Solved

An Urgent Problem With Reading Event Logger

Posted on 1998-05-27
1
464 Views
Last Modified: 2013-12-03
why isn't this program returning the correct EventID code
from the logger and always return 0 even when all events in the logger are with diffrent id  ?
In fact this is very much alike the sample program in the
sdk ?


#include  <stdio.h>
#include "events.hpp"
#include <iostream.h>      

void EventThread::RunThread()
{

      HANDLE h,hEvent;
      EVENTLOGRECORD *m_event;
      BYTE bBuffer[MAX_PATH];
      DWORD dwRead,dwNeeded,cRecords=0,dwThisRecord =0;
      

    h = OpenEventLog(NULL,"Application");
    if (h == NULL)
      {
            cout << "can't open the event logger";
      }

      m_event = (EVENTLOGRECORD*) &bBuffer;

      hEvent = CreateEvent( LPSECURITY_ATTRIBUTES(NULL) ,
                                      FALSE,
                                      FALSE,
                                 "EventHandle");

      if (!GetNumberOfEventLogRecords(h,&cRecords))
            cout << "error . Couldn't read or write ";
      else
            cout << "number of records in the system  event log is :"
                   << cRecords << endl;

      cout << "Waiting for more events \n";
      while(1)
      {
            
            NotifyChangeEventLog(h,hEvent);
            WaitForSingleObject(hEvent,INFINITE);
            {
                  ReadEventLog(h,
                         EVENTLOG_BACKWARDS_READ,
                               0,
                               m_event,
                               sizeof(EVENTLOGRECORD),
                               &dwRead,
                               &dwNeeded);
            

      if (m_event->EventType == EVENTLOG_ERROR_TYPE )
                  {
                        switch (m_event->EventID)
                        {
                        case 4:
                              {
                            cout << " ccc was notified about bad sector on disk ";
                              }
                        default:
                              cout << " A Unknown event was raised ";
                        }
                  }
                        
            m_event = (EVENTLOGRECORD*) &bBuffer;
            }
      }

      CloseEventLog(h);
}


UTL_Status EventThread::StopThread(DWORD number)
{

      // TODO
      return 0;
}



void main()
{

      EventThread* local = new EventThread;
      local->RunThread();

}
0
Comment
Question by:sector
1 Comment
 

Accepted Solution

by:
mwalsh111097 earned 200 total points
ID: 1404369
If you check the return from the ReadEventLog() function, you will find that it is, in fact, failing.  GetLastError returns 0x57, which indicates an invalid parameter to the function.  When you change the flags to be "EVENTLOG_BACKWARDS_READ | EVENTLOG_SEQUENTIAL_READ" and change the buffer size to be "sizeof(bBuffer)" then everything works as it should.
0

Featured Post

Is Your Active Directory as Secure as You Think?

More than 75% of all records are compromised because of the loss or theft of a privileged credential. Experts have been exploring Active Directory infrastructure to identify key threats and establish best practices for keeping data safe. Attend this month’s webinar to learn more.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

zlib is a free compression library (a DLL) on which the popular gzip utility is built.  In this article, we'll see how to use the zlib functions to compress and decompress data in memory; that is, without needing to use a temporary file.  We'll be c…
What my article will show is if you ever had to do processing to a listbox without being able to just select all the items in it. My software Visual Studio 2008 crystal report v11 My issue was I wanted to add crystal report to a form and show…
This is Part 3 in a 3-part series on Experts Exchange to discuss error handling in VBA code written for Excel. Part 1 of this series discussed basic error handling code using VBA. http://www.experts-exchange.com/videos/1478/Excel-Error-Handlin…
This is used to tweak the memory usage for your computer, it is used for servers more so than workstations but just be careful editing registry settings as it may cause irreversible results. I hold no responsibility for anything you do to the regist…

863 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

25 Experts available now in Live!

Get 1:1 Help Now