[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fg21VsKaYxDptlecuikk86euF4KdkhnFaQ0Xz7vPXWvk":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":33,"aiModel":30,"aiConfidence":30,"updatedAt":50,"createdAt":50,"_status":49},719,"Why is the TimeGenerated field value 0x33333333 significant in EVT file parsing?","In EVT files, the end‑of‑file record has a fixed structure where the `TimeGenerated` field is set to the constant 0x33333333. During traversal, when the program encounters this value, it knows that the end of valid log records has been reached and can stop processing. This marker is essential because EVT files do not store an explicit record count in a simple way, making the sentinel value necessary for correct iteration.","\u003Cp>In EVT files, the end‑of‑file record has a fixed structure where the `TimeGenerated` field is set to the constant 0x33333333. During traversal, when the program encounters this value, it knows that the end of valid log records has been reached and can stop processing. This marker is essential because EVT files do not store an explicit record count in a simple way, making the sentinel value necessary for correct iteration.\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fwindows-event-viewer-log-evt-single-log-deletion-part-2-program-implementation-for-deleting-log-records-within-a-specified-time-range-from-evt-files\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","why-is-the-timegenerated-field-value-0x33333333-significant-in-evt-file-parsing-1777482183434","TimeGenerated, 0x33333333, end of file record, sentinel, EVT file structure",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":27,"cover":30,"author":31,"views":19,"readingTime":32,"status":33,"publishedAt":34,"seo":35,"tags":39,"qaPairs":40,"meta":46,"updatedAt":47,"createdAt":48,"_status":49},177,"Windows Event Viewer Log (EVT) Single Log Deletion (Part 2) – Program Implementation for Deleting Log Records within a Specified Time Range from EVT Files","windows-event-viewer-log-evt-single-log-deletion-part-2-program-implementation-for-deleting-log-records-within-a-specified-time-range-from-evt-files","Learn how to delete log records from EVT files within a specified time range. Includes program approach, time_t to GMT conversion, and open-source code.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>The second article in the Windows Event Viewer Log (EVT) Single Log Deletion series. It introduces the approach for deleting log records within a specified time range from an EVT file, addresses multiple design considerations in the program implementation, and provides open-source code.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>Approach for deleting log records within a specified time range from a given EVT file\u003C\u002Fli>\u003Cli>Program implementation details\u003C\u002Fli>\u003Cli>Open-source code\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Approach for Deleting Log Records within a Specified Time Range from an EVT File\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Compared to the single log deletion method for EVTX files mentioned in previous articles, the same approach cannot be applied to EVT files.\u003C\u002Fp>\u003Cp>This is because the EVT file structure does not include a unique value like EventRecordID, making it impossible to locate a specific log entry.\u003C\u002Fp>\u003Cp>Through analysis, it was found that the log creation time can be used as an input parameter. By specifying a start date and an end date, the log content within that time range can be deleted.\u003C\u002Fp>\u003Cp>The format of the log creation time is of type time_t, requiring consideration of the conversion between the time_t type and Greenwich Mean Time (GMT).\u003C\u002Fp>\u003Cp>In terms of program implementation, the approach is as follows:\u003C\u002Fp>\u003Cul>\u003Cli>Traverse all logs, filter out those meeting deletion criteria, and save the remaining log content.\u003C\u002Fli>\u003Cli>After filtering, subtract the number of deleted log entries from the Record numbers of subsequent logs.\u003C\u002Fli>\u003Cli>Update the End of file record offset, Last (newest) record number, and Maximum file size in the file header.\u003C\u002Fli>\u003Cli>Update the End of file record offset and Last (newest) record number in the end of file record.\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x03 Conversion between time_t type and Greenwich Mean Time (GMT).\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>Calendar Time\u003C\u002Fh3>\u003Cp>Calendar time, represented by the time_t data type.\u003C\u002Fp>\u003Cp>Represents 'relative time,' which avoids being affected by time zones; calendar time is the same across different time zones.\u003C\u002Fp>\u003Ch3>time_t type:\u003C\u002Fh3>\u003Cp>Essentially a long integer, representing the number of seconds from 1970-01-01 00:00:00 to the current time.\u003C\u002Fp>\u003Cp>Defined as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>struct tm\u003Cbr>{\u003Cbr>    int tm_sec;   \u002F\u002F seconds after the minute - [0, 60] including leap second\u003Cbr>    int tm_min;   \u002F\u002F minutes after the hour - [0, 59]\u003Cbr>    int tm_hour;  \u002F\u002F hours since midnight - [0, 23]\u003Cbr>    int tm_mday;  \u002F\u002F day of the month - [1, 31]\u003Cbr>    int tm_mon;   \u002F\u002F months since January - [0, 11]\u003Cbr>    int tm_year;  \u002F\u002F years since 1900\u003Cbr>    int tm_wday;  \u002F\u002F days since Sunday - [0, 6]\u003Cbr>    int tm_yday;  \u002F\u002F days since January 1 - [0, 365]\u003Cbr>    int tm_isdst; \u002F\u002F daylight savings time flag\u003Cbr>};\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Note that the year is relative to 1900\u003C\u002Fp>\u003Ch3>Coordinated Universal Time (UTC)\u003C\u002Fh3>\u003Cp>Coordinated Universal Time, also known as World Standard Time, i.e., Greenwich Mean Time (GMT)\u003C\u002Fp>\u003Cp>There are time zone differences; calculating local time requires considering the time difference\u003C\u002Fp>\u003Cp>Example C code for type conversion:\u003C\u002Fp>\u003Cp>Convert Calendar Time to GMT:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>#include \u003Cstdio.h>\u003Cbr>#include \u003Ctime.h>\u003Cbr>int main()\u003Cbr>{\u003Cbr>\t__int64 CalTime = 1531788377;\u003Cbr>\tstruct tm GmTime;\u003Cbr>\tchar GmBuf[26];\u003Cbr>\t_gmtime64_s(&amp;GmTime, &amp;CalTime);\u003Cbr>\tstrftime(GmBuf, 26, \"%m\u002F%d\u002F%Y %r\", &amp;GmTime);\u003Cbr>\tprintf(\"GmTime   :%s\\n\", GmBuf);\u003Cbr>\treturn 0;\u003Cbr>}\u003C\u002Ftime.h>\u003C\u002Fstdio.h>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Convert Calendar Time to local time (considering time difference):\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>#include \u003Cstdio.h>\u003Cbr>#include \u003Ctime.h>\u003Cbr>int main()\u003Cbr>{\u003Cbr>\t__int64 CalTime = 1531788377;\u003Cbr>\tstruct tm LocalTime;\u003Cbr>\tchar LocalBuf[26];\u003Cbr>\t_localtime64_s(&amp;LocalTime, &amp;CalTime);\u003Cbr>\tstrftime(LocalBuf, 26, \"%m\u002F%d\u002F%Y %r\", &amp;LocalTime);\u003Cbr>\tprintf(\"LocalTime:%s\\n\",LocalBuf);\u003Cbr>\treturn 0;\u003Cbr>}\u003C\u002Ftime.h>\u003C\u002Fstdio.h>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Convert time to Calendar Time:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>#include \u003Cstdio.h>\u003Cbr>#include \u003Ctime.h>\u003Cbr>time_t StringToDatetime(char *str)\u003Cbr>{\u003Cbr>\ttm tm_;\u003Cbr>\tint year, month, day, hour, minute, second;\u003Cbr>\tsscanf_s(str, \"%d-%d-%d %d:%d:%d\", &amp;year, &amp;month, &amp;day, &amp;hour, &amp;minute, &amp;second);\u003Cbr>\ttm_.tm_year = year - 1900;\u003Cbr>\ttm_.tm_mon = month - 1;\u003Cbr>\ttm_.tm_mday = day;\u003Cbr>\ttm_.tm_hour = hour-1;\u003Cbr>\ttm_.tm_min = minute;\u003Cbr>\ttm_.tm_sec = second;\u003Cbr>\ttm_.tm_isdst = 0;\u003Cbr>\ttime_t t_ = mktime(&amp;tm_);\u003Cbr>\treturn t_;\u003Cbr>}\u003Cbr>int main()\u003Cbr>{\u003Cbr>\ttime_t sec = StringToDatetime(\"2018-7-16 17:46:17\");\u003Cbr>\tprintf(\"\\n%ld\\n\", sec);\u003Cbr>\treturn 0;\u003Cbr>}\u003C\u002Ftime.h>\u003C\u002Fstdio.h>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x04 Program Implementation Details\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Structure Definitions\u003C\u002Fh3>\u003Cp>File header definition can be referenced at:\u003C\u002Fp>\u003Cp>https:\u002F\u002Ftechnet.microsoft.com\u002Fzh-cn\u002Flibrary\u002Fbb309024\u003C\u002Fp>\u003Cp>Event records definition can be referenced at:\u003C\u002Fp>\u003Cp>https:\u002F\u002Ftechnet.microsoft.com\u002Fzh-cn\u002Flibrary\u002Faa363646\u003C\u002Fp>\u003Cp>End of file record definition can be referenced at:\u003C\u002Fp>\u003Cp>https:\u002F\u002Ftechnet.microsoft.com\u002Fzh-cn\u002Flibrary\u002Fbb309022\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>In the program implementation, to avoid redefinition, I modified the structure name of event records\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>typedef struct _EVTLOGRECORD {\u003Cbr>\tDWORD Length;\u003Cbr>\tDWORD Reserved;\u003Cbr>\tDWORD RecordNumber;\u003Cbr>\tDWORD TimeGenerated;\u003Cbr>\tDWORD TimeWritten;\u003Cbr>\tDWORD EventID;\u003Cbr>\tWORD  EventType;\u003Cbr>\tWORD  NumStrings;\u003Cbr>\tWORD  EventCategory;\u003Cbr>\tWORD  ReservedFlags;\u003Cbr>\tDWORD ClosingRecordNumber;\u003Cbr>\tDWORD StringOffset;\u003Cbr>\tDWORD UserSidLength;\u003Cbr>\tDWORD UserSidOffset;\u003Cbr>\tDWORD DataLength;\u003Cbr>\tDWORD DataOffset;\u003Cbr>} EVTLOGRECORD, *PEVTLOGRECORD;\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>2. Filter Conditions\u003C\u002Fh3>\u003Cp>The TimeGenerated field of the end of file record has a fixed structure with the value 0x33333333\u003C\u002Fp>\u003Cp>During traversal, if TimeGenerated equals 0x33333333, it indicates the end of file record has been located and traversal should terminate\u003C\u002Fp>\u003Ch3>3. Traversal Method\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>while (currentRecordPtr-&gt;TimeGenerated != 0x33333333)\u003Cbr>{\u003Cbr>\t\tif (currentRecordPtr-&gt;TimeGenerated\u003Cstarttimenum ||=\"\" currentrecordptr-=\"\">TimeGenerated&gt;EndTimeNum)\u003Cbr>\t\t{\t\t\u003Cbr>\t\t\t\u002F\u002Fnot selected evt record,copy it\u003Cbr>\t\t}\u003Cbr>\t\telse\u003Cbr>\t\t{\u003Cbr>\t\t\t\u002F\u002Fdelete record\u003Cbr>\t\t}\u003Cbr>\t\tcurrentRecordPtr = nextRecordPtr;\u003Cbr>\t\tnextRecordPtr = (PEVTLOGRECORD)((PBYTE)nextRecordPtr + nextRecordPtr-&gt;Length);\u003Cbr>}\u003C\u002Fstarttimenum>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>4. Log Preservation\u003C\u002Fh3>\u003Cp>Obtain the complete content of the log file by reading the file and save it in an array\u003C\u002Fp>\u003Cp>If deleting intermediate log content, it is necessary to remove a certain segment from the middle of the array\u003C\u002Fp>\u003Cp>Here, the approach is to define a new array and, during traversal, only copy logs that meet the conditions\u003C\u002Fp>\u003Cp>I chose to use memcpy; its advantage is that the first parameter can specify the starting address\u003C\u002Fp>\u003Ch3>5. Deleted Log Count\u003C\u002Fh3>\u003Cp>Count the total number of deleted logs, and subtract the total number of deleted logs from the Record number of subsequent logs\u003C\u002Fp>\u003Cp>Subtract the total number of deleted logs from the Last (newest) record number of event records and the end of file record\u003C\u002Fp>\u003Cp>The complete code has been open-sourced, download address:\u003C\u002Fp>\u003Cp>`An open-source project\u003C\u002Fp>\u003Cp>sys1.evt download address:\u003C\u002Fp>\u003Cp>`An open-source project\u003C\u002Fp>\u003Cp>The program reads the file sys1.evt, deletes logs within the specified time range from 2018-7-16 17:46:17 to 2018-7-16 17:46:40, totaling 4 entries\u003C\u002Fp>\u003Cp>Generates files sys2.evt and sys3.evt\u003C\u002Fp>\u003Cp>sys2.evt does not remove trailing empty values\u003C\u002Fp>\u003Cp>sys3.evt removes trailing empty values\u003C\u002Fp>\u003Ch2>0x05 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces the approach and implementation details for deleting log records within a specified time range in evt files, with open-source code, which differs significantly from the deletion methods for evtx files\u003C\u002Fp>\u003Cp>Moreover, the method for deleting evt log records within a specified time range on the current system also differs greatly from that for evtx, which will be detailed in the next article\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr",null,"Onedaysec",5,"published","2026-02-02T07:38:21.202Z",{"title":36,"description":14,"keywords":37,"ogImage":30,"canonicalUrl":30,"noIndex":38},"Delete EVT Logs by Time Range: Program Implementation Guide","Windows Event Viewer, EVT file deletion, log removal, time range deletion, program implementation, open source code, time_t conversion, GMT time, log forensics",false,[],{"docs":41,"hasNextPage":38},[4,42,43,44,45],718,717,716,715,{"title":30,"description":30,"image":30},"2026-07-24T02:07:20.052Z","2026-07-23T16:02:00.018Z","draft","2026-07-23T16:14:22.122Z"]