Код:

@echo off
setlocal enabledelayedexpansion
For /F "Tokens=1* Delims==" %%A In ('WMIC NTEVENTLOG GET LogFileName /Value^|FindStr .^| Findstr /i /c:"Application" /c:"System" /c:"Security"') Do (
Call WMIC NTEVENTLOG Where ^(LogFileName^="%%B"^) Call BackupEventLog "C:\%%B.evtx"
)
pause
exit