Windows Event Log Viewer Windows Event Log Viewer

Download Windows Event Log Viewer & Monitoring Software

Windows Event Log Viewer & Monitoring Software opens live Windows logs and .evtx files brought from another PC, explains what each Event ID means, and alerts you when a rule you set fires.

Windows 11 / 10Free trial, no sign-up
Windows Event Log Viewer Screenshot.
A server reboots at three in the morning and nobody knows why. A user cannot sign in and swears the password is right. Windows already wrote the answer down. SoftOrbits Windows Event Log Viewer opens the event log, filters it to the events that matter, and explains each one in plain words. It reads the live logs of your own PC, the same logs on computers you administer, and files copied from someone else's.

How to download and use the Windows Event Log Viewer & Monitoring Software

Install it.
1

Install it

Download the Windows Event Log Viewer & Monitoring Software and run the installer. No account or e-mail address is required. The program opens on an empty window with that machine's log tree on the left, so every log is one click away.

Open a log.
2

Open a log

Pick any live log on the machine, or open an .evtx file a colleague sent you. A log of 34,215 records is indexed in under half a second. A file with 300,000 records takes about four seconds the first time; after that, jumps through it take milliseconds.

Cut it down to the incident.
3

Cut it down to the incident

Set a time window, level, Event ID or account name. Three theories get tested in a minute. The Event ID box also takes ranges and exclusions, such as 10,100-200!150.

Read it, then watch for it.
4

Read it, then watch for it

Open an event and the built-in reference explains its code and fields in plain words. Make a rule for an event that must never pass unnoticed, and the program monitors the event log for you. The next one appears in your tray while you work in another window.

Read the log on the machine down the hall.

Read the log on the machine down the hall

Windows Event Log Viewer & Monitoring Software reads event logs from other computers across the network. A connected machine sits in the same tree as your own PC, with every log one click away. In a domain, it uses the Windows account you already work under and asks for no password. Anywhere else, enter a user and password once. The password stays in memory while the program is open and is never saved. The connection uses RPC, so the remote computer must allow remote event log access through its firewall, the same rule Event Viewer needs. The built-in network scan checks a /24 subnet in about four seconds and reports which of its 254 addresses answer.

Forensic Mode finds records the log no longer has

Every EVTX block starts with the same eight bytes and is exactly 65,536 bytes long. Forensic Mode uses that structure to walk a file, disk image or entire drive byte by byte, ignoring the file header and finding blocks the normal reader cannot reach. It can recover records left in free space after a log was deleted or rotated, and read a log with a destroyed header. On a test file with its header wiped, it recovered 23,367 events from 316 blocks in about a second and a half. Duplicate blocks are recognised and shown once, so a drive scan does not show the same events three times. In the program, it is in the File menu as 'Deep scan for lost events'.

Forensic Mode finds records the log no longer has.
The one line that explains the outage.

The one line that explains the outage

Windows Event Log Viewer & Monitoring Software narrows a System log of 34,232 records to the 615 matching your filter in 49 ms. You can test another idea immediately.

Event ID 41 finally says something

The honest translation of Event ID 41 is 'the machine went down without a clean shutdown'. The log itself never says that. Windows keeps event wording inside the program that wrote it, so a log carried over from another PC usually says 'The description for Event ID cannot be found'. Our reference explains 181 events in normal language. On the working Windows box we measured it against, that covered 94.6 percent of the log.

Event ID 41 finally says something.
You hear about it before the user calls.

You hear about it before the user calls

Failed sign-ins every ten minutes look like an attack on a chart. Windows event log monitoring here is one rule: this Event ID, this log, this account. The program keeps reading the log while you work, then puts a notice in the tray. The rule we tested on 4625 fired on a real failed sign-in, not on a synthetic event planted for the screenshot.

Opens the log the built-in viewer refuses

'The event log file is corrupted (1500)' is where Event Viewer gives up, often because the header broke while the events remain. Forensic Mode reads past the broken header and pulls the records out. It also opens a file copied from a PC that will not boot.

Opens the log the built-in viewer refuses.

Two logs, one timeline

Merge the Application and System event logs into one timeline and sort them together: 57,609 events resorted in 16 ms. When several records carry the same field value, follow the chain. On a busy Application log, that reduced 23,321 lines to the 419 belonging to the same incident in 43 ms.

Ready-made breakdowns

Fifteen prepared views cover common searches: who signed in, who failed to sign in, why the computer restarted, new services, and disk and file system problems. Pick one, then narrow it with a text search over the whole log.

Export that fits the report

The export writes CSV and Excel for numbers, HTML and PDF for an incident report, and rows directly into an MS SQL Server table. 23,317 rows landed there in 3.5 seconds, with the count matching a second count from a separate SQL client.

Your setup is still there tomorrow

Workspaces save tabs, filters and columns, so you can reopen the same investigation next week. Two tabs came back with 1,978 and 4,604 events under the same conditions. A snapshot freezes the selection itself, so nothing in it moves later.

The event log analyzer view

The summary view groups a log by source, code or day, so you can see that one driver produced most of yesterday's errors before reading a record. Add a field as your own column when it is missing from the standard grid.

Every log, live or on disk

It opens live Application, System, Security and Setup logs, plus everything under Applications and Services Logs. It also opens files, including one a colleague mailed you and the legacy .evt left by XP and Server 2003 boxes.

Windows Event Log Viewer
Windows Event Log ViewerDownload the Windows Event Log Viewer & Monitoring Software, open the log that has been bothering you all week, and find out what actually happened.

Who needs Windows Event Log Viewer & Monitoring Tool

For IT admins

One person keeps twenty machines alive. When the file server restarts at night, Event ID 1074 or 41 gives you the answer, but finding it and showing it to the boss takes ten minutes.

For helpdesk and outsourced IT

Logs reach you as an attachment from a client whose network you cannot enter. The file opens with its events explained, so the answer comes from the log.

For power users

Your own PC drops out of a game and reboots itself, or shows a blue screen. Read 6008 and 41, see when it started, and check what happened just before.

Windows Event Log Viewer
Windows Event Log Viewer
Price
from $ 39.99 / month
Version
3.2
File Size
72 Mb
Last updated on
10/09/26
System Requirements
  • Windows 11/10/8.1/8/7 (32/64 bit)
  • Intel i3, AMD Ryzen 5 or above
  • 4 GB of RAM or above
  • NVIDIA® GeForce® series 8 and 8M, Intel® HD Graphics 2000, Quadro FX 4800, Quadro FX 5600, AMD Radeon™ R600, Mobility Radeon™ HD 4330, Mobility FirePro™ series, Radeon™ R5 M230 or higher graphics card with up-to-date drivers
  • 1280 × 768 screen resolution, 32-bit color
  • 1 GB of free hard disk space or above

Frequently Asked Questions

In C:\\Windows\\System32\\winevt\\Logs. It is the Windows event log location, with one .evtx file per log named after it. When a machine will not boot, pull the file from that folder with a rescue disk and read it on a PC that still works.

Open the file from the program, or double-click it in Explorer once the association is set. It reads like a log from your own machine, with no import step and nothing installed on the machine the file came from. The descriptions are still there, unlike what a foreign log normally gives you.

EVTX is the binary log format Windows has used since Vista. It is written in blocks and cannot be read in a text editor. Older Windows XP and Server 2003 machines wrote .evt instead. This log file viewer reads both.

The Security event log uses Event ID 4625 for a failure and 4624 for a success. Read the logon type next to the number: type 2 is somebody at the keyboard, type 3 is a network login, and type 10 is remote desktop, which matters when failures come at four in the morning.

This is event log monitoring software with a viewer attached. It reads logs on the machines you work with and warns you on your own PC according to the rules you set. It runs without a collection server or agents. Open a log, or leave a rule watching one.

Filter first, export second. The program exports what is on the screen, not the whole log. Push the data into a SQL table when it has to outlive the ticket and query it there next quarter.

Try Deep Scan before writing the file off. It looks for the records themselves and puts back what it can find. A file that lost its tail lost those events for good. Copy the damaged file first and work on the copy.

For the Security log, yes. Windows itself asks for those rights. Most other logs open under a normal account. An .evtx file on your desktop needs no rights.

Both. Counts by source and code, two logs merged into one timeline, related records pulled into a chain, and results pushed into a SQL table when the answer has to outlive the ticket.

Rate Windows Event Log Viewer

  • Windows 7
  • Windows 8
  • Windows 10
  • Windows 11
Author: SoftOrbits (English)
4.5
Avg. rating: 4.5 from 827 votes
Good

Risk-free download

progressive-webapps/apis/offline-first Created with Sketch.
100% offline
Your files never leave your PC
Safe & secure download
Directly from the official website
No sign-up required
No account or email to get started
Trusted since 2006
Desktop software for Windows