Event Viewer
Event Viewer (eventvwr.msc) shows the event logs in which Windows, services and apps record information, warnings and errors. It is the first place to look after a crash, an unexpected restart or a failing driver or update. Many errors in the logs are harmless; what matters is what happened at the time of the problem.
1The main logs
Windows Logs > System records drivers, services and the start and shutdown of Windows. Windows Logs > Application records app errors. Applications and Services Logs contain detailed logs of individual components, for example Microsoft > Windows > WindowsUpdateClient.
2Useful events
In the System log, event 41 from Kernel-Power means Windows restarted without a clean shutdown, and event 6008 records an unexpected shutdown. 'Filter Current Log' narrows a log by level, source, event ID or time.
3Command line
wevtutil el lists the logs, wevtutil qe System /c:20 /rd:true /f:text shows the newest 20 System events, and wevtutil epl System C:\temp\system.evtx exports a log. In PowerShell, 'Get-WinEvent' reads the same logs.
How to find the cause of an unexpected restart
- Press Win+R, type eventvwr.msc and press Enter.
- Open Windows Logs > System and choose Filter Current Log.
- Select the Critical and Error levels and set the time range around the restart.
- Open the events closest to the restart and note their source and event ID.
- Search the event ID together with the source in the Microsoft documentation.
Cautions
- Errors and warnings appear on every healthy PC; do not trust programs or pages that use them to claim the PC is infected.
- Clearing a log deletes its history; export it first if you may need it.
Related articles
- Task SchedulerWhat Windows Task Scheduler does, where tasks live, and how to view, disable or remove a task safely.
- Device ManagerHow to use Device Manager to find devices without drivers, read error codes, update, roll back or uninstall a driver.
- SFC (System File Checker)What sfc /scannow does, how to read its results, where the CBS.log is and when to run DISM first.
Sources
- Event logging (Microsoft Learn) learn.microsoft.com
- wevtutil (Microsoft Learn) learn.microsoft.com
Last reviewed: