# Powershell Get-WinEvent - to iterate through all event logs

**URL:** <https://forums.powershell.org/t/powershell-get-winevent-to-iterate-through-all-event-logs/4475>\
**Category:** PowerShell Help\
**Created:** [July 5, 2015, 4:41pm UTC](https://forums.powershell.org/t/powershell-get-winevent-to-iterate-through-all-event-logs/4475 "2015-07-05T16:41:21Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![andrew-rasdell](https://avatars.discourse-cdn.com/v4/letter/a/a87d85/32.png) [@andrew-rasdell](https://forums.powershell.org/u/andrew-rasdell)\
**Post date:** [July 5, 2015, 4:41pm UTC](https://forums.powershell.org/t/powershell-get-winevent-to-iterate-through-all-event-logs/4475/1 "2015-07-05T16:41:21Z")

</div>

I am trying to write a query to iterate through all the Windows event logs, essentially to cross reference any errors of interest with a problem we are investigating on our Win 7 workstation fleet.  
$logs=(Get-WinEvent -ListLog \* | Where-Object {$\_.Recordcount -gt 0}).logname

Get-WinEvent -LogName $log -FilterXPath ‘\*[System[Level=1] or System[Level=2]]’ -MaxEvents 50 -ErrorAction SilentlyContinue

I am a little stuck in regards to filtering (-FilterXpath) for a specific date, in addition to the Level1, Level2 errors - any suggestions greatly appreciated

---

<div class="post-metadata">

**Author:** ![ganeshbabu-jeyabalan](https://avatars.discourse-cdn.com/v4/letter/g/848f3c/32.png) [@ganeshbabu-jeyabalan](https://forums.powershell.org/u/ganeshbabu-jeyabalan)\
**Post date:** [July 5, 2015, 7:28pm UTC](https://forums.powershell.org/t/powershell-get-winevent-to-iterate-through-all-event-logs/4475/2 "2015-07-05T19:28:59Z")

</div>

As building a “xpath” could be challenging, especially when dealing with dates, your best bet to construct it is using the Event Viewer GUI’s Filter current log option (yes, Even get-winevent’s help suggests that). To do that, open the Event viewer and choose the log you want to filter and choose the “Filter Current log” option and fill it with your requirements and now click on the XML tab. You should be able to see the xpath friendly xml query which can be used in your powershell code.

Ex -  
Below is the XML query for filtering all “Errors and Warnings” logged in the “Date Range” under “SYSTEM” logs

```
*[System[(Level=2 or Level=3) and TimeCreated[@SystemTime&gt;='2015-07-01T11:00:01.000Z' and @SystemTime&lt;=&#039;2015-07-06T11:00:00.999Z&#039;]]]

```

---

<div class="post-metadata">

**Author:** ![andrew-rasdell](https://avatars.discourse-cdn.com/v4/letter/a/a87d85/32.png) [@andrew-rasdell](https://forums.powershell.org/u/andrew-rasdell)\
**Post date:** [July 6, 2015, 2:50pm UTC](https://forums.powershell.org/t/powershell-get-winevent-to-iterate-through-all-event-logs/4475/3 "2015-07-06T14:50:36Z")

</div>

Thanks GJ, appreciated.

---

<div class="post-metadata">

**Author:** ![dotnVo](https://avatars.discourse-cdn.com/v4/letter/d/4af34b/32.png) [@dotnVo](https://forums.powershell.org/u/dotnVo)\
**Post date:** [May 16, 2024, 8:45pm UTC](https://forums.powershell.org/t/powershell-get-winevent-to-iterate-through-all-event-logs/4475/4 "2024-05-16T20:45:03Z")

</div>


