3、然后单击“Windows日志”——“系统” ,然后选择打开右边的“筛选当前日记”,如下图: 4、在“筛选当前日志”窗口中,事件来源选择“eventlog”,在如下图位置输入“6005,6006”。 ps:eventlog标示开关,而6005表示开机,6006表示关机。 5、输好后点击确定,在主要窗口就会筛选出我们电脑最近时间的开机关机情况,如下...
6006,INFORMATIONAL,EventLog,Tue Nov 27 14:09:26 2001,, 事件日誌服務已中止。6005,INFORMATIONAL, EventLog,Tue Nov 27 10:11:37 2001,,事件日誌服務 已啟動。 6006 事件表示由具有關閉網域控制站使用者權利的使用者啟動的計劃性關機。6005 事件表示已啟動事件日誌服務。這會在啟動時發生。 6008 與 1001 事...
Event code: 3005 Event message: An unhandled exception has occurred. Event Collector Server Sizing Question Event error 7031: The RdAgent service terminated unexpectedly Event forwarding error code 0x6 event generation for id above 1000 Event ID - 11 KDC Encountered Duplicate Names EVENT ID - 36885...
查了下资料: 其中6005,6006的解说,基本正确,但是 有一个 6009(6009信息EventLog按ctrl、alt、delete键(非正常)关机)基本不正确... 我这里机子上 开机也会有 6009,难道是 按ctrl、alt、delete键 就会有 6009?未查到 ms的官方说明... 3、 4、 5、...
If you're looking for a system initiated shutdown/restart, look for event 1074. The details for this event will tell you what process initiated the restart and what reason was given, and you can check the reason code for further information about why the system shut down or restarted. ...
EventLog 6005 System Start EventLog 6006 System Shutdown EventLog 6009 Operating system version at boot time Save Dump 1000, 1001 Blue screen event SysMgmt 4188 Blue screen event DrWatson All Application Failures Application Popup 26 Out of Virtual Memory errors Autochk 1001 Chkdsk was run on sys...
If you're looking for a system initiated shutdown/restart, look for event 1074. The details for this event will tell you what process initiated the restart and what reason was given, and you can check the reason code for further information about why the system shut down or restarted. ...
159 线程 ID 的地址不正确。 160 至少有一个参数不正确。 161 指定的路径无效。 162 信号已暂停。 164 无法在系统中创建更多的线程。 167 无法锁定文件区域。...1084 不能以安全模式开始这项服务 EVENT_ID 安全事件信息 1100 --- ...
577 or 578 with the SeLoadDriverPrivilege access privilege indicated. The user account that made use of this user right is identified in the event details. This event can indicate a user's attempt to load an unauthorized or Trojan horse (a type of malicious code) version of a device ...
If you're looking for a system initiated shutdown/restart, look for event 1074. The details for this event will tell you what process initiated the restart and what reason was given, and you can check the reason code for further information about why the system shut down or restarted. ...