FullEventLogView is another useful free tool from NirSoft, capable of parsing Windows 10, 8, 7, and Vista event logs. A computer forensic examiner can use it to view both event logs from a local computer and EVTX files, which can be found at %SystemRoot%\Windows\System32\winevt\Logs.
Event log analysis with FullEventLogView
Getting ready
Go to the FullEventLogView download page on NirSoft's website (the link is presented in the See Also section), and get the 32-bit or 64-bit version of the tool, according to your system. Unpack the archive you downloaded and you are ready to go.