Solved

windows 8 audit log files location

Posted on 2014-12-30
3
450 Views
Last Modified: 2014-12-31
On a windows 8 PC, what is the actual file which stores local logon events. We have a copy of all files from a Windows 8 PC, and need some utility to review the actual audit log events, but need to know whcih file they are stored in first (and where that file lives by default), plus any suggestions on a tool which can take orphansed event log files and produce a report from them (i.e. allow you to filter for logon events).
0
Comment
Question by:pma111
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
3 Comments
 
LVL 96

Accepted Solution

by:
Experienced Member earned 167 total points
ID: 40523604
The Event Logs are stored here:

C:\Windows\System32\winevt\Logs

I do not know how easily they can be moved or viewed. Here is an older Microsoft Technical Article that you may be able to adapt.

https://support.microsoft.com/kb/315417
0
 
LVL 82

Assisted Solution

by:David Johnson, CD, MVP
David Johnson, CD, MVP earned 167 total points
ID: 40523827
you can open them in the event viewer
0
 
LVL 55

Assisted Solution

by:McKnife
McKnife earned 166 total points
ID: 40524004
...and the particular file is security.evtx
0

Featured Post

Optimize your web performance

What's in the eBook?
- Full list of reasons for poor performance
- Ultimate measures to speed things up
- Primary web monitoring types
- KPIs you should be monitoring in order to increase your ROI

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Windows 10 Creator Update has just been released and I have it working very well on my laptop. Read below for issues, fixes and ideas.
In this post we will be converting StringData saved within a text file into a hash table. This can be further used in a PowerShell script for replacing settings that are dynamic in nature from environment to environment.
This is used to tweak the memory usage for your computer, it is used for servers more so than workstations but just be careful editing registry settings as it may cause irreversible results. I hold no responsibility for anything you do to the regist…
Get a first impression of how PRTG looks and learn how it works.   This video is a short introduction to PRTG, as an initial overview or as a quick start for new PRTG users.
Suggested Courses

628 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question