[rt.cpan.org #61484] missing results with Win32::EventLog
[email protected] ("Paul Faulstich via RT")
| Newsgroups | perl.libwin32 |
|---|---|
| Message-ID | <[email protected]> |
Mon Sep 20 10:05:52 2010: Request 61484 was acted upon. Transaction: Ticket created by [email protected] Queue: Win32-EventLog Subject: missing results with Win32::EventLog Broken in: (no value) Severity: (no value) Owner: Nobody Requestors: [email protected] Status: new Ticket <URL: https://rt.cpan.org/Ticket/Display.html?id=61484 > I am finding that Win32::EventLog does not consistently pull all the data from the event log. I suspect this may be because I am pulling data from remote machines. I have looked though the source code for a place that might have a hidden timeout or synchronization issue that is causing events to be dropped, but I am not seeing it. Also, I can run my script over and over, and I get the same results, which I wouldn't expect with a timeout or synchronization problem. I also wonder if it has to do with needing to change the value of other parameters, such as NumberOfBytesToRead, which I don't appear to be able to set. See http://msdn.microsoft.com/en-us/library/aa363674%28VS.85%29.aspx Enclosed are three files: * my example perl script. This script prints details of all events whose Source includes the string "Symantec". For other events, it prints just the Source name. (exampleEventLog.pl) * the results from running the perl script, which contains only 4 entries with a source of Symantec Antivirus (example.out5.txt) * a screenshot of the EventViewer for that machine, which shows far more than 4 entries for Symantec Antivirus, including entries interspersed between those that the perl script found. (snap447.png) Please let me know if there are other tests I can do to help resolve this problem. I guess the good news is my results are consistent with any given PC. Thanks, Paul -- Paul Faulstich, GIAC GSEC SEnnovation.com
example.out5.txt
(text/plain, 5.9 KB)
Machine: BG60246 !!!!! Source: crypt32 !!!!! Source: crypt32 !!!!! Source: crypt32 !!!!! Source: crypt32 !!!!! Source: crypt32 !!!!! Source: crypt32 !!!!! Source: crypt32 !!!!! Source: crypt32 !!!!! Source: crypt32 !!!!! Source: crypt32 !!!!! Source: crypt32 !!!!! Source: crypt32 !!!!! Source: crypt32 !!!!! Source: crypt32 !!!!! Source: crypt32 !!!!! Source: crypt32 !!!!! Source: crypt32 !!!!! Source: crypt32 !!!!! Source: SecurityCenter !!!!! Source: ccSvcHst !!!!! Source: crypt32 !!!!! Source: crypt32 !!!!! Source: crypt32 !!!!! Source: crypt32 !!!!! Source: crypt32 !!!!! Source: crypt32 !!!!! Source: crypt32 !!!!! Source: Offline Files !!!!! Source: crypt32 !!!!! Source: crypt32 !!!!! Source: RCONSVC !!!!! Source: crypt32 !!!!! Source: crypt32 !!!!! Source: crypt32 !!!!! Source: crypt32 !!!!! Source: crypt32 !!!!! Source: crypt32 !!!!! Source: crypt32 !!!!! Source: crypt32 !!!!! Source: crypt32 !!!!! Source: crypt32 !!!!! Source: crypt32 !!!!! Source: crypt32 ==================================================== Sat Sep 18 22:51:59 2010 BG60246[12] Symantec AntiVirus:INFORMATION Changed value 'HKLM\SOFTWARE\Symantec\Symantec Endpoint Protection\AV\Storages\MicrosoftExchangeClient\RealTimeScan\FileType' from '0' to '1' ==================================================== Sat Sep 18 22:51:59 2010 BG60246[12] Symantec AntiVirus:INFORMATION New Value 'HKLM\SOFTWARE\Symantec\Symantec Endpoint Protection\AV\Quarantine\ForwardingPort' = '33' ==================================================== Sat Sep 18 22:51:52 2010 BG60246[14] Symantec AntiVirus:INFORMATION Symantec Endpoint Protection services startup was successful. !!!!! Source: MsiInstaller !!!!! Source: crypt32 !!!!! Source: MsiInstaller !!!!! Source: MsiInstaller !!!!! Source: ccSvcHst !!!!! Source: SescLU !!!!! Source: RCONSVC ==================================================== Fri Sep 17 23:17:43 2010 BG60246[14] Symantec AntiVirus:INFORMATION Symantec Endpoint Protection services startup was successful. !!!!! Source: MsiInstaller !!!!! Source: MsiInstaller !!!!! Source: UPHClean !!!!! Source: MsiInstaller !!!!! Source: MsiInstaller !!!!! Source: MsiInstaller !!!!! Source: UPHClean !!!!! Source: MsiInstaller !!!!! Source: Folder Redirection !!!!! Source: RCONSVC !!!!! Source: MsiInstaller !!!!! Source: Outlook !!!!! Source: RCONSVC !!!!! Source: MsiInstaller !!!!! Source: MsiInstaller !!!!! Source: MsiInstaller !!!!! Source: Outlook !!!!! Source: MsiInstaller !!!!! Source: MsiInstaller !!!!! Source: MsiInstaller !!!!! Source: MsiInstaller !!!!! Source: MsiInstaller !!!!! Source: MsiInstaller !!!!! Source: MsiInstaller !!!!! Source: MsiInstaller !!!!! Source: MsiInstaller !!!!! Source: MsiInstaller !!!!! Source: MsiInstaller !!!!! Source: MsiInstaller !!!!! Source: MsiInstaller !!!!! Source: MsiInstaller !!!!! Source: MsiInstaller !!!!! Source: MsiInstaller !!!!! Source: MsiInstaller !!!!! Source: MsiInstaller !!!!! Source: MsiInstaller !!!!! Source: MsiInstaller !!!!! Source: MsiInstaller !!!!! Source: MsiInstaller !!!!! Source: MsiInstaller !!!!! Source: MsiInstaller !!!!! Source: MsiInstaller !!!!! Source: MsiInstaller !!!!! Source: MsiInstaller !!!!! Source: MsiInstaller !!!!! Source: MsiInstaller !!!!! Source: MsiInstaller !!!!! Source: MsiInstaller !!!!! Source: MsiInstaller !!!!! Source: MsiInstaller !!!!! Source: MsiInstaller !!!!! Source: MsiInstaller !!!!! Source: MsiInstaller !!!!! Source: MsiInstaller !!!!! Source: MsiInstaller !!!!! Source: MsiInstaller !!!!! Source: MsiInstaller !!!!! Source: MsiInstaller !!!!! Source: MsiInstaller !!!!! Source: MsiInstaller !!!!! Source: MsiInstaller !!!!! Source: MsiInstaller !!!!! Source: MsiInstaller !!!!! Source: MsiInstaller !!!!! Source: MsiInstaller !!!!! Source: MsiInstaller !!!!! Source: MsiInstaller !!!!! Source: UPHClean !!!!! Source: MsiInstaller !!!!! Source: MsiInstaller !!!!! Source: MsiInstaller !!!!! Source: MsiInstaller !!!!! Source: MsiInstaller !!!!! Source: MsiInstaller !!!!! Source: MsiInstaller !!!!! Source: WinMgmt !!!!! Source: WinMgmt !!!!! Source: RCONSVC !!!!! Source: MsiInstaller !!!!! Source: MsiInstaller !!!!! Source: MsiInstaller !!!!! Source: WinMgmt !!!!! Source: WinMgmt !!!!! Source: WinMgmt !!!!! Source: WinMgmt !!!!! Source: MsiInstaller !!!!! Source: crypt32 !!!!! Source: crypt32 !!!!! Source: crypt32 !!!!! Source: crypt32 !!!!! Source: MsiInstaller !!!!! Source: MsiInstaller !!!!! Source: MsiInstaller !!!!! Source: MsiInstaller !!!!! Source: MsiInstaller !!!!! Source: MsiInstaller !!!!! Source: MsiInstaller !!!!! Source: MsiInstaller !!!!! Source: MsiInstaller !!!!! Source: MsiInstaller !!!!! Source: MsiInstaller !!!!! Source: MsiInstaller !!!!! Source: MsiInstaller !!!!! Source: MsiInstaller !!!!! Source: MsiInstaller !!!!! Source: MsiInstaller !!!!! Source: MsiInstaller !!!!! Source: MsiInstaller !!!!! Source: MsiInstaller !!!!! Source: MsiInstaller !!!!! Source: MsiInstaller !!!!! Source: MsiInstaller !!!!! Source: MsiInstaller !!!!! Source: MsiInstaller !!!!! Source: MsiInstaller !!!!! Source: MsiInstaller !!!!! Source: MsiInstaller !!!!! Source: MsiInstaller !!!!! Source: MsiInstaller !!!!! Source: MsiInstaller !!!!! Source: MsiInstaller !!!!! Source: MsiInstaller !!!!! Source: MsiInstaller !!!!! Source: MsiInstaller !!!!! Source: MsiInstaller !!!!! Source: MsiInstaller !!!!! Source: MsiInstaller !!!!! Source: MsiInstaller !!!!! Source: MsiInstaller !!!!! Source: MsiInstaller !!!!! Source: MsiInstaller !!!!! Source: MsiInstaller !!!!! Source: MsiInstaller !!!!! Source: MsiInstaller !!!!! Source: MsiInstaller !!!!! Source: MsiInstaller !!!!! Source: MsiInstaller !!!!! Source: MsiInstaller !!!!! Source: MsiInstaller !!!!! Source: MsiInstaller !!!!! Source: MsiInstaller !!!!! Source: LoadPerf !!!!! Source: System.ServiceModel.Install 3.0.0.0 !!!!! Source: System.ServiceModel.Install 3.0.0.0 !!!!! Source: MsiInstaller !!!!! Source: MsiInstaller !!!!! Source: MsiInstaller !!!!! Source: MsiInstaller !!!!! Source: MsiInstaller !!!!! Source: UPHClean
exampleEventLog.pl
(application/octet-stream, 1.3 KB)
use strict;
use Win32::EventLog;
my $EventLog;
# each event has a type, this is a translation of the common types
my %type = (1 => "ERROR",
2 => "WARNING",
4 => "INFORMATION",
8 => "AUDIT_SUCCESS",
16 => "AUDIT_FAILURE");
# if this is set, we also retrieve the full text of every
# message on each Read( )
$Win32::EventLog::GetMessageText = 1;
my $machinename = "BG60246";
print "Machine: $machinename\n";
# open the System event log
my $log = new Win32::EventLog("Application", $machinename)
or die "Unable to open system log:$^E\n";
# read through it one record at a time, starting with the first entry
my $entry;
while ($log->Read((EVENTLOG_SEQUENTIAL_READ|EVENTLOG_BACKWARDS_READ),
1,$entry)){
if (index($entry->{Source}, "Symantec") >=0) {
# this is a symantec entry
print "====================================================\n";
print scalar localtime($entry->{TimeGenerated})." ";
print $entry->{Computer}."[".($entry->{EventID} &
0xffff)."] ";
print $entry->{Source}.":".$type{$entry->{EventType}};
print $entry->{Message};
} else {
print "!!!!!\nSource: $entry->{Source}\n";
}
}
snap447.png
(image/png, 37.1 KB) - not displayed