How To Clear Administrative Events Log - Event Viewer

ColTom2

New member
Local time
11:38 AM
Messages
20
Hi:

Does anyone know how to clear the Administrative Events log listed under Custom Views in the Event Viewer?

All the logs listed under the Windows logs have options to clear, but the above does not.

Thanks,

ColTom2
 

My Computer My Computer

At a glance

Windows 71.80 gigahertz Intel Celeron Dual-Core1914 Megabytes Usable Installed Memory
Computer Manufacturer/Model Number
Toshiba L455-S5980
OS
Windows 7
CPU
1.80 gigahertz Intel Celeron Dual-Core
Motherboard
TOSHIBA NBWAA 1.00
Memory
1914 Megabytes Usable Installed Memory
Sound Card
Realtek High Definition Audio
Monitor(s) Displays
Generic PnP Monitor (15.3"vis)
Hard Drives
Hitachi HTS543225L9SA00 [Hard drive] (250.06 GB)
Thats just a filter. I dont know of any way to clear it other than clearing all events that appear in it under: System, Security and Application event logs.
 

My Computer My Computer

At a glance

Windows 7 Ultimate (x86)Intel 2.20 Dual Core4 GBnVidia 9400 GT (512 MB)
Computer Manufacturer/Model Number
Dell Dimension E520
OS
Windows 7 Ultimate (x86)
CPU
Intel 2.20 Dual Core
Memory
4 GB
Graphics Card(s)
nVidia 9400 GT (512 MB)
Sound Card
Sigmatel C Major HD
Monitor(s) Displays
22" Samsung 2232 bw
Screen Resolution
1680x1050
Mouse
Microsoft Arc
Other Info
Wacom Graphire 4 (6x8) Tablet
Well apparently they are cummulative and just keep adding on each day. Surely there must be some simple manner in which to clear these Administrative Events.

Or is there a max number that will be allowed to appear or will they just go on to an infinte number?

Thanks,

ColTom2
 

My Computer My Computer

At a glance

Windows 71.80 gigahertz Intel Celeron Dual-Core1914 Megabytes Usable Installed Memory
Computer Manufacturer/Model Number
Toshiba L455-S5980
OS
Windows 7
CPU
1.80 gigahertz Intel Celeron Dual-Core
Motherboard
TOSHIBA NBWAA 1.00
Memory
1914 Megabytes Usable Installed Memory
Sound Card
Realtek High Definition Audio
Monitor(s) Displays
Generic PnP Monitor (15.3"vis)
Hard Drives
Hitachi HTS543225L9SA00 [Hard drive] (250.06 GB)
Events are recorded all the time. Constantly. What your looking at is a filter comprised of events from numerous logs/sources. I dont know of any way to remove the filter. But even if it could be removed, the events will still be recorded.

There are max number/log sizes for every log. The filter from what I can tell has no limit. You can adjust the limit (max size) for individual logs.
 

Attachments

  • Events.PNG
    Events.PNG
    19 KB · Views: 752

My Computer My Computer

At a glance

Windows 7 Ultimate (x86)Intel 2.20 Dual Core4 GBnVidia 9400 GT (512 MB)
Computer Manufacturer/Model Number
Dell Dimension E520
OS
Windows 7 Ultimate (x86)
CPU
Intel 2.20 Dual Core
Memory
4 GB
Graphics Card(s)
nVidia 9400 GT (512 MB)
Sound Card
Sigmatel C Major HD
Monitor(s) Displays
22" Samsung 2232 bw
Screen Resolution
1680x1050
Mouse
Microsoft Arc
Other Info
Wacom Graphire 4 (6x8) Tablet
Hi:

Does anyone know how to clear the Administrative Events log listed under Custom Views in the Event Viewer?

All the logs listed under the Windows logs have options to clear, but the above does not.

Thanks,

ColTom2

I've tried this and it works to do what you are asking. Save the code as .bat and run it. I'll try and search for the source and post back with it.
Code:
@echo off
FOR /F "tokens=1,2*" %%V IN ('bcdedit') DO SET adminTest=%%V
IF (%adminTest%)==(Access) goto noAdmin
for /F "tokens=*" %%G in ('wevtutil.exe el') DO (call :do_clear "%%G")
echo.
echo Event Logs have been cleared! ^<press any key^>
goto theEnd
:do_clear
echo clearing %1
wevtutil.exe cl %1
goto :eof
:noAdmin
echo You must run this script as an Administrator!
echo ^<press any key^>
:theEnd
pause>NUL
 

My Computer My Computer

At a glance

Windows 7 Professional 32-bit (6.1, Build 7600)Intel(R) Pentium(R) 4 3.00 GHz HT2.0 GBATI Mobility Radeon 9600 64MB
Computer Manufacturer/Model Number
Averatec 6130HS-20
OS
Windows 7 Professional 32-bit (6.1, Build 7600)
CPU
Intel(R) Pentium(R) 4 3.00 GHz HT
Memory
2.0 GB
Graphics Card(s)
ATI Mobility Radeon 9600 64MB
Sound Card
Realtek AC'97 Audio
Screen Resolution
1280 x 800
Hard Drives
Seagate 96023A 60GB 7200RPM -
Seagate FreeAgentDesktop 250GB
Cooling
20 Inch Box Fan
Mouse
Targus PAWM10 Wireless Optical Laptop Mouse
Hi Greg:

Running the batch file as you provided did the trick, as it cleaned out all Administrative Event Log entries. Wonder what else it cleaned out....

Thanks,

Co;Tom2
 

My Computer My Computer

At a glance

Windows 71.80 gigahertz Intel Celeron Dual-Core1914 Megabytes Usable Installed Memory
Computer Manufacturer/Model Number
Toshiba L455-S5980
OS
Windows 7
CPU
1.80 gigahertz Intel Celeron Dual-Core
Motherboard
TOSHIBA NBWAA 1.00
Memory
1914 Megabytes Usable Installed Memory
Sound Card
Realtek High Definition Audio
Monitor(s) Displays
Generic PnP Monitor (15.3"vis)
Hard Drives
Hitachi HTS543225L9SA00 [Hard drive] (250.06 GB)
Hi Coltom,

There is a tutorial in this forum for this and a way to run in admin mode.

HERE
 

My Computer My Computer

At a glance

Windows 7 x64 Ultimate SP1I5 875K UnlockedKingston HyperX Genesis DDR3-1600MHz 9-9-9-27...EVGA GeForce GTX 570 HD 732 MHz GPU 1280 MB, ...
Computer Manufacturer/Model Number
Asus
OS
Windows 7 x64 Ultimate SP1
CPU
I5 875K Unlocked
Motherboard
P7P55D-E-PRO
Memory
Kingston HyperX Genesis DDR3-1600MHz 9-9-9-27 @ 1.65V XMP
Graphics Card(s)
EVGA GeForce GTX 570 HD 732 MHz GPU 1280 MB, 152 GB Mem
Sound Card
Onboard Via 1828S
Monitor(s) Displays
Samsung T240 HD
Screen Resolution
Dual 1920X1200 1027X768
Hard Drives
OCZ Vertex II Extended Sandforce SSD 60 Gig 2X WD Black Caviar 1 terabyte 6GBS Transer Sata 3 Marvell Chip
PSU
Corsair Gold fully Modular 80 Plus 850
Case
Coolermaster Half X Full Tower
Cooling
Noctua NH-U12P
Keyboard
MS
Mouse
MS
Internet Speed
Fast enough
Other Info
My fridge has a water tap
Hi Greg:

Running the batch file as you provided did the trick, as it cleaned out all Administrative Event Log entries. Wonder what else it cleaned out....

Thanks,

Co;Tom2

Do a search for wevtutil.exe and one of the MS related sites should be near the top listing. It's a tool for managing event logs
 

My Computer My Computer

At a glance

Windows 7 Professional 32-bit (6.1, Build 7600)Intel(R) Pentium(R) 4 3.00 GHz HT2.0 GBATI Mobility Radeon 9600 64MB
Computer Manufacturer/Model Number
Averatec 6130HS-20
OS
Windows 7 Professional 32-bit (6.1, Build 7600)
CPU
Intel(R) Pentium(R) 4 3.00 GHz HT
Memory
2.0 GB
Graphics Card(s)
ATI Mobility Radeon 9600 64MB
Sound Card
Realtek AC'97 Audio
Screen Resolution
1280 x 800
Hard Drives
Seagate 96023A 60GB 7200RPM -
Seagate FreeAgentDesktop 250GB
Cooling
20 Inch Box Fan
Mouse
Targus PAWM10 Wireless Optical Laptop Mouse
The tutorial that I give shows what is being cleared. Basically just anything in the event viewer.
 

My Computer My Computer

At a glance

Windows 7 x64 Ultimate SP1I5 875K UnlockedKingston HyperX Genesis DDR3-1600MHz 9-9-9-27...EVGA GeForce GTX 570 HD 732 MHz GPU 1280 MB, ...
Computer Manufacturer/Model Number
Asus
OS
Windows 7 x64 Ultimate SP1
CPU
I5 875K Unlocked
Motherboard
P7P55D-E-PRO
Memory
Kingston HyperX Genesis DDR3-1600MHz 9-9-9-27 @ 1.65V XMP
Graphics Card(s)
EVGA GeForce GTX 570 HD 732 MHz GPU 1280 MB, 152 GB Mem
Sound Card
Onboard Via 1828S
Monitor(s) Displays
Samsung T240 HD
Screen Resolution
Dual 1920X1200 1027X768
Hard Drives
OCZ Vertex II Extended Sandforce SSD 60 Gig 2X WD Black Caviar 1 terabyte 6GBS Transer Sata 3 Marvell Chip
PSU
Corsair Gold fully Modular 80 Plus 850
Case
Coolermaster Half X Full Tower
Cooling
Noctua NH-U12P
Keyboard
MS
Mouse
MS
Internet Speed
Fast enough
Other Info
My fridge has a water tap
Nicely done the batch file runs perfectly! ;)
 

My Computer My Computer

At a glance

Windows 7 Ultimate x64I76 x 1.5V DDR3 DIMM sockets supporting up to 2...GeForce GTX 580
Computer Manufacturer/Model Number
Alienware
OS
Windows 7 Ultimate x64
CPU
I7
Motherboard
GA-X58-USB3
Memory
6 x 1.5V DDR3 DIMM sockets supporting up to 24 GB of system
Graphics Card(s)
GeForce GTX 580
Sound Card
Realtek ALC892 codec 2/4/5.1/7.1-channel
Monitor(s) Displays
NEC Display Solutions E321 Black 32"
Screen Resolution
1366 x 768
Hard Drives
OCZ Colossus LT Series OCZSSD2-1CLSLT1T 3.5" 1TB SATA II MLC Internal Solid State Drive
PSU
XFX Black Edition XPS-850W-BES 850W ATX12V
Case
Antec
Cooling
Zalman
Keyboard
Microsoft
Mouse
Microsoft
Whines get better with age?

OK, not whining- Just expressing appreciation that threads like this are still maintained. This issue isn't critical for me, but it was still a nuisance seeing all those Administrative Events that I couldn't delete directly from the list.

I tried the script provided by Greg S and it worked beautifully! Thank you! Happy Camper and all that...
 

My Computer My Computer

At a glance

Dual-Boot WinXPP (x32), Win 7 Ent (x64)Intel Core2Duo (T9400 @ 2.53GHz)4GB
Computer Manufacturer/Model Number
HP 8730w (laptop)
OS
Dual-Boot WinXPP (x32), Win 7 Ent (x64)
CPU
Intel Core2Duo (T9400 @ 2.53GHz)
Memory
4GB
View the Windows events by Event Log Explorer

1. Try Event Log Explorer , it's free for personal use.
2. If you need to clear a log on a local computer, this computer will be listed in the tree.
If you need to clear a log on a remote computer, add this computer by pressing Add computer button.
3. Double click on the computer in the tree to expand event logs.
4. Find the log you need to clear, click right mouse button on it and select clear.
5. Confirm clearing.
6. Double click on the log to open it to make sure thay the log contains no events.
 
Last edited:

My Computer My Computer

At a glance

32
Computer type
PC/Desktop
OS
32
It's a long time since I looked at any code.
Can anyone add comments to each lin of this code to help me understand
how it works?

Code:
@echo off
FOR /F "tokens=1,2*" %%V IN ('bcdedit') DO SET adminTest=%%V
IF (%adminTest%)==(Access) goto noAdmin
for /F "tokens=*" %%G in ('wevtutil.exe el') DO (call :do_clear "%%G")
echo.
echo Event Logs have been cleared! ^<press any key^>
goto theEnd
:do_clear
echo clearing %1
wevtutil.exe cl %1
goto :eof
:noAdmin
echo You must run this script as an Administrator!
echo ^<press any key^>
:theEnd
pause>NUL
 
Last edited:

My Computer My Computer

At a glance

Windows 7 64Bit
OS
Windows 7 64Bit
Back
Top