Link to home
Start Free TrialLog in
Avatar of Pau Lo
Pau Lo

asked on

event logs specific to power on/off (windows 7)

are there any specific event logs on windows (windows 7) that indicate the exact time a machine was powered on and off. I know from analysis and testing of security.evtx its pretty close if you pick the first and last event of the day to the time a machine has been on/off but I did wonder if there was an exact event in one of the windows and/or applications and services logs which would specifically relate to power on/off for a laptop device.
ASKER CERTIFIED SOLUTION
Avatar of ☠ MASQ ☠
☠ MASQ ☠

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of Pau Lo
Pau Lo

ASKER

MASQ, thank you. Are they in a particular log/or spread across multiple  e.g. security.evtx? I need to pull them out of an image of a HDD rather than a live running system.
They will all be in the System Event log file but they are spread around at least half a dozen different Sources:

12 - Kernel General
13 - Kernel General
20 - Kernel Boot
109 - Kernel Power
1074 - User32
6005 - Event Log
6006 - Event Log
6013 - Event Log