Old Windows events can be converted to new events by adding 4096 to the Event ID.
Windows Event Log analysis can help an investigator draw a timeline based on the logging information and the discovered artifacts, but a deep knowledge of events IDs is mandatory.Īccording to the version of Windows installed on the system under investigation, the number and types of events will differ, so the events logged by a Windows XP machine may be incompatible with an event log analysis tool designed for Windows 8.įor example, Event ID 551 on a Windows XP machine refers to a logoff event the Windows 7 equivalent is Event ID 4647. During a forensic investigation, Windows Event Logs are the primary source of evidence.