Reviewing events with PowerShell
We also can use PowerShell commands to review event logs or filter events from local and remote computers without any additional service configurations. Get-EventLog
is the primary cmdlet we can use for this task, as shown in the following example:
Get-EventLog -List
The previous command will list the details about the log files in your local system, including the log file name, max log file size, and number of entries.
Get-EventLog -LogName 'Directory Service' | fl
The previous command will list all the events under the Directory Service
log file. We can also limit the number of events we need to list. As an example, if we only need to list the latest 5 events from the Directory Service
log file, we can use the following command:
Get-EventLog -Newest 5 -LogName 'Directory Service'
We can further filter it down by listing events according to entry type, as shown in the following example:
Get-EventLog...