Repository files navigation Project 5 – Windows Event Viewer Log Analysis
Learn how to use Windows Event Viewer to investigate security events.
Practice reviewing Windows logs to identify successful logins, failed logins, and other activity that could help during a security investigation.
Windows 10 Pro
Windows Event Viewer
Security Log
Desktop Environment
Navigating Windows Event Viewer
Reviewing Windows Security Logs
Filtering event logs
Investigating successful logon events
Investigating failed logon events
Identifying Windows Event IDs
Understanding Windows authentication events
Tool
Purpose
Windows Event Viewer
Review Windows event logs
Windows Security Log
Analyze authentication activity
Filter Current Log
Search for specific Event IDs
Event Properties
Review event details
Opened Windows Event Viewer.
Navigated to the Windows Security log.
Reviewed Windows authentication events.
Filtered the Security log by Event ID.
Investigated successful logon events.
Reviewed failed logon attempts.
Examined event details including usernames, logon types, and timestamps.
Learned how Windows records authentication activity for investigations.
01 – Opening Windows Event Viewer
02 – Viewing Windows Security Log
03 – Filtering Windows Security Logs
04 – Investigating Successful Logon Events
05 – Investigating Windows Logoff Events
I learned how Windows records security activity using Event Viewer.
I became more comfortable filtering logs to quickly find specific events.
I learned how to identify successful and failed authentication attempts.
I realized how important timestamps and Event IDs are during an investigation.
I gained confidence navigating Windows logs without relying on third-party tools.
Windows Event Viewer is one of the first places a SOC analyst checks during an investigation.
Authentication logs help identify who logged in, when they logged in, and whether the activity was successful or failed.
Event IDs make it easier to locate important security events without searching through thousands of log entries.
Understanding Windows logs helps build a timeline during incident response.
You can’t perform that action at this time.