如何用New-ScheduledTaskTrigger创建Windows事件ID触发的计划任务
Got it, I’ve run into this exact scenario before—PowerShell 5.1’s New-ScheduledTaskTrigger doesn’t have a built-in parameter for event log triggers, so you have to use the underlying COM objects to build the trigger manually. Here’s how to replace your existing $Trigger section without rewriting the rest of your script:
Step 1: Replace the $Trigger Block
Swap out your current $Trigger = New-ScheduledTaskTrigger -At 4:00am -Daily line with this code. Adjust the event query XML to match your specific event ID and log source:
# Create an event-based trigger using the Schedule.Service COM object $taskService = New-Object -ComObject Schedule.Service $taskService.Connect() # Connect to the local task scheduler service # Create an event trigger (0x10 is the constant for TASK_TRIGGER_EVENT) $Trigger = $taskService.NewTask().Triggers.Create(0x00000010) # Define the event filter query (customize this to your needs) $Trigger.Subscription = @" <QueryList> <Query Id="0" Path="System"> <!-- Replace "System" with your target log (e.g., "Application") --> <Select Path="System">*[System[(EventID=1074) and Provider[@Name='User32']]]</Select> <!-- Replace EventID=1074 and Provider[@Name='User32'] with your event details --> </Query> </QueryList> "@ # Enable the trigger $Trigger.Enabled = $true
Step 2: Key Customizations to Make
- Log Path: Change
"System"in the XML to the log you want to monitor (e.g.,"Application","Security", or a custom log name). - Event ID: Replace
1074with your target event ID. - Provider Name: Adjust
User32to the provider name associated with your event (find this in the Event Viewer under the event’s "Details" tab).
Step 3: Verify Your Event Query
Before registering the task, test your query to make sure it finds the events you want:
$query = @" <QueryList> <Query Id="0" Path="System"> <Select Path="System">*[System[(EventID=1074) and Provider[@Name='User32']]]</Select> </Query> </QueryList> "@ Get-WinEvent -FilterXml $query
If this returns the expected events, your trigger is configured correctly.
Full Modified Script
Here’s how your complete script will look with the new trigger:
Copy-Item "\\networkDrive\Backups\scripts\Reset-Sessions.ps1" "c:\scripts\Reset-Sessions.ps1" # --- Modified Trigger Block --- $taskService = New-Object -ComObject Schedule.Service $taskService.Connect() $Trigger = $taskService.NewTask().Triggers.Create(0x00000010) $Trigger.Subscription = @" <QueryList> <Query Id="0" Path="System"> <Select Path="System">*[System[(EventID=1074) and Provider[@Name='User32']]]</Select> </Query> </QueryList> "@ $Trigger.Enabled = $true # --- End Modified Trigger Block --- $User= 'Nt Authority\System' $Action= New-ScheduledTaskAction -Execute "Powershell.exe" -Argument "-executionpolicy bypass -File c:\scripts\Reset-Sessions.ps1" Register-ScheduledTask -TaskName "Reset-Sessions" -Trigger $Trigger -User $User -Action $Action -RunLevel Highest -Force
Important Notes
- Run PowerShell as Administrator—creating event-triggered tasks requires elevated permissions.
- If you need more complex filters (e.g., event message contains specific text), expand the XML query with additional conditions (you can use the Event Viewer’s "Filter Current Log" feature to generate valid query XML quickly).
内容的提问来源于stack exchange,提问作者Roan

