The essentials

Quick reference

One focused task per row. Jump to the related section for complete, working examples.

UseSyntaxExamples
Inspect object membersGet-Process | Get-MemberView examples
Inspect one objectGet-Process | Select-Object -First 1 | Format-List *View examples
Filter by one propertyGet-Process | Where-Object CPU -gt 10View examples
Filter with a script blockGet-Service | Where-Object { $_.Status -eq 'Running' -and $_.CanStop }View examples
Select propertiesGet-Process | Select-Object Name, IdView examples
Take the first objectsGet-Process | Select-Object -First 5View examples
Expand one propertyGet-Process | Select-Object -ExpandProperty NameView examples
Calculate a propertyGet-Process | Select-Object Name, @{Name='MemoryMB'; Expression={[math]::Round($_.WorkingSet64 / 1MB, 1)}}View examples
Sort descendingGet-Process | Sort-Object WorkingSet64 -DescendingView examples
Transform each objectGet-Process | ForEach-Object { $_.Name.ToUpperInvariant() }View examples
Group by a propertyGet-Service | Group-Object StatusView examples
Measure numeric valuesGet-ChildItem -File | Measure-Object Length -Sum -AverageView examples
Save and continueGet-Process | Tee-Object -Variable processes | Sort-Object CPU -DescendingView examples
Export objects to CSVGet-Process | Select-Object Name, Id, CPU | Export-Csv processes.csv -NoTypeInformationView examples
Import CSV objectsImport-Csv processes.csvView examples
Format a final tableGet-Process | Sort-Object CPU -Descending | Format-Table Name, Id, CPU -AutoSizeView examples
Run an action per objectGet-ChildItem *.log | ForEach-Object { Compress-Archive -LiteralPath $_.FullName -DestinationPath ($_.FullName + '.zip') }View examples

PowerShell pipelines pass structured objects between commands rather than passing only display text. Inspect those objects, filter early, select the properties you need, and reserve formatting commands for the end of interactive output.

Step by step

Detailed examples

01

Inspect what the pipeline contains

Get-Member reveals the .NET type and available properties and methods. Select one representative object and format every property when you need to see actual values. This inspection step prevents guesswork when building filters and calculated properties.

Discover process object capabilities
Get-Process | Get-Member
Inspect one process in detail
Get-Process |
  Select-Object -First 1 |
  Format-List *

Note: Format-List is appropriate here because display is the final goal; do not place it before commands that need the original process objects.

Back to quick reference ↑
02

Filter objects by their properties

Where-Object keeps inputs for which a condition is true. The comparison-statement form is concise for one property, while a script block supports multiple tests and uses $_ for the current object. Filter as early as practical to reduce later work.

Find processes with recorded CPU time
Get-Process |
  Where-Object CPU -gt 10 |
  Select-Object Name, Id, CPU
Find running services that can stop
Get-Service |
  Where-Object {
    $_.Status -eq 'Running' -and $_.CanStop
  } |
  Select-Object Name, DisplayName, Status
Back to quick reference ↑
03

Shape objects for the next command

Select-Object can choose properties, limit the number of objects, expand a single property's value, or create calculated properties. Unlike formatting commands, selection produces objects that later commands can still sort, filter, measure, or export.

Select and calculate process properties
Get-Process |
  Select-Object -First 10 Name, Id, @{
    Name = 'MemoryMB'
    Expression = { [math]::Round($_.WorkingSet64 / 1MB, 1) }
  }
Extract service names as strings
$names = Get-Service |
  Where-Object Status -eq 'Running' |
  Select-Object -ExpandProperty Name

$names.GetType().FullName

Note: Use -ExpandProperty when the next command needs raw property values rather than custom objects containing that property.

Back to quick reference ↑
04

Sort objects and transform values

Sort-Object orders whole objects using one or more properties. ForEach-Object runs a script block for every input and emits any resulting values. When the block performs changes, test the input pipeline first and use commands that support -WhatIf where available.

Show the largest processes
Get-Process |
  Sort-Object WorkingSet64 -Descending |
  Select-Object -First 10 Name, Id, WorkingSet64
Normalize names into strings
Get-Process |
  Select-Object -ExpandProperty Name |
  ForEach-Object { $_.ToUpperInvariant() } |
  Sort-Object -Unique
Archive each selected log
Get-ChildItem -File -Filter '*.log' |
  ForEach-Object {
    $destination = $_.FullName + '.zip'
    Compress-Archive -LiteralPath $_.FullName -DestinationPath $destination
  }

Note: This example writes archives. Inspect the Get-ChildItem results before running it and decide how existing destination files should be handled.

Back to quick reference ↑
05

Group and measure pipeline data

Group-Object returns one group object per distinct property value, including its count and members. Measure-Object calculates counts and optional numeric statistics without retaining every input for display.

Count services by status
Get-Service |
  Group-Object Status |
  Sort-Object Count -Descending |
  Select-Object Name, Count
Measure files in a directory
$summary = Get-ChildItem -File |
  Measure-Object Length -Sum -Average

$summary | Select-Object Count, Sum, Average
Back to quick reference ↑
06

Capture output without ending the pipeline

Tee-Object stores the objects it receives in a variable or file and also sends them to the next command. A variable preserves the live objects for later inspection, while writing to a file produces formatted text unless another serialization command is used.

Keep a process snapshot and show its largest members
Get-Process |
  Tee-Object -Variable processes |
  Sort-Object WorkingSet64 -Descending |
  Select-Object -First 5 Name, WorkingSet64

$processes | Measure-Object

Note: The variable contains the same kind of process objects that entered Tee-Object, not the final selected display rows.

Back to quick reference ↑
07

Export reusable object data

Export-Csv serializes object properties into CSV columns. Select stable properties first, use -NoTypeInformation for a clean header, and remember that Import-Csv reconstructs property values as strings rather than restoring the original .NET object type.

Export a process report
Get-Process |
  Select-Object Name, Id, CPU, WorkingSet64 |
  Export-Csv -Path './processes.csv' -NoTypeInformation -Encoding utf8
Import and filter the report
Import-Csv './processes.csv' |
  Where-Object { [double]$_.CPU -gt 10 } |
  Sort-Object { [double]$_.CPU } -Descending

Note: CSV fields are strings after import, so cast numeric values before numeric comparisons or sorting.

Back to quick reference ↑
08

Format only at the display boundary

Format-Table and Format-List produce formatting instructions for the display system, not ordinary domain objects. Put them at the end of an interactive pipeline. Use Select-Object instead when data will continue to another command, be exported, or be returned from a function.

Render a final process table
Get-Process |
  Where-Object CPU -gt 10 |
  Sort-Object CPU -Descending |
  Format-Table Name, Id, CPU -AutoSize
Keep data reusable before exporting
Get-Process |
  Select-Object Name, Id, CPU |
  Export-Csv './processes.csv' -NoTypeInformation

Note: Do not insert Format-Table before Export-Csv; the CSV would describe formatting records instead of process properties.

Back to quick reference ↑

Sources and further reading

References

Authoritative documentation used to verify and expand this cheat sheet.

  1. Microsoft LearnWork with the Windows PowerShell pipelinelearn.microsoft.com
  2. Microsoft LearnRemoving Objects from the Pipeline with Where-Objectlearn.microsoft.com
  3. Microsoft LearnExport-Csvlearn.microsoft.com
  4. Microsoft LearnMeasure-Objectlearn.microsoft.com
  5. Microsoft LearnGroup-Objectlearn.microsoft.com

Help us improve

Found a typo or missing example?

Tell us what would make this cheat sheet clearer, more complete, or more useful.

Share feedback