Windows Vista New Event Viewer

Here’s a good surprise: the Event Viewer has had a complete reengineering. The new Event Viewer:

• Can collect events from many systems to one system’s log, allowing you to centralize event logs.

• Lets you easily tell it what to do if particular events occur, like telling it to send you an e-mail, run a program, reboot a system, or the like.

• Allows you to create custom queries so you can essentially tweak Event Viewer to show you just the things that you want to see.

• Event Viewer Reports its data in XML.

There are several ways to start Event Viewer
• If you reenabled the Start Run… command as I suggested earlier in this chapter, just click Start/Run… and then fill in eventvwr and click OK.

• If you restored Administrative Tools to your Start menu, then just click Start Administrative Tools –> Event Viewer.

• Alternatively you’ll need to do a little spelunking in Control Panel: click Start –> Control Panel –> System and Maintenance and, under “Administrative Tools,” click “View event logs.”

XML Format Comes to Event Viewer
Yes, I know, you’ve heard the abbreviation “XML” far too often, but here’s a case where you’ll like it. Let’s take an example event, a simple security event that reports that the system’s time was successfully changed.

Note at first that Event Viewer presents the event in a different format than the one that we’ve seen since NT 3.1. Notice that there’s a button that’s actually labeled “Copy” instead of hoping that you just somehow know that the button on the XP Event Viewer that looks like two pieces of paper means “click this and the relevant stuff from this event will be copied in ASCII text format to the Clipboard.”

Custom Queries Lets You Customize Event Viewer
It’s always been possible to filter items in Event Viewer in a simple way by right-clicking in the Event Log, choosing New Log View, and then adjusting its filter properties. But Vista’s Event Viewer takes it a bit further.

Like the old Event Viewer, you get a pane down the left-hand side listing the logs that you can peruse. But instead of the standard Application, System and Security, Vista’s Event Viewer fine-tunes your events into dozens of smaller “sub-logs.” You can see in its right-hand pane a summary of entries and, you’ll note, there are more levels of event than Information, Warning, Error, Audit Success, and Audit Failure; now there’s also Critical. But look in the upper left-hand corner and you’ll notice a folder called “Custom Views” and, inside that, a folder named “Administrative Events.”

Related Post

If you enjoyed this post, please consider to leave a comment or subscribe to the feed and get future articles delivered to your feed reader.

Comments

No comments yet.

Leave a comment

(required)

(required)


All incoming search terms for this post