< previous page page_429 next page >

Page 429
      }
   Set the EVENTLOGRECORD pointer to the start of the buffer
   pevlr = (EVENTLOGRECORD *) &bBuffer;
   }
The pevlr variable is a pointer variable that initially points to the start of an arbitrarily sized buffer. This example reads as many records as possible into the buffer. It then scans through each entry in the buffer.
It's important to take the time to understand exactly what the code is doing rather than try to mimic it line by line in Visual Basic. The best way to do this, if you are not a C programmer, is to back up and read the documentation for the function before trying to figure out the C code. Once you realize that the ReadEventLog function is capable of reading multiple event log records, the code here begins to make sense.
You may wonder why you should read multiple records in a double loop as shown here. Why use a byte array instead of reading one or more EVENTLOGRECORD structures directly?
The trick is in the structure itself. As you can see from the structure declaration, some of the variables in the structure are actually offsets to strings and other variable-length data. The question arises: Where can this additional data be found? The answer is that the data is placed in the buffer along with and immediately after the EVENTLOGRECORD structure. More information can be found in the Win32 SDK documentation for the structure. After the last field in the structure, it shows the following fields:
// TCHAR SourceName[]
// TCHAR Computername[]
// SID   UserSid
// TCHAR Strings[]
// BYTE  Data[]
// CHAR  Pad[]
// DWORD Length;
These fields can't be defined in the structure itself because they are of variable length. So we need to allocate a buffer that will hold not only the EVENTLOGRECORD structure, but all of the data for the event as well. The Length field contains the total length of the structure and includes the length of the variable length fields. It is stored both at the beginning and end of the structure to make it easier to scan forward or backward through the buffer. The following variables correspond exactly to those in the C example:
Private Const BUFFER_SIZE = 8192  ' Arbitrary number
Dim bBuffer(BUFFER_SIZE) As Byte

 
< previous page page_429 next page >