You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

PowerShell Get-WinEvent按关键词与提供程序名查询报错排查

Fixing "The specified image file did not contain a resource section" in PowerShell Event Log Tool

Hey there! As a fellow PowerShell learner, I totally get how frustrating this random error can be when your tool mostly works but breaks on specific filters. Let's break down why this happens and how to fix it.

Why You're Seeing This Error

That Get-WinEvent error almost always comes down to old or corrupted event log entries. When you filter by keywords or provider names, PowerShell tries to load metadata (like friendly message text) for matching entries. If an entry's source program is no longer installed, or its resource files are missing, PowerShell throws that "no resource section" error—and sometimes spits out unrelated old logs as a side effect.

Solution 1: Use XPath Filters (More Efficient)

Instead of relying on Get-WinEvent's built-in -ProviderName or -Message parameters, use an XPath query. This skips the resource loading step for filtering, so you avoid the error entirely. Here's how to adapt your code:

# Example: Filter by provider name and keyword
$targetProvider = "Your-Provider-Name"
$searchKeyword = "your-keyword"

# Build the XPath query
$xpath = @"
*[
    System/Provider[@Name='$targetProvider'] and
    (EventData/Data[contains(.,'$searchKeyword')] or Message[contains(.,'$searchKeyword')])
]
"@

# Run the query with error handling to skip bad entries
Get-WinEvent -LogName Application -FilterXPath $xpath -ErrorAction SilentlyContinue

The -ErrorAction SilentlyContinue flag will skip any problematic log entries instead of crashing your script.

Solution 2: Filter After Fetching Logs (Simpler for Beginners)

If XPath feels intimidating, you can first fetch all relevant logs (with error handling) and then filter them in memory. This avoids the resource loading issue because you're working with the raw event objects:

# Get all events first, skipping errors
$allEvents = Get-WinEvent -LogName Application -ErrorAction SilentlyContinue

# Filter for provider name and keyword
$filteredEvents = $allEvents | Where-Object {
    $_.ProviderName -eq "Your-Provider-Name" -and
    $_.Message -match $searchKeyword
}

# Output the results
$filteredEvents

Note: This might be slower for large log sets, but it's straightforward and reliable.

Quick Tweaks for Your Existing Script

  • Add -ErrorAction SilentlyContinue to every Get-WinEvent call to prevent single bad entries from breaking the whole tool.
  • If you're using -Message for keyword searches, switch to -FilterXPath or post-fetch filtering as above—this is the main trigger for the resource error.

内容的提问来源于stack exchange,提问作者RRice

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.29 06:54:48