How to Check Computer Activity History on Windows 10

To check activity history on a Windows 10 computer, start with three places: Recent items for files that were opened (press Windows key + R, type shell:recent and press Enter), the web browser’s history (Ctrl + H) for websites, and Event Viewer for when the PC was turned on, woken and signed in to. Together they show what was used and when.

Applies to: Windows 10, version 22H2. The same tools exist in Windows 11. Last reviewed October 7, 2026.

Use this on your own PC, or with permission. Checking someone else’s activity without their knowledge can break workplace rules or the law, depending on where you live.

Ways to check computer activity history on Windows 10
Where Windows 10 records what you did and when. This is a drawing, not a screenshot.

Method 1: See recently opened files

  1. Press Windows key + R, type shell:recent and press Enter.
  2. Select View > Details, then click the Date modified column to sort by most recent.

Each shortcut is a file or folder that was opened, with the time it was last opened. File Explorer’s Quick access view also lists recent files, and right-clicking an app on the taskbar shows its recent documents. To check for changed files, open a folder such as Documents or Downloads and sort by Date modified.

Method 2: Check browser history

  • Edge, Chrome and Firefox: press Ctrl + H to see history by date.
  • Downloads: press Ctrl + J for the downloads list.

History is per browser and per browser profile, so check each one. Private or InPrivate windows don’t save history.

Method 3: See when the PC was used in Event Viewer

  1. Right-click Start and select Event Viewer.
  2. Expand Windows Logs and select System.
  3. Select Filter Current Log on the right and enter these event IDs in the box: 6005,6006,6008,1,42.
  4. Select OK and read the list by date and time.

What the IDs mean:

  • 6005: Windows started.
  • 6006: Windows shut down normally. 6008 means it shut down unexpectedly.
  • 42 (source Kernel-Power): the PC went to sleep. 1 (source Power-Troubleshooter): it woke up.

See who signed in

  1. In Event Viewer, select Windows Logs > Security.
  2. Filter for event ID 4624 (successful sign-in) and 4625 (failed sign-in).
  3. Open an event and look at Account Name and Logon Type. Type 2 is someone at the keyboard, 7 is unlocking the PC, and 10 is a Remote Desktop connection.

The Security log includes many entries from Windows itself, such as SYSTEM, so focus on your user names. For a quick check of one account’s last sign-in, run net user YourName in Command Prompt and look at Last logon.

Method 4: Check Windows activity history (Timeline)

If Store my activity history on this device is on in Settings > Privacy > Activity history, press Windows key + Tab and scroll down to see recent apps, files and websites by day. For the Windows 11 version, see how to view activity history on Windows 11.

Method 5: See which apps used the internet

Open Settings > Network & Internet > Data usage (or Status > Data usage) and select your connection. It lists how much data each app used in the last 30 days, which shows apps that were active even if no files were opened.

Method 6: Check installed programs and changes

  • Press Windows key + R, type perfmon /rel and press Enter. Reliability Monitor shows, day by day, apps installed and removed, Windows updates and crashes.
  • In Settings > Apps > Apps & features, sort by Install date to find anything new.
  • Check the Recycle Bin for recently deleted files; sort by Date Deleted.

Clear your own history

To remove recent files lists and other traces of your own use, see how to clear recent files in Windows 10. Browsers clear history with Ctrl + Shift + Delete.

Protect your PC from others

  • Lock the PC with Windows key + L whenever you step away.
  • Give each person their own Windows account rather than sharing one.
  • Use a PIN or password, and turn off Remote Desktop if you don’t use it.
  • Windows 10 no longer gets regular security updates; see how to enroll in Windows 10 Extended Security Updates or upgrade to Windows 11.

Troubleshooting

The Security log has no sign-in events

Logon auditing may be turned off. On Windows 10 Pro, open secpol.msc and check Local Policies > Audit Policy > Audit logon events. You need an administrator account to read the Security log.

Recent items is empty

Recent items may be turned off. Open Settings > Personalization > Start and turn on Show recently opened items.

Get Our Free Newsletter

How-to guides and tech deals

You may opt out at any time.
Read our Privacy Policy