使用Get-WinEvent获取事件时ReplacementStrings属性不显示
解决Get-WinEvent无法显示ReplacementStrings属性的问题
不需要启用任何系统设置,问题根源在于Get-WinEvent和Get-EventLog返回的对象类型不同,默认输出的属性集合存在差异:
Get-EventLog返回EventLogEntry对象,默认属性列表包含ReplacementStringsGet-WinEvent返回EventLogRecord对象,默认输出不会展示ReplacementStrings,但该属性实际是存在的
你可以通过以下几种方式查看该属性:
- 指定选择ReplacementStrings属性
Get-WinEvent -LogName System -MaxEvents 5 | Select-Object Id, ReplacementStrings
- 展开ReplacementStrings属性
如果需要直接查看属性内的具体内容,可使用-ExpandProperty:
Get-WinEvent -LogName System -MaxEvents 5 | Select-Object -ExpandProperty ReplacementStrings
- 显示对象所有属性
用Format-List *可以列出该对象的全部属性,自然包含ReplacementStrings:
Get-WinEvent -LogName System -MaxEvents 5 | Format-List *
内容的提问来源于stack exchange,提问作者Joe Joe
相关产品推荐
相关产品推荐

