Windows Event Viewer Basics for Administrators
Windows records operating-system and application events in event logs. Event Viewer provides a graphical way to browse and filter them; PowerShell can retrieve matching records for a focused check. An event is one piece of evidence: read its time, source, level, message, and surrounding events before deciding what it means.
The steps are read-only until the optional export. Do not clear logs as part of routine troubleshooting; preserve the original records according to your organization’s policy.
Step 1: Open Event Viewer
Launch the Windows Event Viewer Console
Open the ToolOpen Event Viewer from the Start menu or run eventvwr.msc. In the left pane, expand Windows Logs to see common channels. The exact available channels depend on Windows edition, installed components, and policy.
Press Win+R, enter eventvwr.msc, then press Enter.Start-Process eventvwr.mscStep 2: Choose a Log and Read an Event
Start with System or Application Events
Browse EventsChoose Windows Logs → System for operating-system and service events, or Application for application events. Select an event to read its General message and inspect details such as provider, event ID, level, and timestamp. The Security log may require elevated permissions and depends on enabled audit policy.
Event Viewer└─ Windows Logs ├─ Application ├─ Security └─ System❯ View Expected Console Output
For each event, record:Time created · Log name · Source/provider · Level · Event ID · MessageStep 3: Filter the Current Log
Narrow Events by Time, Level, or Source
FilterIn the right-side Actions pane, choose Filter Current Log. Set a time range and, when useful, a level or event source. Start with a broad enough window to include the symptoms before and after the reported time. Event IDs are provider-specific; do not assume the same ID means the same thing in every log.
Windows Logs → System → Actions → Filter Current Log...Choose the time range and levels relevant to the incident.❯ View Expected Console Output
The event list is filtered for the selected channel and criteria.Choose Clear Filter from the Actions pane to return to the full log view.Step 4: Query Recent Events with PowerShell
Filter Events Before Formatting the Results
PowerShellGet-WinEvent can filter at the event-log source. This example requests up to 20 Error-level events from the System log created in the last two hours, then selects useful fields. If no events match, PowerShell may report that none were found; that does not prove the system has no issue.
$Query = @{ LogName = 'System' Level = 2 # Error StartTime = (Get-Date).AddHours(-2)}
Get-WinEvent -FilterHashtable $Query -MaxEvents 20 | Select-Object TimeCreated, Id, LevelDisplayName, ProviderName, Message | Format-List❯ View Expected Console Output
TimeCreated : 10/5/2026 9:14:03 AMId : 7000LevelDisplayName : ErrorProviderName : Service Control ManagerMessage : The service failed to start.Step 5: Save an Event Log When Evidence Must Be Preserved
Export a Copy to an Approved Evidence Location
Preserve RecordsIf an investigation or change record requires a copy, select Save All Events As… for the full channel or Save Filtered Log File As… for the filtered view. Save as an Event Log file (.evtx) in a restricted location approved for logs, and record the channel, time range, operator, and export time. Do not choose Clear Log.
Actions → Save All Events As... (full channel)Actions → Save Filtered Log File As... (filtered view)File type: Event Files (*.evtx)❯ View Expected Console Output
The exported .evtx is a separate copy. The source event log remains on the host.