diff --git a/Get-EventData.ps1 b/Get-EventData.ps1 index 98098f1..5ac5feb 100644 --- a/Get-EventData.ps1 +++ b/Get-EventData.ps1 @@ -1,20 +1,60 @@ -Function Get-EventData { - params( - [string]$LogName, - [string]$ProviderName, - [datetime]$SearchFromTime - ) +# This script depends on the host, port, username, and password being defined in the calling script +If ( -not($SFTPHost) ) { LogErr "SFTP host is not defined, this script will exit." ; Exit } +If ( -not($SFTPPort) ) { LogErr "SFTP port is not defined, this script will exit." ; Exit } +If ( -not($SFTPUser) ) { LogErr "SFTP username is not defined, this script will exit." ; Exit } +If ( -not($SFTPPass) ) { LogErr "SFTP password is not defined, this script will exit." ; Exit } - # Store search position of event logs in the Windows Registry - # This should eliminate the possibility of double-reporting the same event - $BaseKey = 'HKLM:\SOFTWARE\ATERA Networks\Get-EventData' +$ExportedEvents = "${Env:TEMP}\${Env:COMPUTERNAME}_events.csv" + +# Install Posh-SSH module +If ( !(Get-Module -ListAvailable -Name Posh-SSH) ) { + LogMsg "Installing Posh-SSH module" + Install-Module -Name Posh-SSH -Force +} + +# Cleanup previous runs +If ( Test-Path $ExportedEvents ) { + LogMsg "Deleting exported events from previous script run ""${ExportedEvents}""" + Try { Remove-Item $ExportedEvents -Force -ErrorAction Stop } + Catch { LogMsg "Cannot remove files from previous script execution. This script cannot run." ; Exit } +} + +# Get all available log files +$Logs = Get-WinEvent -ListLog * + +# Export all significant events from all available log files +ForEach ($Log in $Logs) { + $LogName = $Log.LogName + LogMsg "Exporting events from: ${LogName}" + Try { Get-WinEvent -LogName $LogName -FilterXPath "Event/System[Level=1 or Level=2 or Level=3]" -ErrorAction Stop | Select LogName,ProviderName,Level,Id,Message | Export-Csv -Path "${ExportedEvents}" -Append -NoTypeInformation -ErrorAction Stop } + Catch { LogErr $_.Exception.Message } +} + +# Deduplicate exported events +LogMsg "Deduplicating and sorting all exported events" +Try { + $TempEvents = Import-Csv $ExportedEvents -ErrorAction Stop | Sort-Object LogName,ProviderName,Id -Unique + $TempEvents | Sort-Object -Property LogName,ProviderName | Export-Csv $ExportedEvents -NoTypeInformation -ErrorAction Stop +} +Catch { LogErr $_.Exception.Message } + +# Upload to SFTP site +If ( Test-Path $ExportedEvents ) { + $SFTPCred = New-Object System.Management.Automation.PSCredential($SFTPUser,$SFTPPass) + $DestinationFile = $(Split-Path -Path $ExportedEvents -Leaf) - $AllLogs = (Get-WinEvent -ListLog *) - $LogsWithEvents = ($AllLogs | Where-Object { $_.RecordCount -gt 0 }) + # Wait for a random amount of time before starting the connection and uploading + Start-Sleep -Seconds $(Get-Random -Minimum 1 -Maximum 120) - ForEach ( $logWithEvents in $LogsWithEvents ) { - - } + # Make the connection and upload the file + $SFTPSession = New-SFTPSession -ComputerName $SFTPHost -Credential $SFTPCred -AcceptKey -Port $SFTPPort + LogMsg "Uploading events to SFTP site" + Try { Set-SFTPItem -SessionId $SFTPSession.SessionId -Path $ExportedEvents -Destination . -Force } + Catch { LogErr $_.Exception.Message } + Finally { Remove-SFTPSession -SessionId $SFTPSession.SessionId } + +} - -} \ No newline at end of file +# Cleanup +LogMsg "Deleting ""${ExportedEvents}""" +Remove-Item $ExportedEvents -Force -ErrorAction SilentlyContinue \ No newline at end of file