Read a Windows event log (.evtx) without Event Viewer
Drop a .evtx file, such as a System, Security or Application log copied off a Windows PC, to read it on a Mac, on Linux or on a phone. See every record with its time, Event ID, level, source and event data. Filter by level, Event ID, provider or any word, open the full XML of a record, and save the rows you filtered as CSV. Logons, failed logons, new user accounts, new processes, newly installed services and cleared logs are listed separately.
The log is read on your device. Nothing is uploaded, and no name or address in it is looked up.
What it shows
- The file header: which log it is (System, Security, Application, or a channel such as
Microsoft-Windows-PowerShell/Operational), the computer that wrote it, how many records it holds and their range of record IDs, the oldest and newest record, how many 64 KB chunks are in use, and the header's two flags: dirty (Windows still had the log open when it was copied, which is normal for a log taken from a running PC) and full. - Every record in a scrolling table that stays fast with hundreds of thousands of rows: time in UTC, Event ID, level, provider (the program or Windows component that logged it), computer, and a one-line message built from the record's own event data, such as
ServiceName: BCSWAP · ImagePath: C:\Windows\system32\drivers\BCSWAP.sys · StartType: disabled. Errors and failures are tinted. - Filters: pick a level (Critical, Error, Warning, Information, Verbose, and Audit Success or Audit Failure for Security logs), a provider, one or more Event IDs separated by commas, and type a word, user name, IP address or path to keep the records that mention it. The CSV saves exactly the rows the filters show.
- The full XML of any record, as Event Viewer's "XML View" shows it: the
Systemblock with provider, Event ID, level, task, keywords, time, process and thread IDs, channel, computer and user SID, thenEventDataorUserDatawith every field. - Notable events, each counted and listed with the fields that matter: 4624 successful logon and 4625 failed logon (account, logon type such as 3 network or 10 Remote Desktop, source address), 4720 user account created, 4688 process created (with the command line, if command-line auditing was on), 7045 service installed (name, program path, start type, account), and 1102 or 104 log cleared (who cleared it). Only what the record holds is shown.
A worked example: a month of a Windows 7 System log
python-evtx, Willi Ballenthin's Python parser for this format, ships a System log called system.evtx (1,118,208 bytes) in its tests; it came from the test data of plaso, the forensic timeline tool. It opens as EVTX version 3.1 with the dirty flag set: 17 chunks in the file, of which 9 are in use and 8 never written. Those 9 chunks hold 1,601 records, IDs 12,049 to 13,649, from 2012-03-14 04:17:38 UTC to 2012-04-08 01:28:13 UTC, all from the computer WKS-WIN764BITB.shieldbase.local. The first record is Event ID 105 from Microsoft-Windows-Eventlog, saying the previous System log was backed up to Archive-System-2012-03-14-04-17-39-932.evtx. 1,288 of the records are Service Control Manager's 7036 (a service started or stopped); filter for level Error and 8 remain, plus 2 Critical (Kernel-Power 41: the PC restarted without shutting down cleanly). The notable-events list shows 12 services installed (7045), among them BCWipe service running C:\Program Files (x86)\Jetico\BCWipe\BCWipeSvc.exe, the service of a file-wiping program, and PsExec running %SystemRoot%\PSEXESVC.EXE three times on 2012-04-05: the service Sysinternals PsExec installs on a PC when someone runs commands on it from another machine.
Where the logs are, and how to copy one
Windows keeps its logs in C:\Windows\System32\winevt\Logs, one .evtx file per channel (System.evtx, Security.evtx, Application.evtx, Microsoft-Windows-PowerShell%4Operational.evtx, where %4 stands for a slash). The files are locked while Windows runs, so copy them with Event Viewer's "Save All Events As…", or from an administrator prompt with wevtutil epl Security C:\Temp\Security.evtx. Reading the Security log needs administrator rights on the PC it comes from; this page does not need any.
What this cannot do
- No message text from Windows. The sentence Event Viewer shows in its "General" tab ("A service was installed in the system…") is not in the .evtx file: Windows builds it from a message table inside the program or DLL that logged the event, on the PC that has that program. This page has no such DLLs, so the message column lists the raw event data fields instead. For classic events the fields have no names (
Data 1,Data 2), and their meaning is in the documentation for the Event ID. - Damaged chunks are skipped and counted. Every 64 KB chunk carries two CRC-32 checksums. A chunk whose checksum does not match is left out, and the summary says how many were; records in it are not recovered. A record that cannot be decoded inside a good chunk is listed with the error instead of its data. Records deleted from a log, or carved from free space on a disk, are not searched for.
- Not the old .evt format. Windows XP and Server 2003 wrote .evt files (they start with
LfLe), a different binary format that this page does not read. Logs exported as .csv open in the CSV viewer. - Times are UTC. Event logs store UTC to a tenth of a microsecond; Event Viewer shows them in the PC's own time zone, so its clock times differ by that offset.
- Size. The whole file is read into memory. Windows sets the System and Application logs to 20 MB by default, which opens in a second or two; a log of several hundred MB with a million records needs a lot of memory, which a phone may not have.