{"id":74,"date":"2007-02-15T15:43:03","date_gmt":"2007-02-15T23:43:03","guid":{"rendered":"http:\/\/testblog.sapien.com\/index.php\/2007\/02\/15\/powershell-quick-event-log\/"},"modified":"2007-02-15T15:43:03","modified_gmt":"2007-02-15T23:43:03","slug":"powershell-quick-event-log","status":"publish","type":"post","link":"https:\/\/dev.sapien.com\/blog\/2007\/02\/15\/powershell-quick-event-log\/","title":{"rendered":"PowerShell Quick Event Log"},"content":{"rendered":"<p>These days I&#8217;m in to fast and furious coding. It seems I no longer have time to develop full, robust scripts with beautiful output and error handling.&nbsp; I just need information.&nbsp; Fortunately PowerShell is great at giving you lots of information. As long as you know how to ask for it. One daily task I have is checking my event log for the latest events. Here is a fast and furious single line expression that will display the last 10 entries in all the event logs on my system:<\/p>\n<p><font size=\"2\" face=\"Lucida Console\" color=\"#0000ff\" style=\"color: rgb(0, 0, 255);\">foreach ($log in (get-eventlog -list -asString)) {write-host $log -fore Green -back Black; Get-eventlog $log -newest 10|Select TimeGenerated,EntryType,Source,EventID,Message | more}<\/font><\/p>\n<p>The foreach cmdlet is iterating through the list of event logs as returned by <\/p>\n<p><font size=\"2\" face=\"Lucida Console\" color=\"#0000ff\" style=\"color: rgb(0, 0, 255);\">(get-eventlog -list -asString)<\/font><\/p>\n<p>For each log, I write the log name in Green on a&nbsp; Black background, primarily so I can tell which entries go with which logs.<\/p>\n<p><font size=\"2\" face=\"Lucida Console\" color=\"#0000ff\" style=\"color: rgb(0, 0, 255);\">write-host $log -fore Green -back Black<\/font><\/p>\n<p>I then call Get-EventLog to retrieve the newest 10 entries, passing the logfile name as $log:<\/p>\n<p><font size=\"2\" face=\"Lucida Console\" color=\"#0000ff\" style=\"color: rgb(0, 0, 255);\">Get-eventlog&nbsp; $log -newest 10<\/font><\/p>\n<p>Each entry has more information than I really need so I use Select-object to filter just the information I&#8217;m after:<\/p>\n<p><font size=\"2\" face=\"Lucida Console\" color=\"#0000ff\" style=\"color: rgb(0, 0, 255);\">Select TimeGenerated,EntryType,Source,EventID,Message<\/font><\/p>\n<p>Finally, I pipe everything through More so I can page through the results. Even though this is a single command, it is a lot to type each time, so you should put it in a function, in your profile or in a standalone script.<\/p>\n<p>&nbsp;<\/p>\n<div class=\"wlWriterSmartContent\" id=\"0767317B-992E-4b12-91E0-4F059A8CECA8:4aff19ff-aaa6-4195-8b4e-1305be8ad587\" style=\"margin: 0px; padding: 0px; display: inline;\">Technorati tags: <a href=\"http:\/\/technorati.com\/tags\/PowerShell\" rel=\"tag\">PowerShell<\/a>, <a href=\"http:\/\/technorati.com\/tags\/Scripting\" rel=\"tag\">Scripting<\/a>, <a href=\"http:\/\/technorati.com\/tags\/EventLogs\" rel=\"tag\">EventLogs<\/p>\n<p><\/a><\/div>\n<div class=\"wlWriterSmartContent\" id=\"0767317B-992E-4b12-91E0-4F059A8CECA8:049f9474-2199-4fc0-be42-927f24234609\" style=\"margin: 0px; padding: 0px; display: inline;\">del.icio.us tags: <a href=\"http:\/\/del.icio.us\/popular\/PowerShell\" rel=\"tag\">PowerShell<\/a>, <a href=\"http:\/\/del.icio.us\/popular\/Scripting\" rel=\"tag\">Scripting<\/a>, <a href=\"http:\/\/del.icio.us\/popular\/EventLogs\" rel=\"tag\">EventLogs<\/a><\/div>\n","protected":false},"excerpt":{"rendered":"<p>These days I&#8217;m in to fast and furious coding. It seems I no longer have time to develop full, robust scripts with beautiful output and error handling.  I just need information.  Fortunately PowerShell is great at giving you lots of information. As long as you know how to ask for it. One daily task I have is checking my event log for the latest events. Here is a fast and furious single line expression that will display the last 10 entries in all the event logs on my system<\/p>\n","protected":false},"author":3,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"footnotes":""},"categories":[25],"tags":[],"class_list":["post-74","post","type-post","status-publish","format-standard","hentry","category-windows-powershell"],"jetpack_featured_media_url":"","_links":{"self":[{"href":"https:\/\/dev.sapien.com\/blog\/wp-json\/wp\/v2\/posts\/74","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/dev.sapien.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/dev.sapien.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/dev.sapien.com\/blog\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/dev.sapien.com\/blog\/wp-json\/wp\/v2\/comments?post=74"}],"version-history":[{"count":0,"href":"https:\/\/dev.sapien.com\/blog\/wp-json\/wp\/v2\/posts\/74\/revisions"}],"wp:attachment":[{"href":"https:\/\/dev.sapien.com\/blog\/wp-json\/wp\/v2\/media?parent=74"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/dev.sapien.com\/blog\/wp-json\/wp\/v2\/categories?post=74"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/dev.sapien.com\/blog\/wp-json\/wp\/v2\/tags?post=74"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}