| Previous | Next |
| UTC_E_SCRIPT_TERMINATED | UTC_E_TRACE_NOT_RUNNING |
UTC_E_INVALID_CUSTOM_FILTER
Separate cause from final symptom: ToggleTraceWithCustomFilterAction filter
UTC_E_INVALID_CUSTOM_FILTER has the unsigned value 0x87C5100C. In UTC it comes from scenario filter parser and evaluator, where ToggleTraceWithCustomFilterAction filter owns the decision. The first diagnostic step is to separate configuration, policy and runtime state. The immediate contract failed because the custom filter attached to a trace-toggle action failed validation before it could control providers, so diagnosis should remain at that boundary until a controlled comparison crosses it.
UTC filters are typed programs, not plain text searches. Parsing, command validation, name lookup, signature binding and evaluation are distinct phases. Capturing the normalized expression and inferred operand types is essential for a useful diagnosis.
High-value observations
| UTC diagnostic field | Value |
|---|---|
| Owning state or object | ToggleTraceWithCustomFilterAction filter |
| Producing layer | scenario filter parser and evaluator |
| Do not confuse with | UTC_E_INVALID_FILTER refers to a scenario filter that can never be satisfied |
| Evidence to collect | complete filter expression, declared variables, function names, types, schema version and profile ID |
| Narrow comparison | start the same trace without the custom filter, then add clauses one at a time |
A focused experiment
- Associate this result with one request, one scenario version and one service process ID.
- Save complete filter expression, declared variables, function names, types, schema version and profile ID and the first lower-level HRESULT if one exists.
- Change no policy, provider set or destination except for this test: start the same trace without the custom filter, then add clauses one at a time.
- Compare the produced artifacts and operational events, not only the top-level return value.
Nearby result: UTC_E_INVALID_FILTER — refers to a scenario filter that can never be satisfied.
Typed-filter note
Save the filter after variable substitution and type inference, not only the authoring XML. A visually plausible expression can still fail because the runtime command table, scope or operand types differ from the authoring tool. Test with one synthetic event whose fields and types are known exactly.
Recovery criteria
Correct the filter grammar and types instead of changing ETW providers or buffer counts.
Technical references
- Microsoft Open Specifications: Windows error-code registry — reference for scenario filter parser and evaluator while interpreting this result.
- Microsoft: Universal Telemetry Client configuration diagnosis — reference for scenario filter parser and evaluator while interpreting it.
- Microsoft: Windows Event Log query schema
- Microsoft: Querying Windows Event Log
Looking for a different code? Search another status or error code.
