【问题标题】:How to generate an event log similar to the one provided如何生成与提供的事件日志类似的事件日志
【发布时间】:2014-02-03 15:22:57
【问题描述】:

以下是 ActiveDirectory 生成的日志事件。我有一个读取此类日志并处理它们的应用程序。我想制作一个测试应用程序,它将模拟活动目录事件并将类似的日志写入 Windows 事件日志。

<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
 <System>
    <Provider Name="SIMULATOR" /> 
    <EventID Qualifiers="0">4769</EventID> 
    <Level>0</Level> 
    <Task>0</Task> 
    <Keywords>0xa0000000000000</Keywords> 
    <TimeCreated SystemTime="2014-02-03T10:52:20.000000000Z" /> 
    <EventRecordID>35215</EventRecordID> 
    <Channel>Application</Channel> 
    <Computer>dev.local</Computer> 
    <Security /> 
</System>
<EventData>
    <Data Name="TargetUserName">WIN2K8R2-PCX$</Data>
    <Data Name="TargetDomainName">dev.local</Data>
    <Data Name="TargetSid">S-1-5-21-527455857-2257904818-3601372424-1001</Data>
    <Data Name="ServiceName">Administrator</Data> 
    <Data Name="ServiceSid">S-1-5-21-527455857-2257904818-3601372424-502</Data>
    <Data Name="TicketOptions">0x40810010</Data>
    <Data Name="Status">0x0</Data>
    <Data Name="TicketEncryptionType">0x12</Data>
    <Data Name="PreAuthType">2</Data>
    <Data Name="IpAddress">84.1.24.45</Data>
    <Data Name="IpPort">0</Data>
    <Data Name="CertIssuerName" />
    <Data Name="CertSerialNumber" />
    <Data Name="CertThumbprint" />
 </EventData>

请注意,EventData 元素中有多个 Data 元素!

如果我使用以下内容,我会得到多个数据元素,但如何指定每个数据元素的 Name 属性?

string [] eventLog = new string[] {"A", "S", "D"};
EventLog log = new EventLog {Source = "source"};
log.WriteEvent(eventInstance, eventLog);

在this的文章中发现可以通过EventDescriptor/EventProvider使用ActiveDirectory注册的manifest。但这不会在事件日志中写入任何内容。

我按照here 给出的步骤找到了活动目录 guid。在我的系统上,指南如下

Active Directory Domain Services: SAM    {8E598056-8993-11D2-819E-0000F875A064}
Active Directory: Kerberos Client        {BBA3ADD2-C229-4CDB-AE2B-57EB6966B0C4}
Active Directory: NetLogon               {F33959B4-DBEC-11D2-895B-00C04F79AB69}

【问题讨论】:

    标签: c# .net active-directory event-log


    【解决方案1】:

    Here's one way

    根据我的阅读方式,您需要:

    1. 使用 ManifestGenerator (EcManGen.exe) 为您的应用创建清单框架。
    2. 使用清单来描述您要保留的数据。
    3. 使用 ManifestCompiler (mc.exe) 编译清单,生成(除其他外).cs 和 .rc 文件。
    4. 使用 ResourceCompiler (rc.exe) 将 .rc 编译为真实资源 (.res)
    5. 使用 C# 编译器 (csc.exe) 将 .cs 和 .res 文件编译成程序集。 (需要使用/unsafe)
    6. 将程序集添加到您的项目中。
    7. 作为管理员,运行 wevutil 将清单添加到将记录这些日志的计算机。

    所有这些都完成后,您可以使用程序集中的EventProvider 或常规的EventProvider(带有自定义EventDescriptor)。

    【讨论】:

      猜你喜欢
      • 2012-02-27
      • 1970-01-01
      • 2018-05-26
      • 1970-01-01
      • 2022-11-30
      • 2019-12-25
      • 1970-01-01
      • 1970-01-01
      • 1970-01-01
      相关资源
      最近更新 更多