{"id":276,"date":"2017-03-20T11:34:02","date_gmt":"2017-03-20T11:34:02","guid":{"rendered":"http:\/\/eventlogxp.com\/blog\/?p=276"},"modified":"2017-03-20T13:33:03","modified_gmt":"2017-03-20T13:33:03","slug":"access-event-logs-from-windows-recovery-mode","status":"publish","type":"post","link":"https:\/\/eventlogxp.com\/blog\/access-event-logs-from-windows-recovery-mode\/","title":{"rendered":"Access event logs from Windows recovery mode"},"content":{"rendered":"<p>Sometimes this happens. Your computer stops booting correctly and needs to be fixed. Even safe mode doesn&#8217;t help. You don&#8217;t know the reason of the fault \u2013 it may be a hardware failure or a driver bug, but you don&#8217;t want to reinstall the operating system. There is a good chance that Windows logs may contain some useful information for troubleshooting. However, you cannot boot into the system to read the logs. What can you do?<\/p>\n<p>As a rule, you can disconnect your hard drive, connect it to another computer and read event logs as files there. But sometimes it is impossible (e.g. your drive is unremovable, inaccessible or you don&#8217;t have another computer with the same connection interface).<\/p>\n<p>You may try to start your PC with the recovery console and then use Command Prompt.<\/p>\n<p><strong>The easiest way to access recovery console on Windows 7 is:<\/strong><\/p>\n<ol>\n<li>Remove all removable disks (CDs, DVDs) from your computer, power on your computer.<\/li>\n<li>Press and hold the F8 key as your computer starts. You need to press F8 before the Windows logo appears. If the Windows logo appears, you need switch your PC off and restart it again.<br \/>\n<a href=\"http:\/\/eventlogxp.com\/blog\/wp-content\/uploads\/2017\/03\/win7_advanced_boot_options.png\" data-rel=\"lightbox-gallery-dyuoK1ES\" data-rl_title=\"\" data-rl_caption=\"\" title=\"\"><img loading=\"lazy\" class=\"alignnone size-medium wp-image-277\" src=\"http:\/\/eventlogxp.com\/blog\/wp-content\/uploads\/2017\/03\/win7_advanced_boot_options-300x188.png\" alt=\"Windows 7 advanced boot options\" width=\"300\" height=\"188\" srcset=\"https:\/\/eventlogxp.com\/blog\/wp-content\/uploads\/2017\/03\/win7_advanced_boot_options-300x188.png 300w, https:\/\/eventlogxp.com\/blog\/wp-content\/uploads\/2017\/03\/win7_advanced_boot_options.png 640w\" sizes=\"(max-width: 300px) 100vw, 300px\" \/><\/a><\/li>\n<li>Select Repair Your Computer<br \/>\n<a href=\"http:\/\/eventlogxp.com\/blog\/wp-content\/uploads\/2017\/03\/win7_system_recovery_options.png\" data-rel=\"lightbox-gallery-dyuoK1ES\" data-rl_title=\"\" data-rl_caption=\"\" title=\"\"><img loading=\"lazy\" class=\"alignnone size-medium wp-image-278\" src=\"http:\/\/eventlogxp.com\/blog\/wp-content\/uploads\/2017\/03\/win7_system_recovery_options-300x225.png\" alt=\"Windows 7 recovery options\" width=\"300\" height=\"225\" srcset=\"https:\/\/eventlogxp.com\/blog\/wp-content\/uploads\/2017\/03\/win7_system_recovery_options-300x225.png 300w, https:\/\/eventlogxp.com\/blog\/wp-content\/uploads\/2017\/03\/win7_system_recovery_options.png 483w\" sizes=\"(max-width: 300px) 100vw, 300px\" \/><\/a><\/li>\n<\/ol>\n<p>Now you can\u00a0click on Command Prompt. Voila, you may run Windows applications now!<\/p>\n<p>You may get more information at<br \/>\n<a href=\"https:\/\/support.microsoft.com\/en-us\/help\/17101\/windows-7-system-recovery-options\">https:\/\/support.microsoft.com\/en-us\/help\/17101\/windows-7-system-recovery-options<\/a><\/p>\n<p>Unfortunately, this approach commonly may fail with Windows 8 and Windows 10 (although it&#8217;s worth to try!). Please check this article which explains this issue:<br \/>\n<a href=\"https:\/\/blogs.msdn.microsoft.com\/b8\/2012\/05\/22\/designing-for-pcs-that-boot-faster-than-ever-before\/\">https:\/\/blogs.msdn.microsoft.com\/b8\/2012\/05\/22\/designing-for-pcs-that-boot-faster-than-ever-before\/<\/a><\/p>\n<p>To load into recovery console Microsoft suggests to boot your computer either with previously created recovery drive or use the installation media.<br \/>\nHowever I discovered that if you forcibly restart your computer several times when booting, Windows detects that something goes wrong and suggests to repair.<br \/>\n<a href=\"http:\/\/eventlogxp.com\/blog\/wp-content\/uploads\/2017\/03\/windows10-didnt-load-correctly.png\" data-rel=\"lightbox-gallery-dyuoK1ES\" data-rl_title=\"\" data-rl_caption=\"\" title=\"\"><img loading=\"lazy\" class=\"alignnone size-medium wp-image-279\" src=\"http:\/\/eventlogxp.com\/blog\/wp-content\/uploads\/2017\/03\/windows10-didnt-load-correctly-300x112.png\" alt=\"Windows didn't load correctly - repair options\" width=\"300\" height=\"112\" srcset=\"https:\/\/eventlogxp.com\/blog\/wp-content\/uploads\/2017\/03\/windows10-didnt-load-correctly-300x112.png 300w, https:\/\/eventlogxp.com\/blog\/wp-content\/uploads\/2017\/03\/windows10-didnt-load-correctly-768x288.png 768w, https:\/\/eventlogxp.com\/blog\/wp-content\/uploads\/2017\/03\/windows10-didnt-load-correctly-660x247.png 660w, https:\/\/eventlogxp.com\/blog\/wp-content\/uploads\/2017\/03\/windows10-didnt-load-correctly.png 843w\" sizes=\"(max-width: 300px) 100vw, 300px\" \/><\/a><\/p>\n<p>Click &#8220;See advanced repair option&#8221;, then click Troubleshoot and then click &#8220;Advanced Options&#8221;.<\/p>\n<p>On Advanced Options screen you can see different options to recover your PC, but since we decided to check logs first, select Command Prompt Option.<\/p>\n<p>Now you are in.<br \/>\n<a href=\"http:\/\/eventlogxp.com\/blog\/wp-content\/uploads\/2017\/03\/command-prompt.png\" data-rel=\"lightbox-gallery-dyuoK1ES\" data-rl_title=\"\" data-rl_caption=\"\" title=\"\"><img loading=\"lazy\" class=\"alignnone size-medium wp-image-280\" src=\"http:\/\/eventlogxp.com\/blog\/wp-content\/uploads\/2017\/03\/command-prompt-300x171.png\" alt=\"Command Prompt\" width=\"300\" height=\"171\" srcset=\"https:\/\/eventlogxp.com\/blog\/wp-content\/uploads\/2017\/03\/command-prompt-300x171.png 300w, https:\/\/eventlogxp.com\/blog\/wp-content\/uploads\/2017\/03\/command-prompt-660x376.png 660w, https:\/\/eventlogxp.com\/blog\/wp-content\/uploads\/2017\/03\/command-prompt.png 728w\" sizes=\"(max-width: 300px) 100vw, 300px\" \/><\/a><\/p>\n<p>You may be surprised, but you will see X: drive in the command prompt. \u00a0This is a recovery drive and you can see it only in the recovery session.<\/p>\n<p>Another surprise is that C: drive contains no data!<\/p>\n<p>Your original C: drive would be probably drive D: now. You can check it by viewing its contents e.g. by typing<br \/>\nDIR D:\\<\/p>\n<p>Let&#8217;s try to view events. First we need to run Event Log Explorer. You may think that you can run Event Viewer, but Windows won&#8217;t be able to start neither eventvwr.exe nor eventvwr.msc.<\/p>\n<p>If you have Event Log Explorer originally installed in C:\\Program Files (x86)\\Event Log Explorer, it&#8217;s now on D: drive and you can run it as follows:<\/p>\n<p>&#8220;D:\\Program Files (x86)\\Event Log Explorer\\elex.exe&#8221; (don&#8217;t forget to use double quotes or such paths).<br \/>\n<a href=\"http:\/\/eventlogxp.com\/blog\/wp-content\/uploads\/2017\/03\/elex-recovery-mode.png\" data-rel=\"lightbox-gallery-dyuoK1ES\" data-rl_title=\"\" data-rl_caption=\"\" title=\"\"><img loading=\"lazy\" class=\"alignnone size-medium wp-image-281\" src=\"http:\/\/eventlogxp.com\/blog\/wp-content\/uploads\/2017\/03\/elex-recovery-mode-300x185.png\" alt=\"event log explorer in recovery console\" width=\"300\" height=\"185\" srcset=\"https:\/\/eventlogxp.com\/blog\/wp-content\/uploads\/2017\/03\/elex-recovery-mode-300x185.png 300w, https:\/\/eventlogxp.com\/blog\/wp-content\/uploads\/2017\/03\/elex-recovery-mode-660x407.png 660w, https:\/\/eventlogxp.com\/blog\/wp-content\/uploads\/2017\/03\/elex-recovery-mode.png 696w\" sizes=\"(max-width: 300px) 100vw, 300px\" \/><\/a><\/p>\n<p>You can see a strange computer name in the tree and you will see no logs under this name. This happens because you are in recovery mode and Windows started in minimal configuration (eventlog service is disabled, Windows gives a random name to the PC).<\/p>\n<p>However you can still access the original event logs as files. They are on the system drive in \\Windows\\System32\\winevt\\Logs\\ \u00a0folder.<\/p>\n<p>So let&#8217;s try to open System log. It will be D:\\Windows\\System32\\winevt\\Logs\\System.evtx file. You can use any open method \u2013 all of them should work correctly. I would recommend use New API since it&#8217;s a native method for modern Windows.<br \/>\n<a href=\"http:\/\/eventlogxp.com\/blog\/wp-content\/uploads\/2017\/03\/elex-recovery-event-files.png\" data-rel=\"lightbox-gallery-dyuoK1ES\" data-rl_title=\"\" data-rl_caption=\"\" title=\"\"><img loading=\"lazy\" class=\"alignnone size-medium wp-image-282\" src=\"http:\/\/eventlogxp.com\/blog\/wp-content\/uploads\/2017\/03\/elex-recovery-event-files-300x179.png\" alt=\"Viewing event files from recovery mode\" width=\"300\" height=\"179\" srcset=\"https:\/\/eventlogxp.com\/blog\/wp-content\/uploads\/2017\/03\/elex-recovery-event-files-300x179.png 300w, https:\/\/eventlogxp.com\/blog\/wp-content\/uploads\/2017\/03\/elex-recovery-event-files-768x457.png 768w, https:\/\/eventlogxp.com\/blog\/wp-content\/uploads\/2017\/03\/elex-recovery-event-files-660x393.png 660w, https:\/\/eventlogxp.com\/blog\/wp-content\/uploads\/2017\/03\/elex-recovery-event-files.png 988w\" sizes=\"(max-width: 300px) 100vw, 300px\" \/><\/a><\/p>\n<p>Now you can explore your event logs and hopefully you will be able to locate and troubleshoot\u00a0the problem.<\/p>\n<p>&nbsp;<\/p>\n<a class=\"synved-social-button synved-social-button-share synved-social-size-24 synved-social-resolution-single synved-social-provider-facebook nolightbox\" data-provider=\"facebook\" target=\"_blank\" rel=\"nofollow\" title=\"Share on Facebook\" href=\"https:\/\/www.facebook.com\/sharer.php?u=https%3A%2F%2Feventlogxp.com%2Fblog%2Fwp-json%2Fwp%2Fv2%2Fposts%2F276&#038;t=Access%20event%20logs%20from%20Windows%20recovery%20mode&#038;s=100&#038;p&#091;url&#093;=https%3A%2F%2Feventlogxp.com%2Fblog%2Fwp-json%2Fwp%2Fv2%2Fposts%2F276&#038;p&#091;images&#093;&#091;0&#093;=https%3A%2F%2Feventlogxp.com%2Fblog%2Fwp-content%2Fuploads%2F2017%2F03%2Feventlog-recovery-mode.jpg&#038;p&#091;title&#093;=Access%20event%20logs%20from%20Windows%20recovery%20mode\" style=\"font-size: 0px;width:24px;height:24px;margin:0;margin-bottom:5px;margin-right:5px\"><img alt=\"Facebook\" title=\"Share on Facebook\" class=\"synved-share-image synved-social-image synved-social-image-share\" width=\"24\" height=\"24\" style=\"display: inline;width:24px;height:24px;margin: 0;padding: 0;border: none\" src=\"https:\/\/eventlogxp.com\/blog\/wp-content\/plugins\/social-media-feather\/synved-social\/image\/social\/regular\/48x48\/facebook.png\" \/><\/a><a class=\"synved-social-button synved-social-button-share synved-social-size-24 synved-social-resolution-single synved-social-provider-twitter nolightbox\" data-provider=\"twitter\" target=\"_blank\" rel=\"nofollow\" title=\"Share on Twitter\" href=\"https:\/\/twitter.com\/intent\/tweet?url=https%3A%2F%2Feventlogxp.com%2Fblog%2Fwp-json%2Fwp%2Fv2%2Fposts%2F276&#038;text=Check%20this%20Event%20Log%20Explorer%20blog%20post\" style=\"font-size: 0px;width:24px;height:24px;margin:0;margin-bottom:5px;margin-right:5px\"><img alt=\"twitter\" title=\"Share on Twitter\" class=\"synved-share-image synved-social-image synved-social-image-share\" width=\"24\" height=\"24\" style=\"display: inline;width:24px;height:24px;margin: 0;padding: 0;border: none\" src=\"https:\/\/eventlogxp.com\/blog\/wp-content\/plugins\/social-media-feather\/synved-social\/image\/social\/regular\/48x48\/twitter.png\" \/><\/a><a class=\"synved-social-button synved-social-button-share synved-social-size-24 synved-social-resolution-single synved-social-provider-reddit nolightbox\" data-provider=\"reddit\" target=\"_blank\" rel=\"nofollow\" title=\"Share on Reddit\" href=\"https:\/\/www.reddit.com\/submit?url=https%3A%2F%2Feventlogxp.com%2Fblog%2Fwp-json%2Fwp%2Fv2%2Fposts%2F276&#038;title=Access%20event%20logs%20from%20Windows%20recovery%20mode\" style=\"font-size: 0px;width:24px;height:24px;margin:0;margin-bottom:5px;margin-right:5px\"><img alt=\"reddit\" title=\"Share on Reddit\" class=\"synved-share-image synved-social-image synved-social-image-share\" width=\"24\" height=\"24\" style=\"display: inline;width:24px;height:24px;margin: 0;padding: 0;border: none\" src=\"https:\/\/eventlogxp.com\/blog\/wp-content\/plugins\/social-media-feather\/synved-social\/image\/social\/regular\/48x48\/reddit.png\" \/><\/a><a class=\"synved-social-button synved-social-button-share synved-social-size-24 synved-social-resolution-single synved-social-provider-pinterest nolightbox\" data-provider=\"pinterest\" target=\"_blank\" rel=\"nofollow\" title=\"Pin it with Pinterest\" href=\"https:\/\/pinterest.com\/pin\/create\/button\/?url=https%3A%2F%2Feventlogxp.com%2Fblog%2Fwp-json%2Fwp%2Fv2%2Fposts%2F276&#038;media=https%3A%2F%2Feventlogxp.com%2Fblog%2Fwp-content%2Fuploads%2F2017%2F03%2Feventlog-recovery-mode.jpg&#038;description=Access%20event%20logs%20from%20Windows%20recovery%20mode\" style=\"font-size: 0px;width:24px;height:24px;margin:0;margin-bottom:5px;margin-right:5px\"><img alt=\"pinterest\" title=\"Pin it with Pinterest\" class=\"synved-share-image synved-social-image synved-social-image-share\" width=\"24\" height=\"24\" style=\"display: inline;width:24px;height:24px;margin: 0;padding: 0;border: none\" src=\"https:\/\/eventlogxp.com\/blog\/wp-content\/plugins\/social-media-feather\/synved-social\/image\/social\/regular\/48x48\/pinterest.png\" \/><\/a><a class=\"synved-social-button synved-social-button-share synved-social-size-24 synved-social-resolution-single synved-social-provider-linkedin nolightbox\" data-provider=\"linkedin\" target=\"_blank\" rel=\"nofollow\" title=\"Share on Linkedin\" href=\"https:\/\/www.linkedin.com\/shareArticle?mini=true&#038;url=https%3A%2F%2Feventlogxp.com%2Fblog%2Fwp-json%2Fwp%2Fv2%2Fposts%2F276&#038;title=Access%20event%20logs%20from%20Windows%20recovery%20mode\" style=\"font-size: 0px;width:24px;height:24px;margin:0;margin-bottom:5px;margin-right:5px\"><img alt=\"linkedin\" title=\"Share on Linkedin\" class=\"synved-share-image synved-social-image synved-social-image-share\" width=\"24\" height=\"24\" style=\"display: inline;width:24px;height:24px;margin: 0;padding: 0;border: none\" src=\"https:\/\/eventlogxp.com\/blog\/wp-content\/plugins\/social-media-feather\/synved-social\/image\/social\/regular\/48x48\/linkedin.png\" \/><\/a><a class=\"synved-social-button synved-social-button-share synved-social-size-24 synved-social-resolution-single synved-social-provider-mail nolightbox\" data-provider=\"mail\" rel=\"nofollow\" title=\"Share by email\" href=\"mailto:?subject=Access%20event%20logs%20from%20Windows%20recovery%20mode&#038;body=Check%20this%20Event%20Log%20Explorer%20blog%20post:%20https%3A%2F%2Feventlogxp.com%2Fblog%2Fwp-json%2Fwp%2Fv2%2Fposts%2F276\" style=\"font-size: 0px;width:24px;height:24px;margin:0;margin-bottom:5px\"><img alt=\"mail\" title=\"Share by email\" class=\"synved-share-image synved-social-image synved-social-image-share\" width=\"24\" height=\"24\" style=\"display: inline;width:24px;height:24px;margin: 0;padding: 0;border: none\" src=\"https:\/\/eventlogxp.com\/blog\/wp-content\/plugins\/social-media-feather\/synved-social\/image\/social\/regular\/48x48\/mail.png\" \/><\/a>","protected":false},"excerpt":{"rendered":"<p>Sometimes this happens. Your computer stops booting correctly and needs to be fixed. Even safe mode doesn&#8217;t help. You don&#8217;t know the reason of the fault \u2013 it may be a hardware failure or a driver bug, but you don&#8217;t want to reinstall the operating system. There is a good chance that Windows logs may contain some useful information for troubleshooting. However, you cannot boot\u2026 <span class=\"read-more\"><a href=\"https:\/\/eventlogxp.com\/blog\/access-event-logs-from-windows-recovery-mode\/\">Read More &raquo;<\/a><\/span><\/p>\n","protected":false},"author":2,"featured_media":283,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[39],"tags":[50,9],"amp_enabled":true,"_links":{"self":[{"href":"https:\/\/eventlogxp.com\/blog\/wp-json\/wp\/v2\/posts\/276"}],"collection":[{"href":"https:\/\/eventlogxp.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/eventlogxp.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/eventlogxp.com\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/eventlogxp.com\/blog\/wp-json\/wp\/v2\/comments?post=276"}],"version-history":[{"count":5,"href":"https:\/\/eventlogxp.com\/blog\/wp-json\/wp\/v2\/posts\/276\/revisions"}],"predecessor-version":[{"id":288,"href":"https:\/\/eventlogxp.com\/blog\/wp-json\/wp\/v2\/posts\/276\/revisions\/288"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/eventlogxp.com\/blog\/wp-json\/wp\/v2\/media\/283"}],"wp:attachment":[{"href":"https:\/\/eventlogxp.com\/blog\/wp-json\/wp\/v2\/media?parent=276"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/eventlogxp.com\/blog\/wp-json\/wp\/v2\/categories?post=276"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/eventlogxp.com\/blog\/wp-json\/wp\/v2\/tags?post=276"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}