How to Check the Windows Event Log (Event Viewer Guide)

Windows keeps detailed logs of what happens on your PC, including crashes, errors, failed updates, unexpected shutdowns, sign-ins, and service problems. When something goes wrong, the Windows Event Log is usually the first place to look. This guide shows how to open Event Viewer, which logs matter, how to filter out the noise, which event IDs to know, and how to check logs from PowerShell. It also explains why a few red errors are normal.

Quick Answer

Press Windows key + R, type eventvwr.msc, and press Enter. Expand Windows Logs and click System (hardware, drivers, and shutdowns) or Application (app crashes). Click Filter Current Log, check Critical and Error, pick a time range, and click OK. Then click an event to read its details.

Event Viewer Filter Current Log dialog with Critical and Error levels checked and a Last 7 days time range, with the OK button highlighted
Filter to Critical and Error events (1) for a recent time range and click OK (2) to cut through the noise.

Open Event Viewer

  • Press Windows + R, type eventvwr.msc, and press Enter.
  • Or right-click Start and choose Event Viewer.
  • Or search Start for Event Viewer.

Security logs require an administrator account. Other logs are readable by standard users.

Which Log Should You Check?

Log What it records Check it for
System Windows components, drivers, hardware, power Blue screens, unexpected restarts, driver and disk errors
Application Programs and app components App crashes and freezes
Security Sign-ins, account changes, audit events Failed sign-ins, who logged in when
Setup Windows installs and updates Update installation problems
Applications and Services Logs Detailed logs for specific components Windows Update, Defender, and other deep troubleshooting

For a quick overview across all logs, open Custom Views > Administrative Events, which shows only warnings, errors, and critical events.

Filter the Log

  1. Click a log, such as System.
  2. In the right-hand Actions pane, click Filter Current Log.
  3. Set Logged (for example, Last 24 hours or Last 7 days).
  4. Check Critical and Error (and Warning if needed).
  5. To find specific events, type IDs in the <All Event IDs> box, such as 41, 1001, 6008.
  6. Click OK. Click Clear Filter to see everything again.

To save a filter for reuse, click Create Custom View with the same settings.

Useful Event IDs

Event ID Log / Source Meaning
41 System / Kernel-Power The PC restarted without shutting down cleanly
1001 System / BugCheck A blue screen occurred (includes the stop code)
6008 System / EventLog The previous shutdown was unexpected
6005 / 6006 System / EventLog Event log service started / stopped (boot and shutdown times)
1074 System / User32 A user or program started a shutdown or restart (shows which)
7031 / 7034 System / Service Control Manager A service stopped unexpectedly
1000 Application / Application Error A program crashed (shows the app and faulting module)
4624 / 4625 Security Successful / failed sign-in

Read an Event

  • The General tab describes what happened in plain text.
  • The Details tab shows raw data, such as the BugcheckCode in a Kernel-Power 41 event.
  • Note the Source and Event ID, then search them together for known fixes.

Check Event Logs with PowerShell

Task Command
Latest 20 System errors Get-WinEvent -FilterHashtable @{LogName='System'; Level=1,2} -MaxEvents 20
Unexpected shutdowns Get-WinEvent -FilterHashtable @{LogName='System'; Id=41,6008} -MaxEvents 10
App crashes in the last day Get-WinEvent -FilterHashtable @{LogName='Application'; Id=1000; StartTime=(Get-Date).AddDays(-1)}
Export a log wevtutil epl System C:\Temp\System.evtx

Save, Share, or Clear Logs

  • Save: right-click a log and choose Save All Events As (.evtx) to send to a technician.
  • Clear: right-click a log and choose Clear Log. Save it first if you might need it, because clearing can’t be undone.

Don’t Panic About Every Error

Every Windows PC logs errors and warnings that are harmless, such as a service timing out at startup or a DCOM warning. Focus on errors that line up with the time your problem happened, or ones that repeat. Beware of phone calls or pop-ups that point to Event Viewer errors as “proof” of a virus. That’s a common tech-support scam.

Reliability Monitor: A Friendlier View

Run perfmon /rel to see a day-by-day timeline of crashes, failures, and updates. Click any red X for details. It’s the easiest way to connect a problem to an update or new driver. For crash details, see our guide to checking blue screen logs.

Investigating a crash? Read why Windows 10 crashes and how to diagnose it.

Frequently Asked Questions

Where are Windows event log files stored?

In C:\Windows\System32\winevt\Logs as .evtx files. Open them through Event Viewer rather than editing them directly.

How far back do event logs go?

Each log has a maximum size and overwrites old events when full. Right-click a log and choose Properties to see or change its size.

Is this the same in Windows 11?

Yes. Event Viewer works the same in Windows 10 and Windows 11.

Summary

  1. Open Event Viewer with eventvwr.msc.
  2. Check Windows Logs > System and Application, or Administrative Events.
  3. Filter to Critical and Error for the time of the problem.
  4. Look up the Source and Event ID, using the table above as a starting point.
  5. Use Get-WinEvent or Reliability Monitor for faster checks.