PowerShell provides built-in EventLog cmdlets for collecting and inspecting Windows event logs. The most commonly used cmdlet is Get-EventLog, which retrieves events from local logs such as Application, System, Security, etc.

Key cmdlets

  • Get-EventLog – read events from a specific log
  • Other related cmdlets can be found with Get-Help *EventLog

Common usage

Get-EventLog -LogName Application -Newest 20
Get-EventLog -LogName System      -Newest 20
Get-EventLog -LogName Security    -Newest 20

Accessing the Security log typically requires administrative privileges.

Why it matters in digital investigations

Event logs are a primary source of Digital Evidence for user activity, system changes, errors, and security events. PowerShell's built-in event log cmdlets allow investigators to query these logs programmatically and efficiently (see PowerShell as an Acquisition Engine).