Using the Event Log in Windows. Where is the Windows Event Log Using Filters and Custom Views

Event Viewer in Windows displays a history (log) of system messages and events generated by programs - errors, information messages and warnings. By the way, scammers can sometimes use event viewing to deceive users - even on a normally functioning computer, there will always be error messages in the log.

Launch Event Viewer

In order to start Windows Event Viewer, type this very phrase in the search or go to “Control Panel” - “Administration” - “Event Viewer”

Actually, why am I writing about this at all, since there is nothing interesting for Windows event viewer? regular user? Still this function(or program, utility) Windows can be useful when problems arise with your computer - when a blue screen death of Windows, or a random reboot occurs - in the event viewer you can find the cause of these events. For example, an error in the system log can provide information about which hardware driver caused the failure for subsequent actions to correct the situation. Just look for an error that occurred while your computer rebooted, froze, or displayed a blue screen of death - the error will be marked as critical.

There are other uses for Event Viewer. For example, Windows records the time it takes for the operating system to fully boot. Or, if your computer hosts a server, you can enable shutdown and reboot event recording - every time someone shuts down the PC, they will be required to enter a reason for it, and you can later view all shutdowns and reboots and the entered reason for the event.

In addition, you can use event viewing in conjunction with the task scheduler - click right click mouse on any event and select “Bind task to event”. Whenever this event occurs, Windows will run the corresponding task.

Hello everyone, the topic is how to view windows logs. I think everyone knows what logs are, but if suddenly you are a beginner, then logs are system events occurring in the operating system of both Windows and Linux, which help track what, where and when happened and who did it. Any system administrator must be able to read Windows logs.

An example from real life is the situation when on one of the IBM servers the disk failed and for technical support I collected server logs so they could diagnose the problem. The Event Viewer service is responsible for collecting and recording logs in Windows. Event Viewer is a convenient tool for obtaining system logs.

How to open in Event Viewer

You can go into the Event Viewer snap-in very simply, suitable for any Windows versions. Press the magic buttons

Win+R and enter eventvwr.msc

A Windows Event Viewer window will open in which you need to expand the Windows Logs item. Let's go through each of the magazines.

Log Application contains records related to programs on your computer. The log is written when the program was launched, if it was launched with an error, then this will also be reflected here.

An audit log is needed to understand who did what and when. For example, logged in or logged out, tried to gain access. All success or failure audits are written here.

The Installation item records Windows logs about what was installed and when, for example, programs or updates.

The most important magazine is the system. All the most necessary and important things are written down here. For example, you had a blue screen bsod, and these messages that are recorded here will help you determine its cause.

There are also Windows logs for more specific services, such as DHCP or DNS. Event Viewer cuts everything :).

Suppose you have more than a million events in the Security log, you will probably immediately ask the question whether there is filtering, since viewing all of them is masochism. This is provided for in the event viewer; windows logs can be conveniently filtered out, leaving only what is needed. On the right in the Actions area there is a button Filter current log.

You will be asked to specify the event level:

  • Critical
  • Error
  • Warning
  • Intelligence
  • Details

It all depends on the search task; if you are looking for errors, then there is no point in other types of messages. Next, in order to narrow the scope of your event viewing search, you can specify the desired event source and code.

So, as you can see, parsing Windows logs is very simple, we search, we find, we solve. A quick clearing of Windows logs may also be useful:

View windows PowerShell logs

It would be strange if PowerShell couldn’t do this; to display log files, open PowerShell and enter the following command

Get-EventLog -Logname "System"

As a result, you will receive a list of System logs

The same can be done for other magazines, for example Applications

Get-EventLog -Logname "Application"

small list of abbreviations

  • Event code - EventID
  • Computer - MachineName
  • Event sequence number - Data, Index
  • Category of tasks - Category
  • Category code - CategoryNumber
  • Level - EntryType
  • Event message - Message
  • Source - Source
  • Event generation date - ReplacementString, InstanceID, TimeGenerated
  • Event recording date - TimeWritten
  • User - UserName
  • Website
  • Division - Container

For example, in order to display events in the command shell only with the columns “Level”, “Event Record Date”, “Source”, “Event Code”, “Category” and “Event Message” for the “System” log, run the command:

Get-EventLog –LogName ‘System’ | Format-Table EntryType, TimeWritten, Source, EventID, Category, Message

If you need to display in more detail, then replace Format-Table with Format-List

Get-EventLog –LogName ‘System’ | Format-List EntryType, TimeWritten, Source, EventID, Category, Message

As you can see, the format is already more readable.

You can also filter the logs, for example show the last 20 messages

Get-EventLog –Logname ‘System’ –Newest 20

Additional Products

You can also automate the collection of events using tools such as:

  • Zabbix monitoring complex
  • Through event forwarding using Windows to the collector server
  • Through the Netwrix audit suite
  • If you have SCOM, then it can aggregate any Windows platform logs
  • Any DLP systems

So whether you choose to use event viewer or PowerShell to view windows events, it's up to you.

Remote viewing of logs

  • First method

Not long ago, the Windows Server 2019 operating system introduced the Windows Admin Center remote administration component. It allows you to carry out remote control computer or server, I already told him in more detail. Here I want to show that by installing it on your workstation, you can connect from a browser to other computers and easily view their event logs, thereby studying Windows logs. In my example there will be a server SVT2019S01, We find it in the list of available ones and connect (Let me remind you that this is how we did remote network setup in Windows).

Next, you select the “Events” tab, select the desired log; in my example, I want to see all the logs for the system. From my point of view, viewing everything here is much more convenient than viewing events. The advantage is that you can do this from any phone or tablet. There is a convenient search form in the right corner

If you need to produce more fine filtration logs, then you can use the filter button.

Here you can also select the event level, for example leaving only critical and errors, set the time range, event code and source.

Here is an example of filtering by event 19.

It is very convenient to export the entire log to evxt format, which can then be easily opened through the event log. So, Windows Admin Center is a powerful tool for viewing logs.

  • Second method

The second way to remotely view Windows logs is to use the Computer Management snap-in or the same “Event Viewer”. To view Windows logs on another computer or server, in the snap-in, right-click on the top item and select "" from the context menu.

We indicate the name of another computer, in my example it will be SVT2019S01

If everything is fine and there are no blockages from the firewall or antivirus, then you will be taken to remote event viewing. If there are blockages, you will receive a message like COM+ traffic is not flowing through.

I also want to note that there are entire log aggregation systems, such as Zabbix or SCOM, but this is a different level of tasks..

How to use view

What information can be learned from the magazine? If your computer systematically produces errors, randomly reboots, or displays a “blue screen of death,” then all events that led to a malfunction are logged by the system. When viewing information you can find out at what time which service, driver, or hardware component caused a particular error. Based on this information, the necessary measures can be taken to eliminate violations.

In addition to error information, the log can be used for other purposes. You can link to any event occurring in the system performing a specific task. This will allow in the future, if a similar situation arises, to automatically fulfill the set condition.

To do this, it is enough on any element from the list call context menu right-click and select " Link a task».

Clearing the event log

Removing all information from the journal is also not difficult. To do this, in the left block of the log window, select the menu tree element that needs to be cleared, right-click to call up the context menu - "Clear log"