aim-web2.1.0rc9

This commit is contained in:
admin_rb
2026-09-22 19:23:17 +02:00
parent d095887d2e
commit 3dfc80b782
438 changed files with 31613 additions and 1510 deletions
@@ -0,0 +1,37 @@
---
# PURPOSE: Export Windows event logs
# DESCRIPTION: Export selected event channels to EVTX files on the target; existing event logs are not cleared.
# TARGETS: windows
# INPUTS (omitted values inherit inventory / role defaults):
# aim_debug [bool]: false
# event_age_days [int]: 45
# export_folder [text]: C:\Logs
# event_log_channels [list]: Application, Security, System, Setup
# AUTH: existing inventory / Vault credentials; no embedded passwords.
# EXAMPLE: ansible-playbook -i inventories/<customer>/hosts.yml
# playbooks/maintenance_export_event_logs.yml --limit <host> --vault-id <customer>@prompt
- name: Maintenance | Export Windows event logs
hosts: windows
gather_facts: false
pre_tasks:
- name: AIM | Validate diagnostics option
ansible.builtin.assert:
that:
- (aim_debug | default(false)) is boolean or (aim_debug | default(false) | string | lower) in ['true',
'false']
fail_msg: aim_debug must be a YAML/JSON boolean.
quiet: true
- name: AIM | Reject mixed platform membership
ansible.builtin.assert:
that:
- (group_names | intersect(['linux', 'windows', 'sophosxgs', 'pfsense']) | length) <= 1
fail_msg: This host belongs to incompatible platform groups. Use globally unique subgroups.
quiet: true
- name: AIM | Execution context
ansible.builtin.debug:
msg:
host: '{{ inventory_hostname }}'
diagnostics: Enabled; secret values are never included by this task.
when: aim_debug | default(false) | bool
roles:
- role: maintenance_export_event_logs