What the Event Log actually is
The Windows Event Log service (eventlog) collects events from dozens of providers — drivers, services, applications, the security subsystem — and writes them into binary .evtx files in C:\Windows\System32\winevt\Logs\. The readable front end is Event Viewer (eventvwr.msc), which shows the same records with severity, source and event ID. The classic advice "check the logs" always means this folder: it is the system's black box recorder, and it has worked the same way on every Windows since Vista.
Five channels do most of the work. Application records program crashes and hangs; System carries driver and service complaints; Security stores logon audits (4624 success, 4625 failure) and is readable by administrators only; Setup keeps the machine's own history of Windows updates and upgrades. Beyond them sit hundreds of hidden analytic and debug channels that Microsoft engineers enable on demand — they exist, but they are off by default and write almost nothing.
- Application.evtx — program crashes, hangs, installer events
- System.evtx — drivers, services, hardware warnings
- Security.evtx — logon attempts 4624/4625, administrators only
- Setup.evtx — the machine's own Windows upgrade history
- C:\Windows\System32\winevt\Logs\ — where every channel lives as a .evtx file
Size limits: why the logs never eat your disk
Each channel has its own maximum, set in the log's Properties dialog ("Maximum log size (KB)") and stored in the registry under HKLM\SYSTEM\CurrentControlSet\Services\EventLog. On desktop Windows the classic defaults sit around 20 MB per channel, adjustable in 64 KB increments up to 4 GB. That cap is what keeps a hard-working machine's logs at a few dozen megabytes after years of uptime: when a log reaches its limit, the default policy is "Overwrite events as needed (oldest first)" — the file never grows past the ceiling, old events simply vanish.
The one escape route is archiving. If a log is switched to "Archive the log when full, do not overwrite events", Windows renames the filled file to Archive-Application-YYYY-MM-DD-HHMMSS.evtx and starts a fresh one — and the archives pile up in the same folder with no built-in cleanup. That is the single scenario where winevt\Logs genuinely grows: not the live logs, but years of archived copies nobody asked for.
Trimming it without breaking anything
Do not delete .evtx files directly: the Windows Event Log service holds them open, and deleting a live channel's file from under it corrupts the log and earns you errors in — of all places — the Event Log. The supported way is Clear Log in Event Viewer, which can save the current contents before wiping. Lowering the maximum in Properties is just as safe, and it applies on the log's next wrap-around.
Clearing also has a diagnostic price worth naming honestly: these logs are the only record of why the machine crashed last Tuesday. Clear them after you have pulled out what you need, not before. As a space-recovery target the folder is a rounding error on a modern disk — a browser cache on the same machine is a hundred times bigger — so event-log maintenance is a surgical tool, not a cleanup category.
Questions and Answers
Where are Windows event logs stored?
In C:\Windows\System32\winevt\Logs — one .evtx file per channel. Event Viewer (eventvwr.msc) reads exactly these files, so anything you clear there is gone from disk as well.
What is the maximum size of the Windows event log?
Each channel has its own limit — about 20 MB by default on desktop Windows, adjustable from 64 KB up to 4 GB. When the limit is hit, the oldest events are overwritten unless archiving is enabled.
Know what is included before you buy.
The one-time 30-minute trial covers core tools. PRO-labelled features stay locked until a paid license is activated.
Read next
Write to us: [email protected]