Clear Windows Event Logs with wevtutil
More actions
Monitoring and operational reference for Clear Windows Event Logs with wevtutil.
Overview
The original command on this page was written for Windows 7 / Windows Server 2008, but wevtutil remains available on modern versions of Windows and Windows Server.
Warning: Clearing event logs is destructive and removes useful diagnostic and security evidence. Only clear logs for a deliberate administrative reason, such as lab testing, troubleshooting, image preparation, or another approved maintenance activity. In managed environments, clearing logs may also generate security alerts.
Clear all Windows Event Logs
Run Command Prompt as Administrator.
To enumerate all registered event logs:
wevtutil el
To clear all registered logs:
for /f "delims=" %x in ('wevtutil el') do wevtutil cl "%x"
When used inside a .bat or .cmd file, use a double percent sign:
for /f "delims=" %%x in ('wevtutil el') do wevtutil cl "%%x"
The delims= option ensures that log names containing spaces are processed as a complete line.
PowerShell equivalent
Run PowerShell as Administrator:
Get-WinEvent -ListLog * -ErrorAction SilentlyContinue |
Where-Object { $_.RecordCount -gt 0 } |
ForEach-Object {
wevtutil cl "$($_.LogName)"
}
Some protected, analytic, or debug channels may return an error when clearing. This does not necessarily mean that the normal event logs failed to clear.
Clear individual event logs
If you only need to clear a specific log, it is safer to target it directly:
wevtutil cl Application wevtutil cl System wevtutil cl Security
You can list available log names with:
wevtutil el