aim-web2.1.0rc9
This commit is contained in:
@@ -0,0 +1,63 @@
|
||||
|
||||
- name: Event logs | Validate input
|
||||
ansible.builtin.assert:
|
||||
that:
|
||||
- event_age_days | int > 0
|
||||
- event_age_days | int <= 36500
|
||||
- export_folder is string
|
||||
- export_folder | length > 0
|
||||
- event_log_channels is sequence
|
||||
- event_log_channels is not string
|
||||
- event_log_channels | length > 0
|
||||
fail_msg: Supply a positive age, a target folder and at least one event channel.
|
||||
quiet: true
|
||||
- name: Event logs | Ensure export directory
|
||||
ansible.windows.win_file:
|
||||
path: '{{ export_folder }}'
|
||||
state: directory
|
||||
- name: Event logs | Export selected channels
|
||||
ansible.windows.win_powershell:
|
||||
script: |
|
||||
[CmdletBinding(SupportsShouldProcess)]
|
||||
param([int]$EventAgeDays, [string]$ExportFolder, [string[]]$Channels)
|
||||
$ErrorActionPreference = 'Stop'
|
||||
$Ansible.Changed = $false
|
||||
$date = Get-Date -Format 'yyyy-MM-dd_HHmmss'
|
||||
$maxAgeMs = [int64]([timespan]::FromDays($EventAgeDays).TotalMilliseconds)
|
||||
$q = "*[System[TimeCreated[timediff(@SystemTime) <= $maxAgeMs]]]"
|
||||
$map = @{ Application='APP'; Security='SEC'; System='SYS'; Setup='INS' }
|
||||
$files = @()
|
||||
foreach ($log in $Channels) {
|
||||
$suffix = if ($map.ContainsKey($log)) { $map[$log] } else { $log -replace '[^A-Za-z0-9_.-]', '_' }
|
||||
$filename = Join-Path $ExportFolder "$date-$suffix.evtx"
|
||||
if ($PSCmdlet.ShouldProcess($filename, "Export $log")) {
|
||||
& wevtutil.exe epl $log $filename "/q:$q" | Out-Null
|
||||
if ($LASTEXITCODE -ne 0) { throw "Event export failed for channel '$log'. Exit: $LASTEXITCODE" }
|
||||
if (-not (Test-Path -LiteralPath $filename)) { throw "Event export file is missing: $filename" }
|
||||
$Ansible.Changed = $true
|
||||
}
|
||||
$files += $filename
|
||||
}
|
||||
$Ansible.Result = @{ files=$files; channels=$Channels; days=$EventAgeDays }
|
||||
parameters:
|
||||
EventAgeDays: '{{ event_age_days | int }}'
|
||||
ExportFolder: '{{ export_folder }}'
|
||||
Channels: '{{ event_log_channels }}'
|
||||
error_action: stop
|
||||
register: _aim_event_exports
|
||||
- name: Event logs | Export summary
|
||||
ansible.builtin.debug:
|
||||
msg: '{{ _aim_event_exports.result }}'
|
||||
- name: AIM | Publish operation result
|
||||
ansible.builtin.set_stats:
|
||||
per_host: true
|
||||
aggregate: false
|
||||
data:
|
||||
aim_output:
|
||||
protocol: aim_output_v1
|
||||
schema: event_log_export_v1
|
||||
data:
|
||||
mode: "{{ 'check' if ansible_check_mode else 'apply' }}"
|
||||
days: '{{ event_age_days | int }}'
|
||||
channels: '{{ event_log_channels }}'
|
||||
files: '{{ [] if ansible_check_mode else _aim_event_exports.result.files | default([]) }}'
|
||||
Reference in New Issue
Block a user