takeown /f “C:\Windows\System32\winevt\Logs”
icacls “C:\Windows\System32\winevt\Logs” /grant Administrators:F
takeown 更换所有者
icals 获取权限
icacls “C:\Windows\System32\winevt\Logs” /reset
icacls “C:\Windows\System32\winevt\Logs” /inheritance:d
Get-WmiObject -Class win32_service -Filter “name = ‘eventlog’”
Get-WmiObject -Class win32_service -Filter “name = ‘eventlog’” | select -exp ProcessId
taskkill ProcessId