{"id":90,"date":"2007-03-14T14:53:56","date_gmt":"2007-03-14T22:53:56","guid":{"rendered":"http:\/\/testblog.sapien.com\/index.php\/2007\/03\/14\/improved-remote-wmi-event-log-queries\/"},"modified":"2007-03-14T14:53:56","modified_gmt":"2007-03-14T22:53:56","slug":"improved-remote-wmi-event-log-queries","status":"publish","type":"post","link":"https:\/\/dev.sapien.com\/blog\/2007\/03\/14\/improved-remote-wmi-event-log-queries\/","title":{"rendered":"Improved Remote WMI Event Log Queries"},"content":{"rendered":"<p>I responded to a comment about <a href=\"\/current\/2007\/2\/15\/more-fast-furious-remote-event-logs.html\">querying remote event logs<\/a> using WMI.&nbsp; The issue is performance, especially when filtering.&nbsp; The commenter was using code like this:<\/p>\n<p><font style=\"color: #0000ff\" face=\"Lucida Console\" color=\"#0000ff\" size=\"1\">$d=get-date<br \/>$BeginDate=[System.Management.ManagementDateTimeConverter]::ToDMTFDateTime($d.AddDays(-7)) <br \/>$B = get-wmiobject &ndash;class win32_ntlogevent &ndash;computerName $FQDNservername -credential $Credentials | Where-object { $_.logfile -eq &#8220;system&#8221; -and ($_.eventcode &ndash;eq &ldquo;20048&#8221; -and $_.TimeWritten -ge $BeginDate) } | select-object Logfile,EventCode,TimeGenerated,TimeWritten,Message<\/font><\/p>\n<p>I tried it out while running a network trace and it took a long time to complete.&nbsp; Lots of WMI information coming across the wire. Then I realized it is slow because the the Get-WMIObject cmdlet has to complete first, then it has to send the results to the Where-Object cmdlet.&nbsp; The better approach is to use a WMI query so the results are filtered in place.&nbsp; Here&#8217;s my revised code, that also includes a technique to indicate how long the process took:<\/p>\n<p><font style=\"color: #0000ff\" face=\"Lucida Console\" color=\"#0000ff\" size=\"1\">$start=Get-Date<br \/>$d=Get-Date<br \/>$computer=&#8221;dc01&#8221;<br \/>$BeginDate=[System.Management.ManagementDateTimeConverter]::ToDMTFDateTime($d.AddDays(-7)) <br \/><\/font><font style=\"color: #0000ff\" face=\"Lucida Console\" color=\"#0000ff\" size=\"1\">$B = get-wmiobject -query &#8220;Select Logfile,Eventcode,TimeGenerated,TimeWritten,Message from win32_ntlogevent where logfile=&#8217;System&#8217; AND eventcode=&#8217;7036&#8217; AND TimeWritten &gt;=&#8217;$BeginDate&#8217;&#8221; -computername $computer<br \/>$end=Get-Date <br \/><\/font><font style=\"color: #0000ff\" face=\"Lucida Console\" color=\"#0000ff\" size=\"1\">$Runtime=$end-$start<br \/>$B | Select TimeGenerated,TimeWritten,EventCode,Message |format-table <br \/><\/font><font style=\"color: #0000ff\" face=\"Lucida Console\" color=\"#0000ff\" size=\"1\">write-host $b.count &#8220;records&#8221; <br \/><\/font><font size=\"1\"><font style=\"color: #0000ff\" face=\"Lucida Console\" color=\"#0000ff\">write-host &#8220;Runtime: &#8221; $runtime.hours &#8220;hrs&#8221; $runtime.minutes &#8220;min&#8221; $runtime.seconds &#8220;sec&#8221; $runtime.milliseconds &#8220;ms&#8221; <\/font><\/font><\/p>\n<p>Now the query completes in a fraction of the time. <\/p>\n<div class=\"wlWriterSmartContent\" id=\"0767317B-992E-4b12-91E0-4F059A8CECA8:d07b38c5-6859-495b-8af8-4226fd723cd4\" style=\"padding-right: 0px; display: inline; padding-left: 0px; padding-bottom: 0px; margin: 0px; padding-top: 0px\"><span class=\"sizeLess20\">Technorati tags: <\/span><a href=\"http:\/\/technorati.com\/tags\/PowerShell\" rel=\"tag\"><span class=\"sizeLess20\">PowerShell<\/span><\/a><span class=\"sizeLess20\">, <\/span><a href=\"http:\/\/technorati.com\/tags\/WMI\" rel=\"tag\"><span class=\"sizeLess20\">WMI<\/span><\/a><span class=\"sizeLess20\">, <\/span><a href=\"http:\/\/technorati.com\/tags\/EventLogs\" rel=\"tag\"><span class=\"sizeLess20\">EventLogs<\/span><\/a><span class=\"sizeLess20\">, <\/span><a href=\"http:\/\/technorati.com\/tags\/Get-WMIObject\" rel=\"tag\"><span class=\"sizeLess20\">Get-WMIObject<\/span><\/a><\/div>\n<div class=\"wlWriterSmartContent\" id=\"0767317B-992E-4b12-91E0-4F059A8CECA8:27d7a134-2e5e-486b-848f-6ef77337e3ac\" style=\"padding-right: 0px; display: inline; padding-left: 0px; padding-bottom: 0px; margin: 0px; padding-top: 0px\"><span class=\"sizeLess20\">del.icio.us tags: <\/span><a href=\"http:\/\/del.icio.us\/popular\/PowerShell\" rel=\"tag\"><span class=\"sizeLess20\">PowerShell<\/span><\/a><span class=\"sizeLess20\">, <\/span><a href=\"http:\/\/del.icio.us\/popular\/WMI\" rel=\"tag\"><span class=\"sizeLess20\">WMI<\/span><\/a><span class=\"sizeLess20\">, <\/span><a href=\"http:\/\/del.icio.us\/popular\/EventLogs\" rel=\"tag\"><span class=\"sizeLess20\">EventLogs<\/span><\/a><span class=\"sizeLess20\">, <\/span><a href=\"http:\/\/del.icio.us\/popular\/Get-WMIObject\" rel=\"tag\"><span class=\"sizeLess20\">Get-WMIObject<\/span><\/a><\/div>\n","protected":false},"excerpt":{"rendered":"<p>I responded to a comment about querying remote event logs using WMI.&nbsp; The issue is performance, especially when filtering.&nbsp; The commenter was using code like this: $d=get-date$BeginDate=[System.Management.ManagementDateTimeConverter]::ToDMTFDateTime($d.AddDays(-7)) $B = get-wmiobject &ndash;class win32_ntlogevent &ndash;computerName $FQDNservername -credential $Credentials | Where-object { $_.logfile -eq &#8220;system&#8221; -and ($_.eventcode &ndash;eq &ldquo;20048&#8221; -and $_.TimeWritten -ge $BeginDate) } | select-object Logfile,EventCode,TimeGenerated,TimeWritten,Message I [&hellip;]<\/p>\n","protected":false},"author":3,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"footnotes":""},"categories":[25],"tags":[],"class_list":["post-90","post","type-post","status-publish","format-standard","hentry","category-windows-powershell"],"jetpack_featured_media_url":"","_links":{"self":[{"href":"https:\/\/dev.sapien.com\/blog\/wp-json\/wp\/v2\/posts\/90","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/dev.sapien.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/dev.sapien.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/dev.sapien.com\/blog\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/dev.sapien.com\/blog\/wp-json\/wp\/v2\/comments?post=90"}],"version-history":[{"count":0,"href":"https:\/\/dev.sapien.com\/blog\/wp-json\/wp\/v2\/posts\/90\/revisions"}],"wp:attachment":[{"href":"https:\/\/dev.sapien.com\/blog\/wp-json\/wp\/v2\/media?parent=90"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/dev.sapien.com\/blog\/wp-json\/wp\/v2\/categories?post=90"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/dev.sapien.com\/blog\/wp-json\/wp\/v2\/tags?post=90"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}