Event ID: 20272 logged in windows system event log, http://technet.microsoft.com/en-us/library/cc733849(WS.10).aspx
The user: %1 connected on port: %2 on: %3 at: %4 and disconnected on: %5 at: %6. The user was active for: %7 minutes %8 seconds. %9 bytes were sent and %10 bytes were received. The reason for disconnecting was: %11.
When viewwed in the event log appears as
5876B8}: The user domain\first.last connected on port VPN2-127 on 1/10/2011 at 7:53 PM and disconnected on 1/10/2011 at 9:13 PM. The user was active for 80 minutes 33 seconds. 19113013 bytes were sent and 2478245 bytes were received. The reason for disconnecting was user request.
Question, the message does not contain the ":" colon character, is there a way in powershell to extract the %1 to %11 values with out assuming instring posistioning?
I have code in powershell to locate, read and export to csv. Looking for code to extract system entered values.
Thanks in advance.