Network Security Internet Technology Development Database Servers Mobile Phone Android Software Apple Software Computer Software News IT Information

In addition to Weibo, there is also WeChat

Please pay attention

WeChat public account

Shulou

Windows log files find columns that meet the criteria and count

2025-01-15 Update From: SLTechnology News&Howtos shulou NAV: SLTechnology News&Howtos > Servers >

Share

Shulou(Shulou.com)06/02 Report--

Because it is necessary to count the number of windows login failures per day

"wevtutil el" / / list log name

"wevtutil gl log name" / / gets log configuration information.

You can use command and option names in the form of short (such as ep / uni) or long (such as enum-publishers / unicode).

Commands, options, and option values are not case-sensitive.

Variables are all in uppercase.

Wevtutil COMMAND [ARGUMENT [ARGUMENT]...] [/ OPTION:VALUE [/ OPT

Command:

El | enum-logs lists the log name.

Gl | get-log gets log configuration information.

Sl | set-log modifies log configuration.

Ep | enum-publishers lists the event publisher.

Gp | get-publisher gets the configuration information of the publisher.

Im | install-manifest installs event publishers and logs from the inventory.

Um | uninstall-manifest unloads event publishers and logs from the inventory.

Qe | query-events queries events from logs or log files.

Gli | get-log-info gets log status information.

Epl | export-log exports logs.

Al | Log exported by archive-log archive.

Cl | clear-log clears the log.

First export the log file to the text format wevtutil qe Security > c:\ log.txt

Log file% SystemRoot%\ System32\ Winevt\ Logs\ Security.evtx

Look for the number of login failures in a given day. "0xc000006d" login failure code

Find / n "2016-12-06" log.txt | find / c "0xc000006d"

Common methods of find

Find "ABC" d:\ test.txt, which means to look for all lines containing the string bathome in the text file test.txt under the root of the D disk.

Find / I "Abc" test.txt means case insensitive

Find / v "Abc" test.txt, which means to look for lines that do not contain the string Abc (Abc is case-sensitive), and if abc is not case-sensitive, it should be written as find / I / v "Abc" test.txt.

Find / c "abc" test.txt. Count the lines that contain a string

Find / n "abc" test.txt displays the line number at the beginning of each line

Welcome to subscribe "Shulou Technology Information " to get latest news, interesting things and hot topics in the IT industry, and controls the hottest and latest Internet news, technology news and IT industry trends.

Views: 0

*The comments in the above article only represent the author's personal views and do not represent the views and positions of this website. If you have more insights, please feel free to contribute and share.

Share To

Servers

Wechat

© 2024 shulou.com SLNews company. All rights reserved.

12
Report