MegaBites-AI/Windows-powershell
0372
1# Copyright (c) Microsoft Corporation.2# Licensed under the MIT License.3Describe 'New-WinEvent' -Tags "CI" {4 5 Context "New-WinEvent tests" {6 7 BeforeAll {8 $originalDefaultParameterValues = $PSDefaultParameterValues.Clone()9 if ( ! $IsWindows ) {10 $PSDefaultParameterValues["it:skip"] = $true11 }12 13 $ProviderName = 'Microsoft-Windows-PowerShell'14 $SimpleEventId = 4096215 $ComplexEventId = 3286816 }17 18 AfterAll {19 $global:PSDefaultParameterValues = $originalDefaultParameterValues20 }21 22 It 'Simple New-WinEvent without any payload' {23 New-WinEvent -ProviderName $ProviderName -Id $SimpleEventId -Version 124 $filter = @{ ProviderName = $ProviderName; Id = $SimpleEventId}25 (Get-WinEvent -FilterHashtable $filter).Count | Should -BeGreaterThan 026 }27 28 It 'No provider found error' {29 { New-WinEvent -ProviderName NonExistingProvider -Id 0 } | Should -Throw -ErrorId 'System.ArgumentException,Microsoft.PowerShell.Commands.NewWinEventCommand'30 }31 32 It 'EmptyProviderName error' {33 { New-WinEvent -ProviderName $null -Id 0 } | Should -Throw -ErrorId 'ParameterArgumentValidationErrorNullNotAllowed,Microsoft.PowerShell.Commands.NewWinEventCommand'34 }35 36 It 'IncorrectEventId error' {37 { New-WinEvent $ProviderName -Id 999999 } | Should -Throw -ErrorId 'Microsoft.PowerShell.Commands.EventWriteException,Microsoft.PowerShell.Commands.NewWinEventCommand'38 }39 40 It 'IncorrectEventVersion error' {41 { New-WinEvent -ProviderName $ProviderName -Id $SimpleEventId -Version 99 } | Should -Throw -ErrorId 'Microsoft.PowerShell.Commands.EventWriteException,Microsoft.PowerShell.Commands.NewWinEventCommand'42 }43 44 It 'PayloadMismatch error' {45 $logPath = Join-Path $TestDrive 'testlog1.txt'46 # this will print the warning with expected event template to the file47 New-WinEvent -ProviderName $ProviderName -Id $ComplexEventId *> $logPath48 Get-Content $logPath -Raw | Should -Match 'data name="FragmentPayload"'49 }50 }51}52 