A–Z
Glossary
Plain-language definitions of the WMI and CIM repository terms used across the blog.
- CCM_RecentlyUsedApps (SCCM software metering)
- ConfigMgr client WMI class recording, per user and executable, the path, last launch time, launch count and file version information.
- ActiveScriptEventConsumer
- The standard WMI consumer that runs VBScript or JScript, inline (ScriptText) or from a file (ScriptFilename), in scrcons.exe as SYSTEM.
- CIM repository (WMI repository)
- The on-disk database where WMI stores class definitions and instances: OBJECTS.DATA, INDEX.BTR and MAPPING1-3.MAP in System32\wbem\Repository.
- CommandLineEventConsumer
- The standard WMI consumer that starts a process: CommandLineTemplate, ExecutablePath and WorkingDirectory, launched as SYSTEM when its filter fires.
- Event consumer (__EventConsumer)
- The WMI object that says what to do when a filter fires: run a command line or a script, write a log line, an event log entry or an e-mail.
- __EventFilter
- The WMI class that describes the trigger of an event subscription: a named WQL query, its language and the namespace it watches.
- __FilterToConsumerBinding
- The WMI object that links an event filter to an event consumer. Without it, neither fires; with it, the consumer runs every time the filter matches.
- INDEX.BTR
- The WMI repository's B-tree index: text keys made of hashed namespace, class and instance names that point to records in OBJECTS.DATA.
- MAPPING1.MAP, MAPPING2.MAP, MAPPING3.MAP
- The WMI repository's page maps: they translate logical page numbers of OBJECTS.DATA and INDEX.BTR into physical pages. Three generations are kept.
- OBJECTS.DATA
- The WMI repository file that holds every class definition and instance in 8 KiB pages, including event filters, consumers and bindings.
- scrcons.exe (WMI Standard Event Consumer)
- The Windows process that runs ActiveScriptEventConsumer scripts. Seeing it run, or its children, points to a WMI script subscription.
- WMI namespace (root\subscription)
- A folder-like container of WMI classes and instances, such as root\cimv2. Permanent event subscriptions normally live in root\subscription.
- WMI (Windows Management Instrumentation)
- Windows' management layer: it exposes system information as classes and instances, answers WQL queries and can run actions when events happen.
- WQL (WMI Query Language)
- The SQL-like language WMI uses for data and event queries; event filters use it to describe the event that triggers a subscription.