Creating a Custom View in the Event Viewer

by Barry Dysert
(last updated September 12, 2016)

2

The Windows Event Viewer captures a lot of information about your system—so much so that it may sometimes be hard to find what you're looking for. That's why the ability to create custom views is so handy.

For example, let's say you want to create a custom view that shows you only the times when the computer has been shut down or restarted. Start by displaying the Event Viewer. (The easiest way to do this is to use the search capabilities of Windows to look for "Event Viewer", without the quote marks.) (See Figure 1.)

Figure 1. Event Viewer main screen.

Since we're interested in system starts and shutdowns, use the left pane of the screen to navigate to Application and Services Logs | Microsoft | Windows | Diagnostics-Performance | Operational. After drilling down that far, the Event Viewer screen should be quite different from the main one you previously saw. (See Figure 2.)

Figure 2. Navigating to the "Operational" event log.

In the right pane, near the top, click on Create Custom View. Windows displays the Create Custom View dialog box. The Filter tab should be displayed in the dialog box. (See Figure 3.)

Figure 3. Creating a Custom View.

The controls in the dialog box allow you to specify exactly what you want to see in the view. You can specify the time the event was logged, what event level you're interested in, what log and source are to be used, the Event IDs to include, the keywords will be used to filter the view, and the user and computers related to the view.

Since we are interested in startups and shutdowns at any time, for any event level, and since we've already navigated to the correct event log, we don't need to change anything here. Similarly, we don't care about the event sources or really anything else on the screen except for the Event IDs. As it turns out, a Windows startup is denoted by the Event ID of 100, and a Windows shutdown is denoted by the Event ID of 200. So, all we need to do is enter the two numbers, separated by a comma, into the textbox that currently says "<All Event IDs>.

We enter "100,200" (without the quotes) in the textbox and click OK. Windows displays the Save Filter to Custom View dialog box, which provides the opportunity to specify a name for the view we are creating. (See Figure 4.)

Figure 4. Saving the Custom View.

I'll name the custom view "Restarts" and provide a brief description about the view. Then I click OK to save the new custom view. The name of the view appears in the right pane of the Event Viewer, and can easily be displayed by simple double-clicking on it. I now have just the information I want, without all the other events logged by Windows.

 This tip (12819) applies to Windows 7, 8, and 10.

Author Bio

Barry Dysert

Barry has been a computer professional for over 30 years, working in different positions such as technical team leader, project manager, and software developer.  He is currently a senior software engineer with an emphasis on developing custom applications under Microsoft Windows. ...

MORE FROM BARRY

Changing Sounds Associated with Windows Events

You can customize Windows so that various sounds (or none) are associated with various Windows events. This tip explains how ...

Discover More

Understanding the Pictures Folder

The Pictures folder is one of several system libraries specifically optimized to hold digital pictures. This tip tells you ...

Discover More

Creating a Simple Batch File

One of the powerful capabilities built into Windows is the ability to create and use batch files to perform a wide variety of ...

Discover More
More WindowsTips

What is the Purpose of the Application Event Log?

The Application event log holds messages generated by applications and services. This tip explains more about it.

Discover More

What is the Purpose of the Forwarded Events Event Log?

The Forwarded Events event log collects events that have been forwarded from other computers. In this way you can login to ...

Discover More

Using the Event Viewer to Examine Remote Event Logs

Assuming you have proper access to remote computers, you can examine their event logs from your system without much trouble. ...

Discover More
Subscribe

FREE SERVICE: Get tips like this every week in WindowsTips, a free productivity newsletter. Enter your address and click "Subscribe."

View most recent newsletter.

Comments

If you would like to add an image to your comment (not an avatar, but an image to help in making the point of your comment), include the characters [{fig}] in your comment text. You’ll be prompted to upload your image when you submit the comment. Images larger than 600px wide or 1000px tall will be reduced. Up to three images may be included in a comment. All images are subject to review. Commenting privileges may be curtailed if inappropriate images are posted.

What is one less than 4?

2016-09-12 09:08:46

phantomphixer

Displaying "Event Viewer" in Win 10
1. Right click start up icon
2. Click on Event Viewer


2016-09-12 06:33:56

Shreepad S M Gandhi

Thanks Barry. Since I got to know about this for the first time, I followed exactly as explained here. Could successfully create a Custom View named 'Restarts' (for a run to check the occurrence of events in the last 12 hours.)
A small query. You have said,
"As it turns out, a Windows startup is denoted by the Event ID of 100, and a Windows shutdown is denoted by the Event ID of 200"
What all the other common Events and How do we know the Event ID's for these? Thanks a lot though


Newest Tips
Subscribe

FREE SERVICE: Get tips like this every week in WindowsTips, a free productivity newsletter. Enter your address and click "Subscribe."

(Your e-mail address is not shared with anyone, ever.)

View the most recent newsletter.