Scroll to navigation

EVTXINFO(1) General Commands Manual EVTXINFO(1)

NAME

evtxinfodetermines information about a Windows XML Event Log (EVTX) file

SYNOPSIS

evtxinfo [-c codepage] [-hvV] source

DESCRIPTION

evtxinfo is a utility to determine information about a Windows XML Event Log (EVTX) file

evtxinfo is part of the libevtx package. libevtx is a library to access the Windows XML Event Log (EVTX) format

source is the source file.

The options are as follows:

codepage
codepage of ASCII strings, options: ascii, windows-874, windows-932, windows-936, windows-949, windows-950, windows-1250, windows-1251, windows-1252 (default), windows-1253, windows-1254, windows-1255, windows-1256, windows-1257 or windows-1258
shows this help
verbose output to stderr
print version

ENVIRONMENT

None

FILES

None

EXAMPLES

# evtxinfo Application.evtx
evtxinfo 20260623

Windows Event Viewer Log (EVTX) information:
	Version				: 3.1
	Number of records		: 8515
	Number of recovered records	: 126
	Log type			: Application

DIAGNOSTICS

Errors, verbose and debug output are printed to stderr when verbose output -v is enabled. Verbose and debug output are only printed when enabled at compilation.

SEE ALSO

evtxexport(1)

AUTHORS

Joachim Metz <joachim.metz@gmail.com>

BUGS

Please report bugs of any kind on the project issue tracker: https://github.com/libyal/libevtx/issues

COPYRIGHT

Copyright (C) 2011-2026, Joachim Metz <joachim.metz@gmail.com>.

This is free software; see the source for copying conditions. There is NO warranty; not even for MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.

June 25, 2026 Linux 6.4.0-150700.53.73-default