Improve Get-WinEvent -ListLog exception handling (#27395)

This commit is contained in:
MartinGC94
2026-05-05 12:56:48 -07:00
committed by GitHub
parent 36673f6d46
commit 11eb374478
2 changed files with 37 additions and 13 deletions
@@ -518,9 +518,11 @@ namespace Microsoft.PowerShell.Commands
||
(wildLogPattern.IsMatch(logName)))
{
EventLogConfiguration logObj;
EventLogInformation logInfoObj;
try
{
EventLogConfiguration logObj = new(logName, eventLogSession);
logObj = new EventLogConfiguration(logName, eventLogSession);
//
// Skip direct channels matching the wildcard unless -Force is present.
@@ -533,19 +535,25 @@ namespace Microsoft.PowerShell.Commands
continue;
}
EventLogInformation logInfoObj = eventLogSession.GetLogInformation(logName, PathType.LogName);
PSObject outputObj = new(logObj);
outputObj.Properties.Add(new PSNoteProperty("FileSize", logInfoObj.FileSize));
outputObj.Properties.Add(new PSNoteProperty("IsLogFull", logInfoObj.IsLogFull));
outputObj.Properties.Add(new PSNoteProperty("LastAccessTime", logInfoObj.LastAccessTime));
outputObj.Properties.Add(new PSNoteProperty("LastWriteTime", logInfoObj.LastWriteTime));
outputObj.Properties.Add(new PSNoteProperty("OldestRecordNumber", logInfoObj.OldestRecordNumber));
outputObj.Properties.Add(new PSNoteProperty("RecordCount", logInfoObj.RecordCount));
WriteObject(outputObj);
bMatchFound = true;
logInfoObj = eventLogSession.GetLogInformation(logName, PathType.LogName);
}
catch (UnauthorizedAccessException exc)
{
string exceptionMsg = string.Format(CultureInfo.InvariantCulture, GetEventResources.LogInfoNoAccess, logName);
var newExc = new UnauthorizedAccessException(exceptionMsg, exc);
string recommendationMsg = GetEventResources.SuggestElevation;
var eRecord = new ErrorRecord(newExc, "LogInfoNoAccess", ErrorCategory.PermissionDenied, logName)
{
ErrorDetails = new ErrorDetails(string.Empty)
{
RecommendedAction = recommendationMsg
}
};
WriteError(eRecord);
continue;
}
catch (Exception exc)
{
@@ -556,6 +564,16 @@ namespace Microsoft.PowerShell.Commands
WriteError(new ErrorRecord(outerExc, "LogInfoUnavailable", ErrorCategory.NotSpecified, null));
continue;
}
PSObject outputObj = new(logObj);
outputObj.Properties.Add(new PSNoteProperty("FileSize", logInfoObj.FileSize));
outputObj.Properties.Add(new PSNoteProperty("IsLogFull", logInfoObj.IsLogFull));
outputObj.Properties.Add(new PSNoteProperty("LastAccessTime", logInfoObj.LastAccessTime));
outputObj.Properties.Add(new PSNoteProperty("LastWriteTime", logInfoObj.LastWriteTime));
outputObj.Properties.Add(new PSNoteProperty("OldestRecordNumber", logInfoObj.OldestRecordNumber));
outputObj.Properties.Add(new PSNoteProperty("RecordCount", logInfoObj.RecordCount));
WriteObject(outputObj);
}
}
@@ -255,6 +255,12 @@ The defined template is following:
<data name="LogInfoUnavailable" xml:space="preserve">
<value>To access the '{0}' log start PowerShell with elevated user rights. Error: {1}</value>
</data>
<data name="LogInfoNoAccess" xml:space="preserve">
<value>Access denied for log: '{0}'.</value>
</data>
<data name="SuggestElevation" xml:space="preserve">
<value>Launch PowerShell with elevated user rights.</value>
</data>
<data name="NoEventMessage" xml:space="preserve">
<value>Cannot retrieve event message text.</value>
</data>