Tools to help build windows event manifest

pip install InstrumentationManifestTools


Generating Event Manifests

You'll need the Windows SDK installed to generate and edit the .man files.

Editing man files

Use ECManGen.exe

Specifying the location of messageFileName and resourceFileName in the .man file is how the WPA application finds the event meta information for the UI.

Compiling man files

Use mc.exe to generate header and resource files from the man file.

-um option generates function calls to record the events

mc -um

Installing the manifest

Use the following command to install the manifest on a machine

wevtutil im

Use the following command to remove the manifest from a machine

wevtutil im

Recording the correct providers

Generate a .wprp file in order to add the providers to WPR and select them for recording.