PsLogList 2.62

PsLogList 2.62 Screenshot The Resource Kit comes with a program, elogdump, which allows you to dump the contents of an Event Log on the local or a remote computer.

Developer:   Mark Russinovich
      software by Mark Russinovich →
Price:  0.00
License:   Freeware
File size:   0K
Language:   
OS:   Windows Vista (?)
Rating:   0 /5 (0 votes)

The Resource Kit comes with a program, elogdump, which allows you to dump the contents of an Event Log on the local or a remote computer. PsLogList is a clone of elogdump except that PsLogList lets you login to remote systems in situations your current set of security credentials would not permit access to the Event Log, and PsLogList retrieves message strings from the computer on which the event log you view resides.

The default behavior of PsLogList is to show the contents of the System Event Log on the local computer, with visually-friendly formatting of Event Log records. Command line options let you view logs on different computers, use a different account to view a log, or to have the output formatted in a string-search friendly way.

usage: psloglist [-?] [\\computer[,computer[,...] | @file [-u username [-p password]]] [-s [-t delimiter]] [-m #|-n #|-h #|-d #|-w][-c][-x][-r][-a mm/dd/yy][-b mm/dd/yy][-f filter] [-i ID[,ID[,...] | -e ID[,ID[,...]]] [-o event source[,event source][,..]]] [-q event source[,event source][,..]]] [-l event log file]

@file
Execute the command on each of the computers listed in the file.
-a
Dump records timestamped after specified date.
-b
Dump records timestamped before specified date.
-c
Clear the event log after displaying.
-d
Only display records from previous n days.
-e
Exclude events with the specified ID or IDs (up to 10).
-f
Filter event types with filter string (e.g. "-f w" to filter warnings).
-h
Only display records from previous n hours.
-i
Show only events with the specified ID or IDs (up to 10).
-l
Dump records from the specified event log file.
-m
Only display records from previous n minutes.
-n
Only display the number of most recent entries specified.
-o
Show only records from the specified event source (e.g. \"-o cdrom\").
-p
Specifies optional password for user name. If you omit this you will be prompted to enter a hidden password.
-q
Omit records from the specified event source or sources (e.g. \"-q cdrom\").
-r
Dump log from least recent to most recent.
-s
This switch has PsLogList print Event Log records one-per-line, with comma delimited fields. This format is convenient for text searches, e.g. psloglist | findstr /i text, and for importing the output into a spreadsheet.
-t
The default delimeter is a comma, but can be overriden with the specified character.
-u
Specifies optional user name for login to remote computer.
-w
Wait for new events, dumping them as they generate (local system only).
-x
Dump extended data.
eventlog
By default PsLogList shows the contents of the System Event Log. Specify a different event log by typing in the first few letters of the log name, application, system, or security.

Like Win NT/2K's built-in Event Viewer and the Resource Kit's elogdump, PsLogList uses the Event Log API, which is documented in Windows Platform SDK. PsLogList loads message source modules on the system where the event log being viewed resides so that it correctly displays event log messages.

tags event log  event source  the specified  records from  the event  from the  only display  with the  from previous  display records  the system  specified event  dump records  

PsLogList 2.62 screenshot


Download PsLogList 2.62

 Download PsLogList 2.62


Authors software

Bluescreen 3.2 Bluescreen 3.2
Mark Russinovich

One of the most feared colors in the NT world is blue.

Du v 1.00 r 7 Du v 1.00 r 7
Mark Russinovich

Du (disk usage) will report the disk space usage for the directory you specify.

Sigcheck 1.0 Sigcheck 1.0
Mark Russinovich

Verify that images are digitally signed and dump version information with this simple command-line utility called Sigcheck.

AccessChk 1.03 AccessChk 1.03
Mark Russinovich

As a part of ensuring that they've created a secure environment Windows administrators often need to know what kind of accesses specific users or groups have to resources including files, directories, Registry keys, and Windows services.

CacheSet 1.0 CacheSet 1.0
Mark Russinovich

CacheSet is an applet which helps you manipulate the working-set parameters of the system file cache.

Similar software

PsLogList 2.62 PsLogList 2.62
Mark Russinovich

The Resource Kit comes with a program, elogdump, which allows you to dump the contents of an Event Log on the local or a remote computer.

Event Catcher 1.0.0.24 Event Catcher 1.0.0.24
Eric Fetty

Event Catcher is a task-tray utility that will monitor local or remote windows boxes for new entries in their event log.

Filesofdir 1.0 Filesofdir 1.0
Bindesh Kumar Singh

Filesofdir will dump specific directory contents.

Count Characters 3.0 Count Characters 3.0
Funduc Software

Count Characters helps you dump the contents of various combo, edit, list boxes, static, and button fields to the clipboard.

DPus 1.0 DPus 1.0
Lterno

DPus is a free gdi and memory leak detection program.

Resource Explorer 1.2 Resource Explorer 1.2
Seb Flipper

Resource Explorer displays the contents of any exe, dll, sys, cpl, ocx, scr, amc and ax files.

Event Manager 2.1.0.247 Event Manager 2.1.0.247
RoteBetaSoftware

Event Manager is a useful program that helps you to remember your appointments.

zero Dump 0.1 zero Dump 0.1
Ashkbiz Danehkar

zero Dump is able to hook window controls and modify them.

Resource .NET 2.7.2386.41158 Resource .NET 2.7.2386.41158
fish

Resource .

Event 'Minder 1.1 Event 'Minder 1.1
Chris Stromberger

Event 'Minder is a small reminder program that will help you remember birthdays, anniversaries, etc.

Other software in this category

Nullsoft Beep 0.3 Nullsoft Beep 0.3
Nullsoft, Inc

Nullsoft Beep is an application that makes your computer sound like computers sound in the movies.

AR Soft RAM Disk 1.20 AR Soft RAM Disk 1.20
AR Soft

The AR RAM Disk is a freeware driver for Windows NT or Windows 2000.

DBX Plugin for Windows Commander Beta DBX Plugin for Windows Commander Beta
Labs99

DBX Plugin is an additional component for Windows Commander allowing you to read contents of Microsoft Outlook Express files.

4th split 1.1.9.0 4th split 1.1.9.0
Sergey S. Tkachenko

4th split is used for splitting impossibly large files on blocks.

HDCopy 2.104 HDCopy 2.104
Kurt Zimmermann

HDCopy is recommended to make a boot disk.