Skip to content

TechDirectArchive

Hands-on IT, Cloud, Security & DevOps Insights

  • Home
  • About
  • Advertise With US
  • Reviews
  • Contact
  • Toggle search form
Home » Windows Server » How to create a custom view in Windows Event Viewer

How to create a custom view in Windows Event Viewer

Posted on 03/05/202001/10/2023 Christian By Christian No Comments on How to create a custom view in Windows Event Viewer
create a custom view in Windows Event Viewer

Event Logs contain lots of useful information. By creating a custom view in Windows Event Viewer you can easily see the specific errors you want to see. This article was created in order to display Sysmon events as described in this article.

– Launch Windows Event Viewer as shown below

Launch Windows Event Viewer

Click on create Custom View, this will open the window below.
– Select By source and then Sysmon from the drop-down menu

Select By source and then Sysmon

I included all event level as shown below. Other parameters were currently not vital to me. So you can decide to include other parameters as shown below.

Click on OK

Now you can enter the Custom view name (in my case, I will name it Sysmon) as shown below.
– You can choose to enter a description and when you are done,
– Click on Ok.

Enter a Custom view name and description and click OK

The custom view will now appear on the left of the Event Viewer and can be used to analyze events (logs). Don’t forget that the view may be empty if there aren’t any recent activities on the PC or workstation.
– In my case, I simulated and initiated some events already.

the view may be empty if there aren't any recent activities on the PC or workstation

If you found this guide on How to create a custom view in Windows Event Viewer useful, kindly support us and also leave a comment below.

Rate this post

Thank you for reading this post. Kindly share it with others.

  • Share on X (Opens in new window) X
  • Share on Reddit (Opens in new window) Reddit
  • Share on LinkedIn (Opens in new window) LinkedIn
  • Share on Facebook (Opens in new window) Facebook
  • Share on Pinterest (Opens in new window) Pinterest
  • Share on Tumblr (Opens in new window) Tumblr
  • Share on Telegram (Opens in new window) Telegram
  • Share on WhatsApp (Opens in new window) WhatsApp
  • Share on Mastodon (Opens in new window) Mastodon
  • Share on Bluesky (Opens in new window) Bluesky
  • Share on Threads (Opens in new window) Threads
  • Share on Nextdoor (Opens in new window) Nextdoor
Windows Server Tags:Event Viewer, eventlog, Microsoft Windows, Windows Server 2016

Post navigation

Previous Post: Sysmon from SysInternal: What is System Monitor and how to install and use it
Next Post: How to reset your built-in Local Administrator password in Windows 10

Related Posts

  • image 63
    What to do when your Remote Desktop Licensing Manager Server Crashes Windows
  • hero activedirectory 1
    Active Directory Contact and a User Account Object Differences Security | Vulnerability Scans and Assessment
  • Database Connection Stuck on Working on it
    How to fix TeamPass stuck on working on it Network | Monitoring
  • Screenshot 2021 03 16 at 21.14.05
    Unable to locate the account: Fix call to DsGetDcNameWithAccount failed with return value 0x0000054B Windows Server
  • c
    Action cannot be complete because the computer is open in Wimserv Windows Server
  • Computer policy could not be updated
    How to fix Computer Policy could not be updated successfully Windows

More Related Articles

image 63 What to do when your Remote Desktop Licensing Manager Server Crashes Windows
hero activedirectory 1 Active Directory Contact and a User Account Object Differences Security | Vulnerability Scans and Assessment
Database Connection Stuck on Working on it How to fix TeamPass stuck on working on it Network | Monitoring
Screenshot 2021 03 16 at 21.14.05 Unable to locate the account: Fix call to DsGetDcNameWithAccount failed with return value 0x0000054B Windows Server
c Action cannot be complete because the computer is open in Wimserv Windows Server
Computer policy could not be updated How to fix Computer Policy could not be updated successfully Windows

Leave a Reply Cancel reply

You must be logged in to post a comment.

Microsoft MVP

VEEAMLEGEND

vexpert-badge-stars-5

Virtual Background

GoogleNews

Categories

veeaam100

Veeam Vanguard

  • Smartscreen defender blocking application
    Unable to run downloaded Programs due to Defender SmartScreen Windows
  • Featured image 2
    Enable Microsoft Defender SmartScreen: How to prevent Exe files from getting deleted randomly in Windows 10 and 11 Security | Vulnerability Scans and Assessment
  • change keyboard layout windows 10 thumb800
    How to use the On-Screen Keyboard Windows
  • Hub Transport 1
    Hub Transport Server: Resolving ‘Failed to Reach Running Status’ Network | Monitoring
  • image 1
    Install and License Devolutions Remote Desktop Manager on Mac Mac
  • updates
    Out-of-Band Security Update for PrintNightmare: Patch released for Windows Print Spooler Remote Code Execution Vulnerability Security | Vulnerability Scans and Assessment
  • windows 10 technical preview windows 10 logo microsoft 97543 1920x1080
    Windows Editions: Various Operating Systems available for Windows Windows
  • centos feature
    How to change the system time zone under RedHat and CentOS Linux

Subscribe to Blog via Email

Enter your email address to subscribe to this blog and receive notifications of new posts by email.

Join 1,808 other subscribers
  • RSS - Posts
  • RSS - Comments
  • About
  • Authors
  • Write for us
  • Advertise with us
  • General Terms and Conditions
  • Privacy policy
  • Feedly
  • Telegram
  • Youtube
  • Facebook
  • Instagram
  • LinkedIn
  • Tumblr
  • Pinterest
  • Twitter
  • mastodon

Tags

AWS Azure Bitlocker Microsoft Windows PowerShell WDS Windows 10 Windows 11 Windows Deployment Services Windows Server 2016

Copyright © 2025 TechDirectArchive

 

Loading Comments...
 

You must be logged in to post a comment.