Logging

PowerShell comes packed with many logging capabilities, which can be seen in the EventLog.

Logs for Windows PowerShell:

This log source contains basic information about Windows PowerShell. We have actually used this log source previously, when we searched for the engine version filtering Event ID 400.

Remoting Logs:

These logs are mainly used for troubleshooting purposes, to validate misbehavior on remoting. They can also be used for forensic approaches to validate the established connections from or to specific machines.

PowerShell ...

Get Learn PowerShell Core 6.0 now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.