event log: format of date and time

tripleclick

New member
Local time
11:34 AM
Messages
27
Hello, I'm new here. Just starting with a question re the event log of Windows 7:

In what format are date and time of logged events in .evtx files? How can I find and translate them when I look at the file content with a hex viewer? (File seems to be corrupt. Can't open it with the Windows event viewer.)

Thanks in advance!
 

My Computer My Computer

At a glance

Windows 7 Pro x64Intel Core2 Duo T9600 @ 2.80GHz4 GBNvidia Quadro FX 770M
Computer Manufacturer/Model Number
HP Elitebook 8530w
OS
Windows 7 Pro x64
CPU
Intel Core2 Duo T9600 @ 2.80GHz
Memory
4 GB
Graphics Card(s)
Nvidia Quadro FX 770M
Sound Card
Analog Devices: SoundMAX Integrated Digital HD Audio
Screen Resolution
1680 x 1050
Hard Drives
ST9500420AS ATA
Hello, I'm new here. Just starting with a question re the event log of Windows 7:

In what format are date and time of logged events in .evtx files? How can I find and translate them when I look at the file content with a hex viewer? (File seems to be corrupt. Can't open it with the Windows event viewer.)

Thanks in advance!

Welcome to SevenForums.

Let Win 7 open your .evtx files. The default is Event Viewer.

The average user will be using Event Viewer to view the event logs.

True, with a healthy work in time, you can learn to use PowerShell to extract and parse event logs.

I use a powershell script to clear all of my event logs - not for the space savings but to make the job of separating the wheat from the chaff easier.
 

My Computer My Computer

At a glance

MS Windows 7 Ultimate SP1 64-bitAMD A10-4600M6.00 GB Dual-Channel DDR3 @ 798MHz (11-11-12-28)AMD Radeon HD 7660G
Computer Manufacturer/Model Number
Toshiba Satellite S875D-S7239 laptop
OS
MS Windows 7 Ultimate SP1 64-bit
CPU
AMD A10-4600M
Motherboard
AMD Pumori (Socket FT1)
Memory
6.00 GB Dual-Channel DDR3 @ 798MHz (11-11-12-28)
Graphics Card(s)
AMD Radeon HD 7660G
Sound Card
High Definition Audio Device
Monitor(s) Displays
Generic PnP Monitor (1600x900@60Hz)
Screen Resolution
1600x900@60Hz
Hard Drives
SSD 119GB Corsair CSSD-V128GB2 ATA Device
Keyboard
Standard PS/2 Keyboard
Mouse
HP Wireless Optical Mobile Mouse Model FHA-3410
Internet Speed
What the local pub, local coffee shop offers.
Other Info
Optical Drive:MATSHITA BD-CMB UJ160B ATA Device


Also have an Asus ha1002xp netbook with Win 7 Ultimate installed.
Thanks karlsnooks, PowerShell might be just a bit of an overkill for now. I just need to be able to find and read the dates and times at the moment. I can't open the corrupt file with Windows event viewer. (Will look into PowerShell when I have more time on my hands.)
 

My Computer My Computer

At a glance

Windows 7 Pro x64Intel Core2 Duo T9600 @ 2.80GHz4 GBNvidia Quadro FX 770M
Computer Manufacturer/Model Number
HP Elitebook 8530w
OS
Windows 7 Pro x64
CPU
Intel Core2 Duo T9600 @ 2.80GHz
Memory
4 GB
Graphics Card(s)
Nvidia Quadro FX 770M
Sound Card
Analog Devices: SoundMAX Integrated Digital HD Audio
Screen Resolution
1680 x 1050
Hard Drives
ST9500420AS ATA
The easiest way is to simply with wndows exploer to open the file. The default is the event viwer snap in. The event viewer will show you data nd time.
 

My Computer My Computer

At a glance

MS Windows 7 Ultimate SP1 64-bitAMD A10-4600M6.00 GB Dual-Channel DDR3 @ 798MHz (11-11-12-28)AMD Radeon HD 7660G
Computer Manufacturer/Model Number
Toshiba Satellite S875D-S7239 laptop
OS
MS Windows 7 Ultimate SP1 64-bit
CPU
AMD A10-4600M
Motherboard
AMD Pumori (Socket FT1)
Memory
6.00 GB Dual-Channel DDR3 @ 798MHz (11-11-12-28)
Graphics Card(s)
AMD Radeon HD 7660G
Sound Card
High Definition Audio Device
Monitor(s) Displays
Generic PnP Monitor (1600x900@60Hz)
Screen Resolution
1600x900@60Hz
Hard Drives
SSD 119GB Corsair CSSD-V128GB2 ATA Device
Keyboard
Standard PS/2 Keyboard
Mouse
HP Wireless Optical Mobile Mouse Model FHA-3410
Internet Speed
What the local pub, local coffee shop offers.
Other Info
Optical Drive:MATSHITA BD-CMB UJ160B ATA Device


Also have an Asus ha1002xp netbook with Win 7 Ultimate installed.
Umm... thanks, but as I have written twice: the file is corrupt, thus I cannot open/view it with the event viewer. But I can look at the content with a hex viewer.
 

My Computer My Computer

At a glance

Windows 7 Pro x64Intel Core2 Duo T9600 @ 2.80GHz4 GBNvidia Quadro FX 770M
Computer Manufacturer/Model Number
HP Elitebook 8530w
OS
Windows 7 Pro x64
CPU
Intel Core2 Duo T9600 @ 2.80GHz
Memory
4 GB
Graphics Card(s)
Nvidia Quadro FX 770M
Sound Card
Analog Devices: SoundMAX Integrated Digital HD Audio
Screen Resolution
1680 x 1050
Hard Drives
ST9500420AS ATA
I'm trying to understand.

You have an event viewer with which you can view events. Events are stored in Event Logs. If the Event Log is on a remote machine, then just export the log , bring the log to your machine and import the log.

Of course iindividual events can be exported, the details can be copied to a text file.
 

My Computer My Computer

At a glance

MS Windows 7 Ultimate SP1 64-bitAMD A10-4600M6.00 GB Dual-Channel DDR3 @ 798MHz (11-11-12-28)AMD Radeon HD 7660G
Computer Manufacturer/Model Number
Toshiba Satellite S875D-S7239 laptop
OS
MS Windows 7 Ultimate SP1 64-bit
CPU
AMD A10-4600M
Motherboard
AMD Pumori (Socket FT1)
Memory
6.00 GB Dual-Channel DDR3 @ 798MHz (11-11-12-28)
Graphics Card(s)
AMD Radeon HD 7660G
Sound Card
High Definition Audio Device
Monitor(s) Displays
Generic PnP Monitor (1600x900@60Hz)
Screen Resolution
1600x900@60Hz
Hard Drives
SSD 119GB Corsair CSSD-V128GB2 ATA Device
Keyboard
Standard PS/2 Keyboard
Mouse
HP Wireless Optical Mobile Mouse Model FHA-3410
Internet Speed
What the local pub, local coffee shop offers.
Other Info
Optical Drive:MATSHITA BD-CMB UJ160B ATA Device


Also have an Asus ha1002xp netbook with Win 7 Ultimate installed.
Thanks for your efforts. I only have a ***corrupt*** .evtx file with already exported events in it. I want to read those events. Because the file is corrupt I cannot view it with the Windows event viewer. When I look into the file with a usual txt editor I can see the ASCII part. But date and time does not seem to be in ASCII format. I therefore look into the file with a hex viewer but still I can't find and decipher dates and times of the events.

I hope you or somebody else understand(s) now. I am sorry if I am not able to describe the situation clear enough.
 

My Computer My Computer

At a glance

Windows 7 Pro x64Intel Core2 Duo T9600 @ 2.80GHz4 GBNvidia Quadro FX 770M
Computer Manufacturer/Model Number
HP Elitebook 8530w
OS
Windows 7 Pro x64
CPU
Intel Core2 Duo T9600 @ 2.80GHz
Memory
4 GB
Graphics Card(s)
Nvidia Quadro FX 770M
Sound Card
Analog Devices: SoundMAX Integrated Digital HD Audio
Screen Resolution
1680 x 1050
Hard Drives
ST9500420AS ATA
I would still appreciate any help from anybody. (I am sorry, if my question was not clear enough. I did my best. But I am open to counter questions.) Thanks in advance!
 

My Computer My Computer

At a glance

Windows 7 Pro x64Intel Core2 Duo T9600 @ 2.80GHz4 GBNvidia Quadro FX 770M
Computer Manufacturer/Model Number
HP Elitebook 8530w
OS
Windows 7 Pro x64
CPU
Intel Core2 Duo T9600 @ 2.80GHz
Memory
4 GB
Graphics Card(s)
Nvidia Quadro FX 770M
Sound Card
Analog Devices: SoundMAX Integrated Digital HD Audio
Screen Resolution
1680 x 1050
Hard Drives
ST9500420AS ATA
Hey Tripple,

Having the same issue. Did you ever get a solution?
 

My Computer My Computer

At a glance

Windows 7 X64AMD Phenom x4 95504GB Kingston Hyper-x DDR2Sapphire ATI Radeon HD 4870 512
OS
Windows 7 X64
CPU
AMD Phenom x4 9550
Motherboard
ASUS m3a32-mvp deluxe
Memory
4GB Kingston Hyper-x DDR2
Graphics Card(s)
Sapphire ATI Radeon HD 4870 512
Sound Card
Onboard
Monitor(s) Displays
1 x 22" Samsung
No, unfortunately not.
 

My Computer My Computer

At a glance

Windows 7 Pro x64Intel Core2 Duo T9600 @ 2.80GHz4 GBNvidia Quadro FX 770M
Computer Manufacturer/Model Number
HP Elitebook 8530w
OS
Windows 7 Pro x64
CPU
Intel Core2 Duo T9600 @ 2.80GHz
Memory
4 GB
Graphics Card(s)
Nvidia Quadro FX 770M
Sound Card
Analog Devices: SoundMAX Integrated Digital HD Audio
Screen Resolution
1680 x 1050
Hard Drives
ST9500420AS ATA
Back
Top