You wake up, open Remote Desktop, and something is off. A trade you expected isn’t there, or one you didn’t expect is. A stop wasn’t trailed. The EA’s smiley face is a frown. Your first instinct is to fix it: restart the terminal, reattach the EA, move on.
Resist that for ten minutes. MetaTrader and Windows have been keeping a detailed record of everything that happened, and reading it is the difference between knowing why something went wrong and hoping it doesn’t happen again. On a VPS, where nobody watches the screen overnight, the logs are the only witness.
📊 Key Stat: MetaTrader writes a new log file every day for both the terminal (Journal) and your EAs (Experts), and keeps the old ones on disk. Unless someone deleted them, you can go back weeks to find the first sign of a problem.
The Three Logs That Matter
1. The Journal: What the Terminal Did
The Journal tab (in the Toolbox, or Terminal, window) is the terminal’s own diary. It records:
- logins, disconnections and reconnections to the broker’s server, often with the measured ping
- order requests and the server’s responses
- EAs and indicators being loaded, removed or failing to initialise
- terminal startup and shutdown
- live updates of the platform itself
Files live in <data folder>\logs\, one per day, named YYYYMMDD.log.
2. The Experts Log: What Your EA Said
The Experts tab shows messages from your EAs and indicators: everything they Print(), plus runtime errors such as array out of range, division by zero or trade errors with codes.
Files live in <data folder>\MQL4\Logs\ (MT4) or <data folder>\MQL5\Logs\ (MT5), again one per day.
3. Windows Event Viewer: What the Machine Did
If the terminal itself went away, the answer is usually in Windows, not MetaTrader. Open Event Viewer → Windows Logs → System and filter for these event IDs:
- 1074: a process or user initiated a restart or shutdown. This includes Windows Update restarts, and the event names the process.
- 6008: the previous shutdown was unexpected.
- 41 (Kernel-Power): the system rebooted without shutting down cleanly.
- 6005 / 6006: the event log service started or stopped, which is a reliable marker of boot and shutdown times.
💡 Tip: To find the data folder, open MetaTrader and choose File → Open Data Folder. On a VPS it is usually under your user profile’s AppData, not in Program Files. That catches out a lot of people looking for logs in the install folder.
First, Get the Time Zones Straight
This step trips up nearly everyone. MetaTrader log files are stamped with the VPS’s local clock. Your charts and trade history show broker server time. Those are often several hours apart.
Before you correlate anything, work out the offset. Compare a trade’s open time in the History tab (server time) with the log line where the terminal sent that order (local time). Write the offset down. Our time synchronisation guide and daylight saving guide cover why the offset can change twice a year.
⚠️ Warning: A mismatched time zone is the most common reason traders “prove” the wrong cause. If the EA error appears to happen an hour before the connection drop that caused it, check the offset before building a theory.
Reading the Story: Four Common Overnight Mysteries
”My EA Didn’t Take a Trade It Should Have”
Work backwards from the missed signal time:
- Journal: Was the terminal connected at that minute? Look for disconnect and reconnect lines around it.
- Experts: Did the EA print anything? A trade error code points to a specific cause. Complete silence often means the EA wasn’t running, or its filters (time, spread, news) quietly blocked the trade.
- Journal again: Was the EA even loaded? Look for lines showing it was removed or failed to initialise, which often happens after a restart when AutoTrading came up disabled.
If the EA doesn’t print why it skips a signal, that is worth fixing in its own right. EAs that log their decisions (“spread 3.2 > max 2.0, skipping”) make these investigations short.
”The Terminal Was Closed When I Logged In”
Go straight to Event Viewer. A 1074 event at 3am naming the Windows Update service answers the question in one line, and the fix is in how and when to do Windows updates. A 6008 or Kernel-Power 41 event means an unexpected restart. If you see those, raise it with support and include the timestamps.
If Windows shows no restart at all, check the Journal’s last lines before the gap. A terminal that crashed on its own often has an EA or indicator error just before it goes silent.
”I Got Disconnected During the Session”
Journal lines about connection loss and reconnection, with timestamps, show how long you were offline and how often. A single short drop around the broker’s daily maintenance window is normal. Repeated drops during trading hours are not. Record the times and the ping values from the reconnect lines, then read MT4/MT5 no connection errors for the fixes.
”The EA Opened Two Positions Instead of One”
Look for a timeout or “no connection” error on the first attempt in the Experts log, followed by a second send. An EA that retries without checking whether the first order was actually filled will double up. It is a coding issue, not an infrastructure one. Also check that the same EA isn’t running on another terminal or machine against the same account. Our standby VPS guide explains why that happens.
✅ Best Practice: When you investigate an incident, copy that day’s Journal, Experts and relevant Event Viewer entries into a single text file with a short note about what you concluded. After three or four incidents you will have a pattern to look for, and a much better conversation with your EA developer or your broker.
Make Tomorrow’s Investigation Easier
- Ask for decision logging. If you commission or buy EAs, ask for an option that prints why trades were skipped or modified. It costs nothing and saves hours.
- Don’t log every tick. An EA that prints on every tick produces huge log files that are useless to read and waste disk space. See how much disk space a trading VPS needs.
- Archive old logs. Zip logs older than a month and move them out of the data folder. Deleting them is fine too, as long as you are not in the middle of a dispute with a broker or prop firm.
- Add push notifications for errors. An EA that pushes a notification when it hits an error turns a morning mystery into a real-time alert. See push notifications and monitoring.
🚀 Try FXVPS for $2.99. Get 7 days on a Core VPS, with a stable, always-on machine whose logs tell a clean story. Cancel anytime.
When the Logs Point at the VPS
Most overnight mysteries turn out to be EA logic, broker maintenance or Windows updates. Sometimes, though, the logs show a pattern that points at the infrastructure: frequent disconnects with rising pings, unexpected restarts with no update behind them, or an EA that stalls at the same time every day. If so, the next reads are why your VPS might be making your EA lose money and the CPU at 100% fix. If it’s the host, contact support with the timestamps from your logs. That turns a vague “it was slow” into something that can actually be investigated.
Frequently Asked Questions
Where are MT4 log files stored?
Terminal logs are in <data folder>\logs\ and EA logs are in <data folder>\MQL4\Logs\. For MT5, EA logs are in MQL5\Logs\ instead. Use File → Open Data Folder to find the data folder.
Why don’t the times in my logs match my trade history?
Logs use the VPS’s local time, and trade history uses broker server time. Work out the offset first and apply it when correlating events.
How far back do MetaTrader logs go?
As far back as the files on disk. MetaTrader writes one file per day and doesn’t delete old ones on its own, so unless someone has cleaned the folder, you can go back weeks or months.
Can I send my logs to my EA developer?
Yes, and a good developer will ask for them. Send the Experts and Journal files for the day in question. Account numbers appear in the logs, so share them only with people you trust.
Is it safe to delete old log files?
Yes. MetaTrader doesn’t need them to run. Keep recent ones and anything connected to an open dispute with a broker or prop firm.
Related Reading
- MT4 and MT5 Trade Error Codes Explained. Decode the error numbers you find in the Experts log.
- What Stops Working When Your MT4 Terminal Goes Offline. What an overnight outage actually costs.
- Automating EA Restarts with Task Scheduler. Recover automatically once you know the cause.
- Navigating Technical Issues on Your Forex VPS. The broader troubleshooting checklist.