Get-WinEvent
Read the Windows event log
Get-WinEvent -LogName System -MaxEvents 20
- Works on
- Windows
- PowerShell
- 5.1 and later
- Reference
- Microsoft Learn: Get-WinEvent
The event log is where Windows records crashes, failed updates, unexpected shutdowns, and service errors. Get-WinEvent reads it without opening Event Viewer.
The Security log needs an administrator window. System and Application do not.
Common parameters
-LogName SystemorApplication.Get-WinEvent -ListLog *lists them all.-MaxEvents 20keeps it short. Newest come first.-FilterHashtablefilters fast by level, ID, or time.
Try this
Errors (level 2) from the last 24 hours:
Get-WinEvent -FilterHashtable @{ LogName = 'System'; Level = 2; StartTime = (Get-Date).AddDays(-1) } |
Select-Object TimeCreated, Id, ProviderName, Message
Why did the PC restart? Event 1074 records who or what asked for it:
Get-WinEvent -FilterHashtable @{ LogName = 'System'; Id = 1074 } -MaxEvents 5 |
Format-List TimeCreated, Message
Windows PowerShell 5.1 also has the older Get-EventLog. It was removed in PowerShell 7, so learn Get-WinEvent.
Coming from another shell
| Shell | What you might type |
|---|---|
| bash / zsh | journalctl -p err -n 20 |
More in From bash and From cmd.