{"id":145,"date":"2018-07-01T19:38:30","date_gmt":"2018-07-01T10:38:30","guid":{"rendered":"https:\/\/poga.jp\/?p=145"},"modified":"2018-10-18T07:27:25","modified_gmt":"2018-10-17T22:27:25","slug":"%e3%80%90windows%e3%80%91%e3%82%a4%e3%83%99%e3%83%b3%e3%83%88%e3%83%ad%e3%82%b0%e5%8f%96%e5%be%97%e3%82%92%e3%82%b9%e3%82%af%e3%83%aa%e3%83%97%e3%83%88%e3%81%a7%e8%87%aa%e5%8b%95%e5%8c%96%e3%81%97","status":"publish","type":"post","link":"https:\/\/poga.jp\/?p=145","title":{"rendered":"\u3010Windows\u3011\u30a4\u30d9\u30f3\u30c8\u30ed\u30b0\u53d6\u5f97\u3092\u30b9\u30af\u30ea\u30d7\u30c8\u3067\u81ea\u52d5\u5316\u3057\u305f\u3044\uff01"},"content":{"rendered":"<p>\u3061\u3087\u3063\u3068\u524d\u306b\u4ed6\u306e\u30c1\u30fc\u30e0\u304b\u3089\u306e\u5f15\u304d\u7d99\u304e\u3067\u65b0\u305f\u306a\u9867\u5ba2\u306eIT\u57fa\u76e4\u306e\u4fdd\u5b88\u904b\u7528\u62c5\u5f53\u306b\u30a2\u30b5\u30a4\u30f3\u3055\u308c\u307e\u3057\u305f\u3002<\/p>\n<p>\u305d\u306e\u969b\u306b\u5f15\u304d\u7d99\u304e\u30c9\u30ad\u30e5\u30e1\u30f3\u30c8\u306e\u904b\u7528\u624b\u9806\u66f8\u3092\u78ba\u8a8d\u3057\u3066\u3044\u305f\u3089\u3001<strong class=\"keikou\">\u6bce\u6708\u306e\u5b9a\u5e38\u904b\u7528\u306e\u4e2d\u3067\u81ea\u52d5\u5316\u3057\u305f\u307b\u3046\u304c\u52b9\u7387\u3082\u826f\u304f\u30ea\u30b9\u30af\u3082\u5c11\u306a\u304f\u306a\u308b<\/strong>\u3068\u601d\u308f\u308c\u308b\u7b87\u6240\u304c\u591a\u304b\u3063\u305f\u306e\u3067\u904b\u7528\u6539\u5584\u4f5c\u3068\u3057\u3066\u3044\u304f\u3064\u304b\u306e\u30b9\u30af\u30ea\u30d7\u30c8\u3092\u4f5c\u308a\u307e\u3057\u305f\u3002<\/p>\n<p>\u3053\u306e\u8a18\u4e8b\u3067\u306f\u305d\u306e\u6642\u306e\u6210\u679c\u7269\u306e\u5185\u3001\u3082\u3063\u3068\u3082\u6c4e\u7528\u7684\u3067\u3069\u306e\u9867\u5ba2\u306e\u904b\u7528\u306b\u3082\u4f7f\u3048\u305d\u3046\u306a<strong class=\"keikou\">\u300c\u30a4\u30d9\u30f3\u30c8\u30ed\u30b0\u81ea\u52d5\u53d6\u5f97\u30b9\u30af\u30ea\u30d7\u30c8\u300d<\/strong>\u3092\u3054\u7d39\u4ecb\u3057\u307e\u3059\u3002<br \/>\n\uff08\u203b\u3061\u306a\u307f\u306bWindows\u30b5\u30fc\u30d0\u3067\u3059\u3002\uff09<\/p>\n<p>\u30b9\u30af\u30ea\u30d7\u30c8\u306e\u5185\u5bb9\u3068\u3057\u3066\u306f\u3001Windows\u30b5\u30fc\u30d0\u306e\u300c\u30b7\u30b9\u30c6\u30e0\u300d\u3068\u300c\u30a2\u30d7\u30ea\u30b1\u30fc\u30b7\u30e7\u30f3\u300d\u306e\u30a4\u30d9\u30f3\u30c8\u30ed\u30b0\u3092\u524d\u67081\u65e5\u304b\u3089\u672b\u65e5\u307e\u3067\u306e\u671f\u9593\u3092\u4fdd\u5b58\u3059\u308b\u3068\u3044\u3046\u52d5\u304d\u3067\u3059\u3002<br \/>\n\u3053\u306e\u30b9\u30af\u30ea\u30d7\u30c8\u3092\u6bce\u67081\u65e5\u306b\u30bf\u30b9\u30af\u30b9\u30b1\u30b8\u30e5\u30fc\u30e9\u3067\u5b9f\u884c\u3055\u305b\u308b\u4e8b\u3067<strong class=\"keikou\">\u6bce\u6708\u81ea\u52d5\u7684\u306b\u30a4\u30d9\u30f3\u30c8\u30ed\u30b0\u3092\u30d0\u30c3\u30af\u30a2\u30c3\u30d7\u3059\u308b\u4e8b\u304c\u53ef\u80fd<\/strong>\u306b\u306a\u308a\u307e\u3059\u3002<\/p>\n<p>\u307e\u305a\u306f\u65e9\u901f\u30b9\u30af\u30ea\u30d7\u30c8\u306e\u4e2d\u8eab\u3092\u3054\u7d39\u4ecb\u3057\u307e\u3059\u3002<\/p>\n<pre class=\"lang:ps decode:true \" title=\"GetEvLog.ps1\" ># \u30a4\u30d9\u30f3\u30c8\u30ed\u30b0\u81ea\u52d5\u53d6\u5f97\u30b9\u30af\u30ea\u30d7\u30c8\uff08\u524d\u6708\u5206\u3092\u53d6\u5f97\uff09\r\n# \u5bfe\u5fdcOS\uff1aWindows Server 2012\u4ee5\u964d\r\n\r\n# \u53d6\u5f97\u5bfe\u8c61\u306e\u30a4\u30d9\u30f3\u30c8\u30ed\u30b0\u3068\u3057\u3066\u300c\u30b7\u30b9\u30c6\u30e0\u300d\u3068\u300c\u30a2\u30d7\u30ea\u30b1\u30fc\u30b7\u30e7\u30f3\u300d\u3092\u6307\u5b9a\u3059\u308b\r\n$lognames = @(\"System\",\"Application\")\r\n\r\n# \u5148\u6708\u6642\u70b9\u306eyyyyMM\u6587\u5b57\u5217\u3092\u53d6\u5f97\r\n$yyyyMM = (Get-Date).AddMonths(-1).ToString(\"yyyyMM\")\r\n\r\n# \u51fa\u529b\u5148\u3068\u3057\u3066\u300cC:\\EventLog\\(\u30db\u30b9\u30c8\u540d)\\yyyyMM\u300d\u30d5\u30a9\u30eb\u30c0\u3092\u6307\u5b9a\u30fb\u4f5c\u6210\u3059\u308b\u3002\r\n$dstFolder = (\"C:\\EventLog\\\" + $Env:COMPUTERNAME + \"\\\" + $yyyyMM)\r\nif((Test-Path $dstFolder) -eq $False){New-Item $dstFolder -ItemType Directory}\r\n\r\n# \u30a4\u30d9\u30f3\u30c8\u30ed\u30b0\u3092\u53d6\u5f97\u3059\u308b\u5bfe\u8c61\u306e\u671f\u9593\u3092\u6307\u5b9a\u3059\u308b\uff08\u5148\u67081\u65e5\u304b\u3089\u672b\u65e5\u307e\u3067\u306e1\u30f6\u6708\u9593\u3092\u6307\u5b9a\uff09\r\n$startJTime = (Get-Date -Day 1 -hour 0 -minute 0 -second 0).AddMonths(-1)\r\n$endJTime = (Get-Date -Day 1 -hour 0 -minute 0 -second 0)\r\n$startUtcTime = [System.TimeZoneInfo]::ConvertTimeToUtc($startJTime).ToString(\"yyyy-MM-ddTHH:mm:ssZ\")\r\n$endUtcTime = [System.TimeZoneInfo]::ConvertTimeToUtc($endJTime).ToString(\"yyyy-MM-ddTHH:mm:ssZ\")\r\n$filter = @\"\r\n  Event\/System\/TimeCreated[@SystemTime&gt;='$startUtcTime'] and\r\n  Event\/System\/TimeCreated[@SystemTime&lt;'$endUtcTime']\r\n\"@ \r\n\r\n# \u30a4\u30d9\u30f3\u30c8\u30ed\u30b0\u51fa\u529b\u7528\u306e\u30aa\u30d6\u30b8\u30a7\u30af\u30c8\u3092\u4f5c\u6210\r\n$evsession = New-Object -TypeName System.Diagnostics.Eventing.Reader.EventLogSession\r\n\r\n# \u30a4\u30d9\u30f3\u30c8\u30ed\u30b0\u3092evtx\u5f62\u5f0f\u3067\u51fa\u529b\u3059\u308b\uff08\u300cLocaleMetaData\u300d\u3082\u65e5\u672c\u8a9e\u306e\u8868\u793a\u60c5\u5831\u3067\u51fa\u529b\u3055\u305b\u308b\uff09\r\nforeach($logname in $lognames){\r\n  $outfile = $dstFolder + \"\\\" + $Env:COMPUTERNAME + \"_\" + $logname + \"_\" + $yyyyMM + \".evtx\"\r\n  $locale = [System.Globalization.CultureInfo]::CreateSpecificCulture(\"ja-JP\")\r\n  $evsession.ExportLogAndMessages($logname,\"LogName\",$filter,$outfile,$True,$locale)\r\n}\r\n\r\nWScript.Quit<\/pre>\n<p>\u4e0a\u8a18\u306e\u30c6\u30ad\u30b9\u30c8\u30dc\u30c3\u30af\u30b9\u306e\u4e0a\u90e8\u306b\u3042\u308b<strong class=\"keikou\">\u300cCopy\u300d<\/strong>\u30a2\u30a4\u30b3\u30f3\u3092\u30af\u30ea\u30c3\u30af\u3057\u3066\u30b3\u30d4\u30fc\u3057\u3001\u3054\u81ea\u8eab\u306e\u7aef\u672b\u306e\u30c6\u30ad\u30b9\u30c8\u30a8\u30c7\u30a3\u30bf\u4e0a\u306b\u8cbc\u308a\u4ed8\u3051<strong class=\"keikou\">\u300cGetEvLog.ps1\u300d<\/strong>\u3068\u3044\u3046\u540d\u524d\u3067\u4fdd\u5b58\u3057\u3066\u304f\u3060\u3055\u3044\u3002<br \/>\n\u305d\u308c\u3067\u306f\u3001\u5b9f\u969b\u306b\u4f7f\u3044\u65b9\u3092\u8aac\u660e\u3057\u3066\u3044\u304d\u307e\u3059\u3002<\/p>\n<h3>\u5b9f\u969b\u306b\u4f7f\u3063\u3066\u307f\u3088\u3046\uff01<\/h3>\n<img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/poga.jp\/wp-content\/uploads\/2018\/07\/evlog01-1024x682.png\" alt=\"\" width=\"728\" height=\"485\" class=\"alignnone size-large wp-image-151\" srcset=\"https:\/\/poga.jp\/wp-content\/uploads\/2018\/07\/evlog01-1024x682.png 1024w, https:\/\/poga.jp\/wp-content\/uploads\/2018\/07\/evlog01-300x200.png 300w, https:\/\/poga.jp\/wp-content\/uploads\/2018\/07\/evlog01-768x511.png 768w, https:\/\/poga.jp\/wp-content\/uploads\/2018\/07\/evlog01.png 1248w\" sizes=\"(max-width: 728px) 100vw, 728px\" \/>\n<p>\u307e\u305a\u306fWindows Server\u306b\u30ed\u30b0\u30aa\u30f3\u3057\u307e\u3059\u3002<br \/>\n\u30b9\u30af\u30ea\u30d7\u30c8\u304c\u5bfe\u5fdc\u3057\u3066\u3044\u308bOS\u3067\u3059\u304c\u3001PowerShell\u306e\u30d0\u30fc\u30b8\u30e7\u30f3\u306e\u90fd\u5408\u3067<strong class=\"keikou\">Windows Server 2012\u4ee5\u964d\u3068\u306a\u308a\u307e\u3059\u3002<\/strong><br \/>\n\uff08PowerShell\u306e\u30d0\u30fc\u30b8\u30e7\u30f3\u30923\u4ee5\u4e0a\u306b\u4e0a\u3052\u308c\u3070\u4eca\u306e\u3068\u3053\u308d\u73fe\u5f79\u306e2008 R2\u3067\u3082\u4f7f\u3048\u307e\u3059\u3002\uff09<\/p>\n<img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/poga.jp\/wp-content\/uploads\/2018\/07\/evlog02.png\" alt=\"\" width=\"872\" height=\"444\" class=\"alignnone size-full wp-image-152\" srcset=\"https:\/\/poga.jp\/wp-content\/uploads\/2018\/07\/evlog02.png 872w, https:\/\/poga.jp\/wp-content\/uploads\/2018\/07\/evlog02-300x153.png 300w, https:\/\/poga.jp\/wp-content\/uploads\/2018\/07\/evlog02-768x391.png 768w\" sizes=\"(max-width: 872px) 100vw, 872px\" \/>\n<p>\u4eca\u56de\u306eps1\u30b9\u30af\u30ea\u30d7\u30c8\u3092\u4efb\u610f\u306e\u30d5\u30a9\u30eb\u30c0\u306b\u30b3\u30d4\u30fc\u3057\u307e\u3059\u3002<br \/>\n\u30a4\u30d9\u30f3\u30c8\u30ed\u30b0\u306e\u51fa\u529b\u5148\u306b\u3064\u3044\u3066\u306f\u4eca\u56de\u306f\u30b9\u30af\u30ea\u30d7\u30c8\u5185\u306b\u7d76\u5bfe\u30d1\u30b9\u3067\u8a18\u8ff0\u3057\u3066\u3044\u308b\u306e\u3067ps1\u30d5\u30a1\u30a4\u30eb\u306f\u3069\u3053\u306b\u7f6e\u3044\u3066\u3042\u3063\u3066\u3082\u826f\u3044\u3067\u3059\u3002<\/p>\n<img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/poga.jp\/wp-content\/uploads\/2018\/07\/evlog03-1024x642.png\" alt=\"\" width=\"728\" height=\"456\" class=\"alignnone size-large wp-image-153\" srcset=\"https:\/\/poga.jp\/wp-content\/uploads\/2018\/07\/evlog03-1024x642.png 1024w, https:\/\/poga.jp\/wp-content\/uploads\/2018\/07\/evlog03-300x188.png 300w, https:\/\/poga.jp\/wp-content\/uploads\/2018\/07\/evlog03-768x481.png 768w, https:\/\/poga.jp\/wp-content\/uploads\/2018\/07\/evlog03.png 1120w\" sizes=\"(max-width: 728px) 100vw, 728px\" \/>\n<p><strong class=\"keikou\">\u300c\u30bf\u30b9\u30af\u30b9\u30b1\u30b8\u30e5\u30fc\u30e9\u300d<\/strong>\u3092\u7acb\u3061\u4e0a\u3052\u3066\u4eca\u56de\u306e\u30b9\u30af\u30ea\u30d7\u30c8\u3092\u5b9a\u671f\u7684\u306b\u5b9f\u884c\u3059\u308b\u305f\u3081\u306e\u30bf\u30b9\u30af\u3092\u4f5c\u6210\u3057\u307e\u3059\u3002<br \/>\n\u3069\u3053\u3067\u3082\u826f\u3044\u3067\u3059\u304c\u3001\u4e0a\u56f3\u306e\u300c\u30bf\u30b9\u30af\u30b9\u30b1\u30b8\u30e5\u30fc\u30e9\u30e9\u30a4\u30d6\u30e9\u30ea\u300d\u8fba\u308a\u306e\u4f55\u3082\u7121\u3044\u3068\u3053\u308d\u3092\u53f3\u30af\u30ea\u30c3\u30af\u21d2<strong class=\"keikou\">\u300c\u65b0\u3057\u3044\u30bf\u30b9\u30af\u306e\u4f5c\u6210\u300d<\/strong>\u3067\u30bf\u30b9\u30af\u3092\u65b0\u898f\u4f5c\u6210\u3057\u307e\u3059\u3002<\/p>\n<img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/poga.jp\/wp-content\/uploads\/2018\/07\/evlog04.png\" alt=\"\" width=\"738\" height=\"495\" class=\"alignnone size-full wp-image-154\" srcset=\"https:\/\/poga.jp\/wp-content\/uploads\/2018\/07\/evlog04.png 738w, https:\/\/poga.jp\/wp-content\/uploads\/2018\/07\/evlog04-300x200.png 300w\" sizes=\"(max-width: 738px) 100vw, 738px\" \/>\n<p>\u300c\u30bf\u30b9\u30af\u306e\u4f5c\u6210\u300d\u753b\u9762\u304c\u8868\u308c\u308b\u306e\u3067\u3001\u9069\u5f53\u306a\u30bf\u30b9\u30af\u540d\u3092\u4ed8\u3051\u305f\u3089<strong class=\"keikou\">\u300c\u30e6\u30fc\u30b6\u30fc\u307e\u305f\u306f\u30b0\u30eb\u30fc\u30d7\u306e\u5909\u66f4\u300d<\/strong>\u30dc\u30bf\u30f3\u3092\u30af\u30ea\u30c3\u30af\u3057\u307e\u3059\u3002<\/p>\n<img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/poga.jp\/wp-content\/uploads\/2018\/07\/evlog05.png\" alt=\"\" width=\"718\" height=\"368\" class=\"alignnone size-full wp-image-155\" srcset=\"https:\/\/poga.jp\/wp-content\/uploads\/2018\/07\/evlog05.png 718w, https:\/\/poga.jp\/wp-content\/uploads\/2018\/07\/evlog05-300x154.png 300w\" sizes=\"(max-width: 718px) 100vw, 718px\" \/>\n<p>\u300c\u9078\u629e\u3059\u308b\u30aa\u30d6\u30b8\u30a7\u30af\u30c8\u540d\u3092\u5165\u529b\u3057\u3066\u304f\u3060\u3055\u3044\u300d\u306e\u6b04\u306b\u306f<strong class=\"keikou\">\u300csystem\u300d<\/strong>\u3068\u3060\u3051\u5165\u529b\u3057\u3001\u300cOK\u300d\u30dc\u30bf\u30f3\u3092\u30af\u30ea\u30c3\u30af\u3057\u3066\u9589\u3058\u3066\u304f\u3060\u3055\u3044\u3002<br \/>\n\uff08\u3061\u306a\u307f\u306b\u3001\u79c1\u306f\u30bf\u30b9\u30af\u30b9\u30b1\u30b8\u30e5\u30fc\u30e9\u306e\u5b9f\u884c\u30e6\u30fc\u30b6\u306f\u307b\u307c\u5168\u3066System\u6a29\u9650\u306b\u3059\u308b\u6d3e\u3067\u3059\u3002\u305f\u3060\u3057\u30c9\u30e1\u30a4\u30f3\u7ba1\u7406\u8005\u6a29\u9650\u304c\u5fc5\u8981\u306a\u5834\u5408\u306e\u307f\u30c9\u30e1\u30a4\u30f3\u306e\u6a29\u9650\u306b\u3057\u305f\u308a\u3057\u307e\u3059\u3002\uff09<\/p>\n<img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/poga.jp\/wp-content\/uploads\/2018\/07\/evlog06.png\" alt=\"\" width=\"738\" height=\"495\" class=\"alignnone size-full wp-image-156\" srcset=\"https:\/\/poga.jp\/wp-content\/uploads\/2018\/07\/evlog06.png 738w, https:\/\/poga.jp\/wp-content\/uploads\/2018\/07\/evlog06-300x200.png 300w\" sizes=\"(max-width: 738px) 100vw, 738px\" \/>\n<p>\u30bf\u30b9\u30af\u5b9f\u884c\u30e6\u30fc\u30b6\u30fc\u304c<strong class=\"keikou\">\u300cNT AUTHORITY\\SYSTEM\u300d<\/strong>\u306b\u5909\u66f4\u3055\u308c\u305f\u3053\u3068\u3092\u78ba\u8a8d\u3057\u307e\u3059\u3002<br \/>\n\u3061\u306a\u307f\u306b\u300c\u6700\u4e0a\u4f4d\u306e\u7279\u6a29\u3067\u5b9f\u884c\u3059\u308b\u300d\u306b\u306f\u30c1\u30a7\u30c3\u30af\u3092\u5165\u308c\u3066\u3082\u5165\u308c\u306a\u304f\u3066\u3082\u826f\u3044\u3067\u3059\u3002\uff08\u3068\u3044\u3046\u3088\u308aSystem\u3088\u308a\u4e0a\u4f4d\u306e\u6a29\u9650\u306f\u3042\u308a\u307e\u305b\u3093\u3002\uff09<\/p>\n<img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/poga.jp\/wp-content\/uploads\/2018\/07\/evlog07.png\" alt=\"\" width=\"738\" height=\"495\" class=\"alignnone size-full wp-image-157\" srcset=\"https:\/\/poga.jp\/wp-content\/uploads\/2018\/07\/evlog07.png 738w, https:\/\/poga.jp\/wp-content\/uploads\/2018\/07\/evlog07-300x200.png 300w\" sizes=\"(max-width: 738px) 100vw, 738px\" \/>\n<p><strong class=\"keikou\">\u300c\u30c8\u30ea\u30ac\u30fc\u300d<\/strong>\u30bf\u30d6\u306b\u5207\u308a\u66ff\u3048\u3066\u3001\u4e0b\u306e\u300c\u65b0\u898f\u300d\u30dc\u30bf\u30f3\u3092\u30af\u30ea\u30c3\u30af\u3057\u307e\u3059\u3002<\/p>\n<img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/poga.jp\/wp-content\/uploads\/2018\/07\/evlog09.png\" alt=\"\" width=\"912\" height=\"691\" class=\"alignnone size-full wp-image-158\" srcset=\"https:\/\/poga.jp\/wp-content\/uploads\/2018\/07\/evlog09.png 912w, https:\/\/poga.jp\/wp-content\/uploads\/2018\/07\/evlog09-300x227.png 300w, https:\/\/poga.jp\/wp-content\/uploads\/2018\/07\/evlog09-768x582.png 768w\" sizes=\"(max-width: 912px) 100vw, 912px\" \/>\n<p>\u30b9\u30b1\u30b8\u30e5\u30fc\u30eb\u753b\u9762\u304c\u8868\u308c\u308b\u306e\u3067\u5de6\u306e\u8a2d\u5b9a\u3067<strong class=\"keikou\">\u300c\u6bce\u6708\u300d<\/strong>\u306b\u30c1\u30a7\u30c3\u30af\u3092\u5165\u308c\u305f\u5f8c\u3001\u53f3\u5074\u306e\u300c\u6708\u300d\u306e\u9805\u76ee\u3067<strong class=\"keikou\">\u300c\uff1c\u3059\u3079\u3066\u306e\u6708\u3092\u9078\u629e\uff1e\u300d<\/strong>\u306b\u30c1\u30a7\u30c3\u30af\u3092\u5165\u308c\u307e\u3059\u3002<\/p>\n<img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/poga.jp\/wp-content\/uploads\/2018\/07\/evlog10.png\" alt=\"\" width=\"912\" height=\"691\" class=\"alignnone size-full wp-image-159\" srcset=\"https:\/\/poga.jp\/wp-content\/uploads\/2018\/07\/evlog10.png 912w, https:\/\/poga.jp\/wp-content\/uploads\/2018\/07\/evlog10-300x227.png 300w, https:\/\/poga.jp\/wp-content\/uploads\/2018\/07\/evlog10-768x582.png 768w\" sizes=\"(max-width: 912px) 100vw, 912px\" \/>\n<p>\u6b21\u306b<strong class=\"keikou\">\u300c\u65e5\u300d<\/strong>\u306b\u30c1\u30a7\u30c3\u30af\u3092\u5165\u308c\u305f\u5f8c\u3001\u5b9f\u884c\u65e5\u3067<strong class=\"keikou\">\u300c1\u300d<\/strong>\u306b\u30c1\u30a7\u30c3\u30af\u3092\u5165\u308c\u307e\u3059\u3002<\/p>\n<img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/poga.jp\/wp-content\/uploads\/2018\/07\/evlog11.png\" alt=\"\" width=\"912\" height=\"691\" class=\"alignnone size-full wp-image-160\" srcset=\"https:\/\/poga.jp\/wp-content\/uploads\/2018\/07\/evlog11.png 912w, https:\/\/poga.jp\/wp-content\/uploads\/2018\/07\/evlog11-300x227.png 300w, https:\/\/poga.jp\/wp-content\/uploads\/2018\/07\/evlog11-768x582.png 768w\" sizes=\"(max-width: 912px) 100vw, 912px\" \/>\n<p>\u8a2d\u5b9a\u3067\u304d\u305f\u3089\u753b\u50cf\u306e\u3088\u3046\u306b\u300c\u6bce\u67081\u65e5\u300d\u306b\u5b9f\u884c\u3059\u308b\u3001\u3068\u3044\u3046\u30b9\u30b1\u30b8\u30e5\u30fc\u30eb\u306b\u306a\u308a\u307e\u3059\u3002\u3053\u306e\u307e\u307e\u300cOK\u300d\u30dc\u30bf\u30f3\u3092\u30af\u30ea\u30c3\u30af\u3057\u307e\u3059\u3002<br \/>\n\uff08\u5b9f\u884c\u6642\u523b\u306b\u3064\u3044\u3066\u306f\u3053\u3053\u3067\u306f\u7279\u306b\u8a2d\u5b9a\u3057\u3066\u3044\u307e\u305b\u3093\u304c\u3001\u9867\u5ba2\u306e\u672c\u756a\u30b5\u30fc\u30d0\u3067\u8a2d\u5b9a\u3059\u308b\u6642\u306f\u57fa\u672c\u7684\u306b\u306f\u6df1\u591c\u5e2f\u3067\u4e14\u3064\u30d0\u30c3\u30af\u30a2\u30c3\u30d7\u306e\u6642\u9593\u3092\u907f\u3051\u305f\u6642\u9593\u3092\u6307\u5b9a\u3057\u3066\u304f\u3060\u3055\u3044\u3002\uff09<\/p>\n<img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/poga.jp\/wp-content\/uploads\/2018\/07\/evlog12.png\" alt=\"\" width=\"738\" height=\"495\" class=\"alignnone size-full wp-image-161\" srcset=\"https:\/\/poga.jp\/wp-content\/uploads\/2018\/07\/evlog12.png 738w, https:\/\/poga.jp\/wp-content\/uploads\/2018\/07\/evlog12-300x200.png 300w\" sizes=\"(max-width: 738px) 100vw, 738px\" \/>\n<p>\u300c\u30c8\u30ea\u30ac\u30fc\u300d\u304c\u6b63\u5e38\u306b\u8ffd\u52a0\u3055\u308c\u305f\u3053\u3068\u3092\u78ba\u8a8d\u3057\u307e\u3059\u3002<\/p>\n<img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/poga.jp\/wp-content\/uploads\/2018\/07\/evlog13.png\" alt=\"\" width=\"738\" height=\"495\" class=\"alignnone size-full wp-image-162\" srcset=\"https:\/\/poga.jp\/wp-content\/uploads\/2018\/07\/evlog13.png 738w, https:\/\/poga.jp\/wp-content\/uploads\/2018\/07\/evlog13-300x200.png 300w\" sizes=\"(max-width: 738px) 100vw, 738px\" \/>\n<p><strong class=\"keikou\">\u300c\u64cd\u4f5c\u300d<\/strong>\u30bf\u30d6\u306b\u5207\u308a\u66ff\u3048\u3066\u3001\u4e0b\u306e\u300c\u65b0\u898f\u300d\u30dc\u30bf\u30f3\u3092\u30af\u30ea\u30c3\u30af\u3057\u307e\u3059\u3002<\/p>\n<img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/poga.jp\/wp-content\/uploads\/2018\/07\/evlog15.png\" alt=\"\" width=\"583\" height=\"632\" class=\"alignnone size-full wp-image-163\" srcset=\"https:\/\/poga.jp\/wp-content\/uploads\/2018\/07\/evlog15.png 583w, https:\/\/poga.jp\/wp-content\/uploads\/2018\/07\/evlog15-277x300.png 277w\" sizes=\"(max-width: 583px) 100vw, 583px\" \/>\n<p>\u300c\u30d7\u30ed\u30b0\u30e9\u30e0\uff0f\u30b9\u30af\u30ea\u30d7\u30c8\u300d\u306f<strong class=\"keikou\">\u300cpowershell\u300d<\/strong>\u3068\u3060\u3051\u5165\u529b\u3057\u3066\u304f\u3060\u3055\u3044\u3002\uff08\u3082\u3061\u308d\u3093\u3001powershell.exe\u306e\u7d76\u5bfe\u30d1\u30b9\u3092\u5165\u308c\u3066\u3082\u826f\u3044\u3067\u3059\u3002\uff09<\/p>\n<p>\u300c\u5f15\u6570\u306e\u8ffd\u52a0\u300d\u306f\u3001\u753b\u50cf\u3067\u306f\u898b\u5207\u308c\u3066\u3057\u307e\u3063\u3066\u3044\u307e\u3059\u304c<strong class=\"keikou\">\u300c-Command &#8220;.\\GetEvLog.ps1&#8243;\u300d<\/strong>\u3068\u5165\u529b\u3057\u3066\u304f\u3060\u3055\u3044\u3002<\/p>\n<p>\u300c\u958b\u59cb\u300d\u306f\u5148\u307b\u3069ps1\u30d5\u30a1\u30a4\u30eb\u3092\u7f6e\u3044\u305f\u30d5\u30a9\u30eb\u30c0\u306e\u7d76\u5bfe\u30d1\u30b9\u3067\u3042\u308b<strong class=\"keikou\">\u300cC:\\EventLog\\bin\u300d<\/strong>\u3092\u5165\u529b\u3057\u3066\u304f\u3060\u3055\u3044\u3002<\/p>\n<p>\u5168\u3066\u5165\u529b\u3057\u305f\u3089\u300cOK\u300d\u30dc\u30bf\u30f3\u3092\u30af\u30ea\u30c3\u30af\u3057\u307e\u3059\u3002<\/p>\n<img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/poga.jp\/wp-content\/uploads\/2018\/07\/evlog16.png\" alt=\"\" width=\"738\" height=\"495\" class=\"alignnone size-full wp-image-164\" srcset=\"https:\/\/poga.jp\/wp-content\/uploads\/2018\/07\/evlog16.png 738w, https:\/\/poga.jp\/wp-content\/uploads\/2018\/07\/evlog16-300x200.png 300w\" sizes=\"(max-width: 738px) 100vw, 738px\" \/>\n<p>\u300c\u64cd\u4f5c\u300d\u304c\u6b63\u5e38\u306b\u8ffd\u52a0\u3055\u308c\u305f\u3053\u3068\u3092\u78ba\u8a8d\u3057\u307e\u3059\u3002<br \/>\n\u3053\u308c\u3067\u5168\u3066\u306e\u8a2d\u5b9a\u304c\u5b8c\u4e86\u306a\u306e\u3067\u300cOK\u300d\u30dc\u30bf\u30f3\u3092\u30af\u30ea\u30c3\u30af\u3057\u307e\u3059\u3002<\/p>\n<img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/poga.jp\/wp-content\/uploads\/2018\/07\/evlog17-1024x642.png\" alt=\"\" width=\"728\" height=\"456\" class=\"alignnone size-large wp-image-166\" srcset=\"https:\/\/poga.jp\/wp-content\/uploads\/2018\/07\/evlog17-1024x642.png 1024w, https:\/\/poga.jp\/wp-content\/uploads\/2018\/07\/evlog17-300x188.png 300w, https:\/\/poga.jp\/wp-content\/uploads\/2018\/07\/evlog17-768x481.png 768w, https:\/\/poga.jp\/wp-content\/uploads\/2018\/07\/evlog17.png 1120w\" sizes=\"(max-width: 728px) 100vw, 728px\" \/>\n<p>\u3053\u308c\u3067\u30bf\u30b9\u30af\u30b9\u30b1\u30b8\u30e5\u30fc\u30e9\u306b\u4eca\u56de\u306e\u30bf\u30b9\u30af\u3092\u8ffd\u52a0\u51fa\u6765\u307e\u3057\u305f\u3002<\/p>\n<img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/poga.jp\/wp-content\/uploads\/2018\/07\/evlog18_2.png\" alt=\"\" width=\"465\" height=\"153\" class=\"alignnone size-full wp-image-167\" srcset=\"https:\/\/poga.jp\/wp-content\/uploads\/2018\/07\/evlog18_2.png 465w, https:\/\/poga.jp\/wp-content\/uploads\/2018\/07\/evlog18_2-300x99.png 300w\" sizes=\"(max-width: 465px) 100vw, 465px\" \/>\n<p>\u3053\u308c\u3067\u6bce\u67081\u65e5\u306b\u81ea\u52d5\u7684\u306b\u5b9f\u884c\u3055\u308c\u307e\u3059\u304c\u3001\u30c6\u30b9\u30c8\u306e\u70ba\u306b\u4e00\u65e6\u624b\u52d5\u3067\u5b9f\u884c\u3057\u307e\u3057\u3087\u3046\u3002<\/p>\n<img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/poga.jp\/wp-content\/uploads\/2018\/07\/evlog21-1024x391.png\" alt=\"\" width=\"728\" height=\"278\" class=\"alignnone size-large wp-image-168\" srcset=\"https:\/\/poga.jp\/wp-content\/uploads\/2018\/07\/evlog21-1024x391.png 1024w, https:\/\/poga.jp\/wp-content\/uploads\/2018\/07\/evlog21-300x114.png 300w, https:\/\/poga.jp\/wp-content\/uploads\/2018\/07\/evlog21-768x293.png 768w, https:\/\/poga.jp\/wp-content\/uploads\/2018\/07\/evlog21.png 1025w\" sizes=\"(max-width: 728px) 100vw, 728px\" \/>\n<p>\u5148\u6708\u5206\u306e\u30a4\u30d9\u30f3\u30c8\u30ed\u30b0\u306e\u91cf\u306b\u3082\u3088\u308a\u307e\u3059\u304c\u3001\u3060\u3044\u305f\u3044\u5341\u6570\u79d2\u7a0b\u5ea6\u3067\u51e6\u7406\u304c\u5b8c\u4e86\u3057\u307e\u3059\u3002<br \/>\n\u5b8c\u4e86\u3059\u308b\u3068\u753b\u50cf\u306e\u3088\u3046\u306b\u6307\u5b9a\u3057\u305f\u30d5\u30a9\u30eb\u30c0\u306b\u30a4\u30d9\u30f3\u30c8\u30ed\u30b0\u304c\u81ea\u52d5\u7684\u306b\u51fa\u529b\u3055\u308c\u307e\u3059\u3002<\/p>\n<img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/poga.jp\/wp-content\/uploads\/2018\/07\/evlog22-1024x594.png\" alt=\"\" width=\"728\" height=\"422\" class=\"alignnone size-large wp-image-169\" srcset=\"https:\/\/poga.jp\/wp-content\/uploads\/2018\/07\/evlog22-1024x594.png 1024w, https:\/\/poga.jp\/wp-content\/uploads\/2018\/07\/evlog22-300x174.png 300w, https:\/\/poga.jp\/wp-content\/uploads\/2018\/07\/evlog22-768x446.png 768w, https:\/\/poga.jp\/wp-content\/uploads\/2018\/07\/evlog22.png 1111w\" sizes=\"(max-width: 728px) 100vw, 728px\" \/>\n<p>\u4fdd\u5b58\u3055\u308c\u305f\u30a4\u30d9\u30f3\u30c8\u30ed\u30b0\u3092\u958b\u3044\u3066\u3001\u76ee\u7684\u306e\u7a2e\u985e\u306e\u30a4\u30d9\u30f3\u30c8\u30ed\u30b0\u304c\u6307\u5b9a\u3057\u305f\u671f\u9593\uff08\u5148\u6708\uff09\u5206\u304c\u53d6\u308c\u3066\u3044\u308b\u3053\u3068\u3092\u78ba\u8a8d\u3057\u307e\u3059\u3002<\/p>\n<p>\u4ee5\u4e0a\u304c\u57fa\u672c\u7684\u306a\u624b\u9806\u306b\u306a\u308a\u307e\u3059\u3002<\/p>\n<h3>\u30b9\u30af\u30ea\u30d7\u30c8\u306e\u8a73\u7d30\u306a\u5185\u5bb9\u306b\u3064\u3044\u3066<\/h3>\n<p>\u3053\u3053\u304b\u3089\u306f\u3042\u308b\u7a0b\u5ea6\u30b9\u30af\u30ea\u30d7\u30c8\u3092\u30ab\u30b9\u30bf\u30de\u30a4\u30ba\u3067\u304d\u308bSE\u306e\u65b9\u5411\u3051\u306b\u8aac\u660e\u3057\u3066\u3044\u304d\u307e\u3059\u3002<\/p>\n<p>\u3053\u306e\u30b9\u30af\u30ea\u30d7\u30c8\u3067\u306f\u30a4\u30d9\u30f3\u30c8\u30d3\u30e5\u30fc\u30a2\u30fc\u3067\u898b\u3089\u308c\u308b\u307b\u307c\u5168\u3066\u306e\u30ed\u30b0\u3092\u53d6\u5f97\u3067\u304d\u307e\u3059\u3002<br \/>\n\u4eca\u56de\u306e\u5834\u5408\u306f\u300c\u300e\u30b7\u30b9\u30c6\u30e0\u300f\u3068\u300e\u30a2\u30d7\u30ea\u30b1\u30fc\u30b7\u30e7\u30f3\u300f\u300d\u3067\u3001\u300c\u5148\u67081\u65e5\u304b\u3089\u672b\u65e5\u300d\u3067\u3001\u300cLocaleMetaData\u3092\u542b\u3093\u3060evtx\u5f62\u5f0f\u300d\u3067\u51fa\u529b\u3059\u308b\u3002\u3068\u3044\u3046\u8a18\u8f09\u306b\u3057\u3066\u3044\u307e\u3059\u3002<\/p>\n<p>\u307e\u305a\u306f<strong class=\"keikou\">\u30ed\u30b0\u7a2e\u5225<\/strong>\u3067\u3059\u304c\u3001\u30b9\u30af\u30ea\u30d7\u30c8\u3067\u306f\u4e0b\u8a18\u306e\u3088\u3046\u306b\u8a18\u8f09\u3057\u3066\u3044\u307e\u3059\u3002<\/p>\n<pre class=\"lang:ps decode:true \" ># \u53d6\u5f97\u5bfe\u8c61\u306e\u30a4\u30d9\u30f3\u30c8\u30ed\u30b0\u3068\u3057\u3066\u300c\u30b7\u30b9\u30c6\u30e0\u300d\u3068\u300c\u30a2\u30d7\u30ea\u30b1\u30fc\u30b7\u30e7\u30f3\u300d\u3092\u6307\u5b9a\u3059\u308b\r\n$lognames = @(\"System\",\"Application\")<\/pre>\n<p>\u3053\u308c\u306b\u8ffd\u52a0\u3057\u3066\u3001<strong class=\"keikou\">\u300c\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u300d\u30ed\u30b0\u3082\u53d6\u308a\u305f\u3044\uff01<\/strong>\u3068\u9867\u5ba2\u306b\u8a00\u308f\u308c\u305f\u5834\u5408\u306f\u30b9\u30af\u30ea\u30d7\u30c8\u3092\u4e0b\u8a18\u306e\u3088\u3046\u306b\u4fee\u6b63\u3057\u307e\u3059\u3002<\/p>\n<pre class=\"lang:ps decode:true \" ># \u53d6\u5f97\u5bfe\u8c61\u306e\u30a4\u30d9\u30f3\u30c8\u30ed\u30b0\u3068\u3057\u3066\u300c\u30b7\u30b9\u30c6\u30e0\u300d\u3068\u300c\u30a2\u30d7\u30ea\u30b1\u30fc\u30b7\u30e7\u30f3\u300d\u3092\u6307\u5b9a\u3059\u308b\r\n$lognames = @(\"System\",\"Application\",\"Security\")<\/pre>\n<p>\u300c@\u300d\u306f\u6307\u5b9a\u3055\u308c\u305fString\u306e\u6570\u306e\u5206\u3060\u3051\u81ea\u52d5\u7684\u306b\u914d\u5217\u306e\u8981\u7d20\u6570\u3092\u62e1\u5f35\u3057\u3066\u304f\u308c\u307e\u3059\u3002<br \/>\n\u3053\u306e$lognames\u914d\u5217\u306fforeach\u95a2\u6570\u3067\u8981\u7d20\u6570\u306e\u5206\u3060\u3051\u4e00\u3064\u305a\u3064\u5b9f\u884c\u3055\u308c\u307e\u3059\u3002<\/p>\n<p>\u57fa\u672c\u7684\u306b\u53d6\u5f97\u3059\u308b\u30ed\u30b0\u306f\u300c\u30b7\u30b9\u30c6\u30e0\u300d\u300c\u30a2\u30d7\u30ea\u30b1\u30fc\u30b7\u30e7\u30f3\u300d\u306e\u307f\u3067\u826f\u3044\u306f\u305a\u3067\u3059\u304c\u3001\u9867\u5ba2\u306b\u3088\u3063\u3066\u306f\u300c\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u300d\u3068\u5404\u7a2e\u30a2\u30d7\u30ea\u30b1\u30fc\u30b7\u30e7\u30f3\u306e\u8a73\u7d30\u30ed\u30b0\u3092\u6c42\u3081\u3089\u308c\u308b\u5834\u5408\u304c\u3042\u308a\u307e\u3059\u3002<br \/>\n\u30a2\u30d7\u30ea\u30b1\u30fc\u30b7\u30e7\u30f3\u306e\u8a73\u7d30\u30ed\u30b0\u3092\u6307\u5b9a\u3059\u308b\u306b\u306f\u3001\u5bfe\u8c61\u306e\u30ed\u30b0\u306e\u8a73\u7d30\u60c5\u5831\u306b\u3042\u308b<strong class=\"keikou\">\u300c\u30ed\u30b0\u306e\u540d\u524d\u300d<\/strong>\u3092\u6307\u5b9a\u3057\u3066\u3042\u3052\u308c\u3070\u826f\u3044\u3067\u3059\u3002<\/p>\n<p>\u6b21\u306f<strong class=\"keikou\">\u30d5\u30a3\u30eb\u30bf\u30fc<\/strong>\u3067\u3059\u3002<br \/>\n\u4eca\u56de\u306f\u4e0b\u8a18\u306e\u3088\u3046\u306b\u300c\u958b\u59cb\u65e5\u300d(\u5148\u67081\u65e5)\u3068\u300c\u7d42\u4e86\u65e5\u300d(\u5148\u6708\u672b\u65e5)\u3068\u3060\u3051\u6307\u5b9a\u3057\u3066\u30d5\u30a3\u30eb\u30bf\u30ea\u30f3\u30b0\u3057\u307e\u3057\u305f\u3002<\/p>\n<pre class=\"lang:ps decode:true \" >$filter = @\"\r\n  Event\/System\/TimeCreated[@SystemTime&gt;='$startUtcTime'] and\r\n  Event\/System\/TimeCreated[@SystemTime&lt;'$endUtcTime']\r\n\"@<\/pre>\n<p><strong class=\"keikou\">\u3053\u308c\u306band\u3067\u63a5\u7d9a\u3057\u3066\u3055\u3089\u306b\u6761\u4ef6\u3092\u8ffd\u52a0\u3067\u304d\u307e\u3059\u3002<\/strong><br \/>\n\u3088\u304f\u3042\u308b\u30b1\u30fc\u30b9\u3068\u3057\u3066\u300c\u300e\u91cd\u5927\u300f\u3068\u300e\u30a8\u30e9\u30fc\u300f\u3068\u300e\u8b66\u544a\u300f\u306e\u30ed\u30b0\u3060\u3051\u3067\u826f\u3044\u300d\u3068\u6307\u5b9a\u3055\u308c\u308b\u5834\u5408\u304c\u3042\u308a\u307e\u3059\u3002<br \/>\n\uff08\u500b\u4eba\u7684\u306b\u306f\u300e\u60c5\u5831\u300f\u30ed\u30b0\u3092\u542b\u3081\u306a\u3044\u306e\u306f\u304b\u306a\u308a\u5371\u967a\u3060\u3068\u601d\u3044\u307e\u3059\u304c\u2026\u2026\uff08\u5fa9\u65e7\u60c5\u5831\u304c\u5206\u304b\u3089\u306a\u3044\u3057\uff09\u3002\u305d\u308c\u3067\u3082\u306a\u304a\u3053\u306e\u7a2e\u985e\u306e\u30ed\u30b0\u3060\u3051\u3067\u826f\u3044\u3068\u8a00\u308f\u308c\u305f\u3089\u8a2d\u5b9a\u3057\u3066\u3042\u3052\u3066\u304f\u3060\u3055\u3044\u3002\uff09<br \/>\n\u305d\u3046\u3044\u3063\u305f\u5834\u5408\u306f\u4e0b\u8a18\u306e\u3088\u3046\u306b\u5bfe\u8c61\u306e\u30ed\u30b0\u30ec\u30d9\u30eb\u3092\u6761\u4ef6\u306b\u8ffd\u52a0\u3059\u308b\u3053\u3068\u3067\u76ee\u7684\u306e\u30ed\u30b0\u30ec\u30d9\u30eb\u306e\u30ed\u30b0\u3060\u3051\u53d6\u5f97\u3067\u304d\u307e\u3059\u3002<\/p>\n<pre class=\"lang:ps decode:true \" >$filter = @\"\r\n  Event\/System\/TimeCreated[@SystemTime&gt;='$startUtcTime'] and\r\n  Event\/System\/TimeCreated[@SystemTime&lt;'$endUtcTime'] and\r\n  Event\/System[(Level=1  or Level=2 or Level=3)]\r\n\"@<\/pre>\n<p>\u4e0a\u8a18\u306e<strong class=\"keikou\">\u300cLevel=1\u300d\u304c\u91cd\u5927\u30ed\u30b0\u3001\u300cLevel=2\u300d\u304c\u30a8\u30e9\u30fc\u30ed\u30b0\u3001\u300cLevel=3\u300d\u304c\u8b66\u544a\u30ed\u30b0<\/strong>\u3068\u306a\u308a\u307e\u3059\u3002<br \/>\n\u8b66\u544a\u30ed\u30b0\u306f\u4e0d\u8981\u3067\u3001\u524d\u8005\u306e2\u3064\u3060\u3051\u3067\u826f\u3044\u3068\u8a00\u308f\u308c\u305f\u3089\u300cor Level=3\u300d\u306f\u524a\u9664\u3057\u3066\u304f\u3060\u3055\u3044\u3002<\/p>\n<p>\u6b21\u306f<strong class=\"keikou\">\u30ed\u30b0\u3092\u51fa\u529b\u3059\u308b\u969b\u306e\u5f62\u5f0f<\/strong>\u3067\u3059\u3002\u4ed6\u306e\u30d6\u30ed\u30b0\u3067\u306fevtx\u3067\u51fa\u529b\u3057\u3066\u305d\u308c\u3067\u7d42\u308f\u308a\u3001\u3068\u306a\u3063\u3066\u3044\u308b\u5834\u5408\u304c\u307b\u3068\u3093\u3069\u3067\u3057\u305f\u304c\u3001<br \/>\n\u500b\u4eba\u7684\u306b\u306f\u3069\u3093\u306a\u30d1\u30bd\u30b3\u30f3\u74b0\u5883\u3067\u3082\u30b5\u30fc\u30d0\u3067\u898b\u305f\u6642\u3068\u540c\u3058\u5185\u5bb9\u306e\u30ed\u30b0\u3092\u898b\u3089\u308c\u308b\u3088\u3046\u306b\u3057\u305f\u3044\u305f\u3081\u3001<strong class=\"keikou\">\u300cLocaleMetaData\u300d<\/strong>\u306f\u5fc5\u305a\u4f5c\u6210\u3057\u3066\u3044\u307e\u3059\u3002<br \/>\n\u305d\u306e\u305f\u3081\u3001\u79c1\u306f\u4e0b\u8a18\u306e\u3088\u3046\u306b\u6307\u5b9a\u3057\u3066\u3044\u307e\u3059\u3002<\/p>\n<pre class=\"lang:ps decode:true \" ># \u30a4\u30d9\u30f3\u30c8\u30ed\u30b0\u3092evtx\u5f62\u5f0f\u3067\u51fa\u529b\u3059\u308b\uff08\u300cLocaleMetaData\u300d\u3082\u65e5\u672c\u8a9e\u306e\u8868\u793a\u60c5\u5831\u3067\u51fa\u529b\u3055\u305b\u308b\uff09\r\nforeach($logname in $lognames){\r\n  $outfile = $dstFolder + \"\\\" + $Env:COMPUTERNAME + \"_\" + $logname + \"_\" + $yyyyMM + \".evtx\"\r\n  $locale = [System.Globalization.CultureInfo]::CreateSpecificCulture(\"ja-JP\")\r\n  $evsession.ExportLogAndMessages($logname,\"LogName\",$filter,$outfile,$True,$locale)\r\n}<\/pre>\n<p>\u4e0a\u8a18\u3067\u306f$locale\u306b\u65e5\u672c\u8a9e\u306e\u74b0\u5883\u60c5\u5831\u3092\u4ed8\u4e0e\u3057\u3066\u3001\u62e1\u5f35\u30aa\u30d6\u30b8\u30a7\u30af\u30c8\u3067\u3042\u308b<strong class=\"keikou\">\u300cExportLogAndMessages\u300d<\/strong>\u3067\u660e\u793a\u7684\u306b\u65e5\u672c\u8a9e\u3092\u6307\u5b9a\u3057\u3066\u51fa\u529b\u3057\u3066\u3044\u307e\u3059\u3002<br \/>\n\uff08\u3061\u306a\u307f\u306b$locale\u3092\u7701\u7565\u3059\u308b\u3068\u65e2\u5b9a\u306e\u8a00\u8a9e\u3067LocaleMetaData\u304c\u4f5c\u6210\u3055\u308c\u307e\u3059\u3002\uff09<\/p>\n<p>\u300cLocaleMetaData\u300d\u306a\u3093\u3066\u3044\u3089\u306a\u3044\uff01\u4ffa\u306f\u666e\u901a\u306b\u30a4\u30d9\u30f3\u30c8\u30ed\u30b0\u3092\u51fa\u529b\u3057\u305f\u3044\u3093\u3060\uff01\u3068\u3044\u3063\u305f\u5834\u5408\u306f\u4e0b\u8a18\u306e\u3088\u3046\u306b\u66f8\u304d\u63db\u3048\u308b\u3053\u3068\u3067\u901a\u5e38\u306eevtx\u5f62\u5f0f\u306e\u30ed\u30b0\u3092\u51fa\u529b\u3067\u304d\u307e\u3059\u3002<\/p>\n<pre class=\"lang:ps decode:true \" ># \u30a4\u30d9\u30f3\u30c8\u30ed\u30b0\u3092evtx\u5f62\u5f0f\u3067\u51fa\u529b\u3059\u308b\r\nforeach($logname in $lognames){\r\n  $outfile = $dstFolder + \"\\\" + $Env:COMPUTERNAME + \"_\" + $logname + \"_\" + $yyyyMM + \".evtx\"\r\n  $evsession.ExportLog($logname,\"LogName\",$filter,$outfile)\r\n}<\/pre>\n<p>\u300cExportLogAndMessages\u300d\u306e\u4ee3\u308f\u308a\u306b<strong class=\"keikou\">\u300cExportLog\u300d<\/strong>\u3092\u4f7f\u3063\u3066\u3044\u307e\u3059\u3002\u3053\u3053\u3089\u3078\u3093\u306f\u304a\u597d\u307f\u3067\u6c7a\u3081\u3066\u304f\u3060\u3055\u3044\u3002<\/p>\n<p>\u4ee5\u4e0a\u304c\u30a4\u30d9\u30f3\u30c8\u30ed\u30b0\u81ea\u52d5\u53d6\u5f97\u30b9\u30af\u30ea\u30d7\u30c8\u306e\u3054\u7d39\u4ecb\u306b\u306a\u308a\u307e\u3059\u3002<br \/>\n\u3054\u53c2\u8003\u306b\u306a\u308c\u3070\u5e78\u751a\u3067\u3059\u3002<\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u3061\u3087\u3063\u3068\u524d\u306b\u4ed6\u306e\u30c1\u30fc\u30e0\u304b\u3089\u306e\u5f15\u304d\u7d99\u304e\u3067\u65b0\u305f\u306a\u9867\u5ba2\u306eIT\u57fa\u76e4\u306e\u4fdd\u5b88\u904b\u7528\u62c5\u5f53\u306b\u30a2\u30b5\u30a4\u30f3\u3055\u308c\u307e\u3057\u305f\u3002 \u305d\u306e\u969b\u306b\u5f15\u304d\u7d99\u304e\u30c9\u30ad\u30e5\u30e1\u30f3\u30c8\u306e\u904b\u7528\u624b\u9806\u66f8\u3092\u78ba\u8a8d\u3057\u3066\u3044\u305f\u3089\u3001\u6bce\u6708\u306e\u5b9a\u5e38\u904b\u7528\u306e\u4e2d\u3067\u81ea\u52d5\u5316\u3057\u305f\u307b\u3046\u304c\u52b9\u7387\u3082\u826f\u304f\u30ea\u30b9\u30af\u3082\u5c11\u306a\u304f\u306a\u308b\u3068&#8230;<\/p>\n","protected":false},"author":1,"featured_media":176,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2],"tags":[5,6],"_links":{"self":[{"href":"https:\/\/poga.jp\/index.php?rest_route=\/wp\/v2\/posts\/145"}],"collection":[{"href":"https:\/\/poga.jp\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/poga.jp\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/poga.jp\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/poga.jp\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=145"}],"version-history":[{"count":15,"href":"https:\/\/poga.jp\/index.php?rest_route=\/wp\/v2\/posts\/145\/revisions"}],"predecessor-version":[{"id":201,"href":"https:\/\/poga.jp\/index.php?rest_route=\/wp\/v2\/posts\/145\/revisions\/201"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/poga.jp\/index.php?rest_route=\/wp\/v2\/media\/176"}],"wp:attachment":[{"href":"https:\/\/poga.jp\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=145"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/poga.jp\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=145"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/poga.jp\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=145"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}