So I tried clearing event logs. I can see that it works. System Informer shows me that it's using wevtutil.exe but there is no indication from within...
I'm "assuming" that gallicbear can't get past the bios password before boot (bios boot password). If i'm misunderstanding then ignore my first reply....