wevtail
tail -f for Windows event logs.
wevtail follows Windows event log channels live (push-based, no polling) through the Win32 EvtSubscribe API — like tail -f, but for the event log. It supports following multiple channels at once, colorized or JSON-lines output, XPath filtering, .evtx file replay, and remote-host tailing.
winget install --id Ldogg123.wevtail --exact --source wingetLatest 0.1.1
Details
- Homepage
- https://github.com/Ldogg123/wevtail
- License
- MIT OR Apache-2.0
- Publisher
- Ldogg123
- Support
- https://github.com/Ldogg123/wevtail/issues
- Copyright
- Copyright (c) 2026 Ldogg123
- Moniker
wevtail