How to collect the new "Application and Service Logs" found in Windows 7 or Windows Server 2008 using WMI?

In Windows Server 2008 and Windows 7, new events appear that are classified in the Application and Service Logs section. There is also a subfolder called Microsoft, which also has many subfolders.

Is there a way to collect these events through WMI? For regular Windows Logs, such as Application and Security, you can use the Win32_NTLogEvent WMI class in the cimv2 namespace. However, this class does not provide access to new Microsoft event logs.

Any ideas?

+3
source share
2

WMI, ; , PowerShell wevtutil?

0

, , , , , , , , .. Microsoft-Windows-PrintService/Admin Microsoft-Windows-TaskScheduler/Operational ( ) .

, , , -.

McAffee ( Google, , , !)

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\

https://kc.mcafee.com/corporate/index?page=content&id=KB81367

community.mcafee.com/thread/64301

+2

Source: https://habr.com/ru/post/1735503/


All Articles