Skip to main content
Version: 24.5

Event Log

The event log is a powerful diagnostic tool that, by default, centralizes critical and error events.

List view

eventlog This tab provides information about the log events present on the device, by default it filters errors and only shows those errors with severity Error or Critical, obtaining them from the device at intervals of 10 minutes.

The Event Log section lists the events from the event viewer for Windows devices. By default, Workspaces only processes and displays in this section the critical and error events from the application, security, and system event logs.

Events are collected every 10 minutes by default; in the Workspaces settings, this time can be modified.

The default view is for Today, which begins at 12:00 AM in the timezone defined in the Workspaces instance. Using the button below the search, the time filter can be changed to the values.

  • Today.
  • This week.
  • This month.
  • This quarter.
  • This year.

Filtering options

This view allows the same filtering functionalities available in Workspaces. an example of filtering in this view would be filtering by an event with a specific ID to obtain a list of the affected devices, to subsequently apply corrective actions.

Event log information in Workspaces

tabevent In the details view of a Windows device, a tab is activated that groups the event logs for that device.

Detail view

The event log detail view contains all the information of the event, which is:

  • Event date: Date of event registration in day and time format.
  • Level: severity level of the event.
  • Source: the source of the event.
  • Id. of the event: numeric identifier of the event.
  • Log file: event log file that hosts the event.
  • Machine name: Hostname of the device logging the error.
  • Message: the content of the event message.

Additional event configuration

Users with administrator roles can add events that do not meet the default filtering conditions, for example, to add events with specific ID that, although they have an informational severity level, are relevant to the organization, as well as change the update time of the logs.