Terminal Dojo
Help العربية Sign inGet started

Command library / Get-WinEvent

Get-WinEvent

PowerShellDraft — pending expert review3 practice missions

Read Windows event logs

Reads events from a Windows event log (Security, System, Application, ...) as objects. -LogName picks which log to read, and -MaxEvents caps how many of the most recent entries come back — without it, a busy Security log can return hundreds of thousands of events.

Practice Get-WinEvent

Usage

Get-WinEvent -LogName name [-MaxEvents n]

Options and flags

Examples

Common mistakes

Get-WinEvent -MaxEvents 20 Get-WinEvent -LogName Security -MaxEvents 20

-LogName is never optional — Get-WinEvent needs to know which log to read before it can limit how many events come back from it.

Related commands

journalctllast