Skip to content

TechDirectArchive

Hands-on IT, Cloud, Security & DevOps Insights

  • Home
  • About
  • Advertise With US
  • Reviews
  • Contact
  • Toggle search form
Home » Windows Server » How to create a custom view in Windows Event Viewer

How to create a custom view in Windows Event Viewer

Posted on 03/05/202001/10/2023 Christian By Christian No Comments on How to create a custom view in Windows Event Viewer
create a custom view in Windows Event Viewer

Event Logs contain lots of useful information. By creating a custom view in Windows Event Viewer you can easily see the specific errors you want to see. This article was created in order to display Sysmon events as described in this article.

– Launch Windows Event Viewer as shown below

Launch Windows Event Viewer

Click on create Custom View, this will open the window below.
– Select By source and then Sysmon from the drop-down menu

Select By source and then Sysmon

I included all event level as shown below. Other parameters were currently not vital to me. So you can decide to include other parameters as shown below.

Click on OK

Now you can enter the Custom view name (in my case, I will name it Sysmon) as shown below.
– You can choose to enter a description and when you are done,
– Click on Ok.

Enter a Custom view name and description and click OK

The custom view will now appear on the left of the Event Viewer and can be used to analyze events (logs). Don’t forget that the view may be empty if there aren’t any recent activities on the PC or workstation.
– In my case, I simulated and initiated some events already.

the view may be empty if there aren't any recent activities on the PC or workstation

If you found this guide on How to create a custom view in Windows Event Viewer useful, kindly support us and also leave a comment below.

Rate this post

Thank you for reading this post. Kindly share it with others.

  • Share on X (Opens in new window) X
  • Share on Reddit (Opens in new window) Reddit
  • Share on LinkedIn (Opens in new window) LinkedIn
  • Share on Facebook (Opens in new window) Facebook
  • Share on Pinterest (Opens in new window) Pinterest
  • Share on Tumblr (Opens in new window) Tumblr
  • Share on Telegram (Opens in new window) Telegram
  • Share on WhatsApp (Opens in new window) WhatsApp
  • Share on Mastodon (Opens in new window) Mastodon
  • Share on Bluesky (Opens in new window) Bluesky
  • Share on Threads (Opens in new window) Threads
  • Share on Nextdoor (Opens in new window) Nextdoor
Windows Server Tags:Event Viewer, eventlog, Microsoft Windows, Windows Server 2016

Post navigation

Previous Post: Sysmon from SysInternal: What is System Monitor and how to install and use it
Next Post: How to reset your built-in Local Administrator password in Windows 10

Related Posts

  • Install Lets Encrypt Certificate on Windows with Certbot
    Install Lets Encrypt Certificate on Windows with Certbot Web Server
  • screenshot 2020 02 08 at 20.02.50
    Windows 10 Administrative Shortcut command key Windows Server
  • How To Enable Single Sign On (SSO) For Windows Admin Center
    Setup Windows Admin Center Modern Gateway for Single Sign-On Windows Server
  • windows server
    How to backup and restore a Windows DHCP Server via the DHCP Manager and PowerShell Windows Server
  • PowerShell logo
    PowerShell: How to update PowerShellGet and Package Management Windows Server
  • dfggg 1
    Configuring SimpleSAMLPHP Windows Server

More Related Articles

Install Lets Encrypt Certificate on Windows with Certbot Install Lets Encrypt Certificate on Windows with Certbot Web Server
screenshot 2020 02 08 at 20.02.50 Windows 10 Administrative Shortcut command key Windows Server
How To Enable Single Sign On (SSO) For Windows Admin Center Setup Windows Admin Center Modern Gateway for Single Sign-On Windows Server
windows server How to backup and restore a Windows DHCP Server via the DHCP Manager and PowerShell Windows Server
PowerShell logo PowerShell: How to update PowerShellGet and Package Management Windows Server
dfggg 1 Configuring SimpleSAMLPHP Windows Server

Leave a Reply Cancel reply

You must be logged in to post a comment.

Microsoft MVP

VEEAMLEGEND

vexpert-badge-stars-5

Virtual Background

GoogleNews

Categories

veeaam100

Veeam Vanguard

  • db nginxseriesanisibleplaybook 1540x748 1
    How to install and configure Ansible on Ubuntu Configuration Management Tool
  • How to Decrypt Files and Folders Encrypted with EFS in Windows 10
    How to decrypt Files and Folders Encrypted with an Encryption File System (EFS) in Windows Windows
  • fix this PC cannot run on Windows
    How to Fix “This PC Can’t Run Windows 11” on Hyper Windows
  • iso10
    Mount an ISO image in Windows 10 and 11 Windows
  • 7164 1024x575 1
    How to install MDT PowerShell module on Windows Scripts
  • BitLocker beviour when MBAM Agent is removed   No uninstall options in control panel to remove app
    BitLocker behavior when MBAM agent is removed: No Uninstall Option in Control Panel Windows
  • Blog inside@2x
    How to block automatic delivery of Microsoft Edge Chromium-based Windows
  • gnome
    Determine the version of GNOME running on your Ubuntu Linux Network | Monitoring

Subscribe to Blog via Email

Enter your email address to subscribe to this blog and receive notifications of new posts by email.

Join 1,823 other subscribers
  • RSS - Posts
  • RSS - Comments
  • About
  • Authors
  • Write for us
  • Advertise with us
  • General Terms and Conditions
  • Privacy policy
  • Feedly
  • Telegram
  • Youtube
  • Facebook
  • Instagram
  • LinkedIn
  • Tumblr
  • Pinterest
  • Twitter
  • mastodon

Tags

Active Directory Azure Bitlocker Microsoft Windows PowerShell WDS Windows 10 Windows 11 Windows Deployment Services Windows Server 2016

Copyright © 2025 TechDirectArchive

 

Loading Comments...
 

You must be logged in to post a comment.