$Computer = 'localhost' Get-EventLog -ComputerName $Computer System -Source Microsoft-Windows-Winlogon | select $UserProperty,$TypeProperty,$TimeProeprty