09.02.2014 Views

Windows sysinternals

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Chapter 6 Pstools 193<br />

PsLogList does not require administrative rights to display records from the local Application<br />

or System logs or from a saved *.evt file, or to export the Application or System logs to<br />

an *.evt file. Administrative rights might not be needed to view the Application log of a<br />

remote <strong>Windows</strong> XP computer, but event text will not be accessible. Administrative rights<br />

are required to clear event logs or to access the local Security log or any other remote<br />

event logs.<br />

The rest of PsLogList’s command-line options are summarized in Table 6-2 and are discussed<br />

in more detail in the rest of this section.<br />

TABLE 6-2 PsLogList Command-Line Options<br />

Option<br />

Output options<br />

Description<br />

–x Displays extended data if that is present. (It’s not applicable if –s used.)<br />

–n # Limits the number of records displayed to the specified number.<br />

–r Reverses the order—displays oldest to newest (with default being newest to<br />

oldest).<br />

–s Displays each record on one line with delimited fields.<br />

–t char Specifies the delimiter character to use with –s. Use \t to specify Tab.<br />

–w Waits for new events, displaying them as they are generated. PsLogList runs<br />

until you press Ctrl+C. (Local computer only.)<br />

Timestamp options<br />

–a mm/dd/yyyy Displays records time-stamped on or after the date mm/dd/yyyy.<br />

–b mm/dd/yyyy Displays records time-stamped before the date mm/dd/yyyy.<br />

–d # Displays only records from the previous # days.<br />

–h # Displays only records from the previous # hours.<br />

–m # Displays only records from the previous # minutes.<br />

Event content filtering options<br />

–f filter Filters event types, where each letter in filter represents an event type.<br />

–i ID[,ID,…] Shows only events with the specified ID or IDs (up to 10).<br />

–e ID[,ID,…] Shows events excluding those with the specified ID or IDs (up to 10).<br />

–o source[,source,…] Shows only events from the specified event source or sources. The * character<br />

can be appended for a substring match.<br />

–q source[,source,…] Shows events excluding the specified event source or sources. The * character<br />

can be appended for a substring match.<br />

Log-management options<br />

–z Lists event logs registered on the target system.<br />

–c Clears the event log after displaying records.<br />

–g filename Exports an event log to a *.evt file. (Local computer only.)<br />

–l filename Displays records from a saved *.evt file instead of from an active log.<br />

www.it-ebooks.info

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!