---
title: "Windows XML Event Log (EVTX) parser"
url: "https://axoflow.com/docs/axosyslog-core/4.28/chapter-parsers/windows-eventlog-xml-parser/"
last_modified: "2026-08-05T13:56:51+02:00"
---

> For the complete documentation index, see [llms.txt](https://axoflow.com/docs/axosyslog-core/4.28/llms.txt).

# Windows XML Event Log (EVTX) parser

The `windows-eventlog-xml-parser()` can parse messages in the Windows XML Event Log (EVTX) format.

## Prerequisites

Available in AxoSyslog version 4.5 and later.

On [Debian/Ubuntu](https://axoflow.com/docs/axosyslog-core/4.28/install/debian-ubuntu/index.md), this feature is available in a separate module: install the `axosyslog-mod-xml-parser` package. On [RHEL and compatible distributions](https://axoflow.com/docs/axosyslog-core/4.28/install/rhel-fedora-almalinux/index.md), it’s part of the `axosyslog` base package. If the module isn’t installed, AxoSyslog fails to start with an [`unexpected LL_IDENTIFIER` error](https://axoflow.com/docs/axosyslog-core/4.28/chapter-troubleshooting-syslog-ng/unexpected-ll-identifier/index.md).

## Configuration

See also the equivalent FilterX function, [`parse_windows_eventlog_xml()`](https://axoflow.com/docs/axosyslog-core/4.28/filterx/function-reference/index.md#parse-windows).

Example configuration:

```shell
parser p_win {
    windows-eventlog-xml-parser(prefix(".winlog."));
};
```

The `windows-eventlog-xml-parser()` parser has the same parameters are the same as the [`xml()` parser](https://axoflow.com/docs/axosyslog-core/4.28/chapter-parsers/xml-parser/xml-parser-options/index.md).

Don’t forget to include the parsers in a log statement to actually use it:

```shell
log {
    source(s_local);
    parser(windows-eventlog-xml-parser(prefix(".winlog.")));
    destination(d_local);
};
```

Last modified August 5, 2026: [Adds required packages to parser pages (d1286917)](https://github.com/axoflow/axosyslog-core-docs/commit/d12869175ade2e2652453d62a823a7b95a4c84b6)
