Solved

Event viewer not recording events anymore

Posted on 2007-11-16
6
1,791 Views
Last Modified: 2010-04-21
The event viewer on my Windows Xp install has stopped recording events. It does record something, such as DCOM errors and some information on services, but very few events get recorded. Windows startup and shutdown are not recorded anymore, system errors aren't either.

I am not using filters by the way, the viewer is setup to show all events.

I have uploaded the logs to my site:

http://www.deathless.it/ApplicationEvents.txt
http://www.deathless.it/ProtectionEvents.txt
http://www.deathless.it/SystemEvents.txt

Does anyone know a way to fix the viewer?
0
Comment
Question by:Daniele Brunengo
6 Comments
 
LVL 8

Expert Comment

by:devil_himself
ID: 20297474
Try This

Start > Run > eventvwr.msc > In The Console Tree >Select the Log Type like":Application" > Go To Action > Properties  :---

1.Clear All Your Logs
2.Set your log size to some value of 128MB.
3.Set the log to "Overwrite Events As Needed"
0
 
LVL 9

Expert Comment

by:binary_1001010
ID: 20297589
like what devil said, you might need to clear your log, sometime out of no reason they will get corrupted. if you are concern about auditing, you can save the log first before clearing.
0
 
LVL 83

Accepted Solution

by:
oBdA earned 500 total points
ID: 20297594
Could be that the event logs are corrupt.
Set the startup type of the Event Log Service to "Disabled", reboot.
Rename all .evt files in %Systemroot%\system32\config.
Set the startup type of the Event Log Service back to "Automatic", reboot.
Check the event logs.

How to Delete Corrupt Event Viewer Log Files
http://support.microsoft.com/?kbid=172156
0
Ransomware-A Revenue Bonanza for Service Providers

Ransomware – malware that gets on your customers’ computers, encrypts their data, and extorts a hefty ransom for the decryption keys – is a surging new threat.  The purpose of this eBook is to educate the reader about ransomware attacks.

 

Author Closing Comment

by:Daniele Brunengo
ID: 31409532
Thanks, it worked perfectly.
0
 
LVL 9

Expert Comment

by:binary_1001010
ID: 20302873
.......
0
 
LVL 83

Expert Comment

by:oBdA
ID: 20304172
binary_1001010,
JFTR: trying to clear a *corrupt* event log from the event viewer accomplishes nothing. The only way to recover from this is to recreate the log files from scratch as described above.
0

Featured Post

The Eight Noble Truths of Backup and Recovery

How can IT departments tackle the challenges of a Big Data world? This white paper provides a roadmap to success and helps companies ensure that all their data is safe and secure, no matter if it resides on-premise with physical or virtual machines or in the cloud.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Today, still in the boom of Apple, PC's and products, nearly 50% of the computer users use Windows as graphical operating systems. If you are among those users who love windows, but are grappling to keep the system's hard drive optimized, then you s…
It’s been over a month into 2017, and there is already a sophisticated Gmail phishing email making it rounds. New techniques and tactics, have given hackers a way to authentically impersonate your contacts.How it Works The attack works by targeti…
In this video, we discuss why the need for additional vertical screen space has become more important in recent years, namely, due to the transition in the marketplace of 4x3 computer screens to 16x9 and 16x10 screens (so-called widescreen format). …
Windows 8 came with a dramatically different user interface known as Metro. Notably missing from that interface was a Start button and Start Menu. Microsoft responded to negative user feedback of the Metro interface, bringing back the Start button a…

776 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question