Skip to content

TechDirectArchive

Hands-on IT, Cloud, Security & DevOps Insights

  • Home
  • About
  • Advertise With US
  • Reviews
  • Contact
  • Toggle search form
Home » Windows Server » How to create a custom view in Windows Event Viewer
  • Docker OSTypelinux
    The executor requires OSType=windows, but Docker Engine supports only OSType=linux Containers
  • sql stuck
    How to uninstall Microsoft SQL Server Management Studio Oracle/MSSQL/MySQL
  • Configure Synology DS923+ NAS for File Sharing
    How to Configure Synology DS923+ NAS for File Sharing [Part 2] Reviews
  • Bulk operations in Azure AD
    Perform Bulk User Operations in Azure AD AWS/Azure/OpenShift
  • postgresql on windows
    Install PostgreSQL on Windows server as Veeam Database Engine Oracle/MSSQL/MySQL
  • newsroom hero image password security
    Unable to update the password value provided for the new password and Password Policy Windows Server
  • Featured image DNS Server settings
    Do not use Public DNS in Prod: Change DNS Server in Windows Network | Monitoring
  • screenshot 2020 04 06 at 04.12.00
    How to install and Configure Pleasant Reset Password Virtualization

How to create a custom view in Windows Event Viewer

Posted on 03/05/202001/10/2023 Christian By Christian No Comments on How to create a custom view in Windows Event Viewer
create a custom view in Windows Event Viewer

Event Logs contain lots of useful information. By creating a custom view in Windows Event Viewer you can easily see the specific errors you want to see. This article was created in order to display Sysmon events as described in this article.

– Launch Windows Event Viewer as shown below

Launch Windows Event Viewer

Click on create Custom View, this will open the window below.
– Select By source and then Sysmon from the drop-down menu

Select By source and then Sysmon

I included all event level as shown below. Other parameters were currently not vital to me. So you can decide to include other parameters as shown below.

Click on OK

Now you can enter the Custom view name (in my case, I will name it Sysmon) as shown below.
– You can choose to enter a description and when you are done,
– Click on Ok.

Enter a Custom view name and description and click OK

The custom view will now appear on the left of the Event Viewer and can be used to analyze events (logs). Don’t forget that the view may be empty if there aren’t any recent activities on the PC or workstation.
– In my case, I simulated and initiated some events already.

the view may be empty if there aren't any recent activities on the PC or workstation

If you found this guide on How to create a custom view in Windows Event Viewer useful, kindly support us and also leave a comment below.

Rate this post

Thank you for reading this post. Kindly share it with others.

  • Click to share on X (Opens in new window) X
  • Click to share on Reddit (Opens in new window) Reddit
  • Click to share on LinkedIn (Opens in new window) LinkedIn
  • Click to share on Facebook (Opens in new window) Facebook
  • Click to share on Pinterest (Opens in new window) Pinterest
  • Click to share on Tumblr (Opens in new window) Tumblr
  • Click to share on Telegram (Opens in new window) Telegram
  • Click to share on WhatsApp (Opens in new window) WhatsApp
  • Click to share on Pocket (Opens in new window) Pocket
  • Click to share on Mastodon (Opens in new window) Mastodon
  • Click to share on Bluesky (Opens in new window) Bluesky
  • Click to share on Threads (Opens in new window) Threads
  • Click to share on Nextdoor (Opens in new window) Nextdoor
Windows Server Tags:Event Viewer, eventlog, Microsoft Windows, Windows Server 2016

Post navigation

Previous Post: Sysmon from SysInternal: What is System Monitor and how to install and use it
Next Post: How to reset your built-in Local Administrator password in Windows 10

Related Posts

  • sql server installation
    How to Install all Editions of Microsoft SQL Server 2025 Oracle/MSSQL/MySQL
  • windows update 03
    Check if Windows Updates were installed via the Registry Editor Windows
  • fix Client Certificate Mapping Authentication error
    How to fix Client Certificate Mapping Authentication error Backup
  • yxxycx yx
    How to change the Default First-Site-Name in Active Directory Windows Server
  • Screenshot 2020 05 24 at 22.40.50
    The security database on the server does not have a computer account for this workstation trust relation [Part 1] Windows Server
  • dfggg 1
    Configuring SimpleSAMLPHP Windows Server

More Related Articles

sql server installation How to Install all Editions of Microsoft SQL Server 2025 Oracle/MSSQL/MySQL
windows update 03 Check if Windows Updates were installed via the Registry Editor Windows
fix Client Certificate Mapping Authentication error How to fix Client Certificate Mapping Authentication error Backup
yxxycx yx How to change the Default First-Site-Name in Active Directory Windows Server
Screenshot 2020 05 24 at 22.40.50 The security database on the server does not have a computer account for this workstation trust relation [Part 1] Windows Server
dfggg 1 Configuring SimpleSAMLPHP Windows Server

Leave a Reply Cancel reply

You must be logged in to post a comment.

Microsoft MVP

VEEAMLEGEND

vexpert-badge-stars-5

Virtual Background

GoogleNews

Categories

veeaam100

sysadmin top30a
 
  • Docker OSTypelinux
    The executor requires OSType=windows, but Docker Engine supports only OSType=linux Containers
  • sql stuck
    How to uninstall Microsoft SQL Server Management Studio Oracle/MSSQL/MySQL
  • Configure Synology DS923+ NAS for File Sharing
    How to Configure Synology DS923+ NAS for File Sharing [Part 2] Reviews
  • Bulk operations in Azure AD
    Perform Bulk User Operations in Azure AD AWS/Azure/OpenShift
  • postgresql on windows
    Install PostgreSQL on Windows server as Veeam Database Engine Oracle/MSSQL/MySQL
  • newsroom hero image password security
    Unable to update the password value provided for the new password and Password Policy Windows Server
  • Featured image DNS Server settings
    Do not use Public DNS in Prod: Change DNS Server in Windows Network | Monitoring
  • screenshot 2020 04 06 at 04.12.00
    How to install and Configure Pleasant Reset Password Virtualization

Subscribe to Blog via Email

Enter your email address to subscribe to this blog and receive notifications of new posts by email.

Join 1,841 other subscribers
  • RSS - Posts
  • RSS - Comments
  • About
  • Authors
  • Write for us
  • Advertise with us
  • General Terms and Conditions
  • Privacy policy
  • Feedly
  • Telegram
  • Youtube
  • Facebook
  • Instagram
  • LinkedIn
  • Tumblr
  • Pinterest
  • Twitter
  • mastodon

Tags

AWS Azure Bitlocker Microsoft Windows PowerShell WDS Windows 10 Windows 11 Windows Deployment Services Windows Server 2016

Copyright © 2025 TechDirectArchive

 

Loading Comments...
 

You must be logged in to post a comment.