|
|
|
|
|
|
|
pevlr = VarPtr(bBuffer(0))
While (ReadEventLog(h, EVENTLOG_FORWARDS_READ Or _
EVENTLOG_SEQUENTIAL_READ, _
0, bBuffer(0), BUFFER_SIZE, dwRead, dwNeeded) <> 0)
While dwRead > 0
' Copy the data into the ev structure.
RtlMoveMemory ev, ByVal pevlr, Len(ev)
List1.AddItem " Event Type: " & Hex$(ev.EventType) & _
" Source: " & LoadStringFromPtr(pevlr + _
Len(ev))
dwRead = dwRead - ev.Length
pevlr = pevlr + ev.Length
Wend
' Reset the pointer to the start of the buffer
pevlr = VarPtr(bBuffer(0))
Wend
Call CloseEventLog(h)
End If
End Sub |
|
|
|
|
|
|
|
|
Here's one last challenge: Immediately after the event source string in the buffer, you'll find the computer name. Can you figure out how to retrieve it? The answer is in the actual sample program. |
|
|
|
|
|