Set wmi = GetObject("winmgmts:{impersonationLevel=impersonate,(Security)}!\\" & hostName & "\root\cimv2") RRS feed

  • Question

  • Matthew Beattie,

    I have recently seen your queryeventlogs.vbs cscript on the forum.

    It uses a "moniker" argument for impersonationLevel I have not seen before, i.e (Security).

    Using this resolved a problem I had with the Windows 7 Security event log; its contents being unauthorised to me, with:-

    Set objWMIService = GetObject("winmgmts:" _
        & "{impersonationLevel=impersonate}!\\" & strComputer & "\root\cimv2")

    but readable with:-

    Set objWMIService = GetObject("winmgmts:" _

       & "{impersonationLevel=impersonate,(Security)}!\\" & strComputer & "\root\cimv2")

    Previously, recommended solutions to the problem of adopting administrators authority or using wevtutil to authorise my profile access using its SSID did not work.

    Can you please advise me what other (xxxxxxx) arguments are available for the "moniker" ?

    Is there documentation for them and descriptions of their meaning?

    For instance, I cannot access the Windows Setup event log file; to which I am apparently, unauthorised. Is their a

    (xxxxxx) argument for that?

    I tried:-

    Set objWMIService = GetObject("winmgmts:" _

       & "{impersonationLevel=impersonate,(Setup)}!\\" & strComputer & "\root\cimv2")

    but that does not work..

    Thank you

    • Moved by Bill_Stewart Thursday, January 3, 2019 3:51 PM This is not "debug/fix/rewrite my script for me" forum
    Thursday, November 1, 2018 2:55 PM

All replies

  • This is not a "Matthew Beattie" forum.  Please post in the correct place for this person.

    You can also search the web for the documentation for your question.


    Thursday, November 1, 2018 8:08 PM