Working With WMI Events

Working With WMI Events

  • Comments 6

PowerShell V1 does not provide native support for WMI events. That doesn't mean that you can't use WMI events with PowerShell, it just means that you need to leverage the .NET classes to do so. This falls into the category of "to ship is to choose". Here is a function that you can use to work with WMI events. This function takes a WMI class name (and optionally a path to a namespace [it defaults to root\cimv2]) and gets the events until you enter ESCAPE or 'q' at the keyboard.

Function Get-WmiEvent ($class, $Path="root\cimv2")
$ESCkey = 27
$Qkey = 81

$query = New-Object System.Management.WQlEventQuery "Select * from $class"
$scope = New-Object System.Management.ManagementScope $Path
$watcher = New-Object System.Management.ManagementEventWatcher $scope,$query
$options = New-Object System.Management.EventWatcherOptions
$options.TimeOut = [timespan]"0.0:0:1"
$watcher.Options = $Options
while ($true) {
trap [System.Management.ManagementException] {continue}
if ($host.ui.RawUi.KeyAvailable)
{ $key = $host.ui.RawUI.ReadKey("NoEcho,IncludeKeyUp")
if (($key.VirtualKeyCode -eq $ESCkey) -OR ($key.VirtualKeyCode -eq $Qkey))
{ $watcher.Stop()

Set-Alias gwe Get-WmiEvent

NOTE: This function is available as an attachement below.

From here you might ask yourself the question: OK but what are the WMI Events? You might think that Events follow the naming patter: WMI*EVENT. Sadly, you'd be wrong. Here is how you find all the WMI events in a particular namespace:

PS> Get-WmiObject -list -namespace root\cimv2 |
>> where {$_.__Derivation -contains "__EVENT"}

__NamespaceOperationEvent __NamespaceModificationEvent
__NamespaceDeletionEvent __NamespaceCreationEvent
__ClassOperationEvent __ClassDeletionEvent
__ClassModificationEvent __ClassCreationEvent
__InstanceOperationEvent __InstanceCreationEvent
__MethodInvocationEvent __InstanceModificationEvent
__InstanceDeletionEvent __TimerEvent
__ExtrinsicEvent __SystemEvent
__EventDroppedEvent __EventQueueOverflowEvent
__QOSFailureEvent __ConsumerFailureEvent
MSFT_NetSevereServiceFailed MSFT_NetTransactInvalid
MSFT_NetServiceNotInteractive MSFT_NetTakeOwnership
MSFT_NetServiceConfigBackoutFailed MSFT_NetServiceShutdownFailed
MSFT_NetServiceStartHung MSFT_NetServiceStopControlSuccess
MSFT_NetServiceSlowStartup MSFT_NetCallToFunctionFailed
MSFT_NetBadAccount MSFT_NetBadServiceState
MSFT_NetConnectionTimeout MSFT_NetCircularDependencyAuto
MSFT_NetServiceStartTypeChanged MSFT_NetServiceLogonTypeNotGranted
MSFT_NetServiceStartFailedGroup MSFT_NetDependOnLaterService
MSFT_NetFirstLogonFailedII MSFT_NetServiceDifferentPIDConnected
MSFT_NetServiceCrashNoAction MSFT_NetCircularDependencyDemand
MSFT_NetServiceExitFailed MSFT_NetServiceStartFailedII
MSFT_NetServiceExitFailedSpecific MSFT_NetBootSystemDriversFailed
MSFT_NetInvalidDriverDependency MSFT_NetServiceCrash
MSFT_NetServiceRecoveryFailed MSFT_NetServiceStatusSuccess
MSFT_NetTransactTimeout MSFT_NetFirstLogonFailed
MSFT_NetServiceControlSuccess MSFT_NetServiceStartFailed
MSFT_NetServiceStartFailedNone MSFT_NetReadfileTimeout
MSFT_NetRevertedToLastKnownGood MSFT_NetCallToFunctionFailedII
MSFT_NetDependOnLaterGroup MSFT_WmiSelfEvent
MSFT_WmiEssEvent MSFT_WmiThreadPoolEvent
MSFT_WmiThreadPoolThreadCreated MSFT_WmiThreadPoolThreadDeleted
MSFT_WmiRegisterNotificationSink MSFT_WmiFilterEvent
MSFT_WmiFilterDeactivated MSFT_WmiFilterActivated
MSFT_WmiCancelNotificationSink MSFT_WmiProviderEvent
MSFT_WmiConsumerProviderEvent MSFT_WmiConsumerProviderSinkLoaded
MSFT_WmiConsumerProviderSinkUnloaded MSFT_WmiConsumerProviderUnloaded
MSFT_WmiConsumerProviderLoaded Msft_WmiProvider_OperationEvent
Msft_WmiProvider_ComServerLoadOper... Msft_WmiProvider_OperationEvent_Post
Msft_WmiProvider_PutInstanceAsyncE... Msft_WmiProvider_CreateInstanceEnu...
Msft_WmiProvider_DeleteInstanceAsy... Msft_WmiProvider_CancelQuery_Post
Msft_WmiProvider_NewQuery_Post Msft_WmiProvider_ProvideEvents_Post
Msft_WmiProvider_ExecQueryAsyncEve... Msft_WmiProvider_AccessCheck_Post
Msft_WmiProvider_CreateClassEnumAs... Msft_WmiProvider_DeleteClassAsyncE...
Msft_WmiProvider_ExecMethodAsyncEv... Msft_WmiProvider_GetObjectAsyncEve...
Msft_WmiProvider_PutClassAsyncEven... Msft_WmiProvider_InitializationOpe...
Msft_WmiProvider_InitializationOpe... Msft_WmiProvider_LoadOperationFail...
Msft_WmiProvider_ComServerLoadOper... Msft_WmiProvider_UnLoadOperationEvent
Msft_WmiProvider_LoadOperationEvent Msft_WmiProvider_OperationEvent_Pre
Msft_WmiProvider_DeleteInstanceAsy... Msft_WmiProvider_AccessCheck_Pre
Msft_WmiProvider_ExecQueryAsyncEve... Msft_WmiProvider_DeleteClassAsyncE...
Msft_WmiProvider_NewQuery_Pre Msft_WmiProvider_PutInstanceAsyncE...
Msft_WmiProvider_CreateClassEnumAs... Msft_WmiProvider_ExecMethodAsyncEv...
Msft_WmiProvider_ProvideEvents_Pre Msft_WmiProvider_CancelQuery_Pre
Msft_WmiProvider_PutClassAsyncEven... Msft_WmiProvider_GetObjectAsyncEve...
Msft_WmiProvider_CreateInstanceEnu... MSFT_WMI_GenericNonCOMEvent
Win32_ComputerSystemEvent Win32_ComputerShutdownEvent
Win32_IP4RouteTableEvent MSFT_NCProvEvent
MSFT_NCProvCancelQuery MSFT_NCProvClientConnected
MSFT_NCProvNewQuery MSFT_NCProvAccessCheck
RegistryEvent RegistryKeyChangeEvent
RegistryTreeChangeEvent RegistryValueChangeEvent
Win32_SystemTrace Win32_ProcessTrace
Win32_ProcessStartTrace Win32_ProcessStopTrace
Win32_ModuleTrace Win32_ModuleLoadTrace
Win32_ThreadTrace Win32_ThreadStartTrace
Win32_ThreadStopTrace Win32_PowerManagementEvent
Win32_DeviceChangeEvent Win32_SystemConfigurationChangeEvent


Here is an example of it working (I run this for a while and then type ESC):

PS> gwe Win32_ProcessStopTrace |ft ProcessName,Processid -auto

ProcessName Processid
----------- ---------
ipconfig.exe 4664
notepad.exe 3980
calc.exe 3816

I hope you find this useful.


Jeffrey Snover [MSFT]
Windows PowerShell/MMC Architect
Visit the Windows PowerShell Team blog at:
Visit the Windows PowerShell ScriptCenter at:

Attachment: get-wmievent.ps1
Leave a Comment
  • Please add 1 and 6 and type the answer here:
  • Post
  • This is very interesting especially for WMI based scripts.

    A while ago I wrote a Powershell script which at the end made use of the Windows Media Player ActiveX Control. One thing I wanted to do was to make the script sink the Media Player events. Is it possible to do so in Power Shell? I ask this because a lot of COM objects provided by Windows have this feature of event notifications and it would be nice to know if this is doable in Power shell.


  • hi. I haven't seen any documentation specifically answereing this question:

    Is it necessary to install powershell on a remote system in order to use powershell scripts against from a remote workstation?

    In other words if I install Powershell on my workstations will the scripts run against my servers if I haven't installed powershell on them?


  • > it necessary to install powershell on a remote system in order to use powershell scripts against from a remote workstation?

    Your scripts can run locally and access your remove workstation using the WMI commands.

    Jeffrey Snover [MSFT]

    Windows PowerShell/MMC Architect

    Visit the Windows PowerShell Team blog at:

    Visit the Windows PowerShell ScriptCenter at:

  • This post builds on Jeffrey's post on wmi events -

  • This post builds on Jeffrey's post on wmi events -

  • The WMI events don't appear to function under Windows Vista. Even when run as admin.

Page 1 of 1 (6 items)