Backup / delete event log files
We can delete or backup event log files from command line using wmiccommands. The wmic sub command for managing event log files is nteventlog.
Below are the methods available with ‘wmic nteventlog‘ command.
Backup event log files
We can run the below command to backup a event log file.
wmic nteventlog where filename='logfilename' backupeventlog Backupfilepath
Let’s backup application event log to the file c:\application.evt. Command for this is as below.
wmic nteventlog where filename='application' backupeventlog c:\application.evt
Command to backup security event log file:
wmic nteventlog where filename='security' backupeventlog c:\security.evt
Command to backup system event log file:
wmic nteventlog where filename='system' backupeventlog c:\system.evt
Delete event log files:
Command to delete event log files is:
wmic nteventlog where filename='logfilename' cleareventlog
Command to delete application event log file:
wmic nteventlog where filename='application' cleareventlog
Command to clear system event log file:
wmic nteventlog where filename='system' cleareventlog
Command to clear security events log file:
wmic nteventlog where filename='security' cleareventlog