system logs,troubleshoot thru windows (GCCS) Flashcards

Accessing system logs is essential for troubleshooting and resolving issues on both Windows and Linux systems

1
Q

1
Steps to Access Event Viewer:
Open Event Viewer:
1) Press [Win + R]
to open the Run dialog box.
2) Type [eventvwr] and press
Enter
. This will open the Event Viewer.

A

2Navigating Event Viewer:

The left-hand pane contains several categories of logs, including:
Windows Logs
Application: Events logged by applications.
Security: Security-related events like login attempts.
System: Events logged by Windows system components.
Setup: Events related to application setup.
Forwarded Events: Events collected from remote computers.
Application and Services Logs: Logs for specific applications and services

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

3
Viewing Logs:

Click on a log category (e.g., System) to view events.
In the middle pane, you will see a list of events. Details for each event can be viewed by clicking on it.
The Details pane at the bottom provides more detailed information about the selected event.

A

4
Filtering Events:

You can filter the events for easier navigation by clicking on Filter Current Log in the right-hand pane and setting the desired criteria.
Saving and Exporting Logs:

To save or export a log, click Save All Events As from the right-hand pane and choose the desired format
.evtx or .txt).

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Example Command Usage Windows Event Viewer

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly