WQL - EVENT QUERY
来源:互联网 发布:qq java 版 编辑:程序博客网 时间:2024/06/07 01:53
WMI EVENT QUERY
EVENT-WQL = “SELECT” <PROPERTY-LIST> “FROM” /
<EVENT-CLASS-NAME> <OPTIONAL-WITHIN> <EVENT-WHERE>
OPTIONAL-WITHIN = ["WITHIN" <INTERVAL>]
INTERVAL = 1*DIGIT
EVENT-WHERE = ["WHERE" <EVENT-EXPR>]
EVENT-EXPR = ( (<INSTANCE-STATE> “ISA” <CLASS-NAME> <EXPR2>) /
< EXPR> )
["GROUP WITHIN" <INTERVAL>
( ["BY" [<INSTANCE-STATE> DOT] <PROPERTY-NAME>]
["HAVING" <EXPR>]] )
INSTANCE-STATE = “TARGETINSTANCE” / “PREVIOUSINSTANCE”
WITHIN
SELECT * FROM eventclass WITHIN interval WHERE property = value
GROUP
SELECT * FROM EventClass [WHERE property = value] GROUP WITHIN interval
#Build a WMI query for receiving an event$query= "Select * from __instanceCreationEvent WHERE TargetInstance ISA 'Win32_NTLogEvent' ANDTargetInstance.EventCode=1980 GROUP WITHIN 300"#Register the eventRegister-WmiEvent-Query $query -Action {Write-Host"Eventlog Arrived" }
HAVING
#Build a WMI query for receiving an event$query= "Select * from __instanceCreationEvent WHERE TargetInstance ISA 'Win32_NTLogEvent' ANDTargetInstance.EventCode=1980 GROUP WITHIN 300 HAVING NumberOfEvents > 10"#Register the eventRegister-WmiEvent -Query $query -Action {Write-Host"Eventlog Arrived" }
SELECT * FROM EventClass [WHERE property = value]
GROUP WITHIN interval HAVING NumberOfEvents operator constant
BY
SELECT * FROM EventClass [WHERE property = value]
GROUP WITHIN interval [BY property_list]
#Build a WMI query for receiving an event$query= "Select * from __instanceCreationEvent WHERE TargetInstance ISA 'Win32_NTLogEvent' ` GROUP WITHIN 300 BY TargetInstance.SourceName ` HAVING NumberOfEvents > 10"#Register the eventRegister-WmiEvent-Query $query -Action {Write-Host"Eventlog Arrived" }
- WQL - EVENT QUERY
- WQL - EVENT QUERY (CONTINIUING)
- WMI Query Language (WQL)
- Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60
- WMI中的WQL语言和WQL的测试工具
- WQL获取PC硬件信息
- C#(.Net) 配合WQL实现并口读写
- WMI编程(WQL语句记录)
- WAS M SKFJISDJ WQL RMNJQWKEPL WDFN
- Query
- query
- query
- Query
- QUERY
- query
- query
- QUERY
- 解决 ”Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstan“
- 写一个javascript的事件的各种情况用的switch
- A Crash Course on the Depths of Win32 Structured Exception Handling(文章翻译)
- 定制我的Nexus系统之boot.img的前世今生
- 三角形测试用例设计
- 1. 聚合根、实体、值对象的区别?
- WQL - EVENT QUERY
- 稳步前去
- mac删除项目中的svn文件
- 一位码农写给老婆的代码
- 英语名言名句集锦
- SWT基础学习
- Source Insight使用教程1
- VC获取文件大小!
- WQL - EVENT QUERY (CONTINIUING)