How to actually search in Event Viewer
Press Win+R, type eventvwr, and don't browse the tree — use Filter Current Log on the System log. The event IDs box takes comma-separated codes, a minus sign excludes (41,-6008 means "everything except"), and the Event sources dropdown narrows by origin such as Kernel-Power or WHEA-Logger. A saved filter sticks around in the left pane as a custom view, so you set the search up once. One honest warning: event IDs repeat across sources, so filtering by source plus ID is the difference between signal and noise.
The seven searches that pay off
Kernel-Power 41 is the first stop: it means Windows lost power or locked up without warning — a hard freeze, a forced power-off, a failing PSU — and its count is your machine's real instability score. Event 6008 marks unexpected shutdowns logged at next boot, and BugCheck 1001 captures the BSOD's stop code plus the minidump path — the actual evidence for "why it died while I was away". WHEA-Logger 17, 18 and 19 are hardware-level errors reported by the CPU or platform: a rare one is noise, a repeating pattern on the same core points at CPU, RAM or motherboard. Application Error 1000 and Windows Error Reporting 1001 in the Application log show which desktop apps crash and how often — the silent reason a "flaky" app gets blamed on Windows.
The last two are storage lifelines. Kernel-PnP 219 flags drivers that failed to load for a device — the reason a USB stick or disk "sometimes" doesn't appear. Disk 7 and 153 (storahci/stornvme sources) report bad blocks and command timeouts: a single one is forgettable, but a cluster right after a freeze means you copy the data off before diagnosing further.
- Kernel-Power, ID 41 — dirty power-offs and hard freezes; count them as your instability score
- BugCheck, ID 1001 — BSOD stop codes with the minidump path
- WHEA-Logger, IDs 17/18/19 — hardware errors from CPU, cache or platform; repeats on one core are the tell
- Application Error, ID 1000 — which apps actually crash, and how often
- Kernel-PnP, ID 219 — device drivers that failed to load at boot
- Disk, IDs 7 and 153 — bad blocks and command timeouts; a cluster after the freeze means backup first
Reading what you find
Context beats single events. One 41 after six months of uptime and a known power cut is nothing; five in a week with no power cuts is a pattern worth chasing, especially if WHEA errors share the same timestamps. Cross-check the Application log at the exact minute of a System-log crash — the app that died right before the freeze is usually the suspect, not the victim. And keep Reliability Monitor (perfmon /rel) open next to it: its timeline maps crashes onto installs and updates, which resolves half the "Windows got slow" mysteries by itself.
Questions and Answers
How do I find out why my computer crashed?
Open Event Viewer, filter the System log for Kernel-Power 41 and BugCheck 1001 — they show dirty shutdowns and BSOD stop codes. Match the timestamps against WHEA-Logger errors and Reliability Monitor to see the pattern.
What does Kernel-Power event ID 41 mean?
Windows shut down without warning — a freeze you power-cycled, a real power loss, or failing hardware. One isolated 41 is noise; a repeating count is a problem to investigate.
Know what is included before you buy.
The one-time 30-minute trial covers core tools. PRO-labelled features stay locked until a paid license is activated.
Read next
Write to us: [email protected]