|
|
 |
|
|
|
|
pevlr + sizeof(EVENTLOGRECORD)));
dwRead -= pevlr->Length;
pevlr = (EVENTLOGRECORD *) ((LPBYTE) pevlr + pevlr->Length);
}
pevlr = (EVENTLOGRECORD *) &bBuffer;
}
CloseEventLog(h); |
|
|
|
|
|
|
|
|
Learning how to translate C language code is an essential task for advanced VB programmers. I tried to cover most of the core Win32 API in my book, but with new API functions being defined daily, it is impossible for any book to cover everything that every VB programmer may need to know. That's why I spent two chapters in my API book discussing how to convert C API declarations to Visual Basic. |
|
|
|
|
|
|
|
|
Still, practice makes perfect, and the event log question posed here is an interesting exercise indeed. |
|
|
|
|
|
|
|
|
A first step is to define the EVENTLOGRECORD structure. This can be found in the following api32.txt file, which comes with my Win32 API book: |
|
|
|
|
|
|
|
|
Type EVENTLOGRECORD
Length as Long ' Length of full record
Reserved as Long ' Used by the service
RecordNumber as Long ' Absolute record number
TimeGenerated as Long ' Seconds since 1-1-1970
TimeWritten as Long 'Seconds since 1-1-1970
EventID as Long
EventType as Integer
NumStrings as Integer
EventCategory as Integer
ReservedFlags as Integer ' For use with paired events
ClosingRecordNumber as Long 'For use with paired events
StringOffset as Long ' Offset from beginning of record
UserSidLength as Long
UserSidOffset as Long
DataLength as Long
DataOffset as Long ' Offset from beginning of record
End Type |
|
|
|
|
|
|
|
|
The conversion of this structure from the C type declaration is trivial since it only contains DWORD and WORD types. DWORDs translate into VB Long variables, WORDs into VB integers. |
|
|
|
|
|
|
|
|
Next, let's take a look at the API functions we'll be using: |
|
|
|
|
|
|
|
|
HANDLE OpenEventLog(LPCTSTR lpUNCServerName, LPCTSTR lpSourceName ); |
|
|
|
|
|