Udostępnij za pośrednictwem


Filter Displayed Events

Applies To: Windows Server 2008, Windows Vista

When viewing an event log, you can filter the events being displayed. Event filtering is designed to be temporary and an applied filter can easily be removed. However, if you create a useful filter that you want to reuse, you can save it as a custom view.

To filter displayed events

  1. Start Event Viewer.

  2. In the console tree, select the event log you want to filter.

  3. On the Action menu, click Filter Current Log.

  4. To filter events based on when they occurred, select the corresponding time period from the Logged drop-down list.

Note

If none of the options are acceptable, choose Custom range. In the Custom range dialog box, specify the earliest date and time from which you want events and the latest date and time from which you want events. Click OK.

  1. In Event level, select the check boxes next to the event levels that you want the filter to display.

  2. In the Event source drop-down list, select the check boxes next to the event sources that you want your filter to display.

  3. In Event IDs, type the event IDs that you want your filter to display. Separate multiple event IDs by commas. If you want to include a range of IDs, say 4624 through 4634 inclusive, type 4624-4634. If you want your filter to display events with all IDs except certain ones, type the IDs of those exceptions, preceded by a minus sign. For example, to include all IDs between 4624 and 4634 except for 4630, type 4624-4634,-4630.

  4. In Task Category, select the check boxes next to the task categories in the drop-down list that you want your filter to display.

  5. In the Keywords drop-down list, select the check boxes next to the keywords that you want your filter to display.

  6. In User, enter the name of the user accounts you want your filter to display. To enter multiple user accounts, separate them with a comma (,).

  7. In Computer(s), enter the name of computers that you want the filter to display. This field refers to the source computer of the event. Enter multiple computers by separating them with a comma (,).

  8. Click OK to apply the filter.

Additional Considerations

  • To remove a currently applied filter, on the Action menu, click Clear Filter.

  • Leaving a field in the Filter Current Log dialog box blank specifies that you want the filter to display entries with any value of the corresponding property.

  • You cannot filter on an Event source, Task category, or Keyword that has not yet appeared in the log you are filtering.

  • Filters apply to a single event log. If you want to filter across event logs, you must create a custom view.

Additional Resources

Save Filter as a Custom View