EvtSubscribe causes some events to be missed
16:20 03 Dec 2025

I want to write a small program to work with the EvtSubscribe function. However, I encountered a problem. Every time the callback function is called, I print a message to the screen and then call Sleep(5000). In this case, I noticed that not all the required events are coming.

Could this cause a problem in the future? For example, could the time spent analyzing the event after it arrives result in some events being missed?

int c = 0;

DWORD WINAPI SubscriptionCallback(EVT_SUBSCRIBE_NOTIFY_ACTION action, PVOID pContext, EVT_HANDLE hEvent)
{
    UNREFERENCED_PARAMETER(pContext);
    UNREFERENCED_PARAMETER(hEvent);
    UNREFERENCED_PARAMETER(action);

    printf("%d: Event triggered\n");
    Sleep(5000);

    return 0;
}


int main(void)
{
    EVT_HANDLE hEvt = NULL;
    LPCWSTR Channel = L"Security";
    LPCWSTR Query = L"Event/System[EventID=1102]";

    hEvt = EvtSubscribe(NULL, NULL, Channel, Query, NULL, NULL, (EVT_SUBSCRIBE_CALLBACK)SubscriptionCallback, 1);
    if (hEvt == NULL)
    {
        printf("eRROR %d", GetLastError());
        return - 1;
    }

    while (TRUE)
    {
        Sleep(1000);
    }

I am also running the following Python code to test this.

for i in range(1, 150):
    os.system("wevtutil cl Security")

Result:

0: Event triggered
1: Event triggered

Out of 149 events, only 2 arrived. But without the Sleep function, all events arrived. How can I solve this problem in another way? Maybe I should read all the events every minute within the loop?

c winapi pywin32