iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
PsLogList is a Microsoft Sysinternals command-line utility that dumps Windows Event Log records. It reads local logs by default, can query remote computers with alternate credentials, applies date, event-ID, source, and type filters, and can emit delimiter-separated records for scripts. Version 2.82 is listed by Microsoft as released March 30, 2023.
What PsLogList does
PsLogList is part of the PsTools family. Microsoft describes it as a clone of the Resource Kit’s elogdump, with two important additions: it can log on to a remote computer when the current credentials cannot access that computer’s event log, and it retrieves message strings from the computer hosting the log. It uses the Windows Event Log API and loads message-source modules on the system where the viewed log resides, which helps render provider messages correctly.
With no additional log argument, the documented default is the local computer’s System event log, displayed in a human-readable format. It is a command-line reader rather than a graphical replacement for every Event Viewer workflow.
Install and verify PsLogList
Microsoft’s documented installation is simply to copy PsLogList.exe to a directory on your executable path, then run psloglist from Command Prompt or another shell. The Microsoft utilities index lists PsLogList v2.82 and a 5 MB PsTools download (figures shown on the 2023 listing).
#1 Best Overall
- Download the PsTools package from Microsoft Sysinternals.
- Extract the package and place
PsLogList.exein a directory included inPATH, or change to the directory containing it. - Run
psloglistto display the local System log and confirm that the executable launches.
The documented platform scope is Windows 8.1 and later for client systems and Windows Server 2012 and later for servers.
Command syntax and the options that matter
psloglist [- ] [\computer[,computer[,...] | @file [-u username [-p password]]] [-s [-t delimiter]] [-m #|-n #|-h #|-d #|-w][-c][-x][-r][-a mm/dd/yy][-b mm/dd/yy][-f filter] [-i ID[,ID[,...] | -e ID[,ID,...]] [-o event source[,event source][,..]] [-q event source[,event source][,..]]] [-l event log file] <eventlog>
The final <eventlog> identifies the log to read, such as System, Application, or another available log. The main controls are:
Rank #2
| Option | Purpose | Important qualification |
|---|---|---|
\computer |
Query one or more remote computers. | Use the documented remote-access and credential requirements of the target. |
@file |
Run against every computer named in a file. | Each listed computer is processed by the command. |
-u, -p |
Supply an alternate remote username and optional password. | Use deliberately; avoid exposing passwords in shell history or process listings where possible. |
-a, -b |
Show records after or before a date in mm/dd/yy format. |
The date format follows the documented syntax. |
-m, -h, -d |
Limit output to the previous number of minutes, hours, or days. | These are relative time windows. |
-n |
Show only the specified number of most recent entries. | Useful for a quick tail of a log. |
-i, -e |
Include or exclude event IDs. | Up to 10 IDs are supported in the documented parameter table. |
-o, -q |
Include or omit event sources. | Provide one or more source names. |
-f |
Filter event types, such as warnings. | Use the filter names accepted by PsLogList. |
-s |
Print one record per line with comma-delimited fields. | Designed for searching and ingestion rather than visual reading. |
-t |
Change the delimiter used with structured, one-record-per-line output. | Choose a character that cannot collide with your field data. |
-x |
Include extended event data. | Output may contain additional fields or payload text. |
-r |
List records from least recent to most recent. | Useful when reviewing a time sequence. |
-w |
Wait for new events as they are generated. | Microsoft limits wait mode to the local system. |
-c |
Clear the event log after displaying it. | Destructive administrative action; confirm scope and retention requirements first. |
-l |
Read a specified event-log file. | The file must be an event-log file PsLogList can open. |
Common workflows
Read a local log
psloglist System
psloglist Application
The first command reads the local System log; the second reads the local Application log.
Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Clear out junk files and repair common Windows errorsFree Scan →Read a remote computer’s log
psloglist \SERVER01 System
To use alternate credentials, add the documented username and password switches:
Rank #3
psloglist \SERVER01 -u DOMAINoperator -p System
Remote access still depends on Windows permissions, network reachability, and the target’s event-log configuration. If the supplied account cannot connect, verify name resolution, firewall and RPC access, and rights on the target before changing the command.
Query several computers from a file
psloglist @computers.txt System
Put one computer name per line in computers.txt. Add -u and -p when the same alternate account is appropriate for the targets.
Rank #4
Filter by recency or calendar dates
psloglist -h 2 System
psloglist -d 7 System
psloglist -a 09/01/26 -b 09/30/26 System
The first two examples request the previous two hours and seven days. The date-bounded example uses the documented mm/dd/yy format; adjust dates to the period you actually intend to inspect.
Do these 3 things before closing this tab:
1Fix the driver behind crashes, sound loss and screen glitches2Repair Windows errors before they cause bigger problems3Scan for outdated or missing drivers - takes under a minuteFilter event IDs, sources, and types
psloglist -i 41,6008 System
psloglist -e 7036,7040 System
psloglist -o Service-Control-Manager System
psloglist -q Service-Control-Manager System
psloglist -f warning System
Use -i to keep only listed IDs, -e to omit them, -o to keep named sources, and -q to omit named sources. The -f switch filters by event type; the exact type keyword should match PsLogList’s accepted filter names.
Best Value
Produce ingestion-friendly output
psloglist -s System > system-events.txt
psloglist -s -t "|" System > system-events.psv
psloglist -s -x System > system-events-extended.txt
-s writes one record per line with comma-delimited fields. Add -t to select another delimiter, and -x when extended data is needed. These files are delimiter-separated text, not a guarantee of a standards-compliant CSV dialect; inspect quoting and embedded delimiters before loading them into a parser.
Follow new local events
psloglist -w System
Wait mode remains attached to the local system and prints events as they are generated. It is useful for reproducing a problem while watching the corresponding log, but it is not a remote live-stream feature according to Microsoft’s documented limitations.
Clear a log only as an explicit administrative action
psloglist -c System
PsLogList displays the log and then clears it. Treat this as destructive: preserve required evidence first, obtain authorization, and ensure retention or incident-response procedures do not require the records you are about to remove.
Choosing PsLogList versus other Windows logging tools
| Need | PsLogList | Event Viewer | PowerShell Get-WinEvent |
Centralized collector |
|---|---|---|---|---|
| Local interactive review | Fast command-line listing. | Rich graphical navigation. | Command-line and scriptable. | Usually viewed through a central console. |
| Remote scope | Supported, including alternate credentials. | Supported when connections and permissions are configured. | Supported through the relevant remoting or log-query methods. | Designed for many hosts. |
| Filtering | Time, IDs, sources, and event types. | Graphical custom views and filters. | Highly expressive scripted filtering. | Depends on product and ingestion rules. |
| Structured automation | One-record-per-line output with configurable delimiter. | Less convenient for shell pipelines. | Native object output. | Native normalized/searchable records. |
| Live follow | -w, local system only. |
Live view in the GUI. | Can be scripted with PowerShell patterns. | Continuous collection and alerting. |
| Message rendering | Uses message-source modules on the log’s host. | Windows rendering components. | Provider and message metadata dependent. | Depends on collector normalization. |
| Log destruction | -c can clear after display. |
Clear action is available in the GUI. | Separate administrative commands are normally used. | Retention is controlled centrally. |
Choose PsLogList when a small, portable Sysinternals executable and straightforward text output fit the job. Use PowerShell when object-based processing or complex logic is central, Event Viewer for graphical investigation, and a centralized collector when you need retention, correlation, alerting, or fleet-wide search.
Quick Recap
Troubleshooting and safe operating practices
- No access to a remote log: confirm the computer name, network path, firewall/RPC access, event-log permissions, and credentials. Try an explicitly supplied account only when authorized.
- Unreadable or incomplete messages: message text depends on source modules on the system hosting the log. Verify that the provider’s message resources are available there.
- Unexpected result count: check whether relative options such as
-h,-d, or-nnarrowed the result, and whether-i/-eor source filters excluded records. - Pipeline parsing problems: use
-s, select a delimiter with-t, and account for fields that may contain commas, the chosen delimiter, or extended data. - Events appear in the wrong order: omit or add
-rintentionally;-rrequests least-recent-to-most-recent order. - Evidence preservation: do not use
-cduring routine inspection. Export or otherwise preserve records before any authorized clear operation.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

