I recently used an XML query in Powershell that looked like this:
[cc lang="xml" escaped="true"]$xmlQuery = @'
<Query Id="0" Path="Security">
*[System[(EventID=4624) and TimeCreated[timediff(@SystemTime) <= 86400000]] and EventData[Data[@Name='IPAddress'] and (Data='192.168.11.7')]]
The query was used to filter events from the event log that occurred within the last 24 hours. However I needed to change this 7 days. The unit of time is milliseconds but I wanted to make sure I had it exactly…