You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Windows任务计划程序添加事件小时过滤条件的XPath实现咨询

问题1:是否可以添加TimeCreated条件?

可以实现,Windows事件日志的SystemTime属性使用ISO 8601格式的UTC时间字符串,时序和字符串字典序完全一致,在XPath 1.0下可直接通过字符串比较实现时间筛选:

  • 如果是固定时间点之前的所有事件,直接对@SystemTime做字符串比较即可,比如筛选所有UTC时间2024年1月1日0点前的事件,条件为TimeCreated/@SystemTime < '2024-01-01T00:00:00.0000000Z'
  • 如果是每天固定x点前的事件,可通过substring()方法截取时间部分比较,比如筛选每天UTC时间5点前的事件,条件为substring(TimeCreated/@SystemTime, 12, 5) < '05:00'

完整的查询示例如下:

<QueryList>
  <Query Id="0" Path="Cisco AnyConnect Secure Mobility Client">
    <Select Path="Cisco AnyConnect Secure Mobility Client">
    *[System[Provider[@Name='acvpnagent'] and (EventID=2039) and TimeCreated/@SystemTime < '2024-01-01T00:00:00.0000000Z']]
    </Select>
  </Query>
</QueryList>

注意:SystemTime为UTC时间,若你要使用本地时间的x点,需要先将本地时间转换为UTC时间再写入查询条件,避免时差导致筛选错误。

问题2:Windows 10是否仅支持XPath 1.0?

是的,Windows系统的事件日志查询功能从Vista到Win10/11均只支持XPath 1.0语法,不支持XPath 2.0及以上版本的函数和特性。

内容的提问来源于stack exchange,提问作者Joel Christophel

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.09.28 10:06:03