PowerShell read Eventlog

Diese Seite gibt es auch in Deutsch

With the command "Get-WinEvent" the Windows Eventlog can be accessed via PowerShell

Evaluation: When was the computer rebooted:

Get-WinEvent -FilterHashtable @{logname='system'; id=6005}

Provided the necessary rights, the event log can also be read from another computer:

With the same user on the logged-in computer:

Get-WinEvent -FilterHashtable @{logname='system'; id=6005}

With the logged in user on another computer

Get-WinEvent -FilterHashtable @{logname='system'; id=6005} -ComputerName HOSTNAME

with another user:

Get-WinEvent -FilterHashtable @{logname='system'; id=6005} -ComputerName HOSTNAME -credentials get-credential

Eventlog list

a list of available eventlogs is listed by the following command:

Get-WinEvent -listlog *

The -listlog parameter can search for specific logs:

Get-WinEvent -listlog *GroupPolicy*
positive Bewertung({{pro_count}})
Rate Post:
{{percentage}} % positive
negative Bewertung({{con_count}})

THANK YOU for your review!


Top articles in this section

PowerShell Log-Files: Logging into a textfile - write to file

PowerShell Log-Files: Logging into a textfile - write to file

created: 2022-05-05 from Bernhard

Log files in PowerShell can be created via the Out-File command, via a custom function, or via PowerShell's built-in Transcript. ... continue reading

Preview PowerShell text file and csv read / write

PowerShell text file and csv read / write

created: 2022-05-02 from Bernhard

PowerShell text file and csv read / write ... continue reading

PowerShell Loops and Array

PowerShell Loops and Array

created: 2022-05-02 from Bernhard

An array stores multiple values, similar to a 2-column table. ... continue reading


Questions / Comments