| Previous | Next |
| UTC_E_INVALID_CUSTOM_FILTER | UTC_E_REESCALATED_TOO_QUICKLY |
UTC_E_TRACE_NOT_RUNNING
Map the code to the scenario graph: trace-session lookup
UTC_E_TRACE_NOT_RUNNING (0x87C5100D) is a Universal Telemetry Client result from the ETW trace-session control layer. A reliable investigation preserves the producing action before any cleanup runs. The relevant state is trace-session lookup: a stop, update, flush or collection action could not find the expected running trace. This identifies a specific UTC/DiagTrack condition, not a general service failure.
The Universal Telemetry Client controls ETW sessions on behalf of diagnostic scenarios. ETW sessions have controller-owned names, in-memory buffers, providers, logging modes and lifetimes; a status at this layer should be correlated with the actual session list rather than inferred from the presence of an ETL file.
Data needed for triage
| UTC diagnostic field | Value |
|---|---|
| Producing layer | ETW trace-session control |
| Owning state or object | trace-session lookup |
| Evidence to collect | expected session name/GUID, ETW session enumeration, controller lifetime, prior stop result and service restart history |
| Narrow comparison | start the named profile, verify it in the session list, and repeat the exact operation |
| Do not confuse with | UTC_E_AOT_NOT_RUNNING is specific to the always-on trace |
Reproduce without collateral changes
- Capture expected session name/GUID, ETW session enumeration, controller lifetime, prior stop result and service restart history. Do this before restarting the service or deleting any working directory.
- Perform this one-variable comparison: start the named profile, verify it in the session list, and repeat the exact operation.
Nearby result: UTC_E_AOT_NOT_RUNNING — is specific to the always-on trace.
Trace-session note
Use an ETW controller view to list session name, GUID, mode, buffers and enabled providers while this result is active. The presence of an ETL file from an earlier run is not proof that the required in-memory session currently exists or is owned by UTC.
Fix the contract
Fix session ownership and ordering; never treat an unrelated ETW session as the missing trace.
Technical references
- Microsoft Open Specifications: Windows error-code registry — reference for ETW trace-session control while interpreting this result.
- Microsoft: Universal Telemetry Client configuration diagnosis — reference for ETW trace-session control while interpreting it.
- Microsoft: Event Tracing for Windows
- Microsoft: WPR and ETW sessions
Looking for a different code? Search another status or error code.