MZ@ !L!This program cannot be run in DOS mode. $Rؕ3}3}3}H̴3}H̱3}Rich3}PEL!  @@.rsrc@@0H 8Ph     (@X&p'()*,30H`x      0 @ P ` p             0 @ P ` p   !$v',*x8/.h47; <zL?(A*TC DbD P"QR(ST$T4VXtY]&FMUI LOGMAN.XSLX?AyPq@2̪yv,{%, MUIen-USCcomputer`s`computer`Perform the command on specified remote system.'create`*`*`Create a new data collector.Lstart`*`*`Start an existing data collector and set the begin time to manual.Hstop`*`*`Stop an existing data collector and set the end time to manual.-delete`*`*`Delete an existing data collector.kquery`*`name|providers`Query data collector properties. If no name is given all data collectors are listed.5begin`b`*`Begin the data collector at specified time.1end`e`*`End the data collector at specified time.Prepeat`r`*`Repeat the data collector daily at the specified begin and end times.&name`n`name`Name of the target object.out`o`path|dsn!log`Path of the output log file or the DSN and log set name in a SQL database. The default path is '%systemdrive%\PerfLogs\Admin'.format`f`bin|bincirc|csv|tsv|sql`Specifies the log format for the data collector. For SQL database format, you must use the -o option in the command line with the DNS!log option. The defaults is binary.PA*append`a`*`Append to an existing log file.Xversion`v`nnnnnn|mmddhhmm`Attach file versioning information to the end of the log name.Eruncmd`rc`task`Run the command specified each time the log is closed.Hmax`max`*`Maximum log file size in MB or number of records for SQL logs.enewfile`cnf`*`Create a new file when the specified time has elapsed or when the max size is exceeded.0counters`c`path`Performance counters to collect.Lcounterfile`cf`*`File listing performance counters to collect, one per line.Dsample`si`*`Sample interval for performance counter data collectors.<logname`ln`logger_name`Logger name for Event Trace Sessions.<realtime`rt`*`Run the Event Trace Session in real-time mode.provider`p`provider [flags [level]]`A single Event Trace provider to enable. The terms 'Flags' and 'Keywords' are synonymous in this context.Hproviderfile`pf`*`File listing multiple Event Trace providers to enable.7usermode`ul`*`Run the Event Trace Session in user mode.6buffersize`bs`*`Event Trace Session buffer size in kb.0flushtimer`ft`*`Event Trace Session flush timer.9buffers`nb`min max`Number of Event Trace Session buffers.PAYflushdisk`fd`*`Flushes all the active buffers of an existing Event Trace Session to disk.:update`*`*`Update an existing data collector's properties.user`u`user [password]`User to Run As. Entering a * for the password produces a prompt for the password. The password is not displayed when you type it at the password prompt.Drunfor`rf`*`Run the data collector for the specified period of time.8force`y`*`Answer yes to all questions without prompting.`manual`m`[start] [stop]`Change to manual start or stop instead of a scheduled begin or end time.Zsession`ets`*`Send commands to Event Trace Sessions directly without saving or scheduling.>agelimit`age`limit`Modify aging decay time to <limit> minutes.mode`mode`trace_mode`Event Trace Session logger mode. For more information visit - http://go.microsoft.com/fwlink/?LinkID=136464,counter`*`*`Create a counter data collector.(trace`*`*`Create a trace data collector.(providers`*`*`Show registered providers.clocktype`ct`perf|system|cycle`Specifies the clock resolution to use when logging the time stamp for each event. You can use query performance counter, system time, or CPU cycle.)alert`*`*`Create an alert data collector..cfg`*`*`Create a configuration data collector.-api`*`*`Create an API Tracing data collector.-registry`reg`path`Registry values to collect.,management`mgt`query`WMI objects to collect.9filetocollect`ftc`path`Full path to the files to collect.=networkinterface`ni`*`Enable/Disable network interface query.Qthreshold`th`threshold`Specify counters and their threshold values for and alert.1eventlog`el`*`Enable/Disable event log reporting.PA>rundcs`rdcs`name`Data collector set to start when alert fires..taskname`tn`task`Task to run when alert fires.*taskargument`targ`argument`Task arguments.6exepath`exe`*`Full path to executable for API Tracing.&apinamesonly`ano`*`Log API names only.8modules`mods`path`List of modules to log API calls from.Fincludeapis`inapis`module!api`List of API calls to include in logging.Hexcludeapis`exapis`module!api`List of API calls to exclude from logging.`samplecount`sc`*`Maximum number of samples to collect with a performance counter data collector.%processId`pid`pid`Process identifier.3xml`xml`*`Name of the XML file to import or export..overwrite`ow`*`Overwrite an existing log file.8import`*`*`Import a data collector set from an XML file.6export`*`*`Export a data collector set to an XML file.Glogrecursively`recursive`*`Log APIs recursively beyond the first layer.:async`as`*`Perform the requested operation asynchronously.PAN Data Collector Set Type Status %1!s! %2!-30s!%3!-8s! CounterTraceAlertPAStoppedRunningPendingStatus: %1!s! Name: %1!s! Type: %1!s! File: %1!s! Run As: %1!s! Enter the user name for %1!s!: Enter the password for %1!s!: this connection'Session Id File %1!s! %2!-6s! %3!s! %1!-26s! %2!s! Counters: Logger name: %1!s! PABuffer Size: %1!d! <Invalid Parameter>Start: Stop: <Manual>Duration: (Repeating) <By Size> New File: %1!s! Providers: System/ Provider GUID Name:Logman Windows 2000JProvider Flags Level KeywordLevel Undefined ConfigurationGroupBegin: End: <Default>Registry Keys: ApiTrace CompilingL The Data Collector Set '%1!s!' is currently '%2!s!' and cannot be deleted. PIDPAValue DescriptionImageAMicrosoft TechNet - http://go.microsoft.com/fwlink/?LinkID=136332outputnnnnnn(Process,Thread,Disk)PAlogman start "NT Kernel Logger" -o log.etl -etslogman start "NT Kernel Logger" -p "Windows Kernel Trace" (process,thread) -etslogman start perf_log0logman update perf_log -si 10 -f csv -v mmddhhmm=logman create trace trace_log -nb 16 256 -bs 64 -o c:\logfilelogman create counter perf_log -c "\Processor(_Total)\% Processor Time"logman create counter perf_log -c "\Processor(_Total)\% Processor Time" -max 10 -rf 01:00Jlogman create alert new_alert -th "\Processor(_Total)\% Processor Time>50"logman create cfg cfg_log -reg "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\\"logman create cfg cfg_log -mgt "root\cimv2:SELECT * FROM Win32_OperatingSystem"dlogman create api trace_notepad -exe c:\windows\notepad.exe -o c:\notepad.etllogman create api trace_notepad -exe c:\windows\notepad.exe -mods c:\windows\system32\advapi32.dlllogman create api trace_notepad -exe c:\windows\notepad.exe -exapis kernel32.dll!TlsGetValuelogman.exe create api trace_notepad -exe c:\windows\system32\notepad.exe -bincirc -anohlogman start process_trace -p Microsoft-Windows-Kernel-Process -mode newfile -max 1 -o output%d.etl -etslogman start usermode_trace -p "Service Control Manager Trace" -ul -etslogman query usermode_trace -p "Service Control Manager Trace" -ul -etslogman stop usermode_trace -p "Service Control Manager Trace" -ul -etsVlogman query providerslogman query providers Microsoft-Windows-Diagnostics-NetworkingZlogman start process_trace -p Microsoft-Windows-Kernel-Process 0x10 win:Informational -etsLogman manages the "Performance Logs and Alerts" service for creating and managing Event Trace Session logs and Performance logs.PAdebug`d`level`Debug&h`?`*`Displays context sensitive help.6ini`config`*`Settings file containing command options.PA$The command completed successfully.  Error: >You're running with a restricted token, try running elevated. Unknown  Error: 0x%1!08x! valuefilename [[hh:]mm:]ssy6Arguments '%1!s!' and '%2!s!' are mutually exclusive. Argument '%1!s!' is required. 5At least one of the following arguments is required: DArgument '%1!s!' is not allowed with the other arguments specified.  Verbs: Adverbs: Options: Usage: %1!s! [options] Argument '%1!s!' is unknown. #Argument '%1!s!' is not negatable. 2Argument '%1!s!' has been defined too many times. 1Argument '%1!s!' requires additional parameters. p Note: Where [-] is listed, an extra - negates the option. For example --%1!s! turns off the -%1!s! option. Examples:  Options (%1!s!):  More Information: PA2The file "%1!s!" already exists, overwrite? [y/n] 4VS_VERSION_INFO@%@%?StringFileInfo040904B0LCompanyNameMicrosoft CorporationXFileDescriptionPerformance Log Utilityr)FileVersion6.3.9600.16384 (winblue_rtm.130821-1623)6 InternalNameLogman.exe.LegalCopyright Microsoft Corporation. All rights reserved.FOriginalFilenameLogman.exe.muij%ProductNameMicrosoft Windows Operating SystemBProductVersion6.3.9600.16384DVarFileInfo$Translation  <_locDefinition> <_locDefault _loc="locNone"/> <_locTag _loc="locData">label \ : : : : : : : Off On Counter Trace Configuration Alert TimeStamp Performance System Cycle PlaNone PlaFile PlaRealTime PlaBoth PlaBuffering Unknown Stopped Running Compiling Pending Undefined Unknown : PAPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDING