system logs,troubleshoot thru windows (GCCS) Flashcards
Accessing system logs is essential for troubleshooting and resolving issues on both Windows and Linux systems
1
Steps to Access Event Viewer:
Open Event Viewer:
1) Press [Win + R]
to open the Run dialog box.
2) Type [eventvwr] and press
Enter
. This will open the Event Viewer.
2Navigating Event Viewer:
The left-hand pane contains several categories of logs, including:
Windows Logs
Application: Events logged by applications.
Security: Security-related events like login attempts.
System: Events logged by Windows system components.
Setup: Events related to application setup.
Forwarded Events: Events collected from remote computers.
Application and Services Logs: Logs for specific applications and services
3
Viewing Logs:
Click on a log category (e.g., System) to view events.
In the middle pane, you will see a list of events. Details for each event can be viewed by clicking on it.
The Details pane at the bottom provides more detailed information about the selected event.
4
Filtering Events:
You can filter the events for easier navigation by clicking on Filter Current Log in the right-hand pane and setting the desired criteria.
Saving and Exporting Logs:
To save or export a log, click Save All Events As from the right-hand pane and choose the desired format
.evtx or .txt).
Example Command Usage Windows Event Viewer