Skip to main content

Why you should check your computer's event log regularly and how to do so.

Being a computer genius involves doing some amazing things on a computer system one of which is knowing everything that happens on your computer when you are not around. you must have seen someone or some SysAdmins do this. The secret behind this is checking your event log regularly because everything that happens on your computer get logged into the event log. If you are ever going to catch your hacker, this might be your only hope, but some hackers are smart because they clear the event log when they are done, the only thing you see in the event log is an event informing you that the event log has been cleared.

How to view your event log

Because Windows Operating System is widely used, am going to show you how to do this in Windows using Powershell command line tool.
To view your event logs and perform other event log related operation, open up Windows Powershell (Windows Powershell is available in 7 and above, I can't say about older Windows Operating Systems) and type the following commands:
Get-Eventlog * : This command will get you the list of log which are some how categorized according to their types. Then if want to view events based on a specific log category, you just type [get-eventlog Application] or [get-eventlog "Other Files"], you use the later when the log category name is made up of two or more words.
Clear-Eventlog: This command enables you to clear the event log, when you type this command, it will ask you to enter the log name, but if you already know the name of the log you want to clear, you can just save yourself the trouble and type every thing in one line like this: [Clear-Eventlog Application] or [Clear-Eventlog "Other files"] (provided the log name is made up of more that one word).

Trick: Sometime you might not have the time to just sit and stare at a log screen, you can print the log on a paper for better analysis by Pipe-Lining it to a printer command like this:
[Get-Eventlog Application|Out-Printer] and everything will be printed on a paper.

Note that you have to type the commands without the square brackets.
Thanks for reading.

Comments

Popular posts from this blog

HOW TO WRITE, COMPILE AND RUN C++ CODE ON LINUX KALI

Developing a C++ Program on Kali Linux Without Installing Additional Software This article is for hackers who want to develop a C++ program on Kali Linux without installing any additional software. Some might say you need to install a separate compiler or extra tools to write and run a simple C++ program on Kali Linux. However, I’ll show you how to do it right out of the box. Pre-installed C++ Compiler in Kali Linux Kali Linux comes with a pre-installed C++ compiler called g++ . We will use this to write and compile a basic "Hello, World!" program. Step 1: Check if g++ is Installed Open your terminal and run the following command: g++ -v If the compiler is installed, you should see version details. If not, you will get an error message. Step 2: Create a C++ File In your terminal, type: nano MyCpp.cpp This will create a C++ file and open it in the Nano editor. Step 3: Write the C++ Code Once Nano opens, enter the following C++ code: #include <...

HOW TO INSTALL BLOGENGINE.NET WITH VISUAL STUDIO.

Yes there are lots of article on the internet that already describes how to do this, but that wont stop me from sharing my own idea on how I got mine rocking with visual studio 2012. Now here is the story, I woke up one morning and discovered I was departing from being a beginner programmer to a programmer who is at least worthy to be called a programmer. So I felt I needed to share my programming experience and the only known way I could do that, was to start blogging, hmmm... Just like you, I didn't like blogger, I needed  to be my own boss. So, I started my own blog project, but wait....  Why was I doing that when there are open source blog projects being developed and maintained by developers who are more "programmatically" experienced than I?. BlogEngine was the one I chose and the installation was a breeze. All I did was go to the site, downloaded the first zip file which is tagged "web", extracted it to my visual studio project directory, opened vi...

How to Check Logs or Journal of a Specific Service on Linux

Monitoring logs is an essential part of system administration. On Linux, logs help diagnose issues and track service behavior. This guide covers various ways to check logs for a specific service. Using journalctl for Systemd Services Most modern Linux distributions use systemd , and logs are stored in the journal. To view logs for a specific service, use: journalctl -u service-name.service Example for Nginx: journalctl -u nginx.service Viewing Real-Time Logs To follow logs in real time, use: journalctl -u service-name.service -f This is similar to tail -f for traditional log files. Checking Logs with a Time Filter To see logs from the last 1 hour: journalctl -u service-name.service --since "1 hour ago" For logs between two timestamps: journalctl -u service-name.service --since "2024-02-01 10:00" --until "2024-02-01 12:00" Using Traditional Log Files Some services log to files in /var/log/ . Check: ls /var/log/ For example, Nginx lo...