Typical Microsoft. They were (or maybe are still) in the telemetry-all-the-things craze so what can be more logical than adding an event called "telemetry" to every binary produced with their compiler. In the words of Raymond Chen, "I bet somebody got a bonus for that feature." But as MS's Carrol is quoted in the the fine article:
"We haven’t actually gone through this full exercise with any customers to date though, and we are so far relying on our established approaches to investigate and address potential problems instead."
Even if that ETW event isn't "telemetry" itself, it could be, of course, used in the some hypothetical telemetry code that that would use ETW infrastructure. Which is not bad as is. It's just an event, independent of who uses it.
The main question is, of course, is there such code ("real" telemetry using ETW) in Windows, or is ETW used only for debugging, that is, only by developers.
https://msdn.microsoft.com/en-us/library/windows/desktop/aa3...
My guess is: ETW is already used for some real telemetry: its model seems to allow this.
Technical details of what the functions do:
https://www.reddit.com/r/cpp/comments/4hoyzr/msvc_mutex_is_s...
And the explanation of the ETW by xon_xoff:
https://www.reddit.com/r/cpp/comments/4hoyzr/msvc_mutex_is_s...
"ETW is a general mechanism to log any kind of event, not just performance events, and is used throughout Windows for more than just profiling. Furthermore, it supports both multiple simultaneous consumers and storage in .etl files for later processing. Any program with sufficient privilege can enable tracing of specific event types throughout the system, and user intervention is not required to do so. An example is an automatically generated file called ExplorerStartupLog.etl in the AppData\Local\Microsoft\Windows\Explorer folder. These files being generated locally doesn't mean they can't be transmitted later, and some problem reporting tools use ETW+ETL files to efficiently capture telemetry for upload."