You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何用New-ScheduledTaskTrigger创建Windows事件ID触发的计划任务

Event-Triggered Scheduled Task in PowerShell 5.1 (Replace Only the $Trigger Block)

Got it, I’ve run into this exact scenario before—PowerShell 5.1’s New-ScheduledTaskTrigger doesn’t have a built-in parameter for event log triggers, so you have to use the underlying COM objects to build the trigger manually. Here’s how to replace your existing $Trigger section without rewriting the rest of your script:

Step 1: Replace the $Trigger Block

Swap out your current $Trigger = New-ScheduledTaskTrigger -At 4:00am -Daily line with this code. Adjust the event query XML to match your specific event ID and log source:

# Create an event-based trigger using the Schedule.Service COM object
$taskService = New-Object -ComObject Schedule.Service
$taskService.Connect() # Connect to the local task scheduler service

# Create an event trigger (0x10 is the constant for TASK_TRIGGER_EVENT)
$Trigger = $taskService.NewTask().Triggers.Create(0x00000010)

# Define the event filter query (customize this to your needs)
$Trigger.Subscription = @"
<QueryList>
  <Query Id="0" Path="System"> <!-- Replace "System" with your target log (e.g., "Application") -->
    <Select Path="System">*[System[(EventID=1074) and Provider[@Name='User32']]]</Select>
    <!-- Replace EventID=1074 and Provider[@Name='User32'] with your event details -->
  </Query>
</QueryList>
"@

# Enable the trigger
$Trigger.Enabled = $true

Step 2: Key Customizations to Make

  • Log Path: Change "System" in the XML to the log you want to monitor (e.g., "Application", "Security", or a custom log name).
  • Event ID: Replace 1074 with your target event ID.
  • Provider Name: Adjust User32 to the provider name associated with your event (find this in the Event Viewer under the event’s "Details" tab).

Step 3: Verify Your Event Query

Before registering the task, test your query to make sure it finds the events you want:

$query = @"
<QueryList>
  <Query Id="0" Path="System">
    <Select Path="System">*[System[(EventID=1074) and Provider[@Name='User32']]]</Select>
  </Query>
</QueryList>
"@

Get-WinEvent -FilterXml $query

If this returns the expected events, your trigger is configured correctly.

Full Modified Script

Here’s how your complete script will look with the new trigger:

Copy-Item "\\networkDrive\Backups\scripts\Reset-Sessions.ps1" "c:\scripts\Reset-Sessions.ps1"

# --- Modified Trigger Block ---
$taskService = New-Object -ComObject Schedule.Service
$taskService.Connect()
$Trigger = $taskService.NewTask().Triggers.Create(0x00000010)
$Trigger.Subscription = @"
<QueryList>
  <Query Id="0" Path="System">
    <Select Path="System">*[System[(EventID=1074) and Provider[@Name='User32']]]</Select>
  </Query>
</QueryList>
"@
$Trigger.Enabled = $true
# --- End Modified Trigger Block ---

$User= 'Nt Authority\System'
$Action= New-ScheduledTaskAction -Execute "Powershell.exe" -Argument "-executionpolicy bypass -File c:\scripts\Reset-Sessions.ps1"
Register-ScheduledTask -TaskName "Reset-Sessions" -Trigger $Trigger -User $User -Action $Action -RunLevel Highest -Force

Important Notes

  • Run PowerShell as Administrator—creating event-triggered tasks requires elevated permissions.
  • If you need more complex filters (e.g., event message contains specific text), expand the XML query with additional conditions (you can use the Event Viewer’s "Filter Current Log" feature to generate valid query XML quickly).

内容的提问来源于stack exchange,提问作者Roan

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.14 07:09:21