-
-
Notifications
You must be signed in to change notification settings - Fork 69
Expand file tree
/
Copy pathWrite-Events.ps1
More file actions
21 lines (18 loc) · 694 Bytes
/
Copy pathWrite-Events.ps1
File metadata and controls
21 lines (18 loc) · 694 Bytes
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
Import-Module PSEventViewer -Force
# Classic Event Log source. Registering a missing source is explicit.
Write-EVXEvent `
-LogName Application `
-ProviderName Contoso-App `
-Id 1000 `
-Message 'Service started' `
-CreateSource `
-Confirm:$false
# Registered manifest/ETW provider. The payload is validated and converted from
# the provider template before Windows receives it.
$Result = Write-EVXEvent `
-ProviderName Microsoft-Windows-PowerShell `
-Id 4100 `
-Payload @('Context', 'User data', 'Payload') `
-Confirm:$false
$Result | Select-Object Success, NativeStatus, PayloadCount,
@{ Name = 'LogName'; Expression = { $_.Definition.LogName } }