- name: Event logs | Validate input ansible.builtin.assert: that: - event_age_days | int > 0 - event_age_days | int <= 36500 - export_folder is string - export_folder | length > 0 - event_log_channels is sequence - event_log_channels is not string - event_log_channels | length > 0 fail_msg: Supply a positive age, a target folder and at least one event channel. quiet: true - name: Event logs | Ensure export directory ansible.windows.win_file: path: '{{ export_folder }}' state: directory - name: Event logs | Export selected channels ansible.windows.win_powershell: script: | [CmdletBinding(SupportsShouldProcess)] param([int]$EventAgeDays, [string]$ExportFolder, [string[]]$Channels) $ErrorActionPreference = 'Stop' $Ansible.Changed = $false $date = Get-Date -Format 'yyyy-MM-dd_HHmmss' $maxAgeMs = [int64]([timespan]::FromDays($EventAgeDays).TotalMilliseconds) $q = "*[System[TimeCreated[timediff(@SystemTime) <= $maxAgeMs]]]" $map = @{ Application='APP'; Security='SEC'; System='SYS'; Setup='INS' } $files = @() foreach ($log in $Channels) { $suffix = if ($map.ContainsKey($log)) { $map[$log] } else { $log -replace '[^A-Za-z0-9_.-]', '_' } $filename = Join-Path $ExportFolder "$date-$suffix.evtx" if ($PSCmdlet.ShouldProcess($filename, "Export $log")) { & wevtutil.exe epl $log $filename "/q:$q" | Out-Null if ($LASTEXITCODE -ne 0) { throw "Event export failed for channel '$log'. Exit: $LASTEXITCODE" } if (-not (Test-Path -LiteralPath $filename)) { throw "Event export file is missing: $filename" } $Ansible.Changed = $true } $files += $filename } $Ansible.Result = @{ files=$files; channels=$Channels; days=$EventAgeDays } parameters: EventAgeDays: '{{ event_age_days | int }}' ExportFolder: '{{ export_folder }}' Channels: '{{ event_log_channels }}' error_action: stop register: _aim_event_exports - name: Event logs | Export summary ansible.builtin.debug: msg: '{{ _aim_event_exports.result }}' - name: AIM | Publish operation result ansible.builtin.set_stats: per_host: true aggregate: false data: aim_output: protocol: aim_output_v1 schema: event_log_export_v1 data: mode: "{{ 'check' if ansible_check_mode else 'apply' }}" days: '{{ event_age_days | int }}' channels: '{{ event_log_channels }}' files: '{{ [] if ansible_check_mode else _aim_event_exports.result.files | default([]) }}'