Zetetic.Events is a free command-line tool that can quickly scan and filter multiple running Windows Event Logs, and archived .evt and .evtx files, in parallel.
Submitted by Steve Kradel
It taps into the new 2008 / Windows 7 logging infrastructure when available, but will fall back to 2003 mode when necessary, and supports filtering on event IDs, and start and end dates, as well as text within the event message.
Zetetic.Events automatically discovers your environment’s domain controllers, which makes it especially valuable for diagnosing login failures, account lockouts, and security audit events.
Here is an example:
ZeShell -e 4728-4758,after=19-July-2011
-----------------------------------------------------
Event ID: 4728
Level: Information
Keywords: Audit Success
Publisher: Microsoft-Windows-Security-Auditing
Created: 7/20/2011 2:35:17 PM
Machine: dc-1.demo.net
Log: Security
Description: A member was added to a security-enabled global group.
Subject:
Security ID: S-1-5-21-950928700-2040260430-2032203972-500
Account Name: Administrator
Account Domain: DEMO
Logon ID: 0x454d11
Member:
Security ID: S-1-5-21-950928700-2040260430-2032203972-187428
Account Name: CN=Uncle Fester,OU=ZetDemo,DC=demo,DC=net
Group:
Security ID: S-1-5-21-950928700-2040260430-2032203972-187514
Group Name: Global1
Group Domain: DEMO
Additional Information:
Privileges: -