Sign in to follow this  
Followers 0
llewxam

_EventLog__Read errors

1 post in this topic

The purpose of the code will be to check the Security log and look for multiple failed login attempts, then set a firewall rule to block those IP addresses.  _EventLog__Read is not giving the IP address though:

 

security.jpg

 

That is problem #1, the other is annoying but I can cope with that one.  Using _EventLog__Count does count the number of log entries correctly, but using $Get=_EventLog__Read($hEventLog, False, False, 1) gives False for $Get[0] and all other elements are null.  Doing $Get=_EventLog__Read($hEventLog, True, False) gives over 2,000,000 on $Get[1].

This is being run on Server 2008 R2 x64, AutoIt 3.3.10.1 (same results uncompiled, compiled x86, compiled x64)

Thoughts on either issue?  Having the number record working properly would be a great help but I can work around it.

Thanks

Ian


My projects:

  • IP Scanner - Multi-threaded ping tool to scan your available networks for used and available IP addresses, shows ping times, resolves IPs in to host names, and allows individual IPs to be pinged.
  • INFSniff - Great technicians tool - a tool which scans DriverPacks archives for INF files and parses out the HWIDs to a database file, and rapidly scans the local machine's HWIDs, searches the database for matches, and installs them.
  • PPK3 (Persistent Process Killer V3) - Another for the techs - suppress running processes that you need to keep away, helpful when fighting spyware/viruses.
  • Sync Tool - Folder sync tool with lots of real time information and several checking methods.
  • USMT Front End - Front End for Microsoft's User State Migration Tool, including all files needed for USMT 3.01 and 4.01, 32 bit and 64 bit versions.
  • Audit Tool - Computer audit tool to gather vital hardware, Windows, and Office information for IT managers and field techs. Capabilities include creating a customized site agent.
  • CSV Viewer - Displays CSV files with automatic column sizing and font selection. Lines can also be copied to the clipboard for data extraction.
  • MyDirStat - Lists number and size of files on a drive or specified path, allows for deletion within the app.
  • 2048 Game - My version of 2048, fun tile game.
  • Juice Lab - Ecigarette liquid making calculator.
  • Data Protector - Secure notes to save sensitive information.
  • VHD Footer - Add a footer to a forensic hard drive image to allow it to be mounted or used as a virtual machine hard drive.
  • Find in File - Searches files containing a specified phrase.

Share this post


Link to post
Share on other sites



Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!


Register a new account

Sign in

Already have an account? Sign in here.


Sign In Now
Sign in to follow this  
Followers 0