Glossary
Event consumer (__EventConsumer)
The WMI object that says what to do when a filter fires: run a command line or a script, write a log line, an event log entry or an e-mail.
An event consumer is the what of a WMI subscription: an instance of a class derived from __EventConsumer. Windows ships five: CommandLineEventConsumer, ActiveScriptEventConsumer, LogFileEventConsumer, NTEventLogEventConsumer and SMTPEventConsumer.
Permanent consumers run as SYSTEM. The first two execute code and are the ones seen in persistence. Software can also define its own consumer classes. A consumer acts only when a binding connects it to an event filter.