Event Scavenger 5

Seems like life is just getting more hectic these days. I’ve been running version 5 of my Event gathering tool for a while after I ‘upgraded’ the product last year already but never had the time to actually create any way to package it so others can also use it.

Part of the problem was that I decided to use a new Installer technology (thanks to the brilliant minds at MindLessoft formerly known as Microsoft…) – Wix. Unfortunately Wix is not exactly a walk in the park thing to learn and with limited time it was very hard to create anything that is kinda useful.

Anyway, to make a short story long… I decided to just go ahead and publish the latest version with whatever installers I managed to create up to now (and hope for the best).

So, there is a new ‘stable’ release of Event Scavenger on the CodePlex site. Good luck and may the force be with you…

  1. I have PowerShell script, started using TaskScheduler when computer starts and checking, if running:

    1. starting EventLogWatcher, waiting for new records and inserting to DB
    2. query EventLogs for record between time of last record in DB and time of start script (collecting history when script was not run)

    this Pulling solution is much beter for me:
    + because of EventLogWatcher, I have new EventLog record written in DB immediately, not only in pooling intrvals
    + there is no need open firewall for INCOMMING traffic on all computers, only on DB server
    + there is no need allow security/remotegergistry/user access on all computers

    there is main part of this script:

    run-EventLogWatcherService
    [dateTime]EventLogWatcherServiceStarted = DateTime(Now)
    if (Get-NewEvents.alreadyRunning){
    exit
    } else
    call Get-NewEvents
    call Get-OldEvents
    }
    exit

    function Get-OldEvents
    {
    ForEach ($WinEvent in $(Get-WinEvent -ListLog *)) {
    $WinEventLogName = $WinEvent.LogName
    # skip Exluded
    if ($WinEventExclude -contains $WinEventLogName){
    } else {
    $LastWinEventDate = Get-LastWinEventRecordInDB -WinEventLogName $WinEventLogName -ComputerName $ComputerName
    $filter = @{
    LogName = $WinEventLogName
    StartTime = $LastWinEventDate
    EndTime = $EventLogWatcherServiceStarted
    }
    ForEach ($WinEvent in $(Get-WinEvent -FilterHashtable $filter -ErrorVariable ErrorVar -ErrorAction SilentlyContinue)) {
    $WinEventMessage = Remove-SQLIllegalCharacters -string $WinEvent.Message
    if (Contains-ExcludedWinEvents -WinEventLogName $WinEventLogName -ProviderName $WinEvent.ProviderName -LevelDisplayName $WinEvent.LevelDisplayName -ID $WinEvent.ID) {
    } else {
    $Query = ‘INSERT INTO [EventLogWatcher].[dbo].[WinEventRecords] ([ComputerName], [LogName], [RecordId], [MachineName], [Id], [LevelDisplayName], [Message], [ProviderName], [UserId], [TimeCreated]) VALUES (”’+ $ComputerName +”’,”’+ $WinEventLogName +”’,’+ $WinEvent.RecordId +’,”’+ $WinEvent.MachineName +”’,’+ $WinEvent.Id +’,”’+ $WinEvent.LevelDisplayName +”’,”’+ $WinEventMessage +”’,”’+ $WinEvent.ProviderName +”’,”’+ $WinEvent.UserId +”’,”’+ $WinEvent.TimeCreated +”’);’
    }
    }
    }
    }
    }

    function Get-NewEvents
    {
    $TimeSpan = [TimeSpan]::FromSeconds(1)
    $TimeSpanTimeOut = [TimeSpan]::FromSeconds(10)
    $Scope = New-Object System.Management.ManagementScope(“\\.\root\cimV2”)
    $EventQuery = “TargetInstance ISA ‘Win32_NTLogEvent'” + $EventLogsFilter
    $EventQueryWQL = New-Object System.Management.WQLEventQuery (“__InstanceCreationEvent”,$TimeSpan, $EventQuery )
    $ManagementEventWatcher = New-Object System.Management.ManagementEventWatcher($Scope,$EventQueryWQL)
    $ManagementEventWatcher.Options.Timeout = $TimeSpanTimeOut

    while ($true))) {
    $ManagementEventWatcherEvent = $ManagementEventWatcher.WaitForNextEvent()
    $Event = $ManagementEventWatcherEvent.TargetInstance
    $EventMessage = Remove-SQLIllegalCharacters -string $Event.Message
    $EventTimeGenerated = Convert-WMITime -WMITime $Event.TimeGenerated
    if (Contains-ExcludedEvents -EventLog $Event.Logfile -Source $Event.SourceName -CategoryString $Event.CategoryString -EntryType $Event.Type -EventID $Event.EventCode) {
    } else {
    $Query = ‘INSERT INTO [EventLogWatcher].[dbo].[EventLogRecords] ([ComputerName], [EventLog], [EventID], [MachineName], [Index], [Category], [CategoryNumber], [EntryType], [Message], [Source], [UserName], [InstanceId], [TimeGenerated]) VALUES (”’+ $ComputerName +”’,”’+ $Event.Logfile +”’,’+ $Event.EventCode +’,”’+ $Event.ComputerName +”’,’+ $Event.RecordNumber +’,”’+ $Event.CategoryString +”’,’+ $Event.Category +’,”’+ $Event.Type +”’,”’+ $EventMessage +”’,”’+ $Event.SourceName +”’,”’+ $Event.User +”’,’+ $Event.EventIdentifier +’,”’+ $EventTimeGenerated +”’);’
    }
    }
    }
    $ManagementEventWatcher.Stop()
    }

Leave a Comment


NOTE - You can use these HTML tags and attributes:
<a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <s> <strike> <strong>