Find collection rule for specific Event Id

Beware of word wrap.

foreach ($rule in get-rule | where {$_.category -eq "EventCollection"} | foreach-object {$_.DataSourceCollection})
    if ($rule.get_configuration().ToString() -match "event number")

main menu

Comments (5)

  1. LOL – just approved some old comments and saw this was over 3 years ago.  Sorry for the delay 🙂

  2. Yes, Blake – this is kind of a hack job.  If we handled XML with the correct method, we could pass in regex.

  3. Blake Mengotto says:

    This doesn't seem to work with event id's that are identified with regular expressions, hopefully we can find a fix.

  4. Works great, but… 🙂

    would be great to add the event source to minimize the number of results…

    thanks Jonathan

Skip to main content