JSI Tip 0338 - Event Viewer registry entries for users.

In addition to the entries at tip 315 and tip 337, additional user Event Viewer entries are at:

HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Network\Event Viewer

These values are all type REG_SZ.

 Value   Default   D e s c r i p t i o n 
 Filter   none   Stores the filter scheme used to display data at the last close. 
 Find   none   Stores the filter scheme for the find at the last close. 
 IfNT   1   1=Event Viewer was monitoring an NT computer when it was closed. 0=Not NT. 
 LogType   0   The log you were viewing at the last close. 0=System, 1=Security log, 2=Application, 4=Customized log file. 
 Module   System   Stores the log name (System, Security, Application, Log file name). 

Additionally,

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Network\World Full Access Shared Parameters\SortHyphens

is a type REG_DWORD that determines if hyphens are ignored when sorting alphabetically in Event Viewer, Remoteboot Manager, Server Manager, User Manager, and User Manager for Domains.This value affects the base sort order of lists in Network, Server, Services, and Devices in Control Panel.

A data value of 0 (default) ignores hyphens. For example, "Administrator" appears before "-Sales.". A data value of 1 sorts hyphens; i.e. "-Sales" appears before "Administrator".

Hide comments

Comments

  • Allowed HTML tags: <em> <strong> <blockquote> <br> <p>

Plain text

  • No HTML tags allowed.
  • Web page addresses and e-mail addresses turn into links automatically.
  • Lines and paragraphs break automatically.
Publish