CJSmith dot me

I dump stuff I find useful here

Filtering in Event Viewer Windows Server 2008 onwards

Published / by Chris Smith / Leave a Comment

The Event Viewer from Server 2008 onwards is XML based.
Filters based on XML syntax can be used such as:

<QueryList>
  <Query Id="0" Path="System">
    <Select Path="System"> 
                 *[EventData[Data and (Data='<Search Parameter>')]] 
              </Select>
  </Query>
</QueryList>
 
<QueryList>
  <Query Id="0" Path="Application">
    <Select Path="Application">
                 *[EventData[Data and (Data='<Search Parameter>')]] 
              </Select>
  </Query>
</QueryList>

You can search for anything which appears in the data section such as service names, error messages etc..

- <EventData>
  <Data Name="param1">Service Display Name</Data> 
  <Data Name="param2">Details</Data> 
  <Data Name="param3">Details</Data> 
  <Data Name="param4">Service Name</Data> 
  </EventData>
  </Event>

Notes:
MS Technet

Leave a Reply