windows event viewer basics for helpdesk triage
Teaches helpdesk agents to triage with Windows Event Viewer. Covers which logs matter, filtering, and the common event IDs. Use for training and quick diagnosis. Not a deep forensics guide.
TL;DR
For most tickets you need three logs: Application (app crashes), System (drivers, services, boot), and Security (logons, lockouts). Filter by the last hour and by Error/Critical, then read the newest entries first. Learn five event IDs and you can triage half of all Windows tickets.
The error
(Training/diagnostic; no error.)Steps
- Open Event Viewer (eventvwr.msc) on the affected machine (remote via Computer Management if needed). Expected: console opens.
- Check Windows Logs > System, filtered to the last hour, Errors and Criticals. Expected: you see driver, service, or disk errors if the issue is system-level.
- Check Windows Logs > Application for the crashing app's errors. Expected: the app's faulting module named. This is the escalation detail developers need.
- Check Windows Logs > Security for logon events: 4625 is failed logon, 4740 is account locked. Expected: pattern visible. Filter by the username.
- Note the event ID, source, and timestamp for the ticket. Expected: documented. "Event 1000, faulting module foo.dll, 14:32" is infinitely more useful than "it crashed".
When to use
- Any Windows issue without an obvious cause
- Before escalating to tier 2/3
When not to use
- macOS issues (use Console)
- Issues with clear error messages already
Compatibility
- Windows 10/11; Event Viewer built in
Variants
Remote collection
Use wevtutil to export logs, or have the user save a filtered view as .evtx.
Recurring mystery crashes
Set up a custom view filtered to the app and check it after each crash.
Why it happens
Windows logs nearly everything; the skill is knowing where to look and how to filter. Five minutes in Event Viewer beats an hour of guessing.
Edge cases
- Logs roll over; check soon after the incident or the evidence is gone.
- The five IDs worth memorizing: 4625 (failed logon), 4740 (lockout), 1000 (app crash), 41 (unexpected shutdown), 55 (NTFS corruption).
Provenance
Resolved from the public thread: https://vectle.com/posts/pst_fPcyNWDJ3NyunvGtoSkUCg
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.