.      How to articles       Windows Services       Group Policy             Donate        
Computer step by step
Services Regedit CMD Msconfig

How to Start/Stop Windows Event Log service

Service name: eventlog

Display name: Windows Event Log


Description:

This service manages events and event logs. It supports logging events, querying events, subscribing to events, archiving event logs, and
managing event metadata. It can display events in both XML and plain text format. Stopping this service may compromise security and
reliability of the system.


Path to executable:

C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted

CMD:
This method shows you how to Start/Stop Windows Event Log service from Command Prompt

Please perform the following steps:

Please go to Start and click on the Search programs and files

Type cmd, right click on cmd icon under the Programs and click on Run as administrator

Please confirm User Account Control pop-up

Please select, right and copy a registry key from below, then right click on command prompt window, select Paste and press Enter


To Start Windows Event Log service:

net start eventlog


Note: You can’t start a service if Startup type is on Disabled.


To Stop Windows Event Log service:

net stop eventlog


To change Startup type:

Automatic:

REG add "HKLM\SYSTEM\CurrentControlSet\services\eventlog" /v Start /t REG_DWORD /d 2 /f

Manual:

REG add "HKLM\SYSTEM\CurrentControlSet\services\eventlog" /v Start /t REG_DWORD /d 3 /f

Disabled:

REG add "HKLM\SYSTEM\CurrentControlSet\services\eventlog" /v Start /t REG_DWORD /d 4 /f

Automatic (Delayed Start):

REG add "HKLM\SYSTEM\CurrentControlSet\services\eventlog" /v Start /t REG_DWORD /d 2 /f


Note: When you change to Automatic (Delayed Start) a new key DelayedAutostart is created with value 1.

REG add "HKLM\SYSTEM\CurrentControlSet\services\eventlog" /v DelayedAutostart /t REG_DWORD /d 1 /f


When you change to Automatic from Automatic (Delayed Start), DelayedAutostart change value to 0.

REG add "HKLM\SYSTEM\CurrentControlSet\services\eventlog" /v DelayedAutostart /t REG_DWORD /d 0 /f

                                                                                 Services List