The essentials

Quick reference

One focused task per row. Jump to the related section for complete, working examples.

UseSyntaxExamples
List event logsGet-WinEvent -ListLog *View examples
Find nonempty enabled logsGet-WinEvent -ListLog * | Where-Object { $_.IsEnabled -and $_.RecordCount }View examples
List event providersGet-WinEvent -ListProvider *View examples
Read recent system eventsGet-WinEvent -LogName System -MaxEvents 20View examples
Read one providerGet-WinEvent -ProviderName ` 'Microsoft-Windows-Kernel-General' -MaxEvents 20View examples
Filter by start timeGet-WinEvent -FilterHashtable @{ LogName='System'; ` StartTime=(Get-Date).AddHours(-1) }View examples
Filter error levelsGet-WinEvent -FilterHashtable @{ LogName='System'; ` Level=1,2,3 }View examples
Filter event identifiersGet-WinEvent -FilterHashtable @{ LogName='System'; ` Id=41,6008 }View examples
Filter a provider in a logGet-WinEvent -FilterHashtable @{ LogName='System'; ` ProviderName='Microsoft-Windows-Kernel-General' }View examples
Suppress information eventsGet-WinEvent -FilterHashtable @{ LogName='Application'; ` SuppressHashFilter=@{ Level=4 } }View examples
Select core event fieldsGet-WinEvent -LogName System -MaxEvents 5 | Select-Object TimeCreated, Id, LevelDisplayName, ProviderNameView examples
Read rendered messages$event.MessageView examples
Inspect event XML[xml]$xml = $event.ToXml()View examples
Read an archived logGet-WinEvent -Path 'C:\Evidence\System.evtx' -MaxEvents ` 50View examples
Query a remote computerGet-WinEvent -ComputerName 'Server01' -LogName System ` -MaxEvents 20View examples
Count by event IDGet-WinEvent -LogName System -MaxEvents 500 | Group-Object Id -NoElement | Sort-Object Count -DescendingView examples
Export selected fields$events | Select-Object TimeCreated, Id, ProviderName, Message | Export-Csv '.\events.csv' -NoTypeInformation -Encoding utf8View examples
Return oldest firstGet-WinEvent -LogName System -Oldest -MaxEvents 20View examples
Preserve record identity$event | Select-Object LogName, RecordId, TimeCreated, Id, ProviderNameView examples

Get-WinEvent returns structured event records and filters them close to the log engine. Narrow by log, provider, identifier, level, and time before formatting; preserve record identifiers and XML when evidence matters, and expect permissions and message resources to affect what a session can retrieve.

Step by step

Detailed examples

01

Discover exact log and provider names

-ListLog returns EventLogConfiguration metadata such as enabled state, record count, size, and path; some record counts are null. -ListProvider returns provider metadata and linked logs. Listing every source can be slow and may report access errors, so narrow wildcard patterns when possible. Get-WinEvent is available only on Windows.

Find active PowerShell logs and providers
Get-WinEvent -ListLog '*PowerShell*' |
    Where-Object IsEnabled |
    Select-Object LogName, RecordCount, LogMode, MaximumSizeInBytes
Get-WinEvent -ListProvider 'Microsoft-Windows-PowerShell*' |
    Select-Object Name, LogLinks
Output
# Results vary by Windows edition, installed components, and permissions.
Back to quick reference ↑
02

Bound exploratory queries

-LogName selects a specific log and returns newest records first by default. -ProviderName can combine records from logs linked to that provider. Always use MaxEvents or a time filter during exploration; unbounded queries against busy logs can allocate large collections and delay the investigation.

Compare recent System and provider records
Get-WinEvent -LogName System -MaxEvents 20 |
    Select-Object TimeCreated, Id, LevelDisplayName, ProviderName
Get-WinEvent -ProviderName 'Microsoft-Windows-Kernel-General' -MaxEvents 10 |
    Select-Object TimeCreated, Id, Message
Output
# Event content is specific to the queried computer.
Back to quick reference ↑
03

Filter inside Get-WinEvent

FilterHashtable sends criteria to the event-log query engine and is generally more efficient than retrieving everything into Where-Object. Valid keys include LogName, ProviderName, Id, Level, StartTime, EndTime, UserID, Data, named event-data fields, and SuppressHashFilter. Level values commonly map 1 critical, 2 error, 3 warning, 4 information, and 5 verbose.

System warnings and errors from the last hour
$filter = @{
    LogName = 'System'
    Level = 1, 2, 3
    StartTime = (Get-Date).AddHours(-1)
}
Get-WinEvent -FilterHashtable $filter |
    Select-Object TimeCreated, Id, LevelDisplayName, ProviderName, Message
Output
# Only matching records are retrieved.
Specific identifiers from one provider
Get-WinEvent -FilterHashtable @{
    LogName = 'System'
    ProviderName = 'Microsoft-Windows-Kernel-General'
    Id = 12, 13
} -MaxEvents 50
Output
# The provider, identifiers, and log must exist on the system.
Back to quick reference ↑
04

Prefer record properties and XML over formatted text

EventLogRecord exposes TimeCreated, Id, RecordId, Level, ProviderName, LogName, MachineName, UserId, Properties, Message, and ToXml. Message is localized rendered text and may be unavailable when provider resources are missing. ToXml preserves structured System and EventData fields and is the better fallback for exact extraction.

Inspect one record and its XML data
$event = Get-WinEvent -LogName System -MaxEvents 1
$event | Format-List TimeCreated, Id, RecordId, LevelDisplayName, ProviderName, Message
[xml]$xml = $event.ToXml()
$xml.Event.System | Select-Object EventID, EventRecordID, Computer
$xml.Event.EventData.Data
Output
# Fields depend on the selected event schema.
Back to quick reference ↑
05

Read archived files or authorized remote logs

-Path reads EVT, EVTX, or ETL files directly; ETL input requires -Oldest. -ComputerName uses the event-log remote protocol rather than PowerShell remoting and depends on network, firewall, service, and authorization settings. Record source computer and file hashes when provenance matters, and avoid altering originals during analysis.

Read a bounded archived EVTX file
$path = 'C:\Evidence\System.evtx'
Get-FileHash -LiteralPath $path -Algorithm SHA256
Get-WinEvent -Path $path -MaxEvents 50 |
    Select-Object TimeCreated, Id, RecordId, ProviderName
Output
# The hash identifies the analyzed file bytes.
Query a remote System log
Get-WinEvent -ComputerName 'Server01' -FilterHashtable @{
    LogName = 'System'
    StartTime = (Get-Date).AddMinutes(-30)
} -MaxEvents 100
Output
# Requires remote event-log access and sufficient permissions.
Back to quick reference ↑
06

Summarize bounded records before exporting

Group-Object is useful after a server-side query or MaxEvents bound, not as a substitute for one. Export selected fields instead of entire EventLogRecord objects so the schema is intentional. Messages can contain personal data, internal paths, hostnames, or secrets; protect and redact exports according to sensitivity.

Count identifiers and export detail
$events = Get-WinEvent -FilterHashtable @{
    LogName = 'System'
    StartTime = (Get-Date).AddHours(-6)
} -MaxEvents 500
$events | Group-Object Id -NoElement | Sort-Object Count -Descending
$events | Select-Object TimeCreated, RecordId, Id, LevelDisplayName, ProviderName, Message |
    Export-Csv '.\system-events.csv' -NoTypeInformation -Encoding utf8
Output
# Summary objects are displayed and selected detail is written to CSV.
Back to quick reference ↑
07

Preserve source, order, and record identifiers

Default query order is newest to oldest; -Oldest reverses retrieval direction and is mandatory for ETL files. RecordId identifies a record within one log but can reset when logs are cleared or recreated, so retain LogName, MachineName, ProviderName, Id, TimeCreated, and acquisition context too. Wall-clock timestamps alone may be ambiguous after clock changes.

Capture an ordered diagnostic timeline
Get-WinEvent -FilterHashtable @{
    LogName = 'System'
    StartTime = (Get-Date).AddMinutes(-15)
} -Oldest | Select-Object MachineName, LogName, RecordId, TimeCreated, Id, ProviderName
Output
# Records are emitted from older to newer within the interval.
Back to quick reference ↑

Sources and further reading

References

Authoritative documentation used to verify and expand this cheat sheet.

  1. Microsoft LearnGet-WinEventlearn.microsoft.com
  2. Microsoft LearnCreating Get-WinEvent queries with FilterHashtablelearn.microsoft.com
  3. Microsoft LearnEventLogRecord Classlearn.microsoft.com
  4. Microsoft LearnConsuming Eventslearn.microsoft.com

Help us improve

Found a typo or missing example?

Tell us what would make this cheat sheet clearer, more complete, or more useful.

Share feedback