Skip to content

Windows Application Data Collection

The Windows documentation covers three data capabilities: RUM, Log, and HTTP Trace. .NET/C#, Native C/C++, WebView2, and the Electron Native Bridge share the same Windows SDK product identity. Browser RUM in the Electron Renderer is only responsible for collection and serialization. Trusted fields and the Session are managed uniformly by the Main Process adapter layer and the Windows Native Core, while queuing and upload are handled by the Native Core.

Data Types

Data Domain Purpose Reporting Behavior
RUM Records Session, View, Action, Resource, Error, and Long Task Written to the RUM queue and reported to the RUM Intake
Log Records application logs and can be correlated with the current RUM context Written to a separate Log queue and reported to the Logging Intake
HTTP Trace Injects Trace headers into outbound requests and can be correlated with the corresponding RUM Resource APM spans are not reported independently

Global Attributes

Field Type Description
app_id string The application ID created in the console.
service string GuanceConfig.ServiceName for .NET, guance_sdk_config.service_name for Native, or the Electron native configuration.
env string prod, gray, pre, common, or local.
version string Application version.
sdk_name string Fixed as df_windows_rum_sdk for Windows .NET, Native Core, WebView2, and the Electron Native Bridge.
sdk_version string The version of the current Windows SDK assembly or Native Core. The Electron Adapter must pass the Native SDK version shipped with the application; the business application version cannot be used instead.
application_uuid string Identifier of the current application installation instance.
session_id string Identifier of the current user Session.
session_type string Fixed as user for the Windows SDK.
session_has_replay boolean Whether the current Session has produced uploadable Replay data.
session_sample_rate number Current sampling rate for regular Sessions.
session_on_error_sample_rate number Additional sampling rate for Error Sessions.
view_id string Identifier of the currently active View.
action_id string Identifier of the currently active Action; written when present.
userid string Anonymous user identifier persisted per RUM application ID, or the user ID set through the user API.
user_name, user_email string Written after being set through the user API.
is_signin string T when a user has been set; otherwise F.
os, os_version string Windows name and version.
os_version_major string Windows major version.
device, model string Windows device and model information; written when available.
arch string Architecture of the device where the process runs.
screen_size string Primary display size recorded when available.
locale string Current locale setting.
network_type string wifi, ethernet, mobile, none, or unknown.

Custom context only supplements fields that do not exist; it cannot override SDK reserved fields.

Attributes of Other Data Types

A Session is a user access process aggregated by the console from events under the same session_id. There is no need to call a separate Session API.

Type Description Typical Sources
View Visibility period and performance of a window or business page Window/Form lifecycle, WinUI 3 explicit association, Native window events, WebView2 navigation
Action User operations and their duration Click, menu, selection, switching, input, shortcuts, or manual Action
Resource Network request, status, and duration HttpClient, WinHTTP, WebView2 Fetch/XHR/Resource, or manual Resource
Error Application and page errors Unhandled .NET exceptions, Native crash recovery, WebView2 JavaScript Error, or manual Error
Long Task Long blocking of the UI main thread Windows UI thread detection or manual Long Task

View

Field Type Description
view_id string Unique identifier of the View.
view_name string Window, page, or business View name.
view_referrer string Name of the previous View.
time_spent integer View duration in nanoseconds.
is_active boolean Whether the View is still active at reporting time.
view_action_count integer Number of Actions generated in the View.
view_resource_count integer Number of Resources generated in the View.
view_error_count integer Number of Errors generated in the View.
view_long_task_count integer Number of Long Tasks generated in the View.
view_update_time integer Unix nanosecond timestamp of this View update.

Action

Field Type Description
action_id string Unique identifier of the Action.
action_name string Control, command, or business action name.
action_type string For example, click, key, launch_cold, or launch_hot.
duration integer Action duration in nanoseconds.
action_resource_count integer Number of Resources within the Action scope.
action_error_count integer Number of Errors within the Action scope.
action_long_task_count integer Number of Long Tasks within the Action scope.
app_pre_application_init_time integer For launch Actions, time spent before application code runs.
app_application_init_time integer For launch Actions, time spent in the application initialization phase.
app_first_frame_init_time integer For launch Actions, time spent in the first-frame phase.

Resource

Field Type Description
resource_id string Unique identifier of the Resource.
resource_url string Request URL after privacy policy processing.
resource_url_host string Request hostname.
resource_url_path string Request path.
resource_url_path_group string Normalized path group.
resource_method string HTTP method.
resource_status integer HTTP status code; no valid status is written when no response is received.
resource_status_group string Status code group, for example 2xx.
resource_type string http, native, or a resource type passed in by the application.
duration integer Total Resource duration in nanoseconds.
resource_size integer Response body size in bytes; written when available.
resource_request_size integer Request body size in bytes; written when available.
resource_dns, resource_tcp, resource_ssl, resource_ttfb integer Network phase durations in nanoseconds; written when reliably available.
resource_http_protocol string HTTP protocol version.
trace_id, span_id string Written after Trace and RUM correlation is enabled.
request_header, response_header string Header snapshots written only when permitted by the privacy configuration.
network_instrumentation, network_library string Automatic collection entry point and the identified network library.

Phase durations also mark the source and precision through resource_timing_source, resource_timing_precision, resource_timing_duration, resource_timing_phase, and resource_ttfb_estimated. When no reliable phase data is available, the SDK records only the total duration.

Error

Field Type Description
error_type string Automatic collection uses the standard types in the table below; manual Errors use the type passed in by the application.
error_source string logger for crashes and application exceptions, network for network errors, and webview for WebView2 page errors.
error_situation string run indicates during runtime; Native crashes recovered at the next startup are startup.
error_message string Error summary; for crashes, diagnostic information such as exception type, exception code, or address is included.
error_stack string Full exception or call stack; when a complete Native call stack is unavailable, at least the instruction address is recorded.

Automatically Collected Types

Scenario error_type error_source Description
.NET unhandled exception terminating the process windows_crash logger error_message contains the full exception type and message, and error_stack contains Exception.ToString().
Unhandled SEH or C++ std::terminate native_crash logger Crash information is safely persisted to disk and recovered at the next startup; the exception code, address, or std::terminate information is written to error_message.
Native UI Watchdog detects an unresponsive application anr_error logger Reported after the application becomes responsive again; the duration is written to error_message.
HttpClient request exception, or an automatic Resource returns HTTP 4xx/5xx network_error network The Error is correlated with the corresponding Resource and carries its URL, method, and status information.
WebView2 JavaScript Error Error.name of the JavaScript error, or JavaScriptError when missing webview error_message and error_stack come from the page exception.
Unhandled WebView2 Promise rejection name of the rejection, or UnhandledPromiseRejection when missing webview error_message and error_stack come from the rejection reason.
WebView2 navigation failure WebView2NavigationError webview error_message contains the navigation failure status.
WebView2 process failure WebView2ProcessFailed webview error_message contains the process failure type or reason.

Unobserved Task exceptions and UI thread exceptions caught by WinForms that allow the application to continue running are not crashes; error_type uses the corresponding .NET exception type and error_source is logger. Exception classification and diagnostic details are consistently reflected in error_type, error_message, and error_stack.

Long Task

Field Type Description
duration integer Long Task duration in nanoseconds.
long_task_stack string Call stack recorded when available.
long_task_source string Automatic or manual collection source.
long_task_delay integer Blocking delay detected on the UI thread.
long_task_threshold integer Effective Long Task threshold.
long_task_cooldown integer Cooldown time for consecutive blocking reports.
long_task_suppressed_count integer Number of duplicate reports merged during the cooldown period.

RUM Capability Matrix

Integration Method View Action Resource Error Long Task
WPF Automatic Automatic HttpClient Unhandled exceptions UI thread monitoring
WinForms Automatic Automatic HttpClient Unhandled exceptions UI thread monitoring
WinUI 3 Automatic after window association Automatic HttpClient Unhandled exceptions UI thread monitoring
Native C/C++ Explicit integration via window events Explicit integration via messages or commands WinHTTP adapter or manual API Crash recovery or manual API HWND Watchdog or manual API
WebView2 Page navigation Page interactions Fetch/XHR/Resource JavaScript Error Renderer Long Tasks are not collected
Electron Native Bridge Browser RUM Browser RUM Browser RUM Browser RUM + Main Process events Browser RUM; Renderer unresponsiveness is reported by the Main Process

The Native SDK does not install process-level Detour hooks. The application must explicitly pass in HWND, WinHTTP handles, or business lifecycle events. For integration methods, see Desktop UI Frameworks and Manual RUM Instrumentation.

Log Capability Matrix

Integration Method Custom Log Batch Log Automatic Log Sources RUM Correlation
.NET / C# GuanceSdk.AddLog() GuanceSdk.AddLogs() Can collect System.Diagnostics.Trace Configurable
Native C/C++ guance_log_add() guance_log_add_batch() Console, ETW, and third-party logging libraries are not intercepted at present Configurable
WebView2 Written by the Windows host Written by the Windows host Page Console is not automatically bridged Uses the host's current RUM context
Electron Native Bridge Browser Logs API Converted by the Browser Logs Adapter Console, page errors, or custom scopes are configured by Browser Logs Uses the Native Session, View, and Action context

Log uses a separate queue. When RUM correlation is enabled, the session_id, view_id, and action_id at the time the log is written are reported together with the Log; logs already enqueued are not modified by later context changes.

The core fields of a Log are message and status. It also carries service, env, version, SDK, application, device, and user fields; when RUM correlation is enabled, it further carries session_id, view_id, action_id, and the corresponding names. GlobalContext, user extension attributes, and event-level Properties are written as custom tags but cannot override SDK reserved fields.

Trace Capability Matrix

Integration Method Automatic Boundary Manual Context RUM Resource Correlation Standalone Span Reporting
.NET / C# HttpClient diagnostic subscription or RumHttpMessageHandler ContextProvider Configurable Not supported
Native C/C++ guance_rum_winhttp.hpp guance_trace_create_context() or a callback Configurable Not supported
WebView2 Page requests are handled by the WebView2/Browser side Managed by the page SDK Page Resources are bridged Not uploaded by the Windows SDK
Electron Native Bridge Browser RUM SDK Browser RUM SDK Resources are written to the Native RUM queue through the Bridge Not supported

HTTP Trace generates or passes through request headers and can write trace_id and span_id to the corresponding RUM Resource. For complete APM spans, the application still needs to use a separate APM Tracer. For the specific formats and target filtering, see Trace Configuration.

Data Correlation

  • The five RUM data types share the current session_id.
  • Action, Resource, Error, and Long Task are correlated with the current view_id.
  • Resources, Errors, and Long Tasks generated within an Action's scope are correlated with the corresponding action_id.
  • Starting a new View ends the previous active View.
  • User information updates affect only subsequent data and do not modify historical data.
  • Whether Log and HTTP Trace are correlated with RUM is controlled by their respective EnableLinkRumData or enable_link_rum_data.

Resource Timing

Automatic HttpClient Resources record the total duration by default and mark the timing precision. DNS, TCP, TLS, and TTFB phases can be supplemented through HttpResourceTimingProvider or RumResourceTiming.FromPhases().

The Native WinHTTP adapter records request start, end, status, byte counts, and Trace correlation information. When the application does not have reliable phase timings, it should not estimate or fabricate these fields.

Data Privacy

For how Resource URL query parameters, HTTP headers, Trace targets, and Log attributes are handled, see Privacy and Permissions. User, custom context, and manual event attributes must be sanitized for business privacy by the application before they are written.

Feedback

Is this page helpful?