# Windows event-query incident worksheet

Companion: https://happysysadm.com/windows-powershell/get-winevent-filterhashtable/
Version: 28 September 2026. Blank working template, not evidence of a completed investigation.

## Scope and authority
- Incident reference:
- Administrator and approving owner:
- Machine and service:
- User-visible symptom:
- Approved log access and evidence location:
- Windows version and PowerShell version:

## Query contract
- Local channel or saved EVTX path:
- Incident start/end and explicit time zone:
- Query start/end and explicit time zone:
- Provider, event IDs and severity (reason for each):
- Message or structured-data filter:
- Result cap and return order:
- Exact command used:

## Results and limitations
- Known event used to validate the query:
- Query outcome: completed with results / completed with no matches / failed / partial
- Returned count (sample or complete?):
- Cap reached? If yes, completeness unresolved:
- Errors and corrective action:
- Oldest/newest returned event:
- Retention or missing-interval concerns:
- Original EVTX location and capture time:
- Review-copy location and redactions:
- Correlated application/monitoring evidence:

## Decision
- What the evidence supports:
- What remains unknown:
- Next action, owner and due date:
- Independent review:

Do not record credentials here. Preserve original logs separately with appropriate access and retention. A matching event is a lead, not proof of causation. CSV review copies are not replacements for EVTX evidence.
