Keywords – this field is not usually used, and generally contains useless information.

Windows 1102 The audit log was cleared Windows 1104 The security Log is now full Windows 1105 Event log automatic backup Windows 1108 The event logging service encountered an error

Subscriptions, found in the left-hand menu, is a feature largely used in an enterprise environment to forward events from one server to another so you can manage them all in one location. User – this field tells you whether it was a system component or your user account that was running the process that caused the error.

Windows 4614 A notification package has been loaded by the Security Account Manager.

There are a large number of different types of event logs including Administrative, Operational, Analytic, and Debug log types. Windows 4875 Certificate Services received a request to shut down Windows 4876 Certificate Services backup started Windows 4877 Certificate Services backup completed Windows 4878 Certificate Services restore started Windows 4879 Certificate Services restore completed

Prior to Windows Vista, to determine the name of the program used to open an object, you must find the corresponding event 592.

When a user at a workstation opens an object on a server (such as through a shared folder) these fields will only identify the server program used to open the object. Enter the Event ID number and the Source and the site's search engine filters out the possible resolutions for the particular event.

Windows 5041 A change has been made to IPsec settings. Windows 4891 A configuration entry changed in Certificate Services Windows 4892 A property of Certificate Services changed Windows 4893 Certificate Services archived a key Windows 4894 Certificate Services imported and archived a key

Windows 5143 A network share object was modified Windows 5144 A network share object was deleted. Just use your browser to view saved logs.

Note that the accesses listed include all the accesses requested - not just the access types denied. An event, as described by Microsoft, is any significant happening in a system or in a program that should be brought to a user's attention. If the policy enables auditing for the user, type of access requested and the success/failure result, Windows records generates event 560.

Windows 4666 An application attempted an operation Windows 4667 An application client context was deleted Windows 4668 An application was initialized Windows 4670 Permissions on an object were changed Windows 4671 An application was granted access to an object. Just remember that the Event ID is unique for each application.

A Connection Security Rule was added Windows 5044 A change has been made to IPsec settings. In System Log, events related to system failures like startup errors (for instance a failed driver), hardware crashes (a webcam froze) et al find a mention. To make this change, head down to the following registry key: HKLM\Software\Microsoft\Windows NT\CurrentVersion\EventViewer Find the MicrosoftRedirectionURL value on the right-hand side, and then change the value out from the default.

For example, when a user's authentication fails, the system may generate Event ID 672. Look Through the Windows Diagnostics Performance Log There are a lot of interesting logs to look at when you are troubleshooting, but one of the most interesting is found by browsing the Diagnostics Performance log.

The regular fields on the display contain: Log Name – while in older versions of Windows everything got dumped into the Application or System log, in the more modern editions there are many more specialized logs. You can save out all of the events in a log for viewing later or on another PC, you can copy a view or export it as an XML file. For instance, the Administrative Events view in recent versions of Windows displays all of the Error, Warning, and Critical events whether they originated from the Application log or the System log.

The events themselves are what we're trying to see, of course, and their usefulness can range from really specific and obvious things that you can fix easily to the very vague. Understanding the Interface When you first open Event Viewer, you'll notice it uses the three-pane configuration like many of the other administrative tools in Windows.