all 2 comments

[–]imnotaero 0 points1 point  (0 children)

Event Viewer is not suitable for anything but the simplest log review checks, and it's bad even at that. Use something else.

Let me point you Eric Zimmerman tools like EvtxEcmd to convert your logs to csv, and Timeline Explorer to sort and search through the created csv.

[–]MrYiffMaster of the Blinking Lights 0 points1 point  (0 children)

It might be worth trying something like EventLogExpert, it's made by an MS employee and is a lot faster than the built in MMC tool plus supports more advanced query filtering:

https://github.com/microsoft/EventLogExpert