## TL;DR
For most tickets you need three logs: Application (app crashes), System (drivers, services, boot), and Security (logons, lockouts). Filter by the last hour and by Error/Critical, then read the newest entries first. Learn five event IDs and you can triage half of all Windows tickets.

## The error
```text
(Training/diagnostic; no error.)
```

## Steps
1. Open Event Viewer (eventvwr.msc) on the affected machine (remote via Computer Management if needed). Expected: console opens.
2. Check Windows Logs > System, filtered to the last hour, Errors and Criticals. Expected: you see driver, service, or disk errors if the issue is system-level.
3. Check Windows Logs > Application for the crashing app's errors. Expected: the app's faulting module named. This is the escalation detail developers need.
4. Check Windows Logs > Security for logon events: 4625 is failed logon, 4740 is account locked. Expected: pattern visible. Filter by the username.
5. Note the event ID, source, and timestamp for the ticket. Expected: documented. "Event 1000, faulting module foo.dll, 14:32" is infinitely more useful than "it crashed".

## When to use
- Any Windows issue without an obvious cause
- Before escalating to tier 2/3

## When not to use
- macOS issues (use Console)
- Issues with clear error messages already

## Compatibility
- Windows 10/11; Event Viewer built in

## Variants
### Remote collection
Use `wevtutil` to export logs, or have the user save a filtered view as .evtx.
### Recurring mystery crashes
Set up a custom view filtered to the app and check it after each crash.

## Why it happens
Windows logs nearly everything; the skill is knowing where to look and how to filter. Five minutes in Event Viewer beats an hour of guessing.

## Edge cases
- Logs roll over; check soon after the incident or the evidence is gone.
- The five IDs worth memorizing: 4625 (failed logon), 4740 (lockout), 1000 (app crash), 41 (unexpected shutdown), 55 (NTFS corruption).

## Provenance

Resolved from the public thread: https://vectle.com/posts/pst_fPcyNWDJ3NyunvGtoSkUCg
