Versions:

  • 0.1.1

wevtail is a command-line utility published by Ldogg123 that brings the familiar behavior of the Unix tail -f command to Windows event logs. Rather than periodically polling for new entries, wevtail follows Windows event log channels live using a push-based model built directly on the Win32 EvtSubscribe API, which means events are delivered to the tool as they occur, much as tail -f streams appended lines from a growing file. This design makes it a practical choice for system administrators, developers, and support engineers who need to observe system activity in real time without repeatedly querying the log or opening graphical tools such as Event Viewer. The software supports following multiple event log channels simultaneously, allowing users to monitor, for example, Application, System, and Security channels in a single session. Output can be presented in a colorized human-readable format for interactive use or as JSON lines, which is convenient for piping into other command-line tools, log processors, or structured data pipelines. wevtail also includes XPath filtering, so users can narrow the stream to only the events matching specific criteria rather than sifting through an unfiltered feed. In addition to live monitoring, the tool offers .evtx file replay, enabling analysis of previously exported or archived event logs as though they were being tailed live, which is useful for post-incident investigation and offline diagnostics. Remote-host tailing extends this functionality beyond the local machine, permitting users to follow event logs on other Windows systems across a network. Categorized as a logging and system diagnostics utility for Windows, wevtail is currently available in version 0.1.1, and its catalog history contains a single published version, reflecting an early-stage but functionally focused release.

Tags: