Backup/export custom view automatically from Event Viewerusers unable to view security log in event viewerHow do I fix a custom Event Viewer Log that merges automatically with the Application log?100% uptime for a web applicationWindows Server 2008 what is the proper way to export or backup security event logScript to export custom view Event Viewer to .evtx PowershellSave Custom View from Event Viewer in .evtxHow to export event viewer errors to Excel in Windows Server 2012How Can I Consolidate all Event Viewer Logs from different ServersIs it possible to view events from all event logs (including “Applications and Services Logs”) simultaneously?Enabling Event Viewer auditing on individual file modifications by Handler ID
What was Bran's plan to kill the Night King?
Voltage Balun 1:1
Can my 2 children, aged 10 and 12, who are US citizens, travel to the USA on expired American passports?
Is the book wrong about the Nyquist Sampling Criterion?
Why is "breaking the mould" positively connoted?
Find magical solution to magical equation
History of the kernel of a homomorphism?
What to use instead of cling film to wrap pastry
To kill a cuckoo
As a GM, is it bad form to ask for a moment to think when improvising?
Which sphere is fastest?
Javascript - Run my script only if landscape is detected
Copy previous line to current line from text file
Handling Null values (and equivalents) routinely in Python
Why is my arithmetic with a long long int behaving this way?
Is an HNN extension of a virtually torsion-free group virtually torsion-free?
Is there a word for food that's gone 'bad', but is still edible?
My first C++ game (snake console game)
How long would it take for people to notice a mass disappearance?
Why aren't nationalizations in Russia described as socialist?
All of my Firefox add-ons been disabled suddenly, how can I re-enable them?
Is disk brake effectiveness mitigated by tyres losing traction under strong braking?
How can I get people to remember my character's gender?
Endgame puzzle: How to avoid stalemate and win?
Backup/export custom view automatically from Event Viewer
users unable to view security log in event viewerHow do I fix a custom Event Viewer Log that merges automatically with the Application log?100% uptime for a web applicationWindows Server 2008 what is the proper way to export or backup security event logScript to export custom view Event Viewer to .evtx PowershellSave Custom View from Event Viewer in .evtxHow to export event viewer errors to Excel in Windows Server 2012How Can I Consolidate all Event Viewer Logs from different ServersIs it possible to view events from all event logs (including “Applications and Services Logs”) simultaneously?Enabling Event Viewer auditing on individual file modifications by Handler ID
.everyoneloves__top-leaderboard:empty,.everyoneloves__mid-leaderboard:empty,.everyoneloves__bot-mid-leaderboard:empty height:90px;width:728px;box-sizing:border-box;
How can I simply export or back-up a custom view from the event viewer? I do not want to export the regular Event logs, such as: System, Application, Security etc. But I want to export automatically my own whole custom view log with event id's.
windows-server-2008 eventviewer
add a comment |
How can I simply export or back-up a custom view from the event viewer? I do not want to export the regular Event logs, such as: System, Application, Security etc. But I want to export automatically my own whole custom view log with event id's.
windows-server-2008 eventviewer
You want to export the events that you see in your custom view, or you want to export the Custom View itself?
– Mathias R. Jessen
May 5 '14 at 10:32
I want to export the whole Custom View itself.
– user3603657
May 5 '14 at 10:33
add a comment |
How can I simply export or back-up a custom view from the event viewer? I do not want to export the regular Event logs, such as: System, Application, Security etc. But I want to export automatically my own whole custom view log with event id's.
windows-server-2008 eventviewer
How can I simply export or back-up a custom view from the event viewer? I do not want to export the regular Event logs, such as: System, Application, Security etc. But I want to export automatically my own whole custom view log with event id's.
windows-server-2008 eventviewer
windows-server-2008 eventviewer
edited May 5 '14 at 10:33
user3603657
asked May 5 '14 at 10:28
user3603657user3603657
3317
3317
You want to export the events that you see in your custom view, or you want to export the Custom View itself?
– Mathias R. Jessen
May 5 '14 at 10:32
I want to export the whole Custom View itself.
– user3603657
May 5 '14 at 10:33
add a comment |
You want to export the events that you see in your custom view, or you want to export the Custom View itself?
– Mathias R. Jessen
May 5 '14 at 10:32
I want to export the whole Custom View itself.
– user3603657
May 5 '14 at 10:33
You want to export the events that you see in your custom view, or you want to export the Custom View itself?
– Mathias R. Jessen
May 5 '14 at 10:32
You want to export the events that you see in your custom view, or you want to export the Custom View itself?
– Mathias R. Jessen
May 5 '14 at 10:32
I want to export the whole Custom View itself.
– user3603657
May 5 '14 at 10:33
I want to export the whole Custom View itself.
– user3603657
May 5 '14 at 10:33
add a comment |
1 Answer
1
active
oldest
votes
Open up the Custom View properties, select Edit Filter and then switch to the XML tab and copy the filter.
You can now use the filter with PowerShell, like this:
[xml]$CustomView = @"
<QueryList>
<Query Id="0" Path="Application">
<Select Path="Application">*[System[(Level=2 or Level=3) and ( (EventID >= 1000 and EventID <= 2000) )]]</Select>
</Query>
</QueryList>
"@
Get-WinEvent -FilterXML $CustomView | Export-CSV "C:LogFilesCustomView_$(Get-Date -format "yyyy-MM-DD").log"
Set up a scheduled task to run a script like the above every week
And how can I put this in a scheduled task in the Task Scheduler? I want this custom view every week on friday in a *.evtx file if possible. Should I run a script or something with the Task Scheduler?
– user3603657
May 5 '14 at 10:37
I've put this in a .ps1 file and ran it with PowerShell but nothing happens. The PowerShell appears, but disappears within 1 second and nothing happens after that. No folder is create on C: or such. How to fix it?
– user3603657
May 5 '14 at 11:47
If you used my exact query you probably won't get any results. Run the script from within an existing powershell session to see any errors it might produce
– Mathias R. Jessen
May 5 '14 at 11:51
I still get errors but it's dissappearing so quickly, I can't even read it. Within 1 second it's gone. Can you test your script for errors perhaps?
– user3603657
May 6 '14 at 10:04
I've managed to get it working but now it's saving as a .log file. Isn't there a way to save it as a .xml or csv to open in an Excel sheet? How to make it human readable?? Can I save it as .evtx to open in the Event Viewer?
– user3603657
May 6 '14 at 13:07
add a comment |
Your Answer
StackExchange.ready(function()
var channelOptions =
tags: "".split(" "),
id: "2"
;
initTagRenderer("".split(" "), "".split(" "), channelOptions);
StackExchange.using("externalEditor", function()
// Have to fire editor after snippets, if snippets enabled
if (StackExchange.settings.snippets.snippetsEnabled)
StackExchange.using("snippets", function()
createEditor();
);
else
createEditor();
);
function createEditor()
StackExchange.prepareEditor(
heartbeatType: 'answer',
autoActivateHeartbeat: false,
convertImagesToLinks: true,
noModals: true,
showLowRepImageUploadWarning: true,
reputationToPostImages: 10,
bindNavPrevention: true,
postfix: "",
imageUploader:
brandingHtml: "Powered by u003ca class="icon-imgur-white" href="https://imgur.com/"u003eu003c/au003e",
contentPolicyHtml: "User contributions licensed under u003ca href="https://creativecommons.org/licenses/by-sa/3.0/"u003ecc by-sa 3.0 with attribution requiredu003c/au003e u003ca href="https://stackoverflow.com/legal/content-policy"u003e(content policy)u003c/au003e",
allowUrls: true
,
onDemand: true,
discardSelector: ".discard-answer"
,immediatelyShowMarkdownHelp:true
);
);
Sign up or log in
StackExchange.ready(function ()
StackExchange.helpers.onClickDraftSave('#login-link');
);
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
StackExchange.ready(
function ()
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fserverfault.com%2fquestions%2f593134%2fbackup-export-custom-view-automatically-from-event-viewer%23new-answer', 'question_page');
);
Post as a guest
Required, but never shown
1 Answer
1
active
oldest
votes
1 Answer
1
active
oldest
votes
active
oldest
votes
active
oldest
votes
Open up the Custom View properties, select Edit Filter and then switch to the XML tab and copy the filter.
You can now use the filter with PowerShell, like this:
[xml]$CustomView = @"
<QueryList>
<Query Id="0" Path="Application">
<Select Path="Application">*[System[(Level=2 or Level=3) and ( (EventID >= 1000 and EventID <= 2000) )]]</Select>
</Query>
</QueryList>
"@
Get-WinEvent -FilterXML $CustomView | Export-CSV "C:LogFilesCustomView_$(Get-Date -format "yyyy-MM-DD").log"
Set up a scheduled task to run a script like the above every week
And how can I put this in a scheduled task in the Task Scheduler? I want this custom view every week on friday in a *.evtx file if possible. Should I run a script or something with the Task Scheduler?
– user3603657
May 5 '14 at 10:37
I've put this in a .ps1 file and ran it with PowerShell but nothing happens. The PowerShell appears, but disappears within 1 second and nothing happens after that. No folder is create on C: or such. How to fix it?
– user3603657
May 5 '14 at 11:47
If you used my exact query you probably won't get any results. Run the script from within an existing powershell session to see any errors it might produce
– Mathias R. Jessen
May 5 '14 at 11:51
I still get errors but it's dissappearing so quickly, I can't even read it. Within 1 second it's gone. Can you test your script for errors perhaps?
– user3603657
May 6 '14 at 10:04
I've managed to get it working but now it's saving as a .log file. Isn't there a way to save it as a .xml or csv to open in an Excel sheet? How to make it human readable?? Can I save it as .evtx to open in the Event Viewer?
– user3603657
May 6 '14 at 13:07
add a comment |
Open up the Custom View properties, select Edit Filter and then switch to the XML tab and copy the filter.
You can now use the filter with PowerShell, like this:
[xml]$CustomView = @"
<QueryList>
<Query Id="0" Path="Application">
<Select Path="Application">*[System[(Level=2 or Level=3) and ( (EventID >= 1000 and EventID <= 2000) )]]</Select>
</Query>
</QueryList>
"@
Get-WinEvent -FilterXML $CustomView | Export-CSV "C:LogFilesCustomView_$(Get-Date -format "yyyy-MM-DD").log"
Set up a scheduled task to run a script like the above every week
And how can I put this in a scheduled task in the Task Scheduler? I want this custom view every week on friday in a *.evtx file if possible. Should I run a script or something with the Task Scheduler?
– user3603657
May 5 '14 at 10:37
I've put this in a .ps1 file and ran it with PowerShell but nothing happens. The PowerShell appears, but disappears within 1 second and nothing happens after that. No folder is create on C: or such. How to fix it?
– user3603657
May 5 '14 at 11:47
If you used my exact query you probably won't get any results. Run the script from within an existing powershell session to see any errors it might produce
– Mathias R. Jessen
May 5 '14 at 11:51
I still get errors but it's dissappearing so quickly, I can't even read it. Within 1 second it's gone. Can you test your script for errors perhaps?
– user3603657
May 6 '14 at 10:04
I've managed to get it working but now it's saving as a .log file. Isn't there a way to save it as a .xml or csv to open in an Excel sheet? How to make it human readable?? Can I save it as .evtx to open in the Event Viewer?
– user3603657
May 6 '14 at 13:07
add a comment |
Open up the Custom View properties, select Edit Filter and then switch to the XML tab and copy the filter.
You can now use the filter with PowerShell, like this:
[xml]$CustomView = @"
<QueryList>
<Query Id="0" Path="Application">
<Select Path="Application">*[System[(Level=2 or Level=3) and ( (EventID >= 1000 and EventID <= 2000) )]]</Select>
</Query>
</QueryList>
"@
Get-WinEvent -FilterXML $CustomView | Export-CSV "C:LogFilesCustomView_$(Get-Date -format "yyyy-MM-DD").log"
Set up a scheduled task to run a script like the above every week
Open up the Custom View properties, select Edit Filter and then switch to the XML tab and copy the filter.
You can now use the filter with PowerShell, like this:
[xml]$CustomView = @"
<QueryList>
<Query Id="0" Path="Application">
<Select Path="Application">*[System[(Level=2 or Level=3) and ( (EventID >= 1000 and EventID <= 2000) )]]</Select>
</Query>
</QueryList>
"@
Get-WinEvent -FilterXML $CustomView | Export-CSV "C:LogFilesCustomView_$(Get-Date -format "yyyy-MM-DD").log"
Set up a scheduled task to run a script like the above every week
edited May 5 '14 at 10:44
answered May 5 '14 at 10:34
Mathias R. JessenMathias R. Jessen
22.8k35189
22.8k35189
And how can I put this in a scheduled task in the Task Scheduler? I want this custom view every week on friday in a *.evtx file if possible. Should I run a script or something with the Task Scheduler?
– user3603657
May 5 '14 at 10:37
I've put this in a .ps1 file and ran it with PowerShell but nothing happens. The PowerShell appears, but disappears within 1 second and nothing happens after that. No folder is create on C: or such. How to fix it?
– user3603657
May 5 '14 at 11:47
If you used my exact query you probably won't get any results. Run the script from within an existing powershell session to see any errors it might produce
– Mathias R. Jessen
May 5 '14 at 11:51
I still get errors but it's dissappearing so quickly, I can't even read it. Within 1 second it's gone. Can you test your script for errors perhaps?
– user3603657
May 6 '14 at 10:04
I've managed to get it working but now it's saving as a .log file. Isn't there a way to save it as a .xml or csv to open in an Excel sheet? How to make it human readable?? Can I save it as .evtx to open in the Event Viewer?
– user3603657
May 6 '14 at 13:07
add a comment |
And how can I put this in a scheduled task in the Task Scheduler? I want this custom view every week on friday in a *.evtx file if possible. Should I run a script or something with the Task Scheduler?
– user3603657
May 5 '14 at 10:37
I've put this in a .ps1 file and ran it with PowerShell but nothing happens. The PowerShell appears, but disappears within 1 second and nothing happens after that. No folder is create on C: or such. How to fix it?
– user3603657
May 5 '14 at 11:47
If you used my exact query you probably won't get any results. Run the script from within an existing powershell session to see any errors it might produce
– Mathias R. Jessen
May 5 '14 at 11:51
I still get errors but it's dissappearing so quickly, I can't even read it. Within 1 second it's gone. Can you test your script for errors perhaps?
– user3603657
May 6 '14 at 10:04
I've managed to get it working but now it's saving as a .log file. Isn't there a way to save it as a .xml or csv to open in an Excel sheet? How to make it human readable?? Can I save it as .evtx to open in the Event Viewer?
– user3603657
May 6 '14 at 13:07
And how can I put this in a scheduled task in the Task Scheduler? I want this custom view every week on friday in a *.evtx file if possible. Should I run a script or something with the Task Scheduler?
– user3603657
May 5 '14 at 10:37
And how can I put this in a scheduled task in the Task Scheduler? I want this custom view every week on friday in a *.evtx file if possible. Should I run a script or something with the Task Scheduler?
– user3603657
May 5 '14 at 10:37
I've put this in a .ps1 file and ran it with PowerShell but nothing happens. The PowerShell appears, but disappears within 1 second and nothing happens after that. No folder is create on C: or such. How to fix it?
– user3603657
May 5 '14 at 11:47
I've put this in a .ps1 file and ran it with PowerShell but nothing happens. The PowerShell appears, but disappears within 1 second and nothing happens after that. No folder is create on C: or such. How to fix it?
– user3603657
May 5 '14 at 11:47
If you used my exact query you probably won't get any results. Run the script from within an existing powershell session to see any errors it might produce
– Mathias R. Jessen
May 5 '14 at 11:51
If you used my exact query you probably won't get any results. Run the script from within an existing powershell session to see any errors it might produce
– Mathias R. Jessen
May 5 '14 at 11:51
I still get errors but it's dissappearing so quickly, I can't even read it. Within 1 second it's gone. Can you test your script for errors perhaps?
– user3603657
May 6 '14 at 10:04
I still get errors but it's dissappearing so quickly, I can't even read it. Within 1 second it's gone. Can you test your script for errors perhaps?
– user3603657
May 6 '14 at 10:04
I've managed to get it working but now it's saving as a .log file. Isn't there a way to save it as a .xml or csv to open in an Excel sheet? How to make it human readable?? Can I save it as .evtx to open in the Event Viewer?
– user3603657
May 6 '14 at 13:07
I've managed to get it working but now it's saving as a .log file. Isn't there a way to save it as a .xml or csv to open in an Excel sheet? How to make it human readable?? Can I save it as .evtx to open in the Event Viewer?
– user3603657
May 6 '14 at 13:07
add a comment |
Thanks for contributing an answer to Server Fault!
- Please be sure to answer the question. Provide details and share your research!
But avoid …
- Asking for help, clarification, or responding to other answers.
- Making statements based on opinion; back them up with references or personal experience.
To learn more, see our tips on writing great answers.
Sign up or log in
StackExchange.ready(function ()
StackExchange.helpers.onClickDraftSave('#login-link');
);
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
StackExchange.ready(
function ()
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fserverfault.com%2fquestions%2f593134%2fbackup-export-custom-view-automatically-from-event-viewer%23new-answer', 'question_page');
);
Post as a guest
Required, but never shown
Sign up or log in
StackExchange.ready(function ()
StackExchange.helpers.onClickDraftSave('#login-link');
);
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
Sign up or log in
StackExchange.ready(function ()
StackExchange.helpers.onClickDraftSave('#login-link');
);
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
Sign up or log in
StackExchange.ready(function ()
StackExchange.helpers.onClickDraftSave('#login-link');
);
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
You want to export the events that you see in your custom view, or you want to export the Custom View itself?
– Mathias R. Jessen
May 5 '14 at 10:32
I want to export the whole Custom View itself.
– user3603657
May 5 '14 at 10:33