Local evidence reader

Windows Event Viewer Error Parser

Paste one time-matched Event Viewer record as rendered text or XML and extract the provider, Event ID, time, level, faulting fields, and diagnostic tokens without uploading the event.

Input
10–80 relevant lines
Processing
Browser-local
Output
Facts + limits + next evidence step

Runs locally in this browser

Paste one time-matched event

Use one event that matches the incident time. Provider + Event ID + timestamp are more useful than Event ID alone.

Where to copy from In Event Viewer, select the time-matched event. Copy the General text, or open Details → XML view and copy the event XML.

0 / 40,000 characters · recommended 10–80 relevant lines

Examples
No upload · No pasted-evidence storage · No AI-generated interpretation

What the parser does

Structure one excerpt without turning it into a root-cause verdict

Extracted fields

  • Provider/source
  • Event ID
  • Level
  • Channel/log
  • Timestamp
  • Faulting application/module
  • Exception or status code
  • Diagnostic tokens

Supported input

  • English rendered Event Viewer text
  • Event XML copied from the Details view
  • One time-matched event at a time

Not supported

  • Binary .evtx files
  • Whole event-log exports
  • Automatic Event ID meaning lookup without provider context
  • Root-cause or culprit scoring

Official structure and interpretation boundary

Reviewed sources