Windows XML Event Log (EVTX)

From Forensics Wiki
Revision as of 09:37, 9 February 2013 by Joachim Metz (Talk | contribs)

Jump to: navigation, search

Information icon.png

Please help to improve this article by expanding it.
Further information might be found on the discussion page.

The Windows XML Event Log (EVTX) format was introduces in Windows Vista as a replacement for the Windows Event Log (EVT) format.

Windows EventViewer can represent the EVTX files in both "formatted view" and "XML view". Note that the formatted view can hide significant event data that is stored in the event and can be seen in the XML view.

Contents

Event Viewer

On Windows the event logs can be managed with "Event Viewer" (eventvwr.msc) or "Windows Events Command Line Utility" (wevtutil.exe).

If you export an event log from Event Viewer additional "display information" can be exported. This "display information" is stored in a corresponding "%FILENAME%_%LCID%.MTA", where LCID is the "locale identifier" [1].

Application_1033.MTA

See Also

External Links

File Format

Event Identifiers

Windows Vista/2008

Windows 7

Tools