major change to override Write-Error func

This commit is contained in:
2023-10-05 13:17:18 -04:00
parent bbb4884818
commit 5f4b4565de
42 changed files with 114 additions and 114 deletions
+7 -7
View File
@@ -1,8 +1,8 @@
# This script depends on the host, port, username, and password being defined in the calling script
If ( -not($SFTPHost) ) { LogErr "SFTP host is not defined, this script will exit." ; Exit }
If ( -not($SFTPPort) ) { LogErr "SFTP port is not defined, this script will exit." ; Exit }
If ( -not($SFTPUser) ) { LogErr "SFTP username is not defined, this script will exit." ; Exit }
If ( -not($SFTPPass) ) { LogErr "SFTP password is not defined, this script will exit." ; Exit }
If ( -not($SFTPHost) ) { Write-Error "SFTP host is not defined, this script will exit." ; Exit }
If ( -not($SFTPPort) ) { Write-Error "SFTP port is not defined, this script will exit." ; Exit }
If ( -not($SFTPUser) ) { Write-Error "SFTP username is not defined, this script will exit." ; Exit }
If ( -not($SFTPPass) ) { Write-Error "SFTP password is not defined, this script will exit." ; Exit }
$ExportedEvents = "${Env:TEMP}\${Env:COMPUTERNAME}_events.csv"
@@ -27,7 +27,7 @@ ForEach ($Log in $Logs) {
$LogName = $Log.LogName
Write-Output "Exporting events from: ${LogName}"
Try { Get-WinEvent -LogName $LogName -FilterXPath "Event/System[Level=1 or Level=2 or Level=3]" -ErrorAction Stop | Select LogName,ProviderName,Level,Id,Message | Export-Csv -Path "${ExportedEvents}" -Append -NoTypeInformation -ErrorAction Stop }
Catch { LogErr $_.Exception.Message }
Catch { Write-Error $_.Exception.Message }
}
# Deduplicate exported events
@@ -36,7 +36,7 @@ Try {
$TempEvents = Import-Csv $ExportedEvents -ErrorAction Stop | Sort-Object LogName,ProviderName,Id -Unique
$TempEvents | Sort-Object -Property LogName,ProviderName | Export-Csv $ExportedEvents -NoTypeInformation -ErrorAction Stop
}
Catch { LogErr $_.Exception.Message }
Catch { Write-Error $_.Exception.Message }
# Upload to SFTP site
If ( Test-Path $ExportedEvents ) {
@@ -50,7 +50,7 @@ If ( Test-Path $ExportedEvents ) {
$SFTPSession = New-SFTPSession -ComputerName $SFTPHost -Credential $SFTPCred -AcceptKey -Port $SFTPPort
Write-Output "Uploading events to SFTP site"
Try { Set-SFTPItem -SessionId $SFTPSession.SessionId -Path $ExportedEvents -Destination . -Force }
Catch { LogErr $_.Exception.Message }
Catch { Write-Error $_.Exception.Message }
Finally { Remove-SFTPSession -SessionId $SFTPSession.SessionId }
}