In Windows Server 2008 and Windows 7, new events appear that are classified in the Application and Service Logs section. There is also a subfolder called Microsoft, which also has many subfolders.
Is there a way to collect these events through WMI? For regular Windows Logs, such as Application and Security, you can use the Win32_NTLogEvent WMI class in the cimv2 namespace. However, this class does not provide access to new Microsoft event logs.
Any ideas?
source
share