Avatar of rookie_b
Flag for United Kingdom of Great Britain and Northern Ireland asked on

Check Multiple EVTX archived logs events for a particular user

I need to check multiple archived evtx logs to check what files a particular user has accessed or changed. Object access auditing is enabled and logs are set to archive at a certain size, so I need a way to go through those and export all File System  audit events for that user. I was wondering if there is a way to run this against multiple logs at the same time and there probably is a better way of doing that than running  multiple ISE instances.

PowershellWindows OSWindows Server 2008

Avatar of undefined
Last Comment
Seth Simmons

8/22/2022 - Mon
David Johnson, CD

Log in or sign up to see answer
Become an EE member today7-DAY FREE TRIAL
Members can start a 7-Day Free trial then enjoy unlimited access to the platform
Sign up - Free for 7 days
Learn why we charge membership fees
We get it - no one likes a content blocker. Take one extra minute and find out why we block content.
Not exactly the question you had in mind?
Sign up for an EE membership and get your own personalized solution. With an EE membership, you can ask unlimited troubleshooting, research, or opinion questions.
ask a question

Thanks David, that is definitely checking out. I was just looking for a quick search through a dump of logs, nothing that fancy and involved. All I need is a way to use the get-winevt PS commandlet to run as multiple jobs with the right filters on, but I guess I will just read the manual.
Seth Simmons

No comment has been added to this question in more than 21 days, so it is now classified as abandoned.

I have recommended this question be closed as follows:

Accept: 'David Johnson, CD' (https:#a43347553)

If you feel this question should be closed differently, post an objection and the moderators will review all objections and close it as they feel fit. If no one objects, this question will be closed automatically the way described above.

Experts-Exchange Cleanup Volunteer
Experts Exchange is like having an extremely knowledgeable team sitting and waiting for your call. Couldn't do my job half as well as I do without it!
James Murphy