[Okta Webinar] Learn how to a build a cloud-first strategyRegister Now

x
  • Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 6731
  • Last Modified:

evtx viewer

Is there any free GUI software that can view/search evtx files (event viewer files)..
0
pma111
Asked:
pma111
  • 4
  • 2
  • 2
  • +2
4 Solutions
 
btanExec ConsultantCommented:
Ideally EVT Logparser
http://martin77s.wordpress.com/2010/01/16/evtlogparser/
http://computer.forensikblog.de/mt/mt-search.cgi?IncludeBlogs=3&tag=EvtxParser&limit=20

MyEventViewer (with 'Find By Event Description'. When this option is checked, the find feature also searches inside the description of the event.) http://www.nirsoft.net/utils/my_event_viewer.html

Event Log Explorer (has a free licence personal non-commercial use). It doesn't allow you to connect more then 3 computers. http://eventlogxp.com/features.html

Windows Event Viewer Plus is a portable freeware app but its search feature may not be evident and in depth http://www.thewindowsclub.com/windows-event-viewer-plus-v-1-0-released
0
 
pma111Author Commented:
Thanks is the nirsoft one only for the logs on the pc you run the software. Or can it view orphaned evtx files you have pulled from another system?
0
 
btanExec ConsultantCommented:
yes by default it is used to access the local or remote machine event viewer - just see it as another alternate viewer. It can still process file based using the /LoadFiles when you input as option when running the exe.

For example:
MyEventViewer.exe /LoadFiles "c:\temp\app.evt" "Application"
MyEventViewer.exe /LoadFiles "c:\temp\sec.evt" "Security" "c:\temp\app.evt" "Application"
MyEventViewer.exe /shtml "c:\temp\events1.html" /LoadFiles "c:\temp\sec.evt" "Security" "c:\temp\app.evt" "Application"
MyEventViewer.exe /remote \\MyComputerName
MyEventViewer.exe /remote \\192.168.0.1
0
Concerto Cloud for Software Providers & ISVs

Can Concerto Cloud Services help you focus on evolving your application offerings, while delivering the best cloud experience to your customers? From DevOps to revenue models and customer support, the answer is yes!

Learn how Concerto can help you.

 
trinitrotolueneCommented:
0
 
trinitrotolueneCommented:
0
 
SidCommented:
Event Log Explorer (has a free licence personal non-commercial use).
0
 
Joe Winograd, EE MVE 2015&2016DeveloperCommented:
I'm a huge fan of NirSoft's (free!) utilities, which I've been using for many years:
http://www.nirsoft.net/

One of them is MyEventViewer:
http://www.nirsoft.net/utils/my_event_viewer.html

Scroll to the bottom of the page at the above URL for the download links. Note that there are both 32-bit and 64-bit versions. It is a no-install/stand-alone executable — just unzip the file and run the EXE.

MyEventViewer allows you to view the events of another machine on your network, but you must have full admin access to the remote computer. To do this, use the "/remote" command line option and specify the name or address of the remote computer. For example:

MyEventViewer.exe /remote \\SmithComputer
MyEventViewer.exe /remote \\192.168.0.150

This blog entry explains how to get get full admin access to the remote computer:
http://blog.nirsoft.net/2009/10/22/how-to-connect-a-remote-windows-7vistaxp-computer-with-nirsoft-utilities/

Regards, Joe
0
 
btanExec ConsultantCommented:
yap EVTlog parser, MyeventViewer and Event Log Explorer are good to explore for your need ... eventually there are script for batch job
0
 
pma111Author Commented:
Ultimately though these are logs pulled from an old backup and not live local or remote analysis of current logs
0
 
btanExec ConsultantCommented:
good to test out to make the evtx or evt format is maintained since the tools is to work off offline extracted files
0

Featured Post

Hire Technology Freelancers with Gigs

Work with freelancers specializing in everything from database administration to programming, who have proven themselves as experts in their field. Hire the best, collaborate easily, pay securely, and get projects done right.

  • 4
  • 2
  • 2
  • +2
Tackle projects and never again get stuck behind a technical roadblock.
Join Now