how to setup a powershell code

mordy kurlander 20 Reputation points
2026-09-18T20:49:32.29+00:00

How do I setup a PowerShell script like code that can instantly give me a full list of all the information of by default it should be 24 hours or if i specific more of for example how many times computer was powered on off users logged in all those stuff and all i need to input into it to get that whole list would be a set key word code like that i setup before hand like give-log or something like that and after writing give-log i would also input the amount of hours? Fyi to whoever sees this I'm also a very new beginner at this so please be simple! even though this probably isn't as simple as it is! like for example is saw this online! User's image

Windows for business | Windows Server | User experience | PowerShell
0 comments No comments

Answer accepted by question author
Allan Solomon Mejia 10,145 Reputation points
2026-09-18T20:55:44.2233333+00:00

Hello @mordy kurlander

Yes, you can do this with PowerShell. Since you're just getting started, keep the first version simple and use the Windows Event Logs that already record this information.

For example, the script below asks how many hours you want to look back. If you simply press Enter, it uses the last 24 hours:

$Hours = Read-Host "How many hours should I look back? Press Enter for 24"
if ([string]::IsNullOrWhiteSpace($Hours)) {
    $Hours = 24
}
$StartTime = (Get-Date).AddHours(-[int]$Hours)
Write-Host "`n=== COMPUTER STARTUP / SHUTDOWN ===" -ForegroundColor Cyan
Get-WinEvent -FilterHashtable @{
    LogName   = 'System'
    Id        = 12,13,41,1074,6005,6006,6008
    StartTime = $StartTime
} -ErrorAction SilentlyContinue |
Select-Object TimeCreated, Id, ProviderName, Message |
Format-Table -Wrap
Write-Host "`n=== USER LOGON / LOGOFF ===" -ForegroundColor Cyan
Get-WinEvent -FilterHashtable @{
    LogName   = 'Security'
    Id        = 4624,4634,4647
    StartTime = $StartTime
} -ErrorAction SilentlyContinue |
Select-Object TimeCreated, Id, Message |
Format-Table -Wrap

Run PowerShell as Administrator, paste the script, and press Enter. When prompted:

How many hours should I look back? Press Enter for 24:

Pressing Enter gives you the last 24 hours, while entering 48, for example, searches the last 48 hours.

The IDs in the example have specific meanings. 4624 records a successful logon, 4634 indicates a logon session ended, and 4647 represents a user-initiated logoff.

For startup/shutdown troubleshooting, Windows records events such as 1074 for an initiated shutdown/restart, 6006 for a clean shutdown, 6008 for an unexpected shutdown, and 41 when Windows restarted without shutting down cleanly. Kernel-General events 12 and 13 for OS startup and shutdown.

One important point: this won't necessarily tell you everything that happened on the computer. PowerShell can only report information Windows actually recorded. Some Security events also depend on the auditing policies that were enabled when the activity occurred.

Once this basic version works, you can expand it to produce a cleaner report showing things such as computer startup/shutdown count, usernames, logon/logoff times, failed logons, unexpected shutdowns, and export the results to CSV.

References:

Get-WinEvent documentation

Windows events recommended for monitoring

Troubleshoot unexpected reboots using event logs


Help make this community better for everyone: If this answer helped or resolved your issue, please accept it or upvote it. If not, share more details in a comment so we can continue the discussion and find the right solution. Thank you.

Was this answer helpful?

1 person found this answer helpful.
0 comments No comments

3 additional answers

Sort by: Newest
  1. mordy kurlander 20 Reputation points
    2026-09-20T17:30:10.53+00:00

    Then how come it shows 700 logons and its just not fully accurate or something!??

    Also every time i open PowerShell backup i have to input that full code again? is there a way to make by default I give a certain keyword and in its memory it will know what to do and give me that full thing like this pic User's image

    User's image

    Was this answer helpful?

    0 comments No comments

  2. Allan Solomon Mejia 10,145 Reputation points
    2026-09-20T17:15:49.6533333+00:00

    Hello @mordy kurlander

    Yes, absolutely. The picture you're showing is basically a system summary/dashboard printed in the PowerShell window. We can make your script look much closer to that while still keeping the 24-hour activity information we discussed earlier.

    Here's a simple version to start with:

    function Give-Log {
        param(
            [int]$Hours = 24
        )
        $StartTime = (Get-Date).AddHours(-$Hours)
        # Basic system information
        $OS = Get-CimInstance Win32_OperatingSystem
        $Computer = Get-CimInstance Win32_ComputerSystem
        $CPU = Get-CimInstance Win32_Processor | Select-Object -First 1
        $Uptime = (Get-Date) - $OS.LastBootUpTime
        $TotalRAM = [math]::Round($OS.TotalVisibleMemorySize / 1MB, 1)
        $FreeRAM  = [math]::Round($OS.FreePhysicalMemory / 1MB, 1)
        $UsedRAM  = [math]::Round($TotalRAM - $FreeRAM, 1)
        $Drive = Get-CimInstance Win32_LogicalDisk -Filter "DeviceID='C:'"
        $DiskUsed = [math]::Round(
            (($Drive.Size - $Drive.FreeSpace) / $Drive.Size) * 100, 1
        )
        # Count events during requested period
        $StartupEvents = @(
            Get-WinEvent -FilterHashtable @{
                LogName='System'
                Id=12,6005
                StartTime=$StartTime
            } -ErrorAction SilentlyContinue
        )
        $ShutdownEvents = @(
            Get-WinEvent -FilterHashtable @{
                LogName='System'
                Id=13,1074,6006,6008
                StartTime=$StartTime
            } -ErrorAction SilentlyContinue
        )
        $Logons = @(
            Get-WinEvent -FilterHashtable @{
                LogName='Security'
                Id=4624
                StartTime=$StartTime
            } -ErrorAction SilentlyContinue
        )
        Clear-Host
        Write-Host "============================================================" -ForegroundColor Cyan
        Write-Host "                 WINDOWS SYSTEM REPORT" -ForegroundColor Cyan
        Write-Host "============================================================" -ForegroundColor Cyan
        Write-Host ""
        Write-Host "System Information as of $(Get-Date)"
        Write-Host ""
        Write-Host (" Computer Name:        {0}" -f $env:COMPUTERNAME)
        Write-Host (" Windows:              {0}" -f $OS.Caption)
        Write-Host (" CPU:                  {0}" -f $CPU.Name)
        Write-Host (" Current User:         {0}" -f $env:USERNAME)
        Write-Host (" Uptime:               {0} days, {1} hours" -f $Uptime.Days,$Uptime.Hours)
        Write-Host (" Memory Used:          {0} GB / {1} GB" -f $UsedRAM,$TotalRAM)
        Write-Host (" C: Drive Used:        {0}%" -f $DiskUsed)
        Write-Host ""
        Write-Host "Activity during the last $Hours hours" -ForegroundColor Yellow
        Write-Host ""
        Write-Host (" Computer Startups:    {0}" -f $StartupEvents.Count)
        Write-Host (" Shutdown Events:      {0}" -f $ShutdownEvents.Count)
        Write-Host (" Successful Logons:    {0}" -f $Logons.Count)
        Write-Host ""
        Write-Host "============================================================" -ForegroundColor Cyan
    }
    

    After pasting that into PowerShell, you can simply type:

    Give-Log
    

    and it will show the summary for the last 24 hours.

    If you want 48 hours:

    Give-Log -Hours 48
    

    or seven days:

    Give-Log -Hours 168
    

    The result will look roughly like:

    User's image

    PowerShell can retrieve this system information through CIM/WMI, including the logged-on user, OS information, and other computer details.

    One small warning: 4624 counts successful logon events, not necessarily unique people physically signing into the desktop. Windows generates different logon types for interactive, network, service, and other sessions, so we can improve that part next if you specifically want “people who logged into the computer.”

    Once you're happy with how this looks, the next step would be to save it as a .ps1 file and add the function to your PowerShell profile. Then Give-Log can become your permanent command, so whenever you open PowerShell you can just type Give-Log without pasting the script again.

    We can also make the next version show CPU usage, IP address, failed logins, unexpected shutdowns, the actual usernames that logged in, and the exact startup/shutdown times while keeping this same clean layout. PowerShell's Get-Counter can also retrieve live Windows performance data if you want CPU statistics like the screenshot.

    References:

    Collecting information about computers with PowerShell

    Get-Counter


    Help make this community better for everyone: If this answer helped or resolved your issue, please accept it or upvote it. If not, share more details in a comment so we can continue the discussion and find the right solution. Thank you.

    Was this answer helpful?


  3. mordy kurlander 20 Reputation points
    2026-09-20T01:10:56.0833333+00:00

    This is great but is there a way for it to be more similar to this picture!? User's image

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.