Using XPath starts-with or contains functions to search Windows event logs

后端 未结 3 416
天命终不由人
天命终不由人 2021-01-01 12:00

By editing the XML filter query manually in Windows event viewer, I can find events where the data matches a string exactly:


  

        
3条回答
  •  迷失自我
    2021-01-01 12:30

    Windows Event Log supports a subset of XPath 1.0. It contains only 3 functions: position, Band, timediff.

    Reference: https://docs.microsoft.com/en-us/windows/desktop/WES/consuming-events#xpath-10-limitations

提交回复
热议问题