Rain WikiWindows · Linux · Android

Event Viewer

Built-in toolWindows 7, 8.1, 10, 11Safe to delete: No

Event Viewer (eventvwr.msc) shows the event logs in which Windows, services and apps record information, warnings and errors. It is the first place to look after a crash, an unexpected restart or a failing driver or update. Many errors in the logs are harmless; what matters is what happened at the time of the problem.

1The main logs

Windows Logs > System records drivers, services and the start and shutdown of Windows. Windows Logs > Application records app errors. Applications and Services Logs contain detailed logs of individual components, for example Microsoft > Windows > WindowsUpdateClient.

2Useful events

In the System log, event 41 from Kernel-Power means Windows restarted without a clean shutdown, and event 6008 records an unexpected shutdown. 'Filter Current Log' narrows a log by level, source, event ID or time.

3Command line

wevtutil el lists the logs, wevtutil qe System /c:20 /rd:true /f:text shows the newest 20 System events, and wevtutil epl System C:\temp\system.evtx exports a log. In PowerShell, 'Get-WinEvent' reads the same logs.

How to find the cause of an unexpected restart

  1. Press Win+R, type eventvwr.msc and press Enter.
  2. Open Windows Logs > System and choose Filter Current Log.
  3. Select the Critical and Error levels and set the time range around the restart.
  4. Open the events closest to the restart and note their source and event ID.
  5. Search the event ID together with the source in the Microsoft documentation.

Cautions

  • Errors and warnings appear on every healthy PC; do not trust programs or pages that use them to claim the PC is infected.
  • Clearing a log deletes its history; export it first if you may need it.

Sources

  1. Event logging (Microsoft Learn) learn.microsoft.com
  2. wevtutil (Microsoft Learn) learn.microsoft.com

Last reviewed: