I have a Windows 2003 server, let's call it Mystic Hare, which keeps crashing intermittently. The problem I have in diagnosing the problem, is that the last 3 hours of the Windows System logs are always empty.
1. The last 3 hours of the System log are wiped out during the crash; or
2. There is no event written to the System log during those times.
So I decided to write to the System event log with dummy entries as an experiment.
The command I'm using is:
> eventcreate /L System /T Information /id 1 /d "For testing only"
This is what I see for the dummy System log entry in the Event Viewer"