Capture a Short Process Monitor Trace Without Saving Only the Visible Rows
A filtered Process Monitor window is only one view of a trace. Saving just the displayed rows can remove the surrounding events a technician needs, while saving all events can retain private details hidden by that view. Decide how the original trace will be stored before recording.
Use Microsoft's current Process Monitor on a supported Windows PC. Close unrelated private applications, prepare one reproducible app-start failure and choose a protected destination with room for the capture. Do not leave a diagnostic recording running throughout an ordinary workday.
Record one controlled attempt
Microsoft's client guide calls for an elevated Process Monitor session using the executable matching the system architecture. Reset earlier filters to their default state so an old investigation does not conceal relevant activity.
The tool normally begins capturing automatically. Use File, Capture Events or Ctrl+E to control recording, and check its state. Reproduce the intended failure once and stop promptly. Note what you clicked and approximately when the error appeared.
Save the trace using All events and Native Process Monitor Format, PML. The client guide warns that displayed-only or selected-only events may be insufficient, and that prolonged captures can exhaust memory or disk space.
Open the saved recording to inspect it. Under Tools, Process Tree, locate the application and use Add process to Include filter, or select the relevant process ID through a filter. Keep the reproduction time in view so a different launch is not confused with the failed one.
Keep filtering and disclosure separate
Sysinternals describes its normal filters as non-destructive, and native logs retain data for later analysis. Hiding unrelated rows therefore does not establish that those details have been removed from the saved PML.
Review how the file will be shared with the authorised recipient. Paths, account names and command lines can disclose sensitive information. Keep any public description limited to the necessary observations.
A failed file or Registry operation in a trace needs context; do not grant broad permissions simply because one row says access was denied. The completed capture should establish the process, attempt and surrounding sequence, leaving the repair decision to an evidence-based review.
Sources: Microsoft Process Monitor capabilities; Microsoft app-start trace procedure.