64 lines
2.7 KiB
YAML
64 lines
2.7 KiB
YAML
|
|
- name: Event logs | Validate input
|
|
ansible.builtin.assert:
|
|
that:
|
|
- event_age_days | int > 0
|
|
- event_age_days | int <= 36500
|
|
- export_folder is string
|
|
- export_folder | length > 0
|
|
- event_log_channels is sequence
|
|
- event_log_channels is not string
|
|
- event_log_channels | length > 0
|
|
fail_msg: Supply a positive age, a target folder and at least one event channel.
|
|
quiet: true
|
|
- name: Event logs | Ensure export directory
|
|
ansible.windows.win_file:
|
|
path: '{{ export_folder }}'
|
|
state: directory
|
|
- name: Event logs | Export selected channels
|
|
ansible.windows.win_powershell:
|
|
script: |
|
|
[CmdletBinding(SupportsShouldProcess)]
|
|
param([int]$EventAgeDays, [string]$ExportFolder, [string[]]$Channels)
|
|
$ErrorActionPreference = 'Stop'
|
|
$Ansible.Changed = $false
|
|
$date = Get-Date -Format 'yyyy-MM-dd_HHmmss'
|
|
$maxAgeMs = [int64]([timespan]::FromDays($EventAgeDays).TotalMilliseconds)
|
|
$q = "*[System[TimeCreated[timediff(@SystemTime) <= $maxAgeMs]]]"
|
|
$map = @{ Application='APP'; Security='SEC'; System='SYS'; Setup='INS' }
|
|
$files = @()
|
|
foreach ($log in $Channels) {
|
|
$suffix = if ($map.ContainsKey($log)) { $map[$log] } else { $log -replace '[^A-Za-z0-9_.-]', '_' }
|
|
$filename = Join-Path $ExportFolder "$date-$suffix.evtx"
|
|
if ($PSCmdlet.ShouldProcess($filename, "Export $log")) {
|
|
& wevtutil.exe epl $log $filename "/q:$q" | Out-Null
|
|
if ($LASTEXITCODE -ne 0) { throw "Event export failed for channel '$log'. Exit: $LASTEXITCODE" }
|
|
if (-not (Test-Path -LiteralPath $filename)) { throw "Event export file is missing: $filename" }
|
|
$Ansible.Changed = $true
|
|
}
|
|
$files += $filename
|
|
}
|
|
$Ansible.Result = @{ files=$files; channels=$Channels; days=$EventAgeDays }
|
|
parameters:
|
|
EventAgeDays: '{{ event_age_days | int }}'
|
|
ExportFolder: '{{ export_folder }}'
|
|
Channels: '{{ event_log_channels }}'
|
|
error_action: stop
|
|
register: _aim_event_exports
|
|
- name: Event logs | Export summary
|
|
ansible.builtin.debug:
|
|
msg: '{{ _aim_event_exports.result }}'
|
|
- name: AIM | Publish operation result
|
|
ansible.builtin.set_stats:
|
|
per_host: true
|
|
aggregate: false
|
|
data:
|
|
aim_output:
|
|
protocol: aim_output_v1
|
|
schema: event_log_export_v1
|
|
data:
|
|
mode: "{{ 'check' if ansible_check_mode else 'apply' }}"
|
|
days: '{{ event_age_days | int }}'
|
|
channels: '{{ event_log_channels }}'
|
|
files: '{{ [] if ansible_check_mode else _aim_event_exports.result.files | default([]) }}'
|