Win Eventlog Triage

Triage Windows Event Logs across one or many servers. Pulls Critical/Error events (System + Application by default; Security opt-in) over a time window via PowerShell Remoting (WinRM), groups them deterministically, and returns JSON the agent turns into a short, critical-first summary. Use when the user wants to check/triage/investigate Windows server event logs — e.g. "what happened on SRV01 overnight", "triage the event logs on these servers", or "any errors across the file servers in the last 12 hours". Requires PowerShell 7+ and a tier-admin credential (always prompted).

whobat 473fbf6 5 files · 55.4 KB Updated

File contents

whobat/AI-Agent-skills/tree/main/skills/windows-ops/win-eventlog-triage commit 473fbf6a03

Frequently asked questions

npx skillmds@latest add whobat/win-eventlog-triage