winevt
Script to programmatically interface with Windows Events.
Decision gist · record as of 2026-08-14
Yes, but with caution. The package does what it claims and has no known vulnerabilities, but it has not been actively maintained since 2017 and is marked dormant. Install it if you need direct Windows Event Log access from Python and are willing to accept that bug fixes or compatibility updates are unlikely. High install friction (compiled extension) and Windows-only support limit its audience. Not suitable for new projects requiring ongoing support.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Windows-only; requires Python 3.2 or later (x64 recommended).
- Requires a C compiler and Windows SDK headers to build from source.
- High install friction: the package is a compiled extension with no runtime dependencies, but has not been updated since its initial release in 2017 and is marked dormant.
License · maintenance · safety
MIT (permissive) — MIT license is permissive; you can use this package in commercial and private projects with minimal restrictions, though you must include the license notice.
last release 2017-05-10 (3383 days) · last repo commit 2024-11-10 · 68 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 106,152 downloads/mo, #12,665 on PyPI
Alternatives
Verify before relying
pip install winevt
from winevt import EventLog
query = EventLog.Query("Application", "Event/System/Provider[@Name='Windows Error Reporting']")
for event in query:
print(event.System.Provider['Name'])- Whether the package works reliably on modern Windows versions (tested only on Windows 10 x64 with Python 3.6).
- Whether the package is compatible with Python versions beyond 3.6, given the dormant maintenance status.
- Whether pre-built wheels are available or if compilation is required on installation.
What it is and what it does
Winevt is a Python library that provides direct access to the Windows Event Logging system through the Windows API. Instead of parsing static event log files, it lets you query live event logs, subscribe to real-time events with callbacks, and work with event data as structured objects. The library abstracts Windows event concepts like providers, channels, and bookmarks, making it easier to filter events using XPath queries and traverse event properties programmatically.
The package is Windows-only and designed for system administrators and developers who need to monitor or audit Windows events from Python. It supports local and remote authentication, allows you to maintain your position in an event stream using bookmarks, and can handle multiple concurrent subscriptions. The library returns events as objects with both raw XML and structured property access, so you can work with event data however you prefer.
Use it for
- Monitor system or application event logs in real-time and trigger alerts or actions when specific events occur.
- Audit security events (e.g., failed logins, privilege escalation) across local or remote Windows machines.
- Extract and filter historical events from event logs using XPath queries for compliance or forensic analysis.
- Build a centralized event collection system that subscribes to multiple Windows machines and aggregates events.
- Parse and analyze event log data programmatically without relying on the Windows Event Viewer GUI.
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes, but with caution.
The package does what it claims and has no known vulnerabilities, but it has not been actively maintained since 2017 and is marked dormant. Install it if you need direct Windows Event Log access from Python and are willing to accept that bug fixes or compatibility updates are unlikely. High install friction (compiled extension) and Windows-only support limit its audience. Not suitable for new projects requiring ongoing support.
Install
winevt on PyPI
Before you install
High install friction: the package is a compiled extension with no runtime dependencies, but has not been updated since its initial release in 2017 and is marked dormant. Last commit was in 2024, but the codebase shows no active maintenance. Installation requires a working C compiler and Windows-specific build tools.
Windows-only; requires Python 3.2 or later (x64 recommended). Requires a C compiler and Windows SDK headers to build from source.
License in practice
MIT license is permissive; you can use this package in commercial and private projects with minimal restrictions, though you must include the license notice.
Quickstart
pip install winevt
from winevt import EventLog
query = EventLog.Query("Application", "Event/System/Provider[@Name='Windows Error Reporting']")
for event in query:
print(event.System.Provider['Name'])
Verify before relying
- Whether the package works reliably on modern Windows versions (tested only on Windows 10 x64 with Python 3.6).
- Whether the package is compatible with Python versions beyond 3.6, given the dormant maintenance status.
- Whether pre-built wheels are available or if compilation is required on installation.
Package facts
| License | MIT permissive |
| Python support | Not specified |
| Install friction | High. Source build required |
| Runtime dependencies | None |
| Maintenance | Dormant 3,383 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 106,152 / month, #12,665 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | Development Status :: 5 - Production/StableEnvironment :: ConsoleIntended Audience :: End Users/DesktopLicense :: OSI Approved :: MIT LicenseOperating System :: Microsoft :: WindowsProgramming Language :: Python :: 3 |
Evidence: winevt-0.0.11.tar.gz
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “windows event log query python”
- winevtWinevt lets you query and subscribe to Windows Event Logs directly…
- pySigma-backend-elasticsearchTranslates Sigma security rules into Elasticsearch query formats…
- python-evtxParses Windows Event Log files (.evtx) into structured XML or JSON,…
Give your agent the search over MCP, or paste the wish link into any chat.
More Monitoring packages
Wraps any iterable to display a real-time progress bar in the terminal or Jupyter notebook, showing iteration count, elapsed time, and estimated time remaining.
Provides generated Python code for OpenTelemetry semantic conventions, enabling standardized attribute naming and constant definitions for instrumentation and telemetry collection.
Install it if you are using OpenTelemetry and want to follow semantic conventions correctly.
Provides the reference implementation of the OpenTelemetry API for collecting and exporting traces, metrics, and logs from Python applications.
Provides the abstract API and interfaces for OpenTelemetry instrumentation in Python, defining how to emit traces, metrics, and logs without tying code to a specific SDK implementation.
Exports OpenTelemetry observability data to an OpenTelemetry Collector using Protobuf-encoded messages over HTTP.
Install it if you are using OpenTelemetry in Python and need to send data to a Collector over HTTP.
Provides automatic instrumentation commands and programmatic APIs to inject distributed tracing into Python applications without code changes, detecting and instrumenting packages used by your program.
Install it if you need distributed tracing without code changes and have compatible instrumented packages in your environment.
See also python-evtx · Events · pyeventsystem · azure-eventgrid · aiocop · moonraker-api · pypsrp · azure-eventhub · slackeventsapi · firebase-messaging