﻿<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/"><channel><title>LogViewPlus Support » LogViewPlus Support » Help &amp; Support  » EVTX Windows Event Logs</title><generator>InstantForum 2017-1 Final</generator><description>LogViewPlus Support</description><link>https://www.logviewplus.com/forum/</link><webMaster>LogViewPlus Support</webMaster><lastBuildDate>Mon, 13 Apr 2026 08:38:02 GMT</lastBuildDate><ttl>20</ttl><item><title>EVTX Windows Event Logs</title><link>https://www.logviewplus.com/forum/post/1951</link><description>Perhaps I'm missing it, but when I open EVTX logs, I don't seem to be able to find important information such as the EventID&lt;br/&gt;&lt;br/&gt;We'd like to use LogViewPlus to review Windows Event Logs but we must have access to things like the Event ID.&amp;nbsp; Here is an example with a few system names redacted)&lt;br/&gt;&lt;br/&gt;It seems that items in the System section that I changed to red are only partially visible in LogView Plus. Missing are EventID, Task, EventRecordID etc.&lt;br/&gt;&lt;br/&gt;Windows Event Viewer&lt;br/&gt;&lt;font color="#de1f62"&gt;- System &lt;br/&gt;&lt;br/&gt;  - Provider &lt;br/&gt;&lt;br/&gt;&amp;nbsp;[ Name]  Microsoft-Windows-Security-Auditing &lt;br/&gt;&amp;nbsp;[ Guid]  {54849625-5478-4994-a5ba-3e3b0328c30d} &lt;br/&gt;&lt;/font&gt; &lt;font color="#de1f62"&gt;&lt;br/&gt;&amp;nbsp;EventID 4627 &lt;br/&gt;&lt;/font&gt; &lt;font color="#de1f62"&gt;&lt;br/&gt;&amp;nbsp;Version 0 &lt;br/&gt;&lt;/font&gt; &lt;font color="#de1f62"&gt;&lt;br/&gt;&amp;nbsp;Level 0 &lt;br/&gt;&lt;/font&gt; &lt;font color="#de1f62"&gt;&lt;br/&gt;&amp;nbsp;Task 12554 &lt;br/&gt;&lt;/font&gt; &lt;font color="#de1f62"&gt;&lt;br/&gt;&amp;nbsp;Opcode 0 &lt;br/&gt;&lt;/font&gt; &lt;font color="#de1f62"&gt;&lt;br/&gt;&amp;nbsp;Keywords 0x8020000000000000 &lt;br/&gt;&lt;/font&gt; &lt;font color="#de1f62"&gt;&lt;br/&gt;  - TimeCreated &lt;br/&gt;&lt;br/&gt;&amp;nbsp;[ SystemTime]  2023-07-27T08:57:11.7157887Z &lt;br/&gt;&lt;/font&gt; &lt;font color="#de1f62"&gt;&lt;br/&gt;&amp;nbsp;EventRecordID 1258569507 &lt;br/&gt;&lt;/font&gt; &lt;font color="#de1f62"&gt;&lt;br/&gt;&amp;nbsp;Correlation &lt;br/&gt;&lt;/font&gt; &lt;font color="#de1f62"&gt;&lt;br/&gt;  - Execution &lt;br/&gt;&lt;br/&gt;&amp;nbsp;[ ProcessID]  796 &lt;br/&gt;&amp;nbsp;[ ThreadID]  4624 &lt;br/&gt;&lt;/font&gt; &lt;font color="#de1f62"&gt;&lt;br/&gt;&amp;nbsp;Channel Security &lt;br/&gt;&lt;/font&gt; &lt;font color="#de1f62"&gt;&lt;br/&gt;&amp;nbsp;Computer &amp;lt;REDACTED&amp;gt;&lt;br/&gt;&lt;/font&gt; &lt;font color="#de1f62"&gt;&lt;br/&gt;&amp;nbsp;Security &lt;/font&gt;&lt;br/&gt; &lt;br/&gt;&lt;br/&gt;- EventData &lt;br/&gt;&lt;br/&gt;  SubjectUserSid S-1-0-0 &lt;br/&gt;  SubjectUserName - &lt;br/&gt;  SubjectDomainName - &lt;br/&gt;  SubjectLogonId 0x0 &lt;br/&gt;  TargetUserSid S-1-5-21-88556453-236079572-1039276024-9947 &lt;br/&gt;  TargetUserName LUS14$ &lt;br/&gt;  TargetDomainName &amp;lt;REDACTED&amp;gt;&lt;br/&gt;  TargetLogonId 0x185ebff4 &lt;br/&gt;  LogonType 3 &lt;br/&gt;  EventIdx 1 &lt;br/&gt;  EventCountTotal 1 &lt;br/&gt;  GroupMembership %{S-1-5-21-88556453-236079572-1039276024-515} %{S-1-1-0} %{S-1-5-32-554} %{S-1-5-2} %{S-1-5-11} %{S-1-5-15} %{S-1-18-1} %{S-1-5-21-88556453-236079572-1039276024-8380} %{S-1-16-8448} &lt;br/&gt;&lt;br/&gt;&lt;br/&gt;Here it is within LogViewPlus&lt;br/&gt;&lt;br/&gt;2023-07-27T04:57:11 Information [&amp;lt;Redacted&amp;gt;Security.Microsoft-Windows-Security-Auditing] Group membership information.&lt;br/&gt;&lt;br/&gt;Subject:&lt;br/&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;Security ID:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;S-1-0-0&lt;br/&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;Account Name:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;-&lt;br/&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;Account Domain:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;-&lt;br/&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;Logon ID:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;0x0&lt;br/&gt;&lt;br/&gt;Logon Type:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;3&lt;br/&gt;&lt;br/&gt;New Logon:&lt;br/&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;Security ID:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;S-1-5-21-88556453-236079572-1039276024-9947&lt;br/&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;Account Name:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;LUS14$&lt;br/&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;Account Domain:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;  &amp;lt;REDACTED&amp;gt;&lt;br/&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;Logon ID:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;0x185EBFF4&lt;br/&gt;&lt;br/&gt;Event in sequence:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;1 of 1&lt;br/&gt;&lt;br/&gt;Group Membership:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;br/&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;%{S-1-5-21-88556453-236079572-1039276024-515}&lt;br/&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;%{S-1-1-0}&lt;br/&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;%{S-1-5-32-554}&lt;br/&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;%{S-1-5-2}&lt;br/&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;%{S-1-5-11}&lt;br/&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;%{S-1-5-15}&lt;br/&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;%{S-1-18-1}&lt;br/&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;%{S-1-5-21-88556453-236079572-1039276024-8380}&lt;br/&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;%{S-1-16-8448}&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;</description><pubDate>Sat, 09 Dec 2023 17:52:00 GMT</pubDate><dc:creator>TimHum</dc:creator></item><item><title>RE: EVTX Windows Event Logs</title><link>https://www.logviewplus.com/forum/post/1961</link><description>&amp;gt; It made short work of searching the millions of event log records&lt;br/&gt;&lt;br/&gt;Awesome!&amp;nbsp; Glad to hear you are finding LogViewPlus helpful.&amp;nbsp; &lt;span id="if_insertedNode_1702144143699"&gt;:)&lt;/span&gt;&amp;nbsp; &lt;br/&gt;&lt;br/&gt;I will keep you posted about the next BETA release.&amp;nbsp; I think there is a lot more that we could be doing to make Windows Event logs easier to understand.</description><pubDate>Sat, 09 Dec 2023 17:52:00 GMT</pubDate><dc:creator>LogViewPlus Support</dc:creator></item><item><title>RE: EVTX Windows Event Logs</title><link>https://www.logviewplus.com/forum/post/1957</link><description>Okay, thanks! And at least I'm not crazy.&amp;nbsp; I did try to read the manual and look through this support forum before making my claim.&amp;nbsp; I'm glad you confirmed I didn't miss anything obvious.&lt;br/&gt;&lt;br/&gt;Honestly I don't yet have any suggestions other than the just making all the eventlog data fields available to us :)&lt;br/&gt;&lt;br/&gt;We're just now expanding our use of LogView beyond the primarily basic Syslogs and MTA Spam filter logs.&amp;nbsp; We're now expanding our templates and parsers as we implement larger scale use across our team and applications.&lt;br/&gt;&lt;br/&gt;I had never used the EVTX portion of LogView until a few weeks ago where we had to go through 6 months of Windows Security Audit logs due to a rogue Active Directory Administrator.&amp;nbsp; Even with the missing EventID, LogView saved us a ton of time.&amp;nbsp; It made short work of searching the millions of event log records so we could prove to management what this Admin did.&amp;nbsp; Thank you&lt;br/&gt;</description><pubDate>Sat, 09 Dec 2023 16:03:29 GMT</pubDate><dc:creator>TimHum</dc:creator></item><item><title>RE: EVTX Windows Event Logs</title><link>https://www.logviewplus.com/forum/post/1956</link><description>Hi Tim,&lt;br/&gt;&lt;br/&gt;That is an excellent point.&amp;nbsp; Thanks for highlighting this.&amp;nbsp; You are absolutely right that this information needs to be available as separate columns within LogViewPlus.&amp;nbsp; This is not currently available and frankly I am not sure why - they should be there.&lt;br/&gt;&lt;br/&gt;We have a new release of LogViewPlus coming out in the next few days.&amp;nbsp; Once this release is complete, we will be giving Windows Event Logs a lot more attention.&amp;nbsp; We think being able to analyse Windows Event Logs with the LogViewPlus SQL engine will be really powerful.&amp;nbsp; We want to include prebuilt dashboards similar to our current Web Log and Java GC solutions (currently in BETA).&amp;nbsp; A key step in that process will be adding some of the fields you highlighted above.&lt;br/&gt;&lt;br/&gt;This Windows Event Log release should be out in January.&amp;nbsp; If you have any suggests or ideas for what you would like to see when you open a Windows Event Log, please do let us know.&lt;br/&gt;&lt;br/&gt;Thanks again,&lt;br/&gt;&lt;br/&gt;Toby</description><pubDate>Sat, 09 Dec 2023 11:14:38 GMT</pubDate><dc:creator>LogViewPlus Support</dc:creator></item></channel></rss>