Skip to content

Windows Event Viewer Basics for Administrators

Windows records operating-system and application events in event logs. Event Viewer provides a graphical way to browse and filter them; PowerShell can retrieve matching records for a focused check. An event is one piece of evidence: read its time, source, level, message, and surrounding events before deciding what it means.

The steps are read-only until the optional export. Do not clear logs as part of routine troubleshooting; preserve the original records according to your organization’s policy.


Step 1: Open Event Viewer

01

Launch the Windows Event Viewer Console

Open the Tool

Open Event Viewer from the Start menu or run eventvwr.msc. In the left pane, expand Windows Logs to see common channels. The exact available channels depend on Windows edition, installed components, and policy.

Press Win+R, enter eventvwr.msc, then press Enter.

Step 2: Choose a Log and Read an Event

02

Start with System or Application Events

Browse Events

Choose Windows Logs → System for operating-system and service events, or Application for application events. Select an event to read its General message and inspect details such as provider, event ID, level, and timestamp. The Security log may require elevated permissions and depends on enabled audit policy.

Event Viewer
└─ Windows Logs
├─ Application
├─ Security
└─ System
❯ View Expected Console Output
For each event, record:
Time created · Log name · Source/provider · Level · Event ID · Message

Step 3: Filter the Current Log

03

Narrow Events by Time, Level, or Source

Filter

In the right-side Actions pane, choose Filter Current Log. Set a time range and, when useful, a level or event source. Start with a broad enough window to include the symptoms before and after the reported time. Event IDs are provider-specific; do not assume the same ID means the same thing in every log.

Windows Logs → System → Actions → Filter Current Log...
Choose the time range and levels relevant to the incident.
❯ View Expected Console Output
The event list is filtered for the selected channel and criteria.
Choose Clear Filter from the Actions pane to return to the full log view.

Step 4: Query Recent Events with PowerShell

04

Filter Events Before Formatting the Results

PowerShell

Get-WinEvent can filter at the event-log source. This example requests up to 20 Error-level events from the System log created in the last two hours, then selects useful fields. If no events match, PowerShell may report that none were found; that does not prove the system has no issue.

Terminal window
$Query = @{
LogName = 'System'
Level = 2 # Error
StartTime = (Get-Date).AddHours(-2)
}
Get-WinEvent -FilterHashtable $Query -MaxEvents 20 |
Select-Object TimeCreated, Id, LevelDisplayName, ProviderName, Message |
Format-List
❯ View Expected Console Output
TimeCreated : 10/5/2026 9:14:03 AM
Id : 7000
LevelDisplayName : Error
ProviderName : Service Control Manager
Message : The service failed to start.

Step 5: Save an Event Log When Evidence Must Be Preserved

05

Export a Copy to an Approved Evidence Location

Preserve Records

If an investigation or change record requires a copy, select Save All Events As… for the full channel or Save Filtered Log File As… for the filtered view. Save as an Event Log file (.evtx) in a restricted location approved for logs, and record the channel, time range, operator, and export time. Do not choose Clear Log.

Actions → Save All Events As... (full channel)
Actions → Save Filtered Log File As... (filtered view)
File type: Event Files (*.evtx)
❯ View Expected Console Output
The exported .evtx is a separate copy. The source event log remains on the host.

References

Comments