wevtapi.dll

wevtapi.dll — PE metadata by version
NT 6.0 x86NT 6.1 x64NT 6.3 x86NT 10.0 x64NT 10.0 x64
FileVersion6.0.6002.18005 (lh_sp2rtm.090410-1830)6.1.7600.16385 (win7_rtm.090713-1255)6.3.9600.16384 (winblue_rtm.130821-1623)10.0.19041.3636 (WinBuild.160101.0800)10.0.26100.7309 (WinBuild.160101.0800)
FileDescriptionEventing Consumption and Configuration APIEventing Consumption and Configuration APIEventing Consumption and Configuration APIEventing Consumption and Configuration APIEventing Consumption and Configuration API

Export nameNT 6.0 x86NT 6.1 x64NT 6.3 x86NT 10.0 x64NT 10.0 x64
EvtArchiveExportedLog33322
EvtCancel44433
EvtClearLog55544
EvtClose66655
EvtCreateBookmark77766
EvtCreateRenderContext88877
EvtExportLog99988
EvtFormatMessage10101099
EvtGetChannelConfigProperty1111111010
EvtGetEventInfo1212121111
EvtGetEventMetadataProperty1313131212
EvtGetExtendedStatus1414141313
EvtGetLogInfo1515151414
EvtGetObjectArrayProperty1616161515
EvtGetObjectArraySize1717171616
EvtGetPublisherMetadataProperty1818181717
EvtGetQueryInfo1919191818
EvtIntAssertConfig2020201919
EvtIntCreateBinXMLFromCustomXML21212020
EvtIntCreateLocalLogfile2122222121
EvtIntGetClassicLogDisplayName2223232222
EvtIntRenderResourceEventTemplate2324242323
EvtIntReportAuthzEventAndSourceAsync24→ 25→ 25→ 24→ 24
EvtIntReportEventAndSourceAsync25→ 26→ 26→ 25→ 25
EvtIntRetractConfig2627272626
EvtIntSysprepCleanup11111
EvtIntWriteXmlEventToLocalLogfile2728282727
EvtNext2829292828
EvtNextChannelPath2930302929
EvtNextEventMetadata3031313030
EvtNextPublisherId3132323131
EvtOpenChannelConfig3233333232
EvtOpenChannelEnum3334343333
EvtOpenEventMetadataEnum3435353434
EvtOpenLog3536363535
EvtOpenPublisherEnum3637373636
EvtOpenPublisherMetadata3738383737
EvtOpenSession3839393838
EvtQuery3940403939
EvtRender4041414040
EvtSaveChannelConfig4142424141
EvtSeek4243434242
EvtSetChannelConfigProperty4344444343
EvtSetObjectArrayProperty222
EvtSubscribe4445454444
EvtUpdateBookmark4546464545

Ordinal numbers are shown per version. → indicates a forwarder export (hover for target). Functions absent from a version are shown as blank.