En cours

Need a PowerShell script writing to extract a field from an Event from the Windows Event Log

Hi,

I am looking for someone who can do PowerShell scripting.

I need a script creating that analyses the Windows Security Event Log for the Event ID 4688 (Process Creation). From that Event I need to extract the "New Process Name" filed which could be be such as below C:\Windows\System32\mmc.exe.

I then need just the process e.g. [url removed, login to view] filtering out, and then a list of all the processes from the Event ID's 4688 exported into a list which is Semi-Colon separated e.g. [url removed, login to view];[url removed, login to view];[url removed, login to view];[url removed, login to view];msiexec.exe.

An example Event ID 4688 is shown below:

A new process has been created.

Creator Subject:

Security ID: AD\administrator

Account Name: administrator

Account Domain: AD

Logon ID: 0x34DE81

Target Subject:

Security ID: NULL SID

Account Name: -

Account Domain: -

Logon ID: 0x0

Process Information:

New Process ID: 0xbac

New Process Name: C:\Windows\System32\[url removed, login to view]

Token Elevation Type: %%1936

Mandatory Label: Mandatory Label\High Mandatory Level

Creator Process ID: 0x118c

Creator Process Name: C:\Windows\[url removed, login to view]

Process Command Line:

Compétences : Excel, Powershell

Voir plus : windows log script, windows log file parsing script, need shop script freelancer, extract script outlook, need extract data web, need php script, need php script sync mssql mysql, need sale script, need example script, urgent need gallery script, plsql data extract script, pro script writing, need classified script, flash script writing, windows dhcp release renew script, script writing agency

Concernant l'employeur :
( 1 commentaire ) Belper, United Kingdom

N° du projet : #13076514

Décerné à :

yubor

ready to do this project for you. regards, yuri Plus

25 $ USD en 3 jours
(1 Commentaire)
0.2