[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fLdDWy2MpXHl_Kfr1y56j69Wt-_GidFTtld9wqDKL8XA":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":33,"aiModel":30,"aiConfidence":30,"updatedAt":50,"createdAt":50,"_status":49},715,"Why can't the same single log deletion method used for EVTX files be applied to EVT files?","The EVT file structure does not include a unique identifier like EventRecordID, which is present in EVTX files. Without this unique value, it's impossible to locate and delete a specific log entry directly. Instead, the approach for EVT files uses the log creation time (time_t) as an input parameter, allowing deletion of all logs within a specified time range. This method is detailed in the [Windows Event Viewer Log (EVT) Single Log Deletion (Part 2) – Program Implementation for Deleting Log Records within a Specified Time Range from EVT Files](\u002Fnews\u002Fwindows-event-viewer-log-evt-single-log-deletion-part-2-program-implementation-for-deleting-log-records-within-a-specified-time-range-from-evt-files) article.","\u003Cp>The EVT file structure does not include a unique identifier like EventRecordID, which is present in EVTX files. Without this unique value, it&#39;s impossible to locate and delete a specific log entry directly. Instead, the approach for EVT files uses the log creation time (time_t) as an input parameter, allowing deletion of all logs within a specified time range. This method is detailed in the [Windows Event Viewer Log (EVT) Single Log Deletion (Part 2) – Program Implementation for Deleting Log Records within a Specified Time Range from EVT Files](\u002Fnews\u002Fwindows-event-viewer-log-evt-single-log-deletion-part-2-program-implementation-for-deleting-log-records-within-a-specified-time-range-from-evt-files) article.\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fwindows-event-viewer-log-evt-single-log-deletion-part-2-program-implementation-for-deleting-log-records-within-a-specified-time-range-from-evt-files\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","why-cant-the-same-single-log-deletion-method-used-for-evtx-files-be-applied-to-e-1777482183145","EVT, EVTX, EventRecordID, time_t, log deletion",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":27,"cover":30,"author":31,"views":19,"readingTime":32,"status":33,"publishedAt":34,"seo":35,"tags":39,"qaPairs":40,"meta":46,"updatedAt":47,"createdAt":48,"_status":49},177,"Windows Event Viewer Log (EVT) Single Log Deletion (Part 2) – Program Implementation for Deleting Log Records within a Specified Time Range from EVT Files","windows-event-viewer-log-evt-single-log-deletion-part-2-program-implementation-for-deleting-log-records-within-a-specified-time-range-from-evt-files","Learn how to delete log records from EVT files within a specified time range. Includes program approach, time_t to GMT conversion, and open-source code.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>The second article in the Windows Event Viewer Log (EVT) Single Log Deletion series. It introduces the approach for deleting log records within a specified time range from an EVT file, addresses multiple design considerations in the program implementation, and provides open-source code.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>Approach for deleting log records within a specified time range from a given EVT file\u003C\u002Fli>\u003Cli>Program implementation details\u003C\u002Fli>\u003Cli>Open-source code\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Approach for Deleting Log Records within a Specified Time Range from an EVT File\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Compared to the single log deletion method for EVTX files mentioned in previous articles, the same approach cannot be applied to EVT files.\u003C\u002Fp>\u003Cp>This is because the EVT file structure does not include a unique value like EventRecordID, making it impossible to locate a specific log entry.\u003C\u002Fp>\u003Cp>Through analysis, it was found that the log creation time can be used as an input parameter. By specifying a start date and an end date, the log content within that time range can be deleted.\u003C\u002Fp>\u003Cp>The format of the log creation time is of type time_t, requiring consideration of the conversion between the time_t type and Greenwich Mean Time (GMT).\u003C\u002Fp>\u003Cp>In terms of program implementation, the approach is as follows:\u003C\u002Fp>\u003Cul>\u003Cli>Traverse all logs, filter out those meeting deletion criteria, and save the remaining log content.\u003C\u002Fli>\u003Cli>After filtering, subtract the number of deleted log entries from the Record numbers of subsequent logs.\u003C\u002Fli>\u003Cli>Update the End of file record offset, Last (newest) record number, and Maximum file size in the file header.\u003C\u002Fli>\u003Cli>Update the End of file record offset and Last (newest) record number in the end of file record.\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x03 Conversion between time_t type and Greenwich Mean Time (GMT).\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>Calendar Time\u003C\u002Fh3>\u003Cp>Calendar time, represented by the time_t data type.\u003C\u002Fp>\u003Cp>Represents 'relative time,' which avoids being affected by time zones; calendar time is the same across different time zones.\u003C\u002Fp>\u003Ch3>time_t type:\u003C\u002Fh3>\u003Cp>Essentially a long integer, representing the number of seconds from 1970-01-01 00:00:00 to the current time.\u003C\u002Fp>\u003Cp>Defined as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>struct tm\u003Cbr>{\u003Cbr>    int tm_sec;   \u002F\u002F seconds after the minute - [0, 60] including leap second\u003Cbr>    int tm_min;   \u002F\u002F minutes after the hour - [0, 59]\u003Cbr>    int tm_hour;  \u002F\u002F hours since midnight - [0, 23]\u003Cbr>    int tm_mday;  \u002F\u002F day of the month - [1, 31]\u003Cbr>    int tm_mon;   \u002F\u002F months since January - [0, 11]\u003Cbr>    int tm_year;  \u002F\u002F years since 1900\u003Cbr>    int tm_wday;  \u002F\u002F days since Sunday - [0, 6]\u003Cbr>    int tm_yday;  \u002F\u002F days since January 1 - [0, 365]\u003Cbr>    int tm_isdst; \u002F\u002F daylight savings time flag\u003Cbr>};\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Note that the year is relative to 1900\u003C\u002Fp>\u003Ch3>Coordinated Universal Time (UTC)\u003C\u002Fh3>\u003Cp>Coordinated Universal Time, also known as World Standard Time, i.e., Greenwich Mean Time (GMT)\u003C\u002Fp>\u003Cp>There are time zone differences; calculating local time requires considering the time difference\u003C\u002Fp>\u003Cp>Example C code for type conversion:\u003C\u002Fp>\u003Cp>Convert Calendar Time to GMT:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>#include \u003Cstdio.h>\u003Cbr>#include \u003Ctime.h>\u003Cbr>int main()\u003Cbr>{\u003Cbr>\t__int64 CalTime = 1531788377;\u003Cbr>\tstruct tm GmTime;\u003Cbr>\tchar GmBuf[26];\u003Cbr>\t_gmtime64_s(&amp;GmTime, &amp;CalTime);\u003Cbr>\tstrftime(GmBuf, 26, \"%m\u002F%d\u002F%Y %r\", &amp;GmTime);\u003Cbr>\tprintf(\"GmTime   :%s\\n\", GmBuf);\u003Cbr>\treturn 0;\u003Cbr>}\u003C\u002Ftime.h>\u003C\u002Fstdio.h>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Convert Calendar Time to local time (considering time difference):\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>#include \u003Cstdio.h>\u003Cbr>#include \u003Ctime.h>\u003Cbr>int main()\u003Cbr>{\u003Cbr>\t__int64 CalTime = 1531788377;\u003Cbr>\tstruct tm LocalTime;\u003Cbr>\tchar LocalBuf[26];\u003Cbr>\t_localtime64_s(&amp;LocalTime, &amp;CalTime);\u003Cbr>\tstrftime(LocalBuf, 26, \"%m\u002F%d\u002F%Y %r\", &amp;LocalTime);\u003Cbr>\tprintf(\"LocalTime:%s\\n\",LocalBuf);\u003Cbr>\treturn 0;\u003Cbr>}\u003C\u002Ftime.h>\u003C\u002Fstdio.h>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Convert time to Calendar Time:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>#include \u003Cstdio.h>\u003Cbr>#include \u003Ctime.h>\u003Cbr>time_t StringToDatetime(char *str)\u003Cbr>{\u003Cbr>\ttm tm_;\u003Cbr>\tint year, month, day, hour, minute, second;\u003Cbr>\tsscanf_s(str, \"%d-%d-%d %d:%d:%d\", &amp;year, &amp;month, &amp;day, &amp;hour, &amp;minute, &amp;second);\u003Cbr>\ttm_.tm_year = year - 1900;\u003Cbr>\ttm_.tm_mon = month - 1;\u003Cbr>\ttm_.tm_mday = day;\u003Cbr>\ttm_.tm_hour = hour-1;\u003Cbr>\ttm_.tm_min = minute;\u003Cbr>\ttm_.tm_sec = second;\u003Cbr>\ttm_.tm_isdst = 0;\u003Cbr>\ttime_t t_ = mktime(&amp;tm_);\u003Cbr>\treturn t_;\u003Cbr>}\u003Cbr>int main()\u003Cbr>{\u003Cbr>\ttime_t sec = StringToDatetime(\"2018-7-16 17:46:17\");\u003Cbr>\tprintf(\"\\n%ld\\n\", sec);\u003Cbr>\treturn 0;\u003Cbr>}\u003C\u002Ftime.h>\u003C\u002Fstdio.h>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x04 Program Implementation Details\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Structure Definitions\u003C\u002Fh3>\u003Cp>File header definition can be referenced at:\u003C\u002Fp>\u003Cp>https:\u002F\u002Ftechnet.microsoft.com\u002Fzh-cn\u002Flibrary\u002Fbb309024\u003C\u002Fp>\u003Cp>Event records definition can be referenced at:\u003C\u002Fp>\u003Cp>https:\u002F\u002Ftechnet.microsoft.com\u002Fzh-cn\u002Flibrary\u002Faa363646\u003C\u002Fp>\u003Cp>End of file record definition can be referenced at:\u003C\u002Fp>\u003Cp>https:\u002F\u002Ftechnet.microsoft.com\u002Fzh-cn\u002Flibrary\u002Fbb309022\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>In the program implementation, to avoid redefinition, I modified the structure name of event records\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>typedef struct _EVTLOGRECORD {\u003Cbr>\tDWORD Length;\u003Cbr>\tDWORD Reserved;\u003Cbr>\tDWORD RecordNumber;\u003Cbr>\tDWORD TimeGenerated;\u003Cbr>\tDWORD TimeWritten;\u003Cbr>\tDWORD EventID;\u003Cbr>\tWORD  EventType;\u003Cbr>\tWORD  NumStrings;\u003Cbr>\tWORD  EventCategory;\u003Cbr>\tWORD  ReservedFlags;\u003Cbr>\tDWORD ClosingRecordNumber;\u003Cbr>\tDWORD StringOffset;\u003Cbr>\tDWORD UserSidLength;\u003Cbr>\tDWORD UserSidOffset;\u003Cbr>\tDWORD DataLength;\u003Cbr>\tDWORD DataOffset;\u003Cbr>} EVTLOGRECORD, *PEVTLOGRECORD;\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>2. Filter Conditions\u003C\u002Fh3>\u003Cp>The TimeGenerated field of the end of file record has a fixed structure with the value 0x33333333\u003C\u002Fp>\u003Cp>During traversal, if TimeGenerated equals 0x33333333, it indicates the end of file record has been located and traversal should terminate\u003C\u002Fp>\u003Ch3>3. Traversal Method\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>while (currentRecordPtr-&gt;TimeGenerated != 0x33333333)\u003Cbr>{\u003Cbr>\t\tif (currentRecordPtr-&gt;TimeGenerated\u003Cstarttimenum ||=\"\" currentrecordptr-=\"\">TimeGenerated&gt;EndTimeNum)\u003Cbr>\t\t{\t\t\u003Cbr>\t\t\t\u002F\u002Fnot selected evt record,copy it\u003Cbr>\t\t}\u003Cbr>\t\telse\u003Cbr>\t\t{\u003Cbr>\t\t\t\u002F\u002Fdelete record\u003Cbr>\t\t}\u003Cbr>\t\tcurrentRecordPtr = nextRecordPtr;\u003Cbr>\t\tnextRecordPtr = (PEVTLOGRECORD)((PBYTE)nextRecordPtr + nextRecordPtr-&gt;Length);\u003Cbr>}\u003C\u002Fstarttimenum>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>4. Log Preservation\u003C\u002Fh3>\u003Cp>Obtain the complete content of the log file by reading the file and save it in an array\u003C\u002Fp>\u003Cp>If deleting intermediate log content, it is necessary to remove a certain segment from the middle of the array\u003C\u002Fp>\u003Cp>Here, the approach is to define a new array and, during traversal, only copy logs that meet the conditions\u003C\u002Fp>\u003Cp>I chose to use memcpy; its advantage is that the first parameter can specify the starting address\u003C\u002Fp>\u003Ch3>5. Deleted Log Count\u003C\u002Fh3>\u003Cp>Count the total number of deleted logs, and subtract the total number of deleted logs from the Record number of subsequent logs\u003C\u002Fp>\u003Cp>Subtract the total number of deleted logs from the Last (newest) record number of event records and the end of file record\u003C\u002Fp>\u003Cp>The complete code has been open-sourced, download address:\u003C\u002Fp>\u003Cp>`An open-source project\u003C\u002Fp>\u003Cp>sys1.evt download address:\u003C\u002Fp>\u003Cp>`An open-source project\u003C\u002Fp>\u003Cp>The program reads the file sys1.evt, deletes logs within the specified time range from 2018-7-16 17:46:17 to 2018-7-16 17:46:40, totaling 4 entries\u003C\u002Fp>\u003Cp>Generates files sys2.evt and sys3.evt\u003C\u002Fp>\u003Cp>sys2.evt does not remove trailing empty values\u003C\u002Fp>\u003Cp>sys3.evt removes trailing empty values\u003C\u002Fp>\u003Ch2>0x05 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces the approach and implementation details for deleting log records within a specified time range in evt files, with open-source code, which differs significantly from the deletion methods for evtx files\u003C\u002Fp>\u003Cp>Moreover, the method for deleting evt log records within a specified time range on the current system also differs greatly from that for evtx, which will be detailed in the next article\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr",null,"Onedaysec",5,"published","2026-02-02T07:38:21.202Z",{"title":36,"description":14,"keywords":37,"ogImage":30,"canonicalUrl":30,"noIndex":38},"Delete EVT Logs by Time Range: Program Implementation Guide","Windows Event Viewer, EVT file deletion, log removal, time range deletion, program implementation, open source code, time_t conversion, GMT time, log forensics",false,[],{"docs":41,"hasNextPage":38},[42,43,44,45,4],719,718,717,716,{"title":30,"description":30,"image":30},"2026-07-24T02:07:20.052Z","2026-07-23T16:02:00.018Z","draft","2026-07-23T16:14:21.320Z"]