PowerShell read Eventlog

Diese Seite gibt es auch in Deutsch

With the command "Get-WinEvent" the Windows Eventlog can be accessed via PowerShell

Evaluation: When was the computer rebooted:

Get-WinEvent -FilterHashtable @{logname='system'; id=6005}

Provided the necessary rights, the event log can also be read from another computer:

With the same user on the logged-in computer:

Get-WinEvent -FilterHashtable @{logname='system'; id=6005}

With the logged in user on another computer

Get-WinEvent -FilterHashtable @{logname='system'; id=6005} -ComputerName HOSTNAME

with another user:

Get-WinEvent -FilterHashtable @{logname='system'; id=6005} -ComputerName HOSTNAME -credentials get-credential

Eventlog list

a list of available eventlogs is listed by the following command:

Get-WinEvent -listlog *

The -listlog parameter can search for specific logs:

Get-WinEvent -listlog *GroupPolicy*
positive Bewertung({{pro_count}})
Rate Post:
{{percentage}} % positive
negative Bewertung({{con_count}})

THANK YOU for your review!

Publication: 2022-05-02 from Bernhard 🔔

Top articles in this section

PowerShell Log-Files: Logging into a textfile - write to file
Log files in PowerShell can be created via the Out-File command, via a custom function, or via PowerShell's built-in Transcript.

PowerShell Loops and Array
An array stores multiple values, similar to a 2-column table.

PowerShell text file and csv read / write
PowerShell text file and csv read / write

Questions / Comments