If there is one, a friend tells you that there is a problem with his computer. Maybe, you need to analyze the event log of its system
. After all, in the Windows system, the system event log records too much information, application usage, crashes and other records, Windows system various event records and so on. However, when your friend sends the log in his Windows directory and you want to view and analyze it, I find that the event log crashes!
What is going on here?
The reason is very simple. The event log before Vista
is the .evt file, Vista and the .evtx file!
We can use the Log Parser 2.2 provided by Microsoft (click to enter the official Microsoft page), it can parse the respective supported formats on the corresponding system, the parsing command is:
logparser -i: EVT "SELECT * INTO a.csv FROM b.evt"
but if in Vista, Windows Server 2008, Windows7 and after parsing .evt format may be prompted to log event log on the system crashes, then you need to. The evt format is converted to the .evtx format. Fortunately, Vista and later systems provide the Wevtutil-Windows Events Command Line Utility tool!
Run the command: wevtutil epl application.evt application.evtx /lf:true to convert.
wevtutil The prompts in the system are all in English,:
Windows Events Command Line Utility.
Enables you to retrIEve information about event logs and Publisher
s, install
and uninstall event manifests, run querIEs, and export, archive, and clear logs.
Usage:
You can use either the short (for example , ep /uni) or long (for example,
enum-publishers /unicode) version of the command and option names. Commands,
options and option values are not case-sensitive.
Variables Are noted in all upper-case.
wevtutil COMMAND [ARGUMENT [ARGUMENT] ...] [/OPTION:VALUE [/OPTION:VALUE] ...]
Commands:
el
Now slowly enter the Windows7 era, writing this thing should have no epochal significance. But still
Vista and Server 2008 under how to set up stereo mix recording, this paper gives us solution
SanDisk is an important SSD storage device manufacturer in the world. On Monday, they commented that
Compared to Windows XP, Vista has slightly different startup options. In XP, the user must s
What is a Windows service, how to delete a Windows service
Windows Vista system common patch function introduction
Vista application 0XC00000xx error resolution
Vista system can not see the problem of hidden folders
Realtek HD Audio Driver 2.26 version For Vista/Windows 7
Error code 1450 meaning related issues
EasyBcd software fixes dual-boot issues with Vista and XP
How to crack Vista login password
Vista can't use input method normally
No longer let Vista Explorer display a folder link
Share a lot of details about Vista SP1 that Microsoft revealed.
Win10 install GeForce latest 364.47 driver blue screen how to do
How to set up Win10 to allow applications to communicate through Windows Firewall
Win8 reader how to directly view the pdf file
Win7 system start menu bar blank solution
How to restore the NumLock key of the Win7 keypad?
How to completely shut down the win7 offline file service?
Reasons for IIS to fail gzip open: wildcard application mapping