Windows Application Data Collection¶
The Windows documentation covers three data capabilities: RUM, Log, and HTTP Trace. .NET/C#, Native C/C++, WebView2, and the Electron Native Bridge share the same Windows SDK product identity. Browser RUM in the Electron Renderer is only responsible for collection and serialization. Trusted fields and the Session are managed uniformly by the Main Process adapter layer and the Windows Native Core, while queuing and upload are handled by the Native Core.
Data Types¶
| Data Domain | Purpose | Reporting Behavior |
|---|---|---|
| RUM | Records Session, View, Action, Resource, Error, and Long Task | Written to the RUM queue and reported to the RUM Intake |
| Log | Records application logs and can be correlated with the current RUM context | Written to a separate Log queue and reported to the Logging Intake |
| HTTP Trace | Injects Trace headers into outbound requests and can be correlated with the corresponding RUM Resource | APM spans are not reported independently |
Global Attributes¶
| Field | Type | Description |
|---|---|---|
app_id |
string | The application ID created in the console. |
service |
string | GuanceConfig.ServiceName for .NET, guance_sdk_config.service_name for Native, or the Electron native configuration. |
env |
string | prod, gray, pre, common, or local. |
version |
string | Application version. |
sdk_name |
string | Fixed as df_windows_rum_sdk for Windows .NET, Native Core, WebView2, and the Electron Native Bridge. |
sdk_version |
string | The version of the current Windows SDK assembly or Native Core. The Electron Adapter must pass the Native SDK version shipped with the application; the business application version cannot be used instead. |
application_uuid |
string | Identifier of the current application installation instance. |
session_id |
string | Identifier of the current user Session. |
session_type |
string | Fixed as user for the Windows SDK. |
session_has_replay |
boolean | Whether the current Session has produced uploadable Replay data. |
session_sample_rate |
number | Current sampling rate for regular Sessions. |
session_on_error_sample_rate |
number | Additional sampling rate for Error Sessions. |
view_id |
string | Identifier of the currently active View. |
action_id |
string | Identifier of the currently active Action; written when present. |
userid |
string | Anonymous user identifier persisted per RUM application ID, or the user ID set through the user API. |
user_name, user_email |
string | Written after being set through the user API. |
is_signin |
string | T when a user has been set; otherwise F. |
os, os_version |
string | Windows name and version. |
os_version_major |
string | Windows major version. |
device, model |
string | Windows device and model information; written when available. |
arch |
string | Architecture of the device where the process runs. |
screen_size |
string | Primary display size recorded when available. |
locale |
string | Current locale setting. |
network_type |
string | wifi, ethernet, mobile, none, or unknown. |
Custom context only supplements fields that do not exist; it cannot override SDK reserved fields.
Attributes of Other Data Types¶
A Session is a user access process aggregated by the console from events under the same session_id. There is no need to call a separate Session API.
| Type | Description | Typical Sources |
|---|---|---|
| View | Visibility period and performance of a window or business page | Window/Form lifecycle, WinUI 3 explicit association, Native window events, WebView2 navigation |
| Action | User operations and their duration | Click, menu, selection, switching, input, shortcuts, or manual Action |
| Resource | Network request, status, and duration | HttpClient, WinHTTP, WebView2 Fetch/XHR/Resource, or manual Resource |
| Error | Application and page errors | Unhandled .NET exceptions, Native crash recovery, WebView2 JavaScript Error, or manual Error |
| Long Task | Long blocking of the UI main thread | Windows UI thread detection or manual Long Task |
View¶
| Field | Type | Description |
|---|---|---|
view_id |
string | Unique identifier of the View. |
view_name |
string | Window, page, or business View name. |
view_referrer |
string | Name of the previous View. |
time_spent |
integer | View duration in nanoseconds. |
is_active |
boolean | Whether the View is still active at reporting time. |
view_action_count |
integer | Number of Actions generated in the View. |
view_resource_count |
integer | Number of Resources generated in the View. |
view_error_count |
integer | Number of Errors generated in the View. |
view_long_task_count |
integer | Number of Long Tasks generated in the View. |
view_update_time |
integer | Unix nanosecond timestamp of this View update. |
Action¶
| Field | Type | Description |
|---|---|---|
action_id |
string | Unique identifier of the Action. |
action_name |
string | Control, command, or business action name. |
action_type |
string | For example, click, key, launch_cold, or launch_hot. |
duration |
integer | Action duration in nanoseconds. |
action_resource_count |
integer | Number of Resources within the Action scope. |
action_error_count |
integer | Number of Errors within the Action scope. |
action_long_task_count |
integer | Number of Long Tasks within the Action scope. |
app_pre_application_init_time |
integer | For launch Actions, time spent before application code runs. |
app_application_init_time |
integer | For launch Actions, time spent in the application initialization phase. |
app_first_frame_init_time |
integer | For launch Actions, time spent in the first-frame phase. |
Resource¶
| Field | Type | Description |
|---|---|---|
resource_id |
string | Unique identifier of the Resource. |
resource_url |
string | Request URL after privacy policy processing. |
resource_url_host |
string | Request hostname. |
resource_url_path |
string | Request path. |
resource_url_path_group |
string | Normalized path group. |
resource_method |
string | HTTP method. |
resource_status |
integer | HTTP status code; no valid status is written when no response is received. |
resource_status_group |
string | Status code group, for example 2xx. |
resource_type |
string | http, native, or a resource type passed in by the application. |
duration |
integer | Total Resource duration in nanoseconds. |
resource_size |
integer | Response body size in bytes; written when available. |
resource_request_size |
integer | Request body size in bytes; written when available. |
resource_dns, resource_tcp, resource_ssl, resource_ttfb |
integer | Network phase durations in nanoseconds; written when reliably available. |
resource_http_protocol |
string | HTTP protocol version. |
trace_id, span_id |
string | Written after Trace and RUM correlation is enabled. |
request_header, response_header |
string | Header snapshots written only when permitted by the privacy configuration. |
network_instrumentation, network_library |
string | Automatic collection entry point and the identified network library. |
Phase durations also mark the source and precision through resource_timing_source, resource_timing_precision, resource_timing_duration, resource_timing_phase, and resource_ttfb_estimated. When no reliable phase data is available, the SDK records only the total duration.
Error¶
| Field | Type | Description |
|---|---|---|
error_type |
string | Automatic collection uses the standard types in the table below; manual Errors use the type passed in by the application. |
error_source |
string | logger for crashes and application exceptions, network for network errors, and webview for WebView2 page errors. |
error_situation |
string | run indicates during runtime; Native crashes recovered at the next startup are startup. |
error_message |
string | Error summary; for crashes, diagnostic information such as exception type, exception code, or address is included. |
error_stack |
string | Full exception or call stack; when a complete Native call stack is unavailable, at least the instruction address is recorded. |
Automatically Collected Types¶
| Scenario | error_type |
error_source |
Description |
|---|---|---|---|
| .NET unhandled exception terminating the process | windows_crash |
logger |
error_message contains the full exception type and message, and error_stack contains Exception.ToString(). |
Unhandled SEH or C++ std::terminate |
native_crash |
logger |
Crash information is safely persisted to disk and recovered at the next startup; the exception code, address, or std::terminate information is written to error_message. |
| Native UI Watchdog detects an unresponsive application | anr_error |
logger |
Reported after the application becomes responsive again; the duration is written to error_message. |
HttpClient request exception, or an automatic Resource returns HTTP 4xx/5xx |
network_error |
network |
The Error is correlated with the corresponding Resource and carries its URL, method, and status information. |
| WebView2 JavaScript Error | Error.name of the JavaScript error, or JavaScriptError when missing |
webview |
error_message and error_stack come from the page exception. |
| Unhandled WebView2 Promise rejection | name of the rejection, or UnhandledPromiseRejection when missing |
webview |
error_message and error_stack come from the rejection reason. |
| WebView2 navigation failure | WebView2NavigationError |
webview |
error_message contains the navigation failure status. |
| WebView2 process failure | WebView2ProcessFailed |
webview |
error_message contains the process failure type or reason. |
Unobserved Task exceptions and UI thread exceptions caught by WinForms that allow the application to continue running are not crashes; error_type uses the corresponding .NET exception type and error_source is logger. Exception classification and diagnostic details are consistently reflected in error_type, error_message, and error_stack.
Long Task¶
| Field | Type | Description |
|---|---|---|
duration |
integer | Long Task duration in nanoseconds. |
long_task_stack |
string | Call stack recorded when available. |
long_task_source |
string | Automatic or manual collection source. |
long_task_delay |
integer | Blocking delay detected on the UI thread. |
long_task_threshold |
integer | Effective Long Task threshold. |
long_task_cooldown |
integer | Cooldown time for consecutive blocking reports. |
long_task_suppressed_count |
integer | Number of duplicate reports merged during the cooldown period. |
RUM Capability Matrix¶
| Integration Method | View | Action | Resource | Error | Long Task |
|---|---|---|---|---|---|
| WPF | Automatic | Automatic | HttpClient |
Unhandled exceptions | UI thread monitoring |
| WinForms | Automatic | Automatic | HttpClient |
Unhandled exceptions | UI thread monitoring |
| WinUI 3 | Automatic after window association | Automatic | HttpClient |
Unhandled exceptions | UI thread monitoring |
| Native C/C++ | Explicit integration via window events | Explicit integration via messages or commands | WinHTTP adapter or manual API | Crash recovery or manual API | HWND Watchdog or manual API |
| WebView2 | Page navigation | Page interactions | Fetch/XHR/Resource | JavaScript Error | Renderer Long Tasks are not collected |
| Electron Native Bridge | Browser RUM | Browser RUM | Browser RUM | Browser RUM + Main Process events | Browser RUM; Renderer unresponsiveness is reported by the Main Process |
The Native SDK does not install process-level Detour hooks. The application must explicitly pass in HWND, WinHTTP handles, or business lifecycle events. For integration methods, see Desktop UI Frameworks and Manual RUM Instrumentation.
Log Capability Matrix¶
| Integration Method | Custom Log | Batch Log | Automatic Log Sources | RUM Correlation |
|---|---|---|---|---|
| .NET / C# | GuanceSdk.AddLog() |
GuanceSdk.AddLogs() |
Can collect System.Diagnostics.Trace |
Configurable |
| Native C/C++ | guance_log_add() |
guance_log_add_batch() |
Console, ETW, and third-party logging libraries are not intercepted at present | Configurable |
| WebView2 | Written by the Windows host | Written by the Windows host | Page Console is not automatically bridged | Uses the host's current RUM context |
| Electron Native Bridge | Browser Logs API | Converted by the Browser Logs Adapter | Console, page errors, or custom scopes are configured by Browser Logs | Uses the Native Session, View, and Action context |
Log uses a separate queue. When RUM correlation is enabled, the session_id, view_id, and action_id at the time the log is written are reported together with the Log; logs already enqueued are not modified by later context changes.
The core fields of a Log are message and status. It also carries service, env, version, SDK, application, device, and user fields; when RUM correlation is enabled, it further carries session_id, view_id, action_id, and the corresponding names. GlobalContext, user extension attributes, and event-level Properties are written as custom tags but cannot override SDK reserved fields.
Trace Capability Matrix¶
| Integration Method | Automatic Boundary | Manual Context | RUM Resource Correlation | Standalone Span Reporting |
|---|---|---|---|---|
| .NET / C# | HttpClient diagnostic subscription or RumHttpMessageHandler |
ContextProvider |
Configurable | Not supported |
| Native C/C++ | guance_rum_winhttp.hpp |
guance_trace_create_context() or a callback |
Configurable | Not supported |
| WebView2 | Page requests are handled by the WebView2/Browser side | Managed by the page SDK | Page Resources are bridged | Not uploaded by the Windows SDK |
| Electron Native Bridge | Browser RUM SDK | Browser RUM SDK | Resources are written to the Native RUM queue through the Bridge | Not supported |
HTTP Trace generates or passes through request headers and can write trace_id and span_id to the corresponding RUM Resource. For complete APM spans, the application still needs to use a separate APM Tracer. For the specific formats and target filtering, see Trace Configuration.
Data Correlation¶
- The five RUM data types share the current
session_id. - Action, Resource, Error, and Long Task are correlated with the current
view_id. - Resources, Errors, and Long Tasks generated within an Action's scope are correlated with the corresponding
action_id. - Starting a new View ends the previous active View.
- User information updates affect only subsequent data and do not modify historical data.
- Whether Log and HTTP Trace are correlated with RUM is controlled by their respective
EnableLinkRumDataorenable_link_rum_data.
Resource Timing¶
Automatic HttpClient Resources record the total duration by default and mark the timing precision. DNS, TCP, TLS, and TTFB phases can be supplemented through HttpResourceTimingProvider or RumResourceTiming.FromPhases().
The Native WinHTTP adapter records request start, end, status, byte counts, and Trace correlation information. When the application does not have reliable phase timings, it should not estimate or fabricate these fields.
Data Privacy¶
For how Resource URL query parameters, HTTP headers, Trace targets, and Log attributes are handled, see Privacy and Permissions. User, custom context, and manual event attributes must be sanitized for business privacy by the application before they are written.