似乎找不到正确的语法来查询特定日期范围之间的事件日志
<QueryList>
<Query Id="0" Path="Security">
<Select Path="Security">
*[EventData[Data[@Name='SubjectUserName'] and (Data='test')]]
and
*[System[TimeCreated[@SystemTime'] >= '2015-01-24T00:00:000Z']]
and
*[System[TimeCreated[@SystemTime'] <= '2015-01-26T00:00:000Z']]
</Select>
</Query>
</QueryList>
最佳答案
该语法错误:[System[TimeCreated[@SystemTime] >= ...
必须是[System[TimeCreated[@SystemTime>= ...
请在下面查看我的更正
<QueryList>
<Query Id="0" Path="System">
<Select Path="System">
*[System[TimeCreated[@SystemTime>='2017-12-28T00:00:00' and @SystemTime<='2018-01-04T00:00:00']]]
</Select>
</Query>
</QueryList>
关于xml - EventLog XML查询过滤器日期范围,我们在Stack Overflow上找到一个类似的问题: https://stackoverflow.com/questions/28175718/