Search Multiple Event Log Files

Posted on 2012-08-22
Last Modified: 2012-08-22
I am saving my file share audit log files in 20 MB increments to a share.  They are .EVT format (classic windows event log).  I can easily convert them to .EVTX, but I occasionally need to search 4 days worth of logs for a specific entry.  I really have no easy method of searching 100 .EVT or .EVTX files for a specific entry.  Any help would be greatly appreciated.
Question by:BDizzle
    LVL 12

    Expert Comment

    LVL 43

    Expert Comment

    by:Steve Knight
    Have you looked at logparser?

    You should be able to use a for loop to run it against multiple, e.g. something like this (sorry not got to hand to test at the mo.)


    @echo off
    cd /d "C:\root\of\evt area"
    for /f "tokens=*" %%f in ('dir /b /a-d /s *.evt') do (
     echo Looking at %%f
    " c:\program files\log parser 2.2\logparser" -c -i:EVT -o:TEXLINE "%%~f" output.csv
    LVL 43

    Expert Comment

    by:Steve Knight
    and build your query into logparser command, or export the lot to CSV or whatever and search that.
    LVL 12

    Accepted Solution


    Author Comment

    I had tried event eventlog parser with no success.  I probably had the syntax wrong...  I will look at some of those tools listed.

    Author Closing Comment

    Installed splunk, and indexed within 20 minutes.  Found what I needed right away!  Thanks!

    Featured Post

    How to run any project with ease

    Manage projects of all sizes how you want. Great for personal to-do lists, project milestones, team priorities and launch plans.
    - Combine task lists, docs, spreadsheets, and chat in one
    - View and edit from mobile/offline
    - Cut down on emails

    Join & Write a Comment

    Introduction During my participation as a VBScript contributor at Experts Exchange, one of the most common questions I come across is this: "I have a script that runs against only one computer. How can I make it run against a list of computers in …
    This article is the result of a quest to better understand Task Scheduler 2.0 and all the newer objects available in vbscript in this version over  the limited options we had scripting in Task Scheduler 1.0.  As I started my journey of knowledge I f…
    Need more eyes on your posted question? Go ahead and follow the quick steps in this video to learn how to Request Attention to your question. *Log into your Experts Exchange account *Find the question you want to Request Attention for *Go to the e…
    To add imagery to an HTML email signature, you have two options available to you. You can either add a logo/image by embedding it directly into the signature or hosting it externally and linking to it. The vast majority of email clients display l…

    755 members asked questions and received personalized solutions in the past 7 days.

    Join the community of 500,000 technology professionals and ask your questions.

    Join & Ask a Question

    Need Help in Real-Time?

    Connect with top rated Experts

    24 Experts available now in Live!

    Get 1:1 Help Now