Solved

An Urgent Problem With Reading Event Logger

Posted on 1998-05-27
1
463 Views
Last Modified: 2013-12-03
why isn't this program returning the correct EventID code
from the logger and always return 0 even when all events in the logger are with diffrent id  ?
In fact this is very much alike the sample program in the
sdk ?


#include  <stdio.h>
#include "events.hpp"
#include <iostream.h>      

void EventThread::RunThread()
{

      HANDLE h,hEvent;
      EVENTLOGRECORD *m_event;
      BYTE bBuffer[MAX_PATH];
      DWORD dwRead,dwNeeded,cRecords=0,dwThisRecord =0;
      

    h = OpenEventLog(NULL,"Application");
    if (h == NULL)
      {
            cout << "can't open the event logger";
      }

      m_event = (EVENTLOGRECORD*) &bBuffer;

      hEvent = CreateEvent( LPSECURITY_ATTRIBUTES(NULL) ,
                                      FALSE,
                                      FALSE,
                                 "EventHandle");

      if (!GetNumberOfEventLogRecords(h,&cRecords))
            cout << "error . Couldn't read or write ";
      else
            cout << "number of records in the system  event log is :"
                   << cRecords << endl;

      cout << "Waiting for more events \n";
      while(1)
      {
            
            NotifyChangeEventLog(h,hEvent);
            WaitForSingleObject(hEvent,INFINITE);
            {
                  ReadEventLog(h,
                         EVENTLOG_BACKWARDS_READ,
                               0,
                               m_event,
                               sizeof(EVENTLOGRECORD),
                               &dwRead,
                               &dwNeeded);
            

      if (m_event->EventType == EVENTLOG_ERROR_TYPE )
                  {
                        switch (m_event->EventID)
                        {
                        case 4:
                              {
                            cout << " ccc was notified about bad sector on disk ";
                              }
                        default:
                              cout << " A Unknown event was raised ";
                        }
                  }
                        
            m_event = (EVENTLOGRECORD*) &bBuffer;
            }
      }

      CloseEventLog(h);
}


UTL_Status EventThread::StopThread(DWORD number)
{

      // TODO
      return 0;
}



void main()
{

      EventThread* local = new EventThread;
      local->RunThread();

}
0
Comment
Question by:sector
1 Comment
 

Accepted Solution

by:
mwalsh111097 earned 200 total points
ID: 1404369
If you check the return from the ReadEventLog() function, you will find that it is, in fact, failing.  GetLastError returns 0x57, which indicates an invalid parameter to the function.  When you change the flags to be "EVENTLOG_BACKWARDS_READ | EVENTLOG_SEQUENTIAL_READ" and change the buffer size to be "sizeof(bBuffer)" then everything works as it should.
0

Featured Post

Top 6 Sources for Identifying Threat Actor TTPs

Understanding your enemy is essential. These six sources will help you identify the most popular threat actor tactics, techniques, and procedures (TTPs).

Join & Write a Comment

This article shows a few slightly more advanced techniques for Windows 7 gadget programming, including how to save and restore user settings for your gadget and how to populate the "details" panel that is displayed in the Windows 7 gadget gallery.  …
For a while now I'v been searching for a circular progress control, much like the one you get when first starting your Silverlight application. I found a couple that were written in WPF and there were a few written in Silverlight, but all appeared o…
This is Part 3 in a 3-part series on Experts Exchange to discuss error handling in VBA code written for Excel. Part 1 of this series discussed basic error handling code using VBA. http://www.experts-exchange.com/videos/1478/Excel-Error-Handlin…
When you create an app prototype with Adobe XD, you can insert system screens -- sharing or Control Center, for example -- with just a few clicks. This video shows you how. You can take the full course on Experts Exchange at http://bit.ly/XDcourse.

743 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

11 Experts available now in Live!

Get 1:1 Help Now