event_log

Event Log Plugin Demo


PlatformPub VersionLicenseFlutter Version

A comprehensive Flutter plugin for accessing the Windows Event Log (Event Viewer)
Monitor system events in real-time, query historical events, and manage event subscriptions across Windows Event Log channels with native Win32 integration.

📸 Demo

Event Log Plugin Demo
Real-time event monitoring and historical queries in action

✨ Features

🎯 Real-time Event Monitoring - Subscribe to live events as they occur 📊 Historical Event Queries - Search past events with powerful filtering 🔍 Event Retrieval by ID - Get specific events by their record ID 📝 Channel Management - List and inspect all event log channels 🎨 Advanced Filtering - Filter by level, time range, event ID, provider, and more ⚡ High Performance - Efficient C++ implementation using Windows Event Log API 🔒 Type Safe - Fully typed Dart API with comprehensive error handling

📋 Table of Contents

🖥️ Platform Support

PlatformSupport
Windows
Linux
macOS
Android
iOS

📦 Installation

Run the following command in your terminal:

flutter pub add event_log

Or add this to your package's pubspec.yaml file:

dependencies:
event_log: ^1.0.1

Then run:

flutter pub get

🚀 Quick Start

Get up and running in 3 simple steps:

1️⃣ Import the package

import'package:event_log/event_log.dart';

2️⃣ Query events

final events =awaitEventLog.query(
constEventFilter(channel:'System', maxEvents:10),
);

3️⃣ Subscribe to live events

final subscription =awaitEventLog.subscribe(
constEventFilter(channel:'System'),
);
subscription.listen((event) =>print('🔔 ${event.message}'));

📚 Usage Examples

📋 List Available Channels

// Get all available event log channelsfinal channels =awaitEventLog.listChannels();
for (final channel in channels) {
print('${channel.name}: ${channel.enabled ? "Enabled" : "Disabled"}');
}

📊 Query Historical Events

// Query the last 100 events from the System channelfinal events =awaitEventLog.query(
constEventFilter(
channel:'System',
maxEvents:100,
reverse:true, // Most recent first
),
);
for (final event in events) {
print('${event.timeCreated}: Event ${event.eventId} - ${event.level}');
}

For Analytic and Debug channels, Windows does not allow reverse-native reads. If you set reverse: true, the plugin automatically queries forward and reorders the results in memory so your Dart code still receives newest-first events.

🎯 Filter Events by Level

// Get only errors and critical eventsfinal errorEvents =awaitEventLog.query(
EventFilter(
channel:'Application',
levels: [EventLevel.error, EventLevel.critical],
maxEvents:50,
),
);

⏰ Filter Events by Time Range

// Get events from the last 24 hoursfinal recentEvents =awaitEventLog.query(
EventFilter(
channel:'System',
startTime:DateTime.now().subtract(constDuration(hours:24)),
endTime:DateTime.now(),
),
);

🔴 Subscribe to Real-time Events

// Monitor System events in real-timefinal subscription =awaitEventLog.subscribe(
constEventFilter(channel:'System'),
);
subscription.listen(
(event) {
print('New event: ${event.eventId} - ${event.message}');
},
onError: (error) {
print('Subscription error: $error');
},
);
// Later: cancel the subscriptionawait subscription.cancel();

🔧 Advanced Filtering with XPath

// Use custom XPath queries for complex filteringfinal events =awaitEventLog.query(
constEventFilter(
channel:'Security',
xpathQuery:'*[System[(EventID=4624 or EventID=4625) and TimeCreated[@SystemTime>=\'2026-01-01T00:00:00.000Z\']]]',
),
);

🔍 Get Event by ID

// Retrieve a specific event by its record IDfinal event =awaitEventLog.getById(
12345,
channel:'System', // Optional: specify channel for faster lookup
);
if (event !=null) {
print('Found event: ${event.providerName}');
print('Message: ${event.message}');
print('Time: ${event.timeCreated}');
}

ℹ️ Get Channel Information

// Get detailed information about a channelfinal channelInfo =awaitEventLog.getChannelInfo('System');
if (channelInfo !=null) {
print('Channel: ${channelInfo.name}');
print('Type: ${channelInfo.type}');
print('Enabled: ${channelInfo.enabled}');
print('Log Path: ${channelInfo.logFilePath}');
}

🗑️ Clear Channel Events

⚠️ Requires Administrator Privileges

// Clear all events from a channeltry {
awaitEventLog.clear(
'Application',
backupPath:r'C:\Backups\app_events.evtx', // Optional: backup before clearing
);
print('Channel cleared successfully');
} onAccessDeniedException {
print('Access denied: Administrator privileges required');
} onChannelNotFoundException {
print('Channel not found');
}

📖 API Reference

Event Properties

Each EventRecord contains comprehensive event information:

classEventRecord {
finalint eventRecordId; // Unique event record IDfinalint eventId; // Event identifierfinalEventLevel level; // Severity levelfinalDateTime timeCreated; // TimestampfinalString channel; // Channel namefinalString computer; // Computer namefinalString providerName; // Event providerfinalString? providerGuid; // Provider GUIDfinalint? task; // Task categoryfinalint? opcode; // Operation codefinalint? keywords; // Keywords bitmaskfinalint? processId; // Process IDfinalint? threadId; // Thread IDfinalString? userId; // User SIDfinalString? activityId; // Activity correlation IDfinalString? message; // Formatted messagefinalString? xml; // Event as XMLfinalMap<String, dynamic>? eventData; // Event-specific data
}

Event Levels

enumEventLevel {
critical, // Level 1
error, // Level 2
warning, // Level 3
information, // Level 4
verbose, // Level 5
logAlways, // Level 0
}

Common Channels

  • System - System events (hardware, drivers, OS)
  • Application - Application events
  • Security - Security audit events (requires admin for read access)
  • Setup - Setup and deployment events
  • Windows PowerShell - PowerShell events
  • Microsoft-Windows-* - Various Windows component logs

Error Handling

The plugin provides specific exception types:

try {
final events =awaitEventLog.query(filter);
} onAccessDeniedExceptioncatch (e) {
print('Access denied: ${e.message}');
} onChannelNotFoundExceptioncatch (e) {
print('Channel not found: ${e.message}');
} onInvalidQueryExceptioncatch (e) {
print('Invalid query: ${e.message}');
} onUnsupportedChannelExceptioncatch (e) {
print('Unsupported channel operation: ${e.message}');
} onEventLogExceptioncatch (e) {
print('Event log error: ${e.message}');
}

UnsupportedChannelException is raised when Windows rejects the requested operation for that channel, such as attempting a live subscription on an Analytic or Debug log.

Live subscriptions are supported for Admin and Operational channels. Analytic and Debug channels are the specific channel types that do not support live subscriptions through the Windows Event Log subscription API.


⚡ Performance Considerations

  • Channel-specific queries are faster than cross-channel queries
  • XPath queries with specific filters are more efficient than wildcard queries
  • Subscriptions use Windows Event Log's native callbacks for optimal performance
  • Limit maxEvents to avoid loading excessive data
  • Time range filters help narrow down results

🔐 Permissions

  • Basic queries - Standard user privileges
  • Security channel - Often requires administrator privileges
  • Clear channel - Requires administrator privileges
  • Some subscriptions - May require elevated privileges depending on the channel
  • Live subscriptions - Supported for Admin and Operational channels
  • Analytic and Debug channels - Historical queries are forward-only at the Windows API layer. The plugin transparently emulates reverse: true for queries, but live subscriptions are not supported by the Windows Event Log subscription API and will throw UnsupportedChannelException

💻 Example App

Run the example app to see all features in action:

cd example
flutter run -d windows

🎨 Example App Features

  • Channel Browser - Browse and select from all system channels
  • Historical Queries - Query past events with filtering
  • Event Filtering - Filter by severity level (errors only, warnings, etc.)
  • Live Monitoring - Subscribe to real-time events with visual indicators
  • Event Details - Expandable cards showing all event properties
  • Material Design 3 - Beautiful, modern UI

🛠️ Development

Install the repository-managed Git hooks to auto-format staged Dart and C/C++ files before each commit:

pwsh -File scripts/install-git-hooks.ps1

The pre-commit hook runs:

  • dart format for staged .dart files
  • clang-format -i for staged C/C++ source and header files

To format every tracked Dart and C/C++ file in the repository once:

pwsh -File scripts/format_all.ps1

🏗️ Architecture

The plugin uses:

  • Dart Layer: Clean API with Stream support and Flutter integration
  • Platform Interface: Pluggable architecture for future platform support
  • Windows C++: Native implementation using Windows Event Log API (winevt.h)
  • Method Channels: For synchronous operations (queries, channel info)
  • Event Channels: For asynchronous event streaming (subscriptions)

🔌 Windows Event Log API

This plugin wraps the following Windows APIs:

  • EvtQuery - Query historical events
  • EvtSubscribe - Subscribe to live events
  • EvtNext - Iterate through events
  • EvtRender - Render event data
  • EvtOpenChannelEnum - Enumerate channels
  • EvtClearLog - Clear channel events

🤝 Contributing

Contributions are welcome! Here's how you can help:

  1. 🐛 Report bugs - Open an issue with details
  2. 💡 Suggest features - Share your ideas
  3. 🔧 Submit PRs - Fix bugs or add features
  4. 📖 Improve docs - Help others understand the plugin

Please read our Contributing Guidelines before submitting PRs.

📄 License

Copyright © 2026 Kaan Gönüldinc

Licensed under the Apache License, Version 2.0 (the "License"); you may not use this file except in compliance with the License. You may obtain a copy of the License at

http://www.apache.org/licenses/LICENSE-2.0

Unless required by applicable law or agreed to in writing, software distributed under the License is distributed on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the License for the specific language governing permissions and limitations under the License.

See LICENSE for more details.

About

A comprehensive Flutter plugin for accessing the Windows Event Log (Event Viewer). Monitor system events, query historical logs, and manage subscriptions with full Windows Event Log API support.

Topics

Resources

Code of conduct

Contributing

Security policy

Stars

1 star

Watchers

0 watching

Forks

Releases

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

event_log

Event Log Plugin Demo


PlatformPub VersionLicenseFlutter Version

A comprehensive Flutter plugin for accessing the Windows Event Log (Event Viewer)
Monitor system events in real-time, query historical events, and manage event subscriptions across Windows Event Log channels with native Win32 integration.

📸 Demo

Event Log Plugin Demo
Real-time event monitoring and historical queries in action

✨ Features

🎯 Real-time Event Monitoring - Subscribe to live events as they occur 📊 Historical Event Queries - Search past events with powerful filtering 🔍 Event Retrieval by ID - Get specific events by their record ID 📝 Channel Management - List and inspect all event log channels 🎨 Advanced Filtering - Filter by level, time range, event ID, provider, and more ⚡ High Performance - Efficient C++ implementation using Windows Event Log API 🔒 Type Safe - Fully typed Dart API with comprehensive error handling

📋 Table of Contents

🖥️ Platform Support

PlatformSupport
Windows
Linux
macOS
Android
iOS

📦 Installation

Run the following command in your terminal:

flutter pub add event_log

Or add this to your package's pubspec.yaml file:

dependencies:
event_log: ^1.0.1

Then run:

flutter pub get

🚀 Quick Start

Get up and running in 3 simple steps:

1️⃣ Import the package

import'package:event_log/event_log.dart';

2️⃣ Query events

final events =awaitEventLog.query(
constEventFilter(channel:'System', maxEvents:10),
);

3️⃣ Subscribe to live events

final subscription =awaitEventLog.subscribe(
constEventFilter(channel:'System'),
);
subscription.listen((event) =>print('🔔 ${event.message}'));

📚 Usage Examples

📋 List Available Channels

// Get all available event log channelsfinal channels =awaitEventLog.listChannels();
for (final channel in channels) {
print('${channel.name}: ${channel.enabled ? "Enabled" : "Disabled"}');
}

📊 Query Historical Events

// Query the last 100 events from the System channelfinal events =awaitEventLog.query(
constEventFilter(
channel:'System',
maxEvents:100,
reverse:true, // Most recent first
),
);
for (final event in events) {
print('${event.timeCreated}: Event ${event.eventId} - ${event.level}');
}

For Analytic and Debug channels, Windows does not allow reverse-native reads. If you set reverse: true, the plugin automatically queries forward and reorders the results in memory so your Dart code still receives newest-first events.

🎯 Filter Events by Level

// Get only errors and critical eventsfinal errorEvents =awaitEventLog.query(
EventFilter(
channel:'Application',
levels: [EventLevel.error, EventLevel.critical],
maxEvents:50,
),
);

⏰ Filter Events by Time Range

// Get events from the last 24 hoursfinal recentEvents =awaitEventLog.query(
EventFilter(
channel:'System',
startTime:DateTime.now().subtract(constDuration(hours:24)),
endTime:DateTime.now(),
),
);

🔴 Subscribe to Real-time Events

// Monitor System events in real-timefinal subscription =awaitEventLog.subscribe(
constEventFilter(channel:'System'),
);
subscription.listen(
(event) {
print('New event: ${event.eventId} - ${event.message}');
},
onError: (error) {
print('Subscription error: $error');
},
);
// Later: cancel the subscriptionawait subscription.cancel();

🔧 Advanced Filtering with XPath

// Use custom XPath queries for complex filteringfinal events =awaitEventLog.query(
constEventFilter(
channel:'Security',
xpathQuery:'*[System[(EventID=4624 or EventID=4625) and TimeCreated[@SystemTime>=\'2026-01-01T00:00:00.000Z\']]]',
),
);

🔍 Get Event by ID

// Retrieve a specific event by its record IDfinal event =awaitEventLog.getById(
12345,
channel:'System', // Optional: specify channel for faster lookup
);
if (event !=null) {
print('Found event: ${event.providerName}');
print('Message: ${event.message}');
print('Time: ${event.timeCreated}');
}

ℹ️ Get Channel Information

// Get detailed information about a channelfinal channelInfo =awaitEventLog.getChannelInfo('System');
if (channelInfo !=null) {
print('Channel: ${channelInfo.name}');
print('Type: ${channelInfo.type}');
print('Enabled: ${channelInfo.enabled}');
print('Log Path: ${channelInfo.logFilePath}');
}

🗑️ Clear Channel Events

⚠️ Requires Administrator Privileges

// Clear all events from a channeltry {
awaitEventLog.clear(
'Application',
backupPath:r'C:\Backups\app_events.evtx', // Optional: backup before clearing
);
print('Channel cleared successfully');
} onAccessDeniedException {
print('Access denied: Administrator privileges required');
} onChannelNotFoundException {
print('Channel not found');
}

📖 API Reference

Event Properties

Each EventRecord contains comprehensive event information:

classEventRecord {
finalint eventRecordId; // Unique event record IDfinalint eventId; // Event identifierfinalEventLevel level; // Severity levelfinalDateTime timeCreated; // TimestampfinalString channel; // Channel namefinalString computer; // Computer namefinalString providerName; // Event providerfinalString? providerGuid; // Provider GUIDfinalint? task; // Task categoryfinalint? opcode; // Operation codefinalint? keywords; // Keywords bitmaskfinalint? processId; // Process IDfinalint? threadId; // Thread IDfinalString? userId; // User SIDfinalString? activityId; // Activity correlation IDfinalString? message; // Formatted messagefinalString? xml; // Event as XMLfinalMap<String, dynamic>? eventData; // Event-specific data
}

Event Levels

enumEventLevel {
critical, // Level 1
error, // Level 2
warning, // Level 3
information, // Level 4
verbose, // Level 5
logAlways, // Level 0
}

Common Channels

  • System - System events (hardware, drivers, OS)
  • Application - Application events
  • Security - Security audit events (requires admin for read access)
  • Setup - Setup and deployment events
  • Windows PowerShell - PowerShell events
  • Microsoft-Windows-* - Various Windows component logs

Error Handling

The plugin provides specific exception types:

try {
final events =awaitEventLog.query(filter);
} onAccessDeniedExceptioncatch (e) {
print('Access denied: ${e.message}');
} onChannelNotFoundExceptioncatch (e) {
print('Channel not found: ${e.message}');
} onInvalidQueryExceptioncatch (e) {
print('Invalid query: ${e.message}');
} onUnsupportedChannelExceptioncatch (e) {
print('Unsupported channel operation: ${e.message}');
} onEventLogExceptioncatch (e) {
print('Event log error: ${e.message}');
}

UnsupportedChannelException is raised when Windows rejects the requested operation for that channel, such as attempting a live subscription on an Analytic or Debug log.

Live subscriptions are supported for Admin and Operational channels. Analytic and Debug channels are the specific channel types that do not support live subscriptions through the Windows Event Log subscription API.


⚡ Performance Considerations

  • Channel-specific queries are faster than cross-channel queries
  • XPath queries with specific filters are more efficient than wildcard queries
  • Subscriptions use Windows Event Log's native callbacks for optimal performance
  • Limit maxEvents to avoid loading excessive data
  • Time range filters help narrow down results

🔐 Permissions

  • Basic queries - Standard user privileges
  • Security channel - Often requires administrator privileges
  • Clear channel - Requires administrator privileges
  • Some subscriptions - May require elevated privileges depending on the channel
  • Live subscriptions - Supported for Admin and Operational channels
  • Analytic and Debug channels - Historical queries are forward-only at the Windows API layer. The plugin transparently emulates reverse: true for queries, but live subscriptions are not supported by the Windows Event Log subscription API and will throw UnsupportedChannelException

💻 Example App

Run the example app to see all features in action:

cd example
flutter run -d windows

🎨 Example App Features

  • Channel Browser - Browse and select from all system channels
  • Historical Queries - Query past events with filtering
  • Event Filtering - Filter by severity level (errors only, warnings, etc.)
  • Live Monitoring - Subscribe to real-time events with visual indicators
  • Event Details - Expandable cards showing all event properties
  • Material Design 3 - Beautiful, modern UI

🛠️ Development

Install the repository-managed Git hooks to auto-format staged Dart and C/C++ files before each commit:

pwsh -File scripts/install-git-hooks.ps1

The pre-commit hook runs:

  • dart format for staged .dart files
  • clang-format -i for staged C/C++ source and header files

To format every tracked Dart and C/C++ file in the repository once:

pwsh -File scripts/format_all.ps1

🏗️ Architecture

The plugin uses:

  • Dart Layer: Clean API with Stream support and Flutter integration
  • Platform Interface: Pluggable architecture for future platform support
  • Windows C++: Native implementation using Windows Event Log API (winevt.h)
  • Method Channels: For synchronous operations (queries, channel info)
  • Event Channels: For asynchronous event streaming (subscriptions)

🔌 Windows Event Log API

This plugin wraps the following Windows APIs:

  • EvtQuery - Query historical events
  • EvtSubscribe - Subscribe to live events
  • EvtNext - Iterate through events
  • EvtRender - Render event data
  • EvtOpenChannelEnum - Enumerate channels
  • EvtClearLog - Clear channel events

🤝 Contributing

Contributions are welcome! Here's how you can help:

  1. 🐛 Report bugs - Open an issue with details
  2. 💡 Suggest features - Share your ideas
  3. 🔧 Submit PRs - Fix bugs or add features
  4. 📖 Improve docs - Help others understand the plugin

Please read our Contributing Guidelines before submitting PRs.

📄 License

Copyright © 2026 Kaan Gönüldinc

Licensed under the Apache License, Version 2.0 (the "License"); you may not use this file except in compliance with the License. You may obtain a copy of the License at

http://www.apache.org/licenses/LICENSE-2.0

Unless required by applicable law or agreed to in writing, software distributed under the License is distributed on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the License for the specific language governing permissions and limitations under the License.

See LICENSE for more details.

About

A comprehensive Flutter plugin for accessing the Windows Event Log (Event Viewer). Monitor system events, query historical logs, and manage subscriptions with full Windows Event Log API support.

Topics

Resources

Code of conduct

Contributing

Security policy

Stars

1 star

Watchers

0 watching

Forks

Releases

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

event_log

Event Log Plugin Demo


PlatformPub VersionLicenseFlutter Version

A comprehensive Flutter plugin for accessing the Windows Event Log (Event Viewer)
Monitor system events in real-time, query historical events, and manage event subscriptions across Windows Event Log channels with native Win32 integration.

📸 Demo

Event Log Plugin Demo
Real-time event monitoring and historical queries in action

✨ Features

🎯 Real-time Event Monitoring - Subscribe to live events as they occur 📊 Historical Event Queries - Search past events with powerful filtering 🔍 Event Retrieval by ID - Get specific events by their record ID 📝 Channel Management - List and inspect all event log channels 🎨 Advanced Filtering - Filter by level, time range, event ID, provider, and more ⚡ High Performance - Efficient C++ implementation using Windows Event Log API 🔒 Type Safe - Fully typed Dart API with comprehensive error handling

📋 Table of Contents

🖥️ Platform Support

PlatformSupport
Windows
Linux
macOS
Android
iOS

📦 Installation

Run the following command in your terminal:

flutter pub add event_log

Or add this to your package's pubspec.yaml file:

dependencies:
event_log: ^1.0.1

Then run:

flutter pub get

🚀 Quick Start

Get up and running in 3 simple steps:

1️⃣ Import the package

import'package:event_log/event_log.dart';

2️⃣ Query events

final events =awaitEventLog.query(
constEventFilter(channel:'System', maxEvents:10),
);

3️⃣ Subscribe to live events

final subscription =awaitEventLog.subscribe(
constEventFilter(channel:'System'),
);
subscription.listen((event) =>print('🔔 ${event.message}'));

📚 Usage Examples

📋 List Available Channels

// Get all available event log channelsfinal channels =awaitEventLog.listChannels();
for (final channel in channels) {
print('${channel.name}: ${channel.enabled ? "Enabled" : "Disabled"}');
}

📊 Query Historical Events

// Query the last 100 events from the System channelfinal events =awaitEventLog.query(
constEventFilter(
channel:'System',
maxEvents:100,
reverse:true, // Most recent first
),
);
for (final event in events) {
print('${event.timeCreated}: Event ${event.eventId} - ${event.level}');
}

For Analytic and Debug channels, Windows does not allow reverse-native reads. If you set reverse: true, the plugin automatically queries forward and reorders the results in memory so your Dart code still receives newest-first events.

🎯 Filter Events by Level

// Get only errors and critical eventsfinal errorEvents =awaitEventLog.query(
EventFilter(
channel:'Application',
levels: [EventLevel.error, EventLevel.critical],
maxEvents:50,
),
);

⏰ Filter Events by Time Range

// Get events from the last 24 hoursfinal recentEvents =awaitEventLog.query(
EventFilter(
channel:'System',
startTime:DateTime.now().subtract(constDuration(hours:24)),
endTime:DateTime.now(),
),
);

🔴 Subscribe to Real-time Events

// Monitor System events in real-timefinal subscription =awaitEventLog.subscribe(
constEventFilter(channel:'System'),
);
subscription.listen(
(event) {
print('New event: ${event.eventId} - ${event.message}');
},
onError: (error) {
print('Subscription error: $error');
},
);
// Later: cancel the subscriptionawait subscription.cancel();

🔧 Advanced Filtering with XPath

// Use custom XPath queries for complex filteringfinal events =awaitEventLog.query(
constEventFilter(
channel:'Security',
xpathQuery:'*[System[(EventID=4624 or EventID=4625) and TimeCreated[@SystemTime>=\'2026-01-01T00:00:00.000Z\']]]',
),
);

🔍 Get Event by ID

// Retrieve a specific event by its record IDfinal event =awaitEventLog.getById(
12345,
channel:'System', // Optional: specify channel for faster lookup
);
if (event !=null) {
print('Found event: ${event.providerName}');
print('Message: ${event.message}');
print('Time: ${event.timeCreated}');
}

ℹ️ Get Channel Information

// Get detailed information about a channelfinal channelInfo =awaitEventLog.getChannelInfo('System');
if (channelInfo !=null) {
print('Channel: ${channelInfo.name}');
print('Type: ${channelInfo.type}');
print('Enabled: ${channelInfo.enabled}');
print('Log Path: ${channelInfo.logFilePath}');
}

🗑️ Clear Channel Events

⚠️ Requires Administrator Privileges

// Clear all events from a channeltry {
awaitEventLog.clear(
'Application',
backupPath:r'C:\Backups\app_events.evtx', // Optional: backup before clearing
);
print('Channel cleared successfully');
} onAccessDeniedException {
print('Access denied: Administrator privileges required');
} onChannelNotFoundException {
print('Channel not found');
}

📖 API Reference

Event Properties

Each EventRecord contains comprehensive event information:

classEventRecord {
finalint eventRecordId; // Unique event record IDfinalint eventId; // Event identifierfinalEventLevel level; // Severity levelfinalDateTime timeCreated; // TimestampfinalString channel; // Channel namefinalString computer; // Computer namefinalString providerName; // Event providerfinalString? providerGuid; // Provider GUIDfinalint? task; // Task categoryfinalint? opcode; // Operation codefinalint? keywords; // Keywords bitmaskfinalint? processId; // Process IDfinalint? threadId; // Thread IDfinalString? userId; // User SIDfinalString? activityId; // Activity correlation IDfinalString? message; // Formatted messagefinalString? xml; // Event as XMLfinalMap<String, dynamic>? eventData; // Event-specific data
}

Event Levels

enumEventLevel {
critical, // Level 1
error, // Level 2
warning, // Level 3
information, // Level 4
verbose, // Level 5
logAlways, // Level 0
}

Common Channels

  • System - System events (hardware, drivers, OS)
  • Application - Application events
  • Security - Security audit events (requires admin for read access)
  • Setup - Setup and deployment events
  • Windows PowerShell - PowerShell events
  • Microsoft-Windows-* - Various Windows component logs

Error Handling

The plugin provides specific exception types:

try {
final events =awaitEventLog.query(filter);
} onAccessDeniedExceptioncatch (e) {
print('Access denied: ${e.message}');
} onChannelNotFoundExceptioncatch (e) {
print('Channel not found: ${e.message}');
} onInvalidQueryExceptioncatch (e) {
print('Invalid query: ${e.message}');
} onUnsupportedChannelExceptioncatch (e) {
print('Unsupported channel operation: ${e.message}');
} onEventLogExceptioncatch (e) {
print('Event log error: ${e.message}');
}

UnsupportedChannelException is raised when Windows rejects the requested operation for that channel, such as attempting a live subscription on an Analytic or Debug log.

Live subscriptions are supported for Admin and Operational channels. Analytic and Debug channels are the specific channel types that do not support live subscriptions through the Windows Event Log subscription API.


⚡ Performance Considerations

  • Channel-specific queries are faster than cross-channel queries
  • XPath queries with specific filters are more efficient than wildcard queries
  • Subscriptions use Windows Event Log's native callbacks for optimal performance
  • Limit maxEvents to avoid loading excessive data
  • Time range filters help narrow down results

🔐 Permissions

  • Basic queries - Standard user privileges
  • Security channel - Often requires administrator privileges
  • Clear channel - Requires administrator privileges
  • Some subscriptions - May require elevated privileges depending on the channel
  • Live subscriptions - Supported for Admin and Operational channels
  • Analytic and Debug channels - Historical queries are forward-only at the Windows API layer. The plugin transparently emulates reverse: true for queries, but live subscriptions are not supported by the Windows Event Log subscription API and will throw UnsupportedChannelException

💻 Example App

Run the example app to see all features in action:

cd example
flutter run -d windows

🎨 Example App Features

  • Channel Browser - Browse and select from all system channels
  • Historical Queries - Query past events with filtering
  • Event Filtering - Filter by severity level (errors only, warnings, etc.)
  • Live Monitoring - Subscribe to real-time events with visual indicators
  • Event Details - Expandable cards showing all event properties
  • Material Design 3 - Beautiful, modern UI

🛠️ Development

Install the repository-managed Git hooks to auto-format staged Dart and C/C++ files before each commit:

pwsh -File scripts/install-git-hooks.ps1

The pre-commit hook runs:

  • dart format for staged .dart files
  • clang-format -i for staged C/C++ source and header files

To format every tracked Dart and C/C++ file in the repository once:

pwsh -File scripts/format_all.ps1

🏗️ Architecture

The plugin uses:

  • Dart Layer: Clean API with Stream support and Flutter integration
  • Platform Interface: Pluggable architecture for future platform support
  • Windows C++: Native implementation using Windows Event Log API (winevt.h)
  • Method Channels: For synchronous operations (queries, channel info)
  • Event Channels: For asynchronous event streaming (subscriptions)

🔌 Windows Event Log API

This plugin wraps the following Windows APIs:

  • EvtQuery - Query historical events
  • EvtSubscribe - Subscribe to live events
  • EvtNext - Iterate through events
  • EvtRender - Render event data
  • EvtOpenChannelEnum - Enumerate channels
  • EvtClearLog - Clear channel events

🤝 Contributing

Contributions are welcome! Here's how you can help:

  1. 🐛 Report bugs - Open an issue with details
  2. 💡 Suggest features - Share your ideas
  3. 🔧 Submit PRs - Fix bugs or add features
  4. 📖 Improve docs - Help others understand the plugin

Please read our Contributing Guidelines before submitting PRs.

📄 License

Copyright © 2026 Kaan Gönüldinc

Licensed under the Apache License, Version 2.0 (the "License"); you may not use this file except in compliance with the License. You may obtain a copy of the License at

http://www.apache.org/licenses/LICENSE-2.0

Unless required by applicable law or agreed to in writing, software distributed under the License is distributed on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the License for the specific language governing permissions and limitations under the License.

See LICENSE for more details.

About

A comprehensive Flutter plugin for accessing the Windows Event Log (Event Viewer). Monitor system events, query historical logs, and manage subscriptions with full Windows Event Log API support.

Topics

Resources

Code of conduct

Contributing

Security policy

Stars

1 star

Watchers

0 watching

Forks

Releases

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

event_log

Event Log Plugin Demo


PlatformPub VersionLicenseFlutter Version

A comprehensive Flutter plugin for accessing the Windows Event Log (Event Viewer)
Monitor system events in real-time, query historical events, and manage event subscriptions across Windows Event Log channels with native Win32 integration.

📸 Demo

Event Log Plugin Demo
Real-time event monitoring and historical queries in action

✨ Features

🎯 Real-time Event Monitoring - Subscribe to live events as they occur 📊 Historical Event Queries - Search past events with powerful filtering 🔍 Event Retrieval by ID - Get specific events by their record ID 📝 Channel Management - List and inspect all event log channels 🎨 Advanced Filtering - Filter by level, time range, event ID, provider, and more ⚡ High Performance - Efficient C++ implementation using Windows Event Log API 🔒 Type Safe - Fully typed Dart API with comprehensive error handling

📋 Table of Contents

🖥️ Platform Support

PlatformSupport
Windows
Linux
macOS
Android
iOS

📦 Installation

Run the following command in your terminal:

flutter pub add event_log

Or add this to your package's pubspec.yaml file:

dependencies:
event_log: ^1.0.1

Then run:

flutter pub get

🚀 Quick Start

Get up and running in 3 simple steps:

1️⃣ Import the package

import'package:event_log/event_log.dart';

2️⃣ Query events

final events =awaitEventLog.query(
constEventFilter(channel:'System', maxEvents:10),
);

3️⃣ Subscribe to live events

final subscription =awaitEventLog.subscribe(
constEventFilter(channel:'System'),
);
subscription.listen((event) =>print('🔔 ${event.message}'));

📚 Usage Examples

📋 List Available Channels

// Get all available event log channelsfinal channels =awaitEventLog.listChannels();
for (final channel in channels) {
print('${channel.name}: ${channel.enabled ? "Enabled" : "Disabled"}');
}

📊 Query Historical Events

// Query the last 100 events from the System channelfinal events =awaitEventLog.query(
constEventFilter(
channel:'System',
maxEvents:100,
reverse:true, // Most recent first
),
);
for (final event in events) {
print('${event.timeCreated}: Event ${event.eventId} - ${event.level}');
}

For Analytic and Debug channels, Windows does not allow reverse-native reads. If you set reverse: true, the plugin automatically queries forward and reorders the results in memory so your Dart code still receives newest-first events.

🎯 Filter Events by Level

// Get only errors and critical eventsfinal errorEvents =awaitEventLog.query(
EventFilter(
channel:'Application',
levels: [EventLevel.error, EventLevel.critical],
maxEvents:50,
),
);

⏰ Filter Events by Time Range

// Get events from the last 24 hoursfinal recentEvents =awaitEventLog.query(
EventFilter(
channel:'System',
startTime:DateTime.now().subtract(constDuration(hours:24)),
endTime:DateTime.now(),
),
);

🔴 Subscribe to Real-time Events

// Monitor System events in real-timefinal subscription =awaitEventLog.subscribe(
constEventFilter(channel:'System'),
);
subscription.listen(
(event) {
print('New event: ${event.eventId} - ${event.message}');
},
onError: (error) {
print('Subscription error: $error');
},
);
// Later: cancel the subscriptionawait subscription.cancel();

🔧 Advanced Filtering with XPath

// Use custom XPath queries for complex filteringfinal events =awaitEventLog.query(
constEventFilter(
channel:'Security',
xpathQuery:'*[System[(EventID=4624 or EventID=4625) and TimeCreated[@SystemTime>=\'2026-01-01T00:00:00.000Z\']]]',
),
);

🔍 Get Event by ID

// Retrieve a specific event by its record IDfinal event =awaitEventLog.getById(
12345,
channel:'System', // Optional: specify channel for faster lookup
);
if (event !=null) {
print('Found event: ${event.providerName}');
print('Message: ${event.message}');
print('Time: ${event.timeCreated}');
}

ℹ️ Get Channel Information

// Get detailed information about a channelfinal channelInfo =awaitEventLog.getChannelInfo('System');
if (channelInfo !=null) {
print('Channel: ${channelInfo.name}');
print('Type: ${channelInfo.type}');
print('Enabled: ${channelInfo.enabled}');
print('Log Path: ${channelInfo.logFilePath}');
}

🗑️ Clear Channel Events

⚠️ Requires Administrator Privileges

// Clear all events from a channeltry {
awaitEventLog.clear(
'Application',
backupPath:r'C:\Backups\app_events.evtx', // Optional: backup before clearing
);
print('Channel cleared successfully');
} onAccessDeniedException {
print('Access denied: Administrator privileges required');
} onChannelNotFoundException {
print('Channel not found');
}

📖 API Reference

Event Properties

Each EventRecord contains comprehensive event information:

classEventRecord {
finalint eventRecordId; // Unique event record IDfinalint eventId; // Event identifierfinalEventLevel level; // Severity levelfinalDateTime timeCreated; // TimestampfinalString channel; // Channel namefinalString computer; // Computer namefinalString providerName; // Event providerfinalString? providerGuid; // Provider GUIDfinalint? task; // Task categoryfinalint? opcode; // Operation codefinalint? keywords; // Keywords bitmaskfinalint? processId; // Process IDfinalint? threadId; // Thread IDfinalString? userId; // User SIDfinalString? activityId; // Activity correlation IDfinalString? message; // Formatted messagefinalString? xml; // Event as XMLfinalMap<String, dynamic>? eventData; // Event-specific data
}

Event Levels

enumEventLevel {
critical, // Level 1
error, // Level 2
warning, // Level 3
information, // Level 4
verbose, // Level 5
logAlways, // Level 0
}

Common Channels

  • System - System events (hardware, drivers, OS)
  • Application - Application events
  • Security - Security audit events (requires admin for read access)
  • Setup - Setup and deployment events
  • Windows PowerShell - PowerShell events
  • Microsoft-Windows-* - Various Windows component logs

Error Handling

The plugin provides specific exception types:

try {
final events =awaitEventLog.query(filter);
} onAccessDeniedExceptioncatch (e) {
print('Access denied: ${e.message}');
} onChannelNotFoundExceptioncatch (e) {
print('Channel not found: ${e.message}');
} onInvalidQueryExceptioncatch (e) {
print('Invalid query: ${e.message}');
} onUnsupportedChannelExceptioncatch (e) {
print('Unsupported channel operation: ${e.message}');
} onEventLogExceptioncatch (e) {
print('Event log error: ${e.message}');
}

UnsupportedChannelException is raised when Windows rejects the requested operation for that channel, such as attempting a live subscription on an Analytic or Debug log.

Live subscriptions are supported for Admin and Operational channels. Analytic and Debug channels are the specific channel types that do not support live subscriptions through the Windows Event Log subscription API.


⚡ Performance Considerations

  • Channel-specific queries are faster than cross-channel queries
  • XPath queries with specific filters are more efficient than wildcard queries
  • Subscriptions use Windows Event Log's native callbacks for optimal performance
  • Limit maxEvents to avoid loading excessive data
  • Time range filters help narrow down results

🔐 Permissions

  • Basic queries - Standard user privileges
  • Security channel - Often requires administrator privileges
  • Clear channel - Requires administrator privileges
  • Some subscriptions - May require elevated privileges depending on the channel
  • Live subscriptions - Supported for Admin and Operational channels
  • Analytic and Debug channels - Historical queries are forward-only at the Windows API layer. The plugin transparently emulates reverse: true for queries, but live subscriptions are not supported by the Windows Event Log subscription API and will throw UnsupportedChannelException

💻 Example App

Run the example app to see all features in action:

cd example
flutter run -d windows

🎨 Example App Features

  • Channel Browser - Browse and select from all system channels
  • Historical Queries - Query past events with filtering
  • Event Filtering - Filter by severity level (errors only, warnings, etc.)
  • Live Monitoring - Subscribe to real-time events with visual indicators
  • Event Details - Expandable cards showing all event properties
  • Material Design 3 - Beautiful, modern UI

🛠️ Development

Install the repository-managed Git hooks to auto-format staged Dart and C/C++ files before each commit:

pwsh -File scripts/install-git-hooks.ps1

The pre-commit hook runs:

  • dart format for staged .dart files
  • clang-format -i for staged C/C++ source and header files

To format every tracked Dart and C/C++ file in the repository once:

pwsh -File scripts/format_all.ps1

🏗️ Architecture

The plugin uses:

  • Dart Layer: Clean API with Stream support and Flutter integration
  • Platform Interface: Pluggable architecture for future platform support
  • Windows C++: Native implementation using Windows Event Log API (winevt.h)
  • Method Channels: For synchronous operations (queries, channel info)
  • Event Channels: For asynchronous event streaming (subscriptions)

🔌 Windows Event Log API

This plugin wraps the following Windows APIs:

  • EvtQuery - Query historical events
  • EvtSubscribe - Subscribe to live events
  • EvtNext - Iterate through events
  • EvtRender - Render event data
  • EvtOpenChannelEnum - Enumerate channels
  • EvtClearLog - Clear channel events

🤝 Contributing

Contributions are welcome! Here's how you can help:

  1. 🐛 Report bugs - Open an issue with details
  2. 💡 Suggest features - Share your ideas
  3. 🔧 Submit PRs - Fix bugs or add features
  4. 📖 Improve docs - Help others understand the plugin

Please read our Contributing Guidelines before submitting PRs.

📄 License

Copyright © 2026 Kaan Gönüldinc

Licensed under the Apache License, Version 2.0 (the "License"); you may not use this file except in compliance with the License. You may obtain a copy of the License at

http://www.apache.org/licenses/LICENSE-2.0

Unless required by applicable law or agreed to in writing, software distributed under the License is distributed on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the License for the specific language governing permissions and limitations under the License.

See LICENSE for more details.

About

A comprehensive Flutter plugin for accessing the Windows Event Log (Event Viewer). Monitor system events, query historical logs, and manage subscriptions with full Windows Event Log API support.

Topics

Resources

Code of conduct

Contributing

Security policy

Stars

1 star

Watchers

0 watching

Forks

Releases

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

event_log

Event Log Plugin Demo


PlatformPub VersionLicenseFlutter Version

A comprehensive Flutter plugin for accessing the Windows Event Log (Event Viewer)
Monitor system events in real-time, query historical events, and manage event subscriptions across Windows Event Log channels with native Win32 integration.

📸 Demo

Event Log Plugin Demo
Real-time event monitoring and historical queries in action

✨ Features

🎯 Real-time Event Monitoring - Subscribe to live events as they occur 📊 Historical Event Queries - Search past events with powerful filtering 🔍 Event Retrieval by ID - Get specific events by their record ID 📝 Channel Management - List and inspect all event log channels 🎨 Advanced Filtering - Filter by level, time range, event ID, provider, and more ⚡ High Performance - Efficient C++ implementation using Windows Event Log API 🔒 Type Safe - Fully typed Dart API with comprehensive error handling

📋 Table of Contents

🖥️ Platform Support

PlatformSupport
Windows
Linux
macOS
Android
iOS

📦 Installation

Run the following command in your terminal:

flutter pub add event_log

Or add this to your package's pubspec.yaml file:

dependencies:
event_log: ^1.0.1

Then run:

flutter pub get

🚀 Quick Start

Get up and running in 3 simple steps:

1️⃣ Import the package

import'package:event_log/event_log.dart';

2️⃣ Query events

final events =awaitEventLog.query(
constEventFilter(channel:'System', maxEvents:10),
);

3️⃣ Subscribe to live events

final subscription =awaitEventLog.subscribe(
constEventFilter(channel:'System'),
);
subscription.listen((event) =>print('🔔 ${event.message}'));

📚 Usage Examples

📋 List Available Channels

// Get all available event log channelsfinal channels =awaitEventLog.listChannels();
for (final channel in channels) {
print('${channel.name}: ${channel.enabled ? "Enabled" : "Disabled"}');
}

📊 Query Historical Events

// Query the last 100 events from the System channelfinal events =awaitEventLog.query(
constEventFilter(
channel:'System',
maxEvents:100,
reverse:true, // Most recent first
),
);
for (final event in events) {
print('${event.timeCreated}: Event ${event.eventId} - ${event.level}');
}

For Analytic and Debug channels, Windows does not allow reverse-native reads. If you set reverse: true, the plugin automatically queries forward and reorders the results in memory so your Dart code still receives newest-first events.

🎯 Filter Events by Level

// Get only errors and critical eventsfinal errorEvents =awaitEventLog.query(
EventFilter(
channel:'Application',
levels: [EventLevel.error, EventLevel.critical],
maxEvents:50,
),
);

⏰ Filter Events by Time Range

// Get events from the last 24 hoursfinal recentEvents =awaitEventLog.query(
EventFilter(
channel:'System',
startTime:DateTime.now().subtract(constDuration(hours:24)),
endTime:DateTime.now(),
),
);

🔴 Subscribe to Real-time Events

// Monitor System events in real-timefinal subscription =awaitEventLog.subscribe(
constEventFilter(channel:'System'),
);
subscription.listen(
(event) {
print('New event: ${event.eventId} - ${event.message}');
},
onError: (error) {
print('Subscription error: $error');
},
);
// Later: cancel the subscriptionawait subscription.cancel();

🔧 Advanced Filtering with XPath

// Use custom XPath queries for complex filteringfinal events =awaitEventLog.query(
constEventFilter(
channel:'Security',
xpathQuery:'*[System[(EventID=4624 or EventID=4625) and TimeCreated[@SystemTime>=\'2026-01-01T00:00:00.000Z\']]]',
),
);

🔍 Get Event by ID

// Retrieve a specific event by its record IDfinal event =awaitEventLog.getById(
12345,
channel:'System', // Optional: specify channel for faster lookup
);
if (event !=null) {
print('Found event: ${event.providerName}');
print('Message: ${event.message}');
print('Time: ${event.timeCreated}');
}

ℹ️ Get Channel Information

// Get detailed information about a channelfinal channelInfo =awaitEventLog.getChannelInfo('System');
if (channelInfo !=null) {
print('Channel: ${channelInfo.name}');
print('Type: ${channelInfo.type}');
print('Enabled: ${channelInfo.enabled}');
print('Log Path: ${channelInfo.logFilePath}');
}

🗑️ Clear Channel Events

⚠️ Requires Administrator Privileges

// Clear all events from a channeltry {
awaitEventLog.clear(
'Application',
backupPath:r'C:\Backups\app_events.evtx', // Optional: backup before clearing
);
print('Channel cleared successfully');
} onAccessDeniedException {
print('Access denied: Administrator privileges required');
} onChannelNotFoundException {
print('Channel not found');
}

📖 API Reference

Event Properties

Each EventRecord contains comprehensive event information:

classEventRecord {
finalint eventRecordId; // Unique event record IDfinalint eventId; // Event identifierfinalEventLevel level; // Severity levelfinalDateTime timeCreated; // TimestampfinalString channel; // Channel namefinalString computer; // Computer namefinalString providerName; // Event providerfinalString? providerGuid; // Provider GUIDfinalint? task; // Task categoryfinalint? opcode; // Operation codefinalint? keywords; // Keywords bitmaskfinalint? processId; // Process IDfinalint? threadId; // Thread IDfinalString? userId; // User SIDfinalString? activityId; // Activity correlation IDfinalString? message; // Formatted messagefinalString? xml; // Event as XMLfinalMap<String, dynamic>? eventData; // Event-specific data
}

Event Levels

enumEventLevel {
critical, // Level 1
error, // Level 2
warning, // Level 3
information, // Level 4
verbose, // Level 5
logAlways, // Level 0
}

Common Channels

  • System - System events (hardware, drivers, OS)
  • Application - Application events
  • Security - Security audit events (requires admin for read access)
  • Setup - Setup and deployment events
  • Windows PowerShell - PowerShell events
  • Microsoft-Windows-* - Various Windows component logs

Error Handling

The plugin provides specific exception types:

try {
final events =awaitEventLog.query(filter);
} onAccessDeniedExceptioncatch (e) {
print('Access denied: ${e.message}');
} onChannelNotFoundExceptioncatch (e) {
print('Channel not found: ${e.message}');
} onInvalidQueryExceptioncatch (e) {
print('Invalid query: ${e.message}');
} onUnsupportedChannelExceptioncatch (e) {
print('Unsupported channel operation: ${e.message}');
} onEventLogExceptioncatch (e) {
print('Event log error: ${e.message}');
}

UnsupportedChannelException is raised when Windows rejects the requested operation for that channel, such as attempting a live subscription on an Analytic or Debug log.

Live subscriptions are supported for Admin and Operational channels. Analytic and Debug channels are the specific channel types that do not support live subscriptions through the Windows Event Log subscription API.


⚡ Performance Considerations

  • Channel-specific queries are faster than cross-channel queries
  • XPath queries with specific filters are more efficient than wildcard queries
  • Subscriptions use Windows Event Log's native callbacks for optimal performance
  • Limit maxEvents to avoid loading excessive data
  • Time range filters help narrow down results

🔐 Permissions

  • Basic queries - Standard user privileges
  • Security channel - Often requires administrator privileges
  • Clear channel - Requires administrator privileges
  • Some subscriptions - May require elevated privileges depending on the channel
  • Live subscriptions - Supported for Admin and Operational channels
  • Analytic and Debug channels - Historical queries are forward-only at the Windows API layer. The plugin transparently emulates reverse: true for queries, but live subscriptions are not supported by the Windows Event Log subscription API and will throw UnsupportedChannelException

💻 Example App

Run the example app to see all features in action:

cd example
flutter run -d windows

🎨 Example App Features

  • Channel Browser - Browse and select from all system channels
  • Historical Queries - Query past events with filtering
  • Event Filtering - Filter by severity level (errors only, warnings, etc.)
  • Live Monitoring - Subscribe to real-time events with visual indicators
  • Event Details - Expandable cards showing all event properties
  • Material Design 3 - Beautiful, modern UI

🛠️ Development

Install the repository-managed Git hooks to auto-format staged Dart and C/C++ files before each commit:

pwsh -File scripts/install-git-hooks.ps1

The pre-commit hook runs:

  • dart format for staged .dart files
  • clang-format -i for staged C/C++ source and header files

To format every tracked Dart and C/C++ file in the repository once:

pwsh -File scripts/format_all.ps1

🏗️ Architecture

The plugin uses:

  • Dart Layer: Clean API with Stream support and Flutter integration
  • Platform Interface: Pluggable architecture for future platform support
  • Windows C++: Native implementation using Windows Event Log API (winevt.h)
  • Method Channels: For synchronous operations (queries, channel info)
  • Event Channels: For asynchronous event streaming (subscriptions)

🔌 Windows Event Log API

This plugin wraps the following Windows APIs:

  • EvtQuery - Query historical events
  • EvtSubscribe - Subscribe to live events
  • EvtNext - Iterate through events
  • EvtRender - Render event data
  • EvtOpenChannelEnum - Enumerate channels
  • EvtClearLog - Clear channel events

🤝 Contributing

Contributions are welcome! Here's how you can help:

  1. 🐛 Report bugs - Open an issue with details
  2. 💡 Suggest features - Share your ideas
  3. 🔧 Submit PRs - Fix bugs or add features
  4. 📖 Improve docs - Help others understand the plugin

Please read our Contributing Guidelines before submitting PRs.

📄 License

Copyright © 2026 Kaan Gönüldinc

Licensed under the Apache License, Version 2.0 (the "License"); you may not use this file except in compliance with the License. You may obtain a copy of the License at

http://www.apache.org/licenses/LICENSE-2.0

Unless required by applicable law or agreed to in writing, software distributed under the License is distributed on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the License for the specific language governing permissions and limitations under the License.

See LICENSE for more details.

About

A comprehensive Flutter plugin for accessing the Windows Event Log (Event Viewer). Monitor system events, query historical logs, and manage subscriptions with full Windows Event Log API support.

Topics

Resources

Code of conduct

Contributing

Security policy

Stars

1 star

Watchers

0 watching

Forks

Releases

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

event_log

Event Log Plugin Demo


PlatformPub VersionLicenseFlutter Version

A comprehensive Flutter plugin for accessing the Windows Event Log (Event Viewer)
Monitor system events in real-time, query historical events, and manage event subscriptions across Windows Event Log channels with native Win32 integration.

📸 Demo

Event Log Plugin Demo
Real-time event monitoring and historical queries in action

✨ Features

🎯 Real-time Event Monitoring - Subscribe to live events as they occur 📊 Historical Event Queries - Search past events with powerful filtering 🔍 Event Retrieval by ID - Get specific events by their record ID 📝 Channel Management - List and inspect all event log channels 🎨 Advanced Filtering - Filter by level, time range, event ID, provider, and more ⚡ High Performance - Efficient C++ implementation using Windows Event Log API 🔒 Type Safe - Fully typed Dart API with comprehensive error handling

📋 Table of Contents

🖥️ Platform Support

PlatformSupport
Windows
Linux
macOS
Android
iOS

📦 Installation

Run the following command in your terminal:

flutter pub add event_log

Or add this to your package's pubspec.yaml file:

dependencies:
event_log: ^1.0.1

Then run:

flutter pub get

🚀 Quick Start

Get up and running in 3 simple steps:

1️⃣ Import the package

import'package:event_log/event_log.dart';

2️⃣ Query events

final events =awaitEventLog.query(
constEventFilter(channel:'System', maxEvents:10),
);

3️⃣ Subscribe to live events

final subscription =awaitEventLog.subscribe(
constEventFilter(channel:'System'),
);
subscription.listen((event) =>print('🔔 ${event.message}'));

📚 Usage Examples

📋 List Available Channels

// Get all available event log channelsfinal channels =awaitEventLog.listChannels();
for (final channel in channels) {
print('${channel.name}: ${channel.enabled ? "Enabled" : "Disabled"}');
}

📊 Query Historical Events

// Query the last 100 events from the System channelfinal events =awaitEventLog.query(
constEventFilter(
channel:'System',
maxEvents:100,
reverse:true, // Most recent first
),
);
for (final event in events) {
print('${event.timeCreated}: Event ${event.eventId} - ${event.level}');
}

For Analytic and Debug channels, Windows does not allow reverse-native reads. If you set reverse: true, the plugin automatically queries forward and reorders the results in memory so your Dart code still receives newest-first events.

🎯 Filter Events by Level

// Get only errors and critical eventsfinal errorEvents =awaitEventLog.query(
EventFilter(
channel:'Application',
levels: [EventLevel.error, EventLevel.critical],
maxEvents:50,
),
);

⏰ Filter Events by Time Range

// Get events from the last 24 hoursfinal recentEvents =awaitEventLog.query(
EventFilter(
channel:'System',
startTime:DateTime.now().subtract(constDuration(hours:24)),
endTime:DateTime.now(),
),
);

🔴 Subscribe to Real-time Events

// Monitor System events in real-timefinal subscription =awaitEventLog.subscribe(
constEventFilter(channel:'System'),
);
subscription.listen(
(event) {
print('New event: ${event.eventId} - ${event.message}');
},
onError: (error) {
print('Subscription error: $error');
},
);
// Later: cancel the subscriptionawait subscription.cancel();

🔧 Advanced Filtering with XPath

// Use custom XPath queries for complex filteringfinal events =awaitEventLog.query(
constEventFilter(
channel:'Security',
xpathQuery:'*[System[(EventID=4624 or EventID=4625) and TimeCreated[@SystemTime>=\'2026-01-01T00:00:00.000Z\']]]',
),
);

🔍 Get Event by ID

// Retrieve a specific event by its record IDfinal event =awaitEventLog.getById(
12345,
channel:'System', // Optional: specify channel for faster lookup
);
if (event !=null) {
print('Found event: ${event.providerName}');
print('Message: ${event.message}');
print('Time: ${event.timeCreated}');
}

ℹ️ Get Channel Information

// Get detailed information about a channelfinal channelInfo =awaitEventLog.getChannelInfo('System');
if (channelInfo !=null) {
print('Channel: ${channelInfo.name}');
print('Type: ${channelInfo.type}');
print('Enabled: ${channelInfo.enabled}');
print('Log Path: ${channelInfo.logFilePath}');
}

🗑️ Clear Channel Events

⚠️ Requires Administrator Privileges

// Clear all events from a channeltry {
awaitEventLog.clear(
'Application',
backupPath:r'C:\Backups\app_events.evtx', // Optional: backup before clearing
);
print('Channel cleared successfully');
} onAccessDeniedException {
print('Access denied: Administrator privileges required');
} onChannelNotFoundException {
print('Channel not found');
}

📖 API Reference

Event Properties

Each EventRecord contains comprehensive event information:

classEventRecord {
finalint eventRecordId; // Unique event record IDfinalint eventId; // Event identifierfinalEventLevel level; // Severity levelfinalDateTime timeCreated; // TimestampfinalString channel; // Channel namefinalString computer; // Computer namefinalString providerName; // Event providerfinalString? providerGuid; // Provider GUIDfinalint? task; // Task categoryfinalint? opcode; // Operation codefinalint? keywords; // Keywords bitmaskfinalint? processId; // Process IDfinalint? threadId; // Thread IDfinalString? userId; // User SIDfinalString? activityId; // Activity correlation IDfinalString? message; // Formatted messagefinalString? xml; // Event as XMLfinalMap<String, dynamic>? eventData; // Event-specific data
}

Event Levels

enumEventLevel {
critical, // Level 1
error, // Level 2
warning, // Level 3
information, // Level 4
verbose, // Level 5
logAlways, // Level 0
}

Common Channels

  • System - System events (hardware, drivers, OS)
  • Application - Application events
  • Security - Security audit events (requires admin for read access)
  • Setup - Setup and deployment events
  • Windows PowerShell - PowerShell events
  • Microsoft-Windows-* - Various Windows component logs

Error Handling

The plugin provides specific exception types:

try {
final events =awaitEventLog.query(filter);
} onAccessDeniedExceptioncatch (e) {
print('Access denied: ${e.message}');
} onChannelNotFoundExceptioncatch (e) {
print('Channel not found: ${e.message}');
} onInvalidQueryExceptioncatch (e) {
print('Invalid query: ${e.message}');
} onUnsupportedChannelExceptioncatch (e) {
print('Unsupported channel operation: ${e.message}');
} onEventLogExceptioncatch (e) {
print('Event log error: ${e.message}');
}

UnsupportedChannelException is raised when Windows rejects the requested operation for that channel, such as attempting a live subscription on an Analytic or Debug log.

Live subscriptions are supported for Admin and Operational channels. Analytic and Debug channels are the specific channel types that do not support live subscriptions through the Windows Event Log subscription API.


⚡ Performance Considerations

  • Channel-specific queries are faster than cross-channel queries
  • XPath queries with specific filters are more efficient than wildcard queries
  • Subscriptions use Windows Event Log's native callbacks for optimal performance
  • Limit maxEvents to avoid loading excessive data
  • Time range filters help narrow down results

🔐 Permissions

  • Basic queries - Standard user privileges
  • Security channel - Often requires administrator privileges
  • Clear channel - Requires administrator privileges
  • Some subscriptions - May require elevated privileges depending on the channel
  • Live subscriptions - Supported for Admin and Operational channels
  • Analytic and Debug channels - Historical queries are forward-only at the Windows API layer. The plugin transparently emulates reverse: true for queries, but live subscriptions are not supported by the Windows Event Log subscription API and will throw UnsupportedChannelException

💻 Example App

Run the example app to see all features in action:

cd example
flutter run -d windows

🎨 Example App Features

  • Channel Browser - Browse and select from all system channels
  • Historical Queries - Query past events with filtering
  • Event Filtering - Filter by severity level (errors only, warnings, etc.)
  • Live Monitoring - Subscribe to real-time events with visual indicators
  • Event Details - Expandable cards showing all event properties
  • Material Design 3 - Beautiful, modern UI

🛠️ Development

Install the repository-managed Git hooks to auto-format staged Dart and C/C++ files before each commit:

pwsh -File scripts/install-git-hooks.ps1

The pre-commit hook runs:

  • dart format for staged .dart files
  • clang-format -i for staged C/C++ source and header files

To format every tracked Dart and C/C++ file in the repository once:

pwsh -File scripts/format_all.ps1

🏗️ Architecture

The plugin uses:

  • Dart Layer: Clean API with Stream support and Flutter integration
  • Platform Interface: Pluggable architecture for future platform support
  • Windows C++: Native implementation using Windows Event Log API (winevt.h)
  • Method Channels: For synchronous operations (queries, channel info)
  • Event Channels: For asynchronous event streaming (subscriptions)

🔌 Windows Event Log API

This plugin wraps the following Windows APIs:

  • EvtQuery - Query historical events
  • EvtSubscribe - Subscribe to live events
  • EvtNext - Iterate through events
  • EvtRender - Render event data
  • EvtOpenChannelEnum - Enumerate channels
  • EvtClearLog - Clear channel events

🤝 Contributing

Contributions are welcome! Here's how you can help:

  1. 🐛 Report bugs - Open an issue with details
  2. 💡 Suggest features - Share your ideas
  3. 🔧 Submit PRs - Fix bugs or add features
  4. 📖 Improve docs - Help others understand the plugin

Please read our Contributing Guidelines before submitting PRs.

📄 License

Copyright © 2026 Kaan Gönüldinc

Licensed under the Apache License, Version 2.0 (the "License"); you may not use this file except in compliance with the License. You may obtain a copy of the License at

http://www.apache.org/licenses/LICENSE-2.0

Unless required by applicable law or agreed to in writing, software distributed under the License is distributed on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the License for the specific language governing permissions and limitations under the License.

See LICENSE for more details.

About

A comprehensive Flutter plugin for accessing the Windows Event Log (Event Viewer). Monitor system events, query historical logs, and manage subscriptions with full Windows Event Log API support.

Topics

Resources

Code of conduct

Contributing

Security policy

Stars

1 star

Watchers

0 watching

Forks

Releases

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

event_log

Event Log Plugin Demo


PlatformPub VersionLicenseFlutter Version

A comprehensive Flutter plugin for accessing the Windows Event Log (Event Viewer)
Monitor system events in real-time, query historical events, and manage event subscriptions across Windows Event Log channels with native Win32 integration.

📸 Demo

Event Log Plugin Demo
Real-time event monitoring and historical queries in action

✨ Features

🎯 Real-time Event Monitoring - Subscribe to live events as they occur 📊 Historical Event Queries - Search past events with powerful filtering 🔍 Event Retrieval by ID - Get specific events by their record ID 📝 Channel Management - List and inspect all event log channels 🎨 Advanced Filtering - Filter by level, time range, event ID, provider, and more ⚡ High Performance - Efficient C++ implementation using Windows Event Log API 🔒 Type Safe - Fully typed Dart API with comprehensive error handling

📋 Table of Contents

🖥️ Platform Support

PlatformSupport
Windows
Linux
macOS
Android
iOS

📦 Installation

Run the following command in your terminal:

flutter pub add event_log

Or add this to your package's pubspec.yaml file:

dependencies:
event_log: ^1.0.1

Then run:

flutter pub get

🚀 Quick Start

Get up and running in 3 simple steps:

1️⃣ Import the package

import'package:event_log/event_log.dart';

2️⃣ Query events

final events =awaitEventLog.query(
constEventFilter(channel:'System', maxEvents:10),
);

3️⃣ Subscribe to live events

final subscription =awaitEventLog.subscribe(
constEventFilter(channel:'System'),
);
subscription.listen((event) =>print('🔔 ${event.message}'));

📚 Usage Examples

📋 List Available Channels

// Get all available event log channelsfinal channels =awaitEventLog.listChannels();
for (final channel in channels) {
print('${channel.name}: ${channel.enabled ? "Enabled" : "Disabled"}');
}

📊 Query Historical Events

// Query the last 100 events from the System channelfinal events =awaitEventLog.query(
constEventFilter(
channel:'System',
maxEvents:100,
reverse:true, // Most recent first
),
);
for (final event in events) {
print('${event.timeCreated}: Event ${event.eventId} - ${event.level}');
}

For Analytic and Debug channels, Windows does not allow reverse-native reads. If you set reverse: true, the plugin automatically queries forward and reorders the results in memory so your Dart code still receives newest-first events.

🎯 Filter Events by Level

// Get only errors and critical eventsfinal errorEvents =awaitEventLog.query(
EventFilter(
channel:'Application',
levels: [EventLevel.error, EventLevel.critical],
maxEvents:50,
),
);

⏰ Filter Events by Time Range

// Get events from the last 24 hoursfinal recentEvents =awaitEventLog.query(
EventFilter(
channel:'System',
startTime:DateTime.now().subtract(constDuration(hours:24)),
endTime:DateTime.now(),
),
);

🔴 Subscribe to Real-time Events

// Monitor System events in real-timefinal subscription =awaitEventLog.subscribe(
constEventFilter(channel:'System'),
);
subscription.listen(
(event) {
print('New event: ${event.eventId} - ${event.message}');
},
onError: (error) {
print('Subscription error: $error');
},
);
// Later: cancel the subscriptionawait subscription.cancel();

🔧 Advanced Filtering with XPath

// Use custom XPath queries for complex filteringfinal events =awaitEventLog.query(
constEventFilter(
channel:'Security',
xpathQuery:'*[System[(EventID=4624 or EventID=4625) and TimeCreated[@SystemTime>=\'2026-01-01T00:00:00.000Z\']]]',
),
);

🔍 Get Event by ID

// Retrieve a specific event by its record IDfinal event =awaitEventLog.getById(
12345,
channel:'System', // Optional: specify channel for faster lookup
);
if (event !=null) {
print('Found event: ${event.providerName}');
print('Message: ${event.message}');
print('Time: ${event.timeCreated}');
}

ℹ️ Get Channel Information

// Get detailed information about a channelfinal channelInfo =awaitEventLog.getChannelInfo('System');
if (channelInfo !=null) {
print('Channel: ${channelInfo.name}');
print('Type: ${channelInfo.type}');
print('Enabled: ${channelInfo.enabled}');
print('Log Path: ${channelInfo.logFilePath}');
}

🗑️ Clear Channel Events

⚠️ Requires Administrator Privileges

// Clear all events from a channeltry {
awaitEventLog.clear(
'Application',
backupPath:r'C:\Backups\app_events.evtx', // Optional: backup before clearing
);
print('Channel cleared successfully');
} onAccessDeniedException {
print('Access denied: Administrator privileges required');
} onChannelNotFoundException {
print('Channel not found');
}

📖 API Reference

Event Properties

Each EventRecord contains comprehensive event information:

classEventRecord {
finalint eventRecordId; // Unique event record IDfinalint eventId; // Event identifierfinalEventLevel level; // Severity levelfinalDateTime timeCreated; // TimestampfinalString channel; // Channel namefinalString computer; // Computer namefinalString providerName; // Event providerfinalString? providerGuid; // Provider GUIDfinalint? task; // Task categoryfinalint? opcode; // Operation codefinalint? keywords; // Keywords bitmaskfinalint? processId; // Process IDfinalint? threadId; // Thread IDfinalString? userId; // User SIDfinalString? activityId; // Activity correlation IDfinalString? message; // Formatted messagefinalString? xml; // Event as XMLfinalMap<String, dynamic>? eventData; // Event-specific data
}

Event Levels

enumEventLevel {
critical, // Level 1
error, // Level 2
warning, // Level 3
information, // Level 4
verbose, // Level 5
logAlways, // Level 0
}

Common Channels

  • System - System events (hardware, drivers, OS)
  • Application - Application events
  • Security - Security audit events (requires admin for read access)
  • Setup - Setup and deployment events
  • Windows PowerShell - PowerShell events
  • Microsoft-Windows-* - Various Windows component logs

Error Handling

The plugin provides specific exception types:

try {
final events =awaitEventLog.query(filter);
} onAccessDeniedExceptioncatch (e) {
print('Access denied: ${e.message}');
} onChannelNotFoundExceptioncatch (e) {
print('Channel not found: ${e.message}');
} onInvalidQueryExceptioncatch (e) {
print('Invalid query: ${e.message}');
} onUnsupportedChannelExceptioncatch (e) {
print('Unsupported channel operation: ${e.message}');
} onEventLogExceptioncatch (e) {
print('Event log error: ${e.message}');
}

UnsupportedChannelException is raised when Windows rejects the requested operation for that channel, such as attempting a live subscription on an Analytic or Debug log.

Live subscriptions are supported for Admin and Operational channels. Analytic and Debug channels are the specific channel types that do not support live subscriptions through the Windows Event Log subscription API.


⚡ Performance Considerations

  • Channel-specific queries are faster than cross-channel queries
  • XPath queries with specific filters are more efficient than wildcard queries
  • Subscriptions use Windows Event Log's native callbacks for optimal performance
  • Limit maxEvents to avoid loading excessive data
  • Time range filters help narrow down results

🔐 Permissions

  • Basic queries - Standard user privileges
  • Security channel - Often requires administrator privileges
  • Clear channel - Requires administrator privileges
  • Some subscriptions - May require elevated privileges depending on the channel
  • Live subscriptions - Supported for Admin and Operational channels
  • Analytic and Debug channels - Historical queries are forward-only at the Windows API layer. The plugin transparently emulates reverse: true for queries, but live subscriptions are not supported by the Windows Event Log subscription API and will throw UnsupportedChannelException

💻 Example App

Run the example app to see all features in action:

cd example
flutter run -d windows

🎨 Example App Features

  • Channel Browser - Browse and select from all system channels
  • Historical Queries - Query past events with filtering
  • Event Filtering - Filter by severity level (errors only, warnings, etc.)
  • Live Monitoring - Subscribe to real-time events with visual indicators
  • Event Details - Expandable cards showing all event properties
  • Material Design 3 - Beautiful, modern UI

🛠️ Development

Install the repository-managed Git hooks to auto-format staged Dart and C/C++ files before each commit:

pwsh -File scripts/install-git-hooks.ps1

The pre-commit hook runs:

  • dart format for staged .dart files
  • clang-format -i for staged C/C++ source and header files

To format every tracked Dart and C/C++ file in the repository once:

pwsh -File scripts/format_all.ps1

🏗️ Architecture

The plugin uses:

  • Dart Layer: Clean API with Stream support and Flutter integration
  • Platform Interface: Pluggable architecture for future platform support
  • Windows C++: Native implementation using Windows Event Log API (winevt.h)
  • Method Channels: For synchronous operations (queries, channel info)
  • Event Channels: For asynchronous event streaming (subscriptions)

🔌 Windows Event Log API

This plugin wraps the following Windows APIs:

  • EvtQuery - Query historical events
  • EvtSubscribe - Subscribe to live events
  • EvtNext - Iterate through events
  • EvtRender - Render event data
  • EvtOpenChannelEnum - Enumerate channels
  • EvtClearLog - Clear channel events

🤝 Contributing

Contributions are welcome! Here's how you can help:

  1. 🐛 Report bugs - Open an issue with details
  2. 💡 Suggest features - Share your ideas
  3. 🔧 Submit PRs - Fix bugs or add features
  4. 📖 Improve docs - Help others understand the plugin

Please read our Contributing Guidelines before submitting PRs.

📄 License

Copyright © 2026 Kaan Gönüldinc

Licensed under the Apache License, Version 2.0 (the "License"); you may not use this file except in compliance with the License. You may obtain a copy of the License at

http://www.apache.org/licenses/LICENSE-2.0

Unless required by applicable law or agreed to in writing, software distributed under the License is distributed on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the License for the specific language governing permissions and limitations under the License.

See LICENSE for more details.

About

A comprehensive Flutter plugin for accessing the Windows Event Log (Event Viewer). Monitor system events, query historical logs, and manage subscriptions with full Windows Event Log API support.

Topics

Resources

Code of conduct

Contributing

Security policy

Stars

1 star

Watchers

0 watching

Forks

Releases

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

event_log

Event Log Plugin Demo


PlatformPub VersionLicenseFlutter Version

A comprehensive Flutter plugin for accessing the Windows Event Log (Event Viewer)
Monitor system events in real-time, query historical events, and manage event subscriptions across Windows Event Log channels with native Win32 integration.

📸 Demo

Event Log Plugin Demo
Real-time event monitoring and historical queries in action

✨ Features

🎯 Real-time Event Monitoring - Subscribe to live events as they occur 📊 Historical Event Queries - Search past events with powerful filtering 🔍 Event Retrieval by ID - Get specific events by their record ID 📝 Channel Management - List and inspect all event log channels 🎨 Advanced Filtering - Filter by level, time range, event ID, provider, and more ⚡ High Performance - Efficient C++ implementation using Windows Event Log API 🔒 Type Safe - Fully typed Dart API with comprehensive error handling

📋 Table of Contents

🖥️ Platform Support

PlatformSupport
Windows
Linux
macOS
Android
iOS

📦 Installation

Run the following command in your terminal:

flutter pub add event_log

Or add this to your package's pubspec.yaml file:

dependencies:
event_log: ^1.0.1

Then run:

flutter pub get

🚀 Quick Start

Get up and running in 3 simple steps:

1️⃣ Import the package

import'package:event_log/event_log.dart';

2️⃣ Query events

final events =awaitEventLog.query(
constEventFilter(channel:'System', maxEvents:10),
);

3️⃣ Subscribe to live events

final subscription =awaitEventLog.subscribe(
constEventFilter(channel:'System'),
);
subscription.listen((event) =>print('🔔 ${event.message}'));

📚 Usage Examples

📋 List Available Channels

// Get all available event log channelsfinal channels =awaitEventLog.listChannels();
for (final channel in channels) {
print('${channel.name}: ${channel.enabled ? "Enabled" : "Disabled"}');
}

📊 Query Historical Events

// Query the last 100 events from the System channelfinal events =awaitEventLog.query(
constEventFilter(
channel:'System',
maxEvents:100,
reverse:true, // Most recent first
),
);
for (final event in events) {
print('${event.timeCreated}: Event ${event.eventId} - ${event.level}');
}

For Analytic and Debug channels, Windows does not allow reverse-native reads. If you set reverse: true, the plugin automatically queries forward and reorders the results in memory so your Dart code still receives newest-first events.

🎯 Filter Events by Level

// Get only errors and critical eventsfinal errorEvents =awaitEventLog.query(
EventFilter(
channel:'Application',
levels: [EventLevel.error, EventLevel.critical],
maxEvents:50,
),
);

⏰ Filter Events by Time Range

// Get events from the last 24 hoursfinal recentEvents =awaitEventLog.query(
EventFilter(
channel:'System',
startTime:DateTime.now().subtract(constDuration(hours:24)),
endTime:DateTime.now(),
),
);

🔴 Subscribe to Real-time Events

// Monitor System events in real-timefinal subscription =awaitEventLog.subscribe(
constEventFilter(channel:'System'),
);
subscription.listen(
(event) {
print('New event: ${event.eventId} - ${event.message}');
},
onError: (error) {
print('Subscription error: $error');
},
);
// Later: cancel the subscriptionawait subscription.cancel();

🔧 Advanced Filtering with XPath

// Use custom XPath queries for complex filteringfinal events =awaitEventLog.query(
constEventFilter(
channel:'Security',
xpathQuery:'*[System[(EventID=4624 or EventID=4625) and TimeCreated[@SystemTime>=\'2026-01-01T00:00:00.000Z\']]]',
),
);

🔍 Get Event by ID

// Retrieve a specific event by its record IDfinal event =awaitEventLog.getById(
12345,
channel:'System', // Optional: specify channel for faster lookup
);
if (event !=null) {
print('Found event: ${event.providerName}');
print('Message: ${event.message}');
print('Time: ${event.timeCreated}');
}

ℹ️ Get Channel Information

// Get detailed information about a channelfinal channelInfo =awaitEventLog.getChannelInfo('System');
if (channelInfo !=null) {
print('Channel: ${channelInfo.name}');
print('Type: ${channelInfo.type}');
print('Enabled: ${channelInfo.enabled}');
print('Log Path: ${channelInfo.logFilePath}');
}

🗑️ Clear Channel Events

⚠️ Requires Administrator Privileges

// Clear all events from a channeltry {
awaitEventLog.clear(
'Application',
backupPath:r'C:\Backups\app_events.evtx', // Optional: backup before clearing
);
print('Channel cleared successfully');
} onAccessDeniedException {
print('Access denied: Administrator privileges required');
} onChannelNotFoundException {
print('Channel not found');
}

📖 API Reference

Event Properties

Each EventRecord contains comprehensive event information:

classEventRecord {
finalint eventRecordId; // Unique event record IDfinalint eventId; // Event identifierfinalEventLevel level; // Severity levelfinalDateTime timeCreated; // TimestampfinalString channel; // Channel namefinalString computer; // Computer namefinalString providerName; // Event providerfinalString? providerGuid; // Provider GUIDfinalint? task; // Task categoryfinalint? opcode; // Operation codefinalint? keywords; // Keywords bitmaskfinalint? processId; // Process IDfinalint? threadId; // Thread IDfinalString? userId; // User SIDfinalString? activityId; // Activity correlation IDfinalString? message; // Formatted messagefinalString? xml; // Event as XMLfinalMap<String, dynamic>? eventData; // Event-specific data
}

Event Levels

enumEventLevel {
critical, // Level 1
error, // Level 2
warning, // Level 3
information, // Level 4
verbose, // Level 5
logAlways, // Level 0
}

Common Channels

  • System - System events (hardware, drivers, OS)
  • Application - Application events
  • Security - Security audit events (requires admin for read access)
  • Setup - Setup and deployment events
  • Windows PowerShell - PowerShell events
  • Microsoft-Windows-* - Various Windows component logs

Error Handling

The plugin provides specific exception types:

try {
final events =awaitEventLog.query(filter);
} onAccessDeniedExceptioncatch (e) {
print('Access denied: ${e.message}');
} onChannelNotFoundExceptioncatch (e) {
print('Channel not found: ${e.message}');
} onInvalidQueryExceptioncatch (e) {
print('Invalid query: ${e.message}');
} onUnsupportedChannelExceptioncatch (e) {
print('Unsupported channel operation: ${e.message}');
} onEventLogExceptioncatch (e) {
print('Event log error: ${e.message}');
}

UnsupportedChannelException is raised when Windows rejects the requested operation for that channel, such as attempting a live subscription on an Analytic or Debug log.

Live subscriptions are supported for Admin and Operational channels. Analytic and Debug channels are the specific channel types that do not support live subscriptions through the Windows Event Log subscription API.


⚡ Performance Considerations

  • Channel-specific queries are faster than cross-channel queries
  • XPath queries with specific filters are more efficient than wildcard queries
  • Subscriptions use Windows Event Log's native callbacks for optimal performance
  • Limit maxEvents to avoid loading excessive data
  • Time range filters help narrow down results

🔐 Permissions

  • Basic queries - Standard user privileges
  • Security channel - Often requires administrator privileges
  • Clear channel - Requires administrator privileges
  • Some subscriptions - May require elevated privileges depending on the channel
  • Live subscriptions - Supported for Admin and Operational channels
  • Analytic and Debug channels - Historical queries are forward-only at the Windows API layer. The plugin transparently emulates reverse: true for queries, but live subscriptions are not supported by the Windows Event Log subscription API and will throw UnsupportedChannelException

💻 Example App

Run the example app to see all features in action:

cd example
flutter run -d windows

🎨 Example App Features

  • Channel Browser - Browse and select from all system channels
  • Historical Queries - Query past events with filtering
  • Event Filtering - Filter by severity level (errors only, warnings, etc.)
  • Live Monitoring - Subscribe to real-time events with visual indicators
  • Event Details - Expandable cards showing all event properties
  • Material Design 3 - Beautiful, modern UI

🛠️ Development

Install the repository-managed Git hooks to auto-format staged Dart and C/C++ files before each commit:

pwsh -File scripts/install-git-hooks.ps1

The pre-commit hook runs:

  • dart format for staged .dart files
  • clang-format -i for staged C/C++ source and header files

To format every tracked Dart and C/C++ file in the repository once:

pwsh -File scripts/format_all.ps1

🏗️ Architecture

The plugin uses:

  • Dart Layer: Clean API with Stream support and Flutter integration
  • Platform Interface: Pluggable architecture for future platform support
  • Windows C++: Native implementation using Windows Event Log API (winevt.h)
  • Method Channels: For synchronous operations (queries, channel info)
  • Event Channels: For asynchronous event streaming (subscriptions)

🔌 Windows Event Log API

This plugin wraps the following Windows APIs:

  • EvtQuery - Query historical events
  • EvtSubscribe - Subscribe to live events
  • EvtNext - Iterate through events
  • EvtRender - Render event data
  • EvtOpenChannelEnum - Enumerate channels
  • EvtClearLog - Clear channel events

🤝 Contributing

Contributions are welcome! Here's how you can help:

  1. 🐛 Report bugs - Open an issue with details
  2. 💡 Suggest features - Share your ideas
  3. 🔧 Submit PRs - Fix bugs or add features
  4. 📖 Improve docs - Help others understand the plugin

Please read our Contributing Guidelines before submitting PRs.

📄 License

Copyright © 2026 Kaan Gönüldinc

Licensed under the Apache License, Version 2.0 (the "License"); you may not use this file except in compliance with the License. You may obtain a copy of the License at

http://www.apache.org/licenses/LICENSE-2.0

Unless required by applicable law or agreed to in writing, software distributed under the License is distributed on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the License for the specific language governing permissions and limitations under the License.

See LICENSE for more details.

About

A comprehensive Flutter plugin for accessing the Windows Event Log (Event Viewer). Monitor system events, query historical logs, and manage subscriptions with full Windows Event Log API support.

Topics

Resources

Code of conduct

Contributing

Security policy

Stars

1 star

Watchers

0 watching

Forks

Releases

Contributors

Languages