Glossary
Module Logging (4103)
PowerShell pipeline execution logging: event ID 4103 records commands and bound parameters as they run.
Module logging records pipeline execution details — the commands invoked and their bound parameters — to event ID 4103 in the Microsoft-Windows-PowerShell/Operational log. It complements script block logging: 4104 shows the code that was compiled, 4103 shows the commands as they executed, with a ContextInfo block naming the host, user and engine version.
It is enabled per module (or for *) by the "Turn on Module Logging" policy. In an investigation, 4103 is useful for seeing which cmdlets ran and with what arguments — for example an Invoke-WebRequest with its Uri. See the event-log guide.