Hi NIkita Vertelko,
As I known, this issue often happens because the analytic and debug logs for kernel components aren’t registered or exposed by default in Windows builds.
The file you mentioned, Microsoft-Windows-Kernel-Process.man, is part of the system manifest files, but it’s embedded within Windows rather than available as a standalone file. To confirm whether the log provider exists, you can run the following command:
wevtutil enum-publishers | find "Kernel-Process"
If it doesn’t appear, that means the analytic channel for this provider isn’t registered. In that case, you can use Event Viewer > View > Show Analytic and Debug Logs to check if the channel exists under Applications and Services Logs > Microsoft > Windows > Kernel-Process.
If it’s missing entirely, it’s likely the build doesn’t include that provider’s analytic events. For detailed process tracing, I recommend enabling Kernel-Process ETW tracing through Windows Performance Recorder (WPR) or xperf, which provides equivalent information with better control.
If this answer helps resolve your question, please click “Accept Answer” so others can benefit too. Thank you 😊.
Jason