The summary of ‘How to check shutdown and reboot logs using event viewer in Windows servers?’

This summary of the video was created by an AI. It might contain some inaccuracies.

00:00:0000:08:37

The video tutorial offers a comprehensive guide on using Event Viewer to check shutdown and reboot logs on Windows servers, emphasizing its importance for troubleshooting and monitoring user activities. Key Event IDs covered include:
– Event ID 41 for reboots without complete shutdowns,
– Event ID 6005 for event log service starts,
– Event ID 1074 for application or user-initiated shutdowns or restarts,
– Event ID 6008 for unexpected shutdowns,
– Event ID 6013 for system uptime.

The tutorial details navigating the Event Viewer through "eventvwr" in the Run dialog, filtering events by Event ID, and refining searches by time period. The process is thoroughly explained, providing users a resourceful method to track system activities efficiently. The video concludes by encouraging subscriptions for more technical content and accessing additional resources via the creator's Telegram channel.

00:00:00

In this segment of the video, the tutorial focuses on guiding users on how to check shutdown and reboot logs using Event Viewer in Windows servers. The Event Viewer is a tool that tracks all activities occurring on the computer and is managed by the event log service. It is particularly helpful for troubleshooting errors and monitoring user activities. The video highlights specific event IDs in the system event viewer logs:
– Event ID 41 indicates a reboot without a complete shutdown.
– Event ID 6005 shows the event log service was started.
– Event ID 1074 is recorded when an application forces a shutdown or restart, and also logs when a user restarts or shuts down the computer from the start menu or using Ctrl+Alt+Delete.
– Event ID 6006 is also mentioned but further details are not provided in this segment.

The tutorial also offers additional resources, such as a downloadable PDF from their Telegram channel.

00:03:00

In this part of the video, the focus is on viewing shutdown and reboot logs from the Event Viewer on a Windows computer. It explains specific Event IDs such as 6008 for unexpected shutdowns and 6013 for computer uptime. The steps include opening the Run dialog, typing “eventvwr”, and navigating through the Event Viewer panel to Windows Logs, then System. The video shows how to sort events by Event ID and create a filter for specific Event IDs to search for shutdown, reboot, and startup logs. Users can refine the search further by specifying a time period.

00:06:00

In this part of the video, the presenter discusses how to filter and review shutdown, reboot, and startup logs using Event Viewer in Windows servers. They identify key event IDs:
– Event ID 41, indicating the system rebooted unexpectedly without a clean shutdown.
– Event ID 6013, which provides information on system uptime.
– Event ID 1074, recording when an application or user initiates a system restart or shutdown.

The presenter explains how to find more details about each event in the middle pane of the Event Viewer. They conclude by summarizing the process of checking shutdown and reboot logs, encouraging viewers to subscribe to their channel for more technical videos and access additional resources via their Telegram channel.

Scroll to Top