Professional Documents
Culture Documents
WINDOWS EVENTS: Events are typically used for troubleshooting application and driver software.
EVENT TYPES
There are five types of events that can be logged. All of these have well-defined common data and can optionally
include event-specific data.
The application indicates the event type when it reports an event. Each event must be of a single type. The Event
Viewer displays a different icon for each type in the list view of the event log.
The following table describes the five event types used in event logging.
Error An event that indicates a significant problem such as loss of data or loss of functionality.
For example, if a service fails to load during startup, an Error event is logged.
Warning An event that is not necessarily significant, but may indicate a possible future problem. For
example, when disk space is low, a Warning event is logged. If an application can recover
from an event without loss of functionality or data, it can generally classify the event as a
Warning event.
Informatio An event that describes the successful operation of an application, driver, or service. For
n example, when a network driver loads successfully, it may be appropriate to log an
Information event. Note that it is generally inappropriate for a desktop application to log
an event each time it starts.
Success An event that records an audited security access attempt that is successful. For example, a
Audit user's successful attempt to log on to the system is logged as a Success Audit event.
Failure An event that records an audited security access attempt that fails. For example, if a user
Audit tries to access a network drive and fails, the attempt is logged as a Failure Audit event.
“Logs are records of events that happen in your computer, either by a person or by a running process. They help you
track what happened and troubleshoot problems”
Applications and the operating system (OS) use these event logs to record important hardware and software actions
that the administrator can use to troubleshoot issues with the operating system. The Windows operating system
tracks specific events in its log files, such as application installations, security management, system setup operations
on initial startup, and problems or errors.
Example:
Application events relate to incidents with the software installed on the local computer. If an application such as
Microsoft Word crashes, then the Windows event log will create a log entry about the issue, the application name
and why it crashed.
Security events store information based on the Windows system's audit policies, and the typical events stored
include login attempts and resource access. For example, the security log stores a record when the computer
attempts to verify account credentials when a user tries to log on to a machine.
Setup events include enterprise-focused events relating to the control of domains, such as the location of logs after a
disk configuration.
System events relate to incidents on Windows-specific systems, such as the status of device drivers.
Forwarded events arrive from other machines on the same network when an administrator wants to use a computer
that gathers multiple logs.
The most common location for logs in Windows is the Windows Event Log. It contains logs from the operating
system and several applications such as SQL Server or Internet Information Server (IIS). The logs use a structured
data format, making them easy to search for and analyze. Additionally, some applications write to log files, for
example IIS access logs, in text format.
Windows displays its event logs in the Windows Event Viewer. This application lets you view and navigate the
Windows Event Log, search and filter on particular types of logs, export them for analysis, and more. We’ll start by
showing you how to access it and what features are available.
In Windows Server 2012, the Event Viewer is accessible from a number of places. Most people will open it from the
Control Panel, but we also wanted to show other places it’s accessible from.
From the Administrative Tools window, double-click on Event Viewer app icon.