ChkDsk Audit - Windows
0 Votes |
Description
References:
http://ask-leo.com/how_do_i_see_the_results_of_a_chkdsk_that_ran_on_boot.html
http://www.sevenforums.com/tutorials/96938-check-disk-chkdsk-read-event-viewer-log.html
http://kmwoley.com/blog/?p=441
http://superuser.com/questions/214209/where-are-the-results-of-chkdsk-located-in-windows-7
http://ericphelps.com/uncheck/index.htm
https://www.raymond.cc/blog/how-to-recover-chk-files-created-by-chkdsk-and-scandisk/
Property Details
Properties
Num of ChkDsks
Period
12 hours
* Results in a true/false |

number of records whose (source of it as lowercase contains "chkdsk") of application event log
Num of ChkDsks during wininit of application log
Period
12 hours
* Results in a true/false |

number of records whose(source of it as lowercase ends with "wininit" AND description of it as lowercase contains "chkdsk") of application event log
ChkDsk Logs
Period
12 hours
* Results in a true/false |

pathnames of files whose((name of it as lowercase ends with ".log") AND (name of it as lowercase starts with "chkdsk")) of folders "System Volume Information\Chkdsk" of root folders of drives whose(type of it = "DRIVE_FIXED")
num of ChkDsk Logs
Period
12 hours
* Results in a true/false |

number of files whose((name of it as lowercase ends with ".log") AND (name of it as lowercase starts with "chkdsk")) of folders "System Volume Information\Chkdsk" of root folders of drives whose(type of it = "DRIVE_FIXED")
Total Num of ChkDsks
Period
12 hours
* Results in a true/false |

sum of ( ( number of files whose((name of it as lowercase ends with ".log") AND (name of it as lowercase starts with "chkdsk")) of folders "System Volume Information\Chkdsk" of root folders of drives whose(type of it = "DRIVE_FIXED") );( number of records whose (source of it as lowercase contains "chkdsk") of application event log );( number of records whose(source of it as lowercase ends with "wininit" AND description of it as lowercase contains "chkdsk") of application event log ) )
Found_Files
Period
12 hours
* Results in a true/false |

pathnames of files of folders whose(name of it as lowercase starts with "found.") of root folders of drives whose(type of it = "DRIVE_FIXED")
Number of Found_Files
Period
6 hours
* Results in a true/false |

number of files whose(name of it as lowercase starts with "file" AND name of it as lowercase ends with ".chk") of folders whose(name of it as lowercase starts with "found.") of root folders of drives whose(type of it = "DRIVE_FIXED")
Relevance
isWindows (Relevance 1172)

windows of operating system
Used in 1 analsis | * Results in a true/false |

( exists files of folders "System Volume Information\Chkdsk" of root folders of drives whose(type of it = "DRIVE_FIXED") ) OR ( exists files of folders whose(name of it as lowercase starts with "found.") of root folders of drives whose(type of it = "DRIVE_FIXED") ) OR ( exists records whose (source of it as lowercase contains "chkdsk") of (application event log) ) OR ( exists records whose(source of it as lowercase ends with "wininit" AND description of it as lowercase contains "chkdsk") of (application event log) )
Sharing
Social Media: |
Comments
![]() |
|
This is really interesting information for me. Thanks for sharing!- http://hotmailwiki.com/hotmail-login |