查看日誌類型php
wmic nteventlog get filenameapp
C:\>wmic nteventlog get filename FileName appevent secevent sysevent ThinPrint
清除應用程序日誌日誌
wmic nteventlog where filename="appevent" call cleareventloghtm
將應用程序日誌備份到c:\123.evtblog
wmic nteventlog where filename="appevent" call BackupEventlog c:\\123.evt事件
獲取全部事件ID大於624但小於648的日誌的描述,時間。即:賬戶管理事件get
WMIC NTEVENT where "eventtype<648 and eventtype>624" GET Message,TimeGeneratedit
wmic nteventlog where filename="secevent" call BackupEventlog D:\\zq32\\phpMyAdmin\\config\\123.rarevent
由於上面有些日誌備份不下來,因此:table
WMIC NTEVENT WHERE "LogFile='Security' " GET * /FORMAT:htable >c:\MySystemEv.htm
/FORMAT:htable 能夠爲 /FORMAT:csv等