Diagnose system, application, security, and service issues on a Windows ECS instance by using Event Viewer logs.
Background
Windows system logs fall into four categories:
-
System log
-
Application log
-
Security log
-
Application and service logs
Open Event Viewer
Windows system logs are enabled by default. Connect to the instance and open Event Viewer to view them.
To open Event Viewer:
-
Connect to the Windows instance.
-
Choose . In the Run dialog box, enter
eventvwrand click OK to open Event Viewer. -
In Event Viewer, view the following four types of logs.
NoteUse event IDs from error logs to find solutions in the Microsoft Knowledge Base.
System log
Records events from Windows system components, such as driver or component load failures during startup. Event types are predetermined by Windows.
Application log
Records events from applications. For example, a database program can log file errors here.
Security log
Records valid and invalid logon attempts and resource-related events such as creating, opening, or deleting files. You can configure which events are recorded. For example, enable logon auditing to log system logon attempts.
Application and service logs
Stores events from a single application or component, rather than system-wide events.
Modify log path and back up logs
To change the log storage path or back up logs:
-
In the left navigation pane of Event Viewer, click Windows Logs.
-
Right-click a log name and select Type.
-
In the Log Properties dialog box, modify the following settings as needed.
-
Log path
-
Maximum log size
-
Action when the maximum log size is reached
NoteBy default, logs are saved to the system disk with a maximum size of 20 MB. When exceeded, the oldest events are deleted to make space. Adjust these settings to control log retention.
-