{"id":4613,"date":"2012-11-23T11:59:00","date_gmt":"2012-11-23T11:59:00","guid":{"rendered":"https:\/\/blogs.technet.microsoft.com\/heyscriptingguy\/2012\/11\/23\/powertip-find-all-events-from-all-logs-related-to-powershell\/"},"modified":"2012-11-23T11:59:00","modified_gmt":"2012-11-23T11:59:00","slug":"powertip-find-all-events-from-all-logs-related-to-powershell","status":"publish","type":"post","link":"https:\/\/devblogs.microsoft.com\/scripting\/powertip-find-all-events-from-all-logs-related-to-powershell\/","title":{"rendered":"PowerTip: Find All Events from All Logs Related to PowerShell"},"content":{"rendered":"<p><strong>Summary:<\/strong>&nbsp;Learn how to use the&nbsp;<strong>Get-WinEvent<\/strong>&nbsp;cmdlet to return all events from all logs related to Windows PowerShell.<\/p>\n<p><strong><img decoding=\"async\" src=\"https:\/\/devblogs.microsoft.com\/wp-content\/uploads\/sites\/29\/2019\/02\/q-for-powertip.jpg\" alt=\"Hey, Scripting Guy! Question\" \/>&nbsp;<\/strong>How can I easily find events from all the event logs&mdash;both standard and the ETW logs that are related to Windows PowerShell?<\/p>\n<p style=\"padding-left: 60px\"><img decoding=\"async\" src=\"https:\/\/devblogs.microsoft.com\/wp-content\/uploads\/sites\/29\/2019\/02\/a-for-powertip.jpg\" alt=\"Hey, Scripting Guy! Answer\" \/>&nbsp;Use the&nbsp;<strong>Get-WinEvent<\/strong>&nbsp;cmdlet and use a wild card pattern for the provider name, as shown here.<\/p>\n<p style=\"padding-left: 120px\">Get-WinEvent -ProviderName *powershell*<\/p>\n<p style=\"padding-left: 120px\"><strong>Note<\/strong>&nbsp;&nbsp;&nbsp;You may want to run the command with Admin rights because some logs require Admin rights for access.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"https:\/\/devblogs.microsoft.com\/wp-content\/uploads\/sites\/29\/2019\/02\/7610.Dr.ScriptoForTips.jpg\"><img decoding=\"async\" src=\"https:\/\/devblogs.microsoft.com\/wp-content\/uploads\/sites\/29\/2019\/02\/7610.Dr.ScriptoForTips.jpg\" alt=\"\" border=\"0\" \/><\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Summary:&nbsp;Learn how to use the&nbsp;Get-WinEvent&nbsp;cmdlet to return all events from all logs related to Windows PowerShell. &nbsp;How can I easily find events from all the event logs&mdash;both standard and the ETW logs that are related to Windows PowerShell? &nbsp;Use the&nbsp;Get-WinEvent&nbsp;cmdlet and use a wild card pattern for the provider name, as shown here. Get-WinEvent -ProviderName [&hellip;]<\/p>\n","protected":false},"author":596,"featured_media":87096,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1],"tags":[97,98,356,3,45],"class_list":["post-4613","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-scripting","tag-event-logs","tag-logs-and-monitoring","tag-powertip","tag-scripting-guy","tag-windows-powershell"],"acf":[],"blog_post_summary":"<p>Summary:&nbsp;Learn how to use the&nbsp;Get-WinEvent&nbsp;cmdlet to return all events from all logs related to Windows PowerShell. &nbsp;How can I easily find events from all the event logs&mdash;both standard and the ETW logs that are related to Windows PowerShell? &nbsp;Use the&nbsp;Get-WinEvent&nbsp;cmdlet and use a wild card pattern for the provider name, as shown here. Get-WinEvent -ProviderName [&hellip;]<\/p>\n","_links":{"self":[{"href":"https:\/\/devblogs.microsoft.com\/scripting\/wp-json\/wp\/v2\/posts\/4613","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/devblogs.microsoft.com\/scripting\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/devblogs.microsoft.com\/scripting\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/scripting\/wp-json\/wp\/v2\/users\/596"}],"replies":[{"embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/scripting\/wp-json\/wp\/v2\/comments?post=4613"}],"version-history":[{"count":0,"href":"https:\/\/devblogs.microsoft.com\/scripting\/wp-json\/wp\/v2\/posts\/4613\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/scripting\/wp-json\/wp\/v2\/media\/87096"}],"wp:attachment":[{"href":"https:\/\/devblogs.microsoft.com\/scripting\/wp-json\/wp\/v2\/media?parent=4613"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/scripting\/wp-json\/wp\/v2\/categories?post=4613"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/scripting\/wp-json\/wp\/v2\/tags?post=4613"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}