Windows

Where Are AppLocker Event Logs Stored?

AppLocker writes allow and block events to dedicated evtx logs under Applications and Services Logs.

Last updated

AppLocker decisions do not vanish into the generic Application log. Each enforcement type gets its own channel under Microsoft Windows AppLocker, with separate logs for executables, installers, and scripts.

The files behind those channels sit in the winevt Logs folder with percent-encoded names. You rarely open them directly, since Event Viewer renders the same data, but the paths matter for collectors and SIEM forwarding. Copy the channel name exactly when configuring forwarding or the subscription silently gathers nothing.

Where Windows stores this, by platform

Windows
C:\Windows\System32\winevt\Logs\Microsoft-Windows-AppLocker%4EXE and DLL.evtx

View in Event Viewer under Applications and Services Logs > Microsoft > Windows > AppLocker. The evtx files use %4 escapes for the slashes in the channel names, which breaks naive copy-paste forwarding rules.

Frequently asked questions

Where do I see why an app was blocked?

Open the AppLocker EXE and DLL log first, since blocked launches land there. Pair the timestamp with the user's report to find the exact rule that fired.

Do the events show which rule blocked the file?

Yes. The event text names the file, the publisher or hash condition, and the policy version in force, which is usually enough to write the exception without guessing.

Notice an outdated path? Let us know.