WMI SQL Query for Eventlog

Posted on 2009-04-06
Last Modified: 2012-05-06
I would like to receive the last 5 Entries for each EventID in every logfile or at least for one specific logfile

The table I need is Win32_NTLogEvent

Question by:schubduese
  • 2
LVL 25

Expert Comment

ID: 24078999
Here's a sample to display the last five records from the application logfile, you can adapt it for the other logfile types -
strComputer = "."

strcrlf = chr(13) & chr(10)

Set objWMIService = GetObject("winmgmts:" _

    & "{impersonationLevel=impersonate}!\\" & strComputer & "\root\cimv2")

Set objInstalledLogFiles = objWMIService.ExecQuery _

    ("Select * from Win32_NTEventLogFile Where LogFileName = 'Application'")

For Each objLogfile in objInstalledLogFiles

    intRecords = objLogFile.NumberOfRecords


Set colLoggedEvents = objWMIService.ExecQuery _

    ("Select * From Win32_NTLogEvent Where Logfile = 'Application' AND " & _

        "RecordNumber > " &  cstr(intRecords - 5))

For Each objEvent in colLoggedEvents

    Wscript.Echo "Category: " & objEvent.Category & strcrlf & _

    "Computer Name: " & objEvent.ComputerName  & strcrlf & _

    "Event Code: " & objEvent.EventCode & strcrlf & _

    "Message: " & objEvent.Message & strcrlf & _

    "Record Number: " & objEvent.RecordNumber & strcrlf & _

    "Source Name: " & objEvent.SourceName & strcrlf & _

    "Time Written: " & objEvent.TimeWritten & strcrlf & _

    "Event Type: " & objEvent.Type & strcrlf & _

    "User: " & objEvent.User


Open in new window


Author Comment

ID: 24079263
This returns the last  5 entries over all id's right? What if i need the last 5 entries for each event id?
LVL 25

Accepted Solution

reb73 earned 500 total points
ID: 24082989
WQL (WMI query Language) does not support either the TOP operator or the ORDER BY Clause, so I'm afraid you will have to capture the results of the basic query and loop through the collection populating a recordset which can then be sorted on EventCode and TimeWritten to give you the top 5 for each event code..


Featured Post

IT, Stop Being Called Into Every Meeting

Highfive is so simple that setting up every meeting room takes just minutes and every employee will be able to start or join a call from any room with ease. Never be called into a meeting just to get it started again. This is how video conferencing should work!

Join & Write a Comment

It was really hard time for me to get the understanding of Delegates in C#. I went through many websites and articles but I found them very clumsy. After going through those sites, I noted down the points in a easy way so here I am sharing that unde…
If you need to start windows update installation remotely or as a scheduled task you will find this very helpful.
In this tutorial you'll learn about bandwidth monitoring with flows and packet sniffing with our network monitoring solution PRTG Network Monitor ( If you're interested in additional methods for monitoring bandwidt…
This demo shows you how to set up the containerized NetScaler CPX with NetScaler Management and Analytics System in a non-routable Mesos/Marathon environment for use with Micro-Services applications.

757 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

22 Experts available now in Live!

Get 1:1 Help Now