1.querying the native event log name
get-eventlog-list
2. Query 2018 year 1 month 4 Future error log in the system log
Get-eventlog-logname System-entrytype Error-after 2018-1-4
3. View Individual event log details ( The value of index is the ordinal of the event log )
Get-eventlog-logname System | Where-object {$_.index-eq 2677} | Select-object-property *
4. Query The log after the specified date and sort by index ordinal, filter the top 5 items, and customize the field to generate the table ( the first two behavior fields and separators )
get-eventlog-logname System -computername. -entrytype Error-after 2018-1-4 | Sort-object-descending Index | Select-object-first 7 | Format-table-property index,eventid,machinename,entrytype,source,timegenerated,username,message-autosize| Out-file C:\Log.csv
Note: Can be combined with out-file command to import into the CSV file for easy query (if the display width is not wide enough, be sure to take the parameter "-autosize" and the PowerShell execution form width to 5000 or more, the wider the better)
Windows Event Log Query case