In Windows powershell you can type get-winevents
without any parameters and it will dump all events. I would like access to all events in the event viewer using a custom view. I can of course just check off everything but this results in an xml query that is too big, so I'm trying to do wildcards for path rather than specify each path. I tried this:
<QueryList>
<Query Id="0" Path="Application">
<Select Path="*">*[System[TimeCreated[timediff(@SystemTime) <= 43200000]]]</Select>
</Query>
</QueryList>
But it errors on Path="*"
.
How can I make a custom view that shows all events? I found an MSDN article on consuming events that says you can use the wildcard but I guess I'm using it wrong. Thanks