memory space in bytes.
1367
The peak size of the process VLM virtual memory space in bytes. This value indicates the maximum size of the process VLM virtual memory since the process started.
1369
The current size of the process VLM virtual memory space in bytes that may be allocated. Note that the maximum allocation allowed may be smaller than this value due to fragmentation of the memory space.
1371
The current size of committed VLM memory space for the current process in bytes.
1373
The peak size of the committed VLM memory space in bytes for the current process since the process started.
1375
The current size of all committed VLM memory space in bytes for the system.
1377
The peak size of all committed VLM memory space in bytes since the system was started.
1379
The current size of all committed shared VLM memory space in bytes for the system.
1381
Available KBytes is the amount of physical memory, in Kilobytes, immediately available for allocation to a process or for system use. It is equal to the sum of memory assigned to the standby (cached), free and zero page lists.
1383
Available MBytes is the amount of physical memory, in Megabytes, immediately available for allocation to a process or for system use. It is equal to the sum of memory assigned to the standby (cached), free and zero page lists.
1401
Avg. Disk Queue Length is the average number of both read and write requests that were queued for the selected disk during the sample interval.
1403
Avg. Disk Read Queue Length is the average number of read requests that were queued for the selected disk during the sample interval.
1405
Avg. Disk Write Queue Length is the average number of write requests that were queued for the selected disk during the sample interval.
1407
% Committed Bytes In Use is the ratio of Memory\\Committed Bytes to the Memory\\Commit Limit. Committed memory is the physical memory in use for which space has been reserved in the paging file should it need to be written to disk. The commit limit is determined by the size of the paging file. If the paging file is enlarged, the commit limit increases, and the ratio is reduced). This counter displays the current percentage value only; it is not an average.
1409
The Full Image performance object consists of counters that monitor the virtual address usage of images executed by processes on the computer. Full Image counters are the same counters as contained in Image object with the only difference being the instance name. In the Full Image object, the instance name includes the full file path name of the loaded modules, while in the Image object only the filename is displayed.
1411
The Creating Process ID value is the Process ID of the process that created the process. The creating process may have terminated, so this value may no longer identify a running process.
1413
The rate at which the process is issuing read I/O operations. This counter counts all I/O activity generated by the process to include file, network and device I/Os.
1415
The rate at which the process is issuing write I/O operations. This counter counts all I/O activity generated by the process to include file, network and device I/Os.
1417
The rate at which the process is issuing read and write I/O operations. This counter counts all I/O activity generated by the process to include file, network and device I/Os.
1419
The rate at which the process is issuing I/O operations that are neither read nor write operations (for example, a control function). This counter counts all I/O activity generated by the process to include file, network and device I/Os.
1421
The rate at which the process is reading bytes from I/O operations. This counter counts all I/O activity generated by the process to include file, network and device I/Os.
1423
The rate at which the process is writing bytes to I/O operations. This counter counts all I/O activity generated by the process to include file, network and device I/Os.
1425
The rate at which the process is reading and writing bytes in I/O operations. This counter counts all I/O activity generated by the process to include file, network and device I/Os.
1427
The rate at which the process is issuing bytes to I/O operations that do not involve data such as control operations. This counter counts all I/O activity generated by the process to include file, network and device I/Os.
1451
Displays performance statistics about a Print Queue.
1453
Total number of jobs printed on a print queue since the last restart.
1455
Number of bytes per second printed on a print queue.
1457
Total number of pages printed through GDI on a print queue since the last restart.
1459
Current number of jobs in a print queue.
1461
Current number of references (open handles) to this printer.
1463
Peak number of references (open handles) to this printer.
1465
Current number of spooling jobs in a print queue.
1467
Maximum number of spooling jobs in a print queue since last restart.
1469
Total number of out of paper errors in a print queue since the last restart.
1471
Total number of printer not ready errors in a print queue since the last restart.
1473
Total number of job errors in a print queue since last restart.
1475
Total number of calls from browse clients to this print server to request network browse lists since last restart.
1477
Total number of calls from other print servers to add shared network printers to this server since last restart.
1479
Working Set - Private displays the size of the working set, in bytes, that is use for this process only and not shared nor sharable by other processes.
1481
Working Set - Shared displays the size of the working set, in bytes, that is sharable and may be used by other processes. Because a portion of a process' working set is shareable, does not necessarily mean that other processes are using it.
1483
% Idle Time reports the percentage of time during the sample interval that the disk was idle.
1485
Split IO/Sec reports the rate at which I/Os to the disk were split into multiple I/Os. A split I/O may result from requesting data of a size that is too large to fit into a single I/O or that the disk is fragmented.
1501
Reports the accounting and processor usage data collected by each active named Job object.
1503
Current % Processor Time shows the percentage of the sample interval that the processes in the Job object spent executing code.
1505
Current % User mode Time shows the percentage of the sample interval that the processes in the Job object spent executing code in user mode.
1507
Current % Kernel mode Time shows the percentage of the sample interval that the processes in the Job object spent executing code in kernel or privileged mode.
1509
This Period mSec - Processor shows the time, in milliseconds, of processor time used by all the processes in the Job object, including those that have terminated or that are no longer associated with the Job object, since a time limit on the Job was established.
1511
This Period mSec - User mode shows the time, in milliseconds, of user mode processor time used by all the processes in the Job object, including those that have terminated or that are no longer associated with the Job object, since a time limit on the Job was established.
1513
This Period mSec - Kernel mode shows the time, in milliseconds, of kernel mode processor time used by all the processes in the Job object, including those that have terminated or that are no longer associated with the Job object, since a time limit on the Job was established.
1515
Pages/Sec shows the page fault rate of all the processes in the Job object.
1517
Process Count - Total shows the number of processes, both active and terminated, that are or have been associated with the Job object.
1519
Process Count - Active shows the number of processes that are currently associated with the Job object.
1521
Process Count - Terminated shows the number of processes that have been terminated because of a limit violation.
1523
Total mSec - Processor shows the time, in milliseconds, of processor time used by all the processes in the Job object, including those that have terminated or that are no longer associated with the Job object, since the Job object was created.
1525
Total mSec - User mode shows the time, in milliseconds, of user mode processor time used by all the processes in the Job object, including those that have terminated or that are no longer associated with the Job object, since the Job object was created.
1527
Total mSec - Kernel mode shows the time, in milliseconds, of kernel mode processor time used by all the processes in the Job object, including those that have terminated or that are no longer associated with the Job object, since the Job object was created.
1537
Received Packet Too Big is the number of received packets thatare larger than anticipated.
1539
Received Membership Query is the number of packets received thatquery their membership to a group.
1541
Received Membership Report is the number of packets received thatreport their membership to a group.
1543
Received Membership Reduction is the number of packets received thatcancelled their membership to a group.
1545
Received Router Solicit is the number of packets received thatsolicit the router.
1547
Received Router Advert is the number of packets received thatadvert the router.
1549
% Job object Details shows detailed performance information about the active processes that make up a Job object.
1551
Received Neighbor Solicit is the number of packets received thatsolicit a neighbor.
1553
Received Neighbor Advert is the number of packets received thatadvert a neighbor.
1555
Sent Packet Too Big is the number of sent packets thatare larger than anticipated.
1557
Sent Membership Query is the number of packets sent thatquery their membership to a group.
1559
Sent Membership Report is the number of packets sent thatreport their membership to a group.
1561
Sent Membership Reduction is the number of packets sent thatcancelled their membership to a group.
1563
Sent Router Solicit is the number of packets sent thatsolicit the router.
1565
Sent Router Advert is the number of packets sent thatadvert the router.
1567
Sent Neighbor Solicit is the number of packets sent thatsolicit a neighbor.
1569
Sent Neighbor Advert is the number of packets sent thatadvert a neighbor.
1571
These counters track authentication performance on a per second basis.
1573
This counter tracks the number of NTLM authentications processed per second for the AD on this DC or for local accounts on this member server.
1575
This counter tracks the number of times that clients use a ticket to authenticate to this computer per second.
1577
This counter tracks the number of Authentication Service (AS) requests that are being processed by the Key Distribution Center (KDC) per second. Clients use AS requests to obtain a ticket-granting ticket.
1579
This counter tracks the number of ticket-granting service (TGS) requests that are being processed by the Key Distribution Center (KDC) per second. Clients use these TGS requests to obtain a service ticket, which allows a client to access resources on other computers.
1581
This counter tracks the number of Secure Sockets Layer (SSL) entries that are currently stored in the secure channel (Schannel) session cache. The Schannel session cache stores information about successfully established sessions, such as SSL session IDs. Clients can use this information to reconnect to a server without performing a full SSL handshake.
1583
This counter tracks the number of Secure Sockets Layer (SSL) entries that are currently stored in the secure channel (Schannel) session cache and that are currently in use. The Schannel session cache stores information about successfully established sessions, such as SSL session IDs. Clients can use this information to reconnect to a server without performaing a full SSL handshake.
1585
This counter tracks the number of Secure Sockets Layer (SSL) full client-side handshakes that are being processed per second. During a handshake, signals are exchanged to acknowledge that communication can occur between computers or other devices.
1587
This counter tracks the number of Secure Sockets Layer (SSL) client-side reconnect handshakes that are being processed per second. Reconnect handshakes allow session keys from previous SSL sessions to be used to resume a client/server connection, and they require less memory to process than full handshakes.
1589
This counter tracks the number of Secure Sockets Layer (SSL) full server-side handshakes that are being processed per second. During a handshake, signals are exchanged to acknowledge that communication can occur between computers or other devices.
1591
This counter tracks the number of Secure Sockets Layer (SSL) server-side reconnect handshakes that are being processed per second. Reconnect handshakes allow session keys from previous SSL sessions to be used to resume a client/server connection, and they require less memory to process than full handshakes.
1593
This counter tracks the number of Digest authentications that are being processed per second.
1595
This counter tracks the number of Kerberos requests that a read-only domain controller (RODC) forwards to its hub, per second. This counter is tracked only on a RODC.
1597
Offloaded Connections is the number of TCP connections (over both IPv4 and IPv6) that are currently handled by the TCP chimney offload capable network adapter.
1599
TCP Active RSC Connections is the number of TCP connections (over both IPv4 and IPv6) that are currently receiving large packets from the RSC capable network adapter on this network interface.
1601
TCP RSC Coalesced Packets/sec shows the large packet receive rate across all TCP connections on this network interface.
1603
TCP RSC Exceptions/sec shows the RSC exception rate for receive packets across all TCP connections on this network interface.
1605
TCP RSC Average Packet Size is the average size in bytes of received packets across all TCP connections on this network interface.
1621
This counter tracks the number of armored Authentication Service (AS) requests that are being processed by the Key Distribution Center (KDC) per second.
1623
This counter tracks the number of armored ticket-granting service (TGS) requests that are being processed by the Key Distribution Center (KDC) per second.
1625
This counter tracks the number of Authentication Service (AS) requests explicitly requesting claims that are being processed by the Key Distribution Center (KDC) per second.
1627
This counter tracks the number of service asserted identity (S4U2Self) TGS requests that are explicitly requesting claims. These requests are being processed by the Key Distribution Center (KDC) per second.
1629
This counter tracks the number of constrained delegation (S4U2Proxy) TGS requests that are being processed by the Key Distribution Center (KDC) by checking classic type constrained delegation configuration per second. The classic type constrained delegation is restricted to a single domain and configures the backend services SPN on the middle-tier serviceÂ’s account object.
1631
This counter tracks the number of constrained delegation (S4U2Proxy) TGS requests that are being processed by the Key Distribution Center (KDC) by checking the resource type constrained delegation per second. The resource type constrained delegation can cross domain boundaries and configures the middle-tierÂ’s account on the backend serviceÂ’s account object.
1633
This counter tracks the number of claims-aware ticket-granting service (TGS) requests that are being processed by the Key Distribution Center (KDC) per second. A claims-aware Kerberos client will always request claims during Authentication Service (AS) exchanges.
1671
These counters track the number of security resources and handles used per process.
1673
This counter tracks the number of credential handles in use by a given process. Credential handles are handles to pre-existing credentials, such as a password, that are associated with a user and are established through a system logon.
1675
This counter tracks the number of context handles in use by a given process. Context handles are associated with security contexts established between a client application and a remote peer.
1677
Free & Zero Page List Bytes is the amount of physical memory, in bytes, that is assigned to the free and zero page lists. This memory does not contain cached data. It is immediately available for allocation to a process or for system use.
1679
Modified Page List Bytes is the amount of physical memory, in bytes, that is assigned to the modified page list. This memory contains cached data and code that is not actively in use by processes, the system and the system cache. This memory needs to be written out before it will be available for allocation to a process or for system use.
1681
Standby Cache Reserve Bytes is the amount of physical memory, in bytes, that is assigned to the reserve standby cache page lists. This memory contains cached data and code that is not actively in use by processes, the system and the system cache. It is immediately available for allocation to a process or for system use. If the system runs out of available free and zero memory, memory on lower priority standby cache page lists will be repurposed before memory on higher priority standby cache page lists.
1683
Standby Cache Normal Priority Bytes is the amount of physical memory, in bytes, that is assigned to the normal priority standby cache page lists. This memory contains cached data and code that is not actively in use by processes, the system and the system cache. It is immediately available for allocation to a process or for system use. If the system runs out of available free and zero memory, memory on lower priority standby cache page lists will be repurposed before memory on higher priority standby cache page lists.
1685
Standby Cache Core Bytes is the amount of physical memory, in bytes, that is assigned to the core standby cache page lists. This memory contains cached data and code that is not actively in use by processes, the system and the system cache. It is immediately available for allocation to a process or for system use. If the system runs out of available free and zero memory, memory on lower priority standby cache page lists will be repurposed before memory on higher priority standby cache page lists.
1687
Long-Term Average Standby Cache Lifetime, in seconds. The average lifetime of data in the standby cache over a long interval is measured.
1747
% Idle Time is the percentage of time the processor is idle during the sample interval
1749
% C1 Time is the percentage of time the processor spends in the C1 low-power idle state. % C1 Time is a subset of the total processor idle time. C1 low-power idle state enables the processor to maintain its entire context and quickly return to the running state. Not all systems support the % C1 state.
1751
% C2 Time is the percentage of time the processor spends in the C2 low-power idle state. % C2 Time is a subset of the total processor idle time. C2 low-power idle state enables the processor to maintain the context of the system caches. The C2 power state is a lower power and higher exit latency state than C1. Not all systems support the C2 state.
1753
% C3 Time is the percentage of time the processor spends in the C3 low-power idle state. % C3 Time is a subset of the total processor idle time. When the processor is in the C3 low-power idle state it is unable to maintain the coherency of its caches. The C3 power state is a lower power and higher exit latency state than C2. Not all systems support the C3 state.
1755
C1 Transitions/sec is the rate that the CPU enters the C1 low-power idle state. The CPU enters the C1 state when it is sufficiently idle and exits this state on any interrupt. This counter displays the difference between the values observed in the last two samples, divided by the duration of the sample interval.
1757
C2 Transitions/sec is the rate that the CPU enters the C2 low-power idle state. The CPU enters the C2 state when it is sufficiently idle and exits this state on any interrupt. This counter displays the difference between the values observed in the last two samples, divided by the duration of the sample interval.
1759
C3 Transitions/sec is the rate that the CPU enters the C3 low-power idle state. The CPU enters the C3 state when it is sufficiently idle and exits this state on any interrupt. This counter displays the difference between the values observed in the last two samples, divided by the duration of the sample interval.
1761
Heap performance counters for must used heaps
1763
Memory actively used by this heap (FreeBytes + AllocatedBytes)
1765
Total virtual address space reserved for this heap (includes uncommitted ranges)
1767
ReservedBytes minus last uncommitted range in each segment
1769
Memory on freelists in this heap (does not include uncommitted ranges or blocks in heap cache)
1771
Number of blocks on the list of free blocks >1k in size
1773
1/Average time per allocation (excluding allocs from heap cache)
1775
1/Average time per free (excluding frees to heap cache)
1777
Number of uncommitted ranges in the reserved virtual address
1779
Difference between number of allocations and frees (for leak detection)
1781
Allocations/sec from heap cache
1783
Frees/sec from heap cache
1785
Allocations/sec of size <1k bytes (including heap cache)
1787
Frees/sec of size <1k bytes (including heap cache)
1789
Allocations/sec of size 1-8k bytes
1791
Frees/sec of size 1-8k bytes
1793
Allocations/sec of size over 8k bytes
1795
Frees/sec of size over 8k bytes
1797
Allocations/sec (including from heap cache)
1799
Frees/sec (including to heap cache)
1801
Total number of blocks in the heap cache
1803
Largest number of blocks of any one size in the heap cache
1805
(FreeBytes / CommittedBytes) *100
1807
(VirtualBytes / ReservedBytes) * 100
1809
Collisions/sec on the heap lock
1811
Total number of dirty pages on the system cache
1813
Threshold for number of dirty pages on system cache
1815
Counters that report approximate memory utilization statistics per node on NUMA systems.
1817
Total amount of physical memory associated with a NUMA node in megabytes.
1819
Approximate amount of physical memory on the free and zero page lists for a NUMA node, in megabytes.
1821
The Network Adapter performance object consists of counters that measure the rates at which bytes and packets are sent and received over a physical or virtual network connection. It includes counters that monitor connection errors.
1823
Approximate amount of physical memory on the standby page list for a NUMA node, in megabytes. This counter is available only on 64-bit systems.
1825
Approximate amount of physical memory available for allocation for a NUMA node, in megabytes. Computed as the sum of memory on the zeroed, free, and standby lists for a NUMA node. This counter is available only on 64-bit systems.
1827
The number of SMB BranchCache hash V2 requests that were for the header only received by the server. This indicates how many requests are being done to validate hashes that are already cached by the client.
1829
The number of SMB BranchCache hash V2 generation requests that were sent by SRV2 to the SMB Hash Generation service because a client requested hashes for the file and there was either no hash content for the file or the existing hashes were out of date.
1831
The number of SMB BranchCache hash V2 requests that were received by the server.
1833
The number of SMB BranchCache hash V2 responses that have been sent from the server.
1835
The amount of SMB BranchCache hash V2 data sent from the server. This includes bytes transferred for both hash header requests and full hash data requests.
1837
The amount of SMB BranchCache hash V2 requests that were served from dedup store by the server.
1847
End Marker
1913
The Telphony System
1915
The number of telephone lines serviced by this computer.
1917
The number of telephone devices serviced by this computer.
1919
the number of telephone lines serviced by this computer that are currently active.
1921
The number of telephone devices that are currently being monitored.
1923
The rate of outgoing calls made by this computer.
1925
The rate of incoming calls answered by this computer.
1927
The number of applications that are currently using telephony services.
1929
Current outgoing calls being serviced by this computer.
1931
Current incoming calls being serviced by this computer.
2353
Database provides performance statistics for each process using the ESE high performance embedded database management system.
2355
Pages Converted/sec is the number of times per second a database page is converted from an older database format.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{744C9FEA-08B7-43E1-A729-0F94647D655C}]
"Path"="\Microsoft\Windows\UpdateOrchestrator\Resume On Boot"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{744C9FEA-08B7-43E1-A729-0F94647D655C}]
"URI"="\Microsoft\Windows\UpdateOrchestrator\Resume On Boot"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\UpdateOrchestrator\Resume On Boot]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"RestoreErrorContext"="System Restore failed to extract the file (C:\Users\Doug\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\LiveComm\d44d11591351c228\120712-0049\Att\2000dde0\Resume_LinkedIn.zip) from the restore point."
[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Perflib\009]
"Counter"="1
1847
2
System
4
Memory
6
% Processor Time
10
File Read Operations/sec
12
File Write Operations/sec
14
File Control Operations/sec
16
File Read Bytes/sec
18
File Write Bytes/sec
20
File Control Bytes/sec
24
Available Bytes
26
Committed Bytes
28
Page Faults/sec
30
Commit Limit
32
Write Copies/sec
34
Transition Faults/sec
36
Cache Faults/sec
38
Demand Zero Faults/sec
40
Pages/sec
42
Page Reads/sec
44
Processor Queue Length
46
Thread State
48
Pages Output/sec
50
Page Writes/sec
52
Browser
54
Announcements Server/sec
56
Pool Paged Bytes
58
Pool Nonpaged Bytes
60
Pool Paged Allocs
64
Pool Nonpaged Allocs
66
Pool Paged Resident Bytes
68
System Code Total Bytes
70
System Code Resident Bytes
72
System Driver Total Bytes
74
System Driver Resident Bytes
76
System Cache Resident Bytes
78
Announcements Domain/sec
80
Election Packets/sec
82
Mailslot Writes/sec
84
Server List Requests/sec
86
Cache
88
Data Maps/sec
90
Sync Data Maps/sec
92
Async Data Maps/sec
94
Data Map Hits %
96
Data Map Pins/sec
98
Pin Reads/sec
100
Sync Pin Reads/sec
102
Async Pin Reads/sec
104
Pin Read Hits %
106
Copy Reads/sec
108
Sync Copy Reads/sec
110
Async Copy Reads/sec
112
Copy Read Hits %
114
MDL Reads/sec
116
Sync MDL Reads/sec
118
Async MDL Reads/sec
120
MDL Read Hits %
122
Read Aheads/sec
124
Fast Reads/sec
126
Sync Fast Reads/sec
128
Async Fast Reads/sec
130
Fast Read Resource Misses/sec
132
Fast Read Not Possibles/sec
134
Lazy Write Flushes/sec
136
Lazy Write Pages/sec
138
Data Flushes/sec
140
Data Flush Pages/sec
142
% User Time
144
% Privileged Time
146
Context Switches/sec
148
Interrupts/sec
150
System Calls/sec
152
Level 1 TLB Fills/sec
154
Level 2 TLB Fills/sec
156
Enumerations Server/sec
158
Enumerations Domain/sec
160
Enumerations Other/sec
162
Missed Server Announcements
164
Missed Mailslot Datagrams
166
Missed Server List Requests
168
Server Announce Allocations Failed/sec
170
Mailslot Allocations Failed
172
Virtual Bytes Peak
174
Virtual Bytes
178
Working Set Peak
180
Working Set
182
Page File Bytes Peak
184
Page File Bytes
186
Private Bytes
188
Announcements Total/sec
190
Enumerations Total/sec
198
Current Disk Queue Length
200
% Disk Time
202
% Disk Read Time
204
✨ Ask AI about this thread
No ads, no affiliate links — generated on request from this thread's own
archived content, not written by forum staff. Never run a scan/removal tool
as a self-service step if the original thread describes it being done under
a helper's direct supervision, and don't include your name, email, or other
personal details in a follow-up question. See our privacy page
for details on how this works.