Site icon EfmSoft

What does HRESULT 0x87C5100C (UTC_E_INVALID_CUSTOM_FILTER) mean?

 
Previous Next
UTC_E_SCRIPT_TERMINATED UTC_E_TRACE_NOT_RUNNING

UTC_E_INVALID_CUSTOM_FILTER

Separate cause from final symptom: ToggleTraceWithCustomFilterAction filter

UTC_E_INVALID_CUSTOM_FILTER has the unsigned value 0x87C5100C. In UTC it comes from scenario filter parser and evaluator, where ToggleTraceWithCustomFilterAction filter owns the decision. The first diagnostic step is to separate configuration, policy and runtime state. The immediate contract failed because the custom filter attached to a trace-toggle action failed validation before it could control providers, so diagnosis should remain at that boundary until a controlled comparison crosses it.

UTC filters are typed programs, not plain text searches. Parsing, command validation, name lookup, signature binding and evaluation are distinct phases. Capturing the normalized expression and inferred operand types is essential for a useful diagnosis.

High-value observations

UTC diagnostic fieldValue
Owning state or objectToggleTraceWithCustomFilterAction filter
Producing layerscenario filter parser and evaluator
Do not confuse withUTC_E_INVALID_FILTER refers to a scenario filter that can never be satisfied
Evidence to collectcomplete filter expression, declared variables, function names, types, schema version and profile ID
Narrow comparisonstart the same trace without the custom filter, then add clauses one at a time

A focused experiment

  1. Associate this result with one request, one scenario version and one service process ID.
  2. Save complete filter expression, declared variables, function names, types, schema version and profile ID and the first lower-level HRESULT if one exists.
  3. Change no policy, provider set or destination except for this test: start the same trace without the custom filter, then add clauses one at a time.
  4. Compare the produced artifacts and operational events, not only the top-level return value.

Nearby result: UTC_E_INVALID_FILTER — refers to a scenario filter that can never be satisfied.

Typed-filter note

Save the filter after variable substitution and type inference, not only the authoring XML. A visually plausible expression can still fail because the runtime command table, scope or operand types differ from the authoring tool. Test with one synthetic event whose fields and types are known exactly.

Recovery criteria

Correct the filter grammar and types instead of changing ETW providers or buffer counts.

Technical references


Looking for a different code? Search another status or error code.

Exit mobile version