Get-WinEvent
Using Get-WinEvent
See available Logs
Get-WinEvent -ListLog *list of logs with displayed essential properties
Get-WinEvent -ListLog * | Select-Object LogName, RecordCount, IsClassicLog, IsEnabled, LogMode, LogType | Format-Table -AutoSizeGet-WinEvent -ListProvider * | Format-Table -AutoSize1. Retrieving events from the System log
Get-WinEvent -LogName 'System' -MaxEvents 50 | Select-Object TimeCreated, ID, ProviderName, LevelDisplayName, Message | Format-Table -AutoSize2. Retrieving events from Microsoft-Windows-WinRM/Operational
3. Retrieving events from .evtx Files
4. Filtering events with FilterHashtable
5. Filtering events with FilterHashtable & XML
6. Filtering events with FilterXPath
7. Filtering events based on property values
Last updated

