Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations John Tel on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

How to repair a corrupt event log file?

Status
Not open for further replies.

Pet35

Technical User
Aug 23, 2004
5
HU
Windows 2000 Server SP4.
After a system crash the event log files got corrupt.
The event log service was locked due to the corrupt files.
Thanks to sioxley's advise, I managed to restart the event
log service after removing the old *.evt files.

Now I'd like to repair the damaged files in order to check
what happened before the system crash.

I have tried to open the old files from the event log
viewer, but the viewer got locked again. (Also tried
on an XP computer with the same result.)

So, I would appreciate any ideas how to repair the log.

 
youve got to stop teh event logging service, create new txt files except name the the event log name.evt...SecEvent.evt, System.evt, etc....replace teh files and thatll do it

-Brandon Wilson
MCSE00/03, MCSA:Messaging, MCSA03, A+
almost got a paragraph there :)
 
Hello Brandon,

I'm afraid, I couldn't really understand your instructions.
Can you please describe it a little bit more detailed way.
Thank you for your patience :)

Best regards.
Peter.
 
Try using logparser to read the files.

logparser -i:EVT -o:CSV "Select * into application.csv from application.evt"

logparser -i:EVT -o:CSV "Select * into security.csv from security.evt"

logparser -i:EVT -o:CSV "Select * into system.csv from system.evt"

Not sure if it will work buit it's worth a try.
 
actually i think i misunderstood yours

i was just telling you how to manually rebuild the event viewer

-Brandon Wilson
MCSE00/03, MCSA:Messaging, MCSA03, A+
almost got a paragraph there :)
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top