The Tool Desk
Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
FullEventLogView is a free, portable Windows utility for finding and filtering event records by Event ID, then inspecting or exporting them. Download it from NirSoft’s official page. You do not need a third-party tool for a simple search, though: Windows Event Viewer and PowerShell can filter events too.
One important point: an Event ID is not a diagnosis, and a number by itself is not unique. Always check the log or channel, provider, timestamp, level, message and event data before deciding what an event means.
What an Event ID tells you
An Event ID is one field in a Windows event record. The same numeric ID can mean different things under different providers or channels, so “Event ID 1000” alone is not enough to identify an issue. Record the surrounding context:
Do these 3 things before closing this tab:
1Fix the driver behind crashes, sound loss and screen glitches2Repair Windows errors before they cause bigger problems3Scan for outdated or missing drivers - takes under a minute- Log or channel: for example, System, Application, Security or a provider-specific Operational channel.
- Provider/source: the component that wrote the event, such as Service Control Manager or Microsoft-Windows-Kernel-Power.
- Level and time: Information, Warning, Error or Critical, and when the record was created.
- Record ID and computer: useful when comparing or sharing evidence.
- Message and event data: the description and structured values, including the XML details when available.
“Look up an Event ID” can mean either finding records with that number on a PC, or researching what a particular provider’s event means. A viewer helps with the first and exposes details useful for the second; it is not a universal encyclopedia of event meanings.
#1 Best Overall
- 1.1 GHz (boost up to 2.4GHz) Intel Celeron N5030 Quad-Core
| What you need | Good place to start |
|---|---|
| Find occurrences of an ID on this PC | Event Viewer, PowerShell, or FullEventLogView |
| Inspect the message and XML | Event Viewer or FullEventLogView |
| Search several IDs or export records | FullEventLogView or PowerShell |
| Understand an event in a specific product | The provider’s documentation or the relevant software/hardware vendor |
| Diagnose a symptom | Correlate the event with its time, data, surrounding events and the symptom |
Use FullEventLogView to filter by Event ID
NirSoft describes FullEventLogView as freeware that runs without installation or additional DLL files, and documents support for Windows Vista through Windows 11. It can show events from local or remote computers and open saved .evtx or .etl files. Remote access still depends on Windows permissions and network configuration. Check the official utility page for the current download and details.
- Download the appropriate 32-bit or 64-bit archive from NirSoft’s official page and extract it.
- Run
FullEventLogView.exe. It is portable, but some logs may still require elevated access. - Press F9 to open Advanced Options.
- Enable the option to show only specified Event IDs and enter IDs separated by commas, such as
41, 6008, 1074. - Optionally narrow the results by time range, channel, provider, level or event description, then apply the filter.
- Select a result in the event list and inspect its description, event data and raw XML in the detail area. Sort by time, ID, provider or level as needed.
Check the time window: FullEventLogView displays only the last seven days by default. If the event is older, change the time filter in Advanced Options; otherwise a valid search may appear to return nothing.
NirSoft’s Event ID search guide also documents command-line filtering and CSV export. For example:
Recommended Free Tools
FullEventLogView.exe /EventIDFilter 2 /EventIDFilterStr "41,42,1,1074,6005,6006" /scomma "C:Tempevent-id-list.csv"
/EventIDFilter 2 activates the Event ID filter, /EventIDFilterStr supplies the comma-separated IDs, and /scomma writes a CSV file. Make sure the destination folder exists and is writable; C:Temp is one possible location. The utility also offers other export formats, including HTML, XML and JSON.
Rank #2
- 256 GB SSD of storage.
- Multitasking is easy with 16GB of RAM
- Equipped with a blazing fast Core i5 2.00 GHz processor.
Filter in Event Viewer without downloading anything
- Press Win + R, type
eventvwr.mscand press Enter. - Open the likely log, often Windows Logs > System for system or shutdown issues, or Windows Logs > Application for app errors.
- In the Actions pane, choose Filter Current Log….
- Enter the Event ID or IDs, apply the filter, and open a matching event.
- Review both the General tab and Details > XML View.
Labels and dialog behavior can differ slightly by Windows version. If a multi-ID filter does not behave as expected, try PowerShell. Microsoft documents filtering through Event Viewer and the creation of XML queries via Filter Current Log or Create Custom View.
Search and export with PowerShell
Get-WinEvent is useful for repeatable searches and scripts. Filtering by log and ID at the source is preferable to retrieving a large log and filtering afterward. These examples run in PowerShell on Windows:
One ID in the System log
Get-WinEvent -FilterHashtable @{
LogName = 'System'
Id = 41
} -MaxEvents 50 |
Select-Object TimeCreated, Id, ProviderName, LevelDisplayName, Message
Several IDs
Get-WinEvent -FilterHashtable @{
LogName = 'System'
Id = 41, 6008, 1074
} -MaxEvents 100 |
Select-Object TimeCreated, Id, ProviderName, LevelDisplayName, Message
Limit the search to the past seven days
$start = (Get-Date).AddDays(-7)
Get-WinEvent -FilterHashtable @{
LogName = 'System'
Id = 41, 6008
StartTime = $start
} |
Select-Object TimeCreated, Id, ProviderName, LevelDisplayName, Message
Export matching events to a CSV file
Get-WinEvent -FilterHashtable @{
LogName = 'System'
Id = 41, 6008
} |
Select-Object TimeCreated, Id, ProviderName, LevelDisplayName, Message |
Export-Csv -Path "$env:USERPROFILEDesktopsystem-events.csv" -NoTypeInformation
To inspect event IDs and descriptions registered for a provider, use:
(Get-WinEvent -ListProvider 'Microsoft-Windows-GroupPolicy').Events |
Format-Table Id, Description
This lists provider metadata registered on the machine; it is not a historical list of every event that has occurred. Microsoft documents Get-WinEvent, its -FilterHashtable, XPath and XML filtering, and provider metadata in the Get-WinEvent reference. The cmdlet is Windows-specific. Some logs require appropriate permissions, and the Security log may require an elevated or authorized account. Get-WinEvent is the modern choice over the older Get-EventLog, which is retained for compatibility and covers classic logs. When querying many logs, Microsoft also documents a 256-log Event Log API limitation; query a particular log or process logs individually to avoid that issue.
Rank #3
- 14" diagonal, 1366x768 resolution, HD BrightView LED, Glossy NON-TOUCH Display
Optional: query with wevtutil
For Command Prompt, wevtutil can query logs using an XPath-style filter. This returns up to 20 recent System events with ID 41:
wevtutil qe System /q:"*[System[(EventID=41)]]" /f:text /c:20 /rd:true
To include multiple IDs:
wevtutil qe System /q:"*[System[(EventID=41 or EventID=6008 or EventID=1074)]]" /f:text /c:50 /rd:true
qe queries events, /q: supplies the query, /f:text formats the output as text, /c: limits the number of records and /rd:true requests newest-first ordering. See Microsoft’s wevtutil documentation for its other query and log-management options. PowerShell or FullEventLogView is usually easier for a one-off search.
How to interpret a result—and what to do if none appears
Save more than the number when you report an event or investigate a problem:
PC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchLog/channel:
Provider/source:
Event ID:
Level:
Time created:
Computer:
Record ID:
Message:
Event data/XML:
Then note what happened around that time, whether the event repeats, whether related events appear in other logs, and whether a recent Windows, driver, application or hardware change could be relevant. An event may be a cause, a consequence or routine background activity. A Warning or Error label does not by itself prove Windows is failing; patterns correlated with a real symptom are stronger evidence than an isolated record.
Rank #4
- EFFORTLESS EVERYDAY PERFORMANCE: Powered by Intel Celeron N4020 processor and Windows 11 Home system, delivering reliable, low-power efficiency for daily tasks like document editing, email, online classes, and web browsing
- 15.6-INCH FULL HD DISPLAY: Enjoy immersive visuals on the 15.6" FHD (1920x1080) anti-glare screen with micro-edge bezels. Delivers clear details and comfortable viewing for long study sessions, working on spreadsheets, and video playback
- RESPONSIVE MULTITASKING & STORAGE: Built with 4GB LPDDR4 RAM and 128GB eMMC storage for smooth daily essential use. Expand your storage by up to 1TB via the integrated TF card slot to easily store movies, photos, and working files
- ADVANCED CONNECTIVITY: Outfitted with 2x Full-Featured Type-C ports for data transfer, fast charging, and dual-monitor output, alongside 2x USB 3.2 Gen1 ports and a 3.5mm audio jack for complete peripheral compatibility
- LIGHTWEIGHT & SILENT OPERATION: Slim and portable for effortless travel or commuting. Features a 1MP HD webcam for remote meetings, 38Wh battery with 45W Type-C fast charging, and a fanless silent design for peaceful work environments.
If your search is empty, check the likely log or channel and provider, confirm the ID and time range, and consider whether the log was cleared or overwritten. Some application events live in provider-specific channels rather than the main System or Application logs. Events may also be absent if auditing or an Operational channel was not enabled, or if the event was never generated. For FullEventLogView, remember its seven-day default. For protected logs, use an account with the required access rather than weakening security controls.
If an event says “The description for Event ID … cannot be found,” inspect its XML and event data and identify the provider. The message resource may be unavailable because the generating software was removed, the log came from another computer, language/provider resources do not match, or the record is incomplete. Provider or vendor documentation may explain the data even when the friendly message cannot be rendered.
For a saved .evtx or .etl file, preserve the original and work on a copy. FullEventLogView supports opening those formats, including by dragging a file into the app, but descriptions can be incomplete if the reviewing machine lacks the originating provider’s message resources. Keep the source computer and Windows context in mind.
Free tools Windows power users keep installed
One-click scans. No signup required.
Remote viewing is also conditional: the tool’s support does not override firewall rules, Windows Event Log service settings, credentials, network connectivity or remote-log permissions. Configure access through your organization’s approved process rather than assuming the remote list will be readable.
Best Value
- 【Efficient Performance】 Powered by Intel Core i3 processor (2 cores, 4 threads, up to 3.4GHz) with 12GB RAM and 256GB SSD. Handles multitasking, office software, online classes, and HD video streaming smoothly. Integrated Intel UHD Graphics 620
- Backlit Keyboard & Complete Package】Comes with a cool backlit keyboard. Comes with awebcam, dual stereo speakers (8Ω/1.0W each), DC charger, and user manual – ready for late-night studying, online classes, video conferencing, and daily productivity
- 【Vibrant Display】 15.6-inch Full HD (1920x1080) anti-glare screen with 16:9 aspect ratio delivers crisp images and vivid colors – perfect for studying, watching lectures, or entertainment. Thin-bezel design maximizes viewing area
- 【Fast Connectivity & Expansion】 Equipped with WiFi 6 (802.11ax) and Bluetooth 5.2 for stable, high-speed wireless. Features 3 x USB 3.0, HDMI 2.1, Type-C (supports PD3.0 fast charging), and a TF card slot expandable up to 2TB – easily connect external monitors, mice, drives, or expand storage for all your files
- 【Long Battery Life & Portable】 Built-in 11.55V 5000mAh/57.75Wh high-capacity battery delivers approximately 7 hours of mixed-use battery life – enough for a full day of classes and assignments. Lightweight at just 1.63kg (3.6 lbs) and 19.5mm thin, plus a compact packing size – easily slips into a backpack for campus, library, or coffee shop
Choose the tool that fits
- No downloads or managed PC: Event Viewer is already installed and is the safest default when third-party utilities are not permitted.
- Quick graphical filtering and export: FullEventLogView offers a sortable, table-style view and convenient filters, including for saved logs.
- Automation or repeat investigations: PowerShell’s
Get-WinEventis scriptable and can filter by ID, log and time. - Command-line query: Use
wevtutilwhen you are comfortable with its query syntax. - Central monitoring, alerting or long-term retention: A log-management or SIEM platform may be appropriate, but is usually unnecessary for a single local lookup.
For Windows 10 or 11, choose FullEventLogView rather than NirSoft’s older MyEventViewer; NirSoft warns that MyEventViewer may have errors or crashes on those systems. See its MyEventViewer page for that compatibility note.
Download utilities only from their official source. Event logs can contain usernames, computer and domain names, IP addresses, file paths and security details. Before posting a log, screenshot or export publicly, redact sensitive fields; an online lookup or cloud analyzer is not a substitute for reviewing what data it receives.
For explanations, start with the provider and event payload, then consult Microsoft Learn or the relevant application, hardware or service vendor. Third-party Event ID reference sites can be useful leads, but an ID’s meaning may vary by provider and version; do not apply a generic fix based on the number alone.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

