{"id":1938,"date":"2017-01-03T00:38:14","date_gmt":"2017-01-02T23:38:14","guid":{"rendered":"http:\/\/borncity.com\/win\/?p=1938"},"modified":"2022-06-23T20:58:12","modified_gmt":"2022-06-23T18:58:12","slug":"process-monitor-how-to-enable-windows-10-boot-logging","status":"publish","type":"post","link":"https:\/\/borncity.com\/win\/2017\/01\/03\/process-monitor-how-to-enable-windows-10-boot-logging\/","title":{"rendered":"Process Monitor: How to enable Windows 10 boot logging"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" style=\"float: left; margin: 0px 10px 0px 0px; display: inline\" src=\"http:\/\/www.borncity.com\/blog\/wp-content\/uploads\/2015\/01\/win102.jpg\" width=\"58\" align=\"left\" height=\"58\">Recently I stumbled upon an error: In Windows 10 I wasn't able to use Sysinternals Process Monitor for boot logging. The feature just dropped an error message. Here are the details and a how to cure this issue and enable boot logging.<\/p>\n<p><!--more--><\/p>\n<h3>What we are talking about?<img loading=\"lazy\" decoding=\"async\" alt=\"\" src=\"https:\/\/ssl-vg03.met.vgwort.de\/na\/10350d8d524d4c73a020a806fdef68a6\" width=\"1\" height=\"1\"><\/h3>\n<p>Currently I'm writing a book about Windows 10 insides \u2013 and within a chapter I intended to introduce boot logging with Sysinternals <a href=\"https:\/\/technet.microsoft.com\/en-US\/sysinternals\/processmonitor.aspx?f=255&amp;MSPPError=-2147217396\" target=\"_blank\" rel=\"noopener\">Process Monitor<\/a>. In previous Windows version it was possible, to launch Process Monitor, open <em>Options<\/em> menu and select <em>Enable Boot Logging <\/em>(see screenshot below).<\/p>\n<p><img decoding=\"async\" title=\"Boot logging in Process Monitor\" alt=\"Boot logging in Process Monitor\" src=\"https:\/\/web.archive.org\/web\/20170905090358\/http:\/\/v40.imgup.net\/ProcessMone46e.jpg\"><\/p>\n<p>But in Windows 10 I was greeted with the following error dialog box. I've tested Windows 10 Version 1607, but it seems that all Windows 10 versions are causing this error.<\/p>\n<p><img decoding=\"async\" title=\"Error in Process Monitor\" alt=\"Error in Process Monitor\" src=\"https:\/\/web.archive.org\/web\/20170905085927\/http:\/\/l65.imgup.net\/ProcessMonb599.jpg\"><\/p>\n<p>The dialog box reporting, that Process Monitor was not able to write to a file <em>ProcMon23.sys<\/em>. I checked Windows 7, but this file wasn't available. Then I checked Windows 10 and I found such a file. <\/p>\n<h3>How to solve this issue<\/h3>\n<p>Searching the web, I came across this MSDN article (link broken), where deleting this file in Windows PE was suggested. I tried a different approach (never believe, what Microsoft writes): I fired up Windows explorer and navigated to <\/p>\n<p><em>%SystemRoot%\\System32\\Drivers\\<\/em><\/p>\n<p>and found a file <em>PROCMON23.sys<\/em>. Then I tried to rename this file to <em>_PROCMON23.sys<\/em>. It required administrator privileges, but I was able to process this renaming operation successfully. Microsoft's MSDN article also requires to launch Process Monitor using a command:<\/p>\n<p><em>C:\\procmon\\Procmon \/BackingFile C:\\procmon\\log.pml \/AcceptEula \/Quiet \/noconnect<\/em><\/p>\n<p>I also ignored this advice and launched Process Explorer via a double click. And voil\u00e1, it came up with the window shown above \u2013 and I was able to enable the boot logging option. Inspecting the folder <em>%SystemRoot%\\System32\\Drivers\\ <\/em>showed me, that a new file <em>PROCMON23.sys <\/em>was created \u2013 beside the old file <em>_PROCMON23.sys<\/em>. <\/p>\n<p><strong>Similar articles:<br \/><\/strong><a href=\"https:\/\/borncity.com\/win\/win10-wiki\/\">Windows 10 Wiki<\/a><br \/><a href=\"https:\/\/web.archive.org\/web\/20210512202711\/https:\/\/borncity.com\/win\/2016\/07\/06\/windows10-open-command-prompt-window-as-administrator\/\">Windows 10: Open command prompt window as administrator<\/a><br \/><a href=\"https:\/\/borncity.com\/win\/2016\/07\/08\/check-and-repair-windows-system-files-and-component-store\/\">Check and repair Windows system files and component store<\/a><br \/><a href=\"https:\/\/borncity.com\/win\/2017\/01\/02\/windows-10-update-error-0x80080008\/\">Windows 10: How to fix update error 0x80080008<\/a><br \/><a href=\"https:\/\/borncity.com\/win\/2016\/12\/31\/how-to-block-windows-10-updates\/\">How to block Windows 10 updates<\/a><br \/><a href=\"https:\/\/borncity.com\/win\/2016\/12\/30\/windows-10-hibernation-causes-error-0xc0000411\/\">Windows 10: Hibernation causes error 0xC0000411<\/a><br \/><a href=\"https:\/\/borncity.com\/win\/2016\/12\/29\/windows-78-1-optional-intel-system-driver-updates\/\">Windows 7\/8.1: Optional INTEL System driver updates<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Recently I stumbled upon an error: In Windows 10 I wasn't able to use Sysinternals Process Monitor for boot logging. The feature just dropped an error message. Here are the details and a how to cure this issue and enable &hellip; <a href=\"https:\/\/borncity.com\/win\/2017\/01\/03\/process-monitor-how-to-enable-windows-10-boot-logging\/\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[463,2],"tags":[606,47,605,607,76],"class_list":["post-1938","post","type-post","status-publish","format-standard","hentry","category-issue","category-windows","tag-boot-logging","tag-issue","tag-process-monitor","tag-procmon23-sys","tag-windows-10"],"_links":{"self":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/1938","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/comments?post=1938"}],"version-history":[{"count":0,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/1938\/revisions"}],"wp:attachment":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/media?parent=1938"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/categories?post=1938"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/tags?post=1938"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}