Still celebrating National IT Professionals Day with 3 months of free Premium Membership. Use Code ITDAY17

x
?
Solved

windows 8 audit log files location

Posted on 2014-12-30
3
Medium Priority
?
463 Views
Last Modified: 2014-12-31
On a windows 8 PC, what is the actual file which stores local logon events. We have a copy of all files from a Windows 8 PC, and need some utility to review the actual audit log events, but need to know whcih file they are stored in first (and where that file lives by default), plus any suggestions on a tool which can take orphansed event log files and produce a report from them (i.e. allow you to filter for logon events).
0
Comment
Question by:pma111
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
3 Comments
 
LVL 98

Accepted Solution

by:
John Hurst earned 668 total points
ID: 40523604
The Event Logs are stored here:

C:\Windows\System32\winevt\Logs

I do not know how easily they can be moved or viewed. Here is an older Microsoft Technical Article that you may be able to adapt.

https://support.microsoft.com/kb/315417
0
 
LVL 83

Assisted Solution

by:David Johnson, CD, MVP
David Johnson, CD, MVP earned 668 total points
ID: 40523827
you can open them in the event viewer
0
 
LVL 56

Assisted Solution

by:McKnife
McKnife earned 664 total points
ID: 40524004
...and the particular file is security.evtx
0

Featured Post

Concerto Cloud for Software Providers & ISVs

Can Concerto Cloud Services help you focus on evolving your application offerings, while delivering the best cloud experience to your customers? From DevOps to revenue models and customer support, the answer is yes!

Learn how Concerto can help you.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This article is a collection of issues that people face from time to time and possible solutions to those issues. I hope you enjoy reading it.
This article helps those who get the 0xc004d307 error when trying to rearm (reset the license) Office 2013 in a Virtual Desktop Infrastructure (VDI) and/or those trying to prep the master image for Microsoft Key Management (KMS) activation. (i.e.- C…
This Micro Tutorial hows how you can integrate  Mac OSX to a Windows Active Directory Domain. Apple has made it easy to allow users to bind their macs to a windows domain with relative ease. The following video show how to bind OSX Mavericks to …
Finding and deleting duplicate (picture) files can be a time consuming task. My wife and I, our three kids and their families all share one dilemma: Managing our pictures. Between desktops, laptops, phones, tablets, and cameras; over the last decade…

704 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question