【发布时间】:2014-08-26 09:49:39
【问题描述】:
我有一个事件日志条目,我想查询“Security UserID”来检索它的值。这可能吗?最好使用powershell
Log Name: Application
Source: EventCreate
Date: 26/08/2014 10:17:21
Event ID: 4
Task Category: None
Level: Information
Keywords: Classic
User: DOMAIN\UserName
Computer: COMPUTERNAME
Description:
This is a test
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="EventCreate" />
<EventID Qualifiers="0">4</EventID>
<Level>4</Level>
<Task>0</Task>
<Keywords>0x80000000000000</Keywords>
<TimeCreated SystemTime="2014-08-26T09:17:21.000000000Z" />
<EventRecordID>570080</EventRecordID>
<Channel>Application</Channel>
<Computer>COMPUTERNAME</Computer>
<Security UserID="S-1-5-21-xxxxxxxxxxxxxxxxxxxxxx" />
</System>
<EventData>
<Data>Process Started</Data>
</EventData>
</Event>
【问题讨论】:
-
答案是我找到的,但想知道是否可以通过 get-eventlog 检索此信息
标签: windows events powershell event-viewer