Public/Get-IntuneAgentLog.ps1

function Get-IntuneAgentLog {
    <#
    .EXTERNALHELP IntuneScriptLab-Help.xml
    .SYNOPSIS
        Reads the Intune Management Extension logs as objects, with the events the agent's lines record.
    #>

    [CmdletBinding(DefaultParameterSetName = 'Read')]
    [OutputType('IntuneScriptLab.AgentLogEntry')]
    param(
        [Parameter(ParameterSetName = 'Read', Position = 0)]
        [string[]]$Path,

        [Parameter(ParameterSetName = 'Read')]
        [ValidateSet('Agent', 'AppWorkload', 'HealthScripts', 'AgentExecutor', 'All')]
        [string[]]$Log = @('Agent', 'AppWorkload', 'HealthScripts', 'AgentExecutor'),

        [Parameter(ParameterSetName = 'Read')]
        [string[]]$Id,

        [Parameter(ParameterSetName = 'Read')]
        [string[]]$EventName,

        [Parameter(ParameterSetName = 'Read')]
        [string]$Pattern,

        [Parameter(ParameterSetName = 'Read')]
        [ValidateSet('Information', 'Warning', 'Error')]
        [string[]]$Level,

        [Parameter(ParameterSetName = 'Read')]
        [datetime]$After,

        [Parameter(ParameterSetName = 'Read')]
        [datetime]$Before,

        [Parameter(ParameterSetName = 'Read')]
        [ValidateRange(1, [int]::MaxValue)]
        [int]$Last,

        [Parameter(ParameterSetName = 'List', Mandatory)]
        [switch]$ListEvent
    )
    Write-Verbose "Starting $($MyInvocation.MyCommand.Name) for $($PSBoundParameters.Keys -join ', ')"

    # Touching the table once compiles it, for -ListEvent and for validating -EventName
    $null = Get-IslAgentLogEvent -Message ''
    if ($ListEvent) {
        foreach ($definition in $script:IslAgentLogEvents) {
            [pscustomobject]@{
                PSTypeName = 'IntuneScriptLab.AgentLogEventDefinition'
                Event      = $definition.Event
                Pattern    = $definition.Regex.ToString()
            }
        }
        return
    }
    $knownEvents = @($script:IslAgentLogEvents | ForEach-Object { $_.Event })
    foreach ($name in $EventName) {
        if ($name -notin $knownEvents) {
            throw "Unknown event '$name'. Get-IntuneAgentLog -ListEvent shows the names"
        }
    }

    if (-not $Path) {
        $programData = if ($env:ProgramData) { $env:ProgramData } else { 'C:\ProgramData' }
        $Path = @(Join-Path -Path $programData -ChildPath 'Microsoft\IntuneManagementExtension\Logs')
    }
    $filters = @{
        Agent         = 'IntuneManagementExtension*.log'
        AppWorkload   = 'AppWorkload*.log'
        HealthScripts = 'HealthScripts*.log'
        AgentExecutor = 'AgentExecutor*.log'
        All           = '*.log'
    }
    $files = foreach ($item in $Path) {
        $resolved = (Resolve-Path -LiteralPath $item -ErrorAction Stop).ProviderPath
        if (Test-Path -LiteralPath $resolved -PathType Container) {
            foreach ($name in $Log) {
                Get-ChildItem -LiteralPath $resolved -Filter $filters[$name] -File | ForEach-Object { $_.FullName }
            }
        }
        else { $resolved }
    }
    $files = @($files | Sort-Object -Unique)
    if (-not $files) {
        Write-Warning "No log files under $($Path -join ', ')"
        return
    }

    $idPatterns = @(foreach ($value in $Id) { [regex]::Escape($value) })
    $entries = foreach ($file in $files) {
        Write-Verbose "Reading $file"
        foreach ($entry in ConvertFrom-IslCmTraceLog -Path $file) {
            if ($Level -and $entry.Level -notin $Level) { continue }
            if ($PSBoundParameters.ContainsKey('After') -and $entry.Time -lt $After) { continue }
            if ($PSBoundParameters.ContainsKey('Before') -and $entry.Time -ge $Before) { continue }
            if ($Pattern -and $entry.Message -notmatch $Pattern) { continue }
            if ($idPatterns.Count) {
                $found = $false
                foreach ($idPattern in $idPatterns) {
                    if ($entry.Message -imatch $idPattern) { $found = $true; break }
                }
                if (-not $found) { continue }
            }
            $classified = Get-IslAgentLogEvent -Message $entry.Message
            if ($EventName -and $classified.Event -notin $EventName) { continue }
            $entry.Event = $classified.Event
            $entry.Detail = $classified.Detail
            $entry.Id = $classified.Id
            $entry
        }
    }
    $entries = @($entries | Sort-Object -Property Time, Log, Line)
    if ($Last -and $entries.Count -gt $Last) {
        $entries = $entries[($entries.Count - $Last)..($entries.Count - 1)]
    }
    Write-Verbose "Completed $($MyInvocation.MyCommand.Name): $($entries.Count) entries from $($files.Count) files"
    $entries
}