Windows

wevtutil

SafeEvent logs from the CLI

wevtutil qe System /c:20 /rd:true /f:text

Queries (qe) and exports (epl) event logs — extract incident windows or preserve evtx evidence.

Examples

  • wevtutil epl System C:\temp\sys.evtxExport System log as evtx

Syntax

wevtutil [qe log] [el] [epl log file]

Before you run it

Avoid 'cl' — it destroys evidence.

Used when you see

Windows Update keeps failing
4
If it fails again, pull the error from the event logs
See the whole flow →
Blue screens (BSOD)
1
Get the stop code and time from event logsCheck System log events 41 and 1001.
See the whole flow →
Disk acting up (Windows)
3
Look for disk/ntfs warnings in event logs
See the whole flow →

Related commands

The same reference, with no signal at all

Every command and flow from this site, held on your device and searchable with no connection. Free to install, no ads.

Get it free on the App Store