From 11eb3744784f7c4d43e911a0853ddb20952fffce Mon Sep 17 00:00:00 2001
From: MartinGC94 <42123497+MartinGC94@users.noreply.github.com>
Date: Tue, 5 May 2026 21:56:48 +0200
Subject: [PATCH] Improve `Get-WinEvent -ListLog` exception handling (#27395)
---
.../GetEventCommand.cs | 44 +++++++++++++------
.../resources/GetEventResources.resx | 6 +++
2 files changed, 37 insertions(+), 13 deletions(-)
diff --git a/src/Microsoft.PowerShell.Commands.Diagnostics/GetEventCommand.cs b/src/Microsoft.PowerShell.Commands.Diagnostics/GetEventCommand.cs
index c7a07bab6e..0ce68a31d7 100644
--- a/src/Microsoft.PowerShell.Commands.Diagnostics/GetEventCommand.cs
+++ b/src/Microsoft.PowerShell.Commands.Diagnostics/GetEventCommand.cs
@@ -518,9 +518,11 @@ namespace Microsoft.PowerShell.Commands
||
(wildLogPattern.IsMatch(logName)))
{
+ EventLogConfiguration logObj;
+ EventLogInformation logInfoObj;
try
{
- EventLogConfiguration logObj = new(logName, eventLogSession);
+ logObj = new EventLogConfiguration(logName, eventLogSession);
//
// Skip direct channels matching the wildcard unless -Force is present.
@@ -533,19 +535,25 @@ namespace Microsoft.PowerShell.Commands
continue;
}
- EventLogInformation logInfoObj = eventLogSession.GetLogInformation(logName, PathType.LogName);
-
- PSObject outputObj = new(logObj);
-
- outputObj.Properties.Add(new PSNoteProperty("FileSize", logInfoObj.FileSize));
- outputObj.Properties.Add(new PSNoteProperty("IsLogFull", logInfoObj.IsLogFull));
- outputObj.Properties.Add(new PSNoteProperty("LastAccessTime", logInfoObj.LastAccessTime));
- outputObj.Properties.Add(new PSNoteProperty("LastWriteTime", logInfoObj.LastWriteTime));
- outputObj.Properties.Add(new PSNoteProperty("OldestRecordNumber", logInfoObj.OldestRecordNumber));
- outputObj.Properties.Add(new PSNoteProperty("RecordCount", logInfoObj.RecordCount));
-
- WriteObject(outputObj);
bMatchFound = true;
+ logInfoObj = eventLogSession.GetLogInformation(logName, PathType.LogName);
+ }
+ catch (UnauthorizedAccessException exc)
+ {
+ string exceptionMsg = string.Format(CultureInfo.InvariantCulture, GetEventResources.LogInfoNoAccess, logName);
+ var newExc = new UnauthorizedAccessException(exceptionMsg, exc);
+
+ string recommendationMsg = GetEventResources.SuggestElevation;
+ var eRecord = new ErrorRecord(newExc, "LogInfoNoAccess", ErrorCategory.PermissionDenied, logName)
+ {
+ ErrorDetails = new ErrorDetails(string.Empty)
+ {
+ RecommendedAction = recommendationMsg
+ }
+ };
+
+ WriteError(eRecord);
+ continue;
}
catch (Exception exc)
{
@@ -556,6 +564,16 @@ namespace Microsoft.PowerShell.Commands
WriteError(new ErrorRecord(outerExc, "LogInfoUnavailable", ErrorCategory.NotSpecified, null));
continue;
}
+
+ PSObject outputObj = new(logObj);
+ outputObj.Properties.Add(new PSNoteProperty("FileSize", logInfoObj.FileSize));
+ outputObj.Properties.Add(new PSNoteProperty("IsLogFull", logInfoObj.IsLogFull));
+ outputObj.Properties.Add(new PSNoteProperty("LastAccessTime", logInfoObj.LastAccessTime));
+ outputObj.Properties.Add(new PSNoteProperty("LastWriteTime", logInfoObj.LastWriteTime));
+ outputObj.Properties.Add(new PSNoteProperty("OldestRecordNumber", logInfoObj.OldestRecordNumber));
+ outputObj.Properties.Add(new PSNoteProperty("RecordCount", logInfoObj.RecordCount));
+
+ WriteObject(outputObj);
}
}
diff --git a/src/Microsoft.PowerShell.Commands.Diagnostics/resources/GetEventResources.resx b/src/Microsoft.PowerShell.Commands.Diagnostics/resources/GetEventResources.resx
index f8f41ecc2f..53bf9afe0e 100644
--- a/src/Microsoft.PowerShell.Commands.Diagnostics/resources/GetEventResources.resx
+++ b/src/Microsoft.PowerShell.Commands.Diagnostics/resources/GetEventResources.resx
@@ -255,6 +255,12 @@ The defined template is following:
To access the '{0}' log start PowerShell with elevated user rights. Error: {1}
+
+ Access denied for log: '{0}'.
+
+
+ Launch PowerShell with elevated user rights.
+
Cannot retrieve event message text.