MegaBites-AI/Windows-powershell
0372
1# Copyright (c) Microsoft Corporation.2# Licensed under the MIT License.3Describe 'Get-WinEvent' -Tags "CI" {4 BeforeAll {5 if ( ! $IsWindows )6 {7 $origDefaults = $PSDefaultParameterValues.Clone()8 $PSDefaultParameterValues['it:skip'] = $true9 }10 }11 AfterAll {12 if ( ! $IsWindows ){13 $global:PSDefaultParameterValues = $origDefaults14 }15 }16 Context "Get-WinEvent ListProvider parameter" {17 It 'Get-WinEvent can list the providers' {18 $result = Get-WinEvent -ListProvider * -ErrorAction ignore19 $result | Should -Not -BeNullOrEmpty20 }21 It 'Get-WinEvent can get a provider by name' {22 $providers = Get-WinEvent -ListProvider MSI* -ErrorAction ignore23 $result = Get-WinEvent -ListProvider ($providers[0].name)24 $result | Should -Not -BeNullOrEmpty25 }26 27 }28 Context "Get-WinEvent can retrieve events" {29 # for this set of tests we need to have a provider which has multiple events30 BeforeAll {31 if ( ! $IsWindows ) { return }32 $foundEvents = $false33 $providers = Get-WinEvent -ListProvider * -ErrorAction ignore34 foreach($provider in $providers) {35 $events = Get-WinEvent -provider $provider.name -ErrorAction ignore36 if ( $events.Count -gt 2 ) {37 $providerForTests = $provider38 $foundEvents = $true39 break40 }41 }42 }43 It 'Get-WinEvent can get events from a provider' {44 # we sample the first 20 results, as this could be very large45 $results = Get-WinEvent -provider $providerForTests.Name -max 2046 foreach($event in $results ) {47 $event.providername | Should -Be $providerForTests.name48 }49 }50 It 'Get-WinEvent can get events via logname' {51 $results = Get-WinEvent -LogName $providerForTests.LogLinks.LogName -MaxEvents 1052 $results | Should -Not -BeNullOrEmpty53 }54 It 'Throw if count of lognames exceeds Windows API limit' {55 if ([System.Environment]::OSVersion.Version.Major -ge 10) {56 { Get-WinEvent -LogName * } | Should -Throw -ErrorId "LogCountLimitExceeded,Microsoft.PowerShell.Commands.GetWinEventCommand"57 }58 }59 It 'Get-WinEvent can use the simplest of filters' {60 $filter = @{ ProviderName = $providerForTests.Name }61 $testEvents = Get-WinEvent -FilterHashtable $filter62 63 $testEventDict = [System.Collections.Generic.Dictionary[int, System.Diagnostics.Eventing.Reader.EventLogRecord]]::new()64 foreach ($te in $testEvents)65 {66 $testEventDict.TryAdd($te.Id, $te)67 }68 69 foreach ($e in $events)70 {71 if (-not $testEventDict.ContainsKey($e.Id))72 {73 throw new "Unexpected event log: $e"74 }75 }76 77 $testEvents.Count | Should -Be $events.Count78 }79 It 'Get-WinEvent can use a filter which includes two items' {80 $filter = @{ ProviderName = $providerForTests.Name; Id = $events[0].Id}81 $results = Get-WinEvent -FilterHashtable $filter82 $results | Should -Not -BeNullOrEmpty83 }84 It 'Get-WinEvent can retrieve event via XmlQuery' {85 $level = $events[0].Level86 $logname = $providerForTests.loglinks.logname87 $filter = "<QueryList><Query><Select Path='${logname}'>*[System[Level=${level}]]</Select></Query></QueryList>"88 $results = Get-WinEvent -FilterXml $filter -max 389 $results | Should -Not -BeNullOrEmpty90 }91 It 'Get-WinEvent can retrieve event via XPath' {92 $level = $events[0].Level93 $logname = $providerForTests.loglinks.logname94 $xpathFilter = "*[System[Level=$level]]"95 $results = Get-WinEvent -LogName $logname -FilterXPath $xpathFilter -max 396 $results | Should -Not -BeNullOrEmpty97 }98 99 }100 Context "Get-WinEvent UserData Queries" {101 It 'Get-WinEvent can retrieve events with UserData queries using FilterXml' {102 # this relies on apriori knowledge about the log file103 # the provided log file has been edited to remove MS PII, so we must use -ErrorAction silentlycontinue104 $eventLogFile = [io.path]::Combine($PSScriptRoot, "assets", "Saved-Events.evtx")105 $filter = "<QueryList><Query><Select Path='file://$eventLogFile'>*[UserData/*/Param2='Windows x64']</Select></Query></QueryList>"106 $results = Get-WinEvent -FilterXml $filter -ErrorAction silentlycontinue107 @($results).Count | Should -Be 1108 $results.RecordId | Should -Be 10109 }110 It 'Get-WinEvent can retrieve events with UserData queries using FilterHashtable (one value)' {111 # this relies on apriori knowledge about the log file112 # the provided log file has been edited to remove MS PII, so we must use -ErrorAction silentlycontinue113 $eventLogFile = [io.path]::Combine($PSScriptRoot, "assets", "Saved-Events.evtx")114 $filter = @{ path = "$eventLogFile"; Param2 = "Windows x64"}115 $results = Get-WinEvent -FilterHashtable $filter -ErrorAction silentlycontinue116 @($results).Count | Should -Be 1117 $results.RecordId | Should -Be 10118 }119 It 'Get-WinEvent can retrieve events with UserData queries using FilterHashtable (array of values)' {120 # this relies on apriori knowledge about the log file121 # the provided log file has been edited to remove MS PII, so we must use -ErrorAction silentlycontinue122 $eventLogFile = [io.path]::Combine($PSScriptRoot, "assets", "Saved-Events.evtx")123 $filter = @{ path = "$eventLogFile"; DriverName = "Remote Desktop Easy Print", "Microsoft enhanced Point and Print compatibility driver" }124 $results = Get-WinEvent -FilterHashtable $filter -ErrorAction silentlycontinue125 @($results).Count | Should -Be 2126 ($results.RecordId -contains 9) | Should -BeTrue127 ($results.RecordId -contains 11) | Should -BeTrue128 }129 It 'Get-WinEvent can retrieve events with UserData queries using FilterHashtable (multiple named params)' {130 # this relies on apriori knowledge about the log file131 # the provided log file has been edited to remove MS PII, so we must use -ErrorAction silentlycontinue132 $eventLogFile = [io.path]::Combine($PSScriptRoot, "assets", "Saved-Events.evtx")133 $filter = @{ path = "$eventLogFile"; PackageAware="Not package aware"; DriverName = "Remote Desktop Easy Print", "Microsoft enhanced Point and Print compatibility driver" }134 $results = Get-WinEvent -FilterHashtable $filter -ErrorAction silentlycontinue135 @($results).Count | Should -Be 2136 ($results.RecordId -contains 9) | Should -BeTrue137 ($results.RecordId -contains 11) | Should -BeTrue138 }139 It 'Get-WinEvent can retrieve events with UserData queries using FilterXPath' {140 # this relies on apriori knowledge about the log file141 # the provided log file has been edited to remove MS PII, so we must use -ErrorAction silentlycontinue142 $eventLogFile = [io.path]::Combine($PSScriptRoot, "assets", "Saved-Events.evtx")143 $filter = "*/UserData/*/Param2='Windows x64'"144 $results = Get-WinEvent -Path $eventLogFile -FilterXPath $filter -ErrorAction silentlycontinue145 @($results).Count | Should -Be 1146 $results.RecordId | Should -Be 10147 }148 }149 Context "Get-WinEvent Queries with SuppressHashFilter" {150 It 'Get-WinEvent can suppress events by Id' {151 # this relies on apriori knowledge about the log file152 # the provided log file has been edited to remove MS PII, so we must use -ErrorAction silentlycontinue153 $eventLogFile = [io.path]::Combine($PSScriptRoot, "assets", "Saved-Events.evtx")154 $filter = @{ path = "$eventLogFile"}155 $results = Get-WinEvent -FilterHashtable $filter -ErrorAction silentlycontinue156 $filterSuppress = @{ path = "$eventLogFile"; SuppressHashFilter=@{Id=370}}157 $resultsSuppress = Get-WinEvent -FilterHashtable $filterSuppress -ErrorAction silentlycontinue158 @($results).Count | Should -Be 3159 @($resultsSuppress).Count | Should -Be 2160 }161 It 'Get-WinEvent can suppress events by UserData' {162 # this relies on apriori knowledge about the log file163 # the provided log file has been edited to remove MS PII, so we must use -ErrorAction silentlycontinue164 $eventLogFile = [io.path]::Combine($PSScriptRoot, "assets", "Saved-Events.evtx")165 $filter = @{ path = "$eventLogFile"}166 $results = Get-WinEvent -FilterHashtable $filter -ErrorAction silentlycontinue167 $filterSuppress = @{ path = "$eventLogFile"; SuppressHashFilter=@{Param2 = "Windows x64"}}168 $resultsSuppress = Get-WinEvent -FilterHashtable $filterSuppress -ErrorAction silentlycontinue169 @($results).Count | Should -Be 3170 @($resultsSuppress).Count | Should -Be 2171 }172 }173 It 'can query a System log' {174 Get-WinEvent -LogName System -MaxEvents 1 | Should -Not -BeNullOrEmpty175 }176}177 