Windows Event Log tooling for PowerShell and .NET: typed queries, reporting, export, WEC, automation, and the PSEventViewer module.
-
Updated
Sep 5, 2026 - C#
Windows Event Log tooling for PowerShell and .NET: typed queries, reporting, export, WEC, automation, and the PSEventViewer module.
Cross-Platform, Agent-Native Universal Log Viewer.
Load Windows Event Log (.evtx) files into Elasticsearch, or export them as JSON lines. Born on an offline threat hunt; rebuilt for Elasticsearch 9.
An implementation of a Windows Event Collector server running on GNU/Linux.
WinLogAgent - A user-friendly, modern, and readily deployable Windows log collection client that makes it easy to forward collected logs to a SOC or SIEM.
WinLog Insight, an offline Windows log analyzer, gathers system, security and application logs. Its 90 built-in rules spot brute force, abnormal privilege escalation and other threats. It provides visual risk panels, real-time alerts and one-click PDF/Excel audit reports, storing all logs locally.
Windows Event Log Exporter Tool. Export system, application, and security event logs to CSV, EVTX, XML, TXT.
Setting up a Windows Event Collector
A Python tool that parses EVTX files and converts them into JSON formatted logs mimicking Wazuh agent behavior in version 4.x. wazuhevtx is designed as a helper for wazuh-logtest tool.
An open-source log collector for collecting logs from Windows Event Forwarding
PowerShell Module for using Microsoft Windows Event Viewer Custom Views for Event Log Filtering in PowerShell
Capture all events across all logs produced during the running of a particular exploit/script. Search and filter events
Convert Windows Event Log .evtx files to other formats.
Windows Event Log API binding from winevt.h. https://docs.microsoft.com/en-us/windows/desktop/api/_wes/
Search Windows event log and output results to a text file
A Python script that parses CPER-formatted raw data contained in error event log provided by WHEA-Logger
EVTX forensic library suite — carve records from corrupt files, detect tampering indicators, analyze ETW sessions. No runtime deps.
Python 3-based multithreaded Windows Event monitoring program
Setup-Guide for the central Logserver Graylog (dockerized)
To associate your repository with the windows-event-log topic, visit your repo's landing page and select "manage topics."