Notice: This website is an unofficial Microsoft Knowledge Base (hereinafter KB) archive and is intended to provide a reliable access to deleted content from Microsoft KB. All KB articles are owned by Microsoft Corporation. Read full disclaimer for more details.

The computer quits when you enable an Event Tracing for Windows trace session in Windows Server 2003, in Windows XP, or in Windows 2000


View products that this article applies to.

Symptoms

In Microsoft Windows Server 2003, in Microsoft Windows XP, or in Microsoft Windows 2000, the computer quits (crashes) when you enable an Event Tracing for Windows (ETW) trace session. This issue occurs when you configure the trace session to use a buffer that is more than 4 kilobytes (KB).

↑ Back to the top


Cause

The kernel debugger has a buffer limit of 4 KB. This issue occurs if you use a buffer that is more than 4 KB and you have the KD filter mode enabled when you start the ETW trace session. The computer quits because the kernel debugger (KD) tries to write beyond the kernel debugger's allocated memory.

↑ Back to the top


Workaround

To work around this issue, you can change the buffer size. Use a buffer that is less than 4KB when you start the ETW trace session.

↑ Back to the top


Keywords: kbtshoot, kbprb, KB897125

↑ Back to the top

Article Info
Article ID : 897125
Revision : 1
Created on : 7/20/2005
Published on : 7/20/2005
Exists online : False
Views : 452