# Get-WinEvent to XML, now what?

**URL:** <https://forums.powershell.org/t/get-winevent-to-xml-now-what/8990>\
**Category:** PowerShell Help\
**Created:** [July 10, 2017, 4:26pm UTC](https://forums.powershell.org/t/get-winevent-to-xml-now-what/8990 "2017-07-10T16:26:20Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![matthew230](https://avatars.discourse-cdn.com/v4/letter/m/3ec8ea/32.png) [@matthew230](https://forums.powershell.org/u/matthew230)\
**Post date:** [July 10, 2017, 4:26pm UTC](https://forums.powershell.org/t/get-winevent-to-xml-now-what/8990/1 "2017-07-10T16:26:20Z")

</div>

Good evening,

I’m relatively new to powershell, far more comfortable with SQL.

I need to get some data out of the event logs. I’ve managed to establish so far that I need to use Get-WinEvent and use the xml element to get the actual info I want.

So far I’ve got:

```
$filterxml = "
	
		
		    *[System[(EventID='4624')]]
			and
            (
			*[EventData[Data[@Name='LogonType'] and (Data='10')]]
            or
            *[EventData[Data[@Name='LogonType'] and (Data='2')]]
            )
		
	

"

$Events = Get-WinEvent -maxEvents 1 -Filterxml $filterXml

# Get out the event message data            
ForEach ($Event in $Events) {            
    # Convert the event to XML            
    $eventXML = [xml]$Event.ToXml() 

 #Now what?? I need to find out how to return the actual data in a form I can put into a datatable.
}
```

It seems like it should be so easy to chuck out the values to either into variables or straight into a datatable etc.

I’ve been looking for a solution for a while without any luck.

Thanks in advance for your time.

Matt

---

<div class="post-metadata">

**Author:** ![matthew230](https://avatars.discourse-cdn.com/v4/letter/m/3ec8ea/32.png) [@matthew230](https://forums.powershell.org/u/matthew230)\
**Post date:** [July 11, 2017, 2:29am UTC](https://forums.powershell.org/t/get-winevent-to-xml-now-what/8990/2 "2017-07-11T02:29:11Z")

</div>

Ah, managed to find something that helped: [xml - Working with Event Logs in Powershell - Server Fault](https://serverfault.com/questions/303967/working-with-event-logs-in-powershell)

---

<div class="post-metadata">

**Author:** ![matt-bloomfield](https://avatars.discourse-cdn.com/v4/letter/m/dec6dc/32.png) [@matt-bloomfield](https://forums.powershell.org/u/matt-bloomfield)\
**Post date:** [July 11, 2017, 4:16pm UTC](https://forums.powershell.org/t/get-winevent-to-xml-now-what/8990/3 "2017-07-11T16:16:58Z")

</div>

Ashley McGlone has some good articles explaining how to parse XML Event Data:

[https://blogs.technet.microsoft.com/ashleymcglone/2013/08/28/powershell-get-winevent-xml-madness-getting-details-from-event-logs/](https://blogs.technet.microsoft.com/ashleymcglone/2013/08/28/powershell-get-winevent-xml-madness-getting-details-from-event-logs/)

[https://blogs.technet.microsoft.com/ashleymcglone/2015/08/31/forensics-automating-active-directory-account-lockout-search-with-powershell-an-example-of-deep-xml-filtering-of-event-logs-across-multiple-servers-in-parallel/](https://blogs.technet.microsoft.com/ashleymcglone/2015/08/31/forensics-automating-active-directory-account-lockout-search-with-powershell-an-example-of-deep-xml-filtering-of-event-logs-across-multiple-servers-in-parallel/)

---

<div class="post-metadata">

**Author:** ![dotnVo](https://avatars.discourse-cdn.com/v4/letter/d/4af34b/32.png) [@dotnVo](https://forums.powershell.org/u/dotnVo)\
**Post date:** [May 16, 2024, 8:37pm UTC](https://forums.powershell.org/t/get-winevent-to-xml-now-what/8990/4 "2024-05-16T20:37:53Z")

</div>


