当我运行此脚本查看旧日志文件时,它不提供任何输出,并且该数据位于文件中。
Get-ChildItem -Path c:\test\ -Recurse |
ForEach-Object {
"Parsing $($_.FullName)`r`n"
{
Get-WinEvent userid=JDOE -FilterHashtable @{
logname = Logname=$_.Fullname
id = 4624, 4634, 4674
userid = JDOE
Path = $_.FullName
Level = 2
StartTime = "4/1/16"
EndTime = "6/20/2016"
} -EA Stop
}
}