All Products
Search
Document Center

Elastic Compute Service:Use Windows instance logs

Last Updated:Aug 24, 2026

Diagnose system, application, security, and service issues on a Windows ECS instance by using Event Viewer logs.

Background

Windows system logs fall into four categories:

  • System log

  • Application log

  • Security log

  • Application and service logs

Open Event Viewer

Note

Windows system logs are enabled by default. Connect to the instance and open Event Viewer to view them.

To open Event Viewer:

  1. Connect to the Windows instance.

    See Log on to a Windows instance using Workbench.

  2. Choose Start > Run. In the Run dialog box, enter eventvwr and click OK to open Event Viewer.

  3. In Event Viewer, view the following four types of logs.

    Note

    Use event IDs from error logs to find solutions in the Microsoft Knowledge Base.

    System log

    Records events from Windows system components, such as driver or component load failures during startup. Event types are predetermined by Windows.

    Application log

    Records events from applications. For example, a database program can log file errors here.

    Security log

    Records valid and invalid logon attempts and resource-related events such as creating, opening, or deleting files. You can configure which events are recorded. For example, enable logon auditing to log system logon attempts.

    Application and service logs

    Stores events from a single application or component, rather than system-wide events.

Modify log path and back up logs

To change the log storage path or back up logs:

  1. In the left navigation pane of Event Viewer, click Windows Logs.

  2. Right-click a log name and select Type.

  3. In the Log Properties dialog box, modify the following settings as needed.

    • Log path

    • Maximum log size

    • Action when the maximum log size is reached

      Note

      By default, logs are saved to the system disk with a maximum size of 20 MB. When exceeded, the oldest events are deleted to make space. Adjust these settings to control log retention.