Find collection rule for specific Event Id


Beware of word wrap.

foreach ($rule in get-rule | where {$_.category -eq "EventCollection"} | foreach-object {$_.DataSourceCollection})
    {
    if ($rule.get_configuration().ToString() -match "event number")
        {$rule.get_ParentElement().DisplayName}
    }

main menu


Comments (5)

  1. Anonymous says:

    LOL – just approved some old comments and saw this was over 3 years ago.  Sorry for the delay 🙂

  2. Anonymous says:

    Yes, Blake – this is kind of a hack job.  If we handled XML with the correct method, we could pass in regex.

  3. Blake Mengotto says:

    This doesn't seem to work with event id's that are identified with regular expressions, hopefully we can find a fix.

  4. Works great, but… 🙂

    would be great to add the event source to minimize the number of results…

    thanks Jonathan