Scroll to navigation

EVTXEXPORT(1) General Commands Manual EVTXEXPORT(1)

NAME

evtxexportexports items stored in a Windows XML Event Log (EVTX) file

SYNOPSIS

evtxexport [-c codepage] [-f format] [-l log_file] [-L lcid] [-m mode] [-p message_files_path] [-r registy_files_path] [-s system_file] [-S software_file] [-t event_log_type] [-hTvV] source

DESCRIPTION

evtxexport is a utility to export items stored in a Windows XML Event Log (EVTX) file

evtxexport is part of the libevtx package. libevtx is a library to access the Windows XML Event Log (EVTX) format

source is the source file.

The options are as follows:

codepage
codepage of ASCII strings, options: ascii, windows-874, windows-932, windows-936, windows-949, windows-950, windows-1250, windows-1251, windows-1252 (default), windows-1253, windows-1254, windows-1255, windows-1256, windows-1257 or windows-1258
format
output format, options: xml, text (default)
shows this help
log_file
logs information about the exported items
lcid
preferred language of the message strings (default is 0, which is the first language in the resource file)
mode
export mode, option: all, items (default), recovered 'all' exports the (allocated) items and recovered items, 'items' exports the (allocated) items and 'recovered' exports the recovered items
message_files_path
search PATH for the resource files (default is the current working directory)
registy_files_path
name of the directory containing the SOFTWARE and SYSTEM (Windows) Registry file
system_file
filename of the SYSTEM (Windows) Registry file This option overrides the path provided by -r
software_file
filename of the SOFTWARE (Windows) Registry file This option overrides the path provided by -r
event_log_type
event log type, options: application, security, system if not specified the event log type is determined based on the filename
use event template definitions to parse the event record data
verbose output to stderr
print version

ENVIRONMENT

None

FILES

None

EXAMPLES

# evtxexport Application.evtx
evtxexport 20260623

Event number                    : 1
Creation time                   : Jan 29, 2010 21:47:19.000000000 UTC
Written time                    : Jan 29, 2010 21:47:20.000000000 UTC
Event version                   : 0
Event level                     : Information (4)
Computer name                   : HOSTNAME
Source name                     : Windows Search Service
Channel name                    : Application
Event identifier                : 0x000003f5 (1013)
Number of strings               : 0

DIAGNOSTICS

Errors, verbose and debug output are printed to stderr when verbose output -v is enabled. Verbose and debug output are only printed when enabled at compilation.

SEE ALSO

evtxinfo(1)

AUTHORS

Joachim Metz <joachim.metz@gmail.com>

BUGS

Please report bugs of any kind on the project issue tracker: https://github.com/libyal/libevtx/issues

COPYRIGHT

Copyright (C) 2011-2026, Joachim Metz <joachim.metz@gmail.com>.

This is free software; see the source for copying conditions. There is NO warranty; not even for MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.

July 4, 2026 Linux 6.4.0-150700.53.73-default