Team Ai
Datasetpublic

MegaBites-AI/Windows-powershell

sourceHugging Facemitupdated 6mo agoView on Hugging Face
0likes372downloads
Get-WinEvent.Tests.ps1177 linesDownload Raw Back to Microsoft.PowerShell.Diagnostics
1# Copyright (c) Microsoft Corporation.2# Licensed under the MIT License.3Describe 'Get-WinEvent' -Tags "CI" {4    BeforeAll {5        if ( ! $IsWindows )6        {7            $origDefaults = $PSDefaultParameterValues.Clone()8            $PSDefaultParameterValues['it:skip'] = $true9        }10    }11    AfterAll {12        if ( ! $IsWindows ){13            $global:PSDefaultParameterValues = $origDefaults14        }15    }16    Context "Get-WinEvent ListProvider parameter" {17        It 'Get-WinEvent can list the providers' {18            $result = Get-WinEvent -ListProvider * -ErrorAction ignore19            $result | Should -Not -BeNullOrEmpty20        }21        It 'Get-WinEvent can get a provider by name' {22            $providers = Get-WinEvent -ListProvider MSI* -ErrorAction ignore23            $result = Get-WinEvent -ListProvider ($providers[0].name)24            $result | Should -Not -BeNullOrEmpty25        }26 27    }28    Context "Get-WinEvent can retrieve events" {29        # for this set of tests we need to have a provider which has multiple events30        BeforeAll {31            if ( ! $IsWindows ) { return }32            $foundEvents = $false33            $providers = Get-WinEvent -ListProvider * -ErrorAction ignore34            foreach($provider in $providers) {35                $events = Get-WinEvent -provider $provider.name -ErrorAction ignore36                if ( $events.Count -gt 2 ) {37                    $providerForTests = $provider38                    $foundEvents = $true39                    break40                }41            }42        }43        It 'Get-WinEvent can get events from a provider' {44            # we sample the first 20 results, as this could be very large45            $results = Get-WinEvent -provider $providerForTests.Name -max 2046            foreach($event in $results ) {47                $event.providername | Should -Be $providerForTests.name48            }49        }50        It 'Get-WinEvent can get events via logname' {51            $results = Get-WinEvent -LogName $providerForTests.LogLinks.LogName -MaxEvents 1052            $results | Should -Not -BeNullOrEmpty53        }54        It 'Throw if count of lognames exceeds Windows API limit' {55            if ([System.Environment]::OSVersion.Version.Major -ge 10) {56                { Get-WinEvent -LogName * } | Should -Throw -ErrorId "LogCountLimitExceeded,Microsoft.PowerShell.Commands.GetWinEventCommand"57            }58        }59        It 'Get-WinEvent can use the simplest of filters' {60            $filter = @{ ProviderName = $providerForTests.Name }61            $testEvents = Get-WinEvent -FilterHashtable $filter62 63            $testEventDict = [System.Collections.Generic.Dictionary[int, System.Diagnostics.Eventing.Reader.EventLogRecord]]::new()64            foreach ($te in $testEvents)65            {66                $testEventDict.TryAdd($te.Id, $te)67            }68 69            foreach ($e in $events)70            {71                if (-not $testEventDict.ContainsKey($e.Id))72                {73                    throw new "Unexpected event log: $e"74                }75            }76 77            $testEvents.Count | Should -Be $events.Count78        }79        It 'Get-WinEvent can use a filter which includes two items' {80            $filter = @{ ProviderName = $providerForTests.Name; Id = $events[0].Id}81            $results = Get-WinEvent -FilterHashtable $filter82            $results | Should -Not -BeNullOrEmpty83        }84        It 'Get-WinEvent can retrieve event via XmlQuery' {85            $level = $events[0].Level86            $logname = $providerForTests.loglinks.logname87            $filter = "<QueryList><Query><Select Path='${logname}'>*[System[Level=${level}]]</Select></Query></QueryList>"88            $results = Get-WinEvent -FilterXml $filter -max 389            $results | Should -Not -BeNullOrEmpty90        }91        It 'Get-WinEvent can retrieve event via XPath' {92            $level = $events[0].Level93            $logname  = $providerForTests.loglinks.logname94            $xpathFilter = "*[System[Level=$level]]"95            $results = Get-WinEvent -LogName $logname -FilterXPath $xpathFilter -max 396            $results | Should -Not -BeNullOrEmpty97        }98 99    }100    Context "Get-WinEvent UserData Queries" {101        It 'Get-WinEvent can retrieve events with UserData queries using FilterXml' {102            # this relies on apriori knowledge about the log file103            # the provided log file has been edited to remove MS PII, so we must use -ErrorAction silentlycontinue104            $eventLogFile = [io.path]::Combine($PSScriptRoot, "assets", "Saved-Events.evtx")105            $filter = "<QueryList><Query><Select Path='file://$eventLogFile'>*[UserData/*/Param2='Windows x64']</Select></Query></QueryList>"106            $results = Get-WinEvent -FilterXml $filter -ErrorAction silentlycontinue107            @($results).Count | Should -Be 1108            $results.RecordId | Should -Be 10109        }110        It 'Get-WinEvent can retrieve events with UserData queries using FilterHashtable (one value)' {111            # this relies on apriori knowledge about the log file112            # the provided log file has been edited to remove MS PII, so we must use -ErrorAction silentlycontinue113            $eventLogFile = [io.path]::Combine($PSScriptRoot, "assets", "Saved-Events.evtx")114            $filter = @{ path = "$eventLogFile"; Param2 = "Windows x64"}115            $results = Get-WinEvent -FilterHashtable $filter -ErrorAction silentlycontinue116            @($results).Count | Should -Be 1117            $results.RecordId | Should -Be 10118        }119        It 'Get-WinEvent can retrieve events with UserData queries using FilterHashtable (array of values)' {120            # this relies on apriori knowledge about the log file121            # the provided log file has been edited to remove MS PII, so we must use -ErrorAction silentlycontinue122            $eventLogFile = [io.path]::Combine($PSScriptRoot, "assets", "Saved-Events.evtx")123            $filter = @{ path = "$eventLogFile"; DriverName = "Remote Desktop Easy Print", "Microsoft enhanced Point and Print compatibility driver" }124            $results = Get-WinEvent -FilterHashtable $filter -ErrorAction silentlycontinue125            @($results).Count | Should -Be 2126            ($results.RecordId -contains 9) | Should -BeTrue127            ($results.RecordId -contains 11) | Should -BeTrue128        }129        It 'Get-WinEvent can retrieve events with UserData queries using FilterHashtable (multiple named params)' {130            # this relies on apriori knowledge about the log file131            # the provided log file has been edited to remove MS PII, so we must use -ErrorAction silentlycontinue132            $eventLogFile = [io.path]::Combine($PSScriptRoot, "assets", "Saved-Events.evtx")133            $filter = @{ path = "$eventLogFile"; PackageAware="Not package aware"; DriverName = "Remote Desktop Easy Print", "Microsoft enhanced Point and Print compatibility driver" }134            $results = Get-WinEvent -FilterHashtable $filter -ErrorAction silentlycontinue135            @($results).Count | Should -Be 2136            ($results.RecordId -contains 9) | Should -BeTrue137            ($results.RecordId -contains 11) | Should -BeTrue138        }139        It 'Get-WinEvent can retrieve events with UserData queries using FilterXPath' {140            # this relies on apriori knowledge about the log file141            # the provided log file has been edited to remove MS PII, so we must use -ErrorAction silentlycontinue142            $eventLogFile = [io.path]::Combine($PSScriptRoot, "assets", "Saved-Events.evtx")143            $filter = "*/UserData/*/Param2='Windows x64'"144            $results = Get-WinEvent -Path $eventLogFile -FilterXPath $filter -ErrorAction silentlycontinue145            @($results).Count | Should -Be 1146            $results.RecordId | Should -Be 10147        }148    }149    Context "Get-WinEvent Queries with SuppressHashFilter" {150        It 'Get-WinEvent can suppress events by Id' {151            # this relies on apriori knowledge about the log file152            # the provided log file has been edited to remove MS PII, so we must use -ErrorAction silentlycontinue153            $eventLogFile = [io.path]::Combine($PSScriptRoot, "assets", "Saved-Events.evtx")154            $filter = @{ path = "$eventLogFile"}155            $results = Get-WinEvent -FilterHashtable $filter -ErrorAction silentlycontinue156            $filterSuppress = @{ path = "$eventLogFile";  SuppressHashFilter=@{Id=370}}157            $resultsSuppress = Get-WinEvent -FilterHashtable $filterSuppress -ErrorAction silentlycontinue158            @($results).Count | Should -Be 3159            @($resultsSuppress).Count | Should -Be 2160        }161        It 'Get-WinEvent can suppress events by UserData' {162            # this relies on apriori knowledge about the log file163            # the provided log file has been edited to remove MS PII, so we must use -ErrorAction silentlycontinue164            $eventLogFile = [io.path]::Combine($PSScriptRoot, "assets", "Saved-Events.evtx")165            $filter = @{ path = "$eventLogFile"}166            $results = Get-WinEvent -FilterHashtable $filter -ErrorAction silentlycontinue167            $filterSuppress = @{ path = "$eventLogFile";  SuppressHashFilter=@{Param2 = "Windows x64"}}168            $resultsSuppress = Get-WinEvent -FilterHashtable $filterSuppress -ErrorAction silentlycontinue169            @($results).Count | Should -Be 3170            @($resultsSuppress).Count | Should -Be 2171        }172    }173    It 'can query a System log' {174        Get-WinEvent -LogName System -MaxEvents 1 | Should -Not -BeNullOrEmpty175    }176}177