{"id":719,"date":"2008-11-03T17:00:58","date_gmt":"2008-11-04T01:00:58","guid":{"rendered":"http:\/\/www.sapien.com\/blog\/2008\/11\/03\/november-powershell-one-liner\/"},"modified":"2008-11-03T09:00:31","modified_gmt":"2008-11-03T17:00:31","slug":"november-powershell-one-liner","status":"publish","type":"post","link":"https:\/\/dev.sapien.com\/blog\/2008\/11\/03\/november-powershell-one-liner\/","title":{"rendered":"November PowerShell One-liner"},"content":{"rendered":"<p>[This month&#8217;s SAPIEN newsletter offered this one liner I thought I&#8217;d share with the rest of you].<\/p>\n<p>The following one line PowerShell expression should show you who is logged on to a specific server and desktop and for how long. Most logon sessions use a single instance of Explorer.exe, although it is possible for a user to manually start additional instances of Explorer.exe.<\/p>\n<p><span style=\"color: #0000ff;\"><tt>Get-WmiObject win32_process -filter \"name='explorer.exe'\" -computer \"SERVER01\"\u00a0 |<br \/>\nselect @{name=\"Computer\";Expression={$_.CSNAME}},@{Name=\"Owner\";Expression={<br \/>\n\"{0}\\{1}\" -f $_.getOwner().Domain,$_.getOwner().User}},<br \/>\n@{name=\"Started\";Expression={$_.ConvertToDateTime($_.creationdate)}},<br \/>\n@{name=\"Duration\";Expression={<br \/>\n$started=$_.ConvertToDateTime($_.creationdate)<br \/>\n$now=Get-Date<br \/>\n($now-$started).toString()}},<br \/>\n@{name=\"KernelModeTime(s)\";Expression={$_.KernelModeTime\/10000000}},<br \/>\n@{name=\"UserModeTime(s)\";Expression={$_.UserModeTime\/10000000}}<\/tt><br \/>\n<\/span><\/p>\n<p>This should give you output like this:<br \/>\n<tt><\/tt><\/p>\n<p><tt><span style=\"color: #0000ff;\">Computer\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 : SERVER01<br \/>\nOwner\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 : MyCompany\\Jeff<br \/>\nStarted\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 : 10\/20\/2008 9:01:38 AM<br \/>\nDuration\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 : 1.05:47:58.8702700<br \/>\nKernelModeTime(s) : 123.8179937<br \/>\nUserModeTime(s)\u00a0\u00a0 : 51.9795332<\/span><\/tt><\/p>\n<p><tt><\/tt><br \/>\nThe KernelMode and UserMode times are in seconds. Because this is an object, you can pipe it to other cmdlets to sort, filter, export or convert. If you have comments or questions about this or anything else PowerShell, please visit the forums at <a href=\"http:\/\/www.scriptinganswers.com\" target=\"_blank\">ScriptingAnswers.com<\/a>.<\/p>\n<div id=\"scid:fb3a1972-4489-4e52-abe7-25a00bb07fdf:9e2120e1-bb92-40c6-84c4-2f22a906c3da\" class=\"wlWriterSmartContent\" style=\"padding-right: 0px; display: inline; padding-left: 0px; padding-bottom: 0px; margin: 0px; padding-top: 0px\">\n<p>Download this <a href=\"http:\/\/www.sapien.com\/blog\/wp-content\/uploads\/2008\/10\/nov08oneliner.txt\" target=\"_blank\">code.<\/a><\/div>\n","protected":false},"excerpt":{"rendered":"<p>The following one line PowerShell expression should show you who is logged on to a specific server and desktop and for how long. Most logon sessions use a single instance of Explorer.exe, although it is possible for a user to manually start additional instances of Explorer.exe.<\/p>\n","protected":false},"author":3,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"footnotes":""},"categories":[25],"tags":[249,309,28,35],"class_list":["post-719","post","type-post","status-publish","format-standard","hentry","category-windows-powershell","tag-get-wmiobject","tag-logon","tag-powershell","tag-wmi"],"jetpack_featured_media_url":"","_links":{"self":[{"href":"https:\/\/dev.sapien.com\/blog\/wp-json\/wp\/v2\/posts\/719","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/dev.sapien.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/dev.sapien.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/dev.sapien.com\/blog\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/dev.sapien.com\/blog\/wp-json\/wp\/v2\/comments?post=719"}],"version-history":[{"count":2,"href":"https:\/\/dev.sapien.com\/blog\/wp-json\/wp\/v2\/posts\/719\/revisions"}],"predecessor-version":[{"id":750,"href":"https:\/\/dev.sapien.com\/blog\/wp-json\/wp\/v2\/posts\/719\/revisions\/750"}],"wp:attachment":[{"href":"https:\/\/dev.sapien.com\/blog\/wp-json\/wp\/v2\/media?parent=719"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/dev.sapien.com\/blog\/wp-json\/wp\/v2\/categories?post=719"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/dev.sapien.com\/blog\/wp-json\/wp\/v2\/tags?post=719"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}