viewhack

Read a Windows event log (.evtx) without Event Viewer

Drop a .evtx file, such as a System, Security or Application log copied off a Windows PC, to read it on a Mac, on Linux or on a phone. See every record with its time, Event ID, level, source and event data. Filter by level, Event ID, provider or any word, open the full XML of a record, and save the rows you filtered as CSV. Logons, failed logons, new user accounts, new processes, newly installed services and cleared logs are listed separately.

The log is read on your device. Nothing is uploaded, and no name or address in it is looked up.

What it shows

A worked example: a month of a Windows 7 System log

python-evtx, Willi Ballenthin's Python parser for this format, ships a System log called system.evtx (1,118,208 bytes) in its tests; it came from the test data of plaso, the forensic timeline tool. It opens as EVTX version 3.1 with the dirty flag set: 17 chunks in the file, of which 9 are in use and 8 never written. Those 9 chunks hold 1,601 records, IDs 12,049 to 13,649, from 2012-03-14 04:17:38 UTC to 2012-04-08 01:28:13 UTC, all from the computer WKS-WIN764BITB.shieldbase.local. The first record is Event ID 105 from Microsoft-Windows-Eventlog, saying the previous System log was backed up to Archive-System-2012-03-14-04-17-39-932.evtx. 1,288 of the records are Service Control Manager's 7036 (a service started or stopped); filter for level Error and 8 remain, plus 2 Critical (Kernel-Power 41: the PC restarted without shutting down cleanly). The notable-events list shows 12 services installed (7045), among them BCWipe service running C:\Program Files (x86)\Jetico\BCWipe\BCWipeSvc.exe, the service of a file-wiping program, and PsExec running %SystemRoot%\PSEXESVC.EXE three times on 2012-04-05: the service Sysinternals PsExec installs on a PC when someone runs commands on it from another machine.

Where the logs are, and how to copy one

Windows keeps its logs in C:\Windows\System32\winevt\Logs, one .evtx file per channel (System.evtx, Security.evtx, Application.evtx, Microsoft-Windows-PowerShell%4Operational.evtx, where %4 stands for a slash). The files are locked while Windows runs, so copy them with Event Viewer's "Save All Events As…", or from an administrator prompt with wevtutil epl Security C:\Temp\Security.evtx. Reading the Security log needs administrator rights on the PC it comes from; this page does not need any.

What this cannot do