Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

PsLogList is a Microsoft Sysinternals command-line utility that dumps Windows Event Log records. It reads local logs by default, can query remote computers with alternate credentials, applies date, event-ID, source, and type filters, and can emit delimiter-separated records for scripts. Version 2.82 is listed by Microsoft as released March 30, 2023.

What PsLogList does

PsLogList is part of the PsTools family. Microsoft describes it as a clone of the Resource Kit’s elogdump, with two important additions: it can log on to a remote computer when the current credentials cannot access that computer’s event log, and it retrieves message strings from the computer hosting the log. It uses the Windows Event Log API and loads message-source modules on the system where the viewed log resides, which helps render provider messages correctly.

With no additional log argument, the documented default is the local computer’s System event log, displayed in a human-readable format. It is a command-line reader rather than a graphical replacement for every Event Viewer workflow.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Install and verify PsLogList

Microsoft’s documented installation is simply to copy PsLogList.exe to a directory on your executable path, then run psloglist from Command Prompt or another shell. The Microsoft utilities index lists PsLogList v2.82 and a 5 MB PsTools download (figures shown on the 2023 listing).

  1. Download the PsTools package from Microsoft Sysinternals.
  2. Extract the package and place PsLogList.exe in a directory included in PATH, or change to the directory containing it.
  3. Run psloglist to display the local System log and confirm that the executable launches.

The documented platform scope is Windows 8.1 and later for client systems and Windows Server 2012 and later for servers.

Command syntax and the options that matter

psloglist [- ] [\computer[,computer[,...] | @file [-u username [-p password]]] [-s [-t delimiter]] [-m #|-n #|-h #|-d #|-w][-c][-x][-r][-a mm/dd/yy][-b mm/dd/yy][-f filter] [-i ID[,ID[,...] | -e ID[,ID,...]] [-o event source[,event source][,..]] [-q event source[,event source][,..]]] [-l event log file] <eventlog>

The final <eventlog> identifies the log to read, such as System, Application, or another available log. The main controls are:

Option Purpose Important qualification
\computer Query one or more remote computers. Use the documented remote-access and credential requirements of the target.
@file Run against every computer named in a file. Each listed computer is processed by the command.
-u, -p Supply an alternate remote username and optional password. Use deliberately; avoid exposing passwords in shell history or process listings where possible.
-a, -b Show records after or before a date in mm/dd/yy format. The date format follows the documented syntax.
-m, -h, -d Limit output to the previous number of minutes, hours, or days. These are relative time windows.
-n Show only the specified number of most recent entries. Useful for a quick tail of a log.
-i, -e Include or exclude event IDs. Up to 10 IDs are supported in the documented parameter table.
-o, -q Include or omit event sources. Provide one or more source names.
-f Filter event types, such as warnings. Use the filter names accepted by PsLogList.
-s Print one record per line with comma-delimited fields. Designed for searching and ingestion rather than visual reading.
-t Change the delimiter used with structured, one-record-per-line output. Choose a character that cannot collide with your field data.
-x Include extended event data. Output may contain additional fields or payload text.
-r List records from least recent to most recent. Useful when reviewing a time sequence.
-w Wait for new events as they are generated. Microsoft limits wait mode to the local system.
-c Clear the event log after displaying it. Destructive administrative action; confirm scope and retention requirements first.
-l Read a specified event-log file. The file must be an event-log file PsLogList can open.

Common workflows

Read a local log

psloglist System
psloglist Application

The first command reads the local System log; the second reads the local Application log.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Read a remote computer’s log

psloglist \SERVER01 System

To use alternate credentials, add the documented username and password switches:

psloglist \SERVER01 -u DOMAINoperator -p System

Remote access still depends on Windows permissions, network reachability, and the target’s event-log configuration. If the supplied account cannot connect, verify name resolution, firewall and RPC access, and rights on the target before changing the command.

Query several computers from a file

psloglist @computers.txt System

Put one computer name per line in computers.txt. Add -u and -p when the same alternate account is appropriate for the targets.

Filter by recency or calendar dates

psloglist -h 2 System
psloglist -d 7 System
psloglist -a 09/01/26 -b 09/30/26 System

The first two examples request the previous two hours and seven days. The date-bounded example uses the documented mm/dd/yy format; adjust dates to the period you actually intend to inspect.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Filter event IDs, sources, and types

psloglist -i 41,6008 System
psloglist -e 7036,7040 System
psloglist -o Service-Control-Manager System
psloglist -q Service-Control-Manager System
psloglist -f warning System

Use -i to keep only listed IDs, -e to omit them, -o to keep named sources, and -q to omit named sources. The -f switch filters by event type; the exact type keyword should match PsLogList’s accepted filter names.

Produce ingestion-friendly output

psloglist -s System > system-events.txt
psloglist -s -t "|" System > system-events.psv
psloglist -s -x System > system-events-extended.txt

-s writes one record per line with comma-delimited fields. Add -t to select another delimiter, and -x when extended data is needed. These files are delimiter-separated text, not a guarantee of a standards-compliant CSV dialect; inspect quoting and embedded delimiters before loading them into a parser.

Follow new local events

psloglist -w System

Wait mode remains attached to the local system and prints events as they are generated. It is useful for reproducing a problem while watching the corresponding log, but it is not a remote live-stream feature according to Microsoft’s documented limitations.

Clear a log only as an explicit administrative action

psloglist -c System

PsLogList displays the log and then clears it. Treat this as destructive: preserve required evidence first, obtain authorization, and ensure retention or incident-response procedures do not require the records you are about to remove.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Choosing PsLogList versus other Windows logging tools

Need PsLogList Event Viewer PowerShell Get-WinEvent Centralized collector
Local interactive review Fast command-line listing. Rich graphical navigation. Command-line and scriptable. Usually viewed through a central console.
Remote scope Supported, including alternate credentials. Supported when connections and permissions are configured. Supported through the relevant remoting or log-query methods. Designed for many hosts.
Filtering Time, IDs, sources, and event types. Graphical custom views and filters. Highly expressive scripted filtering. Depends on product and ingestion rules.
Structured automation One-record-per-line output with configurable delimiter. Less convenient for shell pipelines. Native object output. Native normalized/searchable records.
Live follow -w, local system only. Live view in the GUI. Can be scripted with PowerShell patterns. Continuous collection and alerting.
Message rendering Uses message-source modules on the log’s host. Windows rendering components. Provider and message metadata dependent. Depends on collector normalization.
Log destruction -c can clear after display. Clear action is available in the GUI. Separate administrative commands are normally used. Retention is controlled centrally.

Choose PsLogList when a small, portable Sysinternals executable and straightforward text output fit the job. Use PowerShell when object-based processing or complex logic is central, Event Viewer for graphical investigation, and a centralized collector when you need retention, correlation, alerting, or fleet-wide search.

Troubleshooting and safe operating practices

  • No access to a remote log: confirm the computer name, network path, firewall/RPC access, event-log permissions, and credentials. Try an explicitly supplied account only when authorized.
  • Unreadable or incomplete messages: message text depends on source modules on the system hosting the log. Verify that the provider’s message resources are available there.
  • Unexpected result count: check whether relative options such as -h, -d, or -n narrowed the result, and whether -i/-e or source filters excluded records.
  • Pipeline parsing problems: use -s, select a delimiter with -t, and account for fields that may contain commas, the chosen delimiter, or extended data.
  • Events appear in the wrong order: omit or add -r intentionally; -r requests least-recent-to-most-recent order.
  • Evidence preservation: do not use -c during routine inspection. Export or otherwise preserve records before any authorized clear operation.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.