Solved

powershell Get-WinEvent for logon events

Posted on 2014-02-18
5
1,977 Views
Last Modified: 2014-03-14
I have been doing a lot of research the past few days. I'm trying to get a very basic script to run on a Win 2008/Win7 that will give me a list of users who have logged on.

I found a bunch of scripts like the following

Get-WinEvent -computername $server -FilterHashTable @{Logname=$logname;ID=$eventid;StartTime=$starttime;EndTime=$endtime} | where { $_.Message | Select-String "Logon Type: 2" }

I'd like to have a starttime and endtime and I think it should just show the logon type of 2, if I'm not mistaken. It would be great if this could be output to a csv file. Any ideas? Thanks so much.
0
Comment
Question by:cb_it
  • 2
  • 2
5 Comments
 
LVL 10

Accepted Solution

by:
Prashant Girennavar earned 500 total points
ID: 39869184
Pipe the output to Export-csv

i.e

Get-WinEvent -computername $server -FilterHashTable @{Logname=$logname;ID=$eventid;StartTime=$starttime;EndTime=$endtime} | where { $_.Message | Select-String "Logon Type: 2" } | export-csv C:\winlogs.csv -notypeinformation

Let me know if this helps.

Thanks,

-Prashant Girennavar
0
 

Author Comment

by:cb_it
ID: 39870115
Thanks for the info. The script executes and a csv file is created but it's blank. With the script as is what is getting piped to the csv file?

I would like columns for account name, date, time, etc.

Any ideas??
0
 

Author Comment

by:cb_it
ID: 39870119
Just to be clear the main point of this is to run it on a server to get a csv list of who has logged in and when, nothing more. If there is a better script out there let me know! Thanks.
0
 
LVL 68

Expert Comment

by:Qlemo
ID: 39877646
Get-WinEvent -Computer $Server -FilterHashTable  @{
  Logname = 'Security'
  StartTime=$starttime
  EndTime=$endtime
  EventID = 4624
  Data=2
}

Open in new window

gets the respective entries. But parsing the result is a pain ...
0
 
LVL 68

Expert Comment

by:Qlemo
ID: 39909917
I can't see how http:#a39869184 could have answered your question - the resulting file is empty, according to your response.
0

Featured Post

Netscaler Common Configuration How To guides

If you use NetScaler you will want to see these guides. The NetScaler How To Guides show administrators how to get NetScaler up and configured by providing instructions for common scenarios and some not so common ones.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
hiding bulk external contacts 2 32
Powershell knowledge 2 29
Identify disabled AD users with PowerShell 6 39
Nano server Question 2 20
Are you one of those front-line IT Service Desk staff fielding calls, replying to emails, all-the-while working to resolve end-user technological nightmares? I am! That's why I have put together this brief overview of tools and techniques I use in o…
This script checks a path to see if a folder exists. If the folder does exist you will get output "The folder has previously been created. No action taken" If not it will create the folder. Then adds one user modify permission to the folder. It …
Along with being a a promotional video for my three-day Annielytics Dashboard Seminor, this Micro Tutorial is an intro to Google Analytics API data.
This Micro Tutorial demonstrates using Microsoft Excel pivot tables, how to reverse engineer competitors' marketing strategies through backlinks.

895 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

11 Experts available now in Live!

Get 1:1 Help Now