The .evt files located "C:\Windows\System32\config" can be opened using eventvwer.exe located in "C:\Windows\System32"
As the log is text i just wondered where they were stored and if there was a different way to access them but you have made a good point in that it wouldnt be a live log.
Looks like the log is stored in the registry
All the application event logs messages DLLs are defined under the following registry keys:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\ Application
This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
By continuing to use this site, you are consenting to our use of cookies.