in my windows event logs I have: TimeGenerated=20101226191500.000000-360 TimeWritten=20101226191500.000000-360 what is the difference between these to time stamps and were do they come from?
TimeGenerated
is when the event occurred; TimeWritten
is when it was written to the event log. Usually they'll be the same or very close.
See also:
http://msdn.microsoft.com/en-us/library/system.diagnostics.eventlogentry.timegenerated(v=vs.71).aspx