Command library / Get-WinEvent
Get-WinEvent
Read Windows event logs
Reads events from a Windows event log (Security, System, Application, ...) as objects. -LogName picks which log to read, and -MaxEvents caps how many of the most recent entries come back — without it, a busy Security log can return hundreds of thousands of events.
Practice Get-WinEventUsage
Options and flags
-LogNameNAMEwhich event log to read, e.g. Security, System, Application
-MaxEventsNonly return the N most recent events
Examples
Get-WinEvent -LogName SecurityEvery event currently in the Security log — can be huge on a busy host.
Get-WinEvent -LogName Security -MaxEvents 20Just the 20 most recent Security events — a fast, readable check.
Get-WinEvent -LogName System -MaxEvents 50The 50 most recent System log entries — driver and hardware errors live here.
Common mistakes
-LogName is never optional — Get-WinEvent needs to know which log to read before it can limit how many events come back from it.