Windows system log analysis

【Purpose】

Understand the Windows system log and understand the basic usage of the LogParser tool

【software tools】 

OS: Windows7 Software: Event Viewer, LogParser

【Experimental Objective】

1. Use Event Viewer to analyze Windows system logs

2. Use LogParser to analyze Windows logs

【Experimental steps】

Analyze Windows System Logs Using Event Viewer

 Enter eventvwr in cmd and press Enter to open the event viewer, and you can see that there are two categories of Windows logs and application and service logs in the event viewer.

Open the windows security section

 Filter the current log Nearly 24 hours

 View Results

 

Log out of account, log in again

Open the event manager, windows log - security - login

 

View special login

 

Windows log storage location

Double click to view security log

Use the Log program to analyze logs

 

 Use the tool to count the amount of packets

 

 Enter type a.csv

 

 Query security logs

 

 View Results

 

Guess you like

Origin blog.csdn.net/weixin_62757215/article/details/130121501