evtx viewer

Is there any free GUI software that can view/search evtx files (event viewer files)..
LVL 3
pma111Asked:
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

btanExec ConsultantCommented:
Ideally EVT Logparser
http://martin77s.wordpress.com/2010/01/16/evtlogparser/
http://computer.forensikblog.de/mt/mt-search.cgi?IncludeBlogs=3&tag=EvtxParser&limit=20

MyEventViewer (with 'Find By Event Description'. When this option is checked, the find feature also searches inside the description of the event.) http://www.nirsoft.net/utils/my_event_viewer.html

Event Log Explorer (has a free licence personal non-commercial use). It doesn't allow you to connect more then 3 computers. http://eventlogxp.com/features.html

Windows Event Viewer Plus is a portable freeware app but its search feature may not be evident and in depth http://www.thewindowsclub.com/windows-event-viewer-plus-v-1-0-released
0

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
pma111Author Commented:
Thanks is the nirsoft one only for the logs on the pc you run the software. Or can it view orphaned evtx files you have pulled from another system?
0
btanExec ConsultantCommented:
yes by default it is used to access the local or remote machine event viewer - just see it as another alternate viewer. It can still process file based using the /LoadFiles when you input as option when running the exe.

For example:
MyEventViewer.exe /LoadFiles "c:\temp\app.evt" "Application"
MyEventViewer.exe /LoadFiles "c:\temp\sec.evt" "Security" "c:\temp\app.evt" "Application"
MyEventViewer.exe /shtml "c:\temp\events1.html" /LoadFiles "c:\temp\sec.evt" "Security" "c:\temp\app.evt" "Application"
MyEventViewer.exe /remote \\MyComputerName
MyEventViewer.exe /remote \\192.168.0.1
0
What were the top attacks of Q1 2018?

The Threat Lab team analyzes data from WatchGuard’s Firebox Feed, internal and partner threat intelligence, and a research honeynet, to provide insightful analysis about the top threats on the Internet. Check out our Q1 2018 report for smart, practical security advice today!

trinitrotolueneDirector - Software EngineeringCommented:
0
trinitrotolueneDirector - Software EngineeringCommented:
0
SidTechnical SpecialistCommented:
Event Log Explorer (has a free licence personal non-commercial use).
0
Joe Winograd, Fellow&MVEDeveloperCommented:
I'm a huge fan of NirSoft's (free!) utilities, which I've been using for many years:
http://www.nirsoft.net/

One of them is MyEventViewer:
http://www.nirsoft.net/utils/my_event_viewer.html

Scroll to the bottom of the page at the above URL for the download links. Note that there are both 32-bit and 64-bit versions. It is a no-install/stand-alone executable — just unzip the file and run the EXE.

MyEventViewer allows you to view the events of another machine on your network, but you must have full admin access to the remote computer. To do this, use the "/remote" command line option and specify the name or address of the remote computer. For example:

MyEventViewer.exe /remote \\SmithComputer
MyEventViewer.exe /remote \\192.168.0.150

This blog entry explains how to get get full admin access to the remote computer:
http://blog.nirsoft.net/2009/10/22/how-to-connect-a-remote-windows-7vistaxp-computer-with-nirsoft-utilities/

Regards, Joe
0
btanExec ConsultantCommented:
yap EVTlog parser, MyeventViewer and Event Log Explorer are good to explore for your need ... eventually there are script for batch job
0
pma111Author Commented:
Ultimately though these are logs pulled from an old backup and not live local or remote analysis of current logs
0
btanExec ConsultantCommented:
good to test out to make the evtx or evt format is maintained since the tools is to work off offline extracted files
0
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Microsoft Legacy OS

From novice to tech pro — start learning today.

Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.