Windows Event Log Viewer & Monitoring Software opens live Windows logs and .evtx files brought from another PC, explains what each Event ID means, and alerts you when a rule you set fires.
Download the Windows Event Log Viewer & Monitoring Software and run the installer. No account and no e-mail address are asked for. It starts on an empty window with the log tree of that machine on the left, so any of them is one click away.
Pick any live log on the machine, or open an .evtx file a colleague sent you. A log of 34,215 records is indexed in under half a second. A file with 300,000 records takes about four seconds the first time, after that any jump through it costs milliseconds.
Set a time window, a level, an Event ID or an account name. Three theories get tested in a minute, where scrolling the raw list eats an evening. The Event ID box takes ranges and exclusions too, like 10,100-200!150.
Open an event and the built-in reference explains the code and its fields in plain words. If that event must never pass unnoticed again, make a rule and let the program monitor the event log for you. The next one lands in your tray while you are in another window.
The log you need is rarely on the computer you are sitting at. Windows Event Log Viewer & Monitoring Software reads the event logs of other computers across the network. A machine you connect to sits in the same tree as your own PC, one click away from every log on it. In a domain it connects with the Windows account you already work under and asks for no password at all. Anywhere else you give a user and a password once, and that password lives in memory while the program is open and is never saved anywhere. It all goes over RPC, so the far computer has to allow remote event log access through its firewall - the same rule Event Viewer itself needs. Not sure which computers are even up? The built-in network scan walks a /24 subnet in about four seconds and reports which of the 254 addresses answer.
Every block of an EVTX file starts with the same eight bytes and is exactly 65,536 bytes long. Forensic Mode leans on that. It ignores the file header completely and walks a file, a disk image or an entire drive byte by byte, picking up blocks the normal reader can never reach. Records left in free space after a log was deleted or rotated. A log whose header is destroyed - on a test file with the header wiped it pulled out 23,367 events from 316 blocks in about a second and a half. The same block found twice is recognised and shown once, so a drive scan does not read you the same events three times. In the program it sits in the File menu as 'Deep scan for lost events'.
A Windows log is not hard to read. It is hard to read forty thousand times. Windows Event Log Viewer & Monitoring Software narrows a System log of 34,232 records down to the 615 that match your filter in 49 ms. You stop scrolling. You start testing ideas, and a wrong idea costs nothing but the next try.
The honest translation of Event ID 41 is 'the machine went down without a clean shutdown'. The log itself never says that anywhere. Windows keeps the wording of events inside the program that wrote them, so a log carried over from another PC usually answers with 'The description for Event ID cannot be found'. That gap is why we wrote our own reference. It explains 181 events in normal language. On the working Windows box we measured it against, that covered 94.6 percent of the log.
Failed sign-ins every ten minutes look like nothing in a list and like an attack on a chart. Windows event log monitoring here is one rule: this Event ID, this log, this account. The program keeps reading the log while you work on something else, then puts a notice in the tray. The rule we tested on 4625 fired on a real failed sign-in, not on a synthetic event planted for the screenshot.
'The event log file is corrupted (1500)' is where Event Viewer gives up, and often the part that broke is the header, not the events. Forensic Mode above reads straight past the broken header and pulls the records out anyway. Same goes for a PC that will not boot, when the one thing you managed to copy off it was the file itself. It opens here like any other log, and an empty console that hangs after a Windows update stops being your problem.
Merge the Application and System event logs into a single timeline and sort them as one: 57,609 events from two logs, resorted in 16 ms. When several records carry the same field value, follow the chain: on a busy Application log that took 23,321 lines down to the 419 belonging to the same incident, in 43 ms.
Fifteen prepared views cover what gets looked for most. Who signed in, and who failed to. Why the computer restarted. New services installed, disk and file system problems. Pick one instead of building the filter by hand, then narrow it further with a text search over the whole log.
The export writes CSV and Excel for whoever asked for numbers, HTML and PDF for the incident report. Rows can also go straight into a table in MS SQL Server. 23,317 of them landed there in 3.5 seconds, and the row count matched when we counted them again from a separate SQL client.
Workspaces cover what event log management tools promise a single admin. Save tabs, filters and columns, then reopen the same investigation next week: two tabs came back with 1,978 and 4,604 events under the same conditions. A snapshot freezes the selection itself. Nothing in it moves later.
The summary view groups a log by source, by code or by day, so you see already that one driver produced most of yesterday's errors before reading a single record. That is the event log analyzer half of the work. And when the field you need is not in the standard grid, add it as a column of your own.
It opens the live logs of the machine - Application and System, Security and Setup, plus everything filed under Applications and Services Logs. Files as well: the one a colleague mailed you, and the legacy .evt left behind by XP and Server 2003 boxes.
One person keeps twenty machines alive. When the file server restarts at night, the whole answer is Event ID 1074 or 41 plus ten minutes it takes to find it and show to the boss.
Logs reach you as attachment from a client whose network you cannot enter. The file opens with its events explained, so the answer comes out of the log instead of another 'please try again tomorrow'.
Your own PC drops out of a game and reboots itself, or shows a blue screen. Instead of guessing which part is dying, you read 6008 and 41, see the day when it started, and look what happened right before.
Windows Event Log Viewer
72 Mb
3.2
27/07/26