Where/how does Windows store the data in the event logs?
With Windows 2000/Server2003/Windows XP, the logs are stored in the %SystemRoot%\System32\Config
directory, with an .evt
extension.
With Server 2008/Vista and up, the log are stored in the %SystemRoot%\system32\winevt\logs
directory, and have an .evtx
extension. It's possible to convert old .evt
files to the newer .evtx
format
Within the Computer Manager you can also export them to a .txt
or .csv
file.