table of contents
- Tumbleweed 20260705-1.1
- Leap-16.0
- Leap-15.6
| EVTXEXPORT(1) | General Commands Manual | EVTXEXPORT(1) |
NAME¶
evtxexport —
exports items stored in a Windows XML Event Log (EVTX)
file
SYNOPSIS¶
evtxexport |
[-c codepage]
[-f format]
[-l log_file]
[-L lcid]
[-m mode]
[-p message_files_path]
[-r registy_files_path]
[-s system_file]
[-S software_file]
[-t event_log_type]
[-hTvV] source |
DESCRIPTION¶
evtxexport is a utility to export items
stored in a Windows XML Event Log (EVTX) file
evtxexport is part of the
libevtx package. libevtx is
a library to access the Windows XML Event Log (EVTX) format
source is the source file.
The options are as follows:
-ccodepage- codepage of ASCII strings, options: ascii, windows-874, windows-932, windows-936, windows-949, windows-950, windows-1250, windows-1251, windows-1252 (default), windows-1253, windows-1254, windows-1255, windows-1256, windows-1257 or windows-1258
-fformat- output format, options: xml, text (default)
-h- shows this help
-llog_file- logs information about the exported items
-Llcid- preferred language of the message strings (default is 0, which is the first language in the resource file)
-mmode- export mode, option: all, items (default), recovered 'all' exports the (allocated) items and recovered items, 'items' exports the (allocated) items and 'recovered' exports the recovered items
-pmessage_files_path- search PATH for the resource files (default is the current working directory)
-rregisty_files_path- name of the directory containing the SOFTWARE and SYSTEM (Windows) Registry file
-ssystem_file- filename of the SYSTEM (Windows) Registry file This option overrides the path provided by -r
-Ssoftware_file- filename of the SOFTWARE (Windows) Registry file This option overrides the path provided by -r
-tevent_log_type- event log type, options: application, security, system if not specified the event log type is determined based on the filename
-T- use event template definitions to parse the event record data
-v- verbose output to stderr
-V- print version
ENVIRONMENT¶
None
FILES¶
None
EXAMPLES¶
# evtxexport Application.evtx evtxexport 20260623 Event number : 1 Creation time : Jan 29, 2010 21:47:19.000000000 UTC Written time : Jan 29, 2010 21:47:20.000000000 UTC Event version : 0 Event level : Information (4) Computer name : HOSTNAME Source name : Windows Search Service Channel name : Application Event identifier : 0x000003f5 (1013) Number of strings : 0
DIAGNOSTICS¶
Errors, verbose and debug output are printed to stderr when verbose output -v is enabled. Verbose and debug output are only printed when enabled at compilation.
SEE ALSO¶
AUTHORS¶
Joachim Metz <joachim.metz@gmail.com>
BUGS¶
Please report bugs of any kind on the project issue tracker: https://github.com/libyal/libevtx/issues
COPYRIGHT¶
Copyright (C) 2011-2026, Joachim Metz <joachim.metz@gmail.com>.
This is free software; see the source for copying conditions. There is NO warranty; not even for MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.
| July 4, 2026 | Linux 6.4.0-150700.53.73-default |