relog.exe

Relog (Windows Performance Toolkit) - ETW Trace Post-Processing

Application/ToolSafePerformance Tool
CPU Usage
0-2%
Memory
5-20 MB
Location
C:\Program Files (x86)\Windows Kits\10\Tools\x64
Publisher
Microsoft Corporation

Quick Answer

relog.exe is safe. It is a legitimate Windows Performance Toolkit utility used to post-process ETW trace data into human-readable formats like CSV or XML.

Is it a Virus?
✔ NO - Safe
Must be in a Windows Kits folder (see safety verification below)
Warning
Relog.exe is a specialized tracing tool; ensure you're using the official Microsoft Relog from Windows Kits. Large ETL files can spike CPU while processing.
Untrusted origins may bundle counterfeit tools.
Can I Disable?
✔ YES
Only run it when you need to process traces; remove Windows Kits if you don't use it.

What is relog.exe?

relog.exe is the Windows Performance Toolkit command-line utility used to post-process ETW (Event Tracing for Windows) traces. It converts ETL files into human-readable formats (CSV, TSV, or XML) for analysis, filtering, and reporting. It is typically invoked in scripts or during offline profiling.

Relog.exe reads an ETL trace, applies user-specified format options and filters, then writes output to a chosen file. This console tool supports commands to select time ranges, data types, and output formats, enabling automated trace analysis.

Quick Fact: Relog.exe is a core component of ETW workflows; it enables batch processing of traces without a GUI.

Types of Relog Processes

Is relog.exe Safe?

Yes, relog.exe is safe when obtained from Microsoft Windows Kits and installed via official channels.

Is relog.exe a Virus or Malware?

The real relog.exe is not a virus. Malware often tries to imitate legitimate tool names. Always verify the file location and signature.

How to Tell if relog.exe is Legitimate or Malware

  1. File Location: Should be in C:\Program Files (x86)\Windows Kits\10\Tools\x64\Relog.exe or C:\Program Files\Windows Kits\10\Tools\x64\Relog.exe. Other locations are suspicious.
  2. Digital Signature: Right-click Relog.exe → Properties → Digital Signatures. Should show 'Microsoft Corporation'.
  3. Resource Usage: Idle Relog.exe uses minimal CPU/memory; heavy usage during trace processing is expected.
  4. Behavior: Relog.exe should be invoked by a user or a script for a trace processing task; persistent background activity without a trace job is suspicious.

Red Flags: If relog.exe is found outside the Windows Kits folders, lacks a valid digital signature, runs without a known ETL job, or consumes CPU in idle state for extended periods, run antivirus/antimalware checks and verify the Windows Kits installation.

Why Is relog.exe Running on My PC?

relog.exe runs when you start an ETW tracing workflow, or when a script or automation invokes the tool to post-process traces.

Reasons it's running:

Can I Disable or Remove relog.exe?

Yes, you can disable relog.exe. It's safe to ignore if you do not perform ETW trace post-processing. If you uninstall the Windows Performance Toolkit, Relog.exe is removed.

How to Stop relog.exe

How to Uninstall Relog.exe

Common Problems: High CPU or Memory Usage

If relog.exe is consuming excessive resources during trace processing:

Common Causes & Solutions

Quick Fixes:
1. Open an elevated Command Prompt and run a small test with a known ETL file.
2. Use a simple command to convert ETL to CSV (e.g., relog.exe yourtrace.etl -o output.csv -f csv).
3. Split large ETL files into smaller chunks and re-run Relog.
4. Verify output path permissions and ensure enough disk space.
5. Update Windows Kits to the latest version.

Frequently Asked Questions

What is relog.exe?

relog.exe is the command-line utility from the Windows Performance Toolkit that post-processes ETW traces, converting ETL files to readable formats like CSV, TSV, or XML for analysis.

Where is relog.exe located?

Relog.exe is typically found under C:\Program Files (x86)\Windows Kits\10\Tools\x64\ or C:\Program Files\Windows Kits\10\Tools\x64\Relog.exe, depending on your Windows Kits installation.

How do I use relog.exe to convert ETL to CSV?

Open a Command Prompt and run relog.exe input.etl -o output.csv -f csv. You can add filters like -start 00:00:00 -end 01:00:00 to limit data.

Is relog.exe safe to run on Windows 11?

Yes, relog.exe is safe when obtained from the official Windows Kits. Ensure the executable is located in the Windows Kits path and is digitally signed by Microsoft.

Can Relog.exe be used with xperf?

Relog.exe is designed to work with ETW traces generated by xperf or other ETW producers. It post-processes the ETL produced by those tools.

Why does Relog.exe take so long to process traces?

Processing time grows with ETL size, data types selected, and output format. Large traces with many events or filters require more CPU time; using smaller ETL chunks helps.

Related Processes