Fetching directory, one moment please ...
An event tracing controller
tracelog starts and stops tracing sessions, lists trace providers and specifies or excludes trace providers to be used in a session. Trace logs record all system events captured by trace providers. Output is huge.
This utility supports a bewildering array of commands and options to control trace sessions. These are documented at MSDN. An example of the command issued to capture default providers plus Deferred Procedure Calls and Remote Procedure Calls is:
tracelog -start -f
The tracing session will run until stopped with:
|Diagnostic Target:||OS - System Tracing|
|Obtain From:||Windows Driver kit Download|