Monthly Archive


Monthly Archives: July 2009

PowerShell in Practice Ch14&15

The latest MEAP for PowerShell in Practice adds chapters 14 and 15 to the set. The book is essentially complete now – with just the appendix and the stuff at the front to do

It can be obtained from

Technorati Tags: PowerShell in Practice

Its a wrap

When we run a cmdlet such as Get-EventLog we often find that the display is truncated

PS> Get-EventLog -LogName Application | select -First 5

  Index Time          EntryType   Source                 InstanceID Message
   ----- ----          ---------   ------                 ---------- -------
   12961 Jul 31 12:39  Information Com4QLBEx                       0 The description for Event ID '0' in Source 'Com...
   12960 Jul 31 12:39  Information hpqwmiex                        0 The description for Event ID '0' in Source 'hpq...
   12959 Jul 31 12:39  Information Wlclntfy               2147489648 The winlogon notification subscriber <SessionEn...
   12958 Jul 31 12:39  Information Winlogon               1073745925 Windows license validated.
   12957 Jul 31 12:01  Information Windows Error Rep...         1001 Fault bucket , type 0...

If we we need to actually need to see the full information we need to use format-table

PS> Get-EventLog -LogName Application | select -First 2 | Format-Table -Wrap

   Index Time          EntryType   Source                 InstanceID Message
   ----- ----          ---------   ------                 ---------- -------
   12962 Jul 31 12:44  Information HHCTRL                       1904 The description for Event ID '1904' in Source 'HHC
                                                                     TRL' cannot be found.  The local computer may not
                                                                     have the necessary registry information or message
                                                                      DLL files to display the message, or you may not
                                                                     have permission to access them.  The following inf
                                                                     ormation is part of the event:'about:blank', 'http
   12961 Jul 31 12:39  Information Com4QLBEx                       0 The description for Event ID '0' in Source 'Com4QL
                                                                     BEx' cannot be found.  The local computer may not
                                                                     have the necessary registry information or message
                                                                      DLL files to display the message, or you may not
                                                                     have permission to access them.  The following inf
                                                                     ormation is part of the event:'Service started'

The –wrap parameter gives us the capability to display the full data.  This parameter is also available in v1.

Technorati Tags: PowerShell,format

Services and Processes

Services and processes seem to be a constant source of topics for PowerShell.  Probably because they are so fundamental to Windows. I wanted to see the relationship between a service and its underlying process.

##Requires -version 2.0
## create empty array
$data = @()
## create class for object
public class ServProc
    private string _servicename;
    private string _displayname;
    private string _processname;
    private int _processid;
     public string DisplayName {
        get {return _displayname;}
         set {_displayname = value;}
    public string ServiceName {
        get {return _servicename;}
         set {_servicename = value;}
    public string ProcessName {
        get {return _processname;}
         set {_processname = value;}
    public int ProcessId {
        get {return _processid;}
         set {_processid = value;}

Add-Type -TypeDefinition $source

Get-WmiObject -Class Win32_Service | foreach {
    $sp = New-Object -TypeName ServProc
    $sp.displayname = $_.displayname
    $sp.ServiceName = $_.Name
    $sp.ProcessId = $_.ProcessId
    $sp.ProcessName = (Get-Process -Id $($sp.ProcessId)).Name

    $data += $sp

$data | Sort processid | Format-Table -AutoSize


What we need to do is get the services and find the process id and use that to match it to the underlying process.  This sort of problem I would usually create an object and then  use add-member to  add the properties as we loop through the services.

I decided to have a go with Add-Type instead.

Add-Type is cmdlet new to PowerShell version 2. If you are not a programmer you possibly looked at the help information, shuddered and moved on.  I have done a bit of C# programming but don’t class myself as a programmer (bet all programmers reading this are looking at the class definition as saying – yep). As far as I’m concerned if it works its good.

So we start with Requires so that don’t try and run this in version 1.

We can then create an empty array. So far so good.

The next bit is where we create a .NET class. A class is what we use when we create an object – think of it in this case as a template.  The stuff in the here string   $source=@”………..”@ is the C# code that defines the class.

public means that we can access it.  ServProc is its name.  We then have four properties which are created

public  string DisplayName    {
    get {return _displayname;}
     set {_displayname = value;}

by supplying a name eg Displayname and a data type eg string.  We also supply a get and set which do what they say.  Set is usewd when we set the property and get when we read it.  The

private string _displayname;

in effect defines a private variable that is used inside the class. C# IS CASE SENSITIVE!!! and expects a ; as a line terminator

Add-Type is used to create the class.

The Win32_Service WMI class can be used to get the service side information. We create a new object using our class and then set the properties. Notice that we can use the properties of the object as soon as we have created it to get the process name.

Our object is added to the array and we loop for the next service.

Final line of the script displays the data .

The hardest part of using add-type is remembering how to define the properties in C#.  Is it worth doing this compared to Add-Member?

It makes the working part of the script neater but makes the earlier part more complicated.  If you are not  happy with C# probably not for you though other languages can be used. On the other hand if all you want is an object with some properties you have a template here that can be re-used. Just create a private variable for each property and make sure you get the data type right.

Will I use this instead of Add-Member – probably. Especially where I am creating a module with a number of functions that will use the same object.

It wasn’t as difficult as I thought – but I would definitely put this in the advanced PowerShell bucket for now.

User Group Live Meetings

I’ll be doing a couple of Live Meeting webcasts over the next few weeks:

  • PowerShell remoting – including Exchange 2010
  • WMI in PowerShell v2

More info when the dates are finalised.

If there is a particular topic that you would like to see covered please let me know

Technorati Tags: PowerShell User Group

Tombstone Periods

We can get the tombstone period of our Active Directory by

$root = [ADSI]"" 
$ds = [ADSI]("LDAP://CN=Directory Service,CN=Windows NT,CN=Services,CN=Configuration," + $root.DistinguishedName)


But if the value isn't set it means we are using the default which changes depending on the version of Windows used to create the forest in the first place. If we have upgraded then the value may not be what we think it is.

So far I haven’t found a way to get the original version of Windows used to create the forest.  It may not be possible in which case time for a rethink

PowerShell 2.0 ETA

In case you wanted more info on when we can see PowerShell v2 available as a download for XP\2003\Vista\2008  - see

The post says a few months before we can get it.  Why the delay?

Best guess is that the PowerShell Team have been concentrating on Windows 7\2008 R2 and that the final testing, fixing and packaging needs to be done for the other platforms.  Remember how the Vista install package for PowerShell v1 came out  a couple of months after the other versions.

Patience is a virtue – so I’m told.

All good things come to he who waits.

On the other hand – I can’t wait.

Technorati Tags: PowerShell v2

July User Group slides and demo

I’ve put the slides and demo file on my Sky Drive

and download the July_2009 zip file


Today’s the day the gremlins have their picnic

So the story so far.

Our intrepid presenter is sent to the wilds of Northern England and must deliver the Live Meeting to the PowerShell UG from his hotle room.  No problem.

First problem is that the network in the hotel isn’t playing the game  (thats English understatement for broken).  It will occassionally let him connect but not won’t connect to any of the interesting sites on the Internet. No! Not that sort of interesting.  Interesting as is useful like hotmail or blogs of even Live Meeting.

All the usual attempts were made to rectify the problem – try another machine, try a different time, try different part of hotel Eventually the evil deed could be postponed no longer…….  the help desk had to be rung  <gulp>

One quick restart of the router and connection is made. Whew.

Same problem Tuesday, and Wednesday. This isn’t good news.  Ring help desk again and explain sweetly how much pain they are causing – OK you know me too well – Ring up,  have major rant and give up.

Why during all this can I still connect to work email – I’m not paranoid they are out to get me.

Thursday morning connectivity looks good & can connect. Just to be safe email friends and arrange for someone to to explain circumstances if can’t connect.

Thursday evening – connectivity is good, Live Meeting is good, upload slides, share PowerShell and start.  YeeHa.

Spoke too soon.

40 minutes into the session my laptop blue screens (my first ever blue screen on Windows 7 – unbelievable!!)  Why do demos always go wrong???

Quick phone call to get Jonathan to explain whats happening while I frantically re-connect

Finish demo

Finish Q&A.  All done. Time for a beer.

Thank you to those who attended and apologies again for the glitch.  Hope you can make it for the next session.

Technorati Tags: PowerShell User Group

Good news

There’s good news – Windows 7 and Windows 2008 R2 went RTM yesterday.  Look for downloads early next month for TechNet\MSDN subscribers. General availability is 22 October.

But there’s more

Windows 7 and Windows 2008 R2 contain PowerShell v2 – hurrah.  Turned on by default.  Even better.

But there’s more

PowerShell v2 will soon be available for other systems. – Hurrah, hurrah

Excel 2010 PowerShell I

This now works for a non-US locale.

$xl = New-Object -ComObject "Excel.Application"
$xl.visible = $true
$wb = $xl.workbooks


Well to be strictly correct it works in a UK locale and I’m assuming it works for other non-US locales.  As previous versions of Excel threw a wobbly and we had to use an awful work around this is a step forward.

Now we need true PowerShell support for Office 🙂

I know the OpenXml PowerShell functionality has been extended.  Time to try that against Office 2010

Technorati Tags: PowerShell,Office 2010