A log file is a record your computer keeps of what happened and when
A log file is a text file that records events on your computer or device — things like when a program started, what errors it ran into, when you logged in, or when a file was deleted. Your operating system, individual programs, and web servers all create log files automatically. They write to these files in the background while you work, and you rarely see them unless you go looking.
Log files exist because computers need a way to remember what they did. If something breaks, a technician can read the log to see what happened in the minutes or hours before the crash. If you're trying to figure out why a program keeps freezing, the log might show that it ran out of memory. If someone hacked your email account, the log can show what time they logged in and from where.
Most log files are plain text — you can open them in Notepad or any text editor — but they're usually not meant for you to read. They're written in a format that makes sense to programmers and system administrators, with timestamps, error codes, and technical jargon. Still, they're readable if you know what you're looking at.
Key Takeaways
- Log files record events like program crashes, login times, and errors, and are created automatically by your operating system and programs.
- Each log entry includes a timestamp and a description of what happened, so you can see the exact sequence of events.
- You can open most log files with Notepad or a text editor, but they're written in a technical format meant for troubleshooting, not everyday reading.
- Log files help technicians diagnose problems, security teams detect break-ins, and developers fix bugs in their software.
- Different programs and systems store their logs in different places, and older logs are often deleted automatically to save disk space.
Where log files live on your computer
On Windows, the main system log file is stored in C:\Windows\System32\winevt\Logs. Inside that folder you'll find separate logs for System events, Security events, and Application events. The System log records things like when drivers loaded or when Windows shut down. The Security log tracks login attempts and permission changes. The Application log captures errors from programs you've installed.
On Mac, system logs are in /var/log. You can view them through the Console app, which is easier than opening the folder yourself. On Linux, logs are also in /var/log, and you can read them with a terminal command or a text editor.
Individual programs often keep their own logs too. Chrome stores browsing history and crash reports. Outlook keeps a log of email sync errors. Your router has a log of every device that connected to it. These program-specific logs are scattered across different folders depending on where the program installed itself.
Most operating systems delete old log files automatically after a certain number of days — usually 7 to 30 days — to keep them from taking up too much disk space. You can change how long logs are kept, but the default is usually fine for most people.
What information a log file actually contains
Every entry in a log file follows roughly the same pattern: a timestamp, a source (which program or system created the entry), a severity level, and a description of what happened. A typical Windows System log entry might look like this:
2024-01-15 14:32:45 — System — Information — Driver loaded successfully: nvlddmkm.sys
The timestamp tells you exactly when the event occurred. The source tells you what part of the system recorded it. The severity level — Information, Warning, Error, or Critical — tells you how serious it was. Information entries are routine things that happened normally. Warnings mean something unexpected occurred but the system kept working. Errors mean something failed. Critical entries mean the system itself may have crashed or is about to.
The description is where the actual detail lives. It might say a file was deleted, a network connection was lost, a program ran out of memory, or a security update was installed. Some entries are one sentence. Others include error codes, file paths, or memory addresses that only make sense to someone trained in that specific system.
Security logs are more detailed because they're used to detect break-ins. They record every login attempt — successful or failed — along with the username, the time, and sometimes the IP address the login came from. They also log permission changes, file access attempts, and policy changes.
Why log files matter when something goes wrong
When your computer crashes or a program freezes, the log file is often the only record of what led up to it. A technician can open the log, look at the entries from the moment before the crash, and see what the system was trying to do. Maybe it shows that a driver was loading when the crash happened. Maybe it shows that a program was trying to access a file that no longer existed. Maybe it shows that the system ran out of memory.
Log files are also how security teams detect hacks. If someone breaks into your email account, the login log shows what time they logged in and what device or IP address they used. If malware infects your computer, the System log might show suspicious programs loading or unusual network activity. Antivirus software reads logs to understand what happened during an infection.
For developers, log files are how they find bugs. If a program crashes for one user but not others, the developer asks for that user's log file. The log shows exactly what the program was doing when it crashed, what data it was processing, and what error message it hit. Without the log, the developer is just guessing.
How to find and read a log file
On Windows, the easiest way to view logs is through Event Viewer. Press the Windows key, type "Event Viewer," and open it. You'll see three main categories: Windows Logs (System, Security, Application), Applications and Services Logs (logs from specific programs), and Subscriptions. Click on any category to see the entries, sorted by date with the newest first.
If you want to read a program's log file directly, you'll need to know where it stores them. Check the program's settings or help menu — many programs have a "View Log" button or a "Logs" folder. If not, try searching your computer for files ending in .log. On Windows, open File Explorer, click the search box, and type *.log to find all log files.
On Mac, open Applications > Utilities > Console. It shows system logs and program logs in one place. You can search by keyword or filter by log level. On Linux, open a terminal and type tail -f /var/log/syslog to watch the system log in real time, or cat /var/log/syslog to view the whole file.
When you open a log file, don't expect it to read like a story. It's technical and dense. Look for entries marked "Error" or "Critical" near the time something went wrong. Look for repeated errors — if the same error appears 50 times, that's the real problem. If you see an error code, search the internet for that code along with the program name to find out what it means.
Different types of logs for different purposes
System logs record what the operating system itself is doing — drivers loading, services starting, hardware detected, shutdown events. These are the broadest logs and the most useful for diagnosing why your computer won't start or why a device isn't working.
Security logs track login attempts, permission changes, and access to sensitive files. They're usually locked down so that only administrators can read them. If you suspect someone has accessed your computer without permission, the Security log is where you'd look.
Application logs record errors and events from programs you've installed. If Outlook crashes, the Application log will have an entry. If Chrome runs out of memory, it goes in the Application log. These logs are program-specific and vary widely in what they record.
Web server logs record every request a website receives — what page was requested, what time, what device requested it, whether the request succeeded or failed. If you run a website, your web host provides access to these logs so you can see traffic patterns and diagnose problems.
Network logs record connections to and from your computer — what devices connected to your WiFi, what websites you visited, what data was sent and received. Your router keeps a network log. Some security software keeps its own network log.
Frequently Asked Questions
Can I delete log files to free up disk space?
Yes, log files are safe to delete. Your system will create new ones automatically. On Windows, Event Viewer lets you clear logs by right-clicking a log category and selecting "Clear Log." On Mac and Linux, you can delete files in /var/log directly. Older logs are usually deleted automatically anyway, so you rarely need to do this manually.
What does "error code" mean in a log file?
An error code is a number that identifies a specific problem. Instead of writing out "the file could not be found" every time, the system writes "Error 2" or "Error 0x00000002." Each program and operating system has its own set of error codes. You can search the internet for the code and the program name to find out what it means.
Can someone use log files to see what I've been doing on my computer?
System logs don't record what websites you visit or what files you open — they record technical events like program crashes and driver loads. However, your browser keeps its own history, and your router keeps a log of network traffic. If someone has access to your computer or router, they could potentially read those logs. Your operating system's Security log does record login attempts, so someone could see when you logged in.
Why do programs keep creating new log files instead of adding to one big file?
Log files can grow very large very quickly, especially on busy systems. Most programs rotate logs — they write to one file until it reaches a certain size, then start a new file and compress or delete the old one. This keeps any single log file from taking up gigabytes of disk space. It also makes logs easier to organize by date.
Do I need to worry about log files if my computer is working fine?
No. Log files are created automatically and managed automatically. You don't need to check them or maintain them unless something is broken. They're there in the background in case you need them for troubleshooting later.