The essentials
Quick reference
One focused task per row. Jump to the related section for complete, working examples.
| Use | Syntax | Examples |
|---|---|---|
| List event logs | Get-WinEvent -ListLog * | View examples |
| Find nonempty enabled logs | Get-WinEvent -ListLog * |
Where-Object { $_.IsEnabled -and $_.RecordCount } | View examples |
| List event providers | Get-WinEvent -ListProvider * | View examples |
| Read recent system events | Get-WinEvent -LogName System -MaxEvents 20 | View examples |
| Read one provider | Get-WinEvent -ProviderName `
'Microsoft-Windows-Kernel-General' -MaxEvents 20 | View examples |
| Filter by start time | Get-WinEvent -FilterHashtable @{ LogName='System'; `
StartTime=(Get-Date).AddHours(-1) } | View examples |
| Filter error levels | Get-WinEvent -FilterHashtable @{ LogName='System'; `
Level=1,2,3 } | View examples |
| Filter event identifiers | Get-WinEvent -FilterHashtable @{ LogName='System'; `
Id=41,6008 } | View examples |
| Filter a provider in a log | Get-WinEvent -FilterHashtable @{ LogName='System'; `
ProviderName='Microsoft-Windows-Kernel-General' } | View examples |
| Suppress information events | Get-WinEvent -FilterHashtable @{ LogName='Application'; `
SuppressHashFilter=@{ Level=4 } } | View examples |
| Select core event fields | Get-WinEvent -LogName System -MaxEvents 5 |
Select-Object TimeCreated, Id, LevelDisplayName, ProviderName | View examples |
| Read rendered messages | $event.Message | View examples |
| Inspect event XML | [xml]$xml = $event.ToXml() | View examples |
| Read an archived log | Get-WinEvent -Path 'C:\Evidence\System.evtx' -MaxEvents `
50 | View examples |
| Query a remote computer | Get-WinEvent -ComputerName 'Server01' -LogName System `
-MaxEvents 20 | View examples |
| Count by event ID | Get-WinEvent -LogName System -MaxEvents 500 |
Group-Object Id -NoElement |
Sort-Object Count -Descending | View examples |
| Export selected fields | $events |
Select-Object TimeCreated, Id, ProviderName, Message |
Export-Csv '.\events.csv' -NoTypeInformation -Encoding utf8 | View examples |
| Return oldest first | Get-WinEvent -LogName System -Oldest -MaxEvents 20 | View examples |
| Preserve record identity | $event |
Select-Object LogName, RecordId, TimeCreated, Id, ProviderName | View examples |
Get-WinEvent returns structured event records and filters them close to the log engine. Narrow by log, provider, identifier, level, and time before formatting; preserve record identifiers and XML when evidence matters, and expect permissions and message resources to affect what a session can retrieve.
Step by step
Detailed examples
Discover exact log and provider names
-ListLog returns EventLogConfiguration metadata such as enabled state, record count, size, and path; some record counts are null. -ListProvider returns provider metadata and linked logs. Listing every source can be slow and may report access errors, so narrow wildcard patterns when possible. Get-WinEvent is available only on Windows.
Get-WinEvent -ListLog '*PowerShell*' |
Where-Object IsEnabled |
Select-Object LogName, RecordCount, LogMode, MaximumSizeInBytes
Get-WinEvent -ListProvider 'Microsoft-Windows-PowerShell*' |
Select-Object Name, LogLinks # Results vary by Windows edition, installed components, and permissions.Bound exploratory queries
-LogName selects a specific log and returns newest records first by default. -ProviderName can combine records from logs linked to that provider. Always use MaxEvents or a time filter during exploration; unbounded queries against busy logs can allocate large collections and delay the investigation.
Get-WinEvent -LogName System -MaxEvents 20 |
Select-Object TimeCreated, Id, LevelDisplayName, ProviderName
Get-WinEvent -ProviderName 'Microsoft-Windows-Kernel-General' -MaxEvents 10 |
Select-Object TimeCreated, Id, Message # Event content is specific to the queried computer.Filter inside Get-WinEvent
FilterHashtable sends criteria to the event-log query engine and is generally more efficient than retrieving everything into Where-Object. Valid keys include LogName, ProviderName, Id, Level, StartTime, EndTime, UserID, Data, named event-data fields, and SuppressHashFilter. Level values commonly map 1 critical, 2 error, 3 warning, 4 information, and 5 verbose.
$filter = @{
LogName = 'System'
Level = 1, 2, 3
StartTime = (Get-Date).AddHours(-1)
}
Get-WinEvent -FilterHashtable $filter |
Select-Object TimeCreated, Id, LevelDisplayName, ProviderName, Message # Only matching records are retrieved.Get-WinEvent -FilterHashtable @{
LogName = 'System'
ProviderName = 'Microsoft-Windows-Kernel-General'
Id = 12, 13
} -MaxEvents 50 # The provider, identifiers, and log must exist on the system.Prefer record properties and XML over formatted text
EventLogRecord exposes TimeCreated, Id, RecordId, Level, ProviderName, LogName, MachineName, UserId, Properties, Message, and ToXml. Message is localized rendered text and may be unavailable when provider resources are missing. ToXml preserves structured System and EventData fields and is the better fallback for exact extraction.
$event = Get-WinEvent -LogName System -MaxEvents 1
$event | Format-List TimeCreated, Id, RecordId, LevelDisplayName, ProviderName, Message
[xml]$xml = $event.ToXml()
$xml.Event.System | Select-Object EventID, EventRecordID, Computer
$xml.Event.EventData.Data # Fields depend on the selected event schema.Read archived files or authorized remote logs
-Path reads EVT, EVTX, or ETL files directly; ETL input requires -Oldest. -ComputerName uses the event-log remote protocol rather than PowerShell remoting and depends on network, firewall, service, and authorization settings. Record source computer and file hashes when provenance matters, and avoid altering originals during analysis.
$path = 'C:\Evidence\System.evtx'
Get-FileHash -LiteralPath $path -Algorithm SHA256
Get-WinEvent -Path $path -MaxEvents 50 |
Select-Object TimeCreated, Id, RecordId, ProviderName # The hash identifies the analyzed file bytes.Get-WinEvent -ComputerName 'Server01' -FilterHashtable @{
LogName = 'System'
StartTime = (Get-Date).AddMinutes(-30)
} -MaxEvents 100 # Requires remote event-log access and sufficient permissions.Summarize bounded records before exporting
Group-Object is useful after a server-side query or MaxEvents bound, not as a substitute for one. Export selected fields instead of entire EventLogRecord objects so the schema is intentional. Messages can contain personal data, internal paths, hostnames, or secrets; protect and redact exports according to sensitivity.
$events = Get-WinEvent -FilterHashtable @{
LogName = 'System'
StartTime = (Get-Date).AddHours(-6)
} -MaxEvents 500
$events | Group-Object Id -NoElement | Sort-Object Count -Descending
$events | Select-Object TimeCreated, RecordId, Id, LevelDisplayName, ProviderName, Message |
Export-Csv '.\system-events.csv' -NoTypeInformation -Encoding utf8 # Summary objects are displayed and selected detail is written to CSV.Preserve source, order, and record identifiers
Default query order is newest to oldest; -Oldest reverses retrieval direction and is mandatory for ETL files. RecordId identifies a record within one log but can reset when logs are cleared or recreated, so retain LogName, MachineName, ProviderName, Id, TimeCreated, and acquisition context too. Wall-clock timestamps alone may be ambiguous after clock changes.
Get-WinEvent -FilterHashtable @{
LogName = 'System'
StartTime = (Get-Date).AddMinutes(-15)
} -Oldest | Select-Object MachineName, LogName, RecordId, TimeCreated, Id, ProviderName # Records are emitted from older to newer within the interval.Sources and further reading
References
Authoritative documentation used to verify and expand this cheat sheet.
Help us improve
Found a typo or missing example?
Tell us what would make this cheat sheet clearer, more complete, or more useful.



