Process Monitor is an excellent diagnostic tool from Microsoft Sysinternals. It can run a trace during the current Windows session or trace the boot process. Let’s see how to enable boot tracing using Process Monitor.
Enable Boot Logging using Process Monitor
- Download Process Monitor and run it.
- Read and accept the license agreement.
- If the “Filtering Options” dialog appears, dismiss the dialog by pressing Cancel.
- From the Options menu, click “Enable Boot Logging” to enable it.
- Enable “Generate threat profiling events”, choose “Every second”, and click OK.
- Close Process Monitor by clicking File, and clicking Exit.
- Save your work and close all programs that are currently running.
- Right-click Start, click “Shut down or sign out”, and click “Restart”.
- Process Monitor will trace the next boot and write the events to a log file. After entering Windows, reopen Process Monitor.
Note: If you need to reproduce and record a problem after logging in, do so before opening Process Monitor.
- Click “Yes” when you see the following message:
“A log of boot-time activity was created by a previous instance of Process Monitor. Do you wish to save the collected data now?”
- Save the PML boot log in a folder. The default file name is Bootlog.PML.
Note: If the trace size is enormous, Process Monitor saves the trace information into multiple logs, such as Bootlog-1.PML, Bootlog-2.PML, etc.
- The PML trace log will be huge, usually in gigabytes. If you’re going to send the file to someone or share it on the cloud, be sure to zip it. To zip the log(s), select the file(s), right-click, select Send to, and select “Compressed (zipped) folder” from the Send To menu.
- Zipping the log(s) reduces the file size by a whopping 90%.
That’s it.
Related article
Using Process Monitor to Track Registry and File System Changes
One small request: If you liked this post, please share this?
One "tiny" share from you would seriously help a lot with the growth of this blog. Some great suggestions:- Pin it!
- Share it to your favorite blog + Facebook, Reddit
- Tweet it!