Retrieves events from the Application and System event logs.

This script was tested using Python 2.2.2-224 for Microsoft Windows, available from ActiveState.

import win32com.client
strComputer = "."
objWMIService = win32com.client.Dispatch("WbemScripting.SWbemLocator")
objSWbemServices = objWMIService.ConnectServer(strComputer,"root\cimv2")
colItems = objSWbemServices.ExecQuery("Select * from Win32_NTLogEvent")
for objItem in colItems:
    print "Category: ", objItem.Category
    print "Category String: ", objItem.CategoryString
    print "Computer Name: ", objItem.ComputerName
    z = objItem.Data
    if z is None:
        a = 1
        for x in z:
            print "Data: ", x
    print "Event Code: ", objItem.EventCode
    print "Event Identifier: ", objItem.EventIdentifier
    print "Event Type: ", objItem.EventType
    z = objItem.InsertionStrings
    if z is None:
        a = 1
        for x in z:
            print "Insertion Strings: ", x
    print "Logfile: ", objItem.Logfile
    print "Message: ", objItem.Message
    print "Record Number: ", objItem.RecordNumber
    print "Source Name: ", objItem.SourceName
    print "Time Generated: ", objItem.TimeGenerated
    print "Time Written: ", objItem.TimeWritten
    print "Type: ", objItem.Type
    print "User: ", objItem.User