Skip to main content

Why you should check your computer's event log regularly and how to do so.

Being a computer genius involves doing some amazing things on a computer system one of which is knowing everything that happens on your computer when you are not around. you must have seen someone or some SysAdmins do this. The secret behind this is checking your event log regularly because everything that happens on your computer get logged into the event log. If you are ever going to catch your hacker, this might be your only hope, but some hackers are smart because they clear the event log when they are done, the only thing you see in the event log is an event informing you that the event log has been cleared.

How to view your event log

Because Windows Operating System is widely used, am going to show you how to do this in Windows using Powershell command line tool.
To view your event logs and perform other event log related operation, open up Windows Powershell (Windows Powershell is available in 7 and above, I can't say about older Windows Operating Systems) and type the following commands:
Get-Eventlog * : This command will get you the list of log which are some how categorized according to their types. Then if want to view events based on a specific log category, you just type [get-eventlog Application] or [get-eventlog "Other Files"], you use the later when the log category name is made up of two or more words.
Clear-Eventlog: This command enables you to clear the event log, when you type this command, it will ask you to enter the log name, but if you already know the name of the log you want to clear, you can just save yourself the trouble and type every thing in one line like this: [Clear-Eventlog Application] or [Clear-Eventlog "Other files"] (provided the log name is made up of more that one word).

Trick: Sometime you might not have the time to just sit and stare at a log screen, you can print the log on a paper for better analysis by Pipe-Lining it to a printer command like this:
[Get-Eventlog Application|Out-Printer] and everything will be printed on a paper.

Note that you have to type the commands without the square brackets.
Thanks for reading.

Comments

Popular posts from this blog

HOW TO WRITE, COMPILE AND RUN C++ CODE ON LINUX KALI

This article is for hackers who want to develop a c++ program on Kali Linux without having to install any additional software. While some would tell you that you need to install an additional software or a compiler in order to develop a simple program in c++ on Kali Linux, I am going to show you how to develop a c++ program on this distro right out of box. Your Linux Kali comes pre-installed with a c++ compiler called g++ so we are going to write a C++ hello word code and compile it with this compiler. Before we get started, first open up terminal and run to verify if this compiler is installed on you machine: g++ -v if the compiler is pre-installed, you should get the version information of the compiler, otherwise, you should get an error. Now let's jump right in. In your terminal window, type in: nano MyCpp.cpp to create a c++ file and lunch it in nano editor for editing. When nano opens, type in the following c++ code and press Ctrl+x then y and then R

LOAN MANAGEMENT SYSTEM (My Project Idea)

There are many companies that specializes on giving loan to people; they make their profits by collecting interest on any money they lend out, and before a loan can be given to any customer, the customer must provide a collateral and some details such as:  contact details and a reference/guarantor. When the loan is finally given to the customer, they charge interest based on the the amount given to the customer for a given period of time which could be daily, weekly, monthly or yearly.  For example, a company could be collecting interest based on a particular amount for a given period of time like: $200,000 loan would have an interest tag of $2,000  per month until the money is returned, and $100,000 would have an interest of $1,000 per month until the money is returned.  In  addition, the customers need to know when the time for them to pay their interest comes e.g.  at the end of the month or the timing model with which the calculation is being made. Usually, these companies sends ou

How to execute eject command on an ATM Machine using CoreXfs lib on .NET

 In this tutorial, I'm going to demonstrate how to run an eject command on an ATM using CoreXfs, a library I developed.  You can download the library from  here  and follow up with tutorial. First we need to add reference to the downloaded dll. Screen One Once the reference to the dll has been added, you can proceed to coding the application. What I did in the screen below is very simple, I opened the device on the atm using it's logical name so that I can pass in commands. Screen Two So, that's it. thanks for dropping by. You can watch the video below to see how I coded it. Note that this code can only run on an ATM machine. NCR, WINCOR, DIEBOLD, HYOSUNG