The Event Log component is a dynamic-link library (.dll) that runs as part of Services.exe. Event Log stores and retrieves events that can be viewed through the event viewer. By default, there are three types of logs: Security, System, and Application.

Component Configuration

There are no configuration requirements for this component.

Special Notes

The event log service implements the following APIs:

Function Description
BackupEventLog Saves the specified event log to a backup file.
ClearEventLog Clears the specified event log, and optionally saves the current copy of the logfile to a backup file.
CloseEventLog Closes a read handle to the specified event log.
DeregisterEventSource Closes a write handle to the specified event log.
GetEventLogInformation Retrieves information about the specified event log.
GetNumberOfEventLogRecords Retrieves the number of records in the specified event log.
GetOldestEventLogRecord Retrieves the absolute record number of the oldest record in the specified event log.
NotifyChangeEventLog Enables an application to receive notification when an event is written to the specified event logfile.
OpenBackupEventLog Opens a handle to a backup event log.
OpenEventLog Opens a handle to an event log.
ReadEventLog Reads a whole number of entries from the specified event log.
RegisterEventSource Retrieves a registered handle to an event log.
ReportEvent Writes an entry at the end of the specified event log.

For More Information

For more information on this component, see the chapter on Debugging and Error Handling in the Platform Software Development Kit (SDK) at this Microsoft Web site.

]]>
{00000000-0000-0000-0000-000000000000} File USER32.DLL {00000000-0000-0000-0000-000000000000} File RPCRT4.DLL %11% eventlog.dll False File NTDLL.DLL File KERNEL32.DLL File MSVCRT.DLL HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog DisplayName Event Log 1 1 1 HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog Description Logs event messages issued by programs and Windows. Event Log reports contain information that can be useful in diagnosing problems. Reports are viewed in Event Viewer. 1 1 1 HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog 1 1 1 HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog Type 32 4 1 1 HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog Start 2 4 1 1 HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog PlugPlayServiceType 3 4 1 1 HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog ObjectName LocalSystem 1 1 1 HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog ImagePath %SystemRoot%\system32\services.exe 2 1 1 HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog Group Event log 1 1 1 HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog ErrorControl 1 4 1 1 File netevent.dll HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application DisplayNameFile %SystemRoot%\system32\els.dll 2 1 1 HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application DisplayNameID 256 4 1 1 HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application File %SystemRoot%\system32\config\AppEvent.Evt 2 1 1 HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application MaxSize 5046272 4 1 1 HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application PrimaryModule Application 1 1 1 HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application Retention 0 4 1 1 HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Security DisplayNameFile %SystemRoot%\system32\els.dll 2 1 1 HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Security DisplayNameID 257 4 1 1 HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Security File %SystemRoot%\System32\config\SecEvent.Evt 2 1 1 HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Security MaxSize 5046272 4 1 1 HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Security PrimaryModule Security 1 1 1 HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Security Retention 0 4 1 1 HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System DisplayNameFile %SystemRoot%\system32\els.dll 2 1 1 HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System DisplayNameID 258 4 1 1 HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System File %SystemRoot%\system32\config\SysEvent.Evt 2 1 1 HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System MaxSize 5046272 4 1 1 HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System PrimaryModule System 1 1 1 HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System Retention 0 4 1 1 File els.dll File advapi32.dll File WS2_32.dll File PSAPI.DLL File NETAPI32.dll File netmsg.dll {00000000-0000-0000-0000-000000000000} evconcepts.chm %18% False 0 64982 evcon.chm evconcepts.chm Event Log 1.0 Logs event messages issued by programs and Windows. 2000 Microsoft Corp. Microsoft Corp. drbeck drbeck; shbrown 12/18/2000 10/16/2001 12:13:47 AM