strComputer = "."
Set objWMIService = GetObject("winmgmts:" & "{impersonationLevel=impersonate,(Security)}!\\" & strComputer & "\root\CIMV2")
Set colItems = objWMIService.ExecQuery("Select * from Win32_NTLogEvent Where EventCode = '6013'")
msgbox colItems.ItemIndex(0).Message
缺点:查询时间长(需要17秒),CPU占用高。