Viewing Event Logs

by Barry Dysert
(last updated March 16, 2020)

Windows event logs are viewed with a system program called the Event Viewer. The easiest way to start the Event Viewer is to use the searching capabilities of Windows, looking for "Event Viewer" (without the quote marks). Once the program is started, you are greeted by the initial screen. (See Figure 1.)

Figure 1. The Event Viewer's initial window.

The bulk of the screen (the information in the center) presents a summarization of various elements of the event logs. You can drill down on any of these for additional information. Most of the time, though, you'll probably want to go directly to a specific log, in which case you need to expand the "Windows Logs" node near the upper left of the screen. This expansion reveals five major event logs: Application, Security, Setup, System, and Forwarded Events. Click on one of these names to get to the events themselves. For instance, if I click the Application log, I can see all the events contained within that log file. (See Figure 2.)

Figure 2. Viewing the Application log.

When viewing an event log, the Event Viewer screen is divided into four panes. The vertical pane on the left is the navigator pane that allows you to expand and collapse the trees that house the different event logs. The top-center pane lists the events for the selected log. (By default, the events are listed in reverse chronological order so that the most recent events appear at the top.) The bottom-center pane is the preview pane, which can be closed in order to make more room for the events themselves. If open, though, it provides details on the event selected in the upper-center pane. The vertical pane on the right is the action pane, which allows you to perform various actions on the event log or the particular event that is selected.

To view more information about an event, click the event in the upper-center pane. Its details will appear in the preview pane. You can also apply a filter to the events you see, to focus only on the ones that you're currently interested in. For example, you may only want to see "Critical" or "Error" events, or only certain Event IDs. There are many filters you can apply. Just click the "Filter Current Log" link in the Actions pane and create your filter.

It's also possible to save part or all of an event log to disk for historical reasons or in case you want to review it later. To do this, click the "Save Events As" link in the Action pane and you'll be prompted to enter a filename where you want the events to be stored. You can then view this log later just as you would view any of the real-time logs.

The event viewer is a powerful resource that can help a system administrator keep the system in good working order. It can even help programmers who need to record information from their non-GUI programs. Spending the time to get acquainted with the event viewer is time well spent.

 This tip (11565) applies to Windows 7, 8, and 10.

Author Bio

Barry Dysert

Barry has been a computer professional for over 35 years, working in different positions such as technical team leader, project manager, and software developer. He is currently a software engineer with an emphasis on developing custom applications under Microsoft Windows. When not working with Windows or writing Tips, Barry is an amateur writer. His first non-fiction book is titled "A Chronological Commentary of Revelation." ...


Understanding the Search Index

You can utilize Explorer's search utility to find text within files. To make searches fast, Windows maintains a search ...

Discover More

Understanding Regional Settings

Microsoft Windows is "globally friendly." By this I mean that regardless of where you are in the world, you can easily ...

Discover More

Copying Files Using the Command Line

The copy command can be a timesaver over trying to do the similar sort of thing with Windows Explorer. You can copy ...

Discover More
More WindowsTips

Changing How Event Log Overruns are Handled

By default, the event logs are implemented in a circular buffer, i.e., when its maximum size is reached, the oldest ...

Discover More

Deleting Events in Your Event Logs

You don't need to worry about event logs filling up your disk, but you still may want to clean them out eventually. This ...

Discover More

What is the Purpose of the System Event Log?

The System event log holds messages generated by device drivers. This tip explains more about it.

Discover More

FREE SERVICE: Get tips like this every week in WindowsTips, a free productivity newsletter. Enter your address and click "Subscribe."

View most recent newsletter.


If you would like to add an image to your comment (not an avatar, but an image to help in making the point of your comment), include the characters [{fig}] in your comment text. You’ll be prompted to upload your image when you submit the comment. Maximum image size is 6Mpixels. Images larger than 600px wide or 1000px tall will be reduced. Up to three images may be included in a comment. All images are subject to review. Commenting privileges may be curtailed if inappropriate images are posted.

What is eight minus 6?

There are currently no comments for this tip. (Be the first to leave your comment—just use the simple form above!)

Newest Tips

FREE SERVICE: Get tips like this every week in WindowsTips, a free productivity newsletter. Enter your address and click "Subscribe."

(Your e-mail address is not shared with anyone, ever.)

View the most recent newsletter.