The Event Viewer from Server 2008 onwards is XML based.
Filters based on XML syntax can be used such as:
<QueryList> <Query Id="0" Path="System"> <Select Path="System"> *[EventData[Data and (Data='<Search Parameter>')]] </Select> </Query> </QueryList> <QueryList> <Query Id="0" Path="Application"> <Select Path="Application"> *[EventData[Data and (Data='<Search Parameter>')]] </Select> </Query> </QueryList>
You can search for anything which appears in the data section such as service names, error messages etc..
- <EventData> <Data Name="param1">Service Display Name</Data> <Data Name="param2">Details</Data> <Data Name="param3">Details</Data> <Data Name="param4">Service Name</Data> </EventData> </Event>
Notes:
MS Technet