Code:
Microsoft Windows [Version 6.1.7601]
Copyright (c) 2009 Microsoft Corporation. All rights reserved.
C:\Windows\system32>DIR C:\Windows\System32\winevt\logs /on
Volume in drive C has no label.
Volume Serial Number is 127B-6585
Directory of C:\Windows\System32\winevt\logs
12/18/2012 04:50 PM <DIR> .
12/18/2012 04:50 PM <DIR> ..
12/21/2012 12:25 PM 2,166,784 Application.evtx
12/14/2012 10:09 PM 69,632 HardwareEvents.evtx
12/14/2012 10:09 PM 69,632 Internet Explorer.evtx
12/14/2012 10:09 PM 69,632 Key Management Service.evtx
12/14/2012 10:09 PM 69,632 Media Center.evtx
12/14/2012 10:09 PM 69,632 Microsoft-Windows-Application-Experience%
4Problem-Steps-Recorder.evtx
12/21/2012 12:41 AM 69,632 Microsoft-Windows-Application-Experience%
4Program-Compatibility-Assistant.evtx
12/14/2012 10:09 PM 69,632 Microsoft-Windows-Application-Experience%
4Program-Compatibility-Troubleshooter.evtx
12/15/2012 02:35 PM 69,632 Microsoft-Windows-Application-Experience%
4Program-Inventory.evtx
12/16/2012 02:21 AM 69,632 Microsoft-Windows-Application-Experience%
4Program-Telemetry.evtx
12/14/2012 10:57 PM 69,632 Microsoft-Windows-Audio%4CaptureMonitor.e
vtx
12/14/2012 10:57 PM 69,632 Microsoft-Windows-Audio%4Operational.evtx
12/21/2012 12:41 AM 1,052,672 Microsoft-Windows-Bits-Client%4Operationa
l.evtx
12/21/2012 12:27 PM 1,052,672 Microsoft-Windows-BranchCacheSMB%4Operati
onal.evtx
12/21/2012 12:44 PM 69,632 Microsoft-Windows-Dhcp-Client%4Admin.evtx
12/21/2012 12:41 AM 69,632 Microsoft-Windows-Dhcpv6-Client%4Admin.ev
tx
12/21/2012 12:41 AM 1,052,672 Microsoft-Windows-Diagnosis-DPS%4Operatio
nal.evtx
12/15/2012 02:35 PM 69,632 Microsoft-Windows-Diagnosis-Scheduled%4Op
erational.evtx
12/18/2012 04:45 PM 69,632 Microsoft-Windows-Diagnosis-Scripted%4Adm
in.evtx
12/18/2012 04:45 PM 69,632 Microsoft-Windows-Diagnosis-Scripted%4Ope
rational.evtx
12/18/2012 04:50 PM 69,632 Microsoft-Windows-Diagnosis-ScriptedDiagn
osticsProvider%4Operational.evtx
12/21/2012 12:41 AM 1,052,672 Microsoft-Windows-Diagnostics-Performance
%4Operational.evtx
12/21/2012 12:45 PM 1,052,672 Microsoft-Windows-DriverFrameworks-UserMo
de%4Operational.evtx
12/21/2012 12:41 AM 69,632 Microsoft-Windows-Fault-Tolerant-Heap%4Op
erational.evtx
12/21/2012 12:37 PM 1,118,208 Microsoft-Windows-GroupPolicy%4Operationa
l.evtx
12/14/2012 10:57 PM 69,632 Microsoft-Windows-Help%4Operational.evtx
12/21/2012 12:41 AM 69,632 Microsoft-Windows-HomeGroup Provider Serv
ice%4Operational.evtx
12/21/2012 12:35 PM 69,632 Microsoft-Windows-Kernel-EventTracing%4Ad
min.evtx
12/14/2012 10:09 PM 69,632 Microsoft-Windows-Kernel-Power%4Thermal-O
perational.evtx
12/14/2012 10:09 PM 69,632 Microsoft-Windows-Kernel-StoreMgr%4Operat
ional.evtx
12/14/2012 10:09 PM 69,632 Microsoft-Windows-Kernel-WHEA%4Errors.evt
x
12/21/2012 12:31 PM 1,052,672 Microsoft-Windows-Kernel-WHEA%4Operationa
l.evtx
12/21/2012 12:41 AM 69,632 Microsoft-Windows-Known Folders API Servi
ce.evtx
12/15/2012 02:35 PM 69,632 Microsoft-Windows-LanguagePackSetup%4Oper
ational.evtx
12/14/2012 07:29 PM 69,632 Microsoft-Windows-MUI%4Admin.evtx
12/15/2012 02:35 PM 69,632 Microsoft-Windows-MUI%4Operational.evtx
12/14/2012 10:09 PM 69,632 Microsoft-Windows-NCSI%4Operational.evtx
12/14/2012 07:29 PM 69,632 Microsoft-Windows-NetworkAccessProtection
%4Operational.evtx
12/14/2012 07:29 PM 69,632 Microsoft-Windows-NetworkAccessProtection
%4WHC.evtx
12/14/2012 08:01 PM 69,632 Microsoft-Windows-NetworkLocationWizard%4
Operational.evtx
12/21/2012 12:26 PM 1,052,672 Microsoft-Windows-NetworkProfile%4Operati
onal.evtx
12/21/2012 12:27 PM 69,632 Microsoft-Windows-OfflineFiles%4Operation
al.evtx
12/14/2012 10:57 PM 69,632 Microsoft-Windows-PrintService%4Admin.evt
x
12/21/2012 12:41 AM 69,632 Microsoft-Windows-ReadyBoost%4Operational
.evtx
12/21/2012 12:41 AM 69,632 Microsoft-Windows-ReliabilityAnalysisComp
onent%4Operational.evtx
12/14/2012 10:57 PM 69,632 Microsoft-Windows-RemoteDesktopServices-R
dpCoreTS%4Admin.evtx
12/14/2012 10:57 PM 69,632 Microsoft-Windows-RemoteDesktopServices-R
dpCoreTS%4Operational.evtx
12/14/2012 10:57 PM 69,632 microsoft-windows-RemoteDesktopServices-R
emoteDesktopSessionManager%4Admin.evtx
12/21/2012 12:41 AM 69,632 Microsoft-Windows-Resource-Exhaustion-Det
ector%4Operational.evtx
12/21/2012 12:41 AM 69,632 Microsoft-Windows-Resource-Exhaustion-Res
olver%4Operational.evtx
12/14/2012 07:29 PM 69,632 Microsoft-Windows-RestartManager%4Operati
onal.evtx
12/14/2012 10:57 PM 69,632 Microsoft-Windows-TerminalServices-Client
USBDevices%4Admin.evtx
12/14/2012 10:57 PM 69,632 Microsoft-Windows-TerminalServices-Client
USBDevices%4Operational.evtx
12/14/2012 10:09 PM 69,632 Microsoft-Windows-TerminalServices-LocalS
essionManager%4Admin.evtx
12/21/2012 12:41 AM 69,632 Microsoft-Windows-TerminalServices-LocalS
essionManager%4Operational.evtx
12/14/2012 10:57 PM 69,632 Microsoft-Windows-TerminalServices-RDPCli
ent%4Operational.evtx
12/14/2012 10:57 PM 69,632 Microsoft-Windows-TerminalServices-Remote
ConnectionManager%4Admin.evtx
12/14/2012 10:57 PM 69,632 Microsoft-Windows-TerminalServices-Remote
ConnectionManager%4Operational.evtx
12/14/2012 10:57 PM 69,632 Microsoft-Windows-TerminalServices-Server
USBDevices%4Admin.evtx
12/14/2012 10:57 PM 69,632 Microsoft-Windows-TerminalServices-Server
USBDevices%4Operational.evtx
12/21/2012 12:36 PM 69,632 Microsoft-Windows-User Profile Service%4O
perational.evtx
12/21/2012 12:41 AM 69,632 Microsoft-Windows-WER-Diag%4Operational.e
vtx
12/14/2012 09:51 PM 69,632 Microsoft-Windows-Windows Defender%4Opera
tional.evtx
12/14/2012 09:51 PM 69,632 Microsoft-Windows-Windows Defender%4WHC.e
vtx
12/14/2012 10:09 PM 69,632 Microsoft-Windows-Windows Firewall With A
dvanced Security%4ConnectionSecurity.evtx
12/21/2012 12:26 PM 1,052,672 Microsoft-Windows-Windows Firewall With A
dvanced Security%4Firewall.evtx
12/14/2012 07:29 PM 69,632 Microsoft-Windows-WindowsBackup%4ActionCe
nter.evtx
12/15/2012 02:35 PM 1,052,672 Microsoft-Windows-WindowsSystemAssessment
Tool%4Operational.evtx
12/21/2012 12:41 AM 1,052,672 Microsoft-Windows-WindowsUpdateClient%4Op
erational.evtx
12/14/2012 10:09 PM 69,632 Microsoft-Windows-Winlogon%4Operational.e
vtx
12/21/2012 12:26 PM 1,052,672 Microsoft-Windows-WLAN-AutoConfig%4Operat
ional.evtx
12/21/2012 12:25 PM 4,263,936 Security.evtx
12/20/2012 01:18 AM 1,052,672 Setup.evtx
12/21/2012 12:25 PM 18,944,000 System.evtx
12/14/2012 10:09 PM 69,632 Windows PowerShell.evtx
75 File(s) 43,233,280 bytes
2 Dir(s) 73,580,122,112 bytes free
C:\Windows\system32>ICACLS C:\Windows\System32\winevt\logs
C:\Windows\System32\winevt\logs NT SERVICE\eventlog:(OI)(CI)(F)
NT AUTHORITY\SYSTEM:(OI)(CI)(F)
BUILTIN\Administrators:(OI)(CI)(F)
NT AUTHORITY\Authenticated Users:(CI)(R)
Successfully processed 1 files; Failed processing 0 files
C:\Windows\system32>