Skip to main content
Skip table of contents

MS Windows Event Logging XML - PowerShell

PowerShell is a cross-platform task automation solution made up of a command-line shell, a scripting language, and a configuration management framework. PowerShell runs on Windows, Linux, and macOS. As a scripting language, PowerShell is commonly used for automating the management of systems. It is also used to build, test, and deploy solutions, often in CI/CD environments. PowerShell Desired State Configuration (DSC) is a management framework in PowerShell that enables you to manage your enterprise infrastructure with configuration as code.

Device Details

Device NameMS Windows Event Logging XML – PowerShell


MS Windows

Device Type


Supported Model Name/Number

Windows Server 2008, 2012, 2016+

Supported Software Version(s)


Collection Method

MS Windows Event Logging

Configurable Log Output?


Log Source Type

MS Windows Event Logging XML - PowerShell

Log Processing Policy

LogRhythm Default v2.0



Additional Information

Supported Log Messages

(List of LR Tags used to parse the log information for each message type)

TypeProduct VersionSupported Schema Fields
EVID 200, 300N/A<vmid>, <severity>, <vendorinfo>, <dname>, <subject>, <account>, <action>, <objecttype>, <object>, <command>
EVID 400, 403, 600N/A<vmid>, <severity>, <vendorinfo>, <dname>, <status>, <account>, <command>
EVID 500, 501N/A<vmid>, <severity>, <vendorinfo>, <dname>, <account>, <action>, <objecttype>, <object>, <command>
EVID 800 : PS Pipeline ExecutionN/A<vmid>, <severity>. <vendorinfo>, <dname>, <domainorigin>, <login>, <account>, <object>, <command>, <action>
EVID 4100, 4101, 4102, 4103N/A<vmid>, <severity>, <vendorinfo>, <dname>, <domainorigin>, <login>, <action>, <objecttype>, <object>, <command>
EVID 4104 : PS Script ExecutionN/A<vmid>, <severity>, <vendorinfo>, <dname>, <domainorigin>, <login>, <quantity>, <command>, <object>,  <objectname>
EVID 4105, 4106N/A<vmid>, <severity>, <vendorinfo>, <dname>, <domainorigin>, <login>, <object>
EVID 8193, 24577, 40961, 53249N/A<vmid>, <severity>. <vendorinfo>, <dname>, <domainorigin>, <login>
EVID 32784 : PS WinRM ErrorN/A<vmid>, <severity>. <vendorinfo>, <dname>, <domainorigin>, <login>, <session>
EVID 53504 : PS IPC Listening StartedN/A<vmid>, <severity>, <vendorinfo>, <dname>, <domainorigin>, <login>, <processid>
EVID 53506 : PS IPC Listening ErrorN/A<vmid>, <severity>, <vendorinfo>, <dname>, <domainorigin>, <login>, <processid>

Revision History

KB Version

Log Type

Change Type


KB 7.1.622.0MS Windows Event Logging XML – PowerShellNew Log Source TypeNew Device Support for MS Windows Event Logging XML - PowerShell
JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.