1. Launch CMD
Click the start button and type in cmd and run it as administrator.
2. Run Start Command
In the window type in "pktmon start --etw.
3. Run Stop Command
In the same window, run "pktmon stop". This will stop the capture and create the file in location "C:\Windows\System32\pktmon.ETL"
4. Convert ETL to TXT
In the same window type in, "pktmon format PktMon.etl -o mylog.txt. You can now navigate to the location listed in Step 3 to view the TXT file.