
Quote: Originally Posted by
tripleclick
Hello, I'm new here. Just starting with a question re the event log of Windows 7:
In what format are date and time of logged events in .evtx files? How can I find and translate them when I look at the file content with a hex viewer? (File seems to be corrupt. Can't open it with the Windows event viewer.)
Thanks in advance!
Welcome to SevenForums.
Let Win 7 open your .evtx files. The default is Event Viewer.
The average user will be using Event Viewer to view the event logs.
True, with a healthy work in time, you can learn to use PowerShell to extract and parse event logs.
I use a powershell script to clear all of my event logs - not for the space savings but to make the job of separating the wheat from the chaff easier.