Updated to version: 220.127.116.11!
Lets say you have many exported EventLog (evt/evtx) files, and need to search for specific event entries on all of them. how do you do it?
Yes. Of course you can use Microsoft Log Parser 2.2 but then you have to write the cumbersome query yourself. bummer.
EvtLogParser uses the LogParser.dll from Microsoft Log Parser 2.2, and provides a simple UI for the query.
All you need to do, is drag-and-drop or right-click and select to add your files to the list, select the query filter using the query filter panel, and click Query.
Then, you’ll be able to see the query results in the grid view below.
Right-click to view a specific event, save it as a text file or export all the data to an XML file.
Note that Windows Vista, 7 and Server 2008 uses the new evtx format for event log exports.
Since Log Parser uses system APIs to read event log exports, and the old .evt event log format is not “native” any more on these OS’s you’ll probably get an error message saying “The event log file is corrupted”.
So if you want to read evt files on Windows Vista, 7 or Server 2008, you should convert them old-school EventLog files into the shiny new format. You can accomplish this using any of the two methods described below:
1. Through the user interface
just double-click the evt file, wait for it to open, then right-click, select Save Event As, enter the location and filename, click Save and OK.
2. Using the Windows Events Command Line Utility (WevtUTIL)
It’s built in the OS and it’ll convert those old EventLog files from the command line:
wevtutil epl application.evt application.evtx /lf:true
Also, you can copy the text below into Notepad, save it with the .reg extension, and merge it into your registry.
After restarting your system, you’ll be able to right-click an .evt file and select the “Convert to evtx” option from the context menu.
Windows Registry Editor Version 5.00
@=”Convert to evt&x”
@=”\”wevtutil.exe\” epl \”%1\” \”%1x\” /lf:true”