Skip to content

TechDirectArchive

Hands-on IT, Cloud, Security & DevOps Insights

  • Home
  • About
  • Advertise With US
  • Reviews
  • Contact
  • Toggle search form
Home » Windows Server » How to create a custom view in Windows Event Viewer
  • Clickable icons Edge Browser
    Remove clickable icons from the Edge browser JIRA|Confluence|Apps
  • Convert MP4 to MP3
    2 Free Ways to Convert MP4 to MP3 Reviews
  • hero activedirectory
    Create and find Organisation Unit paths in AD Scripts
  • FileZilla
    Access FTP Server from your browser: How to create a shortcut and access Filezilla from Windows Explorer Windows Server
  • VeeamIgnite2022
    Veeam at Microsoft Ignite 2022 from 12-14 October Backup
  • Banner
    How to Scan Your Code by Integrating SonarCloud into Your GitHub Repository Security | Vulnerability Scans and Assessment
  • Banner
    How to Stop OneDrive from Starting Up Automatically on Windows 11 Windows
  • Updates Windows Apps with Norton
    How to update Windows Applications with Norton Updater Anti-Virus Solution

How to create a custom view in Windows Event Viewer

Posted on 03/05/202001/10/2023 Christian By Christian No Comments on How to create a custom view in Windows Event Viewer
create a custom view in Windows Event Viewer

Event Logs contain lots of useful information. By creating a custom view in Windows Event Viewer you can easily see the specific errors you want to see. This article was created in order to display Sysmon events as described in this article.

– Launch Windows Event Viewer as shown below

Launch Windows Event Viewer

Click on create Custom View, this will open the window below.
– Select By source and then Sysmon from the drop-down menu

Select By source and then Sysmon

I included all event level as shown below. Other parameters were currently not vital to me. So you can decide to include other parameters as shown below.

Click on OK

Now you can enter the Custom view name (in my case, I will name it Sysmon) as shown below.
– You can choose to enter a description and when you are done,
– Click on Ok.

Enter a Custom view name and description and click OK

The custom view will now appear on the left of the Event Viewer and can be used to analyze events (logs). Don’t forget that the view may be empty if there aren’t any recent activities on the PC or workstation.
– In my case, I simulated and initiated some events already.

the view may be empty if there aren't any recent activities on the PC or workstation

If you found this guide on How to create a custom view in Windows Event Viewer useful, kindly support us and also leave a comment below.

Rate this post

Thank you for reading this post. Kindly share it with others.

  • Share on X (Opens in new window) X
  • Share on Reddit (Opens in new window) Reddit
  • Share on LinkedIn (Opens in new window) LinkedIn
  • Share on Facebook (Opens in new window) Facebook
  • Share on Pinterest (Opens in new window) Pinterest
  • Share on Tumblr (Opens in new window) Tumblr
  • Share on Telegram (Opens in new window) Telegram
  • Share on WhatsApp (Opens in new window) WhatsApp
  • Share on Pocket (Opens in new window) Pocket
  • Share on Mastodon (Opens in new window) Mastodon
  • Share on Bluesky (Opens in new window) Bluesky
  • Share on Threads (Opens in new window) Threads
  • Share on Nextdoor (Opens in new window) Nextdoor
Windows Server Tags:Event Viewer, eventlog, Microsoft Windows, Windows Server 2016

Post navigation

Previous Post: Sysmon from SysInternal: What is System Monitor and how to install and use it
Next Post: How to reset your built-in Local Administrator password in Windows 10

Related Posts

  • featured 2 2
    Clone a repository and install software from GitHub on Windows Windows Server
  • recovery
    Perform System State Restore of Active Directory via Windows Server backup utility Windows Server
  • maxresdefault
    Error 0x8007232B: Can’t activate Windows on this device as we can’t connect to your organization’s activation server Windows
  • article 1280x720.78eff5c4
    How to reset your built-in Local Administrator password in Windows 10 Windows Server
  • maxresdefault
    How to join a computer to the Domain Windows Server
  • Fix Boot Failed UEFI SCSI Device on HyperV
    How to Fix Boot Failed UEFI SCSI Device on HyperV Virtualization

More Related Articles

featured 2 2 Clone a repository and install software from GitHub on Windows Windows Server
recovery Perform System State Restore of Active Directory via Windows Server backup utility Windows Server
maxresdefault Error 0x8007232B: Can’t activate Windows on this device as we can’t connect to your organization’s activation server Windows
article 1280x720.78eff5c4 How to reset your built-in Local Administrator password in Windows 10 Windows Server
maxresdefault How to join a computer to the Domain Windows Server
Fix Boot Failed UEFI SCSI Device on HyperV How to Fix Boot Failed UEFI SCSI Device on HyperV Virtualization

Leave a Reply Cancel reply

You must be logged in to post a comment.

Microsoft MVP

VEEAMLEGEND

vexpert-badge-stars-5

Virtual Background

GoogleNews

Categories

veeaam100

sysadmin top30a

  • Clickable icons Edge Browser
    Remove clickable icons from the Edge browser JIRA|Confluence|Apps
  • Convert MP4 to MP3
    2 Free Ways to Convert MP4 to MP3 Reviews
  • hero activedirectory
    Create and find Organisation Unit paths in AD Scripts
  • FileZilla
    Access FTP Server from your browser: How to create a shortcut and access Filezilla from Windows Explorer Windows Server
  • VeeamIgnite2022
    Veeam at Microsoft Ignite 2022 from 12-14 October Backup
  • Banner
    How to Scan Your Code by Integrating SonarCloud into Your GitHub Repository Security | Vulnerability Scans and Assessment
  • Banner
    How to Stop OneDrive from Starting Up Automatically on Windows 11 Windows
  • Updates Windows Apps with Norton
    How to update Windows Applications with Norton Updater Anti-Virus Solution

Subscribe to Blog via Email

Enter your email address to subscribe to this blog and receive notifications of new posts by email.

Join 1,832 other subscribers
  • RSS - Posts
  • RSS - Comments
  • About
  • Authors
  • Write for us
  • Advertise with us
  • General Terms and Conditions
  • Privacy policy
  • Feedly
  • Telegram
  • Youtube
  • Facebook
  • Instagram
  • LinkedIn
  • Tumblr
  • Pinterest
  • Twitter
  • mastodon

Tags

Active Directory AWS Azure Bitlocker Microsoft Windows PowerShell WDS Windows 10 Windows 11 Windows Server 2016

Copyright © 2025 TechDirectArchive

 

Loading Comments...
 

You must be logged in to post a comment.