Skip to content

Event Log

Franck SALLET edited this page Sep 5, 2026 · 1 revision

Event Log

Mining the Windows Event Log for actionable signals: logon failures, crashes, scheduled task failures, Schannel/TLS errors, disk errors, and unexpected shutdowns.

9 function(s) in Public/eventlog/.

Functions

Reference

Get-ADLockoutSource

Find the source machine for AD account lockout events.

Reads Security event 4740 from the PDC Emulator or a specified domain controller and correlates events with Active Directory users by SID. Returns typed, pipeline-friendly records sorted with the newest lockout first.

Syntax

Get-ADLockoutSource -Identity <string[]> [-Server <string>] [-MaxEvents <int>] [-After <datetime>] [-Credential <System.Management.Automation.PSCredential>]

Examples

Get-ADLockoutSource -Identity 'jsmith'

Finds the lockout source for 'jsmith' using the discovered PDC Emulator.

Get-ADLockoutSource -Identity 'jsmith' -Server 'DC01.contoso.com'

Finds the lockout source for 'jsmith' by querying the Security log on a specific domain controller.

Get-ADLockedAccount | Get-ADLockoutSource

Pipes currently locked accounts into Get-ADLockoutSource to identify where each lockout originated.

Output: PSWinOps.ADLockoutSource

One object per matching 4740 event, sorted by LockoutTime descending.


Get-DiskErrorEvent

Report disk, controller, NTFS, and storage errors from the System log.

Queries the Windows System event log for known Disk, Ntfs, storahci, and storport error events over a configurable look-back window. Named EventData fields are parsed from event XML so localized message text does not drive classification.

Results are classified from centralized provider and event-ID mappings, aggregated by provider, error type, and device, and returned newest first for each machine. Missing event fields remain empty or null, and remote failures do not stop other computers from being processed.

Syntax

Get-DiskErrorEvent [-ComputerName <string[]>] [-Days <int>] [-MaxEvents <int>] [-DiskNumber <Nullable[int]>] [-CriticalOnly] [-Credential <System.Management.Automation.PSCredential>]

Examples

Get-DiskErrorEvent

Returns recognized disk and storage errors from the local computer over the last seven days.

Get-DiskErrorEvent -ComputerName 'SRV01' -Days 30 -CriticalOnly

Returns critical storage errors from SRV01 over the last 30 days.

'SRV01', 'SRV02' | Get-DiskErrorEvent -MaxEvents 500 -DiskNumber 0

Returns disk-zero errors from multiple computers through pipeline input.

Output: PSWinOps.DiskErrorEvent

One object per recognized storage event, newest first, with classification and an EventCount aggregated over the selected look-back window.


Get-LogonFailure

Aggregate and decode Windows Security 4625 failed-logon events.

Queries the Windows Security event log for 4625 failed-logon events over a look-back window and decodes each into a correlated diagnostic row (account, domain, logon type, decoded failure reason, source IP, workstation and process). Local and remote targets are dispatched through Invoke-RemoteOrLocal; machines with no matching events return nothing and per-machine failures do not stop the remaining targets.

Syntax

Get-LogonFailure [-ComputerName <string[]>] [-Credential <System.Management.Automation.PSCredential>] [-Days <int>] [-MaxEvents <int>] [-UserName <string>]

Examples

Get-LogonFailure -Days 1

Returns decoded failed-logon events for the local machine over the last day.

Get-LogonFailure -ComputerName SRV01 -UserName jdoe -Days 30

Returns decoded failed-logon events for user 'jdoe' on SRV01 over the last 30 days via WinRM.

'SRV01','SRV02' | Get-LogonFailure -MaxEvents 500

Returns up to 500 decoded failed-logon events per machine for SRV01 and SRV02 via pipeline.

Output: PSWinOps.LogonFailure

One object per 4625 failed-logon event, newest first, with decoded account, domain, logon type, failure reason, source IP, workstation and process.


Get-ProcessCrashEvent

Report application crashes and hangs from the Windows Application log.

Queries the Application event log for Application Error, Windows Error Reporting, and optionally Application Hang events over a configurable look-back window. Named EventData fields are parsed from event XML so localized message text and unstable Properties indexes do not affect the core crash details.

Windows Error Reporting events enrich crash correlation through their report ID but never produce a second output row. Results are aggregated by executable name before the optional process filter is applied, then returned newest first for each machine.

Syntax

Get-ProcessCrashEvent [-ComputerName <string[]>] [-Credential <System.Management.Automation.PSCredential>] [-Days <int>] [-MaxEvents <int>] [-ProcessName <string>] [-IncludeHang]

Examples

Get-ProcessCrashEvent

Returns application crash events for the local computer from the last seven days.

Get-ProcessCrashEvent -ComputerName 'SRV01' -Days 30 -ProcessName 'w3wp.exe'

Returns IIS worker-process crashes from SRV01 over the last 30 days.

'SRV01', 'SRV02' | Get-ProcessCrashEvent -MaxEvents 500 -IncludeHang

Returns crash and hang events from multiple computers through pipeline input.

Output: PSWinOps.ProcessCrashEvent

One object per Application Error 1000 crash and, when requested, Application Hang 1002 event. Windows Error Reporting 1001 events are correlated and do not emit rows.


Get-SchannelError

Report Schannel TLS, certificate, and negotiation failures from the System log.

Queries the Schannel provider in the Windows System event log for common TLS and certificate failures. Event XML is parsed for stable diagnostic fields so localized message text does not drive classification or extraction.

Results classify each failure as Certificate, Protocol, Cipher, Alert, or Unknown, aggregate equivalent occurrences, and return newest events first. Missing XML fields remain empty, sensitive key and secret fields are never extracted, and a failure on one computer does not stop the remaining computers from being processed.

Syntax

Get-SchannelError [-ComputerName <string[]>] [-Days <int>] [-MaxEvents <int>] [-EventId <int[]>] [-RemoteHost <string>] [-Credential <System.Management.Automation.PSCredential>]

Examples

Get-SchannelError

Returns Schannel errors from the local computer over the last seven days.

Get-SchannelError -ComputerName 'SRV01' -Days 30 -RemoteHost 'api.example.com'

Returns matching Schannel failures from SRV01 involving the specified peer.

'SRV01', 'SRV02' | Get-SchannelError -MaxEvents 500 -EventId 36888

Returns generated fatal TLS alerts from multiple computers through pipeline input.

Output: PSWinOps.SchannelError

One object per parsed Schannel event, newest first, with normalized classification, extracted XML fields, a FailureCount for equivalent events, and a safe message.


Get-ScheduledTaskFailure

Report failed scheduled-task starts and actions from Task Scheduler.

Queries the Microsoft-Windows-TaskScheduler/Operational event log for task-start and action-failure events over a configurable look-back window. Named EventData fields are parsed from event XML so localized message text does not drive extraction.

Results retain the task path, action, user, raw and hexadecimal result codes, and the latest known run time. FailureCount is aggregated per task over the full window, results are newest first, and failures on one computer do not stop other targets.

Syntax

Get-ScheduledTaskFailure [-ComputerName <string[]>] [-Days <int>] [-MaxEvents <int>] [-TaskPath <string>] [-TaskName <string>] [-Credential <System.Management.Automation.PSCredential>]

Examples

Get-ScheduledTaskFailure

Returns scheduled-task start and action failures from the local computer over the last seven days.

Get-ScheduledTaskFailure -ComputerName 'SRV01' -Days 30 -TaskPath '\Backup\'

Returns failures for tasks under the Backup path on SRV01 over the last 30 days.

'SRV01', 'SRV02' | Get-ScheduledTaskFailure -MaxEvents 500 -TaskName 'NightlyBackup'

Returns failures for the named task from multiple computers through pipeline input.

Output: PSWinOps.ScheduledTaskFailure

One object per recognized Task Scheduler failure event, newest first, with the number of failures for the task across the selected look-back window.


Get-ServiceCrashEvent

Aggregate Service Control Manager crash events per service with counts and exit codes.

Queries the Windows System event log for Service Control Manager crash/abnormal-stop events (IDs 7000, 7009, 7011, 7024, 7031, 7034) over a look-back window and reports one row per event with the resolved service name, display name, last exit code, configured recovery action, and a per-service crash count aggregated over the window. Local and remote targets are dispatched through Invoke-RemoteOrLocal; machines with no matching events return nothing and per-machine failures do not stop the remaining targets.

Syntax

Get-ServiceCrashEvent [-ComputerName <string[]>] [-Credential <System.Management.Automation.PSCredential>] [-Days <int>] [-MaxEvents <int>] [-ServiceName <string>]

Examples

Get-ServiceCrashEvent -Days 7

Returns Service Control Manager crash events for the local machine over the last 7 days.

Get-ServiceCrashEvent -ComputerName SRV01 -ServiceName Spooler -Days 30

Returns crash events for the 'Spooler' service on SRV01 over the last 30 days via WinRM.

'SRV01','SRV02' | Get-ServiceCrashEvent -MaxEvents 100

Returns up to 100 crash events per machine for SRV01 and SRV02 via pipeline.

Output: PSWinOps.ServiceCrashEvent

One object per Service Control Manager crash event (7000, 7009, 7011, 7024, 7031, 7034), newest first, with resolved service name, exit code, window-level crash count and configured recovery action.


Get-UnexpectedShutdown

Reports shutdown and restart events with cause, expectedness and initiator.

Correlates Windows System event log entries (6008 dirty shutdown, Kernel-Power 41 unexpected, 1074 planned shutdown/restart, 6006 clean shutdown, 1076 reason supplied) to report each shutdown or restart with its cause, whether it was expected or unexpected, the initiating process/user and the reason code. Local and remote targets are dispatched through Invoke-RemoteOrLocal; machines with no matching events return nothing.

Syntax

Get-UnexpectedShutdown [-ComputerName <string[]>] [-Credential <System.Management.Automation.PSCredential>] [-MaxEvents <int>] [-Days <int>]

Examples

Get-UnexpectedShutdown

Returns the most recent shutdown/restart events for the local machine over the last 30 days.

Get-UnexpectedShutdown -ComputerName SRV01 -Days 90

Returns shutdown/restart events from SRV01 over the last 90 days via WinRM.

'SRV01','SRV02' | Get-UnexpectedShutdown -MaxEvents 20

Returns up to 20 shutdown/restart events per machine for SRV01 and SRV02 via pipeline.

Output: PSWinOps.UnexpectedShutdown

One object per shutdown/restart-related event (6008, 41, 1074, 6006, 1076), newest first, with cause, expectedness, initiator, reason code and comment.


Get-WindowsUpdateFailure

Report Windows Update failures and restart requirements from the System log.

Queries the Microsoft-Windows-WindowsUpdateClient provider in the System event log for failed installations, required restarts, and optionally successful installations. Named XML EventData fields are parsed so localized event message text does not drive classification or extraction.

Results include the update identity, KB article, raw and hexadecimal error codes, restart status, and event message. Results are newest first, and an error on one computer does not stop the remaining computers from being processed.

Syntax

Get-WindowsUpdateFailure [-ComputerName <string[]>] [-Days <int>] [-MaxEvents <int>] [-KBArticle <string>] [-UpdateTitle <string>] [-IncludeSuccess] [-Credential <System.Management.Automation.PSCredential>]

Examples

Get-WindowsUpdateFailure

Returns failed Windows Update installations and required restarts from the local computer over the last 30 days.

Get-WindowsUpdateFailure -ComputerName 'SRV01' -Days 90 -KBArticle 'KB5030211'

Returns matching Windows Update events from SRV01 over the last 90 days.

'SRV01', 'SRV02' | Get-WindowsUpdateFailure -MaxEvents 500 -IncludeSuccess

Returns failures, required restarts, and successful installations from multiple computers through pipeline input.

Output: PSWinOps.WindowsUpdateFailure

One object per recognized Windows Update event, newest first, with status, update identity, error information, restart state, and the raw event message.


PSWinOps Wiki

Home

Domains

Clone this wiki locally