You are on page 1of 1

set Logs=c:\%computername%-logs

md %logs%
echo %date% %time% collection started > %logs%\%computername%_running.txt
w32tm /debug /enable /file:C:\windows\temp\w32time.log /size:10000000 /entries:0-
300
wevtutil.exe export-log "Microsoft-Windows-Time-Service/Operational" %logs%\
%computername%_EVT-Time-Service.evtx /overwrite:true
wevtutil.exe export-log System %logs%\%computername%_EVT-System.evtx
/overwrite:true
wevtutil.exe export-log Application %logs%\%computername%_EVT-Application.evtx
/overwrite:true
tasklist /v > %logs%\%computername%_Task.txt
Tasklist /svc >> %logs%\%computername%_Task.txt
reg query "HKLM\SYSTEM\CurrentControlSet\Services\W32Time" /s > %logs%\
%computername%_W32time_reg.txt
reg query "HKLM\SOFTWARE\Policies\Microsoft\W32Time" /s > %logs%\%computername
%_W32time_GPreg.txt
Reg query "HKLM\SYSTEM\CurrentControlSet\Control\TimeZoneInformation" /s > %logs%\
%computername%_SystemTimeZone.txt
Reg query "HKLM\SYSTEM\CurrentControlSet\Services\tzautoupdate" /s > %logs%\
%computername%_TZUpdate.txt
Reg query "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones" /s > %logs
%\%computername%_TimeZones.txt
W32tm /tz > %logs%\%computername%_W32TimeZone.txt
Gpresult /f /h %logs%\%computername%_RSOP.html
Sc query w32time > %logs%\%computername%_SC_time.txt
w32tm /query /configuration /verbose > %logs%\%computername%_W32time_config.txt
w32tm /query /peers /verbose > %logs%\%computername%_W32TimePeers.txt
w32tm /query /status /verbose > %logs%\%computername%_W32TimeStatus.txt
w32tm /query /source /verbose > %logs%\%computername%_W32TimeSource.txt
w32tm /stripchart /computer:time.windows.com /samples:10 > %logs%\%computername
%_W32time-windows_StripChart.txt
W32tm /monitor > %logs%\%computername%_W32time-Monitor.txt
auditpol /get /category:* > %logs%\%computername%_Auditpol_Configuraton.txt
schtasks.exe /query /v > %logs%\Schtasks.query.v.txt
schtasks.exe /query /xml > %logs%\Schtasks.query.xml.txt
msinfo32 /nfo %logs%\%computername%_Msinfo.nfo
Copy /y C:\windows\temp\w32time.log %logs%\%computername%_w32time.log
for /F "usebackq tokens=2" %i IN (`nltest /DSGETDC:%userdomain% /PDC ^| find
"DC:"`) do set PDC=%i
set PDC=%PDC:\\=%

set > %logs%\%computername%_ENV.txt


w32tm /stripchart /computer:%PDC% /samples:10 > %logs%\%computername
%_W32PDC_StripChart.txt
echo %date% %time% collection commplete >> %logs%\%computername%_running.txt

You might also like