Solved

WMI SQL Query for Eventlog

Posted on 2009-04-06
3
1,286 Views
Last Modified: 2012-05-06
I would like to receive the last 5 Entries for each EventID in every logfile or at least for one specific logfile

The table I need is Win32_NTLogEvent


0
Comment
Question by:schubduese
  • 2
3 Comments
 
LVL 25

Expert Comment

by:reb73
ID: 24078999
Here's a sample to display the last five records from the application logfile, you can adapt it for the other logfile types -
strComputer = "."
strcrlf = chr(13) & chr(10)
Set objWMIService = GetObject("winmgmts:" _
    & "{impersonationLevel=impersonate}!\\" & strComputer & "\root\cimv2")
 
Set objInstalledLogFiles = objWMIService.ExecQuery _
    ("Select * from Win32_NTEventLogFile Where LogFileName = 'Application'")
 
For Each objLogfile in objInstalledLogFiles
    intRecords = objLogFile.NumberOfRecords
Next
 
Set colLoggedEvents = objWMIService.ExecQuery _
    ("Select * From Win32_NTLogEvent Where Logfile = 'Application' AND " & _
        "RecordNumber > " &  cstr(intRecords - 5))
 
For Each objEvent in colLoggedEvents
    Wscript.Echo "Category: " & objEvent.Category & strcrlf & _
    "Computer Name: " & objEvent.ComputerName  & strcrlf & _
    "Event Code: " & objEvent.EventCode & strcrlf & _
    "Message: " & objEvent.Message & strcrlf & _
    "Record Number: " & objEvent.RecordNumber & strcrlf & _
    "Source Name: " & objEvent.SourceName & strcrlf & _
    "Time Written: " & objEvent.TimeWritten & strcrlf & _
    "Event Type: " & objEvent.Type & strcrlf & _
    "User: " & objEvent.User
Next

Open in new window

0
 

Author Comment

by:schubduese
ID: 24079263
This returns the last  5 entries over all id's right? What if i need the last 5 entries for each event id?
0
 
LVL 25

Accepted Solution

by:
reb73 earned 500 total points
ID: 24082989
WQL (WMI query Language) does not support either the TOP operator or the ORDER BY Clause, so I'm afraid you will have to capture the results of the basic query and loop through the collection populating a recordset which can then be sorted on EventCode and TimeWritten to give you the top 5 for each event code..


0

Featured Post

Master Your Team's Linux and Cloud Stack

Come see why top tech companies like Mailchimp and Media Temple use Linux Academy to build their employee training programs.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Logon script fails 23 45
MS SQL Server time between records 14 46
CREATE DATABASE 3 28
RAISERROR WITH NOWAIT 2 16
Composite queries are used to retrieve the results from joining multiple queries after applying any filters. UNION, INTERSECT, MINUS, and UNION ALL are some of the operators used to get certain desired results.​
This article describes how to use the timestamp of existing data in a database to allow Tableau to calculate the prior work day instead of relying on case statements or if statements to calculate the days of the week.
In a recent question (https://www.experts-exchange.com/questions/29004105/Run-AutoHotkey-script-directly-from-Notepad.html) here at Experts Exchange, a member asked how to run an AutoHotkey script (.AHK) directly from Notepad++ (aka NPP). This video…

856 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question