Windows-Event-Log-Messages icon indicating copy to clipboard operation
Windows-Event-Log-Messages copied to clipboard

Create a PowerShell script to build an event log library

Open iadgovuser1 opened this issue 6 years ago • 0 comments

Parse all the events.json files and find first seen and last seen of each event. A unique entry may be id,level,message, and parameters OR may be id,level,message.

One item of interest is when the message changes for an existing event ID. Either the text changes or the parameters change (used parameters versus defined parameters which may be different).

iadgovuser1 avatar Nov 10 '18 19:11 iadgovuser1