Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- $query = @"
- <QueryList>
- <Query Id="0" Path="Application">
- <Select Path="Application">*[System[(Level=1 or Level=2 or Level=3)]]</Select>
- <Select Path="Security">*[System[(Level=1 or Level=2 or Level=3)]]</Select>
- <Select Path="Setup">*[System[(Level=1 or Level=2 or Level=3)]]</Select>
- <Select Path="System">*[System[(Level=1 or Level=2 or Level=3)]]</Select>
- <Select Path="ForwardedEvents">*[System[(Level=1 or Level=2 or Level=3)]]</Select>
- </Query>
- </QueryList>
- “@
- $file = New-Item -Name EVT.log -Path c:\temp -Force -type file
- Get-WinEvent -ComputerName "SRVLABSPWEB01" -FilterXml $query | %{
- $evt = [xml]$_.toxml();
- $_ | fl * | Out-File $file -Append
- }
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement