move script out of Atera and host it here
This commit is contained in:
+56
-16
@@ -1,20 +1,60 @@
|
|||||||
Function Get-EventData {
|
# This script depends on the host, port, username, and password being defined in the calling script
|
||||||
params(
|
If ( -not($SFTPHost) ) { LogErr "SFTP host is not defined, this script will exit." ; Exit }
|
||||||
[string]$LogName,
|
If ( -not($SFTPPort) ) { LogErr "SFTP port is not defined, this script will exit." ; Exit }
|
||||||
[string]$ProviderName,
|
If ( -not($SFTPUser) ) { LogErr "SFTP username is not defined, this script will exit." ; Exit }
|
||||||
[datetime]$SearchFromTime
|
If ( -not($SFTPPass) ) { LogErr "SFTP password is not defined, this script will exit." ; Exit }
|
||||||
)
|
|
||||||
|
|
||||||
# Store search position of event logs in the Windows Registry
|
$ExportedEvents = "${Env:TEMP}\${Env:COMPUTERNAME}_events.csv"
|
||||||
# This should eliminate the possibility of double-reporting the same event
|
|
||||||
$BaseKey = 'HKLM:\SOFTWARE\ATERA Networks\Get-EventData'
|
# Install Posh-SSH module
|
||||||
|
If ( !(Get-Module -ListAvailable -Name Posh-SSH) ) {
|
||||||
|
LogMsg "Installing Posh-SSH module"
|
||||||
|
Install-Module -Name Posh-SSH -Force
|
||||||
|
}
|
||||||
|
|
||||||
|
# Cleanup previous runs
|
||||||
|
If ( Test-Path $ExportedEvents ) {
|
||||||
|
LogMsg "Deleting exported events from previous script run ""${ExportedEvents}"""
|
||||||
|
Try { Remove-Item $ExportedEvents -Force -ErrorAction Stop }
|
||||||
|
Catch { LogMsg "Cannot remove files from previous script execution. This script cannot run." ; Exit }
|
||||||
|
}
|
||||||
|
|
||||||
|
# Get all available log files
|
||||||
|
$Logs = Get-WinEvent -ListLog *
|
||||||
|
|
||||||
|
# Export all significant events from all available log files
|
||||||
|
ForEach ($Log in $Logs) {
|
||||||
|
$LogName = $Log.LogName
|
||||||
|
LogMsg "Exporting events from: ${LogName}"
|
||||||
|
Try { Get-WinEvent -LogName $LogName -FilterXPath "Event/System[Level=1 or Level=2 or Level=3]" -ErrorAction Stop | Select LogName,ProviderName,Level,Id,Message | Export-Csv -Path "${ExportedEvents}" -Append -NoTypeInformation -ErrorAction Stop }
|
||||||
|
Catch { LogErr $_.Exception.Message }
|
||||||
|
}
|
||||||
|
|
||||||
|
# Deduplicate exported events
|
||||||
|
LogMsg "Deduplicating and sorting all exported events"
|
||||||
|
Try {
|
||||||
|
$TempEvents = Import-Csv $ExportedEvents -ErrorAction Stop | Sort-Object LogName,ProviderName,Id -Unique
|
||||||
|
$TempEvents | Sort-Object -Property LogName,ProviderName | Export-Csv $ExportedEvents -NoTypeInformation -ErrorAction Stop
|
||||||
|
}
|
||||||
|
Catch { LogErr $_.Exception.Message }
|
||||||
|
|
||||||
|
# Upload to SFTP site
|
||||||
|
If ( Test-Path $ExportedEvents ) {
|
||||||
|
$SFTPCred = New-Object System.Management.Automation.PSCredential($SFTPUser,$SFTPPass)
|
||||||
|
$DestinationFile = $(Split-Path -Path $ExportedEvents -Leaf)
|
||||||
|
|
||||||
$AllLogs = (Get-WinEvent -ListLog *)
|
# Wait for a random amount of time before starting the connection and uploading
|
||||||
$LogsWithEvents = ($AllLogs | Where-Object { $_.RecordCount -gt 0 })
|
Start-Sleep -Seconds $(Get-Random -Minimum 1 -Maximum 120)
|
||||||
|
|
||||||
ForEach ( $logWithEvents in $LogsWithEvents ) {
|
# Make the connection and upload the file
|
||||||
|
$SFTPSession = New-SFTPSession -ComputerName $SFTPHost -Credential $SFTPCred -AcceptKey -Port $SFTPPort
|
||||||
}
|
LogMsg "Uploading events to SFTP site"
|
||||||
|
Try { Set-SFTPItem -SessionId $SFTPSession.SessionId -Path $ExportedEvents -Destination . -Force }
|
||||||
|
Catch { LogErr $_.Exception.Message }
|
||||||
|
Finally { Remove-SFTPSession -SessionId $SFTPSession.SessionId }
|
||||||
|
|
||||||
|
}
|
||||||
|
|
||||||
|
# Cleanup
|
||||||
}
|
LogMsg "Deleting ""${ExportedEvents}"""
|
||||||
|
Remove-Item $ExportedEvents -Force -ErrorAction SilentlyContinue
|
||||||
Reference in New Issue
Block a user