I am trying to query the event log of our dedicated redirect server of our Terminal Server Farm so I can obtain the username and IP address of the client connecting to our system.
So far I have the following syntax to dump the entire contents of the logs to a text file. Unfortunately there is just too much data to work with in the resulting file.
wevtutil qe Microsoft-Windows-TerminalServices-RemoteConnectionManager/Operational |findstr EventID^>1149 >Client_IP.txt
The only data I want returned is the following two elements for each line(so I can quickly import into a database):
Prior to today I have never used wevtutil so I find myself at the mercy of the MS documentation which is lacking.
Can someone help me determine the exact syntax to generate a log file with just the two parameters on a single line for each instance of that event ID (1149).