Hello @mordy kurlander
Yes, you can do this with PowerShell. Since you're just getting started, keep the first version simple and use the Windows Event Logs that already record this information.
For example, the script below asks how many hours you want to look back. If you simply press Enter, it uses the last 24 hours:
$Hours = Read-Host "How many hours should I look back? Press Enter for 24"
if ([string]::IsNullOrWhiteSpace($Hours)) {
$Hours = 24
}
$StartTime = (Get-Date).AddHours(-[int]$Hours)
Write-Host "`n=== COMPUTER STARTUP / SHUTDOWN ===" -ForegroundColor Cyan
Get-WinEvent -FilterHashtable @{
LogName = 'System'
Id = 12,13,41,1074,6005,6006,6008
StartTime = $StartTime
} -ErrorAction SilentlyContinue |
Select-Object TimeCreated, Id, ProviderName, Message |
Format-Table -Wrap
Write-Host "`n=== USER LOGON / LOGOFF ===" -ForegroundColor Cyan
Get-WinEvent -FilterHashtable @{
LogName = 'Security'
Id = 4624,4634,4647
StartTime = $StartTime
} -ErrorAction SilentlyContinue |
Select-Object TimeCreated, Id, Message |
Format-Table -Wrap
Run PowerShell as Administrator, paste the script, and press Enter. When prompted:
How many hours should I look back? Press Enter for 24:
Pressing Enter gives you the last 24 hours, while entering 48, for example, searches the last 48 hours.
The IDs in the example have specific meanings. 4624 records a successful logon, 4634 indicates a logon session ended, and 4647 represents a user-initiated logoff.
For startup/shutdown troubleshooting, Windows records events such as 1074 for an initiated shutdown/restart, 6006 for a clean shutdown, 6008 for an unexpected shutdown, and 41 when Windows restarted without shutting down cleanly. Kernel-General events 12 and 13 for OS startup and shutdown.
One important point: this won't necessarily tell you everything that happened on the computer. PowerShell can only report information Windows actually recorded. Some Security events also depend on the auditing policies that were enabled when the activity occurred.
Once this basic version works, you can expand it to produce a cleaner report showing things such as computer startup/shutdown count, usernames, logon/logoff times, failed logons, unexpected shutdowns, and export the results to CSV.
References:
Windows events recommended for monitoring
Troubleshoot unexpected reboots using event logs
Help make this community better for everyone: If this answer helped or resolved your issue, please accept it or upvote it. If not, share more details in a comment so we can continue the discussion and find the right solution. Thank you.