Apparently, logman query providers -pid $pid allows us to see which providers the process $pid writes to.
logman query providers -pid $pid
$pid
But how does the process $pid open a handle to the providers? What's the API?