Windows 7 Forums Search
Welcome to Windows 7 Forums. Our forum is dedicated to helping you find solutions with any problems, errors or issues you are experiencing with Windows 7. The Windows 7 forum also covers news and updates and has an extensive Windows 7 tutorial section that covers a wide range of tips and tricks.


Windows 7 - event log: format of date and time

 
07-24-2011   #1


Windows 7 Pro x64
 
 

event log: format of date and time

Hello, I'm new here. Just starting with a question re the event log of Windows 7:

In what format are date and time of logged events in .evtx files? How can I find and translate them when I look at the file content with a hex viewer? (File seems to be corrupt. Can't open it with the Windows event viewer.)

Thanks in advance!

My System SpecsSystem Spec
07-24-2011   #2


MS Windows 7 Ultimate SP1 64-bit
 
 


Quote   Quote: Originally Posted by tripleclick View Post
Hello, I'm new here. Just starting with a question re the event log of Windows 7:

In what format are date and time of logged events in .evtx files? How can I find and translate them when I look at the file content with a hex viewer? (File seems to be corrupt. Can't open it with the Windows event viewer.)

Thanks in advance!
Welcome to SevenForums.

Let Win 7 open your .evtx files. The default is Event Viewer.

The average user will be using Event Viewer to view the event logs.

True, with a healthy work in time, you can learn to use PowerShell to extract and parse event logs.

I use a powershell script to clear all of my event logs - not for the space savings but to make the job of separating the wheat from the chaff easier.
My System SpecsSystem Spec
07-24-2011   #3


Windows 7 Pro x64
 
 


Thanks karlsnooks, PowerShell might be just a bit of an overkill for now. I just need to be able to find and read the dates and times at the moment. I can't open the corrupt file with Windows event viewer. (Will look into PowerShell when I have more time on my hands.)
My System SpecsSystem Spec
.


07-24-2011   #4


MS Windows 7 Ultimate SP1 64-bit
 
 


The easiest way is to simply with wndows exploer to open the file. The default is the event viwer snap in. The event viewer will show you data nd time.
My System SpecsSystem Spec
07-24-2011   #5


Windows 7 Pro x64
 
 


Umm... thanks, but as I have written twice: the file is corrupt, thus I cannot open/view it with the event viewer. But I can look at the content with a hex viewer.
My System SpecsSystem Spec
07-24-2011   #6


MS Windows 7 Ultimate SP1 64-bit
 
 


I'm trying to understand.

You have an event viewer with which you can view events. Events are stored in Event Logs. If the Event Log is on a remote machine, then just export the log , bring the log to your machine and import the log.

Of course iindividual events can be exported, the details can be copied to a text file.
My System SpecsSystem Spec
07-24-2011   #7


Windows 7 Pro x64
 
 


Thanks for your efforts. I only have a ***corrupt*** .evtx file with already exported events in it. I want to read those events. Because the file is corrupt I cannot view it with the Windows event viewer. When I look into the file with a usual txt editor I can see the ASCII part. But date and time does not seem to be in ASCII format. I therefore look into the file with a hex viewer but still I can't find and decipher dates and times of the events.

I hope you or somebody else understand(s) now. I am sorry if I am not able to describe the situation clear enough.
My System SpecsSystem Spec
07-27-2011   #8


Windows 7 Pro x64
 
 


I would still appreciate any help from anybody. (I am sorry, if my question was not clear enough. I did my best. But I am open to counter questions.) Thanks in advance!
My System SpecsSystem Spec
10-02-2011   #9


Windows 7 X64
 
 


Hey Tripple,

Having the same issue. Did you ever get a solution?
My System SpecsSystem Spec
10-03-2011   #10


Windows 7 Pro x64
 
 


No, unfortunately not.
My System SpecsSystem Spec
Reply

 event log: format of date and time problems?



Thread Tools



Similar Threads for: event log: format of date and time
Thread Forum
Date Format - Change Tutorials
Date format using space as date separator rather than forward slash! General Discussion
Solved Time stamp missing from Date and Time column - Event Viewer Performance & Maintenance
Say the Time Date/Time Field in Task Tray Doesn't Launch Menu Hardware & Devices
Excel and MS-Money 2005 date and time format display issue Microsoft Office


All times are GMT -5. The time now is 12:34 AM.



Windows 7 Forums is an independent web site and has not been authorized,
sponsored, or otherwise approved by Microsoft Corporation.
"Windows 7" and related materials are trademarks of Microsoft Corp.
© Designer Media Ltd
  

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30