When applications on Windows fail they never think to generate an event, not even for something as simple as a "permission denied attempting to open file 'c:\blah'". Instead it's chock full of useless noise from daemons that activate every 2 seconds to poll something and then log that everything is still ok.
https://docs.microsoft.com/en-us/windows/security/threat-pro...
I have seen and hope to never see again worst cases such as the COM control for all of .NET Framework event log messages (everything from .NET system messages to just the mostly plain text storage from applications written in .NET) accidentally badly unregistered leaving all of the event log messages unreadable.
Don't even get me started on this... Microsoft is actually bad for this with even their own .NET-based enterprise applications. As well - it also makes gathering logs from production servers, then performing analysis on a different machine difficult, as that machine will likely have none of the dependencies required.
Text... text and more text, that is universal.