[rt.cpan.org #61484] missing results with Win32::EventLog

[email protected] ("Paul Faulstich via RT")
Newsgroups perl.libwin32
Message-ID <[email protected]>
Mon Sep 20 10:05:52 2010: Request 61484 was acted upon.
Transaction: Ticket created by [email protected]
       Queue: Win32-EventLog
     Subject: missing results with Win32::EventLog
   Broken in: (no value)
    Severity: (no value)
       Owner: Nobody
  Requestors: [email protected]
      Status: new
 Ticket <URL: https://rt.cpan.org/Ticket/Display.html?id=61484 >


I am finding that Win32::EventLog does not consistently pull all the
data from the event log.  I suspect this may be because I am pulling
data from remote machines.  I have looked though the source code for a
place that might have a hidden timeout or synchronization issue that
is causing events to be dropped, but I am not seeing it. Also, I can
run my script over and over, and I get the same results, which I
wouldn't expect with a timeout or synchronization problem.

I also wonder if it has to do with needing to change the value of
other parameters, such as NumberOfBytesToRead, which I don't appear to
be able to set.  See
http://msdn.microsoft.com/en-us/library/aa363674%28VS.85%29.aspx

Enclosed are three files:
* my example perl script. This script prints details of all events
whose Source includes the string "Symantec". For other events, it
prints just the Source name. (exampleEventLog.pl)
* the results from running the perl script, which contains only 4
entries with a source of Symantec Antivirus (example.out5.txt)
* a screenshot of the EventViewer for that machine, which shows far
more than 4 entries for Symantec Antivirus, including entries
interspersed between those that the perl script found. (snap447.png)

Please let me know if there are other tests I can do to help resolve
this problem.  I guess the good news is my results are consistent with
any given PC.

Thanks,

Paul

--
Paul Faulstich, GIAC GSEC
SEnnovation.com
example.out5.txt (text/plain, 5.9 KB)
Machine: BG60246
!!!!!
Source: crypt32
!!!!!
Source: crypt32
!!!!!
Source: crypt32
!!!!!
Source: crypt32
!!!!!
Source: crypt32
!!!!!
Source: crypt32
!!!!!
Source: crypt32
!!!!!
Source: crypt32
!!!!!
Source: crypt32
!!!!!
Source: crypt32
!!!!!
Source: crypt32
!!!!!
Source: crypt32
!!!!!
Source: crypt32
!!!!!
Source: crypt32
!!!!!
Source: crypt32
!!!!!
Source: crypt32
!!!!!
Source: crypt32
!!!!!
Source: crypt32
!!!!!
Source: SecurityCenter
!!!!!
Source: ccSvcHst
!!!!!
Source: crypt32
!!!!!
Source: crypt32
!!!!!
Source: crypt32
!!!!!
Source: crypt32
!!!!!
Source: crypt32
!!!!!
Source: crypt32
!!!!!
Source: crypt32
!!!!!
Source: Offline Files
!!!!!
Source: crypt32
!!!!!
Source: crypt32
!!!!!
Source: RCONSVC
!!!!!
Source: crypt32
!!!!!
Source: crypt32
!!!!!
Source: crypt32
!!!!!
Source: crypt32
!!!!!
Source: crypt32
!!!!!
Source: crypt32
!!!!!
Source: crypt32
!!!!!
Source: crypt32
!!!!!
Source: crypt32
!!!!!
Source: crypt32
!!!!!
Source: crypt32
!!!!!
Source: crypt32
====================================================
Sat Sep 18 22:51:59 2010 BG60246[12] Symantec AntiVirus:INFORMATION


Changed value 'HKLM\SOFTWARE\Symantec\Symantec Endpoint Protection\AV\Storages\MicrosoftExchangeClient\RealTimeScan\FileType' from '0' to '1'
====================================================
Sat Sep 18 22:51:59 2010 BG60246[12] Symantec AntiVirus:INFORMATION


New Value 'HKLM\SOFTWARE\Symantec\Symantec Endpoint Protection\AV\Quarantine\ForwardingPort' = '33'
====================================================
Sat Sep 18 22:51:52 2010 BG60246[14] Symantec AntiVirus:INFORMATION


Symantec Endpoint Protection services startup was successful.
!!!!!
Source: MsiInstaller
!!!!!
Source: crypt32
!!!!!
Source: MsiInstaller
!!!!!
Source: MsiInstaller
!!!!!
Source: ccSvcHst
!!!!!
Source: SescLU
!!!!!
Source: RCONSVC
====================================================
Fri Sep 17 23:17:43 2010 BG60246[14] Symantec AntiVirus:INFORMATION


Symantec Endpoint Protection services startup was successful.
!!!!!
Source: MsiInstaller
!!!!!
Source: MsiInstaller
!!!!!
Source: UPHClean
!!!!!
Source: MsiInstaller
!!!!!
Source: MsiInstaller
!!!!!
Source: MsiInstaller
!!!!!
Source: UPHClean
!!!!!
Source: MsiInstaller
!!!!!
Source: Folder Redirection
!!!!!
Source: RCONSVC
!!!!!
Source: MsiInstaller
!!!!!
Source: Outlook
!!!!!
Source: RCONSVC
!!!!!
Source: MsiInstaller
!!!!!
Source: MsiInstaller
!!!!!
Source: MsiInstaller
!!!!!
Source: Outlook
!!!!!
Source: MsiInstaller
!!!!!
Source: MsiInstaller
!!!!!
Source: MsiInstaller
!!!!!
Source: MsiInstaller
!!!!!
Source: MsiInstaller
!!!!!
Source: MsiInstaller
!!!!!
Source: MsiInstaller
!!!!!
Source: MsiInstaller
!!!!!
Source: MsiInstaller
!!!!!
Source: MsiInstaller
!!!!!
Source: MsiInstaller
!!!!!
Source: MsiInstaller
!!!!!
Source: MsiInstaller
!!!!!
Source: MsiInstaller
!!!!!
Source: MsiInstaller
!!!!!
Source: MsiInstaller
!!!!!
Source: MsiInstaller
!!!!!
Source: MsiInstaller
!!!!!
Source: MsiInstaller
!!!!!
Source: MsiInstaller
!!!!!
Source: MsiInstaller
!!!!!
Source: MsiInstaller
!!!!!
Source: MsiInstaller
!!!!!
Source: MsiInstaller
!!!!!
Source: MsiInstaller
!!!!!
Source: MsiInstaller
!!!!!
Source: MsiInstaller
!!!!!
Source: MsiInstaller
!!!!!
Source: MsiInstaller
!!!!!
Source: MsiInstaller
!!!!!
Source: MsiInstaller
!!!!!
Source: MsiInstaller
!!!!!
Source: MsiInstaller
!!!!!
Source: MsiInstaller
!!!!!
Source: MsiInstaller
!!!!!
Source: MsiInstaller
!!!!!
Source: MsiInstaller
!!!!!
Source: MsiInstaller
!!!!!
Source: MsiInstaller
!!!!!
Source: MsiInstaller
!!!!!
Source: MsiInstaller
!!!!!
Source: MsiInstaller
!!!!!
Source: MsiInstaller
!!!!!
Source: MsiInstaller
!!!!!
Source: MsiInstaller
!!!!!
Source: MsiInstaller
!!!!!
Source: MsiInstaller
!!!!!
Source: MsiInstaller
!!!!!
Source: MsiInstaller
!!!!!
Source: MsiInstaller
!!!!!
Source: UPHClean
!!!!!
Source: MsiInstaller
!!!!!
Source: MsiInstaller
!!!!!
Source: MsiInstaller
!!!!!
Source: MsiInstaller
!!!!!
Source: MsiInstaller
!!!!!
Source: MsiInstaller
!!!!!
Source: MsiInstaller
!!!!!
Source: WinMgmt
!!!!!
Source: WinMgmt
!!!!!
Source: RCONSVC
!!!!!
Source: MsiInstaller
!!!!!
Source: MsiInstaller
!!!!!
Source: MsiInstaller
!!!!!
Source: WinMgmt
!!!!!
Source: WinMgmt
!!!!!
Source: WinMgmt
!!!!!
Source: WinMgmt
!!!!!
Source: MsiInstaller
!!!!!
Source: crypt32
!!!!!
Source: crypt32
!!!!!
Source: crypt32
!!!!!
Source: crypt32
!!!!!
Source: MsiInstaller
!!!!!
Source: MsiInstaller
!!!!!
Source: MsiInstaller
!!!!!
Source: MsiInstaller
!!!!!
Source: MsiInstaller
!!!!!
Source: MsiInstaller
!!!!!
Source: MsiInstaller
!!!!!
Source: MsiInstaller
!!!!!
Source: MsiInstaller
!!!!!
Source: MsiInstaller
!!!!!
Source: MsiInstaller
!!!!!
Source: MsiInstaller
!!!!!
Source: MsiInstaller
!!!!!
Source: MsiInstaller
!!!!!
Source: MsiInstaller
!!!!!
Source: MsiInstaller
!!!!!
Source: MsiInstaller
!!!!!
Source: MsiInstaller
!!!!!
Source: MsiInstaller
!!!!!
Source: MsiInstaller
!!!!!
Source: MsiInstaller
!!!!!
Source: MsiInstaller
!!!!!
Source: MsiInstaller
!!!!!
Source: MsiInstaller
!!!!!
Source: MsiInstaller
!!!!!
Source: MsiInstaller
!!!!!
Source: MsiInstaller
!!!!!
Source: MsiInstaller
!!!!!
Source: MsiInstaller
!!!!!
Source: MsiInstaller
!!!!!
Source: MsiInstaller
!!!!!
Source: MsiInstaller
!!!!!
Source: MsiInstaller
!!!!!
Source: MsiInstaller
!!!!!
Source: MsiInstaller
!!!!!
Source: MsiInstaller
!!!!!
Source: MsiInstaller
!!!!!
Source: MsiInstaller
!!!!!
Source: MsiInstaller
!!!!!
Source: MsiInstaller
!!!!!
Source: MsiInstaller
!!!!!
Source: MsiInstaller
!!!!!
Source: MsiInstaller
!!!!!
Source: MsiInstaller
!!!!!
Source: MsiInstaller
!!!!!
Source: MsiInstaller
!!!!!
Source: MsiInstaller
!!!!!
Source: MsiInstaller
!!!!!
Source: MsiInstaller
!!!!!
Source: MsiInstaller
!!!!!
Source: MsiInstaller
!!!!!
Source: LoadPerf
!!!!!
Source: System.ServiceModel.Install 3.0.0.0
!!!!!
Source: System.ServiceModel.Install 3.0.0.0
!!!!!
Source: MsiInstaller
!!!!!
Source: MsiInstaller
!!!!!
Source: MsiInstaller
!!!!!
Source: MsiInstaller
!!!!!
Source: MsiInstaller
!!!!!
Source: UPHClean
exampleEventLog.pl (application/octet-stream, 1.3 KB)
use strict;

use Win32::EventLog;
my $EventLog;

# each event has a type, this is a translation of the common types
my %type = (1  => "ERROR",
         2  => "WARNING",
         4  => "INFORMATION",
         8  => "AUDIT_SUCCESS",
         16 => "AUDIT_FAILURE");
 
# if this is set, we also retrieve the full text of every 
# message on each Read(  )
$Win32::EventLog::GetMessageText = 1; 


my $machinename  = "BG60246";

print "Machine: $machinename\n";

# open the System event log
my $log = new Win32::EventLog("Application", $machinename) 
  or die "Unable to open system log:$^E\n";

# read through it one record at a time, starting with the first entry
my $entry;
while ($log->Read((EVENTLOG_SEQUENTIAL_READ|EVENTLOG_BACKWARDS_READ),
             1,$entry)){
    if (index($entry->{Source}, "Symantec") >=0) {
        # this is a symantec entry
        print "====================================================\n";
        print scalar localtime($entry->{TimeGenerated})." ";
        print $entry->{Computer}."[".($entry->{EventID} &
              0xffff)."] ";
        print $entry->{Source}.":".$type{$entry->{EventType}};
        print $entry->{Message};

    } else {
        print "!!!!!\nSource: $entry->{Source}\n";
    }
}
snap447.png (image/png, 37.1 KB) - not displayed
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.