Windows7 log query log on and off within 30 days

 

custom view

XML:

 

<QueryList>
  <Query Id="0" Path="System">
    <Select Path="System">*[System[Provider[@Name='Microsoft-Windows-Kernel-General'] and (EventID=12 or EventID=13) and TimeCreated[timediff(@SystemTime) <= 2592000000]]]</Select>
  </Query>
</QueryList>

Guess you like

Origin http://10.200.1.11:23101/article/api/json?id=327050504&siteId=291194637