What Event Viewer is and which logs matter
Event Viewer has shipped with every Windows since the NT era, and it collects the events that programs, services, drivers and the system itself report. The left pane lists the Windows Logs, and four of them do most of the diagnostic work: Application (errors from user programs), System (drivers, services and the OS core), Security (logons and audit events, readable only from an administrator account) and Setup (update history). Each record carries a level — Critical, Error, Warning or Information — plus the time, the source that reported it and the Event ID, which is the key you search for.
Two things keep the logs usable. First, they are circular: each log has a size cap, and when it fills up, Windows overwrites the oldest entries, so you never need to clean the Event Viewer to free space. Second, Information events vastly outnumber the errors — a busy system writes thousands of them a day — so you can safely ignore everything that is not Critical or Error.
- Event ID 41, source Kernel-Power (System) — the PC lost power or was reset with the power button; the classic trace of a freeze
- Event ID 1001, source BugCheck (System) — a blue screen happened; the Details tab shows the stop code, e.g. 0x0000007E
- Event ID 6008, source EventLog (System) — the previous shutdown was unexpected
- Event ID 7031 and 7034, source Service Control Manager (System) — a service crashed; the same ID repeating every few minutes points to a broken app
- Event ID 4101, source Display (System) — the graphics driver was reset mid-render; users see it as a black-screen blink in games
- Event ID 4625 (Security) — a failed logon attempt; a long series of them is worth investigating
How to open Event Viewer and find your error
Open the tool first: right-click Start → Event Viewer, or press Win+R, type eventvwr.msc and hit Enter. If you plan to look at the Security log, do it from an administrator account, otherwise that branch shows an error instead of events. Expand Windows Logs, click System, and sort by Date and time descending — then locate the moment your crash or freeze happened; the entries just before it are the suspects, and the errors that appear after a reboot are usually consequences rather than causes.
To cut the noise, click Filter Current Log on the right, tick Critical and Error, and press OK — the log shrinks to the events that actually matter. Click an event, and the General tab shows the friendly text; switch to Details → Friendly View or XML when you need the raw fields for a web search. The winning search recipe is simple: the Event ID plus the source name plus your Windows version — for example “1001 BugCheck Windows 11”.
Custom views, saved logs and what not to do
When a problem keeps coming back, build a custom view: click Create Custom View, set the same Critical/Error filter plus a time range, and save it — it appears under Custom Views and stays one click away. To hand evidence to a forum or a specialist, right-click the log → Save All Events As and keep the .evtx file; it opens on any Windows machine exactly as it left yours. The Clear Log button is safe to press, because the log refills on its own — but press it only after you have exported what you need.
Keep expectations honest: Event Viewer tells you what broke, not always why, so a blue-screen investigation usually continues with minidump analysis and checks like sfc /scannow or chkdsk. Two shortcuts help along the way: Reliability Monitor (run perfmon /rel) draws the same crashes as a simple timeline of red crosses, and the loud DCOM warnings 10016 and 10010 are famous noise you can ignore.
Questions and Answers
Where do I find the cause of a blue screen in Event Viewer?
In Windows Logs → System, look for Event ID 1001 from the BugCheck source at the time of the crash — the stop code it lists is the starting point for the search.
Is it safe to clear Event Viewer logs?
Yes — the logs refill immediately and Windows overwrites old entries anyway, so nothing breaks. Export the events you need first, because clearing erases them for good.
How do I check Event Viewer for failed logons?
Open the Security log from an administrator account and filter for Event ID 4625, failed logon attempts. A burst of them in the middle of the night deserves a closer look at who or what is trying to get in.
Know what is included before you buy.
The one-time 30-minute trial covers core tools. PRO-labelled features stay locked until a paid license is activated.
Read next
Write to us: [email protected]