Thanks — that output (Get-WinEvent returned nothing for the tight 19:00→19:05 window) is useful information. It simply means Windows didn’t record any System events that matched that exact filter/time window — not that nothing happened. We still need to collect a broader set of evidence for the 19:00–19:01 permanent drop so I can be definitive.
Two short points first
- Your Unifying report already showed “Device doesn’t respond” entries earlier — that strongly suggested a per‑device radio/session failure rather than a full USB controller crash. I’ll confirm whether that same pattern holds for the 19:00 drop.
- The Get-WinEvent call can return “No events” when the filter is too narrow (provider/message patterns didn’t match) or when the event types you need are in a different provider/channel. So we’ll run broader captures now.
Do this now (exact copy/paste — elevated PowerShell)
1) Capture a broad System window that covers the drop (wider window so we don’t miss it):
$start = Get-Date "2025-10-22 17:30:00" # change start if you want an earlier window
Get-WinEvent -FilterHashtable @{LogName='System'; StartTime=$start} |
Where-Object { $
.ProviderName -match 'Kernel-PnP|USBHUB3|USB|Microsoft-Windows-DriverFrameworks-UserMode' -or $.Message -match 'USB|usb|hub|reset|removed|disconnect|device|xhci|ehci|HID' } |
Select-Object TimeCreated, ProviderName, Id, LevelDisplayName, Message |
Out-File "$env:USERPROFILE\Desktop\USB_Events_wide_1730-2000.txt"
2) Dump the current Logitech/Unifying device list (post‑drop device state):
Get-PnpDevice -PresentOnly | Where-Object { $_.InstanceId -match 'VID_046D|VID_0A5C' } | Format-List FriendlyName,InstanceId,Status | Out-File "$env:USERPROFILE\Desktop\MouseDeviceInfo_postdrop.txt"
3) Also save the last 500 System‑level events (raw) in case something odd is stored under other providers:
Get-WinEvent -MaxEvents 500 -LogName System | Select-Object TimeCreated, ProviderName, Id, LevelDisplayName, Message | Out-File "$env:USERPROFILE\Desktop\System_Last500.txt"
4) Stop the monitor (if still running) and attach the monitor log
Stop-Process -Id (Get-Content "$env:USERPROFILE\Desktop\usb_monitor.pid") -Force -ErrorAction SilentlyContinue
Remove-Item "$env:USERPROFILE\Desktop\usb_monitor.pid" -ErrorAction SilentlyContinue
Then attach the file:
C:\Users\<you>\Desktop\USB_Monitor.log
What I need you to attach here after running the above
- USB_Events_wide_1730-2000.txt
- MouseDeviceInfo_postdrop.txt
- System_Last500.txt
- USB_Monitor.log (if you left it running; attach it even if small)
Why these three are decisive
- If the System event file contains lines like “usb x‑y: USB disconnect”, “reset high‑speed USB device”, or xhci_hcd/ehci_hcd port reset at ~19:00 → that’s a host/controller reset and we’ll update a specific chipset/USB driver or BIOS (I’ll give the exact download and steps).
- If the Windows files show the receiver remains present (MouseDeviceInfo_postdrop will show Status: OK or not) and the System events only show per‑device retries or no hub/controller resets, that points to a device/radio/session failure (mouse ↔ receiver). In that case we’ll try the spare receiver, Bluetooth test, or (if tests indicate the mouse itself is faulty) replace the mouse. (Your earlier Unifying log already showed device‑doesn’t‑respond messages; these new Windows files will confirm the same pattern around 19:00.
If the files are large or the event query finishes slowly
- It’s normal for the wide System scan to take a few seconds. If Get‑WinEvent returns a lot of data, attach the files rather than pasting into the chat.
If you prefer a single command that saves everything in one go (alternative)
Run this block (Admin PowerShell). It writes the same files and is a one‑shot capture for the last few hours:
$start = (Get-Date).AddHours(-6)
Get-WinEvent -FilterHashtable @{LogName='System'; StartTime=$start} | Where-Object { $
.ProviderName -match 'Kernel-PnP|USBHUB3|USB|Microsoft-Windows-DriverFrameworks-UserMode' -or $.Message -match 'USB|usb|hub|reset|removed|disconnect|device|xhci|ehci|HID' } | Select TimeCreated,ProviderName,Id,LevelDisplayName,Message | Out-File "$env:USERPROFILE\Desktop\USB_Events
Last6hrs.txt"
Get-PnpDevice -PresentOnly | Where-Object { $.InstanceId -match 'VID_046D|VID_0A5C' } | Format-List FriendlyName,InstanceId,Status | Out-File "$env:USERPROFILE\Desktop\MouseDeviceInfo_postdrop.txt"
Get-WinEvent -MaxEvents 500 -LogName System | Select TimeCreated,ProviderName,Id,LevelDisplayName,Message | Out-File "$env:USERPROFILE\Desktop\System_Last500.txt"
When you’ve attached the files
- I’ll extract the exact lines at ~19:00–19:01 and tell you the single next action (one command/one download or “swap receiver/test Bluetooth/replace mouse”) — no long lists, just the one thing to do next.
One small practical note while you run these
- If the mouse is currently disconnected and you need to run the commands: power‑cycle the mouse to restore input first (or run the commands from another machine remotely). Do not reboot until you’ve saved the Windows events — reboot clears them.
I’ll wait for the three files and will parse them immediately when you attach them.