Windows Event Viewer Guide

View this project on GitHub


1. System Crashes or Unexpected Reboots

Log Location: Windows Logs → System
Other Related Event IDs:

6008 - Unexpected Shutdown

6008.png 6008-2.png

41 (Kernel-Power) - System Rebooted without Clean Shutdown

41.png




2. Application Crashes or Freezes

Log Location: Windows Logs → Application

1000 - Application Error

1000.png

1001 - Windows Error Reporting

1001.png" 1001-2.png"

1002 - Application Hang

1002.png




3. User Account Logon/Logoff Issues

Log Location: Windows Logs → Security

4624 - Successful Logon

4624.png

4625 - Logon Failure

4652.PNG

4634 - Logoff Events

4634.PNG 4634-2.PNG




4. Windows Update Problems

Log Location: Windows Logs → System, Applications and Services Logs → Microsoft → Windows → WindowsUpdateClient → Operational
WU1.png WU2.png
WU3.png WU4.png




5. Group Policy (GPO) Issues

Log Location: Applications and Services Logs → Microsoft → Windows → GroupPolicy → Operational
Other Related Event IDs:

7017

7017.png

1129

1129.png 1129-2.png




6. Performance Issues (Slow Boot or Login)

Log Location: Applications and Services Logs → Microsoft → Windows → Diagnostics-Performance → Operational

100 - Boot Performance

100.png 100-2.png

101 - Application Performance

101.png 101-2.png

200

200.png




7. Driver Issues or Device Failures

Log Location: Windows Logs → System

7000 - Service Failed to Start

7000.png

7001

7001.png

7026 - Driver Loading Failures

7026.png 7026-2.png




8. Malware or Security Incidents

Log Location: Windows Logs → Security, Application, Windows Defender

Malware Detection - Windows Defender

1116

1116.png 1116-2.png

1117

1117.png 1117-2.png

4625 - Multiple Failed Login Attempts

MFailedLA.png




9. Print Job Failures

Log Location: Applications and Services Logs → Microsoft → Windows → PrintService → Operational

307

307.png 307-2.png

7031 - Spooler service errors

7031.png 7031.png


Best Practices for Using Event Viewer

Back to Home