Windows Event Log Viewer: Akaash Nidhiss 2K19/IT/008 Anasuya Mithra 2K19/IT/018
Windows Event Log Viewer: Akaash Nidhiss 2K19/IT/008 Anasuya Mithra 2K19/IT/018
Windows Event
Log Viewer
Akaash Nidhiss 2K19/IT/008
Anasuya Mithra 2K19/IT/018
Index
Introduction
Windoes System Log Files
Application Log File
System Log File
Security Log File
win32evtlog
Code
Output
Conclusion
Introduction
The rapid speed by which technology has grown has
also increased the spate of cybercrimes. Windows
operating system is the most widely used OS, resulting
in its users being on the receiving end of these
cybercrimes. Such crimes brought about the need for
cyber forensics.
Windows operating system and utilised by administrators to diagnose system issues and anomalies, and
audit.
There are 3 types of windows event log files, classified by the type of information it contains - Application
File
TYPES OF WINDOWS EVENT LOG FILES
The Security log contains events such as valid and invalid logon attempts, as well as events
related to resource use, such as creating, opening, or deleting files or other objects.
system components.
startup.
System administrators and technicians require
system logs.
win32evtlog
win32evtlog is a python module that encapsulates the Windows
Windows Event Log API. Each event provider and the events it logs are
the win32evtlog, utilises the API to read and render the events.
Our Program uses this module in python to read and display Application, System and
because they record every event that occurs in the Operating System.
When an unauthenticated user gains access to a system, it takes
Event logs are kept in the system root directory as offline physical