{"id":9551,"date":"2012-05-02T00:01:00","date_gmt":"2012-05-02T00:01:00","guid":{"rendered":"https:\/\/blogs.technet.microsoft.com\/heyscriptingguy\/2012\/05\/02\/how-can-i-use-the-out-gridview-cmdlet-to-search-event-logs\/"},"modified":"2012-05-02T00:01:00","modified_gmt":"2012-05-02T00:01:00","slug":"how-can-i-use-the-out-gridview-cmdlet-to-search-event-logs","status":"publish","type":"post","link":"https:\/\/devblogs.microsoft.com\/scripting\/how-can-i-use-the-out-gridview-cmdlet-to-search-event-logs\/","title":{"rendered":"How Can I Use the Out-GridView Cmdlet to Search Event Logs?"},"content":{"rendered":"<p><b>Summary<\/b>: Learn how to use a simple Windows PowerShell cmdlet to search event logs for errors.<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/devblogs.microsoft.com\/wp-content\/uploads\/sites\/29\/2019\/02\/q-for-powertip.jpg\" alt=\"Hey, Scripting Guy! Question\" \/>&nbsp;Hey, Scripting Guy! I was at a recent <a href=\"http:\/\/www.sqlsaturday.com\/\" target=\"_blank\">SQL Saturday event<\/a>, and there was a person there (unfortunately, I do not remember his name) who was talking about Windows PowerShell. In his talk, he showed something that was pretty cool. It seemed like he created a pivot table on the fly. He was able to sort and filter stuff to find specific information. I do not remember what that was called either. Is this something that is built-in to Windows PowerShell? Is it in Windows PowerShell&nbsp;2.0 or only in the version 3 beta? Or is this something that he created himself?<\/p>\n<p>&mdash;JD<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/devblogs.microsoft.com\/wp-content\/uploads\/sites\/29\/2019\/02\/a-for-powertip.jpg\" alt=\"Hey, Scripting Guy! Answer\" \/>&nbsp;Hello JD,<\/p>\n<p>Microsoft Scripting Guy, Ed Wilson, is here. This has already been one of the greatest weeks ever. The Scripting Wife and I are in <a href=\"http:\/\/www.bing.com\/places\/search?q=Virginia+Beach%2c+Virginia&amp;upgid=35359&amp;qpvt=virginia+beach&amp;FORM=ATRCCN\" target=\"_blank\">Virginia Beach, Virginia<\/a> where I am speaking at the <a href=\"http:\/\/minasiconference.wordpress.com\/minasi-2012-timetable\/\" target=\"_blank\">Mark Minasi Conference<\/a>. I got to meet up with an old friend the other day, and we had dinner together. I had not seen Dan for more than 30 years. We reestablished our friendship over Facebook, and because he lives in Virginia Beach, we thought it would be an awesome time to meet again. Don Jones is also here at the conference speaking, so we have had a lot of fun hanging out with him. Of course, Mark Minasi is here, and it is always a lot of fun to see him again. If it was only Dan, Don, and Mark, the week would be worth it. But the sessions have been awesome, and it has been great to have the high level of interaction with people this week.<\/p>\n<p>Right now, we have a break, and I am sitting in a corner, sipping on a cup of &ldquo;generic&rdquo; <a href=\"http:\/\/en.wikipedia.org\/wiki\/Green_tea\" target=\"_blank\">green tea<\/a> (it just says &ldquo;green&rdquo;), and I am also listening to <a href=\"http:\/\/en.wikipedia.org\/wiki\/Don_Giovanni\" target=\"_blank\">Don Giovanni<\/a> on my <a href=\"http:\/\/www.zune.net\/en-US\/\" target=\"_blank\">Zune<\/a> while I take the opportunity to catch up on some of the email sent to <a href=\"mailto:scripter@microsoft.com\">scripter@microsoft.com<\/a>. I will admit that I miss my tea pot and my stash of <a href=\"http:\/\/en.wikipedia.org\/wiki\/Gunpowder_tea\" target=\"_blank\">Gunpowder Green Tea<\/a> (which I picked up in New York City while the Scripting Wife and I toured China Town with Rich Prescott).<\/p>\n<p>Anyway JD, with Windows PowerShell, you can do anything. But if I had to guess, I would think that the presenter demonstrated using the <b>Out-GridView<\/b> cmdlet. For one thing, <b>Out-GridView<\/b> makes for a great demonstration. For another thing, <b>Out-GridView<\/b> is very useful&mdash;especially for admin types or for others who need to drill-down into potential problem areas.<\/p>\n<p>It is very useful to use the <b>Out-GridView<\/b> cmdlet to aid in parsing event logs. For example, the following command obtains all of the events from the <b>Application<\/b><i> <\/i>log and pipes the resulting <b>EventLog<\/b> entry objects to the <b>Out-GridView<\/b> cmdlet for further processing.<\/p>\n<p style=\"padding-left: 30px\">Get-EventLog application | Out-GridView<\/p>\n<p>At first glance, the output appears a bit overwhelming. The nice thing about the command is that it retrieves information and displays it in the grid much faster than opening the Event Viewer. One reason for this apparent performance increase is that the Windows PowerShell command only retrieves information from one specific event log; whereas, the Event Viewer has many more touch points to address. The resulting GridView control appears in the image that follows.<\/p>\n<p><a href=\"https:\/\/devblogs.microsoft.com\/wp-content\/uploads\/sites\/29\/2019\/02\/2133.hsg-5-2-12-01.png\"><img decoding=\"async\" src=\"https:\/\/devblogs.microsoft.com\/wp-content\/uploads\/sites\/29\/2019\/02\/2133.hsg-5-2-12-01.png\" alt=\"Image of command output\" title=\"Image of command output\" \/><\/a><\/p>\n<p>After the grid contains the event log information, use the <i>Filter <\/i>or the <i>Criteria <\/i>parameter<i> <\/i>to filter the displayed data. By using the <i>Filter <\/i>parameter, you can easily search for text anywhere it might appear in the grid. By using a simple filter like <b>AppCrash<\/b>, you retrieve any events from the Windows Application log that contain the letters <b>AppCrash<\/b> anywhere in the event log record. The image that follows illustrates this technique.<\/p>\n<p><a href=\"https:\/\/devblogs.microsoft.com\/wp-content\/uploads\/sites\/29\/2019\/02\/5086.hsg-5-2-12-02.png\"><img decoding=\"async\" src=\"https:\/\/devblogs.microsoft.com\/wp-content\/uploads\/sites\/29\/2019\/02\/5086.hsg-5-2-12-02.png\" alt=\"Image of command output\" title=\"Image of command output\" \/><\/a><\/p>\n<p>If you know which column contains the information you seek, there are a couple of options available. You can use the column name<i> <\/i>with a colon separator and the search value to limit the search to a specific column. If you use two column names and values, the two filter parameters are <i>anded <\/i>together&mdash;that is, the filter uses both values in the search, and the results must meet both values to display. The filter, that is shown here looks for event log entries that are of the type <b>Information<\/b> and records that have an instance ID of 1001.<\/p>\n<p style=\"padding-left: 30px\">entrytype:information instanceID:1001<\/p>\n<p>The filter applies dynamically to the output in the GridView control. When the typing is complete, the following displays in the control.<\/p>\n<p><a href=\"https:\/\/devblogs.microsoft.com\/wp-content\/uploads\/sites\/29\/2019\/02\/8713.hsg-5-2-12-03.png\"><img decoding=\"async\" src=\"https:\/\/devblogs.microsoft.com\/wp-content\/uploads\/sites\/29\/2019\/02\/8713.hsg-5-2-12-03.png\" alt=\"Image of command output\" title=\"Image of command output\" \/><\/a><\/p>\n<p>When you have completed searching through the data, pressing the red X in the upper-right corner removes the filter and returns all of the unfiltered event log data to the control.<\/p>\n<p>JD, that is all there is to using the <b>Out-GridView<\/b> cmdlet to filter event log data. Join me tomorrow when I will talk about using search criteria to filter information in the GridView control. &nbsp;&nbsp;<\/p>\n<p>I invite you to follow me on <a href=\"http:\/\/bit.ly\/scriptingguystwitter\" target=\"_blank\">Twitter<\/a> and <a href=\"http:\/\/bit.ly\/scriptingguysfacebook\" target=\"_blank\">Facebook<\/a>. If you have any questions, send email to me at <a href=\"mailto:scripter@microsoft.com\" target=\"_blank\">scripter@microsoft.com<\/a>, or post your questions on the <a href=\"http:\/\/bit.ly\/scriptingforum\" target=\"_blank\">Official Scripting Guys Forum<\/a>. See you tomorrow. Until then, peace.<\/p>\n<p><b>Ed Wilson, Microsoft Scripting Guy<\/b>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Summary: Learn how to use a simple Windows PowerShell cmdlet to search event logs for errors. &nbsp;Hey, Scripting Guy! I was at a recent SQL Saturday event, and there was a person there (unfortunately, I do not remember his name) who was talking about Windows PowerShell. In his talk, he showed something that was pretty [&hellip;]<\/p>\n","protected":false},"author":596,"featured_media":87096,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1],"tags":[97,51,98,3,4,45],"class_list":["post-9551","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-scripting","tag-event-logs","tag-getting-started","tag-logs-and-monitoring","tag-scripting-guy","tag-scripting-techniques","tag-windows-powershell"],"acf":[],"blog_post_summary":"<p>Summary: Learn how to use a simple Windows PowerShell cmdlet to search event logs for errors. &nbsp;Hey, Scripting Guy! I was at a recent SQL Saturday event, and there was a person there (unfortunately, I do not remember his name) who was talking about Windows PowerShell. In his talk, he showed something that was pretty [&hellip;]<\/p>\n","_links":{"self":[{"href":"https:\/\/devblogs.microsoft.com\/scripting\/wp-json\/wp\/v2\/posts\/9551","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/devblogs.microsoft.com\/scripting\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/devblogs.microsoft.com\/scripting\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/scripting\/wp-json\/wp\/v2\/users\/596"}],"replies":[{"embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/scripting\/wp-json\/wp\/v2\/comments?post=9551"}],"version-history":[{"count":0,"href":"https:\/\/devblogs.microsoft.com\/scripting\/wp-json\/wp\/v2\/posts\/9551\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/scripting\/wp-json\/wp\/v2\/media\/87096"}],"wp:attachment":[{"href":"https:\/\/devblogs.microsoft.com\/scripting\/wp-json\/wp\/v2\/media?parent=9551"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/scripting\/wp-json\/wp\/v2\/categories?post=9551"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/scripting\/wp-json\/wp\/v2\/tags?post=9551"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}