Skip to content

TechDirectArchive

Hands-on IT, Cloud, Security & DevOps Insights

  • Home
  • About
  • Advertise With US
  • Reviews
  • Contact
  • Toggle search form
Home » Windows Server » How to create a custom view in Windows Event Viewer

How to create a custom view in Windows Event Viewer

Posted on 03/05/202001/10/2023 Christian By Christian No Comments on How to create a custom view in Windows Event Viewer
create a custom view in Windows Event Viewer

Event Logs contain lots of useful information. By creating a custom view in Windows Event Viewer you can easily see the specific errors you want to see. This article was created in order to display Sysmon events as described in this article.

– Launch Windows Event Viewer as shown below

Launch Windows Event Viewer

Click on create Custom View, this will open the window below.
– Select By source and then Sysmon from the drop-down menu

Select By source and then Sysmon

I included all event level as shown below. Other parameters were currently not vital to me. So you can decide to include other parameters as shown below.

Click on OK

Now you can enter the Custom view name (in my case, I will name it Sysmon) as shown below.
– You can choose to enter a description and when you are done,
– Click on Ok.

Enter a Custom view name and description and click OK

The custom view will now appear on the left of the Event Viewer and can be used to analyze events (logs). Don’t forget that the view may be empty if there aren’t any recent activities on the PC or workstation.
– In my case, I simulated and initiated some events already.

the view may be empty if there aren't any recent activities on the PC or workstation

If you found this guide on How to create a custom view in Windows Event Viewer useful, kindly support us and also leave a comment below.

Rate this post

Thank you for reading this post. Kindly share it with others.

  • Share on X (Opens in new window) X
  • Share on Reddit (Opens in new window) Reddit
  • Share on LinkedIn (Opens in new window) LinkedIn
  • Share on Facebook (Opens in new window) Facebook
  • Share on Pinterest (Opens in new window) Pinterest
  • Share on Tumblr (Opens in new window) Tumblr
  • Share on Telegram (Opens in new window) Telegram
  • Share on WhatsApp (Opens in new window) WhatsApp
  • Share on Mastodon (Opens in new window) Mastodon
  • Share on Bluesky (Opens in new window) Bluesky
  • Share on Threads (Opens in new window) Threads
  • Share on Nextdoor (Opens in new window) Nextdoor
Windows Server Tags:Event Viewer, eventlog, Microsoft Windows, Windows Server 2016

Post navigation

Previous Post: Sysmon from SysInternal: What is System Monitor and how to install and use it
Next Post: How to reset your built-in Local Administrator password in Windows 10

Related Posts

  • Configure Data Deduplication on Windows Server
    How to Configure Data Deduplication on Windows Server 2022 Windows Server
  • article 1280x720.192a2586 1 1
    No valid offer received: WDS PXE-E16 error when booting clients Windows Server
  • Uninstall Wampserver
    How to uninstall WAMPServer from Windows Web Server
  • sign11
    Windows sign-in options and account protection on Windows 11 Windows
  • Windows 11 taskbar features remove 1
    How to modify Windows 11 Taskbar via Intune and GPO Windows
  • IIS8
    How to add an account to the local IIS_IUSRS group Windows Server

More Related Articles

Configure Data Deduplication on Windows Server How to Configure Data Deduplication on Windows Server 2022 Windows Server
article 1280x720.192a2586 1 1 No valid offer received: WDS PXE-E16 error when booting clients Windows Server
Uninstall Wampserver How to uninstall WAMPServer from Windows Web Server
sign11 Windows sign-in options and account protection on Windows 11 Windows
Windows 11 taskbar features remove 1 How to modify Windows 11 Taskbar via Intune and GPO Windows
IIS8 How to add an account to the local IIS_IUSRS group Windows Server

Leave a Reply Cancel reply

You must be logged in to post a comment.

Microsoft MVP

VEEAMLEGEND

vexpert-badge-stars-5

Virtual Background

GoogleNews

Categories

veeaam100

Veeam Vanguard

  • linkyourandriodtoyourpc
    Microsoft Phone Link: Connect Android to Windows 11 Windows
  • Dockerxx1
    How to install and uninstall Docker Desktop on Windows 10 and Windows Server Containers
  • win 10 login screen
    Import a user profile in Windows to another PC Windows
  • deactivateandreactivate
    How to deactivate and reactivate a Slack user JIRA|Confluence|Apps
  • Domain
    Connectivity to a writable domain controller from a node could not be determined because of an error Virtualization
  • Syncing Files  and photos with Synology Drive
    Sync file and photos from iOS and Mac with Synology Drive Backup
  • qAS
    How to disable the Microsoft Deployment Toolkit Task Sequence property sheet Windows Server
  • Featured image 1
    How to enable or disable color filters in Windows Windows

Subscribe to Blog via Email

Enter your email address to subscribe to this blog and receive notifications of new posts by email.

Join 1,813 other subscribers
  • RSS - Posts
  • RSS - Comments
  • About
  • Authors
  • Write for us
  • Advertise with us
  • General Terms and Conditions
  • Privacy policy
  • Feedly
  • Telegram
  • Youtube
  • Facebook
  • Instagram
  • LinkedIn
  • Tumblr
  • Pinterest
  • Twitter
  • mastodon

Tags

Active Directory Azure Bitlocker Microsoft Windows PowerShell WDS Windows 10 Windows 11 Windows Deployment Services Windows Server 2016

Copyright © 2025 TechDirectArchive

 

Loading Comments...
 

You must be logged in to post a comment.