Commands · reference

vmlab eventlog

3 min read · 2026-09-02 · vmlab 0.9

vmlab eventlog follows the Windows event log of a guest over the vmlab agent channel. It is the event-log counterpart of vmlab tail: a stream that keeps printing as new events are logged, with no guest network or shell involved.

sh
vmlab eventlog [OPTIONS] <VM>
OptionMeaning
<VM>The machine, as [lab/]name.
--filter <FILTER>XPath filter. Default: everything on the System channel.
-h, --helpPrint help.

The command asks the lab daemon to open an event-log session on the machine's agent and prints each chunk as it arrives, flushing after every chunk. It runs until you press Ctrl-C, the machine stops, or the agent reports a session error. The filter is the same XPath the Windows Event Viewer accepts in its XML filter, and it selects both the channel and the events within it.

The daemon checks the agent's negotiated features before opening the session. A guest whose agent does not advertise the event log, which is every Linux guest and every container, is refused as unsupported with the message that the event log is a Windows-only feature.

sh
vmlab eventlog dc01
vmlab eventlog dc01 --filter "*[System[(Level=1 or Level=2)]]"

Exit status is 0 when the stream ends. not_found (4) means the lab declares no machine by that name. unsupported (6) means the guest's agent has no event log. failed (1) covers a machine that is not running, an agent that does not answer, and a session error such as a filter Windows rejects.