-
Notifications
You must be signed in to change notification settings - Fork 0
Event Log
Mining the Windows Event Log for actionable signals: logon failures, crashes, scheduled task failures, Schannel/TLS errors, disk errors, and unexpected shutdowns.
9 function(s) in Public/eventlog/.
-
Get-ADLockoutSource— Find the source machine for AD account lockout events -
Get-DiskErrorEvent— Report disk, controller, NTFS, and storage errors from the System log -
Get-LogonFailure— Aggregate and decode Windows Security 4625 failed-logon events -
Get-ProcessCrashEvent— Report application crashes and hangs from the Windows Application log -
Get-SchannelError— Report Schannel TLS, certificate, and negotiation failures from the System log -
Get-ScheduledTaskFailure— Report failed scheduled-task starts and actions from Task Scheduler -
Get-ServiceCrashEvent— Aggregate Service Control Manager crash events per service with counts and exit codes -
Get-UnexpectedShutdown— Reports shutdown and restart events with cause, expectedness and initiator -
Get-WindowsUpdateFailure— Report Windows Update failures and restart requirements from the System log
Find the source machine for AD account lockout events.
Reads Security event 4740 from the PDC Emulator or a specified domain controller and correlates events with Active Directory users by SID. Returns typed, pipeline-friendly records sorted with the newest lockout first.
Syntax
Get-ADLockoutSource -Identity <string[]> [-Server <string>] [-MaxEvents <int>] [-After <datetime>] [-Credential <System.Management.Automation.PSCredential>]Examples
Get-ADLockoutSource -Identity 'jsmith'Finds the lockout source for 'jsmith' using the discovered PDC Emulator.
Get-ADLockoutSource -Identity 'jsmith' -Server 'DC01.contoso.com'Finds the lockout source for 'jsmith' by querying the Security log on a specific domain controller.
Get-ADLockedAccount | Get-ADLockoutSourcePipes currently locked accounts into Get-ADLockoutSource to identify where each lockout originated.
Output: PSWinOps.ADLockoutSource
One object per matching 4740 event, sorted by LockoutTime descending.
Report disk, controller, NTFS, and storage errors from the System log.
Queries the Windows System event log for known Disk, Ntfs, storahci, and storport error events over a configurable look-back window. Named EventData fields are parsed from event XML so localized message text does not drive classification.
Results are classified from centralized provider and event-ID mappings, aggregated by provider, error type, and device, and returned newest first for each machine. Missing event fields remain empty or null, and remote failures do not stop other computers from being processed.
Syntax
Get-DiskErrorEvent [-ComputerName <string[]>] [-Days <int>] [-MaxEvents <int>] [-DiskNumber <Nullable[int]>] [-CriticalOnly] [-Credential <System.Management.Automation.PSCredential>]Examples
Get-DiskErrorEventReturns recognized disk and storage errors from the local computer over the last seven days.
Get-DiskErrorEvent -ComputerName 'SRV01' -Days 30 -CriticalOnlyReturns critical storage errors from SRV01 over the last 30 days.
'SRV01', 'SRV02' | Get-DiskErrorEvent -MaxEvents 500 -DiskNumber 0Returns disk-zero errors from multiple computers through pipeline input.
Output: PSWinOps.DiskErrorEvent
One object per recognized storage event, newest first, with classification and an EventCount aggregated over the selected look-back window.
Aggregate and decode Windows Security 4625 failed-logon events.
Queries the Windows Security event log for 4625 failed-logon events over a look-back window and decodes each into a correlated diagnostic row (account, domain, logon type, decoded failure reason, source IP, workstation and process). Local and remote targets are dispatched through Invoke-RemoteOrLocal; machines with no matching events return nothing and per-machine failures do not stop the remaining targets.
Syntax
Get-LogonFailure [-ComputerName <string[]>] [-Credential <System.Management.Automation.PSCredential>] [-Days <int>] [-MaxEvents <int>] [-UserName <string>]Examples
Get-LogonFailure -Days 1Returns decoded failed-logon events for the local machine over the last day.
Get-LogonFailure -ComputerName SRV01 -UserName jdoe -Days 30Returns decoded failed-logon events for user 'jdoe' on SRV01 over the last 30 days via WinRM.
'SRV01','SRV02' | Get-LogonFailure -MaxEvents 500Returns up to 500 decoded failed-logon events per machine for SRV01 and SRV02 via pipeline.
Output: PSWinOps.LogonFailure
One object per 4625 failed-logon event, newest first, with decoded account, domain, logon type, failure reason, source IP, workstation and process.
Report application crashes and hangs from the Windows Application log.
Queries the Application event log for Application Error, Windows Error Reporting, and optionally Application Hang events over a configurable look-back window. Named EventData fields are parsed from event XML so localized message text and unstable Properties indexes do not affect the core crash details.
Windows Error Reporting events enrich crash correlation through their report ID but never produce a second output row. Results are aggregated by executable name before the optional process filter is applied, then returned newest first for each machine.
Syntax
Get-ProcessCrashEvent [-ComputerName <string[]>] [-Credential <System.Management.Automation.PSCredential>] [-Days <int>] [-MaxEvents <int>] [-ProcessName <string>] [-IncludeHang]Examples
Get-ProcessCrashEventReturns application crash events for the local computer from the last seven days.
Get-ProcessCrashEvent -ComputerName 'SRV01' -Days 30 -ProcessName 'w3wp.exe'Returns IIS worker-process crashes from SRV01 over the last 30 days.
'SRV01', 'SRV02' | Get-ProcessCrashEvent -MaxEvents 500 -IncludeHangReturns crash and hang events from multiple computers through pipeline input.
Output: PSWinOps.ProcessCrashEvent
One object per Application Error 1000 crash and, when requested, Application Hang 1002 event. Windows Error Reporting 1001 events are correlated and do not emit rows.
Report Schannel TLS, certificate, and negotiation failures from the System log.
Queries the Schannel provider in the Windows System event log for common TLS and certificate failures. Event XML is parsed for stable diagnostic fields so localized message text does not drive classification or extraction.
Results classify each failure as Certificate, Protocol, Cipher, Alert, or Unknown, aggregate equivalent occurrences, and return newest events first. Missing XML fields remain empty, sensitive key and secret fields are never extracted, and a failure on one computer does not stop the remaining computers from being processed.
Syntax
Get-SchannelError [-ComputerName <string[]>] [-Days <int>] [-MaxEvents <int>] [-EventId <int[]>] [-RemoteHost <string>] [-Credential <System.Management.Automation.PSCredential>]Examples
Get-SchannelErrorReturns Schannel errors from the local computer over the last seven days.
Get-SchannelError -ComputerName 'SRV01' -Days 30 -RemoteHost 'api.example.com'Returns matching Schannel failures from SRV01 involving the specified peer.
'SRV01', 'SRV02' | Get-SchannelError -MaxEvents 500 -EventId 36888Returns generated fatal TLS alerts from multiple computers through pipeline input.
Output: PSWinOps.SchannelError
One object per parsed Schannel event, newest first, with normalized classification, extracted XML fields, a FailureCount for equivalent events, and a safe message.
Report failed scheduled-task starts and actions from Task Scheduler.
Queries the Microsoft-Windows-TaskScheduler/Operational event log for task-start and action-failure events over a configurable look-back window. Named EventData fields are parsed from event XML so localized message text does not drive extraction.
Results retain the task path, action, user, raw and hexadecimal result codes, and the latest known run time. FailureCount is aggregated per task over the full window, results are newest first, and failures on one computer do not stop other targets.
Syntax
Get-ScheduledTaskFailure [-ComputerName <string[]>] [-Days <int>] [-MaxEvents <int>] [-TaskPath <string>] [-TaskName <string>] [-Credential <System.Management.Automation.PSCredential>]Examples
Get-ScheduledTaskFailureReturns scheduled-task start and action failures from the local computer over the last seven days.
Get-ScheduledTaskFailure -ComputerName 'SRV01' -Days 30 -TaskPath '\Backup\'Returns failures for tasks under the Backup path on SRV01 over the last 30 days.
'SRV01', 'SRV02' | Get-ScheduledTaskFailure -MaxEvents 500 -TaskName 'NightlyBackup'Returns failures for the named task from multiple computers through pipeline input.
Output: PSWinOps.ScheduledTaskFailure
One object per recognized Task Scheduler failure event, newest first, with the number of failures for the task across the selected look-back window.
Aggregate Service Control Manager crash events per service with counts and exit codes.
Queries the Windows System event log for Service Control Manager crash/abnormal-stop events (IDs 7000, 7009, 7011, 7024, 7031, 7034) over a look-back window and reports one row per event with the resolved service name, display name, last exit code, configured recovery action, and a per-service crash count aggregated over the window. Local and remote targets are dispatched through Invoke-RemoteOrLocal; machines with no matching events return nothing and per-machine failures do not stop the remaining targets.
Syntax
Get-ServiceCrashEvent [-ComputerName <string[]>] [-Credential <System.Management.Automation.PSCredential>] [-Days <int>] [-MaxEvents <int>] [-ServiceName <string>]Examples
Get-ServiceCrashEvent -Days 7Returns Service Control Manager crash events for the local machine over the last 7 days.
Get-ServiceCrashEvent -ComputerName SRV01 -ServiceName Spooler -Days 30Returns crash events for the 'Spooler' service on SRV01 over the last 30 days via WinRM.
'SRV01','SRV02' | Get-ServiceCrashEvent -MaxEvents 100Returns up to 100 crash events per machine for SRV01 and SRV02 via pipeline.
Output: PSWinOps.ServiceCrashEvent
One object per Service Control Manager crash event (7000, 7009, 7011, 7024, 7031, 7034), newest first, with resolved service name, exit code, window-level crash count and configured recovery action.
Reports shutdown and restart events with cause, expectedness and initiator.
Correlates Windows System event log entries (6008 dirty shutdown, Kernel-Power 41 unexpected, 1074 planned shutdown/restart, 6006 clean shutdown, 1076 reason supplied) to report each shutdown or restart with its cause, whether it was expected or unexpected, the initiating process/user and the reason code. Local and remote targets are dispatched through Invoke-RemoteOrLocal; machines with no matching events return nothing.
Syntax
Get-UnexpectedShutdown [-ComputerName <string[]>] [-Credential <System.Management.Automation.PSCredential>] [-MaxEvents <int>] [-Days <int>]Examples
Get-UnexpectedShutdownReturns the most recent shutdown/restart events for the local machine over the last 30 days.
Get-UnexpectedShutdown -ComputerName SRV01 -Days 90Returns shutdown/restart events from SRV01 over the last 90 days via WinRM.
'SRV01','SRV02' | Get-UnexpectedShutdown -MaxEvents 20Returns up to 20 shutdown/restart events per machine for SRV01 and SRV02 via pipeline.
Output: PSWinOps.UnexpectedShutdown
One object per shutdown/restart-related event (6008, 41, 1074, 6006, 1076), newest first, with cause, expectedness, initiator, reason code and comment.
Report Windows Update failures and restart requirements from the System log.
Queries the Microsoft-Windows-WindowsUpdateClient provider in the System event log for failed installations, required restarts, and optionally successful installations. Named XML EventData fields are parsed so localized event message text does not drive classification or extraction.
Results include the update identity, KB article, raw and hexadecimal error codes, restart status, and event message. Results are newest first, and an error on one computer does not stop the remaining computers from being processed.
Syntax
Get-WindowsUpdateFailure [-ComputerName <string[]>] [-Days <int>] [-MaxEvents <int>] [-KBArticle <string>] [-UpdateTitle <string>] [-IncludeSuccess] [-Credential <System.Management.Automation.PSCredential>]Examples
Get-WindowsUpdateFailureReturns failed Windows Update installations and required restarts from the local computer over the last 30 days.
Get-WindowsUpdateFailure -ComputerName 'SRV01' -Days 90 -KBArticle 'KB5030211'Returns matching Windows Update events from SRV01 over the last 90 days.
'SRV01', 'SRV02' | Get-WindowsUpdateFailure -MaxEvents 500 -IncludeSuccessReturns failures, required restarts, and successful installations from multiple computers through pipeline input.
Output: PSWinOps.WindowsUpdateFailure
One object per recognized Windows Update event, newest first, with status, update identity, error information, restart state, and the raw event message.
Domains
- Active Directory (22)
- Certificate (1)
- Event Log (9)
- Health Check (16)
- IIS (9)
- Network (26)
- NTP (5)
- Proxy (4)
- RDP (6)
- Security (1)
- System (20)
- Utils (4)
- VSS (Shadow Copy) (6)
- Windows Update (10)