{"id":6844,"date":"2021-08-23T20:40:21","date_gmt":"2021-08-24T00:40:21","guid":{"rendered":"https:\/\/kevinjustin.com\/blog\/?p=6844"},"modified":"2021-08-23T20:55:53","modified_gmt":"2021-08-24T00:55:53","slug":"mining-windows-event-log","status":"publish","type":"post","link":"https:\/\/kevinjustin.com\/blog\/2021\/08\/23\/mining-windows-event-log\/","title":{"rendered":"Mining Windows Event Log"},"content":{"rendered":"<figure id=\"attachment_6845\" aria-describedby=\"caption-attachment-6845\" style=\"width: 445px\" class=\"wp-caption alignnone\"><a href=\"https:\/\/kevinjustin.com\/blog\/wp-content\/uploads\/2021\/08\/MineOretoMineCart.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-6845\" src=\"https:\/\/kevinjustin.com\/blog\/wp-content\/uploads\/2021\/08\/MineOretoMineCart.jpg\" alt=\"\" width=\"445\" height=\"315\" srcset=\"https:\/\/kevinjustin.com\/blog\/wp-content\/uploads\/2021\/08\/MineOretoMineCart.jpg 445w, https:\/\/kevinjustin.com\/blog\/wp-content\/uploads\/2021\/08\/MineOretoMineCart-300x212.jpg 300w\" sizes=\"auto, (max-width: 445px) 85vw, 445px\" \/><\/a><figcaption id=\"caption-attachment-6845\" class=\"wp-caption-text\">Mining Ore from the Windows Event Log and finding a way to make it portable<\/figcaption><\/figure>\n<p>&nbsp;<\/p>\n<p>Use Get-WinEvent to use XML and filters from event viewer, to mine an event, including examples for a specific string, from a specific event, in a specific event log?<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>Hopefully this post will help with a few tips to simplify monitoring for events, whether in AzMon, SCOM, or via PowerShell.<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>Let&#8217;s start with the\u00a0Dr Scripto blog post from quite a while ago &#8211;<\/p>\n<p><a href=\"https:\/\/devblogs.microsoft.com\/scripting\/data-mine-the-windows-event-log-by-using-powershell-and-xml\/\" target=\"_blank\" rel=\"noopener\">https:\/\/devblogs.microsoft.com\/scripting\/data-mine-the-windows-event-log-by-using-powershell-and-xml\/<\/a><\/p>\n<p>&nbsp;<\/p>\n<p>Not sure how many people use get-WinEvent, but this is one tool in PowerShell that can help an admin parse the XML side of an event.<\/p>\n<p>&nbsp;<\/p>\n<h5>Example 1<\/h5>\n<p>Query Application Event Log for Severity, Event, and Event Data contains lync.exe<\/p>\n<p>$query = @&#8221;<\/p>\n<p>&lt;QueryList&gt;<\/p>\n<p><span style=\"color: #0000ff;\">\u00a0 &lt;Query Id=&#8221;0&#8243; Path=&#8221;Application&#8221;&gt;<\/span><\/p>\n<p><span style=\"color: #0000ff;\">\u00a0\u00a0\u00a0 &lt;Select Path=&#8221;Application&#8221;&gt;*[System[Provider[@Name=&#8217;Application Hang&#8217;]<\/span><\/p>\n<p><span style=\"color: #0000ff;\">\u00a0\u00a0\u00a0 and (Level=2) and (EventID=1002)]]<\/span><\/p>\n<p><span style=\"color: #0000ff;\">\u00a0\u00a0\u00a0 and *[EventData[Data=&#8217;lync.exe&#8217;]]&lt;\/Select&gt;<\/span><\/p>\n<p><span style=\"color: #0000ff;\">\u00a0 &lt;\/Query&gt;<\/span><\/p>\n<p><span style=\"color: #0000ff;\">&lt;\/QueryList&gt;<\/span><\/p>\n<p><span style=\"color: #0000ff;\">&#8220;@<\/span><\/p>\n<p><span style=\"color: #0000ff;\">Get-WinEvent -FilterXml $query<\/span><\/p>\n<p>&nbsp;<\/p>\n<p><strong>PowerShell output<\/strong><\/p>\n<figure id=\"attachment_6850\" aria-describedby=\"caption-attachment-6850\" style=\"width: 1132px\" class=\"wp-caption alignnone\"><a href=\"https:\/\/kevinjustin.com\/blog\/wp-content\/uploads\/2021\/08\/get-wineventExample-1.png\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-6850 size-full\" src=\"https:\/\/kevinjustin.com\/blog\/wp-content\/uploads\/2021\/08\/get-wineventExample-1.png\" alt=\"Use Get-WinEvent to use XML and filters from event viewer\" width=\"1132\" height=\"478\" srcset=\"https:\/\/kevinjustin.com\/blog\/wp-content\/uploads\/2021\/08\/get-wineventExample-1.png 1132w, https:\/\/kevinjustin.com\/blog\/wp-content\/uploads\/2021\/08\/get-wineventExample-1-300x127.png 300w, https:\/\/kevinjustin.com\/blog\/wp-content\/uploads\/2021\/08\/get-wineventExample-1-1024x432.png 1024w, https:\/\/kevinjustin.com\/blog\/wp-content\/uploads\/2021\/08\/get-wineventExample-1-768x324.png 768w\" sizes=\"auto, (max-width: 709px) 85vw, (max-width: 909px) 67vw, (max-width: 1362px) 62vw, 840px\" \/><\/a><figcaption id=\"caption-attachment-6850\" class=\"wp-caption-text\">Lync.exe event example output<\/figcaption><\/figure>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<h3>Use Get-WinEvent to use XML and filters from event viewer<\/h3>\n<p>The Tip or Trick part of this &#8211; leverage your Event Viewer Filter as a query to use with <span style=\"color: #0000ff;\">get-WinEvent<\/span><\/p>\n<p>Credit for this tip comes from Andrew Blumhardt!<\/p>\n<h5><\/h5>\n<p>See below for examples to &#8216;use Get-WinEvent to use XML and filters from event viewer&#8217;<\/p>\n<p>&nbsp;<\/p>\n<h4><strong>Navigating via Event Viewer:<\/strong><\/h4>\n<p>Hop onto your favorite server, or connect to another server via Event Viewer<\/p>\n<p>Go to the Event Log &gt; Click Filter Current Log<\/p>\n<p>Build out your filter (i.e. choose specific Event Sources, exclude events, include severities, timeframe (start\/end), etc.)<\/p>\n<figure id=\"attachment_6846\" aria-describedby=\"caption-attachment-6846\" style=\"width: 814px\" class=\"wp-caption alignnone\"><a href=\"https:\/\/kevinjustin.com\/blog\/wp-content\/uploads\/2021\/08\/SCVMMEvent25933.png\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-6846 size-full\" src=\"https:\/\/kevinjustin.com\/blog\/wp-content\/uploads\/2021\/08\/SCVMMEvent25933.png\" alt=\"Use Get-WinEvent to use XML and filters from event viewer\" width=\"814\" height=\"831\" srcset=\"https:\/\/kevinjustin.com\/blog\/wp-content\/uploads\/2021\/08\/SCVMMEvent25933.png 814w, https:\/\/kevinjustin.com\/blog\/wp-content\/uploads\/2021\/08\/SCVMMEvent25933-294x300.png 294w, https:\/\/kevinjustin.com\/blog\/wp-content\/uploads\/2021\/08\/SCVMMEvent25933-768x784.png 768w\" sizes=\"auto, (max-width: 709px) 85vw, (max-width: 909px) 67vw, (max-width: 984px) 61vw, (max-width: 1362px) 45vw, 600px\" \/><\/a><figcaption id=\"caption-attachment-6846\" class=\"wp-caption-text\">SCVMM Application Log Event ID 25933<\/figcaption><\/figure>\n<p>Switch to the XML tab (and note you can edit your query further!)<\/p>\n<figure id=\"attachment_6847\" aria-describedby=\"caption-attachment-6847\" style=\"width: 811px\" class=\"wp-caption alignnone\"><a href=\"https:\/\/kevinjustin.com\/blog\/wp-content\/uploads\/2021\/08\/SCVMMEvent25933-XMLQuery.png\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-6847 size-full\" src=\"https:\/\/kevinjustin.com\/blog\/wp-content\/uploads\/2021\/08\/SCVMMEvent25933-XMLQuery.png\" alt=\"SCVMM query example screenshot\" width=\"811\" height=\"829\" srcset=\"https:\/\/kevinjustin.com\/blog\/wp-content\/uploads\/2021\/08\/SCVMMEvent25933-XMLQuery.png 811w, https:\/\/kevinjustin.com\/blog\/wp-content\/uploads\/2021\/08\/SCVMMEvent25933-XMLQuery-293x300.png 293w, https:\/\/kevinjustin.com\/blog\/wp-content\/uploads\/2021\/08\/SCVMMEvent25933-XMLQuery-768x785.png 768w\" sizes=\"auto, (max-width: 709px) 85vw, (max-width: 909px) 67vw, (max-width: 984px) 61vw, (max-width: 1362px) 45vw, 600px\" \/><\/a><figcaption id=\"caption-attachment-6847\" class=\"wp-caption-text\">Event Viewer filter XML tab<\/figcaption><\/figure>\n<p>You can copy the query from the Event Viewer into your <span style=\"color: #0000ff;\">Get-WinEvent<\/span> syntax<\/p>\n<p><span style=\"color: #0000ff;\">$query = @&#8221;<\/span><\/p>\n<p><span style=\"color: #0000ff;\">&lt;QueryList&gt;<\/span><br \/>\n<span style=\"color: #0000ff;\">&lt;Query Id=&#8221;0&#8243; Path=&#8221;Application&#8221;&gt;<\/span><br \/>\n<span style=\"color: #0000ff;\">&lt;Select Path=&#8221;Application&#8221;&gt;*[System[Provider[@Name=&#8217;Microsoft.SystemCenter.VirtualMachineManager.2012.Monitor.UserRoleQuotaUsageMonitor&#8217; or @Name=&#8217;Microsoft.SystemCenter.VirtualMachineManager.2012.Report.ServiceUsageCollection&#8217; or @Name=&#8217;Microsoft.SystemCenter.VirtualMachineManager.2012.Report.VMUsageCollection&#8217; or @Name=&#8217;Microsoft.SystemCenter.VirtualMachineManager.2016.EnableCredSSPClient&#8217; or @Name=&#8217;Microsoft.SystemCenter.VirtualMachineManager.2016.Monitor.UserRoleQuotaUsageMonitor&#8217; or @Name=&#8217;Microsoft.SystemCenter.VirtualMachineManager.2016.Report.ServiceUsageCollection&#8217; or @Name=&#8217;Microsoft.SystemCenter.VirtualMachineManager.2016.Report.VMUsageCollection&#8217;] and (Level=2 or Level=3) and (EventID=25933)]]&lt;\/Select&gt;<\/span><br \/>\n<span style=\"color: #0000ff;\">&lt;\/Query&gt;<\/span><br \/>\n<span style=\"color: #0000ff;\">&lt;\/QueryList&gt;<\/span><\/p>\n<p><span style=\"color: #0000ff;\">&#8220;@<\/span><\/p>\n<p><span style=\"color: #0000ff;\">Get-WinEvent -FilterXml $query<\/span><\/p>\n<p>&nbsp;<\/p>\n<p><strong>PowerShell output<\/strong><\/p>\n<figure id=\"attachment_6848\" aria-describedby=\"caption-attachment-6848\" style=\"width: 1321px\" class=\"wp-caption alignnone\"><a href=\"https:\/\/kevinjustin.com\/blog\/wp-content\/uploads\/2021\/08\/get-winevent-scvmm-Example.png\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-6848 size-full\" src=\"https:\/\/kevinjustin.com\/blog\/wp-content\/uploads\/2021\/08\/get-winevent-scvmm-Example.png\" alt=\"Use Get-WinEvent to use XML and filters from event viewer\" width=\"1321\" height=\"592\" srcset=\"https:\/\/kevinjustin.com\/blog\/wp-content\/uploads\/2021\/08\/get-winevent-scvmm-Example.png 1321w, https:\/\/kevinjustin.com\/blog\/wp-content\/uploads\/2021\/08\/get-winevent-scvmm-Example-300x134.png 300w, https:\/\/kevinjustin.com\/blog\/wp-content\/uploads\/2021\/08\/get-winevent-scvmm-Example-1024x459.png 1024w, https:\/\/kevinjustin.com\/blog\/wp-content\/uploads\/2021\/08\/get-winevent-scvmm-Example-768x344.png 768w\" sizes=\"auto, (max-width: 709px) 85vw, (max-width: 909px) 67vw, (max-width: 1362px) 62vw, 840px\" \/><\/a><figcaption id=\"caption-attachment-6848\" class=\"wp-caption-text\">SCVMM query example screenshot<\/figcaption><\/figure>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<h5><\/h5>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<h5>Example 3<\/h5>\n<p>Grab System Event Log, Event ID 5827\u00a0 (NetLogon denied events)<\/p>\n<p><span style=\"color: #0000ff;\">get-WinEvent -FilterHashtable @{LogName=&#8217;System&#8217;;\u00a0ID=&#8217;5827&#8242;;}<\/span><\/p>\n<p>&nbsp;<\/p>\n<p><strong>PowerShell output<\/strong><\/p>\n<figure id=\"attachment_6851\" aria-describedby=\"caption-attachment-6851\" style=\"width: 1131px\" class=\"wp-caption alignnone\"><a href=\"https:\/\/kevinjustin.com\/blog\/wp-content\/uploads\/2021\/08\/EventID5827Output.png\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-6851 size-full\" src=\"https:\/\/kevinjustin.com\/blog\/wp-content\/uploads\/2021\/08\/EventID5827Output.png\" alt=\"Use Get-WinEvent to use XML and filters from event viewer\" width=\"1131\" height=\"154\" srcset=\"https:\/\/kevinjustin.com\/blog\/wp-content\/uploads\/2021\/08\/EventID5827Output.png 1131w, https:\/\/kevinjustin.com\/blog\/wp-content\/uploads\/2021\/08\/EventID5827Output-300x41.png 300w, https:\/\/kevinjustin.com\/blog\/wp-content\/uploads\/2021\/08\/EventID5827Output-1024x139.png 1024w, https:\/\/kevinjustin.com\/blog\/wp-content\/uploads\/2021\/08\/EventID5827Output-768x105.png 768w\" sizes=\"auto, (max-width: 709px) 85vw, (max-width: 909px) 67vw, (max-width: 1362px) 62vw, 840px\" \/><\/a><figcaption id=\"caption-attachment-6851\" class=\"wp-caption-text\">get-WinEvent filter by logname and event ID<\/figcaption><\/figure>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p><strong>Documentation:<\/strong><\/p>\n<p>Get-WinEvent <a href=\"https:\/\/docs.microsoft.com\/en-us\/powershell\/module\/microsoft.powershell.diagnostics\/get-winevent?view=powershell-7.1\" target=\"_blank\" rel=\"noopener\">https:\/\/docs.microsoft.com\/en-us\/powershell\/module\/microsoft.powershell.diagnostics\/get-winevent?view=powershell-7.1<\/a><\/p>\n<p>MSFT DevBlogs <a href=\"https:\/\/devblogs.microsoft.com\/scripting\/data-mine-the-windows-event-log-by-using-powershell-and-xml\/\" target=\"_blank\" rel=\"noopener\">https:\/\/devblogs.microsoft.com\/scripting\/data-mine-the-windows-event-log-by-using-powershell-and-xml\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>&nbsp; Use Get-WinEvent to use XML and filters from event viewer, to mine an event, including examples for a specific string, from a specific event, in a specific event log? &nbsp; &nbsp; Hopefully this post will help with a few tips to simplify monitoring for events, whether in AzMon, SCOM, or via PowerShell. &nbsp; &nbsp; &hellip; <a href=\"https:\/\/kevinjustin.com\/blog\/2021\/08\/23\/mining-windows-event-log\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;Mining Windows Event Log&#8221;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3,4,6,545,530,11],"tags":[549,56,60,547,147,546,550,211,551,309,310,317,342,495,548],"class_list":["post-6844","post","type-post","status-publish","format-standard","hentry","category-azure","category-azure-monitor","category-log-analytics","category-powershell","category-scom","category-troubleshooting","tag-azmon","tag-azure","tag-azure-monitor","tag-data-mine","tag-event-viewer","tag-get-winevent","tag-hop-onto-your-favorite-server","tag-log-analytics","tag-or-connect-to-another-server-via-event-viewer","tag-posh","tag-powershell","tag-query","tag-scom","tag-xml","tag-xml-query"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.7 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Mining Windows Event Log - Kevin Justin&#039;s Blog<\/title>\n<meta name=\"description\" content=\"Use Get-WinEvent to use XML and filters from event viewer. See examples in the blog for context and usage examples!\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/kevinjustin.com\/blog\/2021\/08\/23\/mining-windows-event-log\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Mining Windows Event Log - Kevin Justin&#039;s Blog\" \/>\n<meta property=\"og:description\" content=\"Use Get-WinEvent to use XML and filters from event viewer. See examples in the blog for context and usage examples!\" \/>\n<meta property=\"og:url\" content=\"https:\/\/kevinjustin.com\/blog\/2021\/08\/23\/mining-windows-event-log\/\" \/>\n<meta property=\"og:site_name\" content=\"Kevin Justin&#039;s Blog\" \/>\n<meta property=\"article:published_time\" content=\"2021-08-24T00:40:21+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2021-08-24T00:55:53+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/kevinjustin.com\/blog\/wp-content\/uploads\/2021\/08\/MineOretoMineCart.jpg\" \/>\n<meta name=\"author\" content=\"WordPress Administrator\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"WordPress Administrator\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/kevinjustin.com\\\/blog\\\/2021\\\/08\\\/23\\\/mining-windows-event-log\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/kevinjustin.com\\\/blog\\\/2021\\\/08\\\/23\\\/mining-windows-event-log\\\/\"},\"author\":{\"name\":\"WordPress Administrator\",\"@id\":\"https:\\\/\\\/kevinjustin.com\\\/blog\\\/#\\\/schema\\\/person\\\/3d7a90f4430bef43134eaa0a7e2cd508\"},\"headline\":\"Mining Windows Event Log\",\"datePublished\":\"2021-08-24T00:40:21+00:00\",\"dateModified\":\"2021-08-24T00:55:53+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/kevinjustin.com\\\/blog\\\/2021\\\/08\\\/23\\\/mining-windows-event-log\\\/\"},\"wordCount\":509,\"commentCount\":0,\"image\":{\"@id\":\"https:\\\/\\\/kevinjustin.com\\\/blog\\\/2021\\\/08\\\/23\\\/mining-windows-event-log\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/kevinjustin.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/08\\\/MineOretoMineCart.jpg\",\"keywords\":[\"AzMon\",\"azure\",\"azure monitor\",\"data mine\",\"event viewer\",\"get-winevent\",\"Hop onto your favorite server\",\"Log Analytics\",\"or connect to another server via Event Viewer\",\"posh\",\"powershell\",\"query\",\"SCOM\",\"xml\",\"XML Query\"],\"articleSection\":[\"Azure\",\"Azure Monitor\",\"Log Analytics\",\"PowerShell\",\"SCOM\",\"Troubleshooting\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/kevinjustin.com\\\/blog\\\/2021\\\/08\\\/23\\\/mining-windows-event-log\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/kevinjustin.com\\\/blog\\\/2021\\\/08\\\/23\\\/mining-windows-event-log\\\/\",\"url\":\"https:\\\/\\\/kevinjustin.com\\\/blog\\\/2021\\\/08\\\/23\\\/mining-windows-event-log\\\/\",\"name\":\"Mining Windows Event Log - Kevin Justin&#039;s Blog\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/kevinjustin.com\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/kevinjustin.com\\\/blog\\\/2021\\\/08\\\/23\\\/mining-windows-event-log\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/kevinjustin.com\\\/blog\\\/2021\\\/08\\\/23\\\/mining-windows-event-log\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/kevinjustin.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/08\\\/MineOretoMineCart.jpg\",\"datePublished\":\"2021-08-24T00:40:21+00:00\",\"dateModified\":\"2021-08-24T00:55:53+00:00\",\"author\":{\"@id\":\"https:\\\/\\\/kevinjustin.com\\\/blog\\\/#\\\/schema\\\/person\\\/3d7a90f4430bef43134eaa0a7e2cd508\"},\"description\":\"Use Get-WinEvent to use XML and filters from event viewer. See examples in the blog for context and usage examples!\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/kevinjustin.com\\\/blog\\\/2021\\\/08\\\/23\\\/mining-windows-event-log\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/kevinjustin.com\\\/blog\\\/2021\\\/08\\\/23\\\/mining-windows-event-log\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/kevinjustin.com\\\/blog\\\/2021\\\/08\\\/23\\\/mining-windows-event-log\\\/#primaryimage\",\"url\":\"https:\\\/\\\/kevinjustin.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/08\\\/MineOretoMineCart.jpg\",\"contentUrl\":\"https:\\\/\\\/kevinjustin.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/08\\\/MineOretoMineCart.jpg\",\"width\":445,\"height\":315,\"caption\":\"Mining Ore from the Windows Event Log and finding a way to make it portable\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/kevinjustin.com\\\/blog\\\/2021\\\/08\\\/23\\\/mining-windows-event-log\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/kevinjustin.com\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Mining Windows Event Log\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/kevinjustin.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/kevinjustin.com\\\/blog\\\/\",\"name\":\"Kevin Justin&#039;s Blog\",\"description\":\"Operational monitoring tools including System Center, Azure Monitor\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/kevinjustin.com\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/kevinjustin.com\\\/blog\\\/#\\\/schema\\\/person\\\/3d7a90f4430bef43134eaa0a7e2cd508\",\"name\":\"WordPress Administrator\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/fca865cc5df90a25ae9533b1d9dea567a78c7469dc3202a376c8d117a0eaea11?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/fca865cc5df90a25ae9533b1d9dea567a78c7469dc3202a376c8d117a0eaea11?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/fca865cc5df90a25ae9533b1d9dea567a78c7469dc3202a376c8d117a0eaea11?s=96&d=mm&r=g\",\"caption\":\"WordPress Administrator\"},\"sameAs\":[\"https:\\\/\\\/kevinjustin.com\"],\"url\":\"https:\\\/\\\/kevinjustin.com\\\/blog\\\/author\\\/wordpress_admin\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Mining Windows Event Log - Kevin Justin&#039;s Blog","description":"Use Get-WinEvent to use XML and filters from event viewer. See examples in the blog for context and usage examples!","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/kevinjustin.com\/blog\/2021\/08\/23\/mining-windows-event-log\/","og_locale":"en_US","og_type":"article","og_title":"Mining Windows Event Log - Kevin Justin&#039;s Blog","og_description":"Use Get-WinEvent to use XML and filters from event viewer. See examples in the blog for context and usage examples!","og_url":"https:\/\/kevinjustin.com\/blog\/2021\/08\/23\/mining-windows-event-log\/","og_site_name":"Kevin Justin&#039;s Blog","article_published_time":"2021-08-24T00:40:21+00:00","article_modified_time":"2021-08-24T00:55:53+00:00","og_image":[{"url":"https:\/\/kevinjustin.com\/blog\/wp-content\/uploads\/2021\/08\/MineOretoMineCart.jpg","type":"","width":"","height":""}],"author":"WordPress Administrator","twitter_card":"summary_large_image","twitter_misc":{"Written by":"WordPress Administrator","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/kevinjustin.com\/blog\/2021\/08\/23\/mining-windows-event-log\/#article","isPartOf":{"@id":"https:\/\/kevinjustin.com\/blog\/2021\/08\/23\/mining-windows-event-log\/"},"author":{"name":"WordPress Administrator","@id":"https:\/\/kevinjustin.com\/blog\/#\/schema\/person\/3d7a90f4430bef43134eaa0a7e2cd508"},"headline":"Mining Windows Event Log","datePublished":"2021-08-24T00:40:21+00:00","dateModified":"2021-08-24T00:55:53+00:00","mainEntityOfPage":{"@id":"https:\/\/kevinjustin.com\/blog\/2021\/08\/23\/mining-windows-event-log\/"},"wordCount":509,"commentCount":0,"image":{"@id":"https:\/\/kevinjustin.com\/blog\/2021\/08\/23\/mining-windows-event-log\/#primaryimage"},"thumbnailUrl":"https:\/\/kevinjustin.com\/blog\/wp-content\/uploads\/2021\/08\/MineOretoMineCart.jpg","keywords":["AzMon","azure","azure monitor","data mine","event viewer","get-winevent","Hop onto your favorite server","Log Analytics","or connect to another server via Event Viewer","posh","powershell","query","SCOM","xml","XML Query"],"articleSection":["Azure","Azure Monitor","Log Analytics","PowerShell","SCOM","Troubleshooting"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/kevinjustin.com\/blog\/2021\/08\/23\/mining-windows-event-log\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/kevinjustin.com\/blog\/2021\/08\/23\/mining-windows-event-log\/","url":"https:\/\/kevinjustin.com\/blog\/2021\/08\/23\/mining-windows-event-log\/","name":"Mining Windows Event Log - Kevin Justin&#039;s Blog","isPartOf":{"@id":"https:\/\/kevinjustin.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/kevinjustin.com\/blog\/2021\/08\/23\/mining-windows-event-log\/#primaryimage"},"image":{"@id":"https:\/\/kevinjustin.com\/blog\/2021\/08\/23\/mining-windows-event-log\/#primaryimage"},"thumbnailUrl":"https:\/\/kevinjustin.com\/blog\/wp-content\/uploads\/2021\/08\/MineOretoMineCart.jpg","datePublished":"2021-08-24T00:40:21+00:00","dateModified":"2021-08-24T00:55:53+00:00","author":{"@id":"https:\/\/kevinjustin.com\/blog\/#\/schema\/person\/3d7a90f4430bef43134eaa0a7e2cd508"},"description":"Use Get-WinEvent to use XML and filters from event viewer. See examples in the blog for context and usage examples!","breadcrumb":{"@id":"https:\/\/kevinjustin.com\/blog\/2021\/08\/23\/mining-windows-event-log\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/kevinjustin.com\/blog\/2021\/08\/23\/mining-windows-event-log\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/kevinjustin.com\/blog\/2021\/08\/23\/mining-windows-event-log\/#primaryimage","url":"https:\/\/kevinjustin.com\/blog\/wp-content\/uploads\/2021\/08\/MineOretoMineCart.jpg","contentUrl":"https:\/\/kevinjustin.com\/blog\/wp-content\/uploads\/2021\/08\/MineOretoMineCart.jpg","width":445,"height":315,"caption":"Mining Ore from the Windows Event Log and finding a way to make it portable"},{"@type":"BreadcrumbList","@id":"https:\/\/kevinjustin.com\/blog\/2021\/08\/23\/mining-windows-event-log\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/kevinjustin.com\/blog\/"},{"@type":"ListItem","position":2,"name":"Mining Windows Event Log"}]},{"@type":"WebSite","@id":"https:\/\/kevinjustin.com\/blog\/#website","url":"https:\/\/kevinjustin.com\/blog\/","name":"Kevin Justin&#039;s Blog","description":"Operational monitoring tools including System Center, Azure Monitor","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/kevinjustin.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/kevinjustin.com\/blog\/#\/schema\/person\/3d7a90f4430bef43134eaa0a7e2cd508","name":"WordPress Administrator","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/fca865cc5df90a25ae9533b1d9dea567a78c7469dc3202a376c8d117a0eaea11?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/fca865cc5df90a25ae9533b1d9dea567a78c7469dc3202a376c8d117a0eaea11?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/fca865cc5df90a25ae9533b1d9dea567a78c7469dc3202a376c8d117a0eaea11?s=96&d=mm&r=g","caption":"WordPress Administrator"},"sameAs":["https:\/\/kevinjustin.com"],"url":"https:\/\/kevinjustin.com\/blog\/author\/wordpress_admin\/"}]}},"_links":{"self":[{"href":"https:\/\/kevinjustin.com\/blog\/wp-json\/wp\/v2\/posts\/6844","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/kevinjustin.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/kevinjustin.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/kevinjustin.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/kevinjustin.com\/blog\/wp-json\/wp\/v2\/comments?post=6844"}],"version-history":[{"count":1,"href":"https:\/\/kevinjustin.com\/blog\/wp-json\/wp\/v2\/posts\/6844\/revisions"}],"predecessor-version":[{"id":6852,"href":"https:\/\/kevinjustin.com\/blog\/wp-json\/wp\/v2\/posts\/6844\/revisions\/6852"}],"wp:attachment":[{"href":"https:\/\/kevinjustin.com\/blog\/wp-json\/wp\/v2\/media?parent=6844"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/kevinjustin.com\/blog\/wp-json\/wp\/v2\/categories?post=6844"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/kevinjustin.com\/blog\/wp-json\/wp\/v2\/tags?post=6844"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}