Win32_NTLogEvent, ROOT\CIMV2

Class | Methods | Properties (16) | Qualifiers (8) | Instances (999) | Namespaces (2)
Samples: VB Script | C# | VB.Net | Search on:Microsoft

Description

This class is used to translate instances from the NT Eventlog.

Win32_NTLogEvent properties

Win32_NTLogEvent has 16 properties (16 Local)

NameOriginCIMType
CategoryWin32_NTLogEvent18 [uint16]
CategoryStringWin32_NTLogEvent8 [string]
ComputerNameWin32_NTLogEvent8 [string]
DataWin32_NTLogEvent17 [Uint8]
EventCodeWin32_NTLogEvent18 [uint16]
EventIdentifierWin32_NTLogEvent19 [uint32]
EventTypeWin32_NTLogEvent17 [uint8]
InsertionStringsWin32_NTLogEvent8 [string]
key
Logfile
Win32_NTLogEvent8 [string]
MessageWin32_NTLogEvent8 [string]
key
RecordNumber
Win32_NTLogEvent19 [uint32]
SourceNameWin32_NTLogEvent8 [string]
TimeGeneratedWin32_NTLogEvent101 [datetime]
TimeWrittenWin32_NTLogEvent101 [datetime]
TypeWin32_NTLogEvent8 [string]
UserWin32_NTLogEvent8 [string]

Detailed description of Win32_NTLogEvent properties

Local properties (16) of Win32_NTLogEvent class

Category property
CIMTYPE'uint16'
Description'Specifies a subcategory for this event. This subcategory is source specific.'
DisplayName'Category'
Category property is in 2 classes of ROOT\cimv2 and in 11 namespaces
CategoryString property
CIMTYPE'string'
Description'Specifies the translation of the subcategory. The translation is source specific.'
DisplayName'Category String'
CategoryString property is in 1 class (Win32_NTLogEvent) of ROOT\cimv2 and in 2 namespaces
ComputerName property
CIMTYPE'string'
Description'The variable-length null-terminated string specifying the name of the computer that generated this event.'
DisplayName'Computer Name'
FixedTrue
ComputerName property is in 4 classes of ROOT\cimv2 and in 11 namespaces
Data property
CIMTYPE'Uint8'
Description'The binary data that accompanied the report of the NT event.'
DisplayName'Binary Data'
Data property is in 2 classes of ROOT\cimv2 and in 14 namespaces
EventCode property
CIMTYPE'uint16'
Description'This property has the value of the lower 16-bits of the EventIdentifier property. It is present to match the value displayed in the NT Event Viewer. NOTE: Two events from the same source may have the same value for this property but may have different severity and EventIdentifier values'
DisplayName'Event Code'
EventCode property is in 1 class (Win32_NTLogEvent) of ROOT\cimv2 and in 4 namespaces
EventIdentifier property
CIMTYPE'uint32'
Description'Identifies the event. This is specific to the source that generated the event log entry, and is used, together with SourceName, to uniquely identify an NT event type.'
DisplayName'Event Identifier'
FixedTrue
EventIdentifier property is in 2 classes of ROOT\cimv2 and in 2 namespaces
EventType property
CIMTYPE'uint8'
Description'The Type property specifies the type of event.'
DisplayName'Type Event'
FixedTrue
ValueMap['0', '1', '2', '3', '4', '5']
Values['Success', 'Error', 'Warning', 'Information', 'Security Audit Success', 'Security Audit Failure']
EventType property is in 5 classes of ROOT\cimv2 and in 14 namespaces
InsertionStrings property
CIMTYPE'string'
Description'The insertion strings that accompanied the report of the NT event.'
DisplayName'Insertion Strings'
InsertionStrings property is in 2 classes of ROOT\cimv2 and in 2 namespaces
Logfile property
CIMTYPE'string'
Description'The name of NT Eventlog logfile. This is used together with the RecordNumber to uniquely identify an instance of this class.'
DisplayName'Log File'
keyTrue
Logfile property is in 2 classes of ROOT\cimv2 and in 4 namespaces
Message property
CIMTYPE'string'
Description'The event message as it appears in the NT Eventlog. This is a standard message with zero or more insertion strings supplied by the source of the NT event. The insertion strings are inserted into the standard message in a predefined format. If there are no insertion strings or there is a problem inserting the insertion strings, only the standard message will be present in this field.'
DisplayName'Message'
Message property is in 5 classes of ROOT\cimv2 and in 142 namespaces
RecordNumber property
CIMTYPE'uint32'
Description'Identifies the event within the NT Eventlog logfile. This is specific to the logfile and is used together with the logfile name to uniquely identify an instance of this class.'
DisplayName'Record Number'
keyTrue
RecordNumber property is in 2 classes of ROOT\cimv2 and in 2 namespaces
SourceName property
CIMTYPE'string'
Description'The variable-length null-terminated string specifying the name of the source (application, service, driver, subsystem) that generated the entry. It is used, together with the EventIdentifier, to uniquely identify an NT event type.'
DisplayName'Source Name'
FixedTrue
SourceName property is in 3 classes of ROOT\cimv2 and in 10 namespaces
TimeGenerated property
CIMTYPE'datetime'
Description'Specifies the time at which the source generated the event.'
DisplayName'Time Generated'
FixedTrue
TimeGenerated property is in 3 classes of ROOT\cimv2 and in 2 namespaces
TimeWritten property
CIMTYPE'datetime'
Description'Specifies the time at which the event was written to the logfile.'
DisplayName'Time Written'
FixedTrue
TimeWritten property is in 1 class (Win32_NTLogEvent) of ROOT\cimv2 and in 2 namespaces
Type property
CIMTYPE'string'
Description'Specifies the type of event. This is an enumerated string'
DisplayName'Type'
FixedTrue
ValueMap['0', '1', '2', '4', '8', '16']
Values['Success', 'Error', 'Warning', 'Information', 'Audit Success', 'Audit Failure']
Type property is in 19 classes of ROOT\cimv2 and in 142 namespaces
User property
CIMTYPE'string'
Description'The user name of the logged on user when the event ocurred. If the user name cannot be determined this will be NULL'
DisplayName'User Name'
User property is in 46 classes of ROOT\cimv2 and in 6 namespaces

Win32_NTLogEvent Qualifiers

NameValueToInstanceToSubclassOverridableAmendedLocal
Description'This class is used to translate instances from the NT Eventlog.'
DisplayName'NT Log Events'
dynamicTrue
EnumPrivileges['SeSecurityPrivilege']
Locale1033
Privileges['SeSecurityPrivilege']
provider'MS_NT_EVENTLOG_PROVIDER'
UUID'{8502C57C-5FBB-11D2-AAC1-006008C78BC7}'

Win32_NTLogEvent System properties

NameValueOriginCIMTypeLocalArray
__PATH'\\.\ROOT\cimv2:Win32_NTLogEvent'___SYSTEM8
__NAMESPACE'ROOT\cimv2'___SYSTEM8
__SERVER'.'___SYSTEM8
__DERIVATION[]___SYSTEM8
__PROPERTY_COUNT16___SYSTEM3
__RELPATH'Win32_NTLogEvent'___SYSTEM8
__DYNASTY'Win32_NTLogEvent'___SYSTEM8
__SUPERCLASSnull___SYSTEM8
__CLASS'Win32_NTLogEvent'___SYSTEM8
__GENUS1___SYSTEM3

Similar Classes to Win32_NTLogEvent

Number of classes:95
Class nameChildsPropertiesMethodsClass
Instances
Child
Instances
AbstractSingleton
__AggregateEvent020----
__ClassCreationEvent030---
__ClassDeletionEvent030---
__ClassModificationEvent040---
__ClassOperationEvent330---
__ConsumerFailureEvent070---
__Event520---
__EventConsumer030---
__EventConsumerProviderRegistration020----
__EventDroppedEvent340---
__EventFilter060----
__EventGenerator100---
__EventProviderRegistration02017---
__EventQueueOverflowEvent050---
__ExtrinsicEvent1520---
__InstanceCreationEvent030---
__InstanceDeletionEvent030---
__InstanceModificationEvent040---
__InstanceOperationEvent430---
__MethodInvocationEvent060---
__NamespaceCreationEvent030---
__NamespaceDeletionEvent030---
__NamespaceModificationEvent040---
__NamespaceOperationEvent330---
__QOSFailureEvent060---
__SystemEvent120---
__TimerEvent040---
MSFT_NCProvEvent450---
MSFT_SCMEvent120---
MSFT_SCMEventLogEvent3820---
MSFT_WMI_GenericNonCOMEvent060---
MSFT_WmiConsumerProviderEvent450---
MSFT_WmiEssEvent520---
MSFT_WmiFilterEvent260---
Msft_WmiProvider_ComServerLoadOperationEvent0150---
Msft_WmiProvider_ComServerLoadOperationFailureEvent0160---
Msft_WmiProvider_CreateClassEnumAsyncEvent_Post0140---
Msft_WmiProvider_CreateClassEnumAsyncEvent_Pre0110---
Msft_WmiProvider_CreateInstanceEnumAsyncEvent_Post0140---
Msft_WmiProvider_CreateInstanceEnumAsyncEvent_Pre0110---
Msft_WmiProvider_DeleteClassAsyncEvent_Post0140---
Msft_WmiProvider_DeleteClassAsyncEvent_Pre0110---
Msft_WmiProvider_DeleteInstanceAsyncEvent_Post0140---
Msft_WmiProvider_DeleteInstanceAsyncEvent_Pre0110---
Msft_WmiProvider_ExecMethodAsyncEvent_Post0160---
Msft_WmiProvider_ExecMethodAsyncEvent_Pre0130---
Msft_WmiProvider_ExecQueryAsyncEvent_Post0150---
Msft_WmiProvider_ExecQueryAsyncEvent_Pre0120---
Msft_WmiProvider_GetObjectAsyncEvent_Post0140---
Msft_WmiProvider_GetObjectAsyncEvent_Pre0110---
Msft_WmiProvider_InitializationOperationEvent090---
Msft_WmiProvider_InitializationOperationFailureEvent0100---
Msft_WmiProvider_LoadOperationEvent0170---
Msft_WmiProvider_LoadOperationFailureEvent0180---
Msft_WmiProvider_OperationEvent990---
Msft_WmiProvider_OperationEvent_Post1390---
Msft_WmiProvider_OperationEvent_Pre1390---
Msft_WmiProvider_ProvideEvents_Post0110---
Msft_WmiProvider_ProvideEvents_Pre0100---
Msft_WmiProvider_PutClassAsyncEvent_Post0140---
Msft_WmiProvider_PutClassAsyncEvent_Pre0110---
Msft_WmiProvider_PutInstanceAsyncEvent_Post0140---
Msft_WmiProvider_PutInstanceAsyncEvent_Pre0110---
Msft_WmiProvider_UnLoadOperationEvent090---
MSFT_WmiProviderEvent140---
MSFT_WmiSelfEvent220---
MSFT_WmiThreadPoolEvent230---
NTEventlogProviderConfig010---
RegistryEvent320---
RegistryKeyChangeEvent040---
RegistryTreeChangeEvent040---
RegistryValueChangeEvent050---
Win32_ComputerShutdownEvent040---
Win32_ComputerSystemEvent130---
Win32_DeviceChangeEvent230---
Win32_FileScreenEvent0150---
Win32_IP4RouteTableEvent020---
Win32_NTEventlogFile0391612---
Win32_NTLogEventComputer02040---
Win32_NTLogEventLog02040---
Win32_NTLogEventUser02040---
Win32_PerfFormattedData_Counters_EventTracingforWindows01501--
Win32_PerfFormattedData_Counters_EventTracingforWindowsSession014024---
Win32_PerfFormattedData_MSSQLMICROSOFTNumberNumberWID_MSSQLMICROSOFTNumberNumberWIDTraceEventStatistics_Costly0140----
Win32_PerfFormattedData_MSSQLSERVER_SQLServerTraceEventStatistics_Costly0140----
Win32_PerfRawData_Counters_EventTracingforWindows01501--
Win32_PerfRawData_Counters_EventTracingforWindowsSession014024---
Win32_PerfRawData_MSSQLMICROSOFTNumberNumberWID_MSSQLMICROSOFTNumberNumberWIDTraceEventStatistics_Costly0140----
Win32_PerfRawData_MSSQLSERVER_SQLServerTraceEventStatistics_Costly0140----
Win32_PowerManagementEvent040---
Win32_QuotaEvent0230---
Win32_RdvProvisioningChangeEvent030---
Win32_SessionBrokerTargetEvent080---
Win32_SystemConfigurationChangeEvent030---
Win32_VolumeChangeEvent040---
comments powered by Disqus
WUtils.com