How to Start/Stop Windows Event Log service
Service name: eventlog
Display name: Windows Event Log
Description:
This service manages events and event logs. It supports logging events, querying events, subscribing to events, archiving event logs, and
managing event metadata. It can display events in both XML and plain text format. Stopping this service may compromise security and
reliability of the system.
Path to executable:
C:\Windows\System32\svchost.exe -
CMD:
This method shows you how to Start/Stop Windows Event Log service from Command Prompt
Please perform the following steps:
Please go to Start and click on the Search programs and files
Type cmd, right click on cmd icon under the Programs and click on Run as administrator
Please confirm User Account Control pop-
Please select, right and copy a registry key from below, then right click on command prompt window, select Paste and press Enter
To Start Windows Event Log service:
net start eventlog
Note: You can’t start a service if Startup type is on Disabled.
To Stop Windows Event Log service:
net stop eventlog
To change Startup type:
Automatic:
REG add "HKLM\SYSTEM\CurrentControlSet\services\eventlog" /v Start /t REG_DWORD /d 2 /f
Manual:
REG add "HKLM\SYSTEM\CurrentControlSet\services\eventlog" /v Start /t REG_DWORD /d 3 /f
Disabled:
REG add "HKLM\SYSTEM\CurrentControlSet\services\eventlog" /v Start /t REG_DWORD /d 4 /f
Automatic (Delayed Start):
REG add "HKLM\SYSTEM\CurrentControlSet\services\eventlog" /v Start /t REG_DWORD /d 2 /f
Note: When you change to Automatic (Delayed Start) a new key DelayedAutostart is created with value 1.
REG add "HKLM\SYSTEM\CurrentControlSet\services\eventlog" /v DelayedAutostart /t REG_DWORD /d 1 /f
When you change to Automatic from Automatic (Delayed Start), DelayedAutostart change value to 0.
REG add "HKLM\SYSTEM\CurrentControlSet\services\eventlog" /v DelayedAutostart /t REG_DWORD /d 0 /f