# Log search working in Windows 7  but not in Windows 10

**URL:** <https://forums.powershell.org/t/log-search-working-in-windows-7-but-not-in-windows-10/12901>\
**Category:** PowerShell Help\
**Created:** [July 23, 2019, 6:11pm UTC](https://forums.powershell.org/t/log-search-working-in-windows-7-but-not-in-windows-10/12901 "2019-07-23T18:11:33Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![andrew-rasdell](https://avatars.discourse-cdn.com/v4/letter/a/a87d85/32.png) [@andrew-rasdell](https://forums.powershell.org/u/andrew-rasdell)\
**Post date:** [July 23, 2019, 6:11pm UTC](https://forums.powershell.org/t/log-search-working-in-windows-7-but-not-in-windows-10/12901/1 "2019-07-23T18:11:33Z")

</div>

Windows 7 x64 PSVersion 5.1.1.14409.1018 - below runs with no issues

```
$cmp = 'localhost'

$time = (Get-Date) - (new-timeSpan -day 2)

$events = Get-WinEvent -cn $cmp -FilterHashtable @{ logname = '*'; level = 1, 2, 3, 4; starttime = $time }
```

Windows 10 x 64 PSVersion 5.1.16299.1146 - the above won’t run, I am missing something here -

```
Get-WinEvent : The data is invalid
At line:7 char:11
+ $events = Get-WinEvent -cn $cmp -FilterHashtable @{ logname = '*'; le ...
+ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
+ CategoryInfo : NotSpecified: (:) [Get-WinEvent], EventLogInvalidDataException
+ FullyQualifiedErrorId : The data is invalid,Microsoft.PowerShell.Commands.GetWinEventCommand
```

It appears the filtering can no longer deal with the logname=‘\*’

Appreciate any pointers

---

<div class="post-metadata">

**Author:** ![kvprasoon](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.powershell.org/kvprasoon/32/4449_2.png) [@kvprasoon](https://forums.powershell.org/u/kvprasoon)\
**Post date:** [July 23, 2019, 9:46pm UTC](https://forums.powershell.org/t/log-search-working-in-windows-7-but-not-in-windows-10/12901/2 "2019-07-23T21:46:33Z")

</div>

Yup, it doesn’t accept \* in Win 7

---

<div class="post-metadata">

**Author:** ![andrew-rasdell](https://avatars.discourse-cdn.com/v4/letter/a/a87d85/32.png) [@andrew-rasdell](https://forums.powershell.org/u/andrew-rasdell)\
**Post date:** [July 24, 2019, 4:09pm UTC](https://forums.powershell.org/t/log-search-working-in-windows-7-but-not-in-windows-10/12901/3 "2019-07-24T16:09:26Z")

</div>

I have knocked this together - it seems to be doing the trick - I’ll refine and push on - cheers

$cmp=‘localhost’

$time = (Get-Date) - (new-timeSpan -hour 1)

$Events=Get-WinEvent -filterhashtable @{Logname = ($LogName=(Get-WinEvent -ListLog \* -ComputerName $cmp| where {$\_.recordcount -gt 0} | Select-Object -ExpandProperty LogName)); starttime = $time}

$Events | select-object -property TimeCreated, Providername, LogName, ID, Message | Sort-Object -Property TimeCreated -Descending | Export-Csv “c:\temp$cmp.csv”

---

<div class="post-metadata">

**Author:** ![andrew-rasdell](https://avatars.discourse-cdn.com/v4/letter/a/a87d85/32.png) [@andrew-rasdell](https://forums.powershell.org/u/andrew-rasdell)\
**Post date:** [July 30, 2019, 8:24pm UTC](https://forums.powershell.org/t/log-search-working-in-windows-7-but-not-in-windows-10/12901/4 "2019-07-30T20:24:20Z")

</div>

Just posting what I am now using on W10-1709 - seems to work well and plenty of scope to refine the details returned

$time = (Get-Date) - (new-timeSpan -hour 5)  
$EventLogNames = (Get-WinEvent -ListLog \* -ComputerName $cmp | where { $\_.recordcount -gt 0 } | select-object -ExpandProperty LogName)

Get-WinEvent -FilterHashtable @{ LogName = $EventLogNames; starttime = $time } -ComputerName $cmp |  
select-object -property TimeCreated, Providername, LogName, ID, @{ n = “Error Level”; e = { switch ($_.level) { “1”{ “Critical” } “2”{ “Error” } “3”{ “Warning” } “4”{ “Information” } } } }, @{ n = “Message”; e = { ($_.message).trim() } } |  
Sort-Object -Property TimeCreated -Descending

---

<div class="post-metadata">

**Author:** ![dotnVo](https://avatars.discourse-cdn.com/v4/letter/d/4af34b/32.png) [@dotnVo](https://forums.powershell.org/u/dotnVo)\
**Post date:** [May 16, 2024, 8:31pm UTC](https://forums.powershell.org/t/log-search-working-in-windows-7-but-not-in-windows-10/12901/5 "2024-05-16T20:31:52Z")

</div>


