get-eventLog system | select-object -unique -expandProperty source
c:\> wmic ntevent where "eventType<3 and logFile = 'system' and timeGenerated>'20190531'" get eventCode, eventIdentifier, recordNumber, sourceName, timeGenerated, type c:\> wmic ntevent where "recordNumber = 5710098" get insertionStrings
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog