# Get-WinEvent filterhashtable AND path?

**URL:** <https://forums.powershell.org/t/get-winevent-filterhashtable-and-path/6458>\
**Category:** PowerShell Help\
**Created:** [May 15, 2016, 10:22pm UTC](https://forums.powershell.org/t/get-winevent-filterhashtable-and-path/6458 "2016-05-15T22:22:24Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![cody-everingham](https://avatars.discourse-cdn.com/v4/letter/c/71e660/32.png) [@cody-everingham](https://forums.powershell.org/u/cody-everingham)\
**Post date:** [May 15, 2016, 10:22pm UTC](https://forums.powershell.org/t/get-winevent-filterhashtable-and-path/6458/1 "2016-05-15T22:22:24Z")

</div>

This works Get-WinEvent -FilterHashtable @{logname=‘Application’} This doesn’t Get-WinEvent -path C:\somevent.evtx -FilterHashtable @{logname=‘Application’}. Does anyone know if you can specify a specific event log when filtering instead of the computers current one?

---

<div class="post-metadata">

**Author:** ![cody-everingham](https://avatars.discourse-cdn.com/v4/letter/c/71e660/32.png) [@cody-everingham](https://forums.powershell.org/u/cody-everingham)\
**Post date:** [May 15, 2016, 10:28pm UTC](https://forums.powershell.org/t/get-winevent-filterhashtable-and-path/6458/2 "2016-05-15T22:28:41Z")

</div>

I have no clue how I missed this.  
Get-winevent -FilterHashtable @{Path="C:\somevent.evtx; logname=‘Application’}  
Anyways I simply needed to do the above to solve my issue.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex019/uploads/powershell/original/1X/385e4f9fe133561ad30a814262fe0e0ae6bc3ef0.png) [@system](https://forums.powershell.org/u/system)\
**Post date:** [May 15, 2016, 10:30pm UTC](https://forums.powershell.org/t/get-winevent-filterhashtable-and-path/6458/3 "2016-05-15T22:30:05Z")

</div>

You would just use -FilterHashtable and add a Path key to it:

```
Get-WinEvent -FilterHashtable @{ LogName = 'Application'; Path = 'C:\someevent.evtx' }
```

[https://technet.microsoft.com/library/5fe94870-ed6b-4ce2-9500-93846cc65c95(v=wps.630).aspx](https://technet.microsoft.com/library/5fe94870-ed6b-4ce2-9500-93846cc65c95%28v=wps.630%29.aspx) has all the details. 🙂

---

<div class="post-metadata">

**Author:** ![dotnVo](https://avatars.discourse-cdn.com/v4/letter/d/4af34b/32.png) [@dotnVo](https://forums.powershell.org/u/dotnVo)\
**Post date:** [May 16, 2024, 8:41pm UTC](https://forums.powershell.org/t/get-winevent-filterhashtable-and-path/6458/4 "2024-05-16T20:41:24Z")

</div>


