DonatShell
Server IP : 180.180.241.3  /  Your IP : 216.73.216.252
Web Server : Microsoft-IIS/7.5
System : Windows NT NETWORK-NHRC 6.1 build 7601 (Windows Server 2008 R2 Standard Edition Service Pack 1) i586
User : IUSR ( 0)
PHP Version : 5.3.28
Disable Function : NONE
MySQL : ON  |  cURL : ON  |  WGET : OFF  |  Perl : OFF  |  Python : OFF  |  Sudo : OFF  |  Pkexec : OFF
Directory :  /Windows/Help/Windows/en-US/

Upload File :
current_dir [ Writeable ] document_root [ Writeable ]

 

Command :


[ HOME SHELL ]     

Current File : /Windows/Help/Windows/en-US/eventviewer.h1s
MZ@PEL!@0Y@.rsrc@@.its @@0	HX||4VS_VERSION_INFOStringFileInfo040904b0b!FileVersion1.00.00                         l"FileDescriptionCompiled Microsoft Help 2.0 TitleBFileStamp991184E801CA041F4JCompilerVersion2.5.71210.08579VCompileDate2009-07-14T01:08:29      >TopicCount72000000000000ALegalCopyright 2005 Microsoft Corporation. All rights reserved.CCCCCCCCCCCCCDVarFileInfo$Translation	tiHõZITOLITLS(X쌡^
V`   x NCAOLPHHC ITSF #~	T-Y쌡^
VY쌡^
VIFCMAOLLNIFCM AOLL//$FXFtiAttribute//$FXFtiAttribute/BTREEI/$FXFtiAttribute/DATA/$FXFtiAttribute/PROPERTYaN/$FXFtiMain//$FXFtiMain/BTREE9/$FXFtiMain/DATAQ*/$FXFtiMain/PROPERTY{N/$Index/$ATTRNAME/\/$Index/$PROPBAG}/$Index/$STRINGS7Z/$Index/$SYSTEMv
/$Index/$TOC//$Index/$TOC/$eventviewer_LH./$Index/$TOPICATTR//$Index/$TOPICSw/$Index/$URLSTR&/$Index/$URLTBL7@/$Index/$VTAIDX$/$Index/AssetId//$Index/AssetId/$BL0//$Index/AssetId/$LEAF_COUNTS//$Index/AssetId/$LEAVES7	/$OBJINST./assets/0/assets/0234cfde-93d4-46c3-a0dd-f26c6273aa26.xmltq0/assets/05fb8bc9-aca3-4bf6-83c3-1834297ccf49.xmle;0/assets/07abe800-89a9-43c5-a7bd-84304a881e7f.xml i0/assets/0b81db9c-f482-4aa5-865a-d467517d9753.xml	c0/assets/129e033f-7c7d-419c-99f2-91053a3ce090.xmllF0/assets/165d8b7c-a85e-42c2-8316-6701f0701c88.xml210/assets/1833ed94-ec57-4783-aed9-4ce3a7bb2fea.xmlcK0/assets/2564192f-b638-47c8-ad31-9dbdf6f198f9.xml.0/assets/28cd5e13-e955-4941-91d9-fec2525e96c7.xmlCQ0/assets/29ae83c2-2fca-4897-b95d-343706080fa5.xml0/assets/386a877a-220a-4a7f-9238-7bacdee90279.xml1N0/assets/3eff5d43-dc9b-4777-9362-b21010adbecb.xml0/assets/4229f239-16a6-4ecd-b3cf-aec03dc08cd5.xml'0/assets/42e22049-94cb-4ace-b3d6-5f3a6ec61caa.xml2v0/assets/473cb9ba-4aee-4717-a517-120371159da8.xml(Y0/assets/4aa6403f-d4b8-43a4-a70d-ceb7f88c524e.xmlE0/assets/543a7a70-4955-4628-b4ee-79f9bad741b1.xmlF0/assets/67e1dc18-b03a-4236-8cb7-0bb191c5a0b7.xml^^0/assets/7511c36a-cf41-41f5-b8cb-f4c233ca2bb3.xml<40/assets/769748f2-603c-44b1-95f0-bd13efdde2a3.xmlp00/assets/7710dc96-8061-4cfe-aafb-c7fdf1c6f7b6.xml 0/assets/79610900-b937-4686-aee3-3d72875d4d66.xml,>0/assets/7b26a107-7c1f-49c1-b5fa-2f6093bfa6bc.xmljC0/assets/7c01708c-ca47-4f62-b731-4ac3f3934786.xml-70/assets/7ed13aea-4580-4ecd-93ef-9b09b504b87a.xmld0/assets/7ee045ef-1e94-414b-9099-193b5b6bc439.xmld*0/assets/816eb4fa-7972-4f2a-9d72-c437c326e7be.xmlt0/assets/8fd4aad5-50bc-4389-bdae-e09ee464e46d.xmlG0/assets/a37fd11e-597a-4d44-9507-a88e937bda50.xmlI!0/assets/ad46b98b-dd6b-4578-9dae-dfac1310ab7a.xmlj10/assets/b7ed11ad-4b4f-43c0-88f6-43de77fc6762.xml%0/assets/cfad9c47-96cc-46d8-b432-2baf661a72bb.xml@H0/assets/df28b174-f31a-4f18-a090-3ccbb394847e.xml90/assets/e1459340-eaed-40c7-93a0-36bd933bdd7e.xmlA	0/assets/edec63a3-fa81-4677-99ae-b6cdada48d6d.xmlJ/0/assets/ff1ea5b3-0127-488d-af6e-0d9267cefdc4.xmlyt/eventviewer_lh.h1cm?/eventviewer_LH.H1F,&/eventviewer_LH.H1TW"/eventviewer_LH.H1VR/eventviewer_LH_AssetId.H1Kyk/eventviewer_LH_BestBet.H1Kdk/eventviewer_LH_LinkTerm.H1KOl/eventviewer_LH_SubjectTerm.H1K;o::DataSpace/NameList<(::DataSpace/Storage/MSCompressed/Content*z,::DataSpace/Storage/MSCompressed/ControlDataT )::DataSpace/Storage/MSCompressed/SpanInfoL/::DataSpace/Storage/MSCompressed/Transform/List<_::DataSpace/Storage/MSCompressed/Transform/{8CEC5846-07A1-11D9-B15E-000D56BFE6EE}/InstanceData/i::DataSpace/Storage/MSCompressed/Transform/{8CEC5846-07A1-11D9-B15E-000D56BFE6EE}/InstanceData/ResetTable$X3::Transform/{8CEC5846-07A1-11D9-B15E-000D56BFE6EE}/
Z
	xeR?,HXpNUncompressedMSCompressedFX쌡^
VLZXCHH<maml:conceptual contentType="conceptual" xmlns:maml="http://schemas.microsoft.com/maml/2004/10" xmlns:dev="http://schemas.microsoft.com/maml/dev/2004/10"><maml:title>Create a Custom View</maml:title><maml:introduction>
<maml:para>You can create a filter that includes events from multiple event logs that satisfy specified criteria. You can then name and save that filter as a custom view. To apply the filter associated with a saved custom view, you navigate to the custom view in the console tree and click its name.</maml:para>

<maml:para></maml:para>
</maml:introduction><maml:content><maml:sections><maml:section><maml:title></maml:title><maml:introduction>
<maml:procedure><maml:title>To create a custom view</maml:title><maml:step><maml:sections><maml:section><maml:title></maml:title>
<maml:para>Start Event Viewer.</maml:para>
</maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title>
<maml:para>On the <maml:ui>Action</maml:ui> menu, click <maml:ui>Create Custom View</maml:ui>. </maml:para>
</maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title>
<maml:para>To filter events based upon when they occurred, select the corresponding time period from the <maml:ui>Logged</maml:ui> drop-down list. </maml:para>

<maml:alertSet class="note"><maml:title>Note </maml:title>
<maml:para>If none of the options are acceptable, choose <maml:ui>Custom range</maml:ui>. In the <maml:ui>Custom range</maml:ui> dialog box, specify the earliest date and time from which you want events and the latest date and time from which you want events. Click <maml:ui>OK</maml:ui>.</maml:para>
</maml:alertSet>
</maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title>
<maml:para>In <maml:ui>Event level</maml:ui>, select the check boxes next to the event levels that you want included in the custom view.</maml:para>
</maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title>
<maml:para>You can either specify the event logs or the event sources of the events that will appear in the custom view.</maml:para>

<maml:list class="unordered">
<maml:listItem>
<maml:para><maml:phrase>To specify the event logs</maml:phrase>: Select the <maml:ui>Event Log</maml:ui> option and, in the <maml:ui>Event log </maml:ui>drop-down list, select the check boxes next to the event logs from which you want to include events.</maml:para>
</maml:listItem>

<maml:listItem>
<maml:para><maml:phrase>To specify the event sources</maml:phrase>: Select the <maml:ui>Event Source</maml:ui> option and, in the <maml:ui>Event source</maml:ui> drop-down list, select the check boxes next to the event sources in the drop-down list that you want to include in the custom view.</maml:para>
</maml:listItem>
</maml:list>
</maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title>
<maml:para>In <maml:ui>Event IDs</maml:ui>, type the event IDs that you want your custom view to display. Separate multiple event IDs by commas. If you want to include a range of IDs, say 4624 through 4634 inclusive, type <maml:userInput>4624-4634</maml:userInput>. If you want your filter to display events with all IDs except certain ones, type the IDs of those exceptions, preceded by a minus sign. For example, to include all IDs between 4624 and 4634 except for 4630, type <maml:userInput>4624-4634,-4630</maml:userInput>.</maml:para>
</maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title>
<maml:para>In <maml:ui>Task Category</maml:ui>, select the check boxes next to the task categories in the drop-down list that you want included in the custom view.</maml:para>
</maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title>
<maml:para>In <maml:ui>Keywords</maml:ui>, select the check boxes next to the keywords in the drop-down list that you want included in the custom view.</maml:para>
</maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title>
<maml:para>In <maml:ui>User</maml:ui>, enter the name of the user accounts you want to display. Enter multiple users by separating them with a comma (,). </maml:para>
</maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title>
<maml:para>In <maml:ui>Computer(s)</maml:ui>, enter the name of the computers that you want your custom view to display. Enter multiple computers by separating them with a comma (,).</maml:para>
</maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title>
<maml:para>Click <maml:ui>OK</maml:ui>.</maml:para>
</maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title>
<maml:para>On the <maml:ui>Save Filter to Custom View</maml:ui> dialog box, in <maml:ui>Name</maml:ui>, type a name for the custom view.</maml:para>
</maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title>
<maml:para>In <maml:ui>Description</maml:ui>, type an optional description of the custom view.</maml:para>
</maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title>
<maml:para>Select the folder in which you want to store the custom view. </maml:para>

<maml:alertSet class="note"><maml:title>Note </maml:title>
<maml:para>Custom views can be stored in the Custom Views folder or any subfolder of the Custom Views folder. You can create new subfolders in the Custom Views folder by selecting it and clicking <maml:ui>New Folder</maml:ui>.</maml:para>
</maml:alertSet>
</maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title>
<maml:para>You can make the Custom View accessible to anyone using the computer or only to someone logged on to your current account.</maml:para>

<maml:list class="unordered">
<maml:listItem>
<maml:para><maml:phrase>To save the custom view and make it accessible to anyone using the computer</maml:phrase>: Ensure the <maml:ui>All Users</maml:ui> check box is selected and click <maml:ui>OK</maml:ui>. </maml:para>
</maml:listItem>

<maml:listItem>
<maml:para><maml:phrase>To save the custom view and make it accessible only to someone logged on to your current account</maml:phrase>: Ensure that the <maml:ui>All Users</maml:ui> check box is not selected and click <maml:ui>OK</maml:ui>.</maml:para>
</maml:listItem>
</maml:list>
</maml:section></maml:sections></maml:step></maml:procedure>
</maml:introduction>
<maml:sections>
<maml:section>
<maml:title>Additional Considerations</maml:title><maml:introduction>
<maml:list class="unordered">
<maml:listItem>
<maml:para>Leaving a field in the <maml:ui>Create Custom View</maml:ui> dialog box blank specifies that you want your filter to display entries with any value of the corresponding property.</maml:para>
</maml:listItem>
</maml:list>
</maml:introduction>
<maml:sections>
<maml:section>
<maml:title>Additional Resources</maml:title><maml:introduction>
<maml:para><maml:navigationLink><maml:linkText>Custom Views</maml:linkText><maml:uri href="mshelp://windows/?id=ff1ea5b3-0127-488d-af6e-0d9267cefdc4"></maml:uri></maml:navigationLink></maml:para>
</maml:introduction></maml:section>
</maml:sections>
</maml:section>
</maml:sections>
</maml:section></maml:sections></maml:content></maml:conceptual><maml:conceptual contentType="conceptual" xmlns:maml="http://schemas.microsoft.com/maml/2004/10" xmlns:dev="http://schemas.microsoft.com/maml/dev/2004/10"><maml:title>Open or Close a Saved Log</maml:title><maml:introduction>
<maml:para>You can open and view a log that has been archived using Event Viewer. You can open multiple saved logs and access them at anytime in the console tree. A log that has been opened in Event Viewer can be closed without deleting the information in the log.</maml:para>

<maml:procedure><maml:title>To open a saved event log</maml:title><maml:step><maml:sections><maml:section><maml:title></maml:title>
<maml:para>Start Event Viewer.</maml:para>
</maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title>
<maml:para>In the <maml:ui>Actions</maml:ui> menu, click <maml:ui>Open Saved Log</maml:ui>.</maml:para>
</maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title>
<maml:para>In the <maml:ui>Look in</maml:ui> box, select the folder where the log file is located.</maml:para>
</maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title>
<maml:para>Select the log file, and then click <maml:ui>Open</maml:ui>.</maml:para>
</maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title>
<maml:para>(Optional) In the <maml:ui>Name</maml:ui> box, enter a new name that will be used for the log in the console tree or you can use the existing name of the log file.</maml:para>

<maml:alertSet class="note"><maml:title>Note </maml:title>
<maml:para>If you enter a name that is different than the log file name, the name is only used to represent the log in the console tree and does not change the name of the log file.</maml:para>
</maml:alertSet>
</maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title>
<maml:para>(Optional) In the <maml:ui>Description</maml:ui> box, enter a description for the log. The description will appear in the center pane when you click the parent folder of the log in the console tree.</maml:para>
</maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title>
<maml:para>(Optional) Click <maml:ui>New Folder</maml:ui>, enter the name for the folder where the opened log will be located, and then click <maml:ui>OK</maml:ui>. If you do not select a parent folder, the new folder will be located in Saved Logs.</maml:para>
</maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title>
<maml:para>(Optional) If you are an administrator on the computer, you can click to clear the <maml:ui>All Users</maml:ui> checkbox if you do not want the opened log to be available to other users when Event Viewer is started. If you do not clear the checkbox, the opened log will be available to all users and they will not be able to remove it from the console tree unless they have administrator rights. </maml:para>
</maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title>
<maml:para>Select the location where you want the log to be located in the console tree. You must place the log in the Saved Logs folder or a new folder under the Saved Logs folder.</maml:para>
</maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title>
<maml:para>Click <maml:ui>OK</maml:ui>.</maml:para>
</maml:section></maml:sections></maml:step></maml:procedure>

<maml:para>You can close a log by deleting the log from the console tree. </maml:para>

<maml:alertSet class="important"><maml:title>Important </maml:title>
<maml:para>When you delete the log, you are only removing it from the console tree; you are not deleting the log file from the system.</maml:para>
</maml:alertSet>

<maml:procedure><maml:title>To remove an open log from the console tree</maml:title><maml:step><maml:sections><maml:section><maml:title></maml:title>
<maml:para>Start Event Viewer if it is not already running.</maml:para>
</maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title>
<maml:para>Select the log that you want to remove from the console tree.</maml:para>
</maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title>
<maml:para>In the <maml:ui>Actions</maml:ui> menu, click <maml:ui>Delete</maml:ui>. You can also right-click the log in the console tree and then click <maml:ui>Delete</maml:ui>, or you can click the log in the console tree and press the <maml:ui>Delete</maml:ui> key.</maml:para>
</maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title>
<maml:para>Click <maml:ui>Yes</maml:ui>.</maml:para>
</maml:section></maml:sections></maml:step></maml:procedure>
</maml:introduction><maml:content><maml:sections><maml:section><maml:title>Additional resources</maml:title>
<maml:introduction><maml:para><maml:navigationLink><maml:linkText>Manage Event Logs</maml:linkText><maml:uri href="mshelp://windows/?id=543a7a70-4955-4628-b4ee-79f9bad741b1"></maml:uri></maml:navigationLink></maml:para></maml:introduction></maml:section></maml:sections></maml:content></maml:conceptual><maml:conceptual contentType="conceptual" xmlns:maml="http://schemas.microsoft.com/maml/2004/10" xmlns:dev="http://schemas.microsoft.com/maml/dev/2004/10"><maml:title>Set Maximum Log Size</maml:title><maml:introduction>
<maml:para>Event logs are stored in files. These files have a default maximum size, which you can change. You can perform this procedure by using the Windows interface or a command line.</maml:para>
</maml:introduction><maml:content><maml:sections><maml:section><maml:title></maml:title><maml:introduction>
<maml:procedure><maml:title>To set maximum log size by using the Windows interface</maml:title><maml:introduction><maml:sections><maml:section><maml:title></maml:title><maml:introduction>
<maml:alertSet class="note"><maml:title>Note </maml:title>
<maml:para>Log size must be a multiple of 64KB and cannot be smaller than 1024KB. If you type a log size rather than use the spinner control, it will be rounded to the nearest multiple of 64KB.</maml:para>
</maml:alertSet>
</maml:introduction></maml:section></maml:sections></maml:introduction><maml:step><maml:sections><maml:section><maml:title></maml:title>
<maml:para>Start Event Viewer.</maml:para>
</maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title>
<maml:para>In the console tree, navigate to and select the event log you want to manage.</maml:para>
</maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title>
<maml:para>On the <maml:ui>Action</maml:ui> menu, click <maml:ui>Properties</maml:ui>.</maml:para>
</maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title>
<maml:para>In <maml:ui>Maximum log size (KB)</maml:ui>, use the spinner control to set the value you want and click <maml:ui>OK</maml:ui>.</maml:para>
</maml:section></maml:sections></maml:step></maml:procedure>

<maml:procedure><maml:title>To set maximum log size by using a command line</maml:title><maml:step><maml:sections><maml:section><maml:title></maml:title>
<maml:para>To open a command prompt, click <maml:ui>Start</maml:ui>, click <maml:ui>Run</maml:ui>, type <maml:userInput>cmd</maml:userInput>, and click <maml:ui>OK</maml:ui>.</maml:para>
</maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title>
<maml:para>Type the following command:</maml:para>

<dev:code>wevtutil sl &lt;LogName&gt; /ms:&lt;MaxSizeInBytes&gt;</dev:code>
</maml:section></maml:sections></maml:step></maml:procedure>

<maml:para>To view the complete syntax for this command, type the following at a command prompt:</maml:para>

<dev:code>wevtutil sl -?</dev:code>
</maml:introduction>
<maml:sections>
<maml:section>
<maml:title>Additional considerations</maml:title><maml:introduction>
<maml:list class="unordered">
<maml:listItem>
<maml:para>You must be a member of the Administrators group to set a maximum log size.</maml:para>
</maml:listItem>

<maml:listItem>
<maml:para>If you set a maximum log size that is smaller than the current size of the log, the maximum size will not be enforced until after the log is cleared.</maml:para>
</maml:listItem>
</maml:list>
</maml:introduction>
<maml:sections>
<maml:section>
<maml:title>Additional references</maml:title><maml:introduction>
<maml:list class="unordered">
<maml:listItem>
<maml:para><maml:navigationLink><maml:linkText>Command-line syntax notation</maml:linkText><maml:uri href="mshelp://windows/?id=7ed13aea-4580-4ecd-93ef-9b09b504b87a"></maml:uri></maml:navigationLink></maml:para>
</maml:listItem>
</maml:list>
</maml:introduction></maml:section>
</maml:sections>
</maml:section>
</maml:sections>
</maml:section></maml:sections></maml:content></maml:conceptual><maml:conceptual contentType="conceptual" xmlns:maml="http://schemas.microsoft.com/maml/2004/10" xmlns:dev="http://schemas.microsoft.com/maml/dev/2004/10"><maml:title>Import a Custom View</maml:title><maml:introduction>
<maml:para>Custom views can be exported as XML files with an XML file name extension. The resulting XML files can be imported using Event Viewer. This allows custom views to be shared between users and computers.</maml:para>
</maml:introduction><maml:content><maml:sections><maml:section><maml:title></maml:title><maml:introduction>
<maml:procedure><maml:title>To import a custom view</maml:title><maml:step><maml:sections><maml:section><maml:title></maml:title>
<maml:para>Start Event Viewer.</maml:para>
</maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title>
<maml:para>On the <maml:ui>Action</maml:ui> menu, click <maml:ui>Import Custom View</maml:ui>.</maml:para>
</maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title>
<maml:para>Navigate to the location of the exported view, click the corresponding .xml file and click <maml:ui>Open</maml:ui>.</maml:para>
</maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title>
<maml:para>On the <maml:ui>Import Custom View File</maml:ui> dialog box, in <maml:ui>Name</maml:ui>, enter a name for the imported custom view.</maml:para>
</maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title>
<maml:para>In <maml:ui>Description</maml:ui>, enter a description of the custom view.</maml:para>
</maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title>
<maml:para>Select the folder in which you want to store the custom view. </maml:para>

<maml:alertSet class="note"><maml:title>Note </maml:title>
<maml:para>Custom views can be stored in the Custom Views folder or any subfolder of the Custom Views folder. You can create new subfolders in the Custom Views folder by selecting it and clicking <maml:ui>New Folder</maml:ui>.</maml:para>
</maml:alertSet>
</maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title>
<maml:para>If you want the custom view to be accessible to anyone using the computer, ensure the <maml:ui>All Users</maml:ui> check box is selected and click <maml:ui>OK</maml:ui>. If you want the custom view to be accessible only to someone logged on to your current account, ensure that the <maml:ui>All Users</maml:ui> check box is not selected and click <maml:ui>OK</maml:ui>.</maml:para>
</maml:section></maml:sections></maml:step></maml:procedure>
</maml:introduction></maml:section><maml:section><maml:title>Additional references</maml:title>
<maml:introduction><maml:para><maml:navigationLink><maml:linkText>Create and Manage Custom Views</maml:linkText><maml:uri href="mshelp://windows/?id=7c01708c-ca47-4f62-b731-4ac3f3934786"></maml:uri></maml:navigationLink></maml:para></maml:introduction></maml:section></maml:sections></maml:content></maml:conceptual><maml:conceptual contentType="conceptual" xmlns:maml="http://schemas.microsoft.com/maml/2004/10" xmlns:dev="http://schemas.microsoft.com/maml/dev/2004/10"><maml:title>Organize Event Presentation</maml:title><maml:introduction></maml:introduction><maml:content><maml:sections><maml:section><maml:title></maml:title><maml:introduction>
<maml:para>Once you have selected the set of events that you are interested in, Event Viewer lets you customize the way those events are presented. You can sort and group events and their properties in various ways, as described in the following topics:</maml:para>

<maml:list class="unordered">
<maml:listItem>
<maml:para><maml:navigationLink><maml:linkText>Filter Displayed Events</maml:linkText><maml:uri href="mshelp://windows/?id=7710dc96-8061-4cfe-aafb-c7fdf1c6f7b6"></maml:uri></maml:navigationLink></maml:para>
</maml:listItem>

<maml:listItem>
<maml:para><maml:navigationLink><maml:linkText>Group Events by a Given Property</maml:linkText><maml:uri href="mshelp://windows/?id=67e1dc18-b03a-4236-8cb7-0bb191c5a0b7"></maml:uri></maml:navigationLink></maml:para>
</maml:listItem>

<maml:listItem>
<maml:para><maml:navigationLink><maml:linkText>Sort Events by a Given Property</maml:linkText><maml:uri href="mshelp://windows/?id=df28b174-f31a-4f18-a090-3ccbb394847e"></maml:uri></maml:navigationLink></maml:para>
</maml:listItem>

<maml:listItem>
<maml:para><maml:navigationLink><maml:linkText>Show or Hide Event Properties</maml:linkText><maml:uri href="mshelp://windows/?id=3eff5d43-dc9b-4777-9362-b21010adbecb"></maml:uri></maml:navigationLink></maml:para>
</maml:listItem>

<maml:listItem>
<maml:para><maml:navigationLink><maml:linkText>Show or Hide Analytic and Debug Logs</maml:linkText><maml:uri href="mshelp://windows/?id=816eb4fa-7972-4f2a-9d72-c437c326e7be"></maml:uri></maml:navigationLink></maml:para>
</maml:listItem>

<maml:listItem>
<maml:para><maml:navigationLink><maml:linkText>Change Order of Event Properties</maml:linkText><maml:uri href="mshelp://windows/?id=769748f2-603c-44b1-95f0-bd13efdde2a3"></maml:uri></maml:navigationLink></maml:para>
</maml:listItem>
</maml:list>
</maml:introduction></maml:section></maml:sections></maml:content></maml:conceptual><maml:conceptual contentType="conceptual" xmlns:maml="http://schemas.microsoft.com/maml/2004/10" xmlns:dev="http://schemas.microsoft.com/maml/dev/2004/10"><maml:title>Configure Computers to Forward and Collect Events</maml:title><maml:introduction>
<maml:para></maml:para>
</maml:introduction><maml:content><maml:sections><maml:section><maml:title></maml:title><maml:introduction>
<maml:para>Before you can create a subscription to collect events on a computer, you must configure both the collecting computer (collector) and each computer from which events will be collected (source). Updated information about event subscriptions may be available online at <maml:navigationLink><maml:linkText>Event Subscriptions</maml:linkText><maml:uri href="http://go.microsoft.com/fwlink/?linkid=71431"></maml:uri></maml:navigationLink>.</maml:para>

<maml:procedure><maml:title>To configure computers in a domain to forward and collect events</maml:title><maml:step><maml:sections><maml:section><maml:title></maml:title>
<maml:para>Log on to all collector and source computers. It is a best practice to use a domain account with administrative privileges.</maml:para>
</maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title>
<maml:para>On each source computer, type the following at an elevated command prompt:</maml:para>

<dev:code>winrm quickconfig</dev:code>

<maml:alertSet class="note"><maml:title>Note </maml:title>
<maml:para>If you intend to specify an event delivery optimization of <maml:ui>Minimize Bandwidth </maml:ui>or <maml:ui>Minimize Latency</maml:ui>, then you must also run the above command on the collector computer.</maml:para>
</maml:alertSet>
</maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title>
<maml:para>On the collector computer, type the following at an elevated command prompt:</maml:para>

<dev:code>wecutil qc</dev:code>
</maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title>
<maml:para>Add the computer account of the collector computer to the local Administrators group on each of the source computers. </maml:para>

<maml:alertSet class="note"><maml:title>Note </maml:title>
<maml:para>By default, the <maml:ui>Local Users and Groups</maml:ui> MMC snap-in does not enable you to add computer accounts. In the <maml:ui>Select Users, Computers, or Groups</maml:ui> dialog box, click the <maml:ui>Object Types</maml:ui> button and select the <maml:ui>Computers</maml:ui> check box. You will then be able to add computer accounts.</maml:para>
</maml:alertSet>
</maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title>
<maml:para>The computers are now configured to forward and collect events. Follow the steps in <maml:navigationLink><maml:linkText>Create a New Subscription</maml:linkText><maml:uri href="mshelp://windows/?id=8fd4aad5-50bc-4389-bdae-e09ee464e46d"></maml:uri></maml:navigationLink> to specify the events you want to have forwarded to the collector.</maml:para>
</maml:section></maml:sections></maml:step></maml:procedure>
</maml:introduction>
<maml:sections>
<maml:section>
<maml:title>Additional Considerations</maml:title><maml:introduction>
<maml:list class="unordered">
<maml:listItem>
<maml:para>In a workgroup environment, you can follow the same basic procedure described above to configure computers to forward and collect events. However, there are some additional steps and considerations for workgroups:</maml:para>

<maml:list class="unordered">
<maml:listItem>
<maml:para>You can only use Normal mode (Pull) subscriptions.</maml:para>
</maml:listItem>

<maml:listItem>
<maml:para>You must add a Windows Firewall exception for Remote Event Log Management on each source computer.</maml:para>
</maml:listItem>

<maml:listItem>
<maml:para>You must add an account with administrator privileges to the Event Log Readers group on each source computer. You must specify this account in the <maml:navigationLink><maml:linkText>Configure Advanced Subscription Settings</maml:linkText><maml:uri href="mshelp://windows/?id=473cb9ba-4aee-4717-a517-120371159da8"></maml:uri></maml:navigationLink> dialog when creating a subscription on the collector computer.</maml:para>
</maml:listItem>

<maml:listItem>
<maml:para>Type <maml:codeInline>winrm set winrm/config/client @{TrustedHosts="&lt;sources&gt;"}</maml:codeInline> at a command prompt on the collector computer to allow all of the source computers to use NTLM authentication when communicating with WinRM on the collector computer. Run this command only once. Where <maml:codeInline>&lt;sources&gt;</maml:codeInline> appears in the command, substitute a list of the names of all of the participating source computers in the workgroup. Separate the names by commas. Alternatively, you can use wildcards to match the names of all the source computers. For example, if you want to configure a set of source computers, each with a name that begins with "msft", you could type this command <maml:codeInline>winrm set winrm/config/client @{TrustedHosts="msft*"} </maml:codeInline>on the collector computer. To learn more about this command, type <maml:codeInline>winrm help config.</maml:codeInline></maml:para>
</maml:listItem>
</maml:list>
</maml:listItem>

<maml:listItem>
<maml:para>If you configure a subscription to use the HTTPS protocol by using the <maml:ui>HTTPS</maml:ui> option in <maml:ui>Advanced Subscription Settings</maml:ui>, you must also set corresponding Windows Firewall exceptions for port 443. For a subscription that uses <maml:ui>Normal</maml:ui> (PULL mode) delivery optimization, you must set the exception only on the source computers. For a subscription that uses either <maml:ui>Minimize Bandwidth</maml:ui> or <maml:ui>Minimize Latency</maml:ui> (PUSH mode) delivery optimizations, you must set the exception on both the source and collector computers.</maml:para>
</maml:listItem>

<maml:listItem>
<maml:para>If you intend to specify a user account by using the <maml:ui>Specific User</maml:ui> option in <maml:ui>Advanced Subscription Settings</maml:ui> when creating the subscription, you must ensure that account is a member of the local Administrators group on each of the source computers in step 4 instead of adding the machine account of the collector computer. Alternatively, you can use the Windows Event Log command-line utility to grant an account access to individual logs. To learn more about this command-line utility, type wevtutil sl -? at a command prompt.</maml:para>
</maml:listItem>
</maml:list>
</maml:introduction></maml:section>
</maml:sections>
</maml:section></maml:sections></maml:content></maml:conceptual><maml:conceptual contentType="conceptual" xmlns:maml="http://schemas.microsoft.com/maml/2004/10" xmlns:dev="http://schemas.microsoft.com/maml/dev/2004/10"><maml:title>Run a Task in Response to a Given Event</maml:title><maml:introduction>
<maml:para></maml:para>
</maml:introduction><maml:content><maml:sections><maml:section><maml:title></maml:title><maml:introduction>
<maml:para>You can configure a task to run when an event meeting specified criteria is logged. </maml:para>

<maml:procedure><maml:title>To Run a Task in Response to a Given Event</maml:title><maml:step><maml:sections><maml:section><maml:title></maml:title>
<maml:para>Start Event Viewer.</maml:para>
</maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title>
<maml:para>In the console tree, navigate to the log that contains the event you want to associate with a task.</maml:para>
</maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title>
<maml:para>Right-click the event and select <maml:ui>Attach Task to This Event</maml:ui>.</maml:para>
</maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title>
<maml:para>Perform each step presented by the <maml:ui>Create Basic Task Wizard</maml:ui>.</maml:para>
</maml:section></maml:sections></maml:step></maml:procedure>
</maml:introduction>
<maml:sections>
<maml:section>
<maml:title>Additional Considerations</maml:title><maml:introduction>
<maml:list class="unordered">
<maml:listItem>
<maml:para>You cannot assign a task to an event in a saved log.</maml:para>
</maml:listItem>

<maml:listItem>
<maml:para>You cannot assign a task to an event in an analytic or debug log.</maml:para>
</maml:listItem>
</maml:list>
</maml:introduction></maml:section>
</maml:sections>
</maml:section><maml:section><maml:title>Additional resources</maml:title>
<maml:introduction><maml:para><maml:navigationLink><maml:linkText>Event Viewer How To...</maml:linkText><maml:uri href="mshelp://windows/?id=b7ed11ad-4b4f-43c0-88f6-43de77fc6762"></maml:uri></maml:navigationLink></maml:para></maml:introduction></maml:section></maml:sections></maml:content></maml:conceptual><maml:conceptual contentType="conceptual" xmlns:maml="http://schemas.microsoft.com/maml/2004/10" xmlns:dev="http://schemas.microsoft.com/maml/dev/2004/10"><maml:title>Troubleshooting Event Viewer</maml:title><maml:introduction>
<maml:para>This section lists a few common issues you may encounter when using Event Viewer. Updated troubleshooting information may be available online at <maml:navigationLink><maml:linkText>Troubleshooting Event Viewer</maml:linkText><maml:uri href="http://go.microsoft.com/fwlink/?LinkId=69698"></maml:uri></maml:navigationLink>.</maml:para>
</maml:introduction><maml:content><maml:sections><maml:section>
<maml:title>What problem are you having?</maml:title><maml:introduction>
<maml:list class="unordered">
<maml:listItem>
<maml:para><maml:navigationLink><maml:linkText>No events appear in an event log</maml:linkText><maml:uri href="mshelp://windows/?id=2564192f-b638-47c8-ad31-9dbdf6f198f9#NO_EVENTS"></maml:uri></maml:navigationLink></maml:para>
</maml:listItem>

<maml:listItem>
<maml:para><maml:navigationLink><maml:linkText>You cannot find any Analytic or Debug logs</maml:linkText><maml:uri href="mshelp://windows/?id=2564192f-b638-47c8-ad31-9dbdf6f198f9#DEBUG_ANALYTIC"></maml:uri></maml:navigationLink></maml:para>
</maml:listItem>

<maml:listItem>
<maml:para><maml:navigationLink><maml:linkText>Event Viewer cannot attach to a remote computer</maml:linkText><maml:uri href="mshelp://windows/?id=2564192f-b638-47c8-ad31-9dbdf6f198f9#NO_REMOTE"></maml:uri></maml:navigationLink></maml:para>
</maml:listItem>

<maml:listItem>
<maml:para><maml:navigationLink><maml:linkText>You cannot see the description associated with an event</maml:linkText><maml:uri href="mshelp://windows/?id=2564192f-b638-47c8-ad31-9dbdf6f198f9#NO_DESCRIPTION"></maml:uri></maml:navigationLink></maml:para>
</maml:listItem>

<maml:listItem>
<maml:para><maml:navigationLink><maml:linkText>You associated a task with an event, but the task did not run in response to the event</maml:linkText><maml:uri href="mshelp://windows/?id=2564192f-b638-47c8-ad31-9dbdf6f198f9#NO_TASK"></maml:uri></maml:navigationLink></maml:para>
</maml:listItem>

<maml:listItem>
<maml:para><maml:navigationLink><maml:linkText>An imported Custom View does not return events</maml:linkText><maml:uri href="mshelp://windows/?id=2564192f-b638-47c8-ad31-9dbdf6f198f9#BROKEN_VIEW"></maml:uri></maml:navigationLink></maml:para>
</maml:listItem>
</maml:list>

<maml:alertSet class="note"><maml:title>Note </maml:title>
<maml:para>If you encounter problems using any feature of Event Viewer, first ensure that the Windows Event Log service is running. If you are working with event subscriptions, ensure that the Windows Event Collector service is running.</maml:para>
</maml:alertSet>
</maml:introduction>
<maml:sections>
<maml:section><maml:title></maml:title><maml:introduction></maml:introduction>
<maml:sections>
<maml:section><maml:title></maml:title><maml:introduction></maml:introduction>
<maml:sections>
<maml:section address="NO_EVENTS">
<maml:title>No events appear in an event log.</maml:title><maml:introduction>
<maml:para>If there are no events in an event log, logging may be disabled on that log or the events may have been cleared by another user. To check whether a log is enabled, right-click the log, click <maml:ui>Properties</maml:ui>, and check the <maml:ui>Enable Logging</maml:ui> option. To check whether the log was cleared, search the System log for an event with an ID value of 104. This event is generated when a log is cleared.</maml:para>
</maml:introduction></maml:section>

<maml:section address="DEBUG_ANALYTIC">
<maml:title>You cannot find any Analytic or Debug logs.</maml:title><maml:introduction>
<maml:para>Analytic and Debug logs are hidden by default. To learn how to make them visible, see <maml:navigationLink><maml:linkText>Show or Hide Analytic and Debug Logs</maml:linkText><maml:uri href="mshelp://windows/?id=816eb4fa-7972-4f2a-9d72-c437c326e7be"></maml:uri></maml:navigationLink>.</maml:para>
</maml:introduction></maml:section>

<maml:section address="NO_REMOTE">
<maml:title>Event Viewer cannot attach to a remote computer.</maml:title><maml:introduction>
<maml:para>If Event Viewer cannot attach to a remote computer, ensure that the remote computer is available on the network. Next, ensure that the <maml:ui>Remote Event Log Management</maml:ui> firewall exception has been set on the remote computer. Finally, ensure that your user account has permission to access the remote computer.</maml:para>
</maml:introduction></maml:section>

<maml:section address="NO_DESCRIPTION">
<maml:title>You cannot see the description associated with an event.</maml:title><maml:introduction>
<maml:para>If you cannot see the description associated with an event, the source application might not be installed on the computer on which you are trying to view the event. You can save the event in a file and view it on a computer that has the application installed, or you can install the application on the local computer.</maml:para>
</maml:introduction></maml:section>

<maml:section address="NO_TASK">
<maml:title>You associated a task with an event, but the task did not run in response to the event.</maml:title><maml:introduction>
<maml:para>You must use Task Scheduler to debug problems with tasks that are associated with events. Open Task Scheduler and search for the task. You must verify both that the task exists and that it is configured to trigger on the correct event.</maml:para>
</maml:introduction></maml:section>

<maml:section address="BROKEN_VIEW">
<maml:title>An imported Custom View does not return events.</maml:title><maml:introduction>
<maml:para>The imported Custom View might include references to logs that are not available on the current computer. To check the logs that are referenced in the custom view, right-click the custom view and click <maml:ui>Properties</maml:ui>, then click <maml:ui>Edit Filter</maml:ui>, and check the <maml:ui>Event Log</maml:ui> drop-down list.</maml:para>
</maml:introduction></maml:section>
</maml:sections>
</maml:section>
</maml:sections>
</maml:section>
</maml:sections>
</maml:section></maml:sections></maml:content></maml:conceptual><maml:conceptual contentType="conceptual" xmlns:maml="http://schemas.microsoft.com/maml/2004/10" xmlns:dev="http://schemas.microsoft.com/maml/dev/2004/10"><maml:title>Online Event Information</maml:title><maml:introduction>
<maml:para>Logged events include a Uniform Resource Locator (URL) link to a Microsoft Web site or a Web site that you can define. When you view an event, you can click <maml:ui>Event Log Online Help</maml:ui>, which sends a request in the form of a query to obtain additional information about the event. The data that is sent is limited to only what is needed to retrieve more information about the event. For more information, please read our <maml:navigationLink><maml:linkText>privacy statement</maml:linkText><maml:uri href="http://go.microsoft.com/fwlink/?linkid=104288"></maml:uri></maml:navigationLink> online.</maml:para>

<maml:para>If you want to define the URL that is associated with the <maml:ui>Event Log Online Help</maml:ui> link to reference a Web site other than the Microsoft Web site, you can either <maml:navigationLink><maml:linkText>define the URL in the registry</maml:linkText><maml:uri href="mshelp://windows/?id=28cd5e13-e955-4941-91d9-fec2525e96c7#BKMK_URLregistry"></maml:uri></maml:navigationLink> or you can <maml:navigationLink><maml:linkText>define the URL in an instrumentation manifest</maml:linkText><maml:uri href="mshelp://windows/?id=28cd5e13-e955-4941-91d9-fec2525e96c7#BKMK_URLmanifest"></maml:uri></maml:navigationLink> for a publisher. If you define the URL in the registry, the link that you use will be the same for all events that are published on the computer where the registry is located. A URL that is defined in the registry will override all URLs defined in instrumentation manifests for publishers. </maml:para>

<maml:para>When you click <maml:ui>Event Log Online Help</maml:ui>, the following parameters are included with the URL and are passed to the Web site:</maml:para>

<maml:table>
<maml:tableHeader>
<maml:row>
<maml:entry>
<maml:para>Parameter</maml:para>
</maml:entry>
<maml:entry>
<maml:para>Description</maml:para>
</maml:entry></maml:row>
</maml:tableHeader>

<maml:row>
<maml:entry>
<maml:para><maml:phrase>Product Name</maml:phrase></maml:para>
</maml:entry>
<maml:entry>
<maml:para>The name of the product that is associated with the publisher of the event.</maml:para>
</maml:entry></maml:row>

<maml:row>
<maml:entry>
<maml:para><maml:phrase>Product Version</maml:phrase></maml:para>
</maml:entry>
<maml:entry>
<maml:para>The version of the product that is defined in the Product Name parameter.</maml:para>
</maml:entry></maml:row>

<maml:row>
<maml:entry>
<maml:para><maml:phrase>Event ID</maml:phrase></maml:para>
</maml:entry>
<maml:entry>
<maml:para>The identification number that was assigned to the event.</maml:para>
</maml:entry></maml:row>

<maml:row>
<maml:entry>
<maml:para><maml:phrase>Event Source</maml:phrase></maml:para>
</maml:entry>
<maml:entry>
<maml:para>The name of the log where the event was published.</maml:para>
</maml:entry></maml:row>

<maml:row>
<maml:entry>
<maml:para><maml:phrase>Locale ID</maml:phrase></maml:para>
</maml:entry>
<maml:entry>
<maml:para>The identification number for the locale of the computer where the event originated.</maml:para>
</maml:entry></maml:row>
</maml:table>
</maml:introduction><maml:content><maml:sections><maml:section><maml:title></maml:title><maml:introduction></maml:introduction>
<maml:sections>
<maml:section address="BKMK_URLregistry">
<maml:title>Define the URL in the Registry</maml:title><maml:introduction>
<maml:para>You can modify both the URL associated with the <maml:ui>Event Log Online Help</maml:ui> link and the program that is used to display the results returned from the Web site that is defined in the URL. The configuration settings are stored in the registry under the HKLM\Software\Microsoft\Windows NT\CurrentVersion\EventViewer\registry key.</maml:para>

<maml:para>The following list describes the registry entries that appear under that key and how they enable you to configure the behavior of the event log online help.</maml:para>

<maml:table>
<maml:tableHeader>
<maml:row>
<maml:entry>
<maml:para>Registry Entry</maml:para>
</maml:entry>
<maml:entry>
<maml:para>Description</maml:para>
</maml:entry></maml:row>
</maml:tableHeader>

<maml:row>
<maml:entry>
<maml:para><maml:phrase>MicrosoftRedirectionProgram</maml:phrase></maml:para>
</maml:entry>
<maml:entry>
<maml:para>Specifies the program that is used to display the information that is returned from the Web site that is associated with the <maml:ui>Event Log Online Help</maml:ui> link.</maml:para>
</maml:entry></maml:row>

<maml:row>
<maml:entry>
<maml:para><maml:phrase>MicrosoftRedirectionProgramCommandLineParameters</maml:phrase></maml:para>
</maml:entry>
<maml:entry>
<maml:para>Specifies the parameters that are passed to the program that is specified in the MicrosoftRedirectionProgram entry.</maml:para>
</maml:entry></maml:row>

<maml:row>
<maml:entry>
<maml:para><maml:phrase>MicrosoftRedirectionURL</maml:phrase></maml:para>
</maml:entry>
<maml:entry>
<maml:para>Specifies the URL that is associated to the Event Log Online Help link. The default value of the entry is: http://go.microsoft.com/fwlink/events.asp.</maml:para>
</maml:entry></maml:row>
</maml:table>
</maml:introduction></maml:section>

<maml:section address="BKMK_URLmanifest">
<maml:title>Define the URL in an Instrumentation Manifest</maml:title><maml:introduction>
<maml:para>You can define the URL for the <maml:ui>Event Log Online Help</maml:ui> link in an instrumentation manifest. To define a URL in an instrumentation manifest you must add the helpLink attribute to the provider element. The following example shows a helpLink attribute defined for a provider.</maml:para>

<dev:code>&lt;provider name="Microsoft-Windows-EventLogSamplePublisher"
guid="{1db28f2e-8f80-4027-8c5a-a11f7f10f62d}"
symbol="MICROSOFT_SAMPLE_PUBLISHER"
resourceFileName="C:\temp\Publisher.exe"
messageFileName="C:\temp\Publisher.exe"
helpLink="http://www.contoso.com"&gt;</dev:code>

<maml:para>For more information about instrumentation manifests, see <maml:navigationLink><maml:linkText>Instrumentation Manifests for Event Publishers</maml:linkText><maml:uri href="http://go.microsoft.com/fwlink/?LinkId=62588"></maml:uri></maml:navigationLink>.</maml:para>
</maml:introduction></maml:section>
</maml:sections>
</maml:section></maml:sections></maml:content></maml:conceptual><maml:conceptual contentType="conceptual" xmlns:maml="http://schemas.microsoft.com/maml/2004/10" xmlns:dev="http://schemas.microsoft.com/maml/dev/2004/10"><maml:title>Display XML Format of a Custom View</maml:title><maml:introduction>
<maml:para>Custom Views are named filters that you can reuse between sessions of Event Viewer. Like other event log filters, a custom view has an XML-based representation. After creating a custom view using the Event Viewer user interface, you can then display and examine the XML that represents the underlying query. This is a convenient way to learn about the XML syntax.</maml:para>

<maml:procedure><maml:title>To display the XML format underlying a custom view</maml:title><maml:step><maml:sections><maml:section><maml:title></maml:title>
<maml:para>Start Event Viewer.</maml:para>
</maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title>
<maml:para>In the console tree, navigate to and select the custom view.</maml:para>
</maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title>
<maml:para>On the <maml:ui>Action</maml:ui> menu, click <maml:ui>Properties</maml:ui>.</maml:para>
</maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title>
<maml:para>On the properties dialog, click <maml:ui>Edit Filter</maml:ui>.</maml:para>
</maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title>
<maml:para>In the <maml:ui>Custom View Properties</maml:ui> dialog box, click the <maml:ui>XML</maml:ui> tab. The XML query for the custom view appears in the text box.</maml:para>
</maml:section></maml:sections></maml:step></maml:procedure>
</maml:introduction><maml:content><maml:sections><maml:section><maml:title></maml:title><maml:introduction></maml:introduction>
<maml:sections>
<maml:section><maml:title></maml:title><maml:introduction></maml:introduction>
<maml:sections>
<maml:section>
<maml:title>Additional Resources</maml:title><maml:introduction>
<maml:para><maml:navigationLink><maml:linkText>Custom Views</maml:linkText><maml:uri href="mshelp://windows/?id=ff1ea5b3-0127-488d-af6e-0d9267cefdc4"></maml:uri></maml:navigationLink></maml:para>
</maml:introduction></maml:section>
</maml:sections>
</maml:section>
</maml:sections>
</maml:section></maml:sections></maml:content></maml:conceptual><maml:conceptual contentType="conceptual" xmlns:maml="http://schemas.microsoft.com/maml/2004/10" xmlns:dev="http://schemas.microsoft.com/maml/dev/2004/10"><maml:title>Event Properties</maml:title><maml:introduction>
<maml:para>The following table lists the common event properties. For more information about event properties and the underlying XML schema, see the <maml:navigationLink><maml:linkText>Event Representation for Event Consumers</maml:linkText><maml:uri href="http://go.microsoft.com/fwlink/?LinkId=69688"></maml:uri></maml:navigationLink> topic in the Windows Event Log Software Development Kit (SDK) online.</maml:para>

<maml:table>
<maml:tableHeader>
<maml:row>
<maml:entry>
<maml:para>Property Name</maml:para>
</maml:entry>
<maml:entry>
<maml:para>Description</maml:para>
</maml:entry></maml:row>
</maml:tableHeader>

<maml:row>
<maml:entry>
<maml:para>Source</maml:para>
</maml:entry>
<maml:entry>
<maml:para>The software that logged the event, which can be either a program name, such as "SQL Server", or a component of the system or of a large program, such as a driver name. For example, "Elnkii" indicates an EtherLink II driver.</maml:para>
</maml:entry></maml:row>

<maml:row>
<maml:entry>
<maml:para>Event ID</maml:para>
</maml:entry>
<maml:entry>
<maml:para>A number identifying the particular event type. The first line of the description usually contains the name of the event type. For example, 6005 is the ID of the event that occurs when the Event Log service is started. The first line of the description of such an event is "The Event log service was started." The Event ID and the Source can be used by product support representatives to troubleshoot system problems.</maml:para>
</maml:entry></maml:row>

<maml:row>
<maml:entry>
<maml:para>Level</maml:para>
</maml:entry>
<maml:entry>
<maml:para>A classification of the event severity. The following event severity levels can occur in the system and application logs: </maml:para>

<maml:list class="unordered">
<maml:listItem>
<maml:para><maml:phrase>Information.</maml:phrase> Indicates that a change in an application or component has occurred, such as an operation has successfully completed, a resource has been created, or a service started.</maml:para>
</maml:listItem>

<maml:listItem>
<maml:para><maml:phrase>Warning.</maml:phrase> Indicates that an issue has occurred that can impact service or result in a more serious problem if action is not taken.</maml:para>
</maml:listItem>

<maml:listItem>
<maml:para><maml:phrase>Error.</maml:phrase> Indicates that a problem has occurred, which might impact functionality that is external to the application or component that triggered the event. </maml:para>
</maml:listItem>

<maml:listItem>
<maml:para><maml:phrase>Critical.</maml:phrase> Indicates that a failure has occurred from which the application or component that triggered the event cannot automatically recover.</maml:para>
</maml:listItem>
</maml:list>

<maml:para>The following event severity levels can occur in the security log:</maml:para>

<maml:list class="unordered">
<maml:listItem>
<maml:para><maml:languageKeyword>Success Audit</maml:languageKeyword><maml:phrase>.</maml:phrase> Indicates that the exercise of a user right has succeeded.  </maml:para>
</maml:listItem>

<maml:listItem>
<maml:para><maml:phrase>Failure Audit.</maml:phrase> Indicates that the exercise of a user right has failed. </maml:para>
</maml:listItem>
</maml:list>

<maml:para>In the Event Viewer normal list view, these are represented by a symbol.</maml:para>
</maml:entry></maml:row>

<maml:row>
<maml:entry>
<maml:para>User</maml:para>
</maml:entry>
<maml:entry>
<maml:para>The name of the user on whose behalf the event occurred. This name is the client ID if the event was actually caused by a server process or the primary ID if impersonation is not taking place. Where applicable, a security log entry contains both the primary and impersonation IDs. Impersonation occurs when the server allows one process to take on the security attributes of another.</maml:para>
</maml:entry></maml:row>

<maml:row>
<maml:entry>
<maml:para>Operational Code</maml:para>
</maml:entry>
<maml:entry>
<maml:para>Contains a numeric value that identifies the activity or a point within an activity that the application was performing when it raised the event. For example, initialization or closing.</maml:para>
</maml:entry></maml:row>

<maml:row>
<maml:entry>
<maml:para>Log </maml:para>
</maml:entry>
<maml:entry>
<maml:para>The name of the log where the event was recorded.</maml:para>
</maml:entry></maml:row>

<maml:row>
<maml:entry>
<maml:para>Task Category</maml:para>
</maml:entry>
<maml:entry>
<maml:para>Used to represent a subcomponent or activity of the event publisher.</maml:para>
</maml:entry></maml:row>

<maml:row>
<maml:entry>
<maml:para>Keywords</maml:para>
</maml:entry>
<maml:entry>
<maml:para>A set of categories or tags that can be used to filter or search for events. Examples include "Network", "Security", or "Resource not found."</maml:para>
</maml:entry></maml:row>

<maml:row>
<maml:entry>
<maml:para>Computer</maml:para>
</maml:entry>
<maml:entry>
<maml:para>The name of the computer on which the event occurred. The computer name is typically the name of the local computer, but it might be the name of a computer that forwarded the event or it might be the name of the local computer before its name was changed.</maml:para>
</maml:entry></maml:row>

<maml:row>
<maml:entry>
<maml:para>Date and Time</maml:para>
</maml:entry>
<maml:entry>
<maml:para>The date and time that the event was logged.</maml:para>
</maml:entry></maml:row>
</maml:table>

<maml:para>The following table lists the properties that can be displayed by adding columns to the Event Viewer display. For more information about adding columns to the display, see <maml:navigationLink><maml:linkText>Show or Hide Event Properties</maml:linkText><maml:uri href="mshelp://windows/?id=3eff5d43-dc9b-4777-9362-b21010adbecb"></maml:uri></maml:navigationLink>.</maml:para>

<maml:table>
<maml:tableHeader>
<maml:row>
<maml:entry>
<maml:para>Property Name</maml:para>
</maml:entry>
<maml:entry>
<maml:para>Description</maml:para>
</maml:entry></maml:row>
</maml:tableHeader>

<maml:row>
<maml:entry>
<maml:para>Process ID</maml:para>
</maml:entry>
<maml:entry>
<maml:para>The identification number for the process that generated the event.</maml:para>
</maml:entry></maml:row>

<maml:row>
<maml:entry>
<maml:para>Thread ID</maml:para>
</maml:entry>
<maml:entry>
<maml:para>The identification number for the thread that generated the event.</maml:para>
</maml:entry></maml:row>

<maml:row>
<maml:entry>
<maml:para>Processor ID</maml:para>
</maml:entry>
<maml:entry>
<maml:para>The identification number for the processor that processed the event.</maml:para>
</maml:entry></maml:row>

<maml:row>
<maml:entry>
<maml:para>Session ID</maml:para>
</maml:entry>
<maml:entry>
<maml:para>The identification number for the terminal server session in which the event occurred.</maml:para>
</maml:entry></maml:row>

<maml:row>
<maml:entry>
<maml:para>Kernel Time</maml:para>
</maml:entry>
<maml:entry>
<maml:para>The elapsed execution time for kernel-mode instructions, in CPU time units. </maml:para>
</maml:entry></maml:row>

<maml:row>
<maml:entry>
<maml:para>User Time</maml:para>
</maml:entry>
<maml:entry>
<maml:para>The elapsed execution time for user-mode instructions, in CPU time units.</maml:para>
</maml:entry></maml:row>

<maml:row>
<maml:entry>
<maml:para>Processor Time</maml:para>
</maml:entry>
<maml:entry>
<maml:para>The elapsed execution time for user-mode instructions, in CPU ticks.</maml:para>
</maml:entry></maml:row>

<maml:row>
<maml:entry>
<maml:para>Correlation Id</maml:para>
</maml:entry>
<maml:entry>
<maml:para>Identifies the activity in the process for which the event is involved. This identifier is used to specify simple relationships between events.</maml:para>
</maml:entry></maml:row>

<maml:row>
<maml:entry>
<maml:para>Relative Correlation Id</maml:para>
</maml:entry>
<maml:entry>
<maml:para>Identifies a related activity in a process for which the event is involved.</maml:para>
</maml:entry></maml:row>
</maml:table>
</maml:introduction><maml:content><maml:sections></maml:sections></maml:content></maml:conceptual><maml:conceptual contentType="conceptual" xmlns:maml="http://schemas.microsoft.com/maml/2004/10" xmlns:dev="http://schemas.microsoft.com/maml/dev/2004/10"><maml:title>Show or Hide Event Properties</maml:title><maml:introduction>
<maml:para>You can customize how Event Viewer displays events by selecting only properties you are interested in viewing.</maml:para>
</maml:introduction><maml:content><maml:sections><maml:section><maml:title></maml:title><maml:introduction>
<maml:procedure><maml:title>To show or hide event properties</maml:title><maml:step><maml:sections><maml:section><maml:title></maml:title>
<maml:para>Start Event Viewer</maml:para>
</maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title>
<maml:para>In the console tree, select an event log, custom view, or saved log.</maml:para>
</maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title>
<maml:para>On the <maml:ui>View</maml:ui> menu, click <maml:ui>Add/Remove</maml:ui> columns.</maml:para>
</maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title>
<maml:para>In the <maml:ui>Add/Remove Columns</maml:ui> dialog box, select the event properties you want to show from the <maml:ui>Available columns</maml:ui> list box and click <maml:ui>Add</maml:ui>. Select the event properties you want to hide from the <maml:ui>Displayed columns</maml:ui> list box and click <maml:ui>Remove</maml:ui>.</maml:para>
</maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title>
<maml:para>Click <maml:ui>OK</maml:ui>.</maml:para>
</maml:section></maml:sections></maml:step></maml:procedure>
</maml:introduction>
<maml:sections>
<maml:section>
<maml:title>Additional Considerations</maml:title><maml:introduction>
<maml:list class="unordered">
<maml:listItem>
<maml:para>Property visibility is retained between sessions.</maml:para>
</maml:listItem>

<maml:listItem>
<maml:para>You cannot hide the Level event property.</maml:para>
</maml:listItem>
</maml:list>
</maml:introduction>
<maml:sections>
<maml:section>
<maml:title>Additional Resources</maml:title><maml:introduction>
<maml:list class="unordered">
<maml:listItem>
<maml:para><maml:navigationLink><maml:linkText>Event Properties</maml:linkText><maml:uri href="mshelp://windows/?id=386a877a-220a-4a7f-9238-7bacdee90279"></maml:uri></maml:navigationLink></maml:para>
</maml:listItem>

<maml:listItem>
<maml:para><maml:navigationLink><maml:linkText>Change Order of Event Properties</maml:linkText><maml:uri href="mshelp://windows/?id=769748f2-603c-44b1-95f0-bd13efdde2a3"></maml:uri></maml:navigationLink></maml:para>
</maml:listItem>
</maml:list>
</maml:introduction></maml:section>
</maml:sections>
</maml:section>
</maml:sections>
</maml:section></maml:sections></maml:content></maml:conceptual><maml:conceptual contentType="conceptual" xmlns:maml="http://schemas.microsoft.com/maml/2004/10" xmlns:dev="http://schemas.microsoft.com/maml/dev/2004/10"><maml:title>Event Viewer</maml:title><maml:introduction>
<maml:para>The Event Viewer is a Microsoft Management Console (MMC) snap-in that enables you to browse and manage event logs. It is an indispensable tool for monitoring the health of systems and troubleshooting issues when they arise. For the latest information about Event Viewer, see <maml:navigationLink><maml:linkText>Event Viewer</maml:linkText><maml:uri href="http://go.microsoft.com/fwlink/?linkid=45698"></maml:uri></maml:navigationLink> online.</maml:para>

<maml:para>Event Viewer enables you to perform the following tasks:</maml:para>

<maml:list class="unordered">
<maml:listItem>
<maml:para>View events from multiple event logs</maml:para>
</maml:listItem>

<maml:listItem>
<maml:para>Save useful event filters as custom views that can be reused</maml:para>
</maml:listItem>

<maml:listItem>
<maml:para>Schedule a task to run in response to an event</maml:para>
</maml:listItem>

<maml:listItem>
<maml:para>Create and manage event subscriptions</maml:para>
</maml:listItem>
</maml:list>
</maml:introduction><maml:content><maml:sections><maml:section>
<maml:title>Viewing Events from Multiple Logs</maml:title><maml:introduction>
<maml:para>When you use Event Viewer to troubleshoot a problem, you need to locate events related to the problem, regardless of which event log they appear in. Event Viewer enables you to filter for specific events across multiple logs. That makes it easy to display all events potentially related to an issue that you are investigating. To specify a filter that spans multiple logs, you need to create a custom view.</maml:para>

<maml:para>For detailed help with creating custom views, see the following topic:</maml:para>

<maml:list class="unordered">
<maml:listItem>
<maml:para><maml:navigationLink><maml:linkText>Create a Custom View</maml:linkText><maml:uri href="mshelp://windows/?id=0234cfde-93d4-46c3-a0dd-f26c6273aa26"></maml:uri></maml:navigationLink></maml:para>
</maml:listItem>
</maml:list>
</maml:introduction></maml:section><maml:section>
<maml:title>Reusable Custom Views</maml:title><maml:introduction>
<maml:para>When you work with Event Logs, your primary challenge is to narrow the set of events to just those that you are interested in. Sometimes this is easy. Other times this involves a great deal of effort; effort that is lost if you do not have some way to save the view of the logs that you worked so hard to create. Event Viewer supports the idea of custom views. Once you have queried and sorted your way to just the events you wanted to analyze, you can save that work as a named view and it will be available for you to reuse in the future. You can even export the view and use it on other computers or share it with other people. </maml:para>

<maml:para>For detailed help with view-related tasks, see the following topics:</maml:para>

<maml:list class="unordered">
<maml:listItem>
<maml:para><maml:navigationLink><maml:linkText>Custom Views</maml:linkText><maml:uri href="mshelp://windows/?id=ff1ea5b3-0127-488d-af6e-0d9267cefdc4"></maml:uri></maml:navigationLink></maml:para>
</maml:listItem>

<maml:listItem>
<maml:para><maml:navigationLink><maml:linkText>Create a Custom View</maml:linkText><maml:uri href="mshelp://windows/?id=0234cfde-93d4-46c3-a0dd-f26c6273aa26"></maml:uri></maml:navigationLink></maml:para>
</maml:listItem>

<maml:listItem>
<maml:para><maml:navigationLink><maml:linkText>Export a Custom View</maml:linkText><maml:uri href="mshelp://windows/?id=79610900-b937-4686-aee3-3d72875d4d66"></maml:uri></maml:navigationLink></maml:para>
</maml:listItem>

<maml:listItem>
<maml:para><maml:navigationLink><maml:linkText>Import a Custom View</maml:linkText><maml:uri href="mshelp://windows/?id=0b81db9c-f482-4aa5-865a-d467517d9753"></maml:uri></maml:navigationLink></maml:para>
</maml:listItem>
</maml:list>
</maml:introduction></maml:section><maml:section>
<maml:title>Integration with Task Scheduler</maml:title><maml:introduction>
<maml:para>Using Event Viewer, you can easily automate responses to events. Event Viewer is integrated with Task Scheduler, enabling you to right-click most events to start scheduling a task to run when that event is logged in the future.</maml:para>

<maml:para>For detailed help with associating tasks with events see:</maml:para>

<maml:list class="unordered">
<maml:listItem>
<maml:para><maml:navigationLink><maml:linkText>Run a Task in Response to a Given Event</maml:linkText><maml:uri href="mshelp://windows/?id=1833ed94-ec57-4783-aed9-4ce3a7bb2fea"></maml:uri></maml:navigationLink></maml:para>
</maml:listItem>
</maml:list>
</maml:introduction></maml:section><maml:section>
<maml:title>Event Subscriptions</maml:title><maml:introduction>
<maml:para>You can collect events from remote computers and store them locally by specifying event subscriptions.</maml:para>

<maml:para>For detailed help with event subscriptions, see the following topic:</maml:para>

<maml:list class="unordered">
<maml:listItem>
<maml:para><maml:navigationLink><maml:linkText>Event Subscriptions</maml:linkText><maml:uri href="mshelp://windows/?id=4aa6403f-d4b8-43a4-a70d-ceb7f88c524e"></maml:uri></maml:navigationLink></maml:para>
</maml:listItem>
</maml:list>
</maml:introduction>
<maml:sections>
<maml:section><maml:title></maml:title><maml:introduction></maml:introduction>
<maml:sections>
<maml:section>
<maml:title>Additional Resources</maml:title><maml:introduction>
<maml:list class="unordered">
<maml:listItem>
<maml:para><maml:navigationLink><maml:linkText>Event Logs</maml:linkText><maml:uri href="mshelp://windows/?id=e1459340-eaed-40c7-93a0-36bd933bdd7e"></maml:uri></maml:navigationLink></maml:para>
</maml:listItem>

<maml:listItem>
<maml:para><maml:navigationLink><maml:linkText>Event Properties</maml:linkText><maml:uri href="mshelp://windows/?id=386a877a-220a-4a7f-9238-7bacdee90279"></maml:uri></maml:navigationLink></maml:para>
</maml:listItem>

<maml:listItem>
<maml:para><maml:navigationLink><maml:linkText>Online Event Information</maml:linkText><maml:uri href="mshelp://windows/?id=28cd5e13-e955-4941-91d9-fec2525e96c7"></maml:uri></maml:navigationLink></maml:para>
</maml:listItem>

<maml:listItem>
<maml:para><maml:navigationLink><maml:linkText>Event Viewer How To...</maml:linkText><maml:uri href="mshelp://windows/?id=b7ed11ad-4b4f-43c0-88f6-43de77fc6762"></maml:uri></maml:navigationLink></maml:para>
</maml:listItem>
<maml:listItem><maml:para><maml:navigationLink><maml:linkText>Troubleshooting Event Viewer</maml:linkText><maml:uri href="mshelp://windows/?id=2564192f-b638-47c8-ad31-9dbdf6f198f9"></maml:uri></maml:navigationLink></maml:para></maml:listItem></maml:list>
</maml:introduction></maml:section>
</maml:sections>
</maml:section>
</maml:sections>
</maml:section></maml:sections></maml:content></maml:conceptual><maml:conceptual contentType="conceptual" xmlns:maml="http://schemas.microsoft.com/maml/2004/10" xmlns:dev="http://schemas.microsoft.com/maml/dev/2004/10"><maml:title>Manage Subscriptions</maml:title><maml:introduction>
<maml:para>You can collect events from remote computers and store them in logs on the local computer. You specify the specific events to collect by creating a subscription. The following topics describe how to work with event subscriptions.</maml:para>

<maml:list class="unordered">
<maml:listItem>
<maml:para><maml:navigationLink><maml:linkText>Configure Computers to Forward and Collect Events</maml:linkText><maml:uri href="mshelp://windows/?id=165d8b7c-a85e-42c2-8316-6701f0701c88"></maml:uri></maml:navigationLink></maml:para>
</maml:listItem>

<maml:listItem>
<maml:para><maml:navigationLink><maml:linkText>Create a New Subscription</maml:linkText><maml:uri href="mshelp://windows/?id=8fd4aad5-50bc-4389-bdae-e09ee464e46d"></maml:uri></maml:navigationLink></maml:para>
</maml:listItem>

<maml:listItem>
<maml:para><maml:navigationLink><maml:linkText>Configure Advanced Subscription Settings</maml:linkText><maml:uri href="mshelp://windows/?id=473cb9ba-4aee-4717-a517-120371159da8"></maml:uri></maml:navigationLink></maml:para>
</maml:listItem>
</maml:list>
</maml:introduction><maml:content><maml:sections></maml:sections></maml:content></maml:conceptual><maml:conceptual contentType="conceptual" xmlns:maml="http://schemas.microsoft.com/maml/2004/10" xmlns:dev="http://schemas.microsoft.com/maml/dev/2004/10"><maml:title>Configure Advanced Subscription Settings</maml:title><maml:introduction>
<maml:para>You can configure how collected events are delivered and specify the account used to manage the process of collecting events. Event Viewer provides three event delivery optimization options: <maml:ui>Normal</maml:ui>, <maml:ui>Minimize Bandwidth</maml:ui> and <maml:ui>Minimize Latency</maml:ui>. The following table lists each option along with a description of when it is an appropriate choice.</maml:para>

<maml:table>
<maml:tableHeader>
<maml:row>
<maml:entry>
<maml:para>Event Delivery Optimization Options</maml:para>
</maml:entry>
<maml:entry>
<maml:para>Description</maml:para>
</maml:entry></maml:row>
</maml:tableHeader>

<maml:row>
<maml:entry>
<maml:para>Normal</maml:para>
</maml:entry>
<maml:entry>
<maml:para>This option ensures reliable delivery of events and does not attempt to conserve bandwidth. It is the appropriate choice unless you need tighter control over bandwidth usage or need forwarded events delivered as quickly as possible. It uses pull delivery mode, batches 5 items at a time and sets a batch timeout of 15 minutes.</maml:para>
</maml:entry></maml:row>

<maml:row>
<maml:entry>
<maml:para>Minimize Bandwidth</maml:para>
</maml:entry>
<maml:entry>
<maml:para>This option ensures that the use of network bandwidth for event delivery is strictly controlled. It is an appropriate choice if you want to limit the frequency of network connections made to deliver events. It uses push delivery mode and sets a batch timeout of 6 hours. In addition, it uses a heartbeat interval of 6 hours.</maml:para>
</maml:entry></maml:row>

<maml:row>
<maml:entry>
<maml:para>Minimize Latency</maml:para>
</maml:entry>
<maml:entry>
<maml:para>This option ensures that events are delivered with minimal delay. It is an appropriate choice if you are collecting alerts or critical events. It uses push delivery mode and sets a batch timeout of 30 seconds.</maml:para>
</maml:entry></maml:row>
</maml:table>

<maml:para>The <maml:ui>Custom</maml:ui> event delivery option is never used when managing subscriptions created by using the Event Viewer snap-in. The Event Viewer can only create subscriptions with event delivery settings that correspond to the <maml:ui>Normal</maml:ui>, <maml:ui>Minimize Bandwidth </maml:ui>or <maml:ui>Minimize Latency</maml:ui> options. However, you can use Event Viewer to manage a subscription that was created or updated by using a different method, like the wecutil command-line tool. In that case, the <maml:ui>Custom</maml:ui> option is selected to indicate that the set of delivery settings of the subscription do not correspond to any of those supported by Event Viewer.</maml:para>

<maml:procedure><maml:title>To configure advanced subscription settings</maml:title><maml:step><maml:sections><maml:section><maml:title></maml:title>
<maml:para>Perform steps 1—6 of the <maml:navigationLink><maml:linkText>Create a New Subscription</maml:linkText><maml:uri href="mshelp://windows/?id=8fd4aad5-50bc-4389-bdae-e09ee464e46d"></maml:uri></maml:navigationLink> procedure.</maml:para>
</maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title>
<maml:para>Click <maml:ui>Advanced</maml:ui>.</maml:para>
</maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title>
<maml:para>On the <maml:ui>Advanced Subscription Settings</maml:ui> dialog box, you can either specify an event delivery optimization or specify the account used to manage the process of collecting events.</maml:para>

<maml:list class="unordered">
<maml:listItem>
<maml:para>To specify an event delivery optimization: Select the <maml:ui>Event Delivery Optimization</maml:ui> option you want and click <maml:ui>OK</maml:ui>.</maml:para>
</maml:listItem>

<maml:listItem>
<maml:para>To specify the account used to manage the process of collecting events, select the <maml:ui>Specific User</maml:ui> option, then click <maml:ui>User and Password</maml:ui> and enter the user name and password of the account and click <maml:ui>OK</maml:ui>. Click <maml:ui>OK</maml:ui> on the <maml:ui>Advanced Subscription Settings</maml:ui> dialog box.</maml:para>
</maml:listItem>
</maml:list>
</maml:section></maml:sections></maml:step></maml:procedure>
</maml:introduction><maml:content><maml:sections><maml:section><maml:title></maml:title><maml:introduction></maml:introduction>
<maml:sections>
<maml:section><maml:title></maml:title><maml:introduction></maml:introduction>
<maml:sections>
<maml:section>
<maml:title>Additional Considerations</maml:title><maml:introduction>
<maml:para>The <maml:ui>Minimize Bandwidth </maml:ui>and <maml:ui>Minimize Latency</maml:ui> options both batch a default number of items at a time. You can determine the value of this default by typing the following command at a command prompt: </maml:para>

<maml:para><maml:computerOutputInline>winrm get winrm/config</maml:computerOutputInline>.</maml:para>

<maml:para>You can change the default number of items in a batch by typing the following command at a command prompt:</maml:para>

<maml:para><maml:computerOutputInline>winrm set winrm/config @{MaxBatchItems=&lt;NumberOfItems&gt;}</maml:computerOutputInline></maml:para>

<maml:para>The following example shows how to change the default number of batched items to five:</maml:para>

<maml:para><maml:computerOutputInline>winrm set winrm/config @{MaxBatchItems="5"}  </maml:computerOutputInline></maml:para>

<maml:para></maml:para>
</maml:introduction></maml:section>

<maml:section>
<maml:title>Additional Resources</maml:title><maml:introduction>
<maml:list class="unordered">
<maml:listItem>
<maml:para><maml:navigationLink><maml:linkText>Event Subscriptions</maml:linkText><maml:uri href="mshelp://windows/?id=4aa6403f-d4b8-43a4-a70d-ceb7f88c524e"></maml:uri></maml:navigationLink></maml:para>
</maml:listItem>

<maml:listItem>
<maml:para><maml:navigationLink><maml:linkText>Configure Computers to Forward and Collect Events</maml:linkText><maml:uri href="mshelp://windows/?id=165d8b7c-a85e-42c2-8316-6701f0701c88"></maml:uri></maml:navigationLink></maml:para>
</maml:listItem>

<maml:listItem>
<maml:para><maml:navigationLink><maml:linkText>Create a New Subscription</maml:linkText><maml:uri href="mshelp://windows/?id=8fd4aad5-50bc-4389-bdae-e09ee464e46d"></maml:uri></maml:navigationLink></maml:para>
</maml:listItem>
</maml:list>
</maml:introduction></maml:section>
</maml:sections>
</maml:section>
</maml:sections>
</maml:section></maml:sections></maml:content></maml:conceptual><maml:conceptual contentType="conceptual" xmlns:maml="http://schemas.microsoft.com/maml/2004/10" xmlns:dev="http://schemas.microsoft.com/maml/dev/2004/10"><maml:title>Event Subscriptions</maml:title><maml:introduction></maml:introduction><maml:content><maml:sections><maml:section><maml:title></maml:title><maml:introduction>
<maml:para>Event Viewer enables you to view events on a single remote computer. However, troubleshooting an issue might require you to examine a set of events stored in multiple logs on multiple computers. </maml:para>

<maml:para>Windows Vista includes the ability to collect copies of events from multiple remote computers and store them locally. To specify which events to collect, you create an event subscription. Among other details, the subscription specifies exactly which events will be collected and in which log they will be stored locally. Once a subscription is active and events are being collected, you can view and manipulate these forwarded events as you would any other locally stored events.</maml:para>

<maml:para>Using the event collecting feature requires that you configure both the forwarding and the collecting computers. The functionality depends on the Windows Remote Management (WinRM) service and the Windows Event Collector (Wecsvc) service. Both of these services must be running on computers participating in the forwarding and collecting process. To learn about the steps required to configure event collecting and forwarding computers, see <maml:navigationLink><maml:linkText>Configure Computers to Forward and Collect Events</maml:linkText><maml:uri href="mshelp://windows/?id=165d8b7c-a85e-42c2-8316-6701f0701c88"></maml:uri></maml:navigationLink>.</maml:para>
</maml:introduction>
<maml:sections>
<maml:section>
<maml:title>Additional Considerations</maml:title><maml:introduction>
<maml:list class="unordered">
<maml:listItem>
<maml:para>You can subscribe to receive events from an existing subscription on a remote computer.</maml:para>
</maml:listItem>
</maml:list>
</maml:introduction>
<maml:sections>
<maml:section>
<maml:title>Additional Resources</maml:title><maml:introduction>
<maml:list class="unordered">
<maml:listItem>
<maml:para> <maml:navigationLink><maml:linkText>Configure Computers to Forward and Collect Events</maml:linkText><maml:uri href="mshelp://windows/?id=165d8b7c-a85e-42c2-8316-6701f0701c88"></maml:uri></maml:navigationLink></maml:para>
</maml:listItem>

<maml:listItem>
<maml:para><maml:navigationLink><maml:linkText>Create a New Subscription</maml:linkText><maml:uri href="mshelp://windows/?id=8fd4aad5-50bc-4389-bdae-e09ee464e46d"></maml:uri></maml:navigationLink></maml:para>
</maml:listItem>
</maml:list>
</maml:introduction></maml:section>
</maml:sections>
</maml:section>
</maml:sections>
</maml:section></maml:sections></maml:content></maml:conceptual><maml:conceptual contentType="conceptual" xmlns:maml="http://schemas.microsoft.com/maml/2004/10" xmlns:dev="http://schemas.microsoft.com/maml/dev/2004/10"><maml:title>Manage Event Logs</maml:title><maml:introduction>
<maml:para></maml:para>
</maml:introduction><maml:content><maml:sections><maml:section><maml:title></maml:title><maml:introduction>
<maml:para>You can use Event Viewer to manage various aspects of your event logs. To do so, you typically: navigate to and select the event log to manage, right-click and select <maml:ui>Properties</maml:ui> to access its properties dialog, and then update the appropriate values. </maml:para>

<maml:para>You can perform the following log management tasks by using Event Viewer:</maml:para>

<maml:list class="unordered">
<maml:listItem>
<maml:para><maml:navigationLink><maml:linkText>Clear an Event Log</maml:linkText><maml:uri href="mshelp://windows/?id=ad46b98b-dd6b-4578-9dae-dfac1310ab7a"></maml:uri></maml:navigationLink></maml:para>
</maml:listItem>

<maml:listItem>
<maml:para><maml:navigationLink><maml:linkText>Set Maximum Log Size</maml:linkText><maml:uri href="mshelp://windows/?id=07abe800-89a9-43c5-a7bd-84304a881e7f"></maml:uri></maml:navigationLink></maml:para>
</maml:listItem>

<maml:listItem>
<maml:para><maml:navigationLink><maml:linkText>Set Log Retention Policy</maml:linkText><maml:uri href="mshelp://windows/?id=7511c36a-cf41-41f5-b8cb-f4c233ca2bb3"></maml:uri></maml:navigationLink></maml:para>
</maml:listItem>

<maml:listItem>
<maml:para><maml:navigationLink><maml:linkText>Enable Analytic and Debug Logs</maml:linkText><maml:uri href="mshelp://windows/?id=edec63a3-fa81-4677-99ae-b6cdada48d6d"></maml:uri></maml:navigationLink></maml:para>
</maml:listItem>

<maml:listItem>
<maml:para><maml:navigationLink><maml:linkText>Archive an Event Log</maml:linkText><maml:uri href="mshelp://windows/?id=7ee045ef-1e94-414b-9099-193b5b6bc439"></maml:uri></maml:navigationLink></maml:para>
</maml:listItem>


<maml:listItem><maml:para><maml:navigationLink><maml:linkText>Open or Close a Saved Log</maml:linkText><maml:uri href="mshelp://windows/?id=05fb8bc9-aca3-4bf6-83c3-1834297ccf49"></maml:uri></maml:navigationLink></maml:para></maml:listItem>
</maml:list>

<maml:para>You can also use the wevtutil.exe command line tool to manage your event logs. Where applicable, the preceding topics include information about how to accomplish the task from the command line. To learn more about the wevtutil.exe command-line tool, type <maml:computerOutputInline>wevtutil /?</maml:computerOutputInline> at a command prompt.</maml:para>
</maml:introduction></maml:section></maml:sections></maml:content></maml:conceptual><maml:conceptual contentType="conceptual" xmlns:maml="http://schemas.microsoft.com/maml/2004/10" xmlns:dev="http://schemas.microsoft.com/maml/dev/2004/10"><maml:title>Group Events by a Given Property</maml:title><maml:introduction>
<maml:para>You can conveniently view all events that share the same value for a given event property. For example, you can view all the events that originated from the same source or all the Warning level events. </maml:para>

<maml:para>You can sort events by property, but the resulting groupings might be large and difficult to navigate. If you run into that limit with sorting, you can instead use the grouping feature of Event Viewer. When you group events, a descriptive heading appears in the list control above each group. Although all members of all groups are visible by default, you can collapse and expand each distinct group by double-clicking the corresponding group heading.</maml:para>
</maml:introduction><maml:content><maml:sections><maml:section><maml:title></maml:title><maml:introduction>
<maml:procedure><maml:title>To group events according to a given property</maml:title><maml:step><maml:sections><maml:section><maml:title></maml:title>
<maml:para>Start Event Viewer.</maml:para>
</maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title>
<maml:para>In the console tree, navigate to and select an event log, custom view, or saved log.</maml:para>
</maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title>
<maml:para>In the header in the event list, right-click the column header that represents the property you want to group by and click <maml:ui>Group events by this column</maml:ui>.</maml:para>
</maml:section></maml:sections></maml:step></maml:procedure>
</maml:introduction>
<maml:sections>
<maml:section>
<maml:title>Additional Considerations</maml:title><maml:introduction>
<maml:list class="unordered">
<maml:listItem>
<maml:para>To remove a grouping, right-click anywhere on the header of any column and click <maml:ui>Remove grouping of events</maml:ui>.</maml:para>
</maml:listItem>

<maml:listItem>
<maml:para>Event Viewer supports only one level of grouping. However, after grouping a set of events, you can then sort the resulting groups by column.</maml:para>
</maml:listItem>

<maml:listItem>
<maml:para>Grouping functionality works regardless of the source of the event records. As long as you are able to load a set of events, you can group them.</maml:para>
</maml:listItem>
</maml:list>
</maml:introduction>
<maml:sections>
<maml:section>
<maml:title>Additional Resources</maml:title><maml:introduction>
<maml:list class="unordered">
<maml:listItem>
<maml:para><maml:navigationLink><maml:linkText>Sort Events by a Given Property</maml:linkText><maml:uri href="mshelp://windows/?id=df28b174-f31a-4f18-a090-3ccbb394847e"></maml:uri></maml:navigationLink></maml:para>
</maml:listItem>
</maml:list>
</maml:introduction></maml:section>
</maml:sections>
</maml:section>
</maml:sections>
</maml:section></maml:sections></maml:content></maml:conceptual><maml:conceptual contentType="conceptual" xmlns:maml="http://schemas.microsoft.com/maml/2004/10" xmlns:dev="http://schemas.microsoft.com/maml/dev/2004/10"><maml:title>Set Log Retention Policy</maml:title><maml:introduction>
<maml:para>Events are stored in a log file that can grow only to a configurable maximum size. After the file has reached its maximum size, what happens to incoming events is determined by the log retention policy. The available log retention policies are as follows:</maml:para>
</maml:introduction><maml:content><maml:sections><maml:section><maml:title></maml:title><maml:introduction>
<maml:table>
<maml:tableHeader>
<maml:row>
<maml:entry>
<maml:para>Retention Policy</maml:para>
</maml:entry>
<maml:entry>
<maml:para>Description</maml:para>
</maml:entry></maml:row>
</maml:tableHeader>

<maml:row>
<maml:entry>
<maml:para>Overwrite events as needed.</maml:para>
</maml:entry>
<maml:entry>
<maml:para>New events continue to be stored when the log file is full. Each new incoming event replaces the oldest event in the log. </maml:para>
</maml:entry></maml:row>

<maml:row>
<maml:entry>
<maml:para>Archive the log when full, do not overwrite events.</maml:para>
</maml:entry>
<maml:entry>
<maml:para>The log is automatically archived when necessary. No events are overwritten. </maml:para>
</maml:entry></maml:row>

<maml:row>
<maml:entry>
<maml:para>Do not overwrite events. (Clear logs manually.)</maml:para>
</maml:entry>
<maml:entry>
<maml:para>Clear the log manually rather than automatically. </maml:para>
</maml:entry></maml:row>
</maml:table>

<maml:para>You can set the log retention policy by using the Windows interface or the Wevtutil command-line tool.</maml:para>

<maml:procedure><maml:title>To set the log retention policy by using the Windows interface</maml:title><maml:step><maml:sections><maml:section><maml:title></maml:title>
<maml:para>Start Event Viewer.</maml:para>
</maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title>
<maml:para>In the console tree, navigate to and select the event log you want to manage.</maml:para>
</maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title>
<maml:para>On the <maml:ui>Action</maml:ui> menu, click <maml:ui>Properties</maml:ui>.</maml:para>
</maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title>
<maml:para>In the <maml:ui>Enable Logging</maml:ui> section of the <maml:ui>General</maml:ui> tab, select the option that corresponds to the retention policy you want to set.</maml:para>
</maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title>
<maml:para>Click <maml:ui>OK</maml:ui>.</maml:para>
</maml:section></maml:sections></maml:step></maml:procedure>

<maml:procedure><maml:title>To set the retention policy by using a command line</maml:title><maml:step><maml:sections><maml:section><maml:title></maml:title>
<maml:para>To open a command prompt, click <maml:ui>Start</maml:ui>, click <maml:ui>Run</maml:ui>, type <maml:userInput>cmd</maml:userInput>, and click <maml:ui>OK</maml:ui>.</maml:para>
</maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title>
<maml:para>Type the following command:</maml:para>

<dev:code>wevtutil sl &lt;LogName&gt; /r:{true | false} /ab:{true | false}</dev:code>
</maml:section></maml:sections></maml:step></maml:procedure>

<maml:para>The 'r' parameter specifies whether to retain the log and the 'ab' parameter specifies whether to automatically back up the log. The following list shows the parameter values of the Wevtutil command-line tool that correspond to each of the above retention policies.</maml:para>

<maml:list class="unordered">
<maml:listItem>
<maml:para>Overwrite events as needed: r = false, ab = false</maml:para>
</maml:listItem>

<maml:listItem>
<maml:para>Archive the log when full, do not overwrite events: r = true, ab = true</maml:para>
</maml:listItem>

<maml:listItem>
<maml:para>Do not overwrite events. (Clear logs manually.): r = true, ab = false</maml:para>
</maml:listItem>
</maml:list>

<maml:para>To view the complete syntax for this command, type the following command:</maml:para>

<dev:code>wevtutil sl -?</dev:code>
</maml:introduction>
<maml:sections>
<maml:section>
<maml:title>Additional considerations</maml:title><maml:introduction>
<maml:list class="unordered">
<maml:listItem>
<maml:para>You must be a member of the Administrators group to set the log retention policy. </maml:para>
</maml:listItem>
</maml:list>
</maml:introduction>
<maml:sections>
<maml:section>
<maml:title>Additional references</maml:title><maml:introduction>
<maml:list class="unordered">
<maml:listItem>
<maml:para><maml:navigationLink><maml:linkText>Command-line syntax notation</maml:linkText><maml:uri href="mshelp://windows/?id=7ed13aea-4580-4ecd-93ef-9b09b504b87a"></maml:uri></maml:navigationLink></maml:para>
</maml:listItem>
</maml:list>
</maml:introduction></maml:section>
</maml:sections>
</maml:section>
</maml:sections>
</maml:section></maml:sections></maml:content></maml:conceptual><maml:conceptual contentType="conceptual" xmlns:maml="http://schemas.microsoft.com/maml/2004/10" xmlns:dev="http://schemas.microsoft.com/maml/dev/2004/10"><maml:title>Change Order of Event Properties</maml:title><maml:introduction>
<maml:para>You can customize how Event Viewer displays events by configuring the order in which properties appear in the details pane.</maml:para>
</maml:introduction><maml:content><maml:sections><maml:section><maml:title></maml:title><maml:introduction>
<maml:procedure><maml:title>To change the order of event properties</maml:title><maml:step><maml:sections><maml:section><maml:title></maml:title>
<maml:para>Start Event Viewer.</maml:para>
</maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title>
<maml:para>In the console tree, navigate to and select an event log, custom view, or saved log.</maml:para>
</maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title>
<maml:para>On the <maml:ui>View</maml:ui> menu, click <maml:ui>Add/Remove Columns</maml:ui>.</maml:para>
</maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title>
<maml:para>On the <maml:ui>Add/Remove Columns</maml:ui> dialog box, in <maml:ui>Displayed columns</maml:ui>, click the event property you want to reorder.</maml:para>
</maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title>
<maml:para>Use the <maml:ui>Move Up</maml:ui> and <maml:ui>Move Down </maml:ui>buttons to position the property. </maml:para>
</maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title>
<maml:para>Click <maml:ui>OK</maml:ui>.</maml:para>
</maml:section></maml:sections></maml:step></maml:procedure>
</maml:introduction>
<maml:sections>
<maml:section>
<maml:title>Additional Considerations</maml:title><maml:introduction>
<maml:list class="unordered">
<maml:listItem>
<maml:para>Properties at the top of the <maml:ui>Displayed columns</maml:ui> list will appear on the left side of the details pane.</maml:para>
</maml:listItem>

<maml:listItem>
<maml:para>Property order is retained between sessions.</maml:para>
</maml:listItem>
</maml:list>
</maml:introduction>
<maml:sections>
<maml:section>
<maml:title>Additional Resources</maml:title><maml:introduction>
<maml:list class="unordered">
<maml:listItem>
<maml:para><maml:navigationLink><maml:linkText>Event Properties</maml:linkText><maml:uri href="mshelp://windows/?id=386a877a-220a-4a7f-9238-7bacdee90279"></maml:uri></maml:navigationLink></maml:para>
</maml:listItem>

<maml:listItem>
<maml:para><maml:navigationLink><maml:linkText>Show or Hide Event Properties</maml:linkText><maml:uri href="mshelp://windows/?id=3eff5d43-dc9b-4777-9362-b21010adbecb"></maml:uri></maml:navigationLink></maml:para>
</maml:listItem>
</maml:list>
</maml:introduction></maml:section>
</maml:sections>
</maml:section>
</maml:sections>
</maml:section></maml:sections></maml:content></maml:conceptual><maml:conceptual contentType="conceptual" xmlns:maml="http://schemas.microsoft.com/maml/2004/10" xmlns:dev="http://schemas.microsoft.com/maml/dev/2004/10"><maml:title>Filter Displayed Events</maml:title><maml:introduction>
<maml:para>When viewing an event log, you can filter the events being displayed. Event filtering is designed to be temporary and an applied filter can easily be removed. However, if you create a useful filter that you want to reuse, you can save it as a custom view.</maml:para>
</maml:introduction><maml:content><maml:sections><maml:section><maml:title></maml:title><maml:introduction>
<maml:procedure><maml:title>To filter displayed events</maml:title><maml:step><maml:sections><maml:section><maml:title></maml:title>
<maml:para>Start Event Viewer.</maml:para>
</maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title>
<maml:para>In the console tree, select the event log you want to filter.</maml:para>
</maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title>
<maml:para>On the <maml:ui>Action</maml:ui> menu, click <maml:ui>Filter Current Log</maml:ui>. </maml:para>
</maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title>
<maml:para>To filter events based on when they occurred, select the corresponding time period from the <maml:ui>Logged</maml:ui> drop-down list. </maml:para>

<maml:alertSet class="note"><maml:title>Note </maml:title>
<maml:para>If none of the options are acceptable, choose <maml:ui>Custom range</maml:ui>. In the <maml:ui>Custom range</maml:ui> dialog box, specify the earliest date and time from which you want events and the latest date and time from which you want events. Click <maml:ui>OK</maml:ui>.</maml:para>
</maml:alertSet>
</maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title>
<maml:para>In <maml:ui>Event level</maml:ui>, select the check boxes next to the event levels that you want the filter to display.</maml:para>
</maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title>
<maml:para>In the <maml:ui>Event source</maml:ui> drop-down list, select the check boxes next to the event sources that you want your filter to display.</maml:para>
</maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title>
<maml:para>In <maml:ui>Event IDs</maml:ui>, type the event IDs that you want your filter to display. Separate multiple event IDs by commas. If you want to include a range of IDs, say 4624 through 4634 inclusive, type <maml:userInput>4624-4634</maml:userInput>. If you want your filter to display events with all IDs except certain ones, type the IDs of those exceptions, preceded by a minus sign. For example, to include all IDs between 4624 and 4634 except for 4630, type <maml:userInput>4624-4634,-4630</maml:userInput>.</maml:para>
</maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title>
<maml:para>In <maml:ui>Task Category</maml:ui>, select the check boxes next to the task categories in the drop-down list that you want your filter to display.</maml:para>
</maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title>
<maml:para>In the <maml:ui>Keywords </maml:ui>drop-down list, select the check boxes next to the keywords that you want your filter to display.</maml:para>
</maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title>
<maml:para>In <maml:ui>User</maml:ui>, enter the name of the user accounts you want your filter to display. To enter multiple user accounts, separate them with a comma (,). </maml:para>
</maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title>
<maml:para>In <maml:ui>Computer(s)</maml:ui>, enter the name of computers that you want the filter to display. This field refers to the source computer of the event. Enter multiple computers by separating them with a comma (,).</maml:para>
</maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title>
<maml:para>Click <maml:ui>OK</maml:ui> to apply the filter.</maml:para>
</maml:section></maml:sections></maml:step></maml:procedure>
</maml:introduction>
<maml:sections>
<maml:section>
<maml:title>Additional Considerations</maml:title><maml:introduction>
<maml:list class="unordered">
<maml:listItem>
<maml:para>To remove a currently applied filter, on the <maml:ui>Action</maml:ui> menu, click <maml:ui>Clear Filter</maml:ui>.</maml:para>
</maml:listItem>

<maml:listItem>
<maml:para>Leaving a field in the <maml:ui>Filter Current Log</maml:ui> dialog box blank specifies that you want the filter to display entries with any value of the corresponding property.</maml:para>
</maml:listItem>

<maml:listItem>
<maml:para>You cannot filter on an Event source, Task category, or Keyword that has not yet appeared in the log you are filtering. </maml:para>
</maml:listItem>

<maml:listItem>
<maml:para>Filters apply to a single event log. If you want to filter across event logs, you must create a custom view.</maml:para>
</maml:listItem>
</maml:list>
</maml:introduction>
<maml:sections>
<maml:section>
<maml:title>Additional Resources</maml:title><maml:introduction>
<maml:para><maml:navigationLink><maml:linkText>Save Filter as a Custom View</maml:linkText><maml:uri href="mshelp://windows/?id=7b26a107-7c1f-49c1-b5fa-2f6093bfa6bc"></maml:uri></maml:navigationLink></maml:para>
</maml:introduction></maml:section>
</maml:sections>
</maml:section>
</maml:sections>
</maml:section></maml:sections></maml:content></maml:conceptual><maml:conceptual contentType="conceptual" xmlns:maml="http://schemas.microsoft.com/maml/2004/10" xmlns:dev="http://schemas.microsoft.com/maml/dev/2004/10"><maml:title>Export a Custom View</maml:title><maml:introduction>
<maml:para>Custom views can be exported as XML files with an XML file name extension. The resulting XML files can be imported using Event Viewer. This allows custom views to be shared between users and computers.</maml:para>

<maml:para></maml:para>

<maml:procedure><maml:title>To export a custom view</maml:title><maml:step><maml:sections><maml:section><maml:title></maml:title>
<maml:para>Start Event Viewer.</maml:para>
</maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title>
<maml:para>In the console tree, select the custom view you want to export.</maml:para>
</maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title>
<maml:para>In the <maml:ui>Actions</maml:ui> pane, click <maml:ui>Export Custom View</maml:ui>.</maml:para>
</maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title>
<maml:para>In the <maml:ui>Save As</maml:ui> dialog box, select a folder, enter a <maml:ui>File name</maml:ui> for the exported file, and then click <maml:ui>Save</maml:ui>.</maml:para>
</maml:section></maml:sections></maml:step></maml:procedure>
</maml:introduction><maml:content><maml:sections><maml:section><maml:title>Additional references</maml:title>
<maml:introduction><maml:para><maml:navigationLink><maml:linkText>Create and Manage Custom Views</maml:linkText><maml:uri href="mshelp://windows/?id=7c01708c-ca47-4f62-b731-4ac3f3934786"></maml:uri></maml:navigationLink></maml:para></maml:introduction></maml:section></maml:sections></maml:content></maml:conceptual><maml:conceptual contentType="conceptual" xmlns:maml="http://schemas.microsoft.com/maml/2004/10" xmlns:dev="http://schemas.microsoft.com/maml/dev/2004/10"><maml:title>Save Filter as a Custom View</maml:title><maml:introduction>
<maml:para>You can save a filter as a Custom View so that you can use it again without having to recreate it.</maml:para>

<maml:procedure><maml:title>To save a filter to reuse later</maml:title><maml:step><maml:sections><maml:section><maml:title></maml:title>
<maml:para>Start Event Viewer.</maml:para>
</maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title>
<maml:para>Follow the steps in <maml:navigationLink><maml:linkText>Filter Displayed Events</maml:linkText><maml:uri href="mshelp://windows/?id=7710dc96-8061-4cfe-aafb-c7fdf1c6f7b6"></maml:uri></maml:navigationLink>.</maml:para>
</maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title>
<maml:para>On the <maml:ui>Action</maml:ui> menu, click <maml:ui>Save Filter As Custom View</maml:ui>.</maml:para>
</maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title>
<maml:para>In <maml:ui>Name</maml:ui>, type the name that you want to use to access the custom view in the future.</maml:para>
</maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title>
<maml:para>In <maml:ui>Description</maml:ui>, type a description of the custom view.</maml:para>
</maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title>
<maml:para>In the console tree, select the location where you want the saved filter to be stored.</maml:para>
</maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title>
<maml:para>To allow all users of the computer to access the view, ensure that the <maml:ui>All Users</maml:ui> check box is selected. To only allow the currently logged on user to access the view, ensure that the <maml:ui>All Users</maml:ui> check box is not selected.</maml:para>
</maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title>
<maml:para>Click <maml:ui>OK</maml:ui>.</maml:para>
</maml:section></maml:sections></maml:step></maml:procedure>
</maml:introduction><maml:content><maml:sections><maml:section><maml:title></maml:title><maml:introduction></maml:introduction>
<maml:sections>
<maml:section><maml:title></maml:title><maml:introduction></maml:introduction>
<maml:sections>
<maml:section>
<maml:title>Additional Resources</maml:title><maml:introduction>
<maml:list class="unordered">
<maml:listItem>
<maml:para><maml:navigationLink><maml:linkText>Create a Custom View</maml:linkText><maml:uri href="mshelp://windows/?id=0234cfde-93d4-46c3-a0dd-f26c6273aa26"></maml:uri></maml:navigationLink></maml:para>
</maml:listItem>

<maml:listItem>
<maml:para><maml:navigationLink><maml:linkText>Filter Displayed Events</maml:linkText><maml:uri href="mshelp://windows/?id=7710dc96-8061-4cfe-aafb-c7fdf1c6f7b6"></maml:uri></maml:navigationLink></maml:para>
</maml:listItem>
</maml:list>
</maml:introduction></maml:section>
</maml:sections>
</maml:section>
</maml:sections>
</maml:section></maml:sections></maml:content></maml:conceptual><maml:conceptual contentType="conceptual" xmlns:maml="http://schemas.microsoft.com/maml/2004/10" xmlns:dev="http://schemas.microsoft.com/maml/dev/2004/10"><maml:title>Create and Manage Custom Views</maml:title><maml:introduction>
<maml:para>Custom views are like filters that have been named and saved. After creating and saving a custom view, you will be able to reuse it without re-creating its underlying filter. To reuse a custom view, navigate to the <maml:ui>Custom Views</maml:ui> category in the console tree and select the name of the custom view. By selecting the custom view, you apply the underlying filter and the results are displayed. You can import and export custom views, enabling you to share them between users and computers.</maml:para>

<maml:para>The following topics describe how to create and manage custom views:</maml:para>

<maml:list class="unordered">
<maml:listItem>
<maml:para><maml:navigationLink><maml:linkText>Create a Custom View</maml:linkText><maml:uri href="mshelp://windows/?id=0234cfde-93d4-46c3-a0dd-f26c6273aa26"></maml:uri></maml:navigationLink></maml:para>
</maml:listItem>

<maml:listItem>
<maml:para><maml:navigationLink><maml:linkText>Export a Custom View</maml:linkText><maml:uri href="mshelp://windows/?id=79610900-b937-4686-aee3-3d72875d4d66"></maml:uri></maml:navigationLink></maml:para>
</maml:listItem>

<maml:listItem>
<maml:para><maml:navigationLink><maml:linkText>Import a Custom View</maml:linkText><maml:uri href="mshelp://windows/?id=0b81db9c-f482-4aa5-865a-d467517d9753"></maml:uri></maml:navigationLink></maml:para>
</maml:listItem>

<maml:listItem>
<maml:para><maml:navigationLink><maml:linkText>Display XML Format of a Custom View</maml:linkText><maml:uri href="mshelp://windows/?id=29ae83c2-2fca-4897-b95d-343706080fa5"></maml:uri></maml:navigationLink></maml:para>
</maml:listItem>

<maml:listItem>
<maml:para><maml:navigationLink><maml:linkText>Save Filter as a Custom View</maml:linkText><maml:uri href="mshelp://windows/?id=7b26a107-7c1f-49c1-b5fa-2f6093bfa6bc"></maml:uri></maml:navigationLink></maml:para>
</maml:listItem>
</maml:list>
</maml:introduction><maml:content><maml:sections></maml:sections></maml:content></maml:conceptual><maml:conceptual contentType="conceptual" xmlns:maml="http://schemas.microsoft.com/maml/2004/10" xmlns:dev="http://schemas.microsoft.com/maml/dev/2004/10"><maml:title>Command-line syntax notation</maml:title><maml:introduction>
<maml:para>The following table describes the notation used to indicate command-line syntax.</maml:para>

<maml:table>
<maml:tableHeader>
<maml:row>
<maml:entry>
<maml:para>Notation</maml:para>
</maml:entry>
<maml:entry>
<maml:para>Description</maml:para>
</maml:entry></maml:row>
</maml:tableHeader>

<maml:row>
<maml:entry>
<maml:para>Text without brackets or braces</maml:para>
</maml:entry>
<maml:entry>
<maml:para>Items you must type as shown</maml:para>
</maml:entry></maml:row>

<maml:row>
<maml:entry>
<maml:para>&lt;Text inside angle brackets&gt;</maml:para>
</maml:entry>
<maml:entry>
<maml:para>Placeholder for which you must supply a value</maml:para>
</maml:entry></maml:row>

<maml:row>
<maml:entry>
<maml:para>[Text inside square brackets]</maml:para>
</maml:entry>
<maml:entry>
<maml:para>Optional items</maml:para>
</maml:entry></maml:row>

<maml:row>
<maml:entry>
<maml:para>{Text inside braces}</maml:para>
</maml:entry>
<maml:entry>
<maml:para>Set of required items; choose one</maml:para>
</maml:entry></maml:row>

<maml:row>
<maml:entry>
<maml:para>Vertical bar (|)</maml:para>
</maml:entry>
<maml:entry>
<maml:para>Separator for mutually exclusive items; choose one</maml:para>
</maml:entry></maml:row>

<maml:row>
<maml:entry>
<maml:para>Ellipsis (…)</maml:para>
</maml:entry>
<maml:entry>
<maml:para>Items that can be repeated</maml:para>
</maml:entry></maml:row>
</maml:table>
</maml:introduction><maml:content><maml:sections></maml:sections></maml:content></maml:conceptual><maml:conceptual contentType="conceptual" xmlns:maml="http://schemas.microsoft.com/maml/2004/10" xmlns:dev="http://schemas.microsoft.com/maml/dev/2004/10"><maml:title>Archive an Event Log</maml:title><maml:introduction>
<maml:para>You can manually save the events in an event log using the following procedure. In addition, certain log retention policies may save events automatically. When you save events, you can include display information that will enable the saved events to be viewed on another computer and you can include information that will enable the saved events to be viewed in a different language.</maml:para>
</maml:introduction><maml:content><maml:sections><maml:section><maml:title></maml:title><maml:introduction>
<maml:procedure><maml:title>To export and archive an event log</maml:title><maml:step><maml:sections><maml:section><maml:title></maml:title>
<maml:para>Start Event Viewer.</maml:para>
</maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title>
<maml:para>In the console tree, navigate to the log you want to archive.</maml:para>
</maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title>
<maml:para>On the <maml:ui>Action</maml:ui> menu, click <maml:ui>Save Events As</maml:ui>.</maml:para>
</maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title>
<maml:para>In <maml:ui>File name</maml:ui>, enter a name for the archived log file.</maml:para>
</maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title>
<maml:para>In <maml:ui>Save as type</maml:ui>, select a file format, and then click <maml:ui>Save</maml:ui>.</maml:para>
</maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title>
<maml:para>(Optional) In the <maml:ui>Display Information</maml:ui> dialog box, if the event log information is not intended to be viewed on another computer, accept the default of <maml:ui>No display information</maml:ui>.</maml:para>
</maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title>
<maml:para>(Optional) In the <maml:ui>Display Information</maml:ui> dialog box, if the event log information is intended to be viewed on another computer, click <maml:ui>Display information for these languages</maml:ui>.</maml:para>
</maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title>
<maml:para>(Optional) If the event log information is intended to be viewed in a different language, select the <maml:ui>Show all available languages</maml:ui> check box.</maml:para>
</maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title>
<maml:para>(Optional) Select the language check boxes for which you want to include language information.</maml:para>
</maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title>
<maml:para>Click <maml:ui>OK</maml:ui>.</maml:para>
</maml:section></maml:sections></maml:step></maml:procedure>

<maml:procedure><maml:title>To export and archive an event log using a command line</maml:title><maml:step><maml:sections><maml:section><maml:title></maml:title>
<maml:para>To open a command prompt, click <maml:ui>Start</maml:ui>, type <maml:userInput>cmd</maml:userInput>, in the <maml:ui>Start Search</maml:ui> box, and then press <maml:ui>Enter</maml:ui>.</maml:para>
</maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title>
<maml:para>To export the log to a file, type the following command:</maml:para>

<dev:code>wevtutil epl &lt;LogName&gt; &lt;FileName.evtx&gt;</dev:code>
</maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title>
<maml:para>To archive the log with display information, type the following command:</maml:para>

<dev:code>wevtutil al &lt;FileName.evtx&gt; [/l:&lt;LocaleString&gt;]</dev:code>
</maml:section></maml:sections></maml:step></maml:procedure>

<maml:para>To view the complete syntax for the wevutil command with the epl option, type the following at a command prompt:</maml:para>

<dev:code>wevtutil epl /?</dev:code>

<maml:para>To view the complete syntax for the wevutil command with the epl option, type the following at a command prompt:</maml:para>

<dev:code>wevtutil al /?</dev:code>
</maml:introduction>
<maml:sections>
<maml:section>
<maml:title>Additional Considerations</maml:title><maml:introduction>
<maml:list class="unordered">
<maml:listItem>
<maml:para>If you archive a log in .evtx file format, you can reopen it in Event Viewer.</maml:para>
</maml:listItem>

<maml:listItem>
<maml:para>Archiving does not delete the contents of the log.</maml:para>
</maml:listItem>

<maml:listItem>
<maml:para>The sort order is not retained when logs are saved.</maml:para>
</maml:listItem>

<maml:listItem>
<maml:para>If you archive a log that is filtered, only the records that satisfy the filter will be saved.</maml:para>
</maml:listItem>

<maml:listItem>
<maml:para>To troubleshoot events that were logged on a remote computer, you must export and archive the log with the display information. The display information for the saved events is stored in the LocaleMetaData folder and should be moved with the log information when the information is viewed on another computer.</maml:para>
</maml:listItem>
</maml:list>
</maml:introduction>
<maml:sections>
<maml:section>
<maml:title>Additional Resources</maml:title><maml:introduction>
<maml:list class="unordered">
<maml:listItem>
<maml:para><maml:navigationLink><maml:linkText>Set Log Retention Policy</maml:linkText><maml:uri href="mshelp://windows/?id=7511c36a-cf41-41f5-b8cb-f4c233ca2bb3"></maml:uri></maml:navigationLink></maml:para>
</maml:listItem>
</maml:list>
</maml:introduction></maml:section>
</maml:sections>
</maml:section>
</maml:sections>
</maml:section></maml:sections></maml:content></maml:conceptual><maml:conceptual contentType="conceptual" xmlns:maml="http://schemas.microsoft.com/maml/2004/10" xmlns:dev="http://schemas.microsoft.com/maml/dev/2004/10"><maml:title>Show or Hide Analytic and Debug Logs</maml:title><maml:introduction>
<maml:para>Analytic and Debug logs are disabled and hidden by default. To work with them, you need to first make them visible in the UI. </maml:para>

<maml:procedure><maml:title>To show or hide analytic and debug logs</maml:title><maml:step><maml:sections><maml:section><maml:title></maml:title>
<maml:para>Start Event Viewer.</maml:para>
</maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title>
<maml:para>Click the View menu. If <maml:ui>Show Analytic and Debug Logs</maml:ui> is selected, Analytic and Debug logs are already visible. No further action is required. If <maml:ui>Show Analytic and Debug Logs</maml:ui> is not selected, select <maml:ui>Show Analytic and Debug Logs</maml:ui> to make these logs visible. Note that a check mark should appear to the left of the menu option.</maml:para>
</maml:section></maml:sections></maml:step></maml:procedure>
</maml:introduction><maml:content><maml:sections><maml:section><maml:title></maml:title><maml:introduction></maml:introduction>
<maml:sections>
<maml:section><maml:title></maml:title><maml:introduction></maml:introduction>
<maml:sections>
<maml:section>
<maml:title>Additional Resources</maml:title><maml:introduction>
<maml:list class="unordered">
<maml:listItem>
<maml:para><maml:navigationLink><maml:linkText>Enable Analytic and Debug Logs</maml:linkText><maml:uri href="mshelp://windows/?id=edec63a3-fa81-4677-99ae-b6cdada48d6d"></maml:uri></maml:navigationLink></maml:para>
</maml:listItem>

<maml:listItem>
<maml:para><maml:navigationLink><maml:linkText>Event Logs</maml:linkText><maml:uri href="mshelp://windows/?id=e1459340-eaed-40c7-93a0-36bd933bdd7e"></maml:uri></maml:navigationLink></maml:para>
</maml:listItem>
</maml:list>
</maml:introduction></maml:section>
</maml:sections>
</maml:section>
</maml:sections>
</maml:section></maml:sections></maml:content></maml:conceptual><maml:conceptual contentType="conceptual" xmlns:maml="http://schemas.microsoft.com/maml/2004/10" xmlns:dev="http://schemas.microsoft.com/maml/dev/2004/10"><maml:title>Create a New Subscription</maml:title><maml:introduction>
<maml:para>To receive forwarded events on a computer, you must set up one or more event subscriptions. Before setting up a subscription, you must configure both the computer that will receive the forwarded events, and the computer or computers that will forward the events. To learn how to configure the computers, see <maml:navigationLink><maml:linkText>Configure Computers to Forward and Collect Events</maml:linkText><maml:uri href="mshelp://windows/?id=165d8b7c-a85e-42c2-8316-6701f0701c88"></maml:uri></maml:navigationLink>.</maml:para>

<maml:para>Once you have configured the computers, you create a subscription to specify which events to collect.</maml:para>

<maml:procedure><maml:title>To create a new subscription</maml:title><maml:step><maml:sections><maml:section><maml:title></maml:title>
<maml:para>On the collector computer, run Event Viewer as an administrator.</maml:para>
</maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title>
<maml:para>Click <maml:ui>Subscriptions</maml:ui> in the console tree. </maml:para>

<maml:alertSet class="note"><maml:title>Note </maml:title>
<maml:para>If the Windows Event Collector service is not started, you will be prompted to confirm that you want to start it. This service must be started to create subscriptions and collect events. You must be a member of the Administrators group to start this service.</maml:para>
</maml:alertSet>
</maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title>
<maml:para>On the <maml:ui>Actions</maml:ui> menu, click <maml:ui>Create Subscription</maml:ui>.</maml:para>
</maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title>
<maml:para>In the <maml:ui>Subscription Name box</maml:ui>, type a name for the subscription.</maml:para>
</maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title>
<maml:para>In the <maml:ui>Description box</maml:ui>, enter an optional description.</maml:para>
</maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title>
<maml:para>In the <maml:ui>Destination Log box</maml:ui>, select the log file where collected events are to be stored. By default, collected events are stored in the ForwardedEvents log.</maml:para>
</maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title>
<maml:para>Click <maml:ui>Add</maml:ui> and select the computers from which events are to be collected.</maml:para>

<maml:alertSet class="note"><maml:title>Note </maml:title>
<maml:para>After adding a computer, you can test connectivity between it and the local computer by selecting the computer and clicking <maml:ui>Test</maml:ui>.</maml:para>
</maml:alertSet>
</maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title>
<maml:para>Click <maml:ui>Select Events</maml:ui> to display the <maml:ui>Query Filter</maml:ui> dialog box. Use the controls in the <maml:ui>Query Filter</maml:ui> dialog box to specify the criteria that events must meet to be collected.</maml:para>
</maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title>
<maml:para>Click <maml:ui>OK</maml:ui> on the <maml:ui>Subscription Properties</maml:ui> dialog box. The subscription will be added to the <maml:ui>Subscriptions</maml:ui> pane and, if the operation was successful, the Status of the subscription will be Active.</maml:para>
</maml:section></maml:sections></maml:step></maml:procedure>

<maml:para>Events raised on the forwarder computers that meet the criteria of the subscription will be copied to the collector computer log specified in step 6. </maml:para>
</maml:introduction><maml:content><maml:sections><maml:section>
<maml:title>Additional Considerations</maml:title><maml:introduction>
<maml:list class="unordered">
<maml:listItem>
<maml:para>You cannot use Event Viewer to create a subscription while it is connected to a remote computer.</maml:para>
</maml:listItem>

<maml:listItem>
<maml:para>You can use the filter from a previously defined Custom View by choosing <maml:ui>Copy from existing Custom View</maml:ui>. Additionally, you can paste an XPATH query into the text box on the XML tab of the <maml:ui>Query Filter</maml:ui> dialog box.</maml:para>
</maml:listItem>

<maml:listItem>
<maml:para>If a newly created subscription does not activate, you can open the <maml:ui>Subscription Properties</maml:ui> dialog box and select individual source computers to view the status for each of them.</maml:para>
</maml:listItem>
</maml:list>
</maml:introduction>
<maml:sections>
<maml:section><maml:title></maml:title><maml:introduction></maml:introduction>
<maml:sections>
<maml:section>
<maml:title>Additional Resources</maml:title><maml:introduction>
<maml:list class="unordered">
<maml:listItem>
<maml:para><maml:navigationLink><maml:linkText>Configure Computers to Forward and Collect Events</maml:linkText><maml:uri href="mshelp://windows/?id=165d8b7c-a85e-42c2-8316-6701f0701c88"></maml:uri></maml:navigationLink></maml:para>
</maml:listItem>

<maml:listItem>
<maml:para><maml:navigationLink><maml:linkText>Configure Advanced Subscription Settings</maml:linkText><maml:uri href="mshelp://windows/?id=473cb9ba-4aee-4717-a517-120371159da8"></maml:uri></maml:navigationLink></maml:para>
</maml:listItem>
</maml:list>
</maml:introduction></maml:section>
</maml:sections>
</maml:section>
</maml:sections>
</maml:section></maml:sections></maml:content></maml:conceptual><maml:conceptual contentType="conceptual" xmlns:maml="http://schemas.microsoft.com/maml/2004/10" xmlns:dev="http://schemas.microsoft.com/maml/dev/2004/10"><maml:title>Start Event Viewer</maml:title><maml:introduction>
<maml:para>The Event Viewer is a Microsoft Management Console (MMC) snap-in. You can start Event Viewer by adding the snap-in to MMC or by double-clicking the snap-in file, Eventvwr.msc, which is located in the %SYSTEMROOT%\system32 folder. In addition, Event Viewer can be started from the Windows interface or the command line by using the following procedures. </maml:para>

<maml:procedure><maml:title>To start Event Viewer by using the Windows interface</maml:title><maml:step><maml:sections><maml:section><maml:title></maml:title>
<maml:para>Click the <maml:ui>Start</maml:ui> button.</maml:para>
</maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title>
<maml:para>Click <maml:ui>Control Panel</maml:ui>.</maml:para>
</maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title>
<maml:para>Click <maml:ui>System and Maintenance</maml:ui>.</maml:para>
</maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title>
<maml:para>Click <maml:ui>Administrative Tools</maml:ui>.</maml:para>
</maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title>
<maml:para>Double-click <maml:ui>Event Viewer</maml:ui>.</maml:para>
</maml:section></maml:sections></maml:step></maml:procedure>

<maml:procedure><maml:title>To start Event Viewer by using a command line</maml:title><maml:step><maml:sections><maml:section><maml:title></maml:title>
<maml:para>Open a command prompt. To open a command prompt, click <maml:ui>Start</maml:ui>, click <maml:ui>All Programs</maml:ui>, click <maml:ui>Accessories</maml:ui> and then click <maml:ui>Command Prompt</maml:ui>.</maml:para>
</maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title>
<maml:para>Type <maml:computerOutputInline>eventvwr</maml:computerOutputInline>.</maml:para>
</maml:section></maml:sections></maml:step></maml:procedure>

<maml:para>The eventvwr.exe command-line tool supports options that determine the computer the snap-in will connect to and the event logs it will display. When connecting to a computer running a previous version of Windows, the tool can be used to start the snap-in and connect to the remote computer, but the additional command-line options are ignored.</maml:para>

<maml:para>To display additional help for the eventvwr command-line tool, type the following command at a command prompt: <maml:computerOutputInline>eventvwr /?</maml:computerOutputInline></maml:para>
</maml:introduction><maml:content><maml:sections><maml:section><maml:title></maml:title><maml:introduction></maml:introduction>
<maml:sections>
<maml:section><maml:title></maml:title><maml:introduction></maml:introduction>
<maml:sections>
<maml:section>
<maml:title>Additional Resources</maml:title><maml:introduction>
<maml:list class="unordered">
<maml:listItem>
<maml:para><maml:navigationLink><maml:linkText>Work with Event Logs on a Remote Computer</maml:linkText><maml:uri href="mshelp://windows/?id=cfad9c47-96cc-46d8-b432-2baf661a72bb"></maml:uri></maml:navigationLink></maml:para>
</maml:listItem>
</maml:list>
</maml:introduction></maml:section>
</maml:sections>
</maml:section>
</maml:sections>
</maml:section></maml:sections></maml:content></maml:conceptual><maml:conceptual contentType="conceptual" xmlns:maml="http://schemas.microsoft.com/maml/2004/10" xmlns:dev="http://schemas.microsoft.com/maml/dev/2004/10"><maml:title>Clear an Event Log</maml:title><maml:introduction>
<maml:para> You can clear events in an event log by using Event Viewer or by using the wevtutil command on a command line.</maml:para>
</maml:introduction><maml:content><maml:sections><maml:section><maml:title></maml:title><maml:introduction>
<maml:procedure><maml:title>To clear an event log by using Event Viewer</maml:title><maml:step><maml:sections><maml:section><maml:title></maml:title>
<maml:para>Start Event Viewer.</maml:para>
</maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title>
<maml:para>In the console tree, navigate to the event log you want to clear.</maml:para>
</maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title>
<maml:para>On the <maml:ui>Action</maml:ui> menu, click <maml:ui>Clear Log</maml:ui>.</maml:para>
</maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title>
<maml:para>You can either clear the event log or save a copy of the event log and then clear it.</maml:para>

<maml:list class="unordered">
<maml:listItem>
<maml:para><maml:phrase>To clear the event log without saving:</maml:phrase> Click <maml:ui>Clear</maml:ui>.</maml:para>
</maml:listItem>

<maml:listItem>
<maml:para><maml:phrase>To clear the event log after saving:</maml:phrase> Click <maml:ui>Save and Clear</maml:ui>, type a name for the saved file in <maml:ui>File name</maml:ui> on the <maml:ui>Save As</maml:ui> dialog box and click <maml:ui>Save</maml:ui>.</maml:para>
</maml:listItem>
</maml:list>
</maml:section></maml:sections></maml:step></maml:procedure>

<maml:procedure><maml:title>To clear an event log by using a command line</maml:title><maml:step><maml:sections><maml:section><maml:title></maml:title>
<maml:para>To open a command prompt, click <maml:ui>Start</maml:ui>, type <maml:userInput>cmd</maml:userInput> in the <maml:ui>Start Search</maml:ui> box, and then press <maml:ui>Enter</maml:ui>.</maml:para>
</maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title>
<maml:para>Type the following command:</maml:para>

<dev:code>wevtutil cl &lt;LogName&gt; [/bu: &lt;backup_file_name&gt;]</dev:code>
</maml:section></maml:sections></maml:step></maml:procedure>

<maml:para>To learn more about the clear log option of the wevtutil command-line tool, type the following command at a command prompt:</maml:para>

<dev:code>wevtutil cl -?</dev:code>
</maml:introduction>
<maml:sections>
<maml:section>
<maml:title>Additional considerations</maml:title><maml:introduction>
<maml:list class="unordered">
<maml:listItem>
<maml:para>You must have Clear permission on the log to perform this operation. By default, Administrators have permission to clear event logs. To set the Clear permission on a log for other groups, type the following command at a command prompt:</maml:para>

<dev:code>wevtutil sl &lt;LogName&gt; /ca:&lt;SecurityDescriptor&gt; </dev:code>

<maml:para>The Security Descriptor for each log is specified by using Security Descriptor Definition Language (SDDL) syntax. For more information about SDDL syntax, see <maml:navigationLink><maml:linkText>Security Descriptor Definition Language</maml:linkText><maml:uri href="http://go.microsoft.com/fwlink/?LinkId=90935"></maml:uri></maml:navigationLink> at the MSDN Web site.<br xmlns="http://ddue.schemas.microsoft.com/authoring/2003/5" xmlns:xlink="http://www.w3.org/1999/xlink" /><br xmlns="http://ddue.schemas.microsoft.com/authoring/2003/5" xmlns:xlink="http://www.w3.org/1999/xlink" />To construct an SDDL string, note that there are three distinct rights that pertain to event logs: Read, Write, and Clear. These rights correspond to the following bits in the access rights field of the ACE string: </maml:para>

<maml:list class="unordered">
<maml:listItem>
<maml:para>1= Read</maml:para>
</maml:listItem>

<maml:listItem>
<maml:para>2 = Write</maml:para>
</maml:listItem>

<maml:listItem>
<maml:para>4 = Clear</maml:para>
</maml:listItem>
</maml:list>

<maml:para>To see the SDDL string for a log, type the following command at a command prompt:</maml:para>

<dev:code>wevtutil gl &lt;LogName&gt;</dev:code>

<maml:para>The following example shows how to add Clear permission to the Application log for the Backup Operators group (A;;0x4;;;BO):</maml:para>

<dev:code>wevtutil sl Application /ca:O:BAG:SYD:(A;;0xf0007;;;SY)(A;;0x7;;;BA)(A;;0x7;;;SO)(A;;0x3;;;IU)(A;;0x3;;;SU)(A;;0x3;;;S-1-5-3)(A;;0x3;;;S-1-5-33)(A;;0x1;;;S-1-5-32-573)(A;;0x4;;;BO)</dev:code>
</maml:listItem>
</maml:list>
</maml:introduction>
<maml:sections>
<maml:section>
<maml:title>Additional references</maml:title><maml:introduction>
<maml:list class="unordered">
<maml:listItem>
<maml:para><maml:navigationLink><maml:linkText>Archive an Event Log</maml:linkText><maml:uri href="mshelp://windows/?id=7ee045ef-1e94-414b-9099-193b5b6bc439"></maml:uri></maml:navigationLink></maml:para>
</maml:listItem>

<maml:listItem>
<maml:para><maml:navigationLink><maml:linkText>Command-line syntax notation</maml:linkText><maml:uri href="mshelp://windows/?id=7ed13aea-4580-4ecd-93ef-9b09b504b87a"></maml:uri></maml:navigationLink></maml:para>
</maml:listItem>
</maml:list>
</maml:introduction></maml:section>
</maml:sections>
</maml:section>
</maml:sections>
</maml:section></maml:sections></maml:content></maml:conceptual><maml:conceptual contentType="conceptual" xmlns:maml="http://schemas.microsoft.com/maml/2004/10" xmlns:dev="http://schemas.microsoft.com/maml/dev/2004/10"><maml:title>Event Viewer How To...</maml:title><maml:introduction>
<maml:para>The topics in the following list contain information and step-by-step procedures that explain how to use the Event Viewer user interface and the wevtutil command line tool to manage events and event logs.</maml:para>

<maml:list class="unordered">
<maml:listItem>
<maml:para><maml:navigationLink><maml:linkText>Start Event Viewer</maml:linkText><maml:uri href="mshelp://windows/?id=a37fd11e-597a-4d44-9507-a88e937bda50"></maml:uri></maml:navigationLink></maml:para>
</maml:listItem>

<maml:listItem>
<maml:para><maml:navigationLink><maml:linkText>Create and Manage Custom Views</maml:linkText><maml:uri href="mshelp://windows/?id=7c01708c-ca47-4f62-b731-4ac3f3934786"></maml:uri></maml:navigationLink></maml:para>
</maml:listItem>

<maml:listItem>
<maml:para><maml:navigationLink><maml:linkText>Organize Event Presentation</maml:linkText><maml:uri href="mshelp://windows/?id=129e033f-7c7d-419c-99f2-91053a3ce090"></maml:uri></maml:navigationLink></maml:para>
</maml:listItem>

<maml:listItem>
<maml:para><maml:navigationLink><maml:linkText>Manage Event Logs</maml:linkText><maml:uri href="mshelp://windows/?id=543a7a70-4955-4628-b4ee-79f9bad741b1"></maml:uri></maml:navigationLink></maml:para>
</maml:listItem>

<maml:listItem>
<maml:para><maml:navigationLink><maml:linkText>Manage Subscriptions</maml:linkText><maml:uri href="mshelp://windows/?id=42e22049-94cb-4ace-b3d6-5f3a6ec61caa"></maml:uri></maml:navigationLink></maml:para>
</maml:listItem>

<maml:listItem>
<maml:para><maml:navigationLink><maml:linkText>Work with Event Logs on a Remote Computer</maml:linkText><maml:uri href="mshelp://windows/?id=cfad9c47-96cc-46d8-b432-2baf661a72bb"></maml:uri></maml:navigationLink></maml:para>
</maml:listItem>

<maml:listItem>
<maml:para><maml:navigationLink><maml:linkText>Run a Task in Response to a Given Event</maml:linkText><maml:uri href="mshelp://windows/?id=1833ed94-ec57-4783-aed9-4ce3a7bb2fea"></maml:uri></maml:navigationLink></maml:para>
</maml:listItem>
</maml:list>
</maml:introduction><maml:content><maml:sections></maml:sections></maml:content></maml:conceptual><maml:conceptual contentType="conceptual" xmlns:maml="http://schemas.microsoft.com/maml/2004/10" xmlns:dev="http://schemas.microsoft.com/maml/dev/2004/10"><maml:title>Work with Event Logs on a Remote Computer</maml:title><maml:introduction>
<maml:para>You can use the Event Viewer or the wevtutil command at a command prompt to manage event logs on a remote computer.</maml:para>
</maml:introduction><maml:content><maml:sections><maml:section><maml:title></maml:title><maml:introduction>
<maml:procedure><maml:title>To use Event Viewer to manage event logs on a remote computer</maml:title><maml:step><maml:sections><maml:section><maml:title></maml:title>
<maml:para>Start Event Viewer.</maml:para>
</maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title>
<maml:para>Click the root node, for example <maml:ui>Event Viewer (Local)</maml:ui>, in the console tree.</maml:para>
</maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title>
<maml:para>On the <maml:ui>Action</maml:ui> menu, click <maml:ui>Connect to Another Computer</maml:ui>.</maml:para>
</maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title>
<maml:para>In the <maml:ui>Another computer</maml:ui> box, type the name or IP address of the remote computer.</maml:para>
</maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title>
<maml:para>(Optional) Select <maml:ui>Connect as another user</maml:ui>, click <maml:ui>Set User</maml:ui>, enter the <maml:ui>User name</maml:ui> and <maml:ui>Password</maml:ui>, end then click <maml:ui>OK</maml:ui>.</maml:para>
</maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title>
<maml:para>Click <maml:ui>OK</maml:ui>.</maml:para>
</maml:section></maml:sections></maml:step></maml:procedure>

<maml:procedure><maml:title>To use wevtutil to manage event logs on a remote computer</maml:title><maml:step><maml:sections><maml:section><maml:title></maml:title>
<maml:para>To open a Command Prompt window, click <maml:ui>Start</maml:ui>, in the <maml:ui>Start Search</maml:ui> box, type <maml:userInput>cmd</maml:userInput>, and then press <maml:ui>Enter</maml:ui>.</maml:para>
</maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title>
<maml:para>Type the following command in the Command Prompt window:</maml:para>

<dev:code>wevtutil &lt;command&gt; /r:&lt;remote_computer_name&gt;</dev:code>
</maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title>
<maml:para>(Optional) To manage event logs on a remote computer as a different user, type the following command in the Command Prompt window:</maml:para>

<dev:code>wevtutil &lt;command&gt; /r:&lt;remote_computer_name&gt; /u:&lt;user_name&gt; /p:&lt;password&gt; </dev:code>
</maml:section></maml:sections></maml:step></maml:procedure>
</maml:introduction>
<maml:sections>
<maml:section>
<maml:title>Additional considerations</maml:title><maml:introduction>
<maml:list class="unordered">
<maml:listItem>
<maml:para>You must enable the <maml:ui>Remote Event Log Management</maml:ui> exception in the Windows Firewall Settings on the remote computer to which you want to connect.</maml:para>
</maml:listItem>

<maml:listItem>
<maml:para>You can type <maml:computerOutputInline>eventvwr</maml:computerOutputInline> <maml:computerOutputInline>&lt;remote_computer_name&gt;</maml:computerOutputInline><maml:codeInline> </maml:codeInline>in a Command Prompt window to start Event Viewer and connect to a remote computer.<maml:computerOutputInline> </maml:computerOutputInline>You can also include options that enable Event Viewer to start with a specified Custom View or with a particular log selected. To learn more about the eventvwr command, type <maml:computerOutputInline>eventvwr /?</maml:computerOutputInline> in a Command Prompt window. Although you can use the eventvwr command to start Event Viewer and connect to computers running previous versions of Windows, any options specified will be ignored.</maml:para>
</maml:listItem>

<maml:listItem>
<maml:para>When connected to a remote computer, Custom Views displayed by the Event Viewer are the Custom Views stored on the local computer. If you click one of those local Custom Views, the underlying query will be run against the event logs on the remote computer.</maml:para>
</maml:listItem>

<maml:listItem>
<maml:para>When connected to a remote computer, the external logs displayed by the Event Viewer are the ones that have been referenced on the local computer.</maml:para>
</maml:listItem>

<maml:listItem>
<maml:para>You may encounter errors if, while connected to a remote computer, you attempt to display Custom Views that reference local external logs. This happens because Event Viewer tries to open those external logs on the remote computer rather then the local computer. This problem does not arise if you use UNC path names to reference the external logs.</maml:para>
</maml:listItem>

<maml:listItem>
<maml:para>To view saved events from a remote computer, you need to save the events on the remote computer with display information. For more information about archiving events with display information, see <maml:navigationLink><maml:linkText>Archive an Event Log</maml:linkText><maml:uri href="mshelp://windows/?id=7ee045ef-1e94-414b-9099-193b5b6bc439"></maml:uri></maml:navigationLink>.</maml:para>
</maml:listItem>
</maml:list>
</maml:introduction>
<maml:sections>
<maml:section>
<maml:title>Additional references</maml:title><maml:introduction>
<maml:list class="unordered">
<maml:listItem>
<maml:para><maml:navigationLink><maml:linkText>Start Event Viewer</maml:linkText><maml:uri href="mshelp://windows/?id=a37fd11e-597a-4d44-9507-a88e937bda50"></maml:uri></maml:navigationLink></maml:para>
</maml:listItem>

<maml:listItem>
<maml:para><maml:navigationLink><maml:linkText>Command-line syntax notation</maml:linkText><maml:uri href="mshelp://windows/?id=7ed13aea-4580-4ecd-93ef-9b09b504b87a"></maml:uri></maml:navigationLink></maml:para>
</maml:listItem>
</maml:list>
</maml:introduction></maml:section>
</maml:sections>
</maml:section>
</maml:sections>
</maml:section></maml:sections></maml:content></maml:conceptual><maml:conceptual contentType="conceptual" xmlns:maml="http://schemas.microsoft.com/maml/2004/10" xmlns:dev="http://schemas.microsoft.com/maml/dev/2004/10"><maml:title>Sort Events by a Given Property</maml:title><maml:introduction>
<maml:para></maml:para>
</maml:introduction><maml:content><maml:sections><maml:section><maml:title></maml:title><maml:introduction>
<maml:para> You can sort any set of events that you are currently viewing by a single event property.</maml:para>

<maml:procedure><maml:title>To sort events by a given property</maml:title><maml:step><maml:sections><maml:section><maml:title></maml:title>
<maml:para>Start Event Viewer </maml:para>
</maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title>
<maml:para>In the console tree, click the event log, custom view, or saved log that you want to sort.</maml:para>
</maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title>
<maml:para>Click the column heading you want to sort by.</maml:para>
</maml:section></maml:sections></maml:step></maml:procedure>
</maml:introduction>
<maml:sections>
<maml:section>
<maml:title>Additional Considerations</maml:title><maml:introduction>
<maml:list class="unordered">
<maml:listItem>
<maml:para>To reverse the sort order, click the column heading a second time.</maml:para>
</maml:listItem>

<maml:listItem>
<maml:para>When a log is archived, the sort order is not saved.</maml:para>
</maml:listItem>
</maml:list>
</maml:introduction>
<maml:sections>
<maml:section>
<maml:title>Additional Resources</maml:title><maml:introduction>
<maml:list class="unordered">
<maml:listItem>
<maml:para><maml:navigationLink><maml:linkText>Group Events by a Given Property</maml:linkText><maml:uri href="mshelp://windows/?id=67e1dc18-b03a-4236-8cb7-0bb191c5a0b7"></maml:uri></maml:navigationLink></maml:para>
</maml:listItem>

<maml:listItem>
<maml:para><maml:navigationLink><maml:linkText>Archive an Event Log</maml:linkText><maml:uri href="mshelp://windows/?id=7ee045ef-1e94-414b-9099-193b5b6bc439"></maml:uri></maml:navigationLink></maml:para>
</maml:listItem>
</maml:list>
</maml:introduction></maml:section>
</maml:sections>
</maml:section>
</maml:sections>
</maml:section></maml:sections></maml:content></maml:conceptual><maml:conceptual contentType="conceptual" xmlns:maml="http://schemas.microsoft.com/maml/2004/10" xmlns:dev="http://schemas.microsoft.com/maml/dev/2004/10"><maml:title>Event Logs</maml:title><maml:introduction>
<maml:para>Windows Vista includes two categories of event logs: <maml:navigationLink><maml:linkText>Windows Logs</maml:linkText><maml:uri href="mshelp://windows/?id=e1459340-eaed-40c7-93a0-36bd933bdd7e#BKMK_WindowsLogs"></maml:uri></maml:navigationLink> and <maml:navigationLink><maml:linkText>Applications and Services</maml:linkText><maml:uri href="mshelp://windows/?id=e1459340-eaed-40c7-93a0-36bd933bdd7e#BKMK_ApplicationAndServicesLogs"></maml:uri></maml:navigationLink> logs. You can use either the Event Viewer or the wevtutil command-line tool to manage event logs. When you use wevtutil to manage event logs, messages that you receive from wevtutil might refer to event logs as channels. In most cases, event logs and channels are equivalent. For more information about event logs and channels, see the <maml:navigationLink><maml:linkText>Event Logs and Channels in Windows Event Log</maml:linkText><maml:uri href="http://go.microsoft.com/fwlink/?LinkId=62587"></maml:uri></maml:navigationLink> topic in the Windows Event Log Software Development Kit (SDK) online.</maml:para>
</maml:introduction><maml:content><maml:sections><maml:section><maml:title></maml:title><maml:introduction></maml:introduction>
<maml:sections>
<maml:section address="BKMK_WindowsLogs">
<maml:title>Windows Logs</maml:title><maml:introduction>
<maml:para>The Windows Logs category includes the logs that were available on previous versions of Windows: the Application, Security, and System logs. It also includes two new logs: the Setup log and the ForwardedEvents log. Windows logs are intended to store events from legacy applications and events that apply to the entire system.</maml:para>
</maml:introduction>
<maml:sections>
<maml:section>
<maml:title>Application log</maml:title><maml:introduction>
<maml:para>The Application log contains events logged by applications or programs. For example, a database program might record a file error in the application log. Program developers decide which events to log.</maml:para>
</maml:introduction></maml:section>

<maml:section>
<maml:title>Security log</maml:title><maml:introduction>
<maml:para>The Security log contains events such as valid and invalid logon attempts, as well as events related to resource use, such as creating, opening, or deleting files or other objects. Administrators can specify what events are recorded in the security log. For example, if you have enabled logon auditing, attempts to log on to the system are recorded in the security log.</maml:para>
</maml:introduction></maml:section>

<maml:section>
<maml:title>Setup log</maml:title><maml:introduction>
<maml:para>The Setup log contains events related to application setup.</maml:para>
</maml:introduction></maml:section>

<maml:section>
<maml:title>System log</maml:title><maml:introduction>
<maml:para>The System log contains events logged by Windows system components. For example, the failure of a driver or other system component to load during startup is recorded in the system log. The event types logged by system components are predetermined by Windows.</maml:para>
</maml:introduction></maml:section>

<maml:section>
<maml:title>ForwardedEvents log</maml:title><maml:introduction>
<maml:para>The ForwardedEvents log is used to store events collected from remote computers. To collect events from remote computers, you must create an event subscription. To learn about event subscriptions, see <maml:navigationLink><maml:linkText>Event Subscriptions</maml:linkText><maml:uri href="mshelp://windows/?id=4aa6403f-d4b8-43a4-a70d-ceb7f88c524e"></maml:uri></maml:navigationLink>.</maml:para>
</maml:introduction></maml:section>
</maml:sections>
</maml:section>

<maml:section address="BKMK_ApplicationAndServicesLogs">
<maml:title>Applications and Services Logs</maml:title><maml:introduction>
<maml:para>Applications and Services logs are a new category of event logs. These logs store events from a single application or component rather than events that might have systemwide impact.</maml:para>

<maml:para>This category of logs includes four subtypes: Admin, Operational, Analytic, and Debug logs. Events in Admin logs are of particular interest to IT Professionals using the Event Viewer to troubleshoot problems. Events in the Admin log should provide you with guidance about how to respond to them. Events in the Operational log are also useful for IT Professionals, but they are likely to require more interpretation. </maml:para>

<maml:para>Admin and Debug logs are not as user friendly. Analytic logs store events that trace an issue and, often, a high volume of events are logged. Debug logs are used by developers when debugging applications. Both Analytic and Debug logs are hidden and disabled by default. To make these logs visible, follow the steps in <maml:navigationLink><maml:linkText>Show or Hide Analytic and Debug Logs</maml:linkText><maml:uri href="mshelp://windows/?id=816eb4fa-7972-4f2a-9d72-c437c326e7be"></maml:uri></maml:navigationLink>. To enable these logs, follow the steps in <maml:navigationLink><maml:linkText>Enable Analytic and Debug Logs</maml:linkText><maml:uri href="mshelp://windows/?id=edec63a3-fa81-4677-99ae-b6cdada48d6d"></maml:uri></maml:navigationLink>.</maml:para>
</maml:introduction>
<maml:sections>
<maml:section>
<maml:title>Admin</maml:title><maml:introduction>
<maml:para>These events are primarily targeted at end users, administrators, and support personnel. The events that are found in the Admin channels indicate a problem and a well-defined solution that an administrator can act on. An example of an admin event is an event that occurs when an application fails to connect to a printer. These events are either well documented or have a message associated with them that gives the reader direct instructions of what must be done to rectify the problem.</maml:para>
</maml:introduction></maml:section>

<maml:section>
<maml:title>Operational</maml:title><maml:introduction>
<maml:para>Operational events are used for analyzing and diagnosing a problem or occurrence. They can be used to trigger tools or tasks based on the problem or occurrence. An example of an operational event is an event that occurs when a printer is added or removed from a system.</maml:para>
</maml:introduction></maml:section>

<maml:section>
<maml:title>Analytic</maml:title><maml:introduction>
<maml:para>Analytic events are published in high volume. They describe program operation and indicate problems that cannot be handled by user intervention.</maml:para>
</maml:introduction></maml:section>

<maml:section>
<maml:title>Debug</maml:title><maml:introduction>
<maml:para>Debug events are used by developers troubleshooting issues with their programs.</maml:para>
</maml:introduction></maml:section>
</maml:sections>
</maml:section>
</maml:sections>
</maml:section><maml:section>
<maml:title>XML-Based Infrastructure</maml:title><maml:introduction>
<maml:para>The infrastructure that underlies event logging has been completely revamped in Windows Vista. Information about each event conforms to an XML schema, and you can access the XML representing a given event. You can also construct XML-based queries against event logs. You do not have to know anything about XML to leverage the new features available. The Event Viewer allows you to access the functionality in an easy-to-use graphical format.</maml:para>
</maml:introduction>
<maml:sections>
<maml:section><maml:title></maml:title><maml:introduction></maml:introduction>
<maml:sections>
<maml:section>
<maml:title>Additional Resources</maml:title><maml:introduction>
<maml:list class="unordered">
<maml:listItem>
<maml:para><maml:navigationLink><maml:linkText>Display XML Format of a Custom View</maml:linkText><maml:uri href="mshelp://windows/?id=29ae83c2-2fca-4897-b95d-343706080fa5"></maml:uri></maml:navigationLink></maml:para>
</maml:listItem>

<maml:listItem>
<maml:para><maml:navigationLink><maml:linkText>Enable Analytic and Debug Logs</maml:linkText><maml:uri href="mshelp://windows/?id=edec63a3-fa81-4677-99ae-b6cdada48d6d"></maml:uri></maml:navigationLink></maml:para>
</maml:listItem>

<maml:listItem>
<maml:para><maml:navigationLink><maml:linkText>Show or Hide Analytic and Debug Logs</maml:linkText><maml:uri href="mshelp://windows/?id=816eb4fa-7972-4f2a-9d72-c437c326e7be"></maml:uri></maml:navigationLink></maml:para>
</maml:listItem>
</maml:list>
</maml:introduction></maml:section>
</maml:sections>
</maml:section>
</maml:sections>
</maml:section></maml:sections></maml:content></maml:conceptual><maml:conceptual contentType="conceptual" xmlns:maml="http://schemas.microsoft.com/maml/2004/10" xmlns:dev="http://schemas.microsoft.com/maml/dev/2004/10"><maml:title>Enable Analytic and Debug Logs</maml:title><maml:introduction>
<maml:para> Analytic and Debug logs are disabled by default. When enabled, they can quickly fill with a large number of entries. For this reason, you will probably want to turn them on for a specified period to gather some troubleshooting data and then turn them off again. You can perform this procedure by using either the Windows interface or a command line.</maml:para>
</maml:introduction><maml:content><maml:sections><maml:section><maml:title></maml:title><maml:introduction>
<maml:procedure><maml:title>To enable Analytic and Debug logs by using the Windows interface</maml:title><maml:step><maml:sections><maml:section><maml:title></maml:title>
<maml:para>Start Event Viewer.</maml:para>
</maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title>
<maml:para>Ensure that Analytic and Debug logs are visible by following the steps in <maml:navigationLink><maml:linkText>Show or Hide Analytic and Debug Logs</maml:linkText><maml:uri href="mshelp://windows/?id=816eb4fa-7972-4f2a-9d72-c437c326e7be"></maml:uri></maml:navigationLink>.</maml:para>
</maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title>
<maml:para>In the console tree, navigate to and select the Analytic or Debug log you want to enable.</maml:para>
</maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title>
<maml:para>On the <maml:ui>Action</maml:ui> menu, click <maml:ui>Properties</maml:ui>.</maml:para>
</maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title>
<maml:para>On the properties dialog box, select <maml:ui>Enable logging</maml:ui> and click <maml:ui>OK</maml:ui>.</maml:para>
</maml:section></maml:sections></maml:step></maml:procedure>

<maml:procedure><maml:title>To enable Analytic and Debug logs by using a command line</maml:title><maml:step><maml:sections><maml:section><maml:title></maml:title>
<maml:para>To open a command prompt, click <maml:ui>Start</maml:ui>, click <maml:ui>Run</maml:ui>, type <maml:userInput>cmd</maml:userInput>, and click <maml:ui>OK</maml:ui>.</maml:para>
</maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title>
<maml:para>Type the following text:</maml:para>

<dev:code>wevtutil sl &lt;logname&gt; /e:true</dev:code>
</maml:section></maml:sections></maml:step></maml:procedure>
</maml:introduction>
<maml:sections>
<maml:section><maml:title></maml:title><maml:introduction></maml:introduction>
<maml:sections>
<maml:section>
<maml:title>Additional references</maml:title><maml:introduction>
<maml:list class="unordered">
<maml:listItem>
<maml:para><maml:navigationLink><maml:linkText>Show or Hide Analytic and Debug Logs</maml:linkText><maml:uri href="mshelp://windows/?id=816eb4fa-7972-4f2a-9d72-c437c326e7be"></maml:uri></maml:navigationLink></maml:para>
</maml:listItem>

<maml:listItem>
<maml:para><maml:navigationLink><maml:linkText>Command-line syntax notation</maml:linkText><maml:uri href="mshelp://windows/?id=7ed13aea-4580-4ecd-93ef-9b09b504b87a"></maml:uri></maml:navigationLink></maml:para>
</maml:listItem>
</maml:list>
</maml:introduction></maml:section>
</maml:sections>
</maml:section>
</maml:sections>
</maml:section></maml:sections></maml:content></maml:conceptual><maml:conceptual contentType="conceptual" xmlns:maml="http://schemas.microsoft.com/maml/2004/10" xmlns:dev="http://schemas.microsoft.com/maml/dev/2004/10"><maml:title>Custom Views</maml:title><maml:introduction>
<maml:para>In previous versions of Event Viewer, you could filter the events in an event log. To create a filter, you specified a set of rules that were used to determine which events in the log would be visible and which would be hidden. You could, for instance, specify that only events with a level value of Error or Warning should be visible. </maml:para>

<maml:para>The ability to filter events is crucial. You need to focus your attention on only those events that apply to the issue you are investigating. The latest version of Event Viewer extends the filtering concept beyond a single event log. It enables you to create a set of rules which select events from the sources you specify and show only the events from those sources whose property values satisfy the rules.</maml:para>

<maml:para>Creating a filter that displays only the events you are interested in for a particular issue can be time-consuming. Custom Views provide a way for you to save that work. Once you have created a filter that displays just the records you are interested in, you can provide the filter with a name and save it to use later. That saved filter is a Custom View.</maml:para>
</maml:introduction><maml:content><maml:sections><maml:section><maml:title></maml:title><maml:introduction></maml:introduction>
<maml:sections>
<maml:section><maml:title></maml:title><maml:introduction></maml:introduction>
<maml:sections>
<maml:section>
<maml:title>Additional Resources</maml:title><maml:introduction>
<maml:list class="unordered">
<maml:listItem>
<maml:para><maml:navigationLink><maml:linkText>Create and Manage Custom Views</maml:linkText><maml:uri href="mshelp://windows/?id=7c01708c-ca47-4f62-b731-4ac3f3934786"></maml:uri></maml:navigationLink></maml:para>
</maml:listItem>
</maml:list>
</maml:introduction></maml:section>
</maml:sections>
</maml:section>
</maml:sections>
</maml:section></maml:sections></maml:content></maml:conceptual><?xml version="1.0" encoding="utf-8"?>
<HelpCollection Id="eventviewer_LH" DTDVersion="1.0" FileVersion="" LangId="1033" Copyright="© 2005 Microsoft Corporation. All rights reserved." Title="Windows Event Viewer" xmlns="http://schemas.microsoft.com/help/collection/2004/11">
	<CompilerOptions CompileResult="H1S" CreateFullTextIndex="Yes" BreakerId="Microsoft.NLG.en.WordBreaker">
		<IncludeFile File="eventviewer_LH.H1F" />
	</CompilerOptions>
	<TOCDef File="eventviewer_LH.H1T" Id="eventviewer_LH_TOC" />
	<VTopicDef File="eventviewer_LH.H1V" />
	<KeywordIndexDef File="eventviewer_LH_AssetId.H1K" />
	<KeywordIndexDef File="eventviewer_LH_BestBet.H1K" />
	<KeywordIndexDef File="eventviewer_LH_LinkTerm.H1K" />
	<KeywordIndexDef File="eventviewer_LH_SubjectTerm.H1K" />
	<ItemMoniker Name="!DefaultTOC" ProgId="HxDs.HxHierarchy" InitData="AnyString" />
	<ItemMoniker Name="!DefaultFullTextSearch" ProgId="HxDs.HxFullTextSearch" InitData="AnyString" />
	<ItemMoniker Name="!DefaultAssetIdIndex" ProgId="HxDs.HxIndex" InitData="AssetId" />
	<ItemMoniker Name="!DefaultBestBetIndex" ProgId="HxDs.HxIndex" InitData="BestBet" />
	<ItemMoniker Name="!DefaultAssociativeIndex" ProgId="HxDs.HxIndex" InitData="LinkTerm" />
	<ItemMoniker Name="!DefaultKeywordIndex" ProgId="HxDs.HxIndex" InitData="SubjectTerm" />
</HelpCollection><?xml version="1.0" encoding="utf-8"?>
<HelpFileList xmlns="http://schemas.microsoft.com/help/filelist/2004/11">
	<File Url="assets\0234cfde-93d4-46c3-a0dd-f26c6273aa26.xml" />
	<File Url="assets\05fb8bc9-aca3-4bf6-83c3-1834297ccf49.xml" />
	<File Url="assets\07abe800-89a9-43c5-a7bd-84304a881e7f.xml" />
	<File Url="assets\0b81db9c-f482-4aa5-865a-d467517d9753.xml" />
	<File Url="assets\129e033f-7c7d-419c-99f2-91053a3ce090.xml" />
	<File Url="assets\165d8b7c-a85e-42c2-8316-6701f0701c88.xml" />
	<File Url="assets\1833ed94-ec57-4783-aed9-4ce3a7bb2fea.xml" />
	<File Url="assets\2564192f-b638-47c8-ad31-9dbdf6f198f9.xml" />
	<File Url="assets\28cd5e13-e955-4941-91d9-fec2525e96c7.xml" />
	<File Url="assets\29ae83c2-2fca-4897-b95d-343706080fa5.xml" />
	<File Url="assets\386a877a-220a-4a7f-9238-7bacdee90279.xml" />
	<File Url="assets\3eff5d43-dc9b-4777-9362-b21010adbecb.xml" />
	<File Url="assets\4229f239-16a6-4ecd-b3cf-aec03dc08cd5.xml" />
	<File Url="assets\42e22049-94cb-4ace-b3d6-5f3a6ec61caa.xml" />
	<File Url="assets\473cb9ba-4aee-4717-a517-120371159da8.xml" />
	<File Url="assets\4aa6403f-d4b8-43a4-a70d-ceb7f88c524e.xml" />
	<File Url="assets\543a7a70-4955-4628-b4ee-79f9bad741b1.xml" />
	<File Url="assets\67e1dc18-b03a-4236-8cb7-0bb191c5a0b7.xml" />
	<File Url="assets\7511c36a-cf41-41f5-b8cb-f4c233ca2bb3.xml" />
	<File Url="assets\769748f2-603c-44b1-95f0-bd13efdde2a3.xml" />
	<File Url="assets\7710dc96-8061-4cfe-aafb-c7fdf1c6f7b6.xml" />
	<File Url="assets\79610900-b937-4686-aee3-3d72875d4d66.xml" />
	<File Url="assets\7b26a107-7c1f-49c1-b5fa-2f6093bfa6bc.xml" />
	<File Url="assets\7c01708c-ca47-4f62-b731-4ac3f3934786.xml" />
	<File Url="assets\7ed13aea-4580-4ecd-93ef-9b09b504b87a.xml" />
	<File Url="assets\7ee045ef-1e94-414b-9099-193b5b6bc439.xml" />
	<File Url="assets\816eb4fa-7972-4f2a-9d72-c437c326e7be.xml" />
	<File Url="assets\8fd4aad5-50bc-4389-bdae-e09ee464e46d.xml" />
	<File Url="assets\a37fd11e-597a-4d44-9507-a88e937bda50.xml" />
	<File Url="assets\ad46b98b-dd6b-4578-9dae-dfac1310ab7a.xml" />
	<File Url="assets\b7ed11ad-4b4f-43c0-88f6-43de77fc6762.xml" />
	<File Url="assets\cfad9c47-96cc-46d8-b432-2baf661a72bb.xml" />
	<File Url="assets\df28b174-f31a-4f18-a090-3ccbb394847e.xml" />
	<File Url="assets\e1459340-eaed-40c7-93a0-36bd933bdd7e.xml" />
	<File Url="assets\edec63a3-fa81-4677-99ae-b6cdada48d6d.xml" />
	<File Url="assets\ff1ea5b3-0127-488d-af6e-0d9267cefdc4.xml" />
</HelpFileList><?xml version="1.0" encoding="utf-8"?>
<VTopicSet DTDVersion="1.0" xmlns="http://schemas.microsoft.com/help/vtopic/2004/11">
	<Vtopic Url="assets\0234cfde-93d4-46c3-a0dd-f26c6273aa26.xml" RLTitle="Create a Custom View">
		<Attr Name="assetid" Value="0234cfde-93d4-46c3-a0dd-f26c6273aa26" />
		<Keyword Index="AssetId" Term="0234cfde-93d4-46c3-a0dd-f26c6273aa26" />
		<Keyword Index="AssetId" Term="0234cfde-93d4-46c3-a0dd-f26c6273aa261033" />
		<Attr Name="appliesToProduct" Value="Windows 7" />
		<Attr Name="appliesToProduct" Value="Windows Server 2008 R2" />
		<Attr Name="appliesToProduct" Value="Windows Vista" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2DATACENTERSERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2ENTERPRISEIA64SERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2ENTERPRISESERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2STANDARDSERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2WEBSERVER" />
		<Attr Name="appliesToSite" Value="BWCOnly" />
		<Attr Name="appliesToSite" Value="VistaITPro" />
		<Attr Name="CommunityContent" Value="1" />
		<Attr Name="WillHaveMamlFeed" Value="True" />
		<Attr Name="zzpub_assetBug" Value="1806" />
		<Attr Name="zzpub_MtpsProductFamily" Value="WS" />
		<Attr Name="zzpub_MTPSVersion" Value="11" />
		<Attr Name="Locale" Value="kbEnglish" />
		<Attr Name="AssetID" Value="0234cfde-93d4-46c3-a0dd-f26c6273aa26" />
		<Attr Name="TopicType" Value="kbArticle" />
	</Vtopic>
	<Vtopic Url="assets\05fb8bc9-aca3-4bf6-83c3-1834297ccf49.xml" RLTitle="Open or Close a Saved Log">
		<Attr Name="assetid" Value="05fb8bc9-aca3-4bf6-83c3-1834297ccf49" />
		<Keyword Index="AssetId" Term="05fb8bc9-aca3-4bf6-83c3-1834297ccf49" />
		<Keyword Index="AssetId" Term="05fb8bc9-aca3-4bf6-83c3-1834297ccf491033" />
		<Attr Name="appliesToProduct" Value="Windows 7" />
		<Attr Name="appliesToProduct" Value="Windows Server 2008 R2" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2DATACENTERSERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2ENTERPRISEIA64SERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2ENTERPRISESERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2STANDARDSERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2WEBSERVER" />
		<Attr Name="appliesToSite" Value="BWCOnly" />
		<Attr Name="CommunityContent" Value="1" />
		<Attr Name="WillHaveMamlFeed" Value="True" />
		<Attr Name="zzpub_assetBug" Value="1806" />
		<Attr Name="zzpub_MtpsProductFamily" Value="WS" />
		<Attr Name="zzpub_MTPSVersion" Value="11" />
		<Attr Name="Locale" Value="kbEnglish" />
		<Attr Name="AssetID" Value="05fb8bc9-aca3-4bf6-83c3-1834297ccf49" />
		<Attr Name="TopicType" Value="kbArticle" />
	</Vtopic>
	<Vtopic Url="assets\07abe800-89a9-43c5-a7bd-84304a881e7f.xml" RLTitle="Set Maximum Log Size">
		<Attr Name="assetid" Value="07abe800-89a9-43c5-a7bd-84304a881e7f" />
		<Keyword Index="AssetId" Term="07abe800-89a9-43c5-a7bd-84304a881e7f" />
		<Keyword Index="AssetId" Term="07abe800-89a9-43c5-a7bd-84304a881e7f1033" />
		<Attr Name="appliesToProduct" Value="Windows 7" />
		<Attr Name="appliesToProduct" Value="Windows Server 2008 R2" />
		<Attr Name="appliesToProduct" Value="Windows Vista" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2DATACENTERSERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2ENTERPRISEIA64SERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2ENTERPRISESERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2STANDARDSERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2WEBSERVER" />
		<Attr Name="appliesToSite" Value="BWCOnly" />
		<Attr Name="appliesToSite" Value="VistaITPro" />
		<Attr Name="CommunityContent" Value="1" />
		<Attr Name="WillHaveMamlFeed" Value="True" />
		<Attr Name="zzpub_assetBug" Value="1806" />
		<Attr Name="zzpub_MtpsProductFamily" Value="WS" />
		<Attr Name="zzpub_MTPSVersion" Value="11" />
		<Attr Name="Locale" Value="kbEnglish" />
		<Attr Name="AssetID" Value="07abe800-89a9-43c5-a7bd-84304a881e7f" />
		<Attr Name="TopicType" Value="kbArticle" />
	</Vtopic>
	<Vtopic Url="assets\0b81db9c-f482-4aa5-865a-d467517d9753.xml" RLTitle="Import a Custom View">
		<Attr Name="assetid" Value="0b81db9c-f482-4aa5-865a-d467517d9753" />
		<Keyword Index="AssetId" Term="0b81db9c-f482-4aa5-865a-d467517d9753" />
		<Keyword Index="AssetId" Term="0b81db9c-f482-4aa5-865a-d467517d97531033" />
		<Attr Name="appliesToProduct" Value="Windows 7" />
		<Attr Name="appliesToProduct" Value="Windows Server 2008 R2" />
		<Attr Name="appliesToProduct" Value="Windows Vista" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2DATACENTERSERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2ENTERPRISEIA64SERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2ENTERPRISESERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2STANDARDSERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2WEBSERVER" />
		<Attr Name="appliesToSite" Value="BWCOnly" />
		<Attr Name="appliesToSite" Value="VistaITPro" />
		<Attr Name="CommunityContent" Value="1" />
		<Attr Name="WillHaveMamlFeed" Value="True" />
		<Attr Name="zzpub_assetBug" Value="1806" />
		<Attr Name="zzpub_MtpsProductFamily" Value="WS" />
		<Attr Name="zzpub_MTPSVersion" Value="11" />
		<Attr Name="Locale" Value="kbEnglish" />
		<Attr Name="AssetID" Value="0b81db9c-f482-4aa5-865a-d467517d9753" />
		<Attr Name="TopicType" Value="kbArticle" />
	</Vtopic>
	<Vtopic Url="assets\129e033f-7c7d-419c-99f2-91053a3ce090.xml" RLTitle="Organize Event Presentation">
		<Attr Name="assetid" Value="129e033f-7c7d-419c-99f2-91053a3ce090" />
		<Keyword Index="AssetId" Term="129e033f-7c7d-419c-99f2-91053a3ce090" />
		<Keyword Index="AssetId" Term="129e033f-7c7d-419c-99f2-91053a3ce0901033" />
		<Attr Name="appliesToProduct" Value="Windows 7" />
		<Attr Name="appliesToProduct" Value="Windows Server 2008 R2" />
		<Attr Name="appliesToProduct" Value="Windows Vista" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2DATACENTERSERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2ENTERPRISEIA64SERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2ENTERPRISESERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2STANDARDSERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2WEBSERVER" />
		<Attr Name="appliesToSite" Value="BWCOnly" />
		<Attr Name="appliesToSite" Value="VistaITPro" />
		<Attr Name="CommunityContent" Value="1" />
		<Attr Name="WillHaveMamlFeed" Value="True" />
		<Attr Name="zzpub_assetBug" Value="1806" />
		<Attr Name="zzpub_MtpsProductFamily" Value="WS" />
		<Attr Name="zzpub_MTPSVersion" Value="11" />
		<Attr Name="Locale" Value="kbEnglish" />
		<Attr Name="AssetID" Value="129e033f-7c7d-419c-99f2-91053a3ce090" />
		<Attr Name="TopicType" Value="kbArticle" />
	</Vtopic>
	<Vtopic Url="assets\165d8b7c-a85e-42c2-8316-6701f0701c88.xml" RLTitle="Configure Computers to Forward and Collect Events">
		<Attr Name="assetid" Value="165d8b7c-a85e-42c2-8316-6701f0701c88" />
		<Keyword Index="AssetId" Term="165d8b7c-a85e-42c2-8316-6701f0701c88" />
		<Keyword Index="AssetId" Term="165d8b7c-a85e-42c2-8316-6701f0701c881033" />
		<Attr Name="appliesToProduct" Value="Windows 7" />
		<Attr Name="appliesToProduct" Value="Windows Server 2008 R2" />
		<Attr Name="appliesToProduct" Value="Windows Vista" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2DATACENTERSERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2ENTERPRISEIA64SERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2ENTERPRISESERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2STANDARDSERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2WEBSERVER" />
		<Attr Name="appliesToSite" Value="BWCOnly" />
		<Attr Name="appliesToSite" Value="VistaITPro" />
		<Attr Name="CommunityContent" Value="1" />
		<Attr Name="WillHaveMamlFeed" Value="True" />
		<Attr Name="zzpub_assetBug" Value="1806" />
		<Attr Name="zzpub_MtpsProductFamily" Value="WS" />
		<Attr Name="zzpub_MTPSVersion" Value="11" />
		<Attr Name="Locale" Value="kbEnglish" />
		<Attr Name="AssetID" Value="165d8b7c-a85e-42c2-8316-6701f0701c88" />
		<Attr Name="TopicType" Value="kbArticle" />
	</Vtopic>
	<Vtopic Url="assets\1833ed94-ec57-4783-aed9-4ce3a7bb2fea.xml" RLTitle="Run a Task in Response to a Given Event">
		<Attr Name="assetid" Value="1833ed94-ec57-4783-aed9-4ce3a7bb2fea" />
		<Keyword Index="AssetId" Term="1833ed94-ec57-4783-aed9-4ce3a7bb2fea" />
		<Keyword Index="AssetId" Term="1833ed94-ec57-4783-aed9-4ce3a7bb2fea1033" />
		<Attr Name="appliesToProduct" Value="Windows 7" />
		<Attr Name="appliesToProduct" Value="Windows Server 2008 R2" />
		<Attr Name="appliesToProduct" Value="Windows Vista" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2DATACENTERSERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2ENTERPRISEIA64SERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2ENTERPRISESERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2STANDARDSERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2WEBSERVER" />
		<Attr Name="appliesToSite" Value="BWCOnly" />
		<Attr Name="appliesToSite" Value="VistaITPro" />
		<Attr Name="CommunityContent" Value="1" />
		<Attr Name="WillHaveMamlFeed" Value="True" />
		<Attr Name="zzpub_assetBug" Value="1806" />
		<Attr Name="zzpub_MtpsProductFamily" Value="WS" />
		<Attr Name="zzpub_MTPSVersion" Value="11" />
		<Attr Name="Locale" Value="kbEnglish" />
		<Attr Name="AssetID" Value="1833ed94-ec57-4783-aed9-4ce3a7bb2fea" />
		<Attr Name="TopicType" Value="kbArticle" />
	</Vtopic>
	<Vtopic Url="assets\2564192f-b638-47c8-ad31-9dbdf6f198f9.xml" RLTitle="Troubleshooting Event Viewer">
		<Attr Name="assetid" Value="2564192f-b638-47c8-ad31-9dbdf6f198f9" />
		<Keyword Index="AssetId" Term="2564192f-b638-47c8-ad31-9dbdf6f198f9" />
		<Keyword Index="AssetId" Term="2564192f-b638-47c8-ad31-9dbdf6f198f91033" />
		<Attr Name="appliesToProduct" Value="Windows 7" />
		<Attr Name="appliesToProduct" Value="Windows Server 2008 R2" />
		<Attr Name="appliesToProduct" Value="Windows Vista" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2DATACENTERSERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2ENTERPRISEIA64SERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2ENTERPRISESERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2STANDARDSERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2WEBSERVER" />
		<Attr Name="appliesToSite" Value="BWCOnly" />
		<Attr Name="appliesToSite" Value="VistaITPro" />
		<Attr Name="CommunityContent" Value="1" />
		<Attr Name="WillHaveMamlFeed" Value="True" />
		<Attr Name="zzpub_assetBug" Value="1806" />
		<Attr Name="zzpub_MtpsProductFamily" Value="WS" />
		<Attr Name="zzpub_MTPSVersion" Value="11" />
		<Attr Name="Locale" Value="kbEnglish" />
		<Attr Name="AssetID" Value="2564192f-b638-47c8-ad31-9dbdf6f198f9" />
		<Attr Name="TopicType" Value="kbArticle" />
	</Vtopic>
	<Vtopic Url="assets\28cd5e13-e955-4941-91d9-fec2525e96c7.xml" RLTitle="Online Event Information">
		<Attr Name="assetid" Value="28cd5e13-e955-4941-91d9-fec2525e96c7" />
		<Keyword Index="AssetId" Term="28cd5e13-e955-4941-91d9-fec2525e96c7" />
		<Keyword Index="AssetId" Term="28cd5e13-e955-4941-91d9-fec2525e96c71033" />
		<Attr Name="appliesToProduct" Value="Windows 7" />
		<Attr Name="appliesToProduct" Value="Windows Server 2008 R2" />
		<Attr Name="appliesToProduct" Value="Windows Vista" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2DATACENTERSERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2ENTERPRISEIA64SERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2ENTERPRISESERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2STANDARDSERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2WEBSERVER" />
		<Attr Name="appliesToSite" Value="BWCOnly" />
		<Attr Name="appliesToSite" Value="VistaITPro" />
		<Attr Name="CommunityContent" Value="1" />
		<Attr Name="WillHaveMamlFeed" Value="True" />
		<Attr Name="zzpub_assetBug" Value="1806" />
		<Attr Name="zzpub_MtpsProductFamily" Value="WS" />
		<Attr Name="zzpub_MTPSVersion" Value="11" />
		<Attr Name="Locale" Value="kbEnglish" />
		<Attr Name="AssetID" Value="28cd5e13-e955-4941-91d9-fec2525e96c7" />
		<Attr Name="TopicType" Value="kbArticle" />
	</Vtopic>
	<Vtopic Url="assets\29ae83c2-2fca-4897-b95d-343706080fa5.xml" RLTitle="Display XML Format of a Custom View">
		<Attr Name="assetid" Value="29ae83c2-2fca-4897-b95d-343706080fa5" />
		<Keyword Index="AssetId" Term="29ae83c2-2fca-4897-b95d-343706080fa5" />
		<Keyword Index="AssetId" Term="29ae83c2-2fca-4897-b95d-343706080fa51033" />
		<Attr Name="appliesToProduct" Value="Windows 7" />
		<Attr Name="appliesToProduct" Value="Windows Server 2008 R2" />
		<Attr Name="appliesToProduct" Value="Windows Vista" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2DATACENTERSERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2ENTERPRISEIA64SERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2ENTERPRISESERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2STANDARDSERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2WEBSERVER" />
		<Attr Name="appliesToSite" Value="BWCOnly" />
		<Attr Name="appliesToSite" Value="VistaITPro" />
		<Attr Name="CommunityContent" Value="1" />
		<Attr Name="WillHaveMamlFeed" Value="True" />
		<Attr Name="zzpub_assetBug" Value="1806" />
		<Attr Name="zzpub_MtpsProductFamily" Value="WS" />
		<Attr Name="zzpub_MTPSVersion" Value="11" />
		<Attr Name="Locale" Value="kbEnglish" />
		<Attr Name="AssetID" Value="29ae83c2-2fca-4897-b95d-343706080fa5" />
		<Attr Name="TopicType" Value="kbArticle" />
	</Vtopic>
	<Vtopic Url="assets\386a877a-220a-4a7f-9238-7bacdee90279.xml" RLTitle="Event Properties">
		<Attr Name="assetid" Value="386a877a-220a-4a7f-9238-7bacdee90279" />
		<Keyword Index="AssetId" Term="386a877a-220a-4a7f-9238-7bacdee90279" />
		<Keyword Index="AssetId" Term="386a877a-220a-4a7f-9238-7bacdee902791033" />
		<Attr Name="appliesToProduct" Value="Windows 7" />
		<Attr Name="appliesToProduct" Value="Windows Server 2008 R2" />
		<Attr Name="appliesToProduct" Value="Windows Vista" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2DATACENTERSERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2ENTERPRISEIA64SERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2ENTERPRISESERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2STANDARDSERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2WEBSERVER" />
		<Attr Name="appliesToSite" Value="BWCOnly" />
		<Attr Name="appliesToSite" Value="VistaITPro" />
		<Attr Name="CommunityContent" Value="1" />
		<Attr Name="WillHaveMamlFeed" Value="True" />
		<Attr Name="zzpub_assetBug" Value="1806" />
		<Attr Name="zzpub_MtpsProductFamily" Value="WS" />
		<Attr Name="zzpub_MTPSVersion" Value="11" />
		<Attr Name="Locale" Value="kbEnglish" />
		<Attr Name="AssetID" Value="386a877a-220a-4a7f-9238-7bacdee90279" />
		<Attr Name="TopicType" Value="kbArticle" />
	</Vtopic>
	<Vtopic Url="assets\3eff5d43-dc9b-4777-9362-b21010adbecb.xml" RLTitle="Show or Hide Event Properties">
		<Attr Name="assetid" Value="3eff5d43-dc9b-4777-9362-b21010adbecb" />
		<Keyword Index="AssetId" Term="3eff5d43-dc9b-4777-9362-b21010adbecb" />
		<Keyword Index="AssetId" Term="3eff5d43-dc9b-4777-9362-b21010adbecb1033" />
		<Attr Name="appliesToProduct" Value="Windows 7" />
		<Attr Name="appliesToProduct" Value="Windows Server 2008 R2" />
		<Attr Name="appliesToProduct" Value="Windows Vista" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2DATACENTERSERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2ENTERPRISEIA64SERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2ENTERPRISESERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2STANDARDSERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2WEBSERVER" />
		<Attr Name="appliesToSite" Value="BWCOnly" />
		<Attr Name="appliesToSite" Value="VistaITPro" />
		<Attr Name="CommunityContent" Value="1" />
		<Attr Name="WillHaveMamlFeed" Value="True" />
		<Attr Name="zzpub_assetBug" Value="1806" />
		<Attr Name="zzpub_MtpsProductFamily" Value="WS" />
		<Attr Name="zzpub_MTPSVersion" Value="11" />
		<Attr Name="Locale" Value="kbEnglish" />
		<Attr Name="AssetID" Value="3eff5d43-dc9b-4777-9362-b21010adbecb" />
		<Attr Name="TopicType" Value="kbArticle" />
	</Vtopic>
	<Vtopic Url="assets\4229f239-16a6-4ecd-b3cf-aec03dc08cd5.xml" RLTitle="Event Viewer [Vista]">
		<Attr Name="assetid" Value="4229f239-16a6-4ecd-b3cf-aec03dc08cd5" />
		<Keyword Index="AssetId" Term="4229f239-16a6-4ecd-b3cf-aec03dc08cd5" />
		<Keyword Index="AssetId" Term="4229f239-16a6-4ecd-b3cf-aec03dc08cd51033" />
		<Attr Name="appliesToProduct" Value="Windows 7" />
		<Attr Name="appliesToProduct" Value="Windows Server 2008 R2" />
		<Attr Name="appliesToProduct" Value="Windows Vista" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2DATACENTERSERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2ENTERPRISEIA64SERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2ENTERPRISESERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2STANDARDSERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2WEBSERVER" />
		<Attr Name="appliesToSite" Value="BWCOnly" />
		<Attr Name="appliesToSite" Value="VistaITPro" />
		<Attr Name="CommunityContent" Value="1" />
		<Attr Name="WillHaveMamlFeed" Value="True" />
		<Attr Name="zzpub_assetBug" Value="1806" />
		<Attr Name="zzpub_MtpsProductFamily" Value="WS" />
		<Attr Name="zzpub_MTPSVersion" Value="11" />
		<Attr Name="Locale" Value="kbEnglish" />
		<Attr Name="AssetID" Value="4229f239-16a6-4ecd-b3cf-aec03dc08cd5" />
		<Attr Name="TopicType" Value="kbArticle" />
	</Vtopic>
	<Vtopic Url="assets\42e22049-94cb-4ace-b3d6-5f3a6ec61caa.xml" RLTitle="Manage Subscriptions">
		<Attr Name="assetid" Value="42e22049-94cb-4ace-b3d6-5f3a6ec61caa" />
		<Keyword Index="AssetId" Term="42e22049-94cb-4ace-b3d6-5f3a6ec61caa" />
		<Keyword Index="AssetId" Term="42e22049-94cb-4ace-b3d6-5f3a6ec61caa1033" />
		<Attr Name="appliesToProduct" Value="Windows 7" />
		<Attr Name="appliesToProduct" Value="Windows Server 2008 R2" />
		<Attr Name="appliesToProduct" Value="Windows Vista" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2DATACENTERSERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2ENTERPRISEIA64SERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2ENTERPRISESERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2STANDARDSERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2WEBSERVER" />
		<Attr Name="appliesToSite" Value="BWCOnly" />
		<Attr Name="appliesToSite" Value="VistaITPro" />
		<Attr Name="CommunityContent" Value="1" />
		<Attr Name="WillHaveMamlFeed" Value="True" />
		<Attr Name="zzpub_assetBug" Value="1806" />
		<Attr Name="zzpub_MtpsProductFamily" Value="WS" />
		<Attr Name="zzpub_MTPSVersion" Value="11" />
		<Attr Name="Locale" Value="kbEnglish" />
		<Attr Name="AssetID" Value="42e22049-94cb-4ace-b3d6-5f3a6ec61caa" />
		<Attr Name="TopicType" Value="kbArticle" />
	</Vtopic>
	<Vtopic Url="assets\473cb9ba-4aee-4717-a517-120371159da8.xml" RLTitle="Configure Advanced Subscription Settings">
		<Attr Name="assetid" Value="473cb9ba-4aee-4717-a517-120371159da8" />
		<Keyword Index="AssetId" Term="473cb9ba-4aee-4717-a517-120371159da8" />
		<Keyword Index="AssetId" Term="473cb9ba-4aee-4717-a517-120371159da81033" />
		<Attr Name="appliesToProduct" Value="Windows 7" />
		<Attr Name="appliesToProduct" Value="Windows Server 2008 R2" />
		<Attr Name="appliesToProduct" Value="Windows Vista" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2DATACENTERSERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2ENTERPRISEIA64SERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2ENTERPRISESERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2STANDARDSERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2WEBSERVER" />
		<Attr Name="appliesToSite" Value="BWCOnly" />
		<Attr Name="appliesToSite" Value="VistaITPro" />
		<Attr Name="CommunityContent" Value="1" />
		<Attr Name="WillHaveMamlFeed" Value="True" />
		<Attr Name="zzpub_assetBug" Value="1806" />
		<Attr Name="zzpub_MtpsProductFamily" Value="WS" />
		<Attr Name="zzpub_MTPSVersion" Value="11" />
		<Attr Name="Locale" Value="kbEnglish" />
		<Attr Name="AssetID" Value="473cb9ba-4aee-4717-a517-120371159da8" />
		<Attr Name="TopicType" Value="kbArticle" />
	</Vtopic>
	<Vtopic Url="assets\4aa6403f-d4b8-43a4-a70d-ceb7f88c524e.xml" RLTitle="Event Subscriptions">
		<Attr Name="assetid" Value="4aa6403f-d4b8-43a4-a70d-ceb7f88c524e" />
		<Keyword Index="AssetId" Term="4aa6403f-d4b8-43a4-a70d-ceb7f88c524e" />
		<Keyword Index="AssetId" Term="4aa6403f-d4b8-43a4-a70d-ceb7f88c524e1033" />
		<Attr Name="appliesToProduct" Value="Windows 7" />
		<Attr Name="appliesToProduct" Value="Windows Server 2008 R2" />
		<Attr Name="appliesToProduct" Value="Windows Vista" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2DATACENTERSERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2ENTERPRISEIA64SERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2ENTERPRISESERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2STANDARDSERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2WEBSERVER" />
		<Attr Name="appliesToSite" Value="BWCOnly" />
		<Attr Name="appliesToSite" Value="VistaITPro" />
		<Attr Name="CommunityContent" Value="1" />
		<Attr Name="WillHaveMamlFeed" Value="True" />
		<Attr Name="zzpub_assetBug" Value="1806" />
		<Attr Name="zzpub_MtpsProductFamily" Value="WS" />
		<Attr Name="zzpub_MTPSVersion" Value="11" />
		<Attr Name="Locale" Value="kbEnglish" />
		<Attr Name="AssetID" Value="4aa6403f-d4b8-43a4-a70d-ceb7f88c524e" />
		<Attr Name="TopicType" Value="kbArticle" />
	</Vtopic>
	<Vtopic Url="assets\543a7a70-4955-4628-b4ee-79f9bad741b1.xml" RLTitle="Manage Event Logs">
		<Attr Name="assetid" Value="543a7a70-4955-4628-b4ee-79f9bad741b1" />
		<Keyword Index="AssetId" Term="543a7a70-4955-4628-b4ee-79f9bad741b1" />
		<Keyword Index="AssetId" Term="543a7a70-4955-4628-b4ee-79f9bad741b11033" />
		<Attr Name="appliesToProduct" Value="Windows 7" />
		<Attr Name="appliesToProduct" Value="Windows Server 2008 R2" />
		<Attr Name="appliesToProduct" Value="Windows Vista" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2DATACENTERSERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2ENTERPRISEIA64SERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2ENTERPRISESERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2STANDARDSERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2WEBSERVER" />
		<Attr Name="appliesToSite" Value="BWCOnly" />
		<Attr Name="appliesToSite" Value="VistaITPro" />
		<Attr Name="CommunityContent" Value="1" />
		<Attr Name="WillHaveMamlFeed" Value="True" />
		<Attr Name="zzpub_assetBug" Value="1806" />
		<Attr Name="zzpub_MtpsProductFamily" Value="WS" />
		<Attr Name="zzpub_MTPSVersion" Value="11" />
		<Attr Name="Locale" Value="kbEnglish" />
		<Attr Name="AssetID" Value="543a7a70-4955-4628-b4ee-79f9bad741b1" />
		<Attr Name="TopicType" Value="kbArticle" />
	</Vtopic>
	<Vtopic Url="assets\67e1dc18-b03a-4236-8cb7-0bb191c5a0b7.xml" RLTitle="Group Events by a Given Property">
		<Attr Name="assetid" Value="67e1dc18-b03a-4236-8cb7-0bb191c5a0b7" />
		<Keyword Index="AssetId" Term="67e1dc18-b03a-4236-8cb7-0bb191c5a0b7" />
		<Keyword Index="AssetId" Term="67e1dc18-b03a-4236-8cb7-0bb191c5a0b71033" />
		<Attr Name="appliesToProduct" Value="Windows 7" />
		<Attr Name="appliesToProduct" Value="Windows Server 2008 R2" />
		<Attr Name="appliesToProduct" Value="Windows Vista" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2DATACENTERSERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2ENTERPRISEIA64SERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2ENTERPRISESERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2STANDARDSERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2WEBSERVER" />
		<Attr Name="appliesToSite" Value="BWCOnly" />
		<Attr Name="appliesToSite" Value="VistaITPro" />
		<Attr Name="CommunityContent" Value="1" />
		<Attr Name="WillHaveMamlFeed" Value="True" />
		<Attr Name="zzpub_assetBug" Value="1806" />
		<Attr Name="zzpub_MtpsProductFamily" Value="WS" />
		<Attr Name="zzpub_MTPSVersion" Value="11" />
		<Attr Name="Locale" Value="kbEnglish" />
		<Attr Name="AssetID" Value="67e1dc18-b03a-4236-8cb7-0bb191c5a0b7" />
		<Attr Name="TopicType" Value="kbArticle" />
	</Vtopic>
	<Vtopic Url="assets\7511c36a-cf41-41f5-b8cb-f4c233ca2bb3.xml" RLTitle="Set Log Retention Policy">
		<Attr Name="assetid" Value="7511c36a-cf41-41f5-b8cb-f4c233ca2bb3" />
		<Keyword Index="AssetId" Term="7511c36a-cf41-41f5-b8cb-f4c233ca2bb3" />
		<Keyword Index="AssetId" Term="7511c36a-cf41-41f5-b8cb-f4c233ca2bb31033" />
		<Attr Name="appliesToProduct" Value="Windows 7" />
		<Attr Name="appliesToProduct" Value="Windows Server 2008 R2" />
		<Attr Name="appliesToProduct" Value="Windows Vista" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2DATACENTERSERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2ENTERPRISEIA64SERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2ENTERPRISESERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2STANDARDSERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2WEBSERVER" />
		<Attr Name="appliesToSite" Value="BWCOnly" />
		<Attr Name="appliesToSite" Value="VistaITPro" />
		<Attr Name="CommunityContent" Value="1" />
		<Attr Name="WillHaveMamlFeed" Value="True" />
		<Attr Name="zzpub_assetBug" Value="1806" />
		<Attr Name="zzpub_MtpsProductFamily" Value="WS" />
		<Attr Name="zzpub_MTPSVersion" Value="11" />
		<Attr Name="Locale" Value="kbEnglish" />
		<Attr Name="AssetID" Value="7511c36a-cf41-41f5-b8cb-f4c233ca2bb3" />
		<Attr Name="TopicType" Value="kbArticle" />
	</Vtopic>
	<Vtopic Url="assets\769748f2-603c-44b1-95f0-bd13efdde2a3.xml" RLTitle="Change Order of Event Properties">
		<Attr Name="assetid" Value="769748f2-603c-44b1-95f0-bd13efdde2a3" />
		<Keyword Index="AssetId" Term="769748f2-603c-44b1-95f0-bd13efdde2a3" />
		<Keyword Index="AssetId" Term="769748f2-603c-44b1-95f0-bd13efdde2a31033" />
		<Attr Name="appliesToProduct" Value="Windows 7" />
		<Attr Name="appliesToProduct" Value="Windows Server 2008 R2" />
		<Attr Name="appliesToProduct" Value="Windows Vista" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2DATACENTERSERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2ENTERPRISEIA64SERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2ENTERPRISESERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2STANDARDSERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2WEBSERVER" />
		<Attr Name="appliesToSite" Value="BWCOnly" />
		<Attr Name="appliesToSite" Value="VistaITPro" />
		<Attr Name="CommunityContent" Value="1" />
		<Attr Name="WillHaveMamlFeed" Value="True" />
		<Attr Name="zzpub_assetBug" Value="1806" />
		<Attr Name="zzpub_MtpsProductFamily" Value="WS" />
		<Attr Name="zzpub_MTPSVersion" Value="11" />
		<Attr Name="Locale" Value="kbEnglish" />
		<Attr Name="AssetID" Value="769748f2-603c-44b1-95f0-bd13efdde2a3" />
		<Attr Name="TopicType" Value="kbArticle" />
	</Vtopic>
	<Vtopic Url="assets\7710dc96-8061-4cfe-aafb-c7fdf1c6f7b6.xml" RLTitle="Filter Displayed Events">
		<Attr Name="assetid" Value="7710dc96-8061-4cfe-aafb-c7fdf1c6f7b6" />
		<Keyword Index="AssetId" Term="7710dc96-8061-4cfe-aafb-c7fdf1c6f7b6" />
		<Keyword Index="AssetId" Term="7710dc96-8061-4cfe-aafb-c7fdf1c6f7b61033" />
		<Attr Name="appliesToProduct" Value="Windows 7" />
		<Attr Name="appliesToProduct" Value="Windows Server 2008 R2" />
		<Attr Name="appliesToProduct" Value="Windows Vista" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2DATACENTERSERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2ENTERPRISEIA64SERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2ENTERPRISESERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2STANDARDSERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2WEBSERVER" />
		<Attr Name="appliesToSite" Value="BWCOnly" />
		<Attr Name="appliesToSite" Value="VistaITPro" />
		<Attr Name="CommunityContent" Value="1" />
		<Attr Name="WillHaveMamlFeed" Value="True" />
		<Attr Name="zzpub_assetBug" Value="1806" />
		<Attr Name="zzpub_MtpsProductFamily" Value="WS" />
		<Attr Name="zzpub_MTPSVersion" Value="11" />
		<Attr Name="Locale" Value="kbEnglish" />
		<Attr Name="AssetID" Value="7710dc96-8061-4cfe-aafb-c7fdf1c6f7b6" />
		<Attr Name="TopicType" Value="kbArticle" />
	</Vtopic>
	<Vtopic Url="assets\79610900-b937-4686-aee3-3d72875d4d66.xml" RLTitle="Export a Custom View">
		<Attr Name="assetid" Value="79610900-b937-4686-aee3-3d72875d4d66" />
		<Keyword Index="AssetId" Term="79610900-b937-4686-aee3-3d72875d4d66" />
		<Keyword Index="AssetId" Term="79610900-b937-4686-aee3-3d72875d4d661033" />
		<Attr Name="appliesToProduct" Value="Windows 7" />
		<Attr Name="appliesToProduct" Value="Windows Server 2008 R2" />
		<Attr Name="appliesToProduct" Value="Windows Vista" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2DATACENTERSERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2ENTERPRISEIA64SERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2ENTERPRISESERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2STANDARDSERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2WEBSERVER" />
		<Attr Name="appliesToSite" Value="BWCOnly" />
		<Attr Name="appliesToSite" Value="VistaITPro" />
		<Attr Name="CommunityContent" Value="1" />
		<Attr Name="WillHaveMamlFeed" Value="True" />
		<Attr Name="zzpub_assetBug" Value="1806" />
		<Attr Name="zzpub_MtpsProductFamily" Value="WS" />
		<Attr Name="zzpub_MTPSVersion" Value="11" />
		<Attr Name="Locale" Value="kbEnglish" />
		<Attr Name="AssetID" Value="79610900-b937-4686-aee3-3d72875d4d66" />
		<Attr Name="TopicType" Value="kbArticle" />
	</Vtopic>
	<Vtopic Url="assets\7b26a107-7c1f-49c1-b5fa-2f6093bfa6bc.xml" RLTitle="Save Filter as a Custom View">
		<Attr Name="assetid" Value="7b26a107-7c1f-49c1-b5fa-2f6093bfa6bc" />
		<Keyword Index="AssetId" Term="7b26a107-7c1f-49c1-b5fa-2f6093bfa6bc" />
		<Keyword Index="AssetId" Term="7b26a107-7c1f-49c1-b5fa-2f6093bfa6bc1033" />
		<Attr Name="appliesToProduct" Value="Windows 7" />
		<Attr Name="appliesToProduct" Value="Windows Server 2008 R2" />
		<Attr Name="appliesToProduct" Value="Windows Vista" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2DATACENTERSERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2ENTERPRISEIA64SERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2ENTERPRISESERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2STANDARDSERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2WEBSERVER" />
		<Attr Name="appliesToSite" Value="BWCOnly" />
		<Attr Name="appliesToSite" Value="VistaITPro" />
		<Attr Name="CommunityContent" Value="1" />
		<Attr Name="WillHaveMamlFeed" Value="True" />
		<Attr Name="zzpub_assetBug" Value="1806" />
		<Attr Name="zzpub_MtpsProductFamily" Value="WS" />
		<Attr Name="zzpub_MTPSVersion" Value="11" />
		<Attr Name="Locale" Value="kbEnglish" />
		<Attr Name="AssetID" Value="7b26a107-7c1f-49c1-b5fa-2f6093bfa6bc" />
		<Attr Name="TopicType" Value="kbArticle" />
	</Vtopic>
	<Vtopic Url="assets\7c01708c-ca47-4f62-b731-4ac3f3934786.xml" RLTitle="Create and Manage Custom Views">
		<Attr Name="assetid" Value="7c01708c-ca47-4f62-b731-4ac3f3934786" />
		<Keyword Index="AssetId" Term="7c01708c-ca47-4f62-b731-4ac3f3934786" />
		<Keyword Index="AssetId" Term="7c01708c-ca47-4f62-b731-4ac3f39347861033" />
		<Attr Name="appliesToProduct" Value="Windows 7" />
		<Attr Name="appliesToProduct" Value="Windows Server 2008 R2" />
		<Attr Name="appliesToProduct" Value="Windows Vista" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2DATACENTERSERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2ENTERPRISEIA64SERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2ENTERPRISESERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2STANDARDSERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2WEBSERVER" />
		<Attr Name="appliesToSite" Value="BWCOnly" />
		<Attr Name="appliesToSite" Value="VistaITPro" />
		<Attr Name="CommunityContent" Value="1" />
		<Attr Name="WillHaveMamlFeed" Value="True" />
		<Attr Name="zzpub_assetBug" Value="1806" />
		<Attr Name="zzpub_MtpsProductFamily" Value="WS" />
		<Attr Name="zzpub_MTPSVersion" Value="11" />
		<Attr Name="Locale" Value="kbEnglish" />
		<Attr Name="AssetID" Value="7c01708c-ca47-4f62-b731-4ac3f3934786" />
		<Attr Name="TopicType" Value="kbArticle" />
	</Vtopic>
	<Vtopic Url="assets\7ed13aea-4580-4ecd-93ef-9b09b504b87a.xml" RLTitle="Command-line syntax notation">
		<Attr Name="assetid" Value="7ed13aea-4580-4ecd-93ef-9b09b504b87a" />
		<Keyword Index="AssetId" Term="7ed13aea-4580-4ecd-93ef-9b09b504b87a" />
		<Keyword Index="AssetId" Term="7ed13aea-4580-4ecd-93ef-9b09b504b87a1033" />
		<Attr Name="appliesToProduct" Value="Windows 7" />
		<Attr Name="appliesToProduct" Value="Windows Server 2008 R2" />
		<Attr Name="appliesToProduct" Value="Windows Vista" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2DATACENTERNOHVSERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2DATACENTERSERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2ENTERPRISEIA64SERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2ENTERPRISENOHVSERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2ENTERPRISESERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2STANDARDNOHVSERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2STANDARDSERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2WEBSERVER" />
		<Attr Name="appliesToSite" Value="BWCOnly" />
		<Attr Name="appliesToSite" Value="VistaITPro" />
		<Attr Name="CommunityContent" Value="1" />
		<Attr Name="WillHaveMamlFeed" Value="True" />
		<Attr Name="zzpub_assetBug" Value="1806" />
		<Attr Name="zzpub_MtpsProductFamily" Value="WS" />
		<Attr Name="zzpub_MTPSVersion" Value="11" />
		<Attr Name="Locale" Value="kbEnglish" />
		<Attr Name="AssetID" Value="7ed13aea-4580-4ecd-93ef-9b09b504b87a" />
		<Attr Name="TopicType" Value="kbArticle" />
	</Vtopic>
	<Vtopic Url="assets\7ee045ef-1e94-414b-9099-193b5b6bc439.xml" RLTitle="Archive an Event Log">
		<Attr Name="assetid" Value="7ee045ef-1e94-414b-9099-193b5b6bc439" />
		<Keyword Index="AssetId" Term="7ee045ef-1e94-414b-9099-193b5b6bc439" />
		<Keyword Index="AssetId" Term="7ee045ef-1e94-414b-9099-193b5b6bc4391033" />
		<Attr Name="appliesToProduct" Value="Windows 7" />
		<Attr Name="appliesToProduct" Value="Windows Server 2008 R2" />
		<Attr Name="appliesToProduct" Value="Windows Vista" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2DATACENTERSERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2ENTERPRISEIA64SERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2ENTERPRISESERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2STANDARDSERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2WEBSERVER" />
		<Attr Name="appliesToSite" Value="BWCOnly" />
		<Attr Name="appliesToSite" Value="VistaITPro" />
		<Attr Name="CommunityContent" Value="1" />
		<Attr Name="WillHaveMamlFeed" Value="True" />
		<Attr Name="zzpub_assetBug" Value="1806" />
		<Attr Name="zzpub_MtpsProductFamily" Value="WS" />
		<Attr Name="zzpub_MTPSVersion" Value="11" />
		<Attr Name="Locale" Value="kbEnglish" />
		<Attr Name="AssetID" Value="7ee045ef-1e94-414b-9099-193b5b6bc439" />
		<Attr Name="TopicType" Value="kbArticle" />
	</Vtopic>
	<Vtopic Url="assets\816eb4fa-7972-4f2a-9d72-c437c326e7be.xml" RLTitle="Show or Hide Analytic and Debug Logs">
		<Attr Name="assetid" Value="816eb4fa-7972-4f2a-9d72-c437c326e7be" />
		<Keyword Index="AssetId" Term="816eb4fa-7972-4f2a-9d72-c437c326e7be" />
		<Keyword Index="AssetId" Term="816eb4fa-7972-4f2a-9d72-c437c326e7be1033" />
		<Attr Name="appliesToProduct" Value="Windows 7" />
		<Attr Name="appliesToProduct" Value="Windows Server 2008 R2" />
		<Attr Name="appliesToProduct" Value="Windows Vista" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2DATACENTERSERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2ENTERPRISEIA64SERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2ENTERPRISESERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2STANDARDSERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2WEBSERVER" />
		<Attr Name="appliesToSite" Value="BWCOnly" />
		<Attr Name="appliesToSite" Value="VistaITPro" />
		<Attr Name="CommunityContent" Value="1" />
		<Attr Name="WillHaveMamlFeed" Value="True" />
		<Attr Name="zzpub_assetBug" Value="1806" />
		<Attr Name="zzpub_MtpsProductFamily" Value="WS" />
		<Attr Name="zzpub_MTPSVersion" Value="11" />
		<Attr Name="Locale" Value="kbEnglish" />
		<Attr Name="AssetID" Value="816eb4fa-7972-4f2a-9d72-c437c326e7be" />
		<Attr Name="TopicType" Value="kbArticle" />
	</Vtopic>
	<Vtopic Url="assets\8fd4aad5-50bc-4389-bdae-e09ee464e46d.xml" RLTitle="Create a New Event Subscription">
		<Attr Name="assetid" Value="8fd4aad5-50bc-4389-bdae-e09ee464e46d" />
		<Keyword Index="AssetId" Term="8fd4aad5-50bc-4389-bdae-e09ee464e46d" />
		<Keyword Index="AssetId" Term="8fd4aad5-50bc-4389-bdae-e09ee464e46d1033" />
		<Attr Name="appliesToProduct" Value="Windows 7" />
		<Attr Name="appliesToProduct" Value="Windows Server 2008 R2" />
		<Attr Name="appliesToProduct" Value="Windows Vista" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2DATACENTERSERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2ENTERPRISEIA64SERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2ENTERPRISESERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2STANDARDSERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2WEBSERVER" />
		<Attr Name="appliesToSite" Value="BWCOnly" />
		<Attr Name="appliesToSite" Value="VistaITPro" />
		<Attr Name="CommunityContent" Value="1" />
		<Attr Name="WillHaveMamlFeed" Value="True" />
		<Attr Name="zzpub_assetBug" Value="1806" />
		<Attr Name="zzpub_MtpsProductFamily" Value="WS" />
		<Attr Name="zzpub_MTPSVersion" Value="11" />
		<Attr Name="Locale" Value="kbEnglish" />
		<Attr Name="AssetID" Value="8fd4aad5-50bc-4389-bdae-e09ee464e46d" />
		<Attr Name="TopicType" Value="kbArticle" />
	</Vtopic>
	<Vtopic Url="assets\a37fd11e-597a-4d44-9507-a88e937bda50.xml" RLTitle="Start Event Viewer [Longhorn]">
		<Attr Name="assetid" Value="a37fd11e-597a-4d44-9507-a88e937bda50" />
		<Keyword Index="AssetId" Term="a37fd11e-597a-4d44-9507-a88e937bda50" />
		<Keyword Index="AssetId" Term="a37fd11e-597a-4d44-9507-a88e937bda501033" />
		<Attr Name="appliesToProduct" Value="Windows 7" />
		<Attr Name="appliesToProduct" Value="Windows Server 2008 R2" />
		<Attr Name="appliesToProduct" Value="Windows Vista" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2DATACENTERSERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2ENTERPRISEIA64SERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2ENTERPRISESERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2STANDARDSERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2WEBSERVER" />
		<Attr Name="appliesToSite" Value="BWCOnly" />
		<Attr Name="appliesToSite" Value="VistaITPro" />
		<Attr Name="CommunityContent" Value="1" />
		<Attr Name="WillHaveMamlFeed" Value="True" />
		<Attr Name="zzpub_assetBug" Value="1806" />
		<Attr Name="zzpub_MtpsProductFamily" Value="WS" />
		<Attr Name="zzpub_MTPSVersion" Value="11" />
		<Attr Name="Locale" Value="kbEnglish" />
		<Attr Name="AssetID" Value="a37fd11e-597a-4d44-9507-a88e937bda50" />
		<Attr Name="TopicType" Value="kbArticle" />
	</Vtopic>
	<Vtopic Url="assets\ad46b98b-dd6b-4578-9dae-dfac1310ab7a.xml" RLTitle="Clear an Event Log">
		<Attr Name="assetid" Value="ad46b98b-dd6b-4578-9dae-dfac1310ab7a" />
		<Keyword Index="AssetId" Term="ad46b98b-dd6b-4578-9dae-dfac1310ab7a" />
		<Keyword Index="AssetId" Term="ad46b98b-dd6b-4578-9dae-dfac1310ab7a1033" />
		<Attr Name="appliesToProduct" Value="Windows 7" />
		<Attr Name="appliesToProduct" Value="Windows Server 2008 R2" />
		<Attr Name="appliesToProduct" Value="Windows Vista" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2DATACENTERSERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2ENTERPRISEIA64SERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2ENTERPRISESERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2STANDARDSERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2WEBSERVER" />
		<Attr Name="appliesToSite" Value="BWCOnly" />
		<Attr Name="appliesToSite" Value="VistaITPro" />
		<Attr Name="CommunityContent" Value="1" />
		<Attr Name="WillHaveMamlFeed" Value="True" />
		<Attr Name="zzpub_assetBug" Value="1806" />
		<Attr Name="zzpub_MtpsProductFamily" Value="WS" />
		<Attr Name="zzpub_MTPSVersion" Value="11" />
		<Attr Name="Locale" Value="kbEnglish" />
		<Attr Name="AssetID" Value="ad46b98b-dd6b-4578-9dae-dfac1310ab7a" />
		<Attr Name="TopicType" Value="kbArticle" />
	</Vtopic>
	<Vtopic Url="assets\b7ed11ad-4b4f-43c0-88f6-43de77fc6762.xml" RLTitle="Event Viewer How To...">
		<Attr Name="assetid" Value="b7ed11ad-4b4f-43c0-88f6-43de77fc6762" />
		<Keyword Index="AssetId" Term="b7ed11ad-4b4f-43c0-88f6-43de77fc6762" />
		<Keyword Index="AssetId" Term="b7ed11ad-4b4f-43c0-88f6-43de77fc67621033" />
		<Attr Name="appliesToProduct" Value="Windows 7" />
		<Attr Name="appliesToProduct" Value="Windows Server 2008 R2" />
		<Attr Name="appliesToProduct" Value="Windows Vista" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2DATACENTERSERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2ENTERPRISEIA64SERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2ENTERPRISESERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2STANDARDSERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2WEBSERVER" />
		<Attr Name="appliesToSite" Value="BWCOnly" />
		<Attr Name="appliesToSite" Value="VistaITPro" />
		<Attr Name="CommunityContent" Value="1" />
		<Attr Name="WillHaveMamlFeed" Value="True" />
		<Attr Name="zzpub_assetBug" Value="1806" />
		<Attr Name="zzpub_MtpsProductFamily" Value="WS" />
		<Attr Name="zzpub_MTPSVersion" Value="11" />
		<Attr Name="Locale" Value="kbEnglish" />
		<Attr Name="AssetID" Value="b7ed11ad-4b4f-43c0-88f6-43de77fc6762" />
		<Attr Name="TopicType" Value="kbArticle" />
	</Vtopic>
	<Vtopic Url="assets\cfad9c47-96cc-46d8-b432-2baf661a72bb.xml" RLTitle="Work with Event Logs on a Remote Computer">
		<Attr Name="assetid" Value="cfad9c47-96cc-46d8-b432-2baf661a72bb" />
		<Keyword Index="AssetId" Term="cfad9c47-96cc-46d8-b432-2baf661a72bb" />
		<Keyword Index="AssetId" Term="cfad9c47-96cc-46d8-b432-2baf661a72bb1033" />
		<Attr Name="appliesToProduct" Value="Windows 7" />
		<Attr Name="appliesToProduct" Value="Windows Server 2008 R2" />
		<Attr Name="appliesToProduct" Value="Windows Vista" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2DATACENTERSERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2ENTERPRISEIA64SERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2ENTERPRISESERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2STANDARDSERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2WEBSERVER" />
		<Attr Name="appliesToSite" Value="BWCOnly" />
		<Attr Name="appliesToSite" Value="VistaITPro" />
		<Attr Name="CommunityContent" Value="1" />
		<Attr Name="WillHaveMamlFeed" Value="True" />
		<Attr Name="zzpub_assetBug" Value="1806" />
		<Attr Name="zzpub_MtpsProductFamily" Value="WS" />
		<Attr Name="zzpub_MTPSVersion" Value="11" />
		<Attr Name="Locale" Value="kbEnglish" />
		<Attr Name="AssetID" Value="cfad9c47-96cc-46d8-b432-2baf661a72bb" />
		<Attr Name="TopicType" Value="kbArticle" />
	</Vtopic>
	<Vtopic Url="assets\df28b174-f31a-4f18-a090-3ccbb394847e.xml" RLTitle="Sort Events by a Given Property">
		<Attr Name="assetid" Value="df28b174-f31a-4f18-a090-3ccbb394847e" />
		<Keyword Index="AssetId" Term="df28b174-f31a-4f18-a090-3ccbb394847e" />
		<Keyword Index="AssetId" Term="df28b174-f31a-4f18-a090-3ccbb394847e1033" />
		<Attr Name="appliesToProduct" Value="Windows 7" />
		<Attr Name="appliesToProduct" Value="Windows Server 2008 R2" />
		<Attr Name="appliesToProduct" Value="Windows Vista" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2DATACENTERSERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2ENTERPRISEIA64SERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2ENTERPRISESERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2STANDARDSERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2WEBSERVER" />
		<Attr Name="appliesToSite" Value="BWCOnly" />
		<Attr Name="appliesToSite" Value="VistaITPro" />
		<Attr Name="CommunityContent" Value="1" />
		<Attr Name="WillHaveMamlFeed" Value="True" />
		<Attr Name="zzpub_assetBug" Value="1806" />
		<Attr Name="zzpub_MtpsProductFamily" Value="WS" />
		<Attr Name="zzpub_MTPSVersion" Value="11" />
		<Attr Name="Locale" Value="kbEnglish" />
		<Attr Name="AssetID" Value="df28b174-f31a-4f18-a090-3ccbb394847e" />
		<Attr Name="TopicType" Value="kbArticle" />
	</Vtopic>
	<Vtopic Url="assets\e1459340-eaed-40c7-93a0-36bd933bdd7e.xml" RLTitle="Event Logs">
		<Attr Name="assetid" Value="e1459340-eaed-40c7-93a0-36bd933bdd7e" />
		<Keyword Index="AssetId" Term="e1459340-eaed-40c7-93a0-36bd933bdd7e" />
		<Keyword Index="AssetId" Term="e1459340-eaed-40c7-93a0-36bd933bdd7e1033" />
		<Attr Name="appliesToProduct" Value="Windows 7" />
		<Attr Name="appliesToProduct" Value="Windows Server 2008 R2" />
		<Attr Name="appliesToProduct" Value="Windows Vista" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2DATACENTERSERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2ENTERPRISEIA64SERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2ENTERPRISESERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2STANDARDSERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2WEBSERVER" />
		<Attr Name="appliesToSite" Value="BWCOnly" />
		<Attr Name="appliesToSite" Value="VistaITPro" />
		<Attr Name="CommunityContent" Value="1" />
		<Attr Name="WillHaveMamlFeed" Value="True" />
		<Attr Name="zzpub_assetBug" Value="1806" />
		<Attr Name="zzpub_MtpsProductFamily" Value="WS" />
		<Attr Name="zzpub_MTPSVersion" Value="11" />
		<Attr Name="Locale" Value="kbEnglish" />
		<Attr Name="AssetID" Value="e1459340-eaed-40c7-93a0-36bd933bdd7e" />
		<Attr Name="TopicType" Value="kbArticle" />
	</Vtopic>
	<Vtopic Url="assets\edec63a3-fa81-4677-99ae-b6cdada48d6d.xml" RLTitle="Enable Analytic and Debug Logs">
		<Attr Name="assetid" Value="edec63a3-fa81-4677-99ae-b6cdada48d6d" />
		<Keyword Index="AssetId" Term="edec63a3-fa81-4677-99ae-b6cdada48d6d" />
		<Keyword Index="AssetId" Term="edec63a3-fa81-4677-99ae-b6cdada48d6d1033" />
		<Attr Name="appliesToProduct" Value="Windows 7" />
		<Attr Name="appliesToProduct" Value="Windows Server 2008 R2" />
		<Attr Name="appliesToProduct" Value="Windows Vista" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2DATACENTERSERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2ENTERPRISEIA64SERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2ENTERPRISESERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2STANDARDSERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2WEBSERVER" />
		<Attr Name="appliesToSite" Value="BWCOnly" />
		<Attr Name="appliesToSite" Value="VistaITPro" />
		<Attr Name="CommunityContent" Value="1" />
		<Attr Name="WillHaveMamlFeed" Value="True" />
		<Attr Name="zzpub_assetBug" Value="1806" />
		<Attr Name="zzpub_MtpsProductFamily" Value="WS" />
		<Attr Name="zzpub_MTPSVersion" Value="11" />
		<Attr Name="Locale" Value="kbEnglish" />
		<Attr Name="AssetID" Value="edec63a3-fa81-4677-99ae-b6cdada48d6d" />
		<Attr Name="TopicType" Value="kbArticle" />
	</Vtopic>
	<Vtopic Url="assets\ff1ea5b3-0127-488d-af6e-0d9267cefdc4.xml" RLTitle="Custom Views">
		<Attr Name="assetid" Value="ff1ea5b3-0127-488d-af6e-0d9267cefdc4" />
		<Keyword Index="AssetId" Term="ff1ea5b3-0127-488d-af6e-0d9267cefdc4" />
		<Keyword Index="AssetId" Term="ff1ea5b3-0127-488d-af6e-0d9267cefdc41033" />
		<Attr Name="appliesToProduct" Value="Windows 7" />
		<Attr Name="appliesToProduct" Value="Windows Server 2008 R2" />
		<Attr Name="appliesToProduct" Value="Windows Vista" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2DATACENTERSERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2ENTERPRISEIA64SERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2ENTERPRISESERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2STANDARDSERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2WEBSERVER" />
		<Attr Name="appliesToSite" Value="BWCOnly" />
		<Attr Name="appliesToSite" Value="VistaITPro" />
		<Attr Name="CommunityContent" Value="1" />
		<Attr Name="WillHaveMamlFeed" Value="True" />
		<Attr Name="zzpub_assetBug" Value="1806" />
		<Attr Name="zzpub_MtpsProductFamily" Value="WS" />
		<Attr Name="zzpub_MTPSVersion" Value="11" />
		<Attr Name="Locale" Value="kbEnglish" />
		<Attr Name="AssetID" Value="ff1ea5b3-0127-488d-af6e-0d9267cefdc4" />
		<Attr Name="TopicType" Value="kbArticle" />
	</Vtopic>
</VTopicSet><?xml version="1.0" encoding="utf-8"?>
<!DOCTYPE HelpTOC>
<HelpTOC xmlns="http://schemas.microsoft.com/help/toc/2004/11" DTDVersion="1.0" Id="eventviewer_LH_TOC" FileVersion="" LangId="1033" ParentNodeIcon="Book" PluginStyle="Hierarchical">
	<HelpTOCNode Url="mshelp://windows/?tocid=5e077942-01d6-4baf-a5f0-f50bb58faa63" Title="">
		<HelpTOCNode Url="mshelp://windows/?id=4229f239-16a6-4ecd-b3cf-aec03dc08cd5" Title="Event Viewer">
			<HelpTOCNode Url="mshelp://windows/?id=e1459340-eaed-40c7-93a0-36bd933bdd7e" Title="Event Logs" />
			<HelpTOCNode Url="mshelp://windows/?id=386a877a-220a-4a7f-9238-7bacdee90279" Title="Event Properties" />
			<HelpTOCNode Url="mshelp://windows/?id=ff1ea5b3-0127-488d-af6e-0d9267cefdc4" Title="Custom Views" />
			<HelpTOCNode Url="mshelp://windows/?id=4aa6403f-d4b8-43a4-a70d-ceb7f88c524e" Title="Event Subscriptions" />
			<HelpTOCNode Url="mshelp://windows/?id=28cd5e13-e955-4941-91d9-fec2525e96c7" Title="Event Information" />
			<HelpTOCNode Url="mshelp://windows/?id=b7ed11ad-4b4f-43c0-88f6-43de77fc6762" Title="Event Viewer How To...">
				<HelpTOCNode Url="mshelp://windows/?id=a37fd11e-597a-4d44-9507-a88e937bda50" Title="Start Event Viewer" />
				<HelpTOCNode Url="mshelp://windows/?id=7c01708c-ca47-4f62-b731-4ac3f3934786" Title="Create and Manage Custom Views">
					<HelpTOCNode Url="mshelp://windows/?id=0234cfde-93d4-46c3-a0dd-f26c6273aa26" Title="Create a Custom View" />
					<HelpTOCNode Url="mshelp://windows/?id=79610900-b937-4686-aee3-3d72875d4d66" Title="Export a Custom View" />
					<HelpTOCNode Url="mshelp://windows/?id=0b81db9c-f482-4aa5-865a-d467517d9753" Title="Import a Custom View" />
					<HelpTOCNode Url="mshelp://windows/?id=29ae83c2-2fca-4897-b95d-343706080fa5" Title="Display Custom View XML" />
					<HelpTOCNode Url="mshelp://windows/?id=7b26a107-7c1f-49c1-b5fa-2f6093bfa6bc" Title="Save Filter as a Custom View" />
				</HelpTOCNode>
				<HelpTOCNode Url="mshelp://windows/?id=129e033f-7c7d-419c-99f2-91053a3ce090" Title="Organize Event Presentation">
					<HelpTOCNode Url="mshelp://windows/?id=7710dc96-8061-4cfe-aafb-c7fdf1c6f7b6" Title="Filter Displayed Events" />
					<HelpTOCNode Url="mshelp://windows/?id=67e1dc18-b03a-4236-8cb7-0bb191c5a0b7" Title="Group Events by a Given Property" />
					<HelpTOCNode Url="mshelp://windows/?id=df28b174-f31a-4f18-a090-3ccbb394847e" Title="Sort Events by a Given Property" />
					<HelpTOCNode Url="mshelp://windows/?id=3eff5d43-dc9b-4777-9362-b21010adbecb" Title="Show or Hide Event Properties" />
					<HelpTOCNode Url="mshelp://windows/?id=816eb4fa-7972-4f2a-9d72-c437c326e7be" Title="Show or Hide Analytic and Debug Logs" />
					<HelpTOCNode Url="mshelp://windows/?id=769748f2-603c-44b1-95f0-bd13efdde2a3" Title="Change Order of Event Properties" />
				</HelpTOCNode>
				<HelpTOCNode Url="mshelp://windows/?id=543a7a70-4955-4628-b4ee-79f9bad741b1" Title="Manage Event Logs">
					<HelpTOCNode Url="mshelp://windows/?id=ad46b98b-dd6b-4578-9dae-dfac1310ab7a" Title="Clear an Event Log" />
					<HelpTOCNode Url="mshelp://windows/?id=07abe800-89a9-43c5-a7bd-84304a881e7f" Title="Set Maximum Log Size" />
					<HelpTOCNode Url="mshelp://windows/?id=7511c36a-cf41-41f5-b8cb-f4c233ca2bb3" Title="Set Log Retention Policy" />
					<HelpTOCNode Url="mshelp://windows/?id=edec63a3-fa81-4677-99ae-b6cdada48d6d" Title="Enable Analytic and Debug Logs" />
					<HelpTOCNode Url="mshelp://windows/?id=7ee045ef-1e94-414b-9099-193b5b6bc439" Title="Archive an Event Log" />
					<HelpTOCNode Url="mshelp://windows/?id=05fb8bc9-aca3-4bf6-83c3-1834297ccf49" Title="Open or Close a Saved Log" />
				</HelpTOCNode>
				<HelpTOCNode Url="mshelp://windows/?id=42e22049-94cb-4ace-b3d6-5f3a6ec61caa" Title="Manage Subscriptions">
					<HelpTOCNode Url="mshelp://windows/?id=165d8b7c-a85e-42c2-8316-6701f0701c88" Title="Configure Computers to Forward and Collect Events" />
					<HelpTOCNode Url="mshelp://windows/?id=8fd4aad5-50bc-4389-bdae-e09ee464e46d" Title="Create a New Subscription" />
					<HelpTOCNode Url="mshelp://windows/?id=473cb9ba-4aee-4717-a517-120371159da8" Title="Configure Advanced Subscription Settings" />
				</HelpTOCNode>
				<HelpTOCNode Url="mshelp://windows/?id=cfad9c47-96cc-46d8-b432-2baf661a72bb" Title="Work with Event Logs on a Remote Computer" />
				<HelpTOCNode Url="mshelp://windows/?id=1833ed94-ec57-4783-aed9-4ce3a7bb2fea" Title="Run a Task in Response to a Given Event" />
			</HelpTOCNode>
			<HelpTOCNode Url="mshelp://windows/?id=2564192f-b638-47c8-ad31-9dbdf6f198f9" Title="Troubleshooting Event Viewer" />
		</HelpTOCNode>
	</HelpTOCNode>
</HelpTOC><?xml version="1.0" encoding="utf-8"?>
<!DOCTYPE HelpIndex>
<HelpIndex DTDVersion="1.0" Name="AssetId" /><?xml version="1.0" encoding="utf-8"?>
<!DOCTYPE HelpIndex>
<HelpIndex DTDVersion="1.0" Name="BestBet" /><?xml version="1.0" encoding="utf-8"?>
<!DOCTYPE HelpIndex>
<HelpIndex DTDVersion="1.0" Name="LinkTerm" /><?xml version="1.0" encoding="utf-8"?>
<!DOCTYPE HelpIndex>
<HelpIndex DTDVersion="1.0" Name="SubjectTerm" /> ey@!FEO|H=TvBRQ(RJ ‚EJIE)GS$PQ"R,Õ}"2<\zy{1ta73Ded $q͐$F@4j@А` H@Q]P@5l5ߕWۼ>̱<\o<]\ _So
TCھ}^3E?CfnG/o
C}^N@[i\.yzھvׯۻ%-<dc[]^u0/omA/p(m
x-mrDׯۻ%_ܷ7ɿ6?.z&_[ھu|V|oẍMeqnN`>}n0!Ο%?U8{g7'!{=oyc_[;:8]Fs3y9F舙__uz1[2wzΛ~_~t_
?~Owou_⃻υgǺʇ;'=yznGWyw|	oxr͞wO7_ݺ~ߚqvi\6#~v'ڮnj&j\)4OrߏBDvN)V+^ŇږN&/vgMx:\<jm[˵\&n'7[gP]H׽'t(^({׹y=zJo^JN'mP:V'7N2Oذ_}
{[[zgslOρgc}clzV_S.īsZsw|\?zRF:؏[['cy6SltC3_>vӇ=g_sk[Ccln=۞Ա9vz;k::Ǧ{5g:v4WAη:$=vcl_czXǞ}qk;k^D[׾;sno|av >uҕok~ok?}[kG}[ZS]o~k}o}k[gos M9[׽vsn߾wn-wxܾ}snݭﻞwwm8~ި^~
w+xܿw~sn
ݛU]E
sU[
ʹWK5c~g'j]m>[^|kv]}U~ͩn|]_;;?>__CA>|||vG}R|M.R}~|Ʃ|ԿNԂka__ocse__w=_/ԩV_j^_qf}v}RڥyqrGF>=w$r!8uۥ7}}8n۶^]V}>S͵pﻜ.;aγ95qه>pC<
0Q>xG<xP={3f<1lr9y'?ק:G3)3:χ5-ߋjk7]wϝ$RWOuo汿}Rᔥs:tVN)3:tθJ{t{JtZyҝ))3=:Ss=S:{Jt޾Jg{tg{Jt^N靿)9)y:S3>S:vJ,O|OΈy)3>:+S.;tf̍OOΏN)9ҝ%)yS:3>:WS_>S:3>:gSJ|t|JtΧJ|tvJ鬠OyҝC)3>S:vJN)3;tr<OΤyӝS:}Jt.ӧJg>}tvS:3>:SJwOΪ鼬Oyҝ[)3;tgwJN)ҝa)9S:xJ,Oyҝg)Jg}t΄ҹS:s<t>ۧJgxOη9q)9ҝu)yy)<t^ι:;SIJg:O,SO/88ox/^x^/ŋx/^x^/ŋx/^x^/ŋx/^x^/ŋx/^x^/ŋx/^x^/ŋx/^x^/)or>
=w4Gh|4E>
#ϏhXϏhx?AGCPhT|4C?!hXd|4]>
ah?Gҏ!h*K?!h:?Oԏ!h4|>
gGCp4|?UGáhh^>
oGC!hj>
s:hv?^׏hw>
CG!8h4|?dُah~4
Bh~4
ӵGC!h,}4>
Hۏ!0h\}42m?æGh>
RéovطyG0``00``00``00``00``00``00``00``0/ϟe[ޟ(o8?uק͜U7-rTN>SV_	Mq)x9|z8r+ϧwor=;ht<
b1F#Ĉ1b#Fb1F#Ĉ1b#Fb1F#Ĉ1b#Fb1F#Ĉ1b#Fb1F#Ĉ1b#Fb1F#Ĉ1b#Fb1F#Ĉ1b#Fb1F#Ĉ1b#Fb1F#Ĉ1b#Fb1F#Ĉ1b#Fb1F#Ĉ1b#FhH]HHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHK
Tbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbcs!d2!CȐ2dC!d2!CȐ2dC!d2!CȐ2dC!d2!CȐ2dC!d2!CȐ2dC!d2!CȐ2dC!d2!CȐ2dC!d2!CȐ2dC!d2!CȐ2d
]%_31~u_us]OGv¸p.\…p\.¸p.\…pqp\.¸p.\…p\.¸ph\p.\9.\…p\.{k\.v
.\w15.fp\.¸p.\…p\.¸p.\ƅwGr>FfL>awx>PwޑՇX;w>'3#}Ϟۆ}>xq÷$}C޳qx4ᙐqp᫸ŅO\4M44MM44MM44MM44MM44MM44MM44MM44MM44MM44MM44MM44MM44MM44MM44MM44MM44MMӧ=qGV[[mVmV[[mVmV[[mVmV[[mVmV[[mVmV[[mVmV[[mVmV[[mVmV[[mVmV[[mVmV[[mVmV[[mVmV[[mVmV[[mn<|NH4MM4ÝM[44MM44MM44MM44MM44MM44MM44MM44MM44MM44MM44MM44MM44MM44MM44MM44MM44MM44MM44MM44MM44MM44MM44MM44MM44MM44MM44MM44MM44MM44MOi:ګjjګjjګjjv
V˵[mVmV[[mVmV[[mVmV[[mVmV[[mVmV[[mVmV[[mVmV[[mVmV[[mVmV[[mVmV[[mVmV[[mVmV[VH|M44MM44MM44MM44MM44MM44MM44MM44MM44MM44MM44MM44MM44MM44MM44MM44MM44MM44MM44MM44MM44MM44MM44MM44MM44MM44MM44MM44MM44MM44MM44MM4̷5߸7ąp.\*FąmV[[mVmV[[mVmV[[mVmV[[mVmV[[mVmV[[mVmV[[mVmV[[mVmV[[mVmV[[mVmV[[mVmV[[mVmV[[mVmV[[mVmV[[mVmV[[mVmV[[mVmV[[mVmV[[mVmV[[mVmV[[mVmV[ծ34M44MM44MM44MM44MM44MM44MM44MM44MM44MM44MM44MM=M44MM44MM44MM44MM44MM44MM44MM44MM44MM44MM44MM44MM44MM44MM44MM44MM44MM44MM44MM4MM44MM44MM44MM44MM44MM44MM44MM44MM44MM44MM44MM44MM44MM44MO44MM44MM44MM44MM44MM44MM44MM44MM44MM44MM44MM44MM44MM44MM44MM44MM44MM4n)iiiiiiiiiiiiiiiiiiiiiiiiiiiiiiii,M46M:hî9gѧ5_xq6!ppclf؛uvuAҚ՘8FC[JW[N5oTW~;*3:s=>{)x$]</:_=xt5=IxifښWٻ" ,hH7$e.aCcUR.;$wc$gB,Ύѣ3huYRf
`-&	JOQH=|Xl,F936Ø
؀~d=.:tg	;H)k<a>
\w$ru߸FBfmjڛW{ﴋP#)$Ŧo]7 K~=}D]E~yC*-}|?i]
GۅvӦ4VO}^MC{pG!(?HAÁui'ܐl燉OAʆ	".V7?
U3'v_$@pZyt<o>B^2kI;->!\!3Z@0/βa}ƲV6C;go.n_߲i9܅u'}>K(	XF	l5tmP
6+w
\Y+V˚7
ҫN%~$Ju]̖~PGB/˯tkx*у{RWT!tf?+,PbBF+	Bd]>? A_iٸW`h>].-i6D[r?akf{&r>TCLF_bK܁4]hWD\)Z`5$>Fq۳=Tc^a!B#Nhr,1uqX1;7EO'9/
uDˁBjFkOIŬ}`,o].E7OZ-Q~wAT^gJ5%m0P~sP2ԣlXY~ak2"0&J>TєQɴvVӔoߞElXKƟE~"5"'НYWuƛQPB9Z~";oWZ}YS^Y㞵$hHV
ؑ.hD}$p~b4>
%Ԗ0ID9!Bq$j#
wD?p9ێOi_=='aKfnÖZn{hM$F"(qEO<iHP)2=[n~Ʒr?M3K!kSH@!Q0e6֣9|y%ى!`Ui^U*7`q=7B][BGTsyw$rѢ /S'2b_+W*C}=wA@?-{^y]s}d#ER$kۜ\L_f$~naE}
+!R)d2'nv?b;[`+Gp,~ttm?ævTԴa*x2	uD n<R/||zY!(YiKkzZcmZ3V9T
wr(@IfX˨췂8\0d@!GIdT`Ӄy$(XJ黎=e\C[d?_ox˒zxDe@ʹd@Y8D:xwRQyky>/8̟t)d:@,c'GzVU!o-r0	2WaJX=&)hjTyľ7UUGNr:˂kE׀*TJZXng̯+sjbi7̧oYԨBbBDa_JJ=%VZA$g
Krknwg/"c^m߱n4pKW%d`n']j0VKz{u9Gi)7z.cc0VV!2-xZ>j?åı~=R4Pv:LO`yTވFdZLΰG+FonltB$dFLfWx%Qq~jtM&`H\nX%aQ6	R3k9t?[ Czwh!|,@yRz6$`#up;pah|h44{
ΥʅBWDA4H2QOl	07KAbmmD
dߦwOo5<z]>}.˙d~xa|^BaO0h3H5H1O󟕣hR*K	V1.RûbW)ywt%Y3C***nJܤƪ{F{=ZMV~BAC~\ޒ9,abi8덩]Q%1XQ2[6->ը\/1I$Ⱦ	\XZoJ(VK%h
YK1U%&ׁ1}.o}xve7Rzk9+$wd1w[?WߋYz;f{c5/x#Ƿ6A~jXp'LoBx׼%	ޖ=WyӚ{?/u7$/Z9E0q]v@aWXkY?pU^4ިv|ܝ^F/K1P`zH|.bLoq_\ʈֶm1:7;GJ	"^G};63^-`:_׉{d:
Ť|e|{sB߅=SwEe,`N\P"-fҕb<)a"DB*iZ=+d>6Z4{SE=Pymt6@aGi¸OA'/$H*^^NuX"TDZ)hI'~KhUzWo8_p썸W֌}	ze2l\>Н])Gdg8SzQ,pTyޕLv}"NZ܎H~
	"N=T들?p K1X>ډDW0Nu2FZ]}#	mw&LkCi$s>"#Z.+I up{߱了E84:<LD`G
NL[߻FE7.rO=(RDsM闶煼7E3bqU!#8XB_TS&RVp.~BIT:f2BFjjVNNZJ?zo3ޫNWϡ,J+)vfY\hڞ2lc?6M+
ʳZfxH! 6+Q43YEϒ}&BE߳ŒrfJ?Çt'Sb -Qm"Ye~ZZ_0FJsԡ9tDr]m<Gߍ3:Z܊)Uќx\&-)l$
`mx=Ϛ~'=mezI:~W]yJ.,[{Sȝ]mo2ZFIv93·W9{I$IO'<_9"Kynjмcj7l Ψt`Ro笠P2!{@q\S6oDG.ך{Fsc)uIQM(.4;;h@yO
34ND.-33r$D9ᆴJ]i\Ε;FǍ \@=z{uP|GiR6׀%Q2[{Jxh<e
NBcULmv,V'RU]p'C^$FW1^T"2kڐ廲wOE#jkd9q*բb
b\5kQU'zcU^SwT~NHPzF)N-kf>3ӗ[)эV|٥SЎ0!(.M!e(8lRKq0%?Gũy'{Sg*XTd#wF#g
+#"6ӯGnVy8(L,?E	9+4Afwr+?γk0ogf

4dI~֌.?YӞi|
Xax^[iJvX0JP=凉/ik&5=NKObph
>KMߞ,L56C;7Kz.Z&Vϒ-Xvd6y.CM$گ,棼2P^v:]-JR)ϗD6Ȳ|ݹ=G[);6JZ#?XP/-Z93Q>Ib1ados?MSx([6>^B0kG7u)jmW[ECo u<e"PG!{`d*{~M'z/fJHl;C.W:B&O[B
5=j8IXd5f=:oڵ26Z0Q3UJYQվt[P:y|GHΔN^I2iXqjD}ť|-YmQ9feW:c5}^BuMu_brۀ\gK;|QZT1vm%s7Fa
cFF-nw1Ł8Zw,.* UWzjO`T!v>/dƋUt$!	n#_V#6eE _D{\a̙jMt/~#ҰH#Q.$5CGұdu`|Eq,a]1Kw!Mj<!lvP:7wRFkz3";Lڝy4uU`f4ͤ;D<<8T{ϙ'#/9zfV-
B<|Xh;!a;͌4_y=@w`(ُ!<vG'ߠUZ$d.ZɄ{^8xϮ*qJz&^8j`,`8\\
[(1ʘerRPL٦&@NNL$I#F(2k RP1!J3-Q~H"+ZuD{<OOAWʽ= B
QD!(BQ!
(DB
QD!(BQ!
?DlLtj]D^
8#fKպEee4Kf`WnXU>z+-%-DxqW34JP&/RbQBW?Y29s!IhW=[NӁ)t6z9"aQ,Fd%rYDpcVf#>ޠS& Lgqte.q/#{ir&kH%hz{c
+dϼ1Ҷxx=aEGW&FXڧJ}fkeo`I08DR@-#Grߞ(P'XLOOԉ})0Z83Cj@qȢB:#W,	`jMl/0Y̭xupR?ai\OE_-h'*hi|5nҜdW("E]U&3q̔:J#ج6ZZ'Qm71pU1S>,9'Kr2b5yh-#4kD˧@VʅR*P߸'M]`2D핮j#`zDB\|x@?Ɍ9
k ԚC$Xz|9[UM}>I*zxD%n8:wrvq,Ȋrk!ubo=no)a2%;1ܓ?sfw9d@g;<Ʌ ﯥ"Z83x@g,um#Qǒm20pjeү0opn+~wGq{p7jBlΐ<~\%#,7;#g57lCW;=^_Z:GUp>q4BZn4pؐr]/(Quvw{yO 0wp 
1L(=Hf7k'I= `Qo_,,_>K%
(u">6dbTxƎ^ƅLq1c\M E>ï'.B`\᱖QZ$v09iΠA|X_8`{kQ=WQckݖW1ds_5fS4']4aGdTP]f}^%x+`/ ?ϥ
;\/4蓆wP<3z-ÖȤv6E8@	rzI<)@8zYf#=Mj(.ʽYc*9nw4u@Bc̩+6oaXU'tWQʠ?׮q,kйʾß*V=\O$>/bYevҺeCXiϢ+s<+R[o\hGe>X'l?0\|	N0IIsu,i-t*Lz`v(N-CڜmkХ%P_TEDfToGLYnm)xüJS_Dv<Y~`a2u2][v(m˭ֆ2ir
sOOoe~H!«l/}&u6ltk)B5O|1cD#fx3q('{SI~\NcinHꠥ,V]vw=/֍#ۊFo
A~h\1=վ8FѢ@.(4Zyi.`hE9Hl#N9Ac&f5pk͚=W
/LU/%mhDVT'74	vtT)5/vUK~nE,_ƏF^ߵ M0wSPZ,"	Sj''Ejfg -zLMίN`%t)譙x6b]\P28
z]c2!꽵YfCaiJ/lHH;*(<Ag$0ybmggDWu
:a1L\m;
>ݎs"洊y}bϳ<NSH2W0rE13UeM#tE:nV6b$CԬd12BNx߬}ݒcn(cUQOނ:
#MSݚLu}!55A;+)e͆c"xm+RspŶp_?`X&mjcgwdqPe_<Ěz=_OqzH`Eq*ò;—kG/-󁭿tt_"dn8f;k"V^N3OEĄD{DPқJ%0ͶsoBhwW7+PTVIw-+f|¡t%UBj\(%F#km~XK31	>nIX<hÜŔOEAJ >_&tJ}
^H*6{5!&Mߏ]Gok\"WrǡI]t	F I5=ڣRgE][&Yr#Up؜pI̅}P)&8	KGH׷)^@ҹ
@ٰ2;KK_)SS9r;GIʜڜ
gh$DrvǷ0y)@xv[ƊWϿo*^Il'a$w,Hi_'c^}no>.G2;/+zઁc4+Nuk"őFSEQg`8JeO#D]WK^*قA-/䀌e
Q;e=v/A+tz[.]2WV]/%*=i")"K藕9M
w]Ň%>5`GpmMҶ)>a1`lLOyÃyZ;-DF]֤?N,S~A@ڽ;6e+3ml`9Q֓.,=B8Q7+hع$N7
nz3.79uq(nKOzr!\=RV"|oU"MtU<Zqn<LR9prrW_'Nn^i3|Yr|$nT9IULvpq4:6|;vubmRUÑ c@(Ϫs+sowX%&)/a }Pn;h"t!6Xm
\7G#sd#,dX]X91[{eDz7@~N2vIKGG,AGq#c(HTlg]Dvep%E%WxW.2L`MWB奲F}GAӸ]D(Ai{YS!<X`EJBuG0JgW}^V}a*$
y>,ؕQ 2O!b팘K^O"u0In	Ce8eVuD"ۑS29wĝZҭHp\d|ЬS[ljJ:&0>Ұ)D}OVK;Jf9\r>W
P
?4Z]kd!8Põ\'⯃ߖ:,:27.&z||B'UVs@8a(3h9QJrʼns.յDZ#;KӐYz|V* :K򈋀̅/τqp#˳0(kEtpG`Tp|yC[xQ#iLAȠ{j`A"RY,^S{=e-d^TLjb&캍{QaХ¦R$l&u.;ܴ4|9.)Rk}
NR(.7vbO]{\EtliYA
;S1XL2,ʿxB\p21̷fwƊ.L_o?I7P&콻BH8C]e_pgyzGg4M
Uxselb]5kTh7'ONc
P+q
Z{
\HSk-&ܔbf
6oJW΄V{tTj313h4ѽ]J,z
v.UD0sSjzmcRGڳӇ)Uҹ"f*		1[K
-ţ\;[fñF8-˱%!nrk)8!T:4Y*oC\xĺ_&yyWY5nj6W5|9!O`U2\10ʗť̥%FɲYb+
ʡej<E져TLLK)d,#>
"08J@H@"P/COvLrr~}#怯8}qغ9
+5ÑEwm
¿u_/B	
AE#_U#<CNG2ӐY*d82\N158&gSU
1BC1vMŽ/Ff0)}\Jí~SFa{䯝>o\}
	_eR/;%曒 ##
I?RpCe5hG*KU2%<ŵC;,GuCJłNAx>vn[gy[Y9jeWI3dj֮O`{ ?=p/<l^x	2=h*~8nz
cS(3v!'^KEFE#7@W,N;[L^^fa'e/-$6H3f9u
"&@bU~1JJ;lV䵰JP9hMjٯq͹覵i(΄O|VjzK.?O+L}rی;1[pJ=L.Gfi4bvْMmL[+:]E
2_P9u3,!\wH}O?<E_\y\l$l&D䢥mVL_5!	<,OzuʁgиEQݓ*zT@5`!&	睵}[54G!/[3uXfX7O$q|Cs	"8*{v-|v	 wmPD=Z'W>ϸhWkTOk]Sه~}Ct2TK#ȳ.h-8LcAU'ev= CR{!!IS0Xs]ȟAj(]YM\4mZweȶb<Bg`0nO4l&3Tn8ݧ=9Wq1
-4Y?R7|,؂MNg\ն^ϘpθӶFL*PM: XjjH9@Oo`P$F	%=|Q%B{R'f|0^	۪t[H.7nYj?5xbS䊾n7Q x52PM쮯hꆫ׻N_W,(ݫzBp^U楄CKs"1	S<ih4Jv貙cَ>fLN0s'$:~>)ʃLWC'dUʡz>߳)pwX?5`k3{]CB*{H%^3NRupoV^T	Pl%'Zs\()'9V>=Xg<m<Tm#j^ZMRJP1xݣڕn/yő\K/2
NJr
zfUg.%
ԩiuVH׺
_pe
ȍ[69\Ӣ,\Rm
RӧlRo8B@@OW+ZmC3&3Iګ4-6	n+ҵkG&Мfؚ>
Ry}?S5^rl{ʀ<}$<y#_\
jrp,bm⌞Km5Ʒ_usUXKQ9K֋o)7O+	?^$i--!K,9)SVs񐤪;ApK}}sqHh"7kV&ej9ʡqTϹ $7cio5/_hjwt{4.BPPBH-1i	#/Eqw^';=P8%])]8`9\tQb?p{F}o	h'>Hfci,Y0\w_=i`?}IZ_%2mW
UܨiȔnr+1coVV!H9>Wo0*0Xxj`8Gp$wdwf9\UK
64}lGD@bsY&=zȎ	h<k(ji-2Hq$8˨*UeGޭcSA7ǵ|_#bJΙ4o&gWuφNV`|9YY
mPfnnZ{rf'誨Ofmp)أxz-#^rEQ7XXjB6;r032k!03NG̵ͬ<VFaJv
3?4D %sAԽ	7_*m?%Vmh7rY㦺T\uK,MK|vY3!V'Ӣywr-+,|X QЏRՇzgم&1/iHnz(ly`KE
e1\7>TvUȚVUS2>dxl8u]<;vaG6TYVUImYr(+JrǠT.p)\h;mrT<	=<~@D.dϊ:A{Jatw >ۚrcz{L{xWcȴlהLrd\+eqȟsrh	
)S%`H.&i!Tm]f\1"od\j=}ͭyMDy~`_{wUwYکO%cU]`|A,[g	R6ZT'hዜΜ[fs%>_k:;61[RĖw'q&@ty)>lfXncz4>Z9Mn`5<fcqap>E@/鳧D+&td0yeq78qzqSsw/x
nt$-&R"M<yLw_CR铬%rrhp
w@x3g
vxqi"^5*cS݃ڸEߠMNnK䁈.;Ԋp[X l,nfoBvm94,1&hfPYxJ{jun
kxaAq񙮱չĆ~_Ʌ|iM	@{%zĄ(ع'
g0"rdVxdZڵ~OCQ@ɗ𳙳p:&奍,E/צ05ͮy\dc1;ԋd|+`gS_>lp;)ijdIrU2ڰ)5]Q*:@]@2STkk%f@	\oq,!e0p,mCp1
sK|Zz\pn׻	f&Sa/|nc=<A^>jPM0hl3@G/d(iǤC³;SO(
e٪ׇeחbiz~6}6֔o-D>!耿R:;엾2kݴm笮Uko8%uODuܝ
C\	@`-s'vi\u%BH/J{~ዘ9f%
:sIko4kD4FRE]4~M}QiRU>a%.hfp!X#-Y
W-s!d44ii'eFP8ga?9
+&=&`aB%54^ý1Ⱥyƿ\8hT\'m5̻Epp*ga)Ut~Z`߶SwqB?W+R dN[	o`95K=4}z6rjE1Ok}mR.801Zg)IJD\br`"%Ocv+I#Qg+"hHEMk9^OiRtN\I< @zʳ8SG7%~GsA6Iy_`6G#"+cfP!{{9NHs
hf!AV!>/`>2-s?TZ[9o{7"DQrP<{%&aQT7`)ȕ/
#Fp!g֢$sAg߫8^;y>@3%RLɟ33Eeu1C0L0/`g%B)4Y,B	aYd]8Sw)AT(NLMJ%%O)9;"rp!Wh5	
18Ɗ1 M|
Ӣ?V}[+5zoc'_hk~b=c_A_\Ou~#U$\,jga^]=0؁}蜐5E[d>?0~%m%G^1.$a[~h3LZωW3!S9ӏFR^eJ,,
ꃾ@ֆޕPP?nĕp&ባ'!kyQ;eT=lE:/
u/6Ǝbgt+4@]6p4}-AȢ7ml4G]~4[#h,^+E#	<&Ƙ{AxutÚgۤ
4e{fdr3k9Y:ٲ3x%EV2j)/${QiD*o4ewtIyZVP;ͥ2u&UE9ȉqI/@
\XQK~-4r]`L9@KӖ-`wulzOQ~n|KMr/2I3\o]DԎ5Ⱥ6QJ0M~Ο/,;<Ș.DzE~]):Flr՗QPp#1}Gg$O_uɡPxVg=~"Ed13{,+
̕j4#`WMHr|X8bY5L@K\OOFeǾ/}RId}6/+o胣G|'^&`1/ԺQu
{O?7	PYc
j+&\CFc/'b	Oŷ]Tרc8NNe6a~	Ud]AW?s)a$(#=p\m8"X#F2c~DDcCwtC^_
p_1ǔJhS^j'W#@HB`m])v/InI^e4"I:
uWɥp/lw^AuP]^=)m_ݣ
;xi훷f{w-%Osw\HʟF=j޻G{IA8sl"Dqe\]7z^o*Fp Ӿ$]XXVtX<jyyn)ށM"dyJP9;Xo{[!\Ώ4:,{
|v4D)X<Ӛ8FxܱZ:!~,m9P[@RH!zvwxѦz@.cl;j2nOjA-Z |	Kq@ߑX~4gB_Q6CV7_oLXڟ'9X]?P!_hvV桚-6,Ua;rZGVfsG<Y13_LwGp<H!K$Aj}(ꈈv[lelKsJhPD,oG
d#9qcƋۧ
"dBQ>xlY.^7oO}ȵP0$K/G-dĐHV"FfNQo=ebny[:k@@%0Io5,j:X1=O-1̇2ticΔb`R:Һ^?Yâ{k*pGwY~ %ӛ*渽Lf_b\Wj;O\Y!fUPΘ3Y{T?(ukт1Hp8Kb6;OkQu|47NиTmp?`t/+f,aE?^a#J 7JR
Mk3,lNu1&*Ae{LMζƯvukC%SNSI=/7nu+;cg^3Lլ҉ccl
T\U8פA:a%P_{8~x;Z?R*^ʉlT)"jD0l[
R˪#Gk
?
>!/}RCTiG<w\kØoж*-Y^_CP_*Ax9;O\T.6,?ώ1ܳ9]~lyjU~۴pУ+C(j5ڵ<T
.K\}p3MղCε`7]$iC 4'Rm}|T$ƅYEbMe4z~B.]s]1GmlU+Uf^|BNا3)vjZ@N}&5BBԬЧ~m-0w/)gEQQ[u{PczU}n2=Ija
Ć202
ksMG8GK:ރCA	嬐I+?'t6^]|צW?v5< 3!GafmJ(:z02g|T*34Ẃɺw'm~ڣ.;*":mum}H^醜u/8nrqI|fx8kfc3	u"2?UP
pxeMI5@X{wb0>	>90GWsAPlwaGPItw0tmY0rIAS\3meI`G	suvH@,V̯ɇM찎PIXr
] pQS.DQ.i$B<*uF[joO3 A*wJmRS=S7p'8ŭaG!H]m=vd9pTojrjl%)<+=jG$4{\&wiUEŢ#eŨLnOVr[}UͬwVX"ڽv!;0h?-LtHt%D?	q\3x1e34xħ$q
╔b"Z_{ҙЖp,yraeXa:5uQby	
|!ۖ+Q[pl5iUv'E6$ܲ7ʲo%>|u\>X2xa%zmBAInbW&ܞ0X6Bo>B8
ҰXH ofNq\ּE?(fRdHgR37.W̴ćg|&HUd/"鿡XphKF<&.?hSqy64J4"/9ZU	NX_=*h<VJUcdG[
G4jN+幙2B<L~RX+nHqKg$QAuw``}r9^@Ћ#,XrnJJYы&4P'^+:pWT=(w6GIӎf/x5}EZ<jExDc\وV^B)qgRo>KG\0Gz]CEsO5gRTA5Y̸^L2yY%u͒NdaWdP$lk$ڋ`mA}RϵԈwʮWw
#Xew2^{UpSe⛓͓^fY٘glrü}[mcxB^$-ie|Mw6ro&F=:Ră|R_i1"
EspxHKZ/rt囒%AC;!F.
"u~mP(֕bjJJD3qd-8HH"!Z\j46*XXP|*+6p-2lGo(C{_^`a|D[7Olٌ
;A*@-
*[5g@׍|!p@i\-#M4w9<O"/?}}*0/wWSĘoB_#KJǏ&fw7)d/[E9^QiZX`r6<d
~}]7*sBUR1
j@-`4& Sse}wF5_yQ̓g4`.'k\XC(ȤJ1I*]~qOoC{o.'~AȘ%8?Ӯm$-ՠ95dA~C夏n I F1"'s :2(Vp{,0Z$5"}6v9|sO4W)L/
,gNu2QʂzӀcj~2ny^Nj=A#7
nKٸ@gMmv5=de(RQٟ4wh5ҍDlur'՟6(DӺq߄//гgJ7rw R?aKc(A,$#bZ˯%Szh͑MxCGF`x~]3Vl\1u-U#gC,:~T!.[w09Z"%)N(	^='٦QƢ,"!߆1;NPN7S+>8=$zjyrNgrWשQ#^E#!7DP<oOª?˾+_Ԃh"ZbsgsA_ך7)F#
}!I#;uQ`sܚ4LD©E[O^W^S/>.'eД\$j
Сfc嵭ZA<S5ŗjVMZ`kuX-&%*(OSl!H^9taɚ)UXᵟHm./HCTg^0^aiN:!oCmB:/u
U-^@uGX{)}ʗЌ'c\jy{ËT7ivFSyiڗJ?
GqO!r;~'p Ah
|=&3zZn\G̣ݖ<2)G}GoDrѳTa@_ttסkw&Tp
U+xkOܩZtbo|;yRdl+Xsk5jo	{L'08aI0`/JkB-N`r(Y Y6>3KMu P>g,BEXD汸QpPdigszHo%NRD-8'ymZK!ޚQ;oV){^	x)tLY}zcSB=$ikC?Q%yt*ۑ`z!ٱ.Qs4nľmPz)IaDKԢ"]jIaVe歆C/øsvb}/gRyEG$Q=[S$=ѓ߀1֏
%K1-AxtNy%'#	zp~<Z_Q?&
d؜\r*d#g
Ew`hAU7K-mܫ(ӚؙBn/XJEIH4,NztC?E[;,an|`82!vW߼
@r~A	aslby[vX	Ί;&jT%K~(P̗qfK1
Fa$qWo9ښ Yx(l
>vַm`hyCD-L6SSCB`3n{y0u@aҶQ"OWP=H	@]El,>~2~.Ze'J.wߍ}+.'%k%טm1V+COMFs.ȡzU0ࢿ$m<M8$*]gevΩ晒o"#uɅS=zazLQʹi7cIBV	ϝ@A|訶bEW03XUQ6LdB{nC#Y+5uK'r|fG\S
<.ԋչSyW*؝rh#\]̯u9xO!,-n7EFaejXX]{zw()	j=RK驄*2lwbKvYiO[J`m8O/^)	1q굞K')"Zo/=c%;
álI2;[لj:Sx3/l|a}%'<
t
Amg\3R48.G%Le&(Z=BQ!
(DB
QD!?PQNOsKH$MBrR91A`H`ыEW"ҳ9\z`Ly6@zOPP{?w7tLӍ9ﶲ5Z/*WTh5KT:T,Yg:<u(JZe5JE)XEf\@aԉiE	rbnXuXaEqP̙YD=Y*υδСz"{Y,>(H{wO<-Ȋ(npPHK]ӨөL)5j9װE{J7K4󂺪qrD3N]/$.͟08-"VW=S,s13h>Rhb29zpqE35o7HY|{$gkhRlsUf9L,k/*XΊ18Qű|%5^ЮW̵y~E]WPY8h^&qSW|MI=?n̞KY,>|Zs_Cԥސ% \jKE;KF	WYEY@QUvg*:jhmͯQˉRQ>+fTZmi`
s#')$%nJ^љmǔò|dxs@zf)k5GN굆rrIf-gLD)lJ-a>fg`XԤNʑm,ܣKpN]ơ&l۠.hkkMv_ŽY[Kfm,zhaIbamZupKU
KW.>lEvpRv:o=D瀪K%ό}/4+č+YJ
)KnтM{fERۤW`DX{6k53݂FȒOF繘B)5b,6ץBPAFXcIN528 g'}шDcGjZ-!3,nmКn͎TM'_C%FĖfwsRPw7Uy2LQiK"*$f}IlAY/%`O_%ZjBW#u&avJ9+b((Ԩ"/FCV"ɮD
_Tد3fSP,V?|t$:6ͳe镃hQ]cfz6/hUmg
fڊh~f
&:UUVjmhCl0b[)u:3JdHK10@
FjZPkqW~*8L>)8CWN.Ps#jw0
\DXyZtyXT5s}Bxf'C	8є;QP)UL,S(F7aGi7
yZ䟋2etf|niŅ	<~Z%ou=5״vw!m4,עr\!~2*RY0ᚷx7j\bTYfV:XYdzSy$\*%JrUy3u>U^2i6W03˲qRAG	޵vdF%9罉3X*)*\*^pݬ3-Pg.kil!C~}sV25ymnӂ0	E$9v
l50ѸqpQ6`eSCExOGO%+}@uq%33_8Lɋsc]SVX1{;``3
8UIXp*:T旔ZKJҢ9ĪhqFîT4*LewCbgVjee遞 "'ɻ:g&/Sg	lϜw)]6)su ^CE7,%!iH{AD?}/sA"uc_`czW㸼:nġ4(B\ bit*-o^ b^դ>٨=-~HÏ!ЋH
y ?Q׽iޯ,x@˛F`2<J	zyzcQ$)Źѳ{1h4!~ʔ"|{{LOq%qr=Ø~ų9Cf'S_>eY;ⵐֳl
ԓ(*=b]y0KaHivX(޷٥k?̽o2xH =ՉRT=?"k2kG<Kx{wB)ESm lz^qv>y+Y{"m:lI!UJ/tHk˦;("GW{E.~ʬoc)"V҄H~RUҌӜ~IJ?>Ȇ~y iú^IJy*6)t[?ꟼ:=W#C]qbPU"sԤ#ۥ4D<?H=هxs?]n幣]vdj
EڞqC_X5g}ڈ\Rpt9'ۈݑxVc i~x
&r}BTɦGCD6?O6=>؍Ų(ʽFsa|0;}*AJbviGVLHS~I
Ox)tX>'v7h,u~}0vz=O!{;Qxq|P' G%{.D7=Nv@֖I9@'ڇz
rOՃΣS,9ǂ=t/MT,T=(}"&bnn'&76iFQbɦnw>wjÎH쟁>نq(܇8Dɩv,3hsA
s7BxHZ=Z6J6>uMU|z&{y
vݾc7bi62('Gizى:ֻm&nJ48-KS&Ȫ:~[z
N7I#NrO?2ǁ(Cnu[B:yp+B فM}/A=~%کBÚm;$݊zBi,|ުOH֒xXP;ˑ*q{$mޣ.rcboUkvO4!'<>VG[ $GoWpmnV<<ه
0EZ[""'qWaN`6q}$o!QSGTr̺mI;
? @2oWڲt(7drG?+RHjo&y8/~g*FU:nd6Y H=.ɕQu^!A*Q
:"տTm;ǫVÑSG9ω
O =?S%v|M}((`lMX^!ϘT6v\c'(_=쑧C8oAHT>:!Ceܒvl(2ЋGvI`7hŐCԊ79tk$,
^IA/2%ߋ5Hȝ%M2/uh5xpC'2{kYEBNF24ާ@@<eXKq){duRtS<?;BݫCOMiwVTdף0&r@ Q"e=BQ!
	dF5ӠТ@
zZp@@=n'
p@ ,pIr+>Cmv" ;ai*]R tH}m(>qϕ:xWɒ@?,6N:YArKL=k% ~QU|:-MM"KN} .^B7nG#7dGNۡ;?yjjbga%A0iyeM,GBXIuQ. ;]nNAvﴐIye-CtMM !O[-DPEЗ31/fY)+oH'̒7&Ig,?B"16>'Qq_9"A[Vp^$r
bm>>NtP{i9CVAbg
_\!ڝNNωjI1_	IIEoeG-7dخb1ğ"`QؐTJBI	aҒ\KBI	!1D&$ʄLHʡI5	&!&BXM@}A6 Y|[zHI		y1'!&BdHOw\2[g)r·?~܀œ~	":n %F{'Z,:FQq=w;DD;@}-
wO
DF~!*Q
ϟ*ygq9|_/?<>\ϟZf׎N\WsI%Is8q''1m-Pz\dkNgIrmqٱ9wͱ;j8ڞw;8jݜwͱjx(w	;懝pNsNm'8aζ9aGw9aGhǞ6=M_ Uc3E"`or (.CŽ{dskEݠϝu{^M:[dlMٶm
MٚM2MI@LWZؠ BCm2CP3`
!>i!RXP}"Ř@ԡ,Y35n\Fu2ؚTɢ#[@.|9"(
IU* FDu9DElJzl	 sm%maeK-gCt8b\BC:"gĜ<l6ZrXĨ934!Whؒe=Ύx(j\dL696n+@q&Pe\9LL&I
mDiFNL~&Ȳq|OdBcN	`0vJJSGzY agG!ǍPJB5gT"2FLxyS{=r[Z(0f8*SCYIx3oYvxQW#6O.929Nd>ɜu)"x2TF(s&hDS|eͲ0y|RWjx5T"2cF&2=#uM8'XKb:V&oPyєCK"KIhqsZx|)*<Θ8<EA19{ydO]DmMW=}U:#)C4Ms2Uȧc)RWt%JC7rOBҭ}x#FK,Y"fgKQDl#)37(TNo<]Z]\#G_?ne#)
F7Uy|9% o3q>AFjhS̈́SoJĔg	QQ_s@΁!6s@/ͪP\s(b5zRlQs^ӺwxT"2KG1AI8	LLXrf"6Tw'~*.Zjw.gZqܥAlNzj-Dem!\:mlC{RӍcc?b[*;*KR$j1NVX%b(CiZ5%Di?;j#s{yHf+A*O:#DZYimN}iK`
'k\w%WC%)g1o}A ]7"c--՚ũtmIWC%(lyWXǤקi"9ra[|}[)
}IyMږW[&bZʯ-ߢDe<&3(B"qԏex\=HQ@u:*%G/=lZ1#s l?L9uܖeL<'Jr:yBq&$`o܋׍<gWv9>N-fݐҙHaG>|'>I
/(3͹KA|<*P<MY'l'2`Th33`0+nL9IOX	--5s3k݅3K:+O>w}SJ󨁨8)04,3="A
fTs>wlk{wG&~g_y薰Ms.z~+/jIT4ZԅBnAlSG0X1Ű|+=KŗX`51y1lh,FKPh=D	7A}/fK%n<F	j!3PQ01Wjg?w`S~|C	PٔDg#'Q|wWT~Ŗε	uM!8&\PxB"dSxOJgn)'Z9!BNbO89"{3?ʲpNp6%yֺ6&ϗzN<|	'T'#N$m<cdqG<)aȧMK'U\|x=I8-.ND	ʩ8z
iJ8,YtIʣ͛:jPfO'f'CIHsp_Fbi;%kM
9YLƹZKiNب#t.MiQl)Y9iOqI	{O443Nug12c{h+rvA1~BTGeȈΛHHӝkSIaW}ɼ韘O2Vn!@j_QExtZ$-~Kx&-#3N(c.1w:.ݢ=qѶ-Ngwi@ƲeNԖc!lvDAqS{{7KXFV*TEҟ,"-<tMQ#NX9В=λ#HٲdfΌ=qcq%_7Br)'	q[6_/ QB=b8E	?U蟱`Ǘ`-tօuq%OV {IBp@8Mnjj\*h	jUt\AH8gS刮Yy
9e@[hk
?yFꭍe`Of+Vɖ}l# Զ\f"2N/M<#tjݥ>t]::Y|642O;CqƧj@ndscc"QJk9ΨGTbƜx<U5j?U^\55VTfj#JfF?9XhԖ
BJ"GVhˮ(oOD˚O q]OMMP5y@),S1`c.DF2m@SGjzPC:đY@
fЪ=4Uᗩ긤oTŁ[֊=4uA룠[jzPC"ԁ
PUD!\%U3EʵwH<*p0ѶRe=Mm@SEjzpR)@I,"I=_dWCr
r~ŧ;vn?nZbe}'pEjAk.a䵂
`ZB9zբiP}v
;l 3;%,:	o[;7]K0|`Vt7ĤhGb	v&]Uy9l9|#‡7k5sPەI	{0WFZֽ<ı29lj3pZkv܊ÚK
g6$ַP#yb3鴷3ꤵQXpl2찤&uAY4Xr$)K
o	<P܄jbt`IփM-9@VZ	*PsJCC%~%Îtb&98V+"f!O
8ՒP^k59vj2ދ#0VKUNyTXV#Y*hN6+fpRXq(!jiho35wb~hBF#N
;KN~1V<̐6+ہ+F8U,R9U%xx$"wEko,w-Ty7n}sϗ
]>.`r+ր\[o"5;z^moȻ_XYux!v7K!J/2<\p}Xo儰Mǿ3%oYCnOr8g_"+7凲{Hov]o+R>w/WO"e0u҂1!ݧ7K_?>?碛"_~j8Lܭ񲻹c_}Ǯ>C\`}*/;{u]x}}߿jRߚw=znziǤz.Vm<xw̧üK&oW_^愷6=aVmd,\kHwârzM߼n?>_{7k:Cyzkڃ_xBz8|<(nS^<u66&h߷;]u;R+]V/ot8\:w/ՄHx
(}X:A*b7/@?@+1@LÃ\K#Vh^&}PVaQy1e$G$+]^JFɅ+5Oq\Ra9dn\qp,Uf?=,S||!WcLl,[qw@QVsTyNYB\<V hevX1YA~ְ;^O&]9ɊEd^70XXʴ7rY1V{
!tYF`_#V7M.K޽Aof<|	|ab3V*_u{~yΌrxLvԲBs#Кśw8Q7ujc	bvJ@UD-*l[۱]:>έ‹~kk+?V"|dڊ`h_v"s
ëkP!]*mL^ꉐ'A;	U׭K(4K)t&Ƥ&1/	2"MchAsol,@'_<F>wws%#vh߸(v"ܡ
wTM	֭e	V۝A[Z+W}][;aYŜSd's'3^m0
ƐtVzcl/h (z^'b]

Anon7 - 2022
AnonSec Team