# Win32\_ntlogevent filtering

**URL:** <https://forums.powershell.org/t/win32-ntlogevent-filtering/23469>\
**Category:** PowerShell Help\
**Created:** [January 24, 2024, 10:23am UTC](https://forums.powershell.org/t/win32-ntlogevent-filtering/23469 "2024-01-24T10:23:40Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![herngyih](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.powershell.org/herngyih/32/5173_2.png) [@herngyih](https://forums.powershell.org/u/herngyih)\
**Post date:** [January 24, 2024, 10:23am UTC](https://forums.powershell.org/t/win32-ntlogevent-filtering/23469/1 "2024-01-24T10:23:40Z")

</div>

The following command works for me

Get-WmiObject -Class win32\_ntlogevent|Where-Object{$_.timewritten -gt $startDate -and $_.type -ne ‘Information’}

All I want really is to determine the results count returned is not 0. I am trying to make sure the server is clean within the past 7 days.I.e no warning or error logs.

I noticed the results will take times to load( logs are many). I am wondering if there is a cleaner way to do this? I can do a while loop and break it once a warning/error log is found but what if the server have none of it but tons of information logs which equally taking a long time.

---

<div class="post-metadata">

**Author:** ![tonyd](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.powershell.org/tonyd/32/1041_2.png) [@tonyd](https://forums.powershell.org/u/tonyd)\
**Post date:** [January 24, 2024, 5:17pm UTC](https://forums.powershell.org/t/win32-ntlogevent-filtering/23469/2 "2024-01-24T17:17:08Z")

</div>

I do something similar as you. Bottom line, if you dont limit the logs that it queries and query them all, i t will simply take time. It also depends on the size of your log files.

With Get–WmiObject deprecated and indications that Get-CimInstance has significant performance gains, have you tried that simple change?

---

<div class="post-metadata">

**Author:** ![herngyih](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.powershell.org/herngyih/32/5173_2.png) [@herngyih](https://forums.powershell.org/u/herngyih)\
**Post date:** [January 26, 2024, 7:02am UTC](https://forums.powershell.org/t/win32-ntlogevent-filtering/23469/3 "2024-01-26T07:02:29Z")

</div>

Thanks again. I appreciate you helping out again. Do you think Get-Ciminstance using dcom will help much? Because my environment doesnt accept pure cIM/WSMAN. Btw,I discovered Get-Winevent really speed up the process.

---

<div class="post-metadata">

**Author:** ![tonyd](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.powershell.org/tonyd/32/1041_2.png) [@tonyd](https://forums.powershell.org/u/tonyd)\
**Post date:** [January 29, 2024, 4:41pm UTC](https://forums.powershell.org/t/win32-ntlogevent-filtering/23469/4 "2024-01-29T16:41:21Z")

</div>

> [@herngyih](#):
>
> Do you think Get-Ciminstance using dcom will help much?

I honestly dont know and have not done any testing.

I also use Get-WinEvent when appropriate. I do believe the primary reason for Get-CimInstance/WmiObject is the ease of querying all logs on the system without detecting all the logs and looping which you would need for Get-WinEvent. At least that is why I chose that method.

It should also be noted that when using Get-WinEvent, queries via either -FilterHashTable or -FilterXPath greatly increases the performance of the task.

---

<div class="post-metadata">

**Author:** ![herngyih](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.powershell.org/herngyih/32/5173_2.png) [@herngyih](https://forums.powershell.org/u/herngyih)\
**Post date:** [January 29, 2024, 11:35pm UTC](https://forums.powershell.org/t/win32-ntlogevent-filtering/23469/5 "2024-01-29T23:35:31Z")

</div>

yes. Using get-winevent with -filterhashtable i can see significant improvement. I appreciate your answers

---

<div class="post-metadata">

**Author:** ![tonyd](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.powershell.org/tonyd/32/1041_2.png) [@tonyd](https://forums.powershell.org/u/tonyd)\
**Post date:** [January 30, 2024, 10:30pm UTC](https://forums.powershell.org/t/win32-ntlogevent-filtering/23469/6 "2024-01-30T22:30:31Z")

</div>

> [@tonyd](#):
>
> It should also be noted that when using Get-WinEvent, queries via either -FilterHashTable or -FilterXPath greatly increases the performance of the task

Well … I could not leave well enough alone. I decided to rewrite my script using Get-WinEvent in a loop of all the logs and the performance increase is amazing. Using CimInstance with win32\_ntlogevent| was taking 12 minutes. Changing to Get-WinEvent in a loop of the logs went down to 6 Seconds !! The results are accurate as well. Thanks for getting me motivated 🙂

---

<div class="post-metadata">

**Author:** ![herngyih](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.powershell.org/herngyih/32/5173_2.png) [@herngyih](https://forums.powershell.org/u/herngyih)\
**Post date:** [January 31, 2024, 12:59am UTC](https://forums.powershell.org/t/win32-ntlogevent-filtering/23469/7 "2024-01-31T00:59:51Z")

</div>

That says a lot about the preformance. I am going to stick to get-winevent for a while

---

<div class="post-metadata">

**Author:** ![dotnVo](https://avatars.discourse-cdn.com/v4/letter/d/4af34b/32.png) [@dotnVo](https://forums.powershell.org/u/dotnVo)\
**Post date:** [March 4, 2024, 8:10pm UTC](https://forums.powershell.org/t/win32-ntlogevent-filtering/23469/8 "2024-03-04T20:10:30Z")

</div>


