viewer9 documentation

SystemStatistics PML Operation

This event can occur at or near the end of a bootlog capture preceeded by a block of ProcessStatistics events for the processes.

PageSize (not shown in Procmon) is in bytes and is used to calculate CommitPeak.

CommitPeak is in bytes and is calculated by multiplying PageSize by the peak commitment page count at evdata[60] (see PML Binary Data and Results Offsets).

SystemCalls and ContextSwitches are 32-bit integers.

Example from 64-bit PML

Hover over field values like Time, ResultCode, and bytes of evdata in this example to see tooltips as they appear in viewer9. The tooltip of the first byte of a color patch tells the field name.

SystemStatistics opcode=1,9

ev=584534

Time:2021-01-16 17:26:55.2484409
Duration:0.0000000
ResultCode:SUCCESS
Tid:11512
PageSize:4096
CommitPeak:4699230208
SystemCalls:10998901
ContextSwitches:2451607

evdata[0-315] file offset 309970942

000 10 00 00 ec 95 01 31 .......1
800 00 00 00 f8 32 4e 1a .....2N.
1600 00 00 00 90 2a 2d b2 .....*-.
2400 00 00 00 82 a8 b2 01 ........
3200 00 00 00 a6 9e 01 00 ........
40d2 0f 01 00 30 c8 1b 00 ....0...
488a 2a 30 00 f6 0e 11 00 .*0.....
5699 0b 49 00 89 81 11 00 ..I.....
641f 39 2c 00 ab 17 01 00 .9,.....
7226 f6 11 00 00 00 00 00 &.......
8029 90 15 00 8a da 07 00 ).......
8812 5d 01 00 00 00 00 00 .]......
9600 00 00 00 00 00 00 00 ........
10400 00 00 00 bb 00 00 00 ........
11207 00 00 00 f3 9b 00 00 ........
12070 dc 00 00 00 00 00 00 p.......
12800 00 00 00 00 00 00 00 ........
13600 00 00 00 de cc be 00 ........
14402 00 00 00 13 1c 00 00 ........
15202 00 00 00 00 00 00 00 ........
16000 00 00 00 02 2a a5 00 .....*..
168b2 45 00 00 55 90 00 00 .E..U...
176f9 0b 00 00 00 00 00 00 ........
184d6 5e 01 00 00 00 00 00 .^......
19201 00 00 00 00 00 00 00 ........
20000 00 00 00 00 00 00 00 ........
20800 00 00 00 00 00 00 00 ........
216f6 66 0f 00 00 00 00 00 .f......
224c7 26 00 00 e7 da 00 00 .&......
23203 00 00 00 59 f5 00 00 ....Y...
2401f a3 00 00 65 01 00 00 ....e...
24891 02 00 00 16 6b 01 00 .....k..
256b0 01 00 00 7b 77 00 00 .....w..
26400 00 00 00 32 00 00 00 ....2...
27200 00 00 00 00 00 00 00 ........
28003 a3 00 00 f7 0b 00 00 ........
28835 0f 09 00 ba 20 00 00 5.... ..
296f2 4d 09 00 97 68 25 00 .M...h%.
30400 00 00 00 00 00 00 00 ........
31275 d4 a7 00 u...

Call Stack stacksize=22

StackAddressmodModNameModPath
0xfffff8055941393911FLTMGR.SYS + 0x43939C:\WINDOWS\System32\drivers\FLTMGR.SYS
0xfffff805594134ab11FLTMGR.SYS + 0x434abC:\WINDOWS\System32\drivers\FLTMGR.SYS
0xfffff8055940be1311FLTMGR.SYS + 0x3be13C:\WINDOWS\System32\drivers\FLTMGR.SYS
0xfffff8055d252f5513ntoskrnl.exe + 0x252f55C:\WINDOWS\system32\ntoskrnl.exe
0xfffff8055d25454413ntoskrnl.exe + 0x254544C:\WINDOWS\system32\ntoskrnl.exe
0xfffff8055d5fec2d13ntoskrnl.exe + 0x5fec2dC:\WINDOWS\system32\ntoskrnl.exe
0xfffff8055d62751e13ntoskrnl.exe + 0x62751eC:\WINDOWS\system32\ntoskrnl.exe
0xfffff8055d5eb19a13ntoskrnl.exe + 0x5eb19aC:\WINDOWS\system32\ntoskrnl.exe
0xfffff8055d66d14f13ntoskrnl.exe + 0x66d14fC:\WINDOWS\system32\ntoskrnl.exe
0xfffff8055d66cd2913ntoskrnl.exe + 0x66cd29C:\WINDOWS\system32\ntoskrnl.exe
0xfffff8055d4071b513ntoskrnl.exe + 0x4071b5C:\WINDOWS\system32\ntoskrnl.exe
0x7ffa1f32ca54324ntdll.dll + 0x9ca54C:\WINDOWS\SYSTEM32\ntdll.dll
0x7ffa1a3b202f278apphelp.dll + 0x4202fC:\WINDOWS\SYSTEM32\apphelp.dll
0x7ffa092123b8252fltLib.dll + 0x23b8C:\WINDOWS\SYSTEM32\FLTLIB.DLL
0x7ff6c1f31f9d220Procmon64.exe + 0x11f9dC:\Users\Ben\AppData\Local\Programs\SysInternals\Procmon64.exe
0x7ff6c1f62eaa220Procmon64.exe + 0x42eaaC:\Users\Ben\AppData\Local\Programs\SysInternals\Procmon64.exe
0x7ff6c1f64aba220Procmon64.exe + 0x44abaC:\Users\Ben\AppData\Local\Programs\SysInternals\Procmon64.exe
0x7ff6c1f71b39220Procmon64.exe + 0x51b39C:\Users\Ben\AppData\Local\Programs\SysInternals\Procmon64.exe
0x7ff6c1f8e219220Procmon64.exe + 0x6e219C:\Users\Ben\AppData\Local\Programs\SysInternals\Procmon64.exe
0x7ff6c1f9f192220Procmon64.exe + 0x7f192C:\Users\Ben\AppData\Local\Programs\SysInternals\Procmon64.exe
0x7ffa1d8f7034309kernel32.dll + 0x17034C:\WINDOWS\System32\KERNEL32.DLL
0x7ffa1f2dd0d1324ntdll.dll + 0x4d0d1C:\WINDOWS\SYSTEM32\ntdll.dll

SystemStatistics is "System Statistics" with a space in Procmon. And likewise, these corresponding detail field names have spaces in Procmon: Commit Peak, System Calls, Context Switches.

See also

Posted 4 Jul 2022 last updated 15 Nov 2022   As viewer9 is just starting out, discussion is invited via email. Please send questions and comments to forum@viewer9.com directly. Threads that might be valuable to other users will be posted as part of the documentation. Posted messages will not include your address or your full name, and might be shortened for brevity.

Copyright 2022, bryantlite, Inc.