SOLVED

How to get event log from Server

%3CLINGO-SUB%20id%3D%22lingo-sub-2180469%22%20slang%3D%22en-US%22%3EHow%20to%20get%20event%20log%20from%20Server%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2180469%22%20slang%3D%22en-US%22%3E%3CP%3EDear%20All%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EPlease%20help%20me.%20I've%20tried%20to%20create%20PS%20script%20in%20order%20to%20get%20event%20log%20when%20file%20is%20either%20deleted%20or%20created%20by%20somebody%20on%20ShareFile%20Server.%20It's%20working%20if%20they%20just%20create%20or%20delete%20only%201%20file%20notification%20will%20be%20sent%20via%20email%20but%20when%20they%20delete%20or%20create%20more%20than%201%20file%20at%20the%20same%20time%20the%20notification%20will%20be%20sent%20only%20the%20latest%20event%20not%20all%20event.%20Anyone%20please%20help%20me.%20Please%20see%20my%20PS%20script%20below.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CPRE%20class%3D%22lia-code-sample%20language-powershell%22%3E%3CCODE%3E%24EventId%20%3D%204663%0A%0A%23%23%24A%20%3D%20Get-WinEvent%20-MaxEvents%201%20%20-FilterHashTable%20%40%7BLogname%20%3D%20%22Security%22%20%3B%20ID%20%3D%20%24EventId%7D%0A%24A%20%3D%20Get-WinEvent%20-MaxEvents%201%20%20-FilterHashTable%20%40%7BLogname%20%3D%20%22Security%22%20%3B%20ID%20%3D%20%24EventId%7D%20%7C%20Where%20%7B%24_.properties%5B10%5D.value%20-eq%20%220x4%22%7D%0A%23%23Get-WinEvent%20-MaxEvents%201%20%20-FilterHashTable%20%40%7BLogname%20%3D%20%22Security%22%20%3B%20ID%20%3D%204663%7D%20%7C%20Where%20%7B%24_.properties%5B10%5D.value%20-eq%20%220x4%22%7D%20%7C%20select%20*%0A%0Aforeach(%24event%20in%20%24A)%7B%0A%24EventIDA%20%3D%20%24event.Id%0A%24MachineNameA%20%3D%20%24event.MachineName%0A%24TimeA%20%3D%20%24event.TimeCreated%0A%24TaskDisplayName%20%3D%20%24event.TaskDisplayName%0A%24RecordID%20%3D%20%24event.RecordId%0A%24AccountName%20%3D%20%24event.Properties%5B1%5D.value%0A%24AccountDomain%20%3D%20%24event.Properties%5B2%5D.value%0A%24ObjectName%20%3D%20%24event.Properties%5B6%5D.value%0A%24Access%20%3D%20%24event.Properties%5B12%5D.value%0A%24test%20%3D%20%24event.Properties%0A%7D%0A%23Write-Output%20%24ObjectName'.evtx'%0A%0A%23%23Get%20date%20and%20time%20to%20create%20event%20log%20file%20--Comment%0A%24logfile%20%3D%20get-date%20-Format%20yyyyMMdd_hhmmsstt%0A%0A%23%23Export%20event%20log%20to%20.evtx%20file%0A%24EventSession%20%3D%20New-Object%20System.Diagnostics.Eventing.Reader.EventLogSession%0A%23%24EventSession.ExportLog('Security'%2C'LogName'%2C%22*%5BSystem%5BEventRecordID%20%3D%20%24RecordID%5D%5D%22%2C%20%22E%3A%5CBackupEventLog%5CRecordID.evtx%22)%0A%24EventSession.ExportLog('Security'%2C'LogName'%2C%22*%5BSystem%5BEventRecordID%20%3D%20%24RecordID%5D%5D%22%2C%20%22E%3A%5CBackupEventLog%5CRecordID.evtx%22)%0ARename-Item%20-Path%20%22E%3A%5CBackupEventLog%5CRecordID.evtx%22%20-NewName%20%22%24logfile.evtx%22%0A%0A%0A%0A%24EmailFrom%20%3D%20%22MyShareFileServer%22%0A%24EmailTo%20%3D%20%22My%20Email%22%2C%20%22My%20Colleague%20Email%22%0A%24Subject%20%3D%22Alert%20From%20%24MachineNameA%22%0A%24MessageA%20%3D%20%24A.Message%0A%0A%24BodyA%20%3D%20%22Event%20log%20URL%3A%20%5C%5CServer%20IP%20Address%5CE%24%5CBackupEventLog%20%0A%60nNotification%20message%20%0A%60----------------------------------------------%0A%60EventID%3A%20%24EventIDA%60nMachineName%3A%20%24MachineNameA%20%60nTime%3A%20%24TimeA%20%60nTask%20Display%20Name%3A%20%24TaskDisplayName%20%60nLogin%20Name%3A%20%24AccountDomain%5C%24AccountName%20%60nPath%3A%20%24ObjectName%20%60nMessage%3A%20%24MessageA%22%0A%23%23%24BodyB%20%3D%20%22EventID%3A%20%24EventIDB%60nSource%3A%20%24SourceB%60nMachineName%3A%20%24MachineNameB%20%60nTime%3A%20%24TimeB%20%60nMessage%3A%20%24MessageB%22%0A%0A%24SMTPServer%20%3D%20%22SMTP%20IP%20Address%22%0A%24SMTPClient%20%3D%20New-Object%20Net.Mail.SmtpClient(%24SmtpServer%2C%20587)%0A%24SMTPClient.EnableSsl%20%3D%20%24true%0ASend-MailMessage%20-SmtpServer%20%24SMTPServer%20-From%20%24EmailFrom%20-To%20%24EmailTo%20-Subject%20%24Subject%20-Body%20%22%24BodyA%22%20-Attachments%20%22E%3A%5CBackupEventLog%5C%24logfile.evtx%22%3C%2FCODE%3E%3C%2FPRE%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-2180469%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EWindows%20PowerShell%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2181439%22%20slang%3D%22en-US%22%3ERe%3A%20How%20to%20get%20event%20log%20from%20Server%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2181439%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F981787%22%20target%3D%22_blank%22%3E%40theyounngun%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3EHi%3C%2FP%3E%3CP%3EYou%20can%20check%20the%20schedule%20history%20and%20see%20what%20happens%20and%20how%20the%20task%20was%20executed%2C%20probably%20you%20will%20find%20something%20like%26nbsp%3B%3CSTRONG%3ETask%20Scheduler%20did%20not%20launch%20task%20%22%5CMyScriptName%22%20because%20instance%20%22%7B317256a8-7ddf-4cf8-8267-90ab66c84907%7D%22%20of%20the%20same%20task%20is%20already%20running.%3C%2FSTRONG%3E%3C%2FP%3E%3CP%3EThe%20Delete%20event%20log%20are%20listed%20one%20each%20another%20and%20I%20think%20that%20the%20Task%20Scheduler%20won't%20start%20the%20script%20as%20another%20instance%20is%20running.%3C%2FP%3E%3CP%3EWhat%20you%20can%20do%20is%20add%20a%20small%20delay%20to%20the%20script%20and%20let%20the%20script%20read%20multiple%20events%20and%20send%20them%20in%20one%20report%2C%20instead%20of%20having%20each%20event%20sent%20alone%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2183661%22%20slang%3D%22en-US%22%3ERe%3A%20How%20to%20get%20event%20log%20from%20Server%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2183661%22%20slang%3D%22en-US%22%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F790105%22%20target%3D%22_blank%22%3E%40farismalaeb%3C%2FA%3E%3CBR%20%2F%3EHi%3CBR%20%2F%3ECan%20you%20guide%20me%20what%20kind%20of%20command%20or%20how%20to%20add%20a%20small%20delay%20to%20script%20%3F%20I'm%20not%20good%20at%20PS%20script.%20By%20the%20way%20do%20I%20have%20to%20make%20a%20change%20%22MaxEvents%22%20%3F%3CBR%20%2F%3E%3CBR%20%2F%3EThank%20you.%3CBR%20%2F%3E%3C%2FLINGO-BODY%3E
Occasional Contributor

Dear All,

 

Please help me. I've tried to create PS script in order to get event log when file is either deleted or created by somebody on ShareFile Server. It's working if they just create or delete only 1 file notification will be sent via email but when they delete or create more than 1 file at the same time the notification will be sent only the latest event not all event. Anyone please help me. Please see my PS script below.

 

 

 

$EventId = 4663

##$A = Get-WinEvent -MaxEvents 1  -FilterHashTable @{Logname = "Security" ; ID = $EventId}
$A = Get-WinEvent -MaxEvents 1  -FilterHashTable @{Logname = "Security" ; ID = $EventId} | Where {$_.properties[10].value -eq "0x4"}
##Get-WinEvent -MaxEvents 1  -FilterHashTable @{Logname = "Security" ; ID = 4663} | Where {$_.properties[10].value -eq "0x4"} | select *

foreach($event in $A){
$EventIDA = $event.Id
$MachineNameA = $event.MachineName
$TimeA = $event.TimeCreated
$TaskDisplayName = $event.TaskDisplayName
$RecordID = $event.RecordId
$AccountName = $event.Properties[1].value
$AccountDomain = $event.Properties[2].value
$ObjectName = $event.Properties[6].value
$Access = $event.Properties[12].value
$test = $event.Properties
}
#Write-Output $ObjectName'.evtx'

##Get date and time to create event log file --Comment
$logfile = get-date -Format yyyyMMdd_hhmmsstt

##Export event log to .evtx file
$EventSession = New-Object System.Diagnostics.Eventing.Reader.EventLogSession
#$EventSession.ExportLog('Security','LogName',"*[System[EventRecordID = $RecordID]]", "E:\BackupEventLog\RecordID.evtx")
$EventSession.ExportLog('Security','LogName',"*[System[EventRecordID = $RecordID]]", "E:\BackupEventLog\RecordID.evtx")
Rename-Item -Path "E:\BackupEventLog\RecordID.evtx" -NewName "$logfile.evtx"



$EmailFrom = "MyShareFileServer"
$EmailTo = "My Email", "My Colleague Email"
$Subject ="Alert From $MachineNameA"
$MessageA = $A.Message

$BodyA = "Event log URL: \\Server IP Address\E$\BackupEventLog 
`nNotification message 
`----------------------------------------------
`EventID: $EventIDA`nMachineName: $MachineNameA `nTime: $TimeA `nTask Display Name: $TaskDisplayName `nLogin Name: $AccountDomain\$AccountName `nPath: $ObjectName `nMessage: $MessageA"
##$BodyB = "EventID: $EventIDB`nSource: $SourceB`nMachineName: $MachineNameB `nTime: $TimeB `nMessage: $MessageB"

$SMTPServer = "SMTP IP Address"
$SMTPClient = New-Object Net.Mail.SmtpClient($SmtpServer, 587)
$SMTPClient.EnableSsl = $true
Send-MailMessage -SmtpServer $SMTPServer -From $EmailFrom -To $EmailTo -Subject $Subject -Body "$BodyA" -Attachments "E:\BackupEventLog\$logfile.evtx"

 

 

10 Replies
best response confirmed by theyounngun (Occasional Contributor)
Solution

@theyounngun 

Hi

You can check the schedule history and see what happens and how the task was executed, probably you will find something like Task Scheduler did not launch task "\MyScriptName" because instance "{317256a8-7ddf-4cf8-8267-90ab66c84907}" of the same task is already running.

The Delete event log are listed one each another and I think that the Task Scheduler won't start the script as another instance is running.

What you can do is add a small delay to the script and let the script read multiple events and send them in one report, instead of having each event sent alone

@farismalaeb
Hi
Can you guide me what kind of command or how to add a small delay to script ? I'm not good at PS script. By the way do I have to make a change "MaxEvents" ?

Thank you.
sleep 20
Ok thanks. I will try to add that to script and might come to you again.

Have a nice day.
Hello Farismalaeb.

I checked the command is Start-Sleep -s 20 and I have to put at the end of script Am I correct ?

Thank you
Hi,
it's better to keep it in the top
Ok Noted. I will try.

Thank so much.

@theyounngun 

Also you can try it from here

farismalaeb_0-1614925824388.png

You can delay the script to be triggered on a delay time.

 

Excellent ! Thank so much.
Hopefully, it helps you :)

Please if the Answer was helpful, Click on Best Response.