Desktop Functions:

   Smart Device Functions:

Show Recent Changes
Subscribe (RSS)
Misc. Pages
Helpful Tools
Suggested Reading
Website TODO List
Support Forum
Download Visual Studio Add-In

Terms of Use
Privacy Policy
BackupEventLog (advapi32)
TODO - a short description

C# Signature:

[DllImport("advapi32.dll", CharSet = CharSet.Unicode, SetLastError = true)]
public static extern bool BackupEventLog(IntPtr hEventLog, string backupFile);

VB Signature:

Declare Function BackupEventLog Lib "advapi32.dll" (TODO) As TODO

User-Defined Types:


Alternative Managed API:

EventLogSession from the namespace System.Diagnostics.Eventing.Reader can be used in most cases (Windows Vista and above only and .NET 4 or above. This throws a PlatformNotSupportedException on Windows XP and Windows 2003 with .NET 4)

To save the 'Appllication' event log:

EventLogSession eventLogSession = new EventLogSession();

eventLogSession.ExportLogAndMessages("Application", PathType.LogName, "", @"logFile.evtx", /tolerateQueryErrors*/ false, CultureInfo.CurrentCulture);



Tips & Tricks:

Please add some!

Sample Code:

Save the application log to disk:

    [DllImport("advapi32.dll", CharSet = CharSet.Unicode, SetLastError = true)]
    static extern IntPtr OpenEventLog(string UNCServerName, string sourceName);

    [DllImport("advapi32.dll", CharSet = CharSet.Unicode, SetLastError = true)]
    static extern bool BackupEventLog(IntPtr hEventLog, string backupFile);

    [DllImport("advapi32.dll", SetLastError = true)]
    static extern bool CloseEventLog(IntPtr hEventLog);

    void SaveLog(string eventLogName, string destinationDirectory)
        string exportedEventLogFileName = Path.Combine(destinationDirectory, eventLogName + ".evt");
        string exportedEventLogFileName = Path.Combine(destinationDirectory, eventlogName + ".evt");

        //Returns handle to Application log if Custom log does not exist.    
        IntPtr logHandle = OpenEventLog(Environment.MachineName, eventLogName);
        IntPtr logHandle = OpenEventLog(Environment.MachineName, eventlogName);

        if (IntPtr.Zero != logHandle)
           bool retValue = BackupEventLog(logHandle, exportedEventLogFileName);
           //If false, notify.


Please edit this page!

Do you have...

  • helpful tips or sample code to share for using this API in managed code?
  • corrections to the existing content?
  • variations of the signature you want to share?
  • additional languages you want to include?

Select "Edit This Page" on the right hand toolbar and edit it! Or add new pages containing supporting types needed for this API (structures, delegates, and more).

Access directly from VS:
Terms of Use
Edit This Page
Find References
Show Printable Version