31 строка
2.0 KiB
XML
31 строка
2.0 KiB
XML
<?xml version="1.0"?>
|
||
<!-- Copyright (c) Microsoft Corporation
|
||
SPDX-License-Identifier: MIT
|
||
-->
|
||
<Task version="1.2" xmlns="http://schemas.microsoft.com/windows/2004/02/mit/task">
|
||
<RegistrationInfo>
|
||
<Author>Microsoft Corporation</Author>
|
||
<Description>Sets up eBPF tracing on boot.</Description>
|
||
</RegistrationInfo>
|
||
<Triggers>
|
||
<BootTrigger>
|
||
<Enabled>true</Enabled>
|
||
</BootTrigger>
|
||
<RegistrationTrigger>
|
||
<Enabled>true</Enabled>
|
||
</RegistrationTrigger>
|
||
</Triggers>
|
||
<Principals>
|
||
<Principal id="Author">
|
||
<!-- SECURITY_LOCAL_SYSTEM_RID (S-1-5-18) -->
|
||
<UserId>S-1-5-18</UserId>
|
||
<RunLevel>HighestAvailable</RunLevel>
|
||
</Principal>
|
||
</Principals>
|
||
<Actions Context="Author">
|
||
<Exec>
|
||
<Command>%comspec%</Command>
|
||
<Arguments>/c ""%ProgramFiles%\ebpf-for-windows\ebpf_tracing.cmd" start /trace_name ebpf_diag /trace_path "%SystemRoot%\Logs\eBPF" /rundown_period 0:35:00 /max_file_size_mb 20"</Arguments>
|
||
</Exec>
|
||
</Actions>
|
||
</Task> |