2 * ReactOS Win32 Applications
3 * Copyright (C) 2007 ReactOS Team
5 * This program is free software; you can redistribute it and/or modify
6 * it under the terms of the GNU General Public License as published by
7 * the Free Software Foundation; either version 2 of the License, or
8 * (at your option) any later version.
10 * This program is distributed in the hope that it will be useful,
11 * but WITHOUT ANY WARRANTY; without even the implied warranty of
12 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
13 * GNU General Public License for more details.
15 * You should have received a copy of the GNU General Public License along
16 * with this program; if not, write to the Free Software Foundation, Inc.,
17 * 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA.
20 * COPYRIGHT : See COPYING in the top level directory
21 * PROJECT : Event Log Viewer
23 * PROGRAMMER: Marc Piulachs (marc.piulachs at codexchange [dot] net)
41 #pragma warning(disable: 4996) /* 'strdup' was declared deprecated */
42 #define _CRT_SECURE_NO_DEPRECATE /* all deprecated unsafe string functions */
45 static const WCHAR szWindowClass
[] = L
"EVENTVWR"; /* the main window class name*/
46 static const WCHAR EVENTLOG_BASE_KEY
[] = L
"SYSTEM\\CurrentControlSet\\Services\\EventLog\\";
48 // MessageFile message buffer size
49 #define EVENT_MESSAGE_EVENTTEXT_BUFFER 1024*10
50 #define EVENT_MESSAGE_FILE_BUFFER 1024*10
51 #define EVENT_DLL_SEPARATOR L";"
52 #define EVENT_MESSAGE_FILE L"EventMessageFile"
53 #define EVENT_CATEGORY_MESSAGE_FILE L"CategoryMessageFile"
54 #define EVENT_PARAMETER_MESSAGE_FILE L"ParameterMessageFile"
56 #define MAX_LOADSTRING 255
59 HINSTANCE hInst
; /* current instance */
60 WCHAR szTitle
[MAX_LOADSTRING
]; /* The title bar text */
61 WCHAR szTitleTemplate
[MAX_LOADSTRING
]; /* The logged-on title bar text */
62 WCHAR szSaveFilter
[MAX_LOADSTRING
]; /* Filter Mask for the save Dialog */
63 HWND hwndMainWindow
; /* Main window */
64 HWND hwndListView
; /* ListView control */
65 HWND hwndStatus
; /* Status bar */
66 HMENU hMainMenu
; /* The application's main menu */
67 WCHAR szStatusBarTemplate
[MAX_LOADSTRING
]; /* The status bar text */
68 PEVENTLOGRECORD
*g_RecordPtrs
= NULL
;
69 DWORD g_TotalRecords
= 0;
72 LPWSTR lpSourceLogName
= NULL
;
73 LPWSTR lpComputerName
= NULL
;
78 /* Forward declarations of functions included in this code module: */
79 ATOM
MyRegisterClass(HINSTANCE hInstance
);
80 BOOL
InitInstance(HINSTANCE
, int);
81 LRESULT CALLBACK
WndProc(HWND
, UINT
, WPARAM
, LPARAM
);
82 INT_PTR CALLBACK
About(HWND
, UINT
, WPARAM
, LPARAM
);
83 INT_PTR CALLBACK
EventDetails(HWND
, UINT
, WPARAM
, LPARAM
);
84 static INT_PTR CALLBACK
StatusMessageWindowProc (HWND
, UINT
, WPARAM
, LPARAM
);
88 wWinMain(HINSTANCE hInstance
,
89 HINSTANCE hPrevInstance
,
95 INITCOMMONCONTROLSEX iccx
;
97 UNREFERENCED_PARAMETER(hPrevInstance
);
98 UNREFERENCED_PARAMETER(lpCmdLine
);
100 /* Whenever any of the common controls are used in your app,
101 * you must call InitCommonControlsEx() to register the classes
102 * for those controls. */
103 iccx
.dwSize
= sizeof(INITCOMMONCONTROLSEX
);
104 iccx
.dwICC
= ICC_LISTVIEW_CLASSES
;
105 InitCommonControlsEx(&iccx
);
107 /* Initialize global strings */
108 LoadStringW(hInstance
, IDS_APP_TITLE
, szTitle
, MAX_LOADSTRING
);
109 LoadStringW(hInstance
, IDS_APP_TITLE_EX
, szTitleTemplate
, MAX_LOADSTRING
);
110 LoadStringW(hInstance
, IDS_STATUS_MSG
, szStatusBarTemplate
, MAX_LOADSTRING
);
111 MyRegisterClass(hInstance
);
113 /* Perform application initialization: */
114 if (!InitInstance(hInstance
, nCmdShow
))
119 hAccelTable
= LoadAccelerators(hInstance
, MAKEINTRESOURCE(IDC_EVENTVWR
));
121 /* Main message loop: */
122 while (GetMessageW(&msg
, NULL
, 0, 0))
124 if (!TranslateAcceleratorW(msg
.hwnd
, hAccelTable
, &msg
))
126 TranslateMessage(&msg
);
127 DispatchMessage(&msg
);
131 return (int)msg
.wParam
;
134 static void FreeRecords(void)
141 for (iIndex
= 0; iIndex
< g_TotalRecords
; iIndex
++)
142 HeapFree(GetProcessHeap(), 0, g_RecordPtrs
[iIndex
]);
143 HeapFree(GetProcessHeap(), 0, g_RecordPtrs
);
148 ShowLastWin32Error(VOID
)
151 LPWSTR lpMessageBuffer
;
153 dwError
= GetLastError();
154 FormatMessageW(FORMAT_MESSAGE_ALLOCATE_BUFFER
| FORMAT_MESSAGE_FROM_SYSTEM
,
158 (LPWSTR
)&lpMessageBuffer
,
162 MessageBoxW(hwndMainWindow
, lpMessageBuffer
, szTitle
, MB_OK
| MB_ICONERROR
);
163 LocalFree(lpMessageBuffer
);
167 EventTimeToSystemTime(DWORD EventTime
,
168 SYSTEMTIME
*pSystemTime
)
170 SYSTEMTIME st1970
= { 1970, 1, 0, 1, 0, 0, 0, 0 };
178 uUCT
.ft
.dwHighDateTime
= 0;
179 uUCT
.ft
.dwLowDateTime
= EventTime
;
180 SystemTimeToFileTime(&st1970
, &u1970
.ft
);
181 uUCT
.ll
= uUCT
.ll
* 10000000 + u1970
.ll
;
182 FileTimeToLocalFileTime(&uUCT
.ft
, &ftLocal
);
183 FileTimeToSystemTime(&ftLocal
, pSystemTime
);
194 c
= s
+ wcslen(s
) - 1;
195 while (c
>= s
&& iswspace(*c
))
203 GetEventMessageFileDLL(IN LPCWSTR lpLogName
,
204 IN LPCWSTR SourceName
,
205 IN LPCWSTR EntryName
,
206 OUT PWCHAR ExpandedName
)
209 BYTE szModuleName
[MAX_PATH
];
210 WCHAR szKeyName
[MAX_PATH
];
212 HKEY hSourceKey
= NULL
;
213 BOOL bReturn
= FALSE
;
215 StringCbCopyW(szKeyName
, sizeof(szKeyName
), L
"SYSTEM\\CurrentControlSet\\Services\\EventLog\\");
216 StringCbCatW(szKeyName
, sizeof(szKeyName
), lpLogName
);
218 if (RegOpenKeyExW(HKEY_LOCAL_MACHINE
,
222 &hAppKey
) == ERROR_SUCCESS
)
224 if (RegOpenKeyExW(hAppKey
,
228 &hSourceKey
) == ERROR_SUCCESS
)
231 if (RegQueryValueExW(hSourceKey
,
235 (LPBYTE
)szModuleName
,
236 &dwSize
) == ERROR_SUCCESS
)
238 /* Returns a string containing the requested substituted environment variable. */
239 ExpandEnvironmentStringsW((LPCWSTR
)szModuleName
, ExpandedName
, MAX_PATH
);
248 ShowLastWin32Error();
251 if (hSourceKey
!= NULL
)
252 RegCloseKey(hSourceKey
);
255 RegCloseKey(hAppKey
);
262 GetEventCategory(IN LPCWSTR KeyName
,
263 IN LPCWSTR SourceName
,
264 IN EVENTLOGRECORD
*pevlr
,
265 OUT PWCHAR CategoryName
)
267 HANDLE hLibrary
= NULL
;
268 WCHAR szMessageDLL
[MAX_PATH
];
269 LPVOID lpMsgBuf
= NULL
;
271 if (GetEventMessageFileDLL (KeyName
, SourceName
, EVENT_CATEGORY_MESSAGE_FILE
, szMessageDLL
))
273 hLibrary
= LoadLibraryExW(szMessageDLL
,
275 DONT_RESOLVE_DLL_REFERENCES
| LOAD_LIBRARY_AS_DATAFILE
);
276 if (hLibrary
!= NULL
)
278 /* Retrieve the message string. */
279 if (FormatMessageW(FORMAT_MESSAGE_FROM_SYSTEM
| FORMAT_MESSAGE_ALLOCATE_BUFFER
| FORMAT_MESSAGE_FROM_HMODULE
| FORMAT_MESSAGE_ARGUMENT_ARRAY
,
281 pevlr
->EventCategory
,
282 MAKELANGID(LANG_NEUTRAL
, SUBLANG_DEFAULT
),
284 EVENT_MESSAGE_FILE_BUFFER
,
287 /* Trim the string */
290 /* Copy the category name */
291 StringCchCopyW(CategoryName
, MAX_PATH
, lpMsgBuf
);
295 LoadStringW(hInst
, IDS_NONE
, CategoryName
, MAX_PATH
);
298 if (hLibrary
!= NULL
)
299 FreeLibrary(hLibrary
);
301 /* Free the buffer allocated by FormatMessage */
309 LoadStringW(hInst
, IDS_NONE
, CategoryName
, MAX_PATH
);
316 GetEventMessage(IN LPCWSTR KeyName
,
317 IN LPCWSTR SourceName
,
318 IN EVENTLOGRECORD
*pevlr
,
319 OUT PWCHAR EventText
)
322 HANDLE hLibrary
= NULL
;
323 WCHAR SourceModuleName
[1000];
324 WCHAR ParameterModuleName
[1000];
325 LPWSTR lpMsgBuf
= NULL
;
326 WCHAR szStringIDNotFound
[MAX_LOADSTRING
];
332 /* TODO : GetEventMessageFileDLL can return a comma separated list of DLLs */
333 if (GetEventMessageFileDLL (KeyName
, SourceName
, EVENT_MESSAGE_FILE
, SourceModuleName
))
335 /* Get the event message */
336 szMessage
= (LPWSTR
)((LPBYTE
)pevlr
+ pevlr
->StringOffset
);
338 /* Allocate space for parameters */
339 szArguments
= malloc(sizeof(LPVOID
) * pevlr
->NumStrings
);
345 for (i
= 0; i
< pevlr
->NumStrings
; i
++)
347 if (wcsstr(szMessage
, L
"%%"))
349 if (GetEventMessageFileDLL(KeyName
, SourceName
, EVENT_PARAMETER_MESSAGE_FILE
, ParameterModuleName
))
351 /* Not yet support for reading messages from parameter message DLL */
355 szArguments
[i
] = szMessage
;
356 szMessage
+= wcslen(szMessage
) + 1;
359 szDll
= wcstok(SourceModuleName
, EVENT_DLL_SEPARATOR
);
360 while ((szDll
!= NULL
) && (!bDone
))
362 hLibrary
= LoadLibraryExW(szDll
,
364 DONT_RESOLVE_DLL_REFERENCES
| LOAD_LIBRARY_AS_DATAFILE
);
365 if (hLibrary
== NULL
)
367 /* The DLL could not be loaded try the next one (if any) */
368 szDll
= wcstok(NULL
, EVENT_DLL_SEPARATOR
);
372 /* Retrieve the message string. */
373 if (FormatMessageW(FORMAT_MESSAGE_FROM_SYSTEM
|
374 FORMAT_MESSAGE_ALLOCATE_BUFFER
|
375 FORMAT_MESSAGE_FROM_HMODULE
|
376 FORMAT_MESSAGE_ARGUMENT_ARRAY
,
379 MAKELANGID(LANG_NEUTRAL
, SUBLANG_DEFAULT
),
382 (va_list*)szArguments
) == 0)
384 /* We haven't found the string , get next DLL (if any) */
385 szDll
= wcstok(NULL
, EVENT_DLL_SEPARATOR
);
391 /* The ID was found and the message was formated */
394 /* Trim the string */
395 TrimNulls((LPWSTR
)lpMsgBuf
);
397 /* Copy the event text */
398 StringCchCopyW(EventText
, EVENT_MESSAGE_EVENTTEXT_BUFFER
, lpMsgBuf
);
402 FreeLibrary(hLibrary
);
408 LoadStringW(hInst
, IDS_EVENTSTRINGIDNOTFOUND
, szStringIDNotFound
, MAX_LOADSTRING
);
409 StringCchPrintfW(EventText
, EVENT_MESSAGE_EVENTTEXT_BUFFER
, szStringIDNotFound
, (pevlr
->EventID
& 0xFFFF), SourceName
);
414 /* No more dlls to try, return result */
418 LoadStringW(hInst
, IDS_EVENTSTRINGIDNOTFOUND
, szStringIDNotFound
, MAX_LOADSTRING
);
419 StringCchPrintfW(EventText
, EVENT_MESSAGE_EVENTTEXT_BUFFER
, szStringIDNotFound
, (pevlr
->EventID
& 0xFFFF), SourceName
);
426 GetEventType(IN WORD dwEventType
,
427 OUT PWCHAR eventTypeText
)
431 case EVENTLOG_ERROR_TYPE
:
432 LoadStringW(hInst
, IDS_EVENTLOG_ERROR_TYPE
, eventTypeText
, MAX_LOADSTRING
);
434 case EVENTLOG_WARNING_TYPE
:
435 LoadStringW(hInst
, IDS_EVENTLOG_WARNING_TYPE
, eventTypeText
, MAX_LOADSTRING
);
437 case EVENTLOG_INFORMATION_TYPE
:
438 LoadStringW(hInst
, IDS_EVENTLOG_INFORMATION_TYPE
, eventTypeText
, MAX_LOADSTRING
);
440 case EVENTLOG_AUDIT_SUCCESS
:
441 LoadStringW(hInst
, IDS_EVENTLOG_AUDIT_SUCCESS
, eventTypeText
, MAX_LOADSTRING
);
443 case EVENTLOG_AUDIT_FAILURE
:
444 LoadStringW(hInst
, IDS_EVENTLOG_AUDIT_FAILURE
, eventTypeText
, MAX_LOADSTRING
);
446 case EVENTLOG_SUCCESS
:
447 LoadStringW(hInst
, IDS_EVENTLOG_SUCCESS
, eventTypeText
, MAX_LOADSTRING
);
450 LoadStringW(hInst
, IDS_EVENTLOG_UNKNOWN_TYPE
, eventTypeText
, MAX_LOADSTRING
);
456 GetEventUserName(EVENTLOGRECORD
*pelr
,
461 WCHAR szDomain
[1024];
464 DWORD cbDomain
= 1024;
466 /* Point to the SID. */
467 lpSid
= (PSID
)((LPBYTE
)pelr
+ pelr
->UserSidOffset
);
470 if (pelr
->UserSidLength
> 0)
472 if (LookupAccountSidW(NULL
,
480 StringCchCopyW(pszUser
, MAX_PATH
, szName
);
490 ShowStatusMessageThread(IN LPVOID lpParameter
)
492 HWND
*phWnd
= (HWND
*)lpParameter
;
496 hWnd
= CreateDialogParam(hInst
,
497 MAKEINTRESOURCE(IDD_PROGRESSBOX
),
499 StatusMessageWindowProc
,
506 ShowWindow(hWnd
, SW_SHOW
);
508 /* Message loop for the Status window */
509 while (GetMessage(&Msg
, NULL
, 0, 0))
511 TranslateMessage(&Msg
);
512 DispatchMessage(&Msg
);
520 QueryEventMessages(LPWSTR lpMachineName
,
525 EVENTLOGRECORD
*pevlr
;
526 DWORD dwRead
, dwNeeded
, dwThisRecord
, dwTotalRecords
= 0, dwCurrentRecord
= 0, dwRecordsToRead
= 0, dwFlags
, dwMaxLength
;
529 LPWSTR lpComputerName
;
531 BOOL bResult
= TRUE
; /* Read succeeded. */
533 WCHAR szWindowTitle
[MAX_PATH
];
534 WCHAR szStatusText
[MAX_PATH
];
535 WCHAR szLocalDate
[MAX_PATH
];
536 WCHAR szLocalTime
[MAX_PATH
];
537 WCHAR szEventID
[MAX_PATH
];
538 WCHAR szEventTypeText
[MAX_LOADSTRING
];
539 WCHAR szCategoryID
[MAX_PATH
];
540 WCHAR szUsername
[MAX_PATH
];
541 WCHAR szEventText
[EVENT_MESSAGE_FILE_BUFFER
];
542 WCHAR szCategory
[MAX_PATH
];
543 WCHAR szData
[MAX_PATH
];
544 PWCHAR lpTitleTemplateEnd
;
547 LVITEMW lviEventItem
;
549 dwFlags
= EVENTLOG_FORWARDS_READ
| EVENTLOG_SEQUENTIAL_READ
;
551 /* Open the event log. */
552 hEventLog
= OpenEventLogW(lpMachineName
,
554 if (hEventLog
== NULL
)
556 ShowLastWin32Error();
560 lpSourceLogName
= lpLogName
;
561 lpComputerName
= lpMachineName
;
563 /* Disable listview redraw */
564 SendMessage(hwndListView
, WM_SETREDRAW
, FALSE
, 0);
566 /* Clear the list view */
567 (void)ListView_DeleteAllItems (hwndListView
);
570 GetOldestEventLogRecord(hEventLog
, &dwThisRecord
);
572 /* Get the total number of event log records. */
573 GetNumberOfEventLogRecords (hEventLog
, &dwTotalRecords
);
574 g_TotalRecords
= dwTotalRecords
;
576 if (dwTotalRecords
> 0)
578 EnableMenuItem(hMainMenu
, ID_CLEAR_EVENTS
, MF_BYCOMMAND
| MF_ENABLED
);
579 EnableMenuItem(hMainMenu
, ID_SAVE_PROTOCOL
, MF_BYCOMMAND
| MF_ENABLED
);
583 EnableMenuItem(hMainMenu
, ID_CLEAR_EVENTS
, MF_BYCOMMAND
| MF_GRAYED
);
584 EnableMenuItem(hMainMenu
, ID_SAVE_PROTOCOL
, MF_BYCOMMAND
| MF_GRAYED
);
587 g_RecordPtrs
= HeapAlloc(GetProcessHeap(), HEAP_ZERO_MEMORY
, dwTotalRecords
* sizeof(PVOID
));
589 /* If we have at least 1000 records show the waiting dialog */
590 if (dwTotalRecords
> 1000)
592 CloseHandle(CreateThread(NULL
,
594 ShowStatusMessageThread
,
600 while (dwCurrentRecord
< dwTotalRecords
)
602 pevlr
= HeapAlloc(GetProcessHeap(), 0, sizeof(EVENTLOGRECORD
));
603 g_RecordPtrs
[dwCurrentRecord
] = pevlr
;
605 bResult
= ReadEventLog(hEventLog
, // Event log handle
606 dwFlags
, // Sequential read
607 0, // Ignored for sequential read
608 pevlr
, // Pointer to buffer
609 sizeof(EVENTLOGRECORD
), // Size of buffer
610 &dwRead
, // Number of bytes read
611 &dwNeeded
); // Bytes in the next record
612 if((!bResult
) && (GetLastError () == ERROR_INSUFFICIENT_BUFFER
))
614 HeapFree(GetProcessHeap(), 0, pevlr
);
615 pevlr
= HeapAlloc(GetProcessHeap(), 0, dwNeeded
);
616 g_RecordPtrs
[dwCurrentRecord
] = pevlr
;
618 ReadEventLogW(hEventLog
, // event log handle
619 dwFlags
, // read flags
620 0, // offset; default is 0
621 pevlr
, // pointer to buffer
622 dwNeeded
, // size of buffer
623 &dwRead
, // number of bytes read
624 &dwNeeded
); // bytes in next record
629 LoadStringW(hInst
, IDS_NOT_AVAILABLE
, szUsername
, MAX_PATH
);
630 LoadStringW(hInst
, IDS_NOT_AVAILABLE
, szEventText
, MAX_PATH
);
631 LoadStringW(hInst
, IDS_NONE
, szCategory
, MAX_PATH
);
633 // Get the event source name.
634 lpSourceName
= (LPWSTR
)((LPBYTE
)pevlr
+ sizeof(EVENTLOGRECORD
));
636 // Get the computer name
637 lpComputerName
= (LPWSTR
)((LPBYTE
)pevlr
+ sizeof(EVENTLOGRECORD
) + (wcslen(lpSourceName
) + 1) * sizeof(WCHAR
));
639 // This ist the data section of the current event
640 lpData
= (LPSTR
)((LPBYTE
)pevlr
+ pevlr
->DataOffset
);
642 // Compute the event type
643 EventTimeToSystemTime(pevlr
->TimeWritten
, &time
);
645 // Get the username that generated the event
646 GetEventUserName(pevlr
, szUsername
);
648 GetDateFormatW(LOCALE_USER_DEFAULT
, DATE_SHORTDATE
, &time
, NULL
, szLocalDate
, MAX_PATH
);
649 GetTimeFormatW(LOCALE_USER_DEFAULT
, TIME_NOSECONDS
, &time
, NULL
, szLocalTime
, MAX_PATH
);
651 GetEventType(pevlr
->EventType
, szEventTypeText
);
652 GetEventCategory(lpLogName
, lpSourceName
, pevlr
, szCategory
);
654 StringCbPrintfW(szEventID
, sizeof(szEventID
), L
"%u", (pevlr
->EventID
& 0xFFFF));
655 StringCbPrintfW(szCategoryID
, sizeof(szCategoryID
), L
"%u", pevlr
->EventCategory
);
657 lviEventItem
.mask
= LVIF_IMAGE
| LVIF_TEXT
| LVIF_PARAM
;
658 lviEventItem
.iItem
= 0;
659 lviEventItem
.iSubItem
= 0;
660 lviEventItem
.lParam
= (LPARAM
)pevlr
;
661 lviEventItem
.pszText
= szEventTypeText
;
663 switch (pevlr
->EventType
)
665 case EVENTLOG_ERROR_TYPE
:
666 lviEventItem
.iImage
= 2;
669 case EVENTLOG_AUDIT_FAILURE
:
670 lviEventItem
.iImage
= 2;
673 case EVENTLOG_WARNING_TYPE
:
674 lviEventItem
.iImage
= 1;
677 case EVENTLOG_INFORMATION_TYPE
:
678 lviEventItem
.iImage
= 0;
681 case EVENTLOG_AUDIT_SUCCESS
:
682 lviEventItem
.iImage
= 0;
685 case EVENTLOG_SUCCESS
:
686 lviEventItem
.iImage
= 0;
690 lviEventItem
.iItem
= ListView_InsertItem(hwndListView
, &lviEventItem
);
692 ListView_SetItemText(hwndListView
, lviEventItem
.iItem
, 1, szLocalDate
);
693 ListView_SetItemText(hwndListView
, lviEventItem
.iItem
, 2, szLocalTime
);
694 ListView_SetItemText(hwndListView
, lviEventItem
.iItem
, 3, lpSourceName
);
695 ListView_SetItemText(hwndListView
, lviEventItem
.iItem
, 4, szCategory
);
696 ListView_SetItemText(hwndListView
, lviEventItem
.iItem
, 5, szEventID
);
697 ListView_SetItemText(hwndListView
, lviEventItem
.iItem
, 6, szUsername
); //User
698 ListView_SetItemText(hwndListView
, lviEventItem
.iItem
, 7, lpComputerName
); //Computer
699 MultiByteToWideChar(CP_ACP
,
705 ListView_SetItemText(hwndListView
, lviEventItem
.iItem
, 8, szData
); //Event Text
707 dwRead
-= pevlr
->Length
;
708 pevlr
= (EVENTLOGRECORD
*)((LPBYTE
) pevlr
+ pevlr
->Length
);
717 EndDialog(hwndDlg
, 0);
719 StringCchPrintfExW(szWindowTitle
,
720 sizeof(szWindowTitle
) / sizeof(WCHAR
),
724 szTitleTemplate
, szTitle
, lpLogName
); /* i = number of characters written */
725 /* lpComputerName can be NULL here if no records was read */
726 dwMaxLength
= cchRemaining
;
728 GetComputerNameW(lpTitleTemplateEnd
, &dwMaxLength
);
730 StringCchCopyW(lpTitleTemplateEnd
, dwMaxLength
, lpComputerName
);
732 StringCbPrintfW(szStatusText
, sizeof(szStatusText
), szStatusBarTemplate
, lpLogName
, dwTotalRecords
);
734 // Update the status bar
735 SendMessageW(hwndStatus
, SB_SETTEXT
, (WPARAM
)0, (LPARAM
)szStatusText
);
737 // Set the window title
738 SetWindowTextW(hwndMainWindow
, szWindowTitle
);
740 // Resume list view redraw
741 SendMessageW(hwndListView
, WM_SETREDRAW
, TRUE
, 0);
743 // Close the event log.
744 CloseEventLog(hEventLog
);
754 WCHAR szFileName
[MAX_PATH
];
756 ZeroMemory(szFileName
, sizeof(szFileName
));
758 sfn
.lpstrFile
= szFileName
;
759 sfn
.nMaxFile
= MAX_PATH
;
761 if (!GetSaveFileNameW(&sfn
))
766 hEventLog
= OpenEventLogW(lpComputerName
, lpSourceLogName
);
769 ShowLastWin32Error();
773 if (!BackupEventLogW(hEventLog
, szFileName
))
775 ShowLastWin32Error();
778 CloseEventLog(hEventLog
);
786 WCHAR szFileName
[MAX_PATH
];
787 WCHAR szMessage
[MAX_LOADSTRING
];
789 ZeroMemory(szFileName
, sizeof(szFileName
));
790 ZeroMemory(szMessage
, sizeof(szMessage
));
792 LoadStringW(hInst
, IDS_CLEAREVENTS_MSG
, szMessage
, MAX_LOADSTRING
);
794 sfn
.lpstrFile
= szFileName
;
795 sfn
.nMaxFile
= MAX_PATH
;
797 switch (MessageBoxW(hwndMainWindow
, szMessage
, szTitle
, MB_YESNOCANCEL
| MB_ICONINFORMATION
))
806 sfn
.lpstrFile
= NULL
;
812 if (!GetSaveFileNameW(&sfn
))
820 hEventLog
= OpenEventLogW(lpComputerName
, lpSourceLogName
);
823 ShowLastWin32Error();
827 if (!ClearEventLogW(hEventLog
, sfn
.lpstrFile
))
829 ShowLastWin32Error();
830 CloseEventLog(hEventLog
);
834 CloseEventLog(hEventLog
);
843 QueryEventMessages(lpComputerName
,
849 MyRegisterClass(HINSTANCE hInstance
)
853 wcex
.cbSize
= sizeof(WNDCLASSEX
);
856 wcex
.lpfnWndProc
= WndProc
;
859 wcex
.hInstance
= hInstance
;
860 wcex
.hIcon
= LoadIcon(hInstance
, MAKEINTRESOURCE(IDI_EVENTVWR
));
861 wcex
.hCursor
= LoadCursor(NULL
, IDC_ARROW
);
862 wcex
.hbrBackground
= (HBRUSH
)(COLOR_WINDOW
+ 1);
863 wcex
.lpszMenuName
= MAKEINTRESOURCE(IDC_EVENTVWR
);
864 wcex
.lpszClassName
= szWindowClass
;
865 wcex
.hIconSm
= LoadIcon(wcex
.hInstance
, MAKEINTRESOURCE(IDI_SMALL
));
867 return RegisterClassExW(&wcex
);
872 GetDisplayNameFile(IN LPCWSTR lpLogName
,
873 OUT PWCHAR lpModuleName
)
877 WCHAR szModuleName
[MAX_PATH
];
881 cbKeyPath
= (wcslen(EVENTLOG_BASE_KEY
) + wcslen(lpLogName
) + 1) * sizeof(WCHAR
);
882 KeyPath
= HeapAlloc(GetProcessHeap(), 0, cbKeyPath
);
888 StringCbCopyW(KeyPath
, cbKeyPath
, EVENTLOG_BASE_KEY
);
889 StringCbCatW(KeyPath
, cbKeyPath
, lpLogName
);
891 if (RegOpenKeyExW(HKEY_LOCAL_MACHINE
, KeyPath
, 0, KEY_READ
, &hKey
) != ERROR_SUCCESS
)
893 HeapFree(GetProcessHeap(), 0, KeyPath
);
897 cbData
= sizeof(szModuleName
);
898 if (RegQueryValueExW(hKey
, L
"DisplayNameFile", NULL
, NULL
, (LPBYTE
)szModuleName
, &cbData
) == ERROR_SUCCESS
)
900 ExpandEnvironmentStringsW(szModuleName
, lpModuleName
, MAX_PATH
);
904 HeapFree(GetProcessHeap(), 0, KeyPath
);
909 GetDisplayNameID(IN LPCWSTR lpLogName
)
913 DWORD dwMessageID
= 0;
917 cbKeyPath
= (wcslen(EVENTLOG_BASE_KEY
) + wcslen(lpLogName
) + 1) * sizeof(WCHAR
);
918 KeyPath
= HeapAlloc(GetProcessHeap(), 0, cbKeyPath
);
924 StringCbCopyW(KeyPath
, cbKeyPath
, EVENTLOG_BASE_KEY
);
925 StringCbCatW(KeyPath
, cbKeyPath
, lpLogName
);
927 if (RegOpenKeyExW(HKEY_LOCAL_MACHINE
, KeyPath
, 0, KEY_READ
, &hKey
) != ERROR_SUCCESS
)
929 HeapFree(GetProcessHeap(), 0, KeyPath
);
933 cbData
= sizeof(dwMessageID
);
934 RegQueryValueExW(hKey
, L
"DisplayNameID", NULL
, NULL
, (LPBYTE
)&dwMessageID
, &cbData
);
937 HeapFree(GetProcessHeap(), 0, KeyPath
);
950 DWORD dwMaxKeyLength
;
951 WCHAR szModuleName
[MAX_PATH
];
952 LPWSTR lpDisplayName
;
953 HANDLE hLibrary
= NULL
;
955 if (RegOpenKeyExW(HKEY_LOCAL_MACHINE
, EVENTLOG_BASE_KEY
, 0, KEY_READ
, &hKey
) != ERROR_SUCCESS
)
960 if (RegQueryInfoKeyW(hKey
, NULL
, NULL
, NULL
, &dwNumLogs
, &dwMaxKeyLength
, NULL
, NULL
, NULL
, NULL
, NULL
, NULL
) != ERROR_SUCCESS
)
972 LogNames
= HeapAlloc(GetProcessHeap(), 0, (dwNumLogs
+ 1) * sizeof(WCHAR
*));
980 for (dwIndex
= 0; dwIndex
< dwNumLogs
; dwIndex
++)
982 LogNames
[dwIndex
] = HeapAlloc(GetProcessHeap(), HEAP_ZERO_MEMORY
, ((dwMaxKeyLength
+ 1) * sizeof(WCHAR
)));
984 if (LogNames
[dwIndex
] != NULL
)
986 lpcName
= dwMaxKeyLength
+ 1;
988 if (RegEnumKeyExW(hKey
, dwIndex
, LogNames
[dwIndex
], &lpcName
, NULL
, NULL
, NULL
, NULL
) == ERROR_SUCCESS
)
990 lpDisplayName
= NULL
;
992 ZeroMemory(szModuleName
, sizeof(szModuleName
));
993 GetDisplayNameFile(LogNames
[dwIndex
], szModuleName
);
994 dwMessageID
= GetDisplayNameID(LogNames
[dwIndex
]);
996 hLibrary
= LoadLibraryExW(szModuleName
, NULL
, DONT_RESOLVE_DLL_REFERENCES
| LOAD_LIBRARY_AS_DATAFILE
);
997 if (hLibrary
!= NULL
)
999 FormatMessageW(FORMAT_MESSAGE_ALLOCATE_BUFFER
| FORMAT_MESSAGE_FROM_HMODULE
, hLibrary
, dwMessageID
, 0, (LPWSTR
)&lpDisplayName
, 0, NULL
);
1000 FreeLibrary(hLibrary
);
1005 InsertMenuW(hMainMenu
, ID_SAVE_PROTOCOL
, MF_BYCOMMAND
| MF_STRING
, ID_FIRST_LOG
+ dwIndex
, lpDisplayName
);
1009 InsertMenuW(hMainMenu
, ID_SAVE_PROTOCOL
, MF_BYCOMMAND
| MF_STRING
, ID_FIRST_LOG
+ dwIndex
, LogNames
[dwIndex
]);
1012 LocalFree(lpDisplayName
);
1017 InsertMenuW(hMainMenu
, ID_SAVE_PROTOCOL
, MF_BYCOMMAND
| MF_SEPARATOR
, ID_FIRST_LOG
+ dwIndex
+ 1, NULL
);
1035 for (dwIndex
= 0; dwIndex
< dwNumLogs
; dwIndex
++)
1037 if (LogNames
[dwIndex
])
1039 HeapFree(GetProcessHeap(), 0, LogNames
[dwIndex
]);
1042 DeleteMenu(hMainMenu
, ID_FIRST_LOG
+ dwIndex
, MF_BYCOMMAND
);
1045 DeleteMenu(hMainMenu
, ID_FIRST_LOG
+ dwIndex
+ 1, MF_BYCOMMAND
);
1047 HeapFree(GetProcessHeap(), 0, LogNames
);
1056 InitInstance(HINSTANCE hInstance
,
1060 LVCOLUMNW lvc
= {0};
1063 hInst
= hInstance
; // Store instance handle in our global variable
1065 hwndMainWindow
= CreateWindowW(szWindowClass
,
1067 WS_OVERLAPPEDWINDOW
| WS_CLIPCHILDREN
,
1068 CW_USEDEFAULT
, 0, CW_USEDEFAULT
, 0,
1073 if (!hwndMainWindow
)
1078 hwndStatus
= CreateWindowExW(0, // no extended styles
1079 STATUSCLASSNAMEW
, // status bar
1080 L
"Done.", // no text
1081 WS_CHILD
| WS_BORDER
| WS_VISIBLE
, // styles
1082 0, 0, 0, 0, // x, y, cx, cy
1083 hwndMainWindow
, // parent window
1084 (HMENU
)100, // window ID
1085 hInstance
, // instance
1086 NULL
); // window data
1088 // Create our listview child window. Note that I use WS_EX_CLIENTEDGE
1089 // and WS_BORDER to create the normal "sunken" look. Also note that
1090 // LVS_EX_ styles cannot be set in CreateWindowEx().
1091 hwndListView
= CreateWindowExW(WS_EX_CLIENTEDGE
,
1094 LVS_SHOWSELALWAYS
| WS_CHILD
| WS_VISIBLE
| LVS_REPORT
,
1104 // After the ListView is created, we can add extended list view styles.
1105 (void)ListView_SetExtendedListViewStyle (hwndListView
, LVS_EX_FULLROWSELECT
);
1107 // Create the ImageList
1108 hSmall
= ImageList_Create(GetSystemMetrics(SM_CXSMICON
),
1109 GetSystemMetrics(SM_CYSMICON
),
1114 // Add event type icons to ImageList
1115 ImageList_AddIcon (hSmall
, LoadIcon(hInstance
, MAKEINTRESOURCE(IDI_INFORMATIONICON
)));
1116 ImageList_AddIcon (hSmall
, LoadIcon(hInstance
, MAKEINTRESOURCE(IDI_WARNINGICON
)));
1117 ImageList_AddIcon (hSmall
, LoadIcon(hInstance
, MAKEINTRESOURCE(IDI_ERRORICON
)));
1119 // Assign ImageList to List View
1120 (void)ListView_SetImageList (hwndListView
, hSmall
, LVSIL_SMALL
);
1122 // Now set up the listview with its columns.
1123 lvc
.mask
= LVCF_TEXT
| LVCF_WIDTH
;
1125 LoadStringW(hInstance
,
1128 sizeof(szTemp
) / sizeof(WCHAR
));
1129 lvc
.pszText
= szTemp
;
1130 (void)ListView_InsertColumn(hwndListView
, 0, &lvc
);
1133 LoadStringW(hInstance
,
1136 sizeof(szTemp
) / sizeof(WCHAR
));
1137 lvc
.pszText
= szTemp
;
1138 (void)ListView_InsertColumn(hwndListView
, 1, &lvc
);
1141 LoadStringW(hInstance
,
1144 sizeof(szTemp
) / sizeof(WCHAR
));
1145 lvc
.pszText
= szTemp
;
1146 (void)ListView_InsertColumn(hwndListView
, 2, &lvc
);
1149 LoadStringW(hInstance
,
1152 sizeof(szTemp
) / sizeof(WCHAR
));
1153 lvc
.pszText
= szTemp
;
1154 (void)ListView_InsertColumn(hwndListView
, 3, &lvc
);
1157 LoadStringW(hInstance
,
1160 sizeof(szTemp
) / sizeof(WCHAR
));
1161 lvc
.pszText
= szTemp
;
1162 (void)ListView_InsertColumn(hwndListView
, 4, &lvc
);
1165 LoadStringW(hInstance
,
1168 sizeof(szTemp
) / sizeof(WCHAR
));
1169 lvc
.pszText
= szTemp
;
1170 (void)ListView_InsertColumn(hwndListView
, 5, &lvc
);
1173 LoadStringW(hInstance
,
1176 sizeof(szTemp
) / sizeof(WCHAR
));
1177 lvc
.pszText
= szTemp
;
1178 (void)ListView_InsertColumn(hwndListView
, 6, &lvc
);
1181 LoadStringW(hInstance
,
1184 sizeof(szTemp
) / sizeof(WCHAR
));
1185 lvc
.pszText
= szTemp
;
1186 (void)ListView_InsertColumn(hwndListView
, 7, &lvc
);
1189 LoadStringW(hInstance
,
1190 IDS_COLUMNEVENTDATA
,
1192 sizeof(szTemp
) / sizeof(WCHAR
));
1193 lvc
.pszText
= szTemp
;
1194 (void)ListView_InsertColumn(hwndListView
, 8, &lvc
);
1196 // Initialize the save Dialog
1197 ZeroMemory(&sfn
, sizeof(sfn
));
1198 ZeroMemory(szSaveFilter
, sizeof(szSaveFilter
));
1200 LoadStringW(hInst
, IDS_SAVE_FILTER
, szSaveFilter
, MAX_LOADSTRING
);
1202 sfn
.lStructSize
= sizeof(sfn
);
1203 sfn
.hwndOwner
= hwndMainWindow
;
1204 sfn
.hInstance
= hInstance
;
1205 sfn
.lpstrFilter
= szSaveFilter
;
1206 sfn
.lpstrInitialDir
= NULL
;
1207 sfn
.Flags
= OFN_HIDEREADONLY
| OFN_SHAREAWARE
;
1208 sfn
.lpstrDefExt
= NULL
;
1210 ShowWindow(hwndMainWindow
, nCmdShow
);
1211 UpdateWindow(hwndMainWindow
);
1215 QueryEventMessages(lpComputerName
, LogNames
[0]);
1217 CheckMenuRadioItem(GetMenu(hwndMainWindow
), ID_FIRST_LOG
, ID_FIRST_LOG
+ dwNumLogs
, ID_FIRST_LOG
, MF_BYCOMMAND
);
1224 WndProc(HWND hWnd
, UINT message
, WPARAM wParam
, LPARAM lParam
)
1232 hMainMenu
= GetMenu(hWnd
);
1236 switch (((LPNMHDR
)lParam
)->code
)
1239 hdr
= (NMHDR FAR
*)lParam
;
1240 if (hdr
->hwndFrom
== hwndListView
)
1242 LPNMITEMACTIVATE lpnmitem
= (LPNMITEMACTIVATE
)lParam
;
1244 if (lpnmitem
->iItem
!= -1)
1247 MAKEINTRESOURCE(IDD_EVENTDETAILDIALOG
),
1257 // Parse the menu selections:
1259 if ((LOWORD(wParam
) >= ID_FIRST_LOG
) && (LOWORD(wParam
) <= ID_FIRST_LOG
+ dwNumLogs
))
1261 if (LogNames
[LOWORD(wParam
) - ID_FIRST_LOG
])
1263 if (QueryEventMessages(lpComputerName
, LogNames
[LOWORD(wParam
) - ID_FIRST_LOG
]))
1265 CheckMenuRadioItem(GetMenu(hWnd
), ID_FIRST_LOG
, ID_FIRST_LOG
+ dwNumLogs
, LOWORD(wParam
), MF_BYCOMMAND
);
1271 switch (LOWORD(wParam
))
1273 case ID_SAVE_PROTOCOL
:
1277 case ID_CLEAR_EVENTS
:
1289 DialogBox(hInst
, MAKEINTRESOURCE(IDD_ABOUTBOX
), hWnd
, About
);
1293 MessageBoxW(hwndMainWindow
,
1294 L
"Help not implemented yet!",
1296 MB_OK
| MB_ICONINFORMATION
);
1300 DestroyWindow(hWnd
);
1304 return DefWindowProc(hWnd
, message
, wParam
, lParam
);
1310 // Gets the window rectangle
1311 GetClientRect(hWnd
, &rect
);
1313 // Relocate the listview
1314 MoveWindow(hwndListView
,
1321 // Resize the statusbar;
1322 SendMessage(hwndStatus
, message
, wParam
, lParam
);
1332 return DefWindowProc(hWnd
, message
, wParam
, lParam
);
1339 // Message handler for about box.
1341 About(HWND hDlg
, UINT message
, WPARAM wParam
, LPARAM lParam
)
1343 UNREFERENCED_PARAMETER(lParam
);
1348 return (INT_PTR
)TRUE
;
1352 if (LOWORD(wParam
) == IDOK
|| LOWORD(wParam
) == IDCANCEL
)
1354 EndDialog(hDlg
, LOWORD(wParam
));
1355 return (INT_PTR
)TRUE
;
1360 return (INT_PTR
)FALSE
;
1364 DisplayEvent(HWND hDlg
)
1366 WCHAR szEventType
[MAX_PATH
];
1367 WCHAR szTime
[MAX_PATH
];
1368 WCHAR szDate
[MAX_PATH
];
1369 WCHAR szUser
[MAX_PATH
];
1370 WCHAR szComputer
[MAX_PATH
];
1371 WCHAR szSource
[MAX_PATH
];
1372 WCHAR szCategory
[MAX_PATH
];
1373 WCHAR szEventID
[MAX_PATH
];
1374 WCHAR szEventText
[EVENT_MESSAGE_EVENTTEXT_BUFFER
];
1375 WCHAR szEventData
[MAX_PATH
];
1376 BOOL bEventData
= FALSE
;
1378 EVENTLOGRECORD
* pevlr
;
1381 // Get index of selected item
1382 iIndex
= (int)SendMessage (hwndListView
, LVM_GETNEXTITEM
, -1, LVNI_SELECTED
| LVNI_FOCUSED
);
1384 li
.mask
= LVIF_PARAM
;
1388 (void)ListView_GetItem(hwndListView
, &li
);
1390 pevlr
= (EVENTLOGRECORD
*)li
.lParam
;
1394 ListView_GetItemText(hwndListView
, iIndex
, 0, szEventType
, sizeof(szEventType
) / sizeof(WCHAR
));
1395 ListView_GetItemText(hwndListView
, iIndex
, 1, szDate
, sizeof(szDate
) / sizeof(WCHAR
));
1396 ListView_GetItemText(hwndListView
, iIndex
, 2, szTime
, sizeof(szTime
) / sizeof(WCHAR
));
1397 ListView_GetItemText(hwndListView
, iIndex
, 3, szSource
, sizeof(szSource
) / sizeof(WCHAR
));
1398 ListView_GetItemText(hwndListView
, iIndex
, 4, szCategory
, sizeof(szCategory
) / sizeof(WCHAR
));
1399 ListView_GetItemText(hwndListView
, iIndex
, 5, szEventID
, sizeof(szEventID
) / sizeof(WCHAR
));
1400 ListView_GetItemText(hwndListView
, iIndex
, 6, szUser
, sizeof(szUser
) / sizeof(WCHAR
));
1401 ListView_GetItemText(hwndListView
, iIndex
, 7, szComputer
, sizeof(szComputer
) / sizeof(WCHAR
));
1403 bEventData
= !(pevlr
->DataLength
== 0);
1405 if (pevlr
->DataLength
> 0)
1407 MultiByteToWideChar(CP_ACP
,
1409 (LPCSTR
)((LPBYTE
)pevlr
+ pevlr
->DataOffset
),
1415 GetEventMessage(lpSourceLogName
, szSource
, pevlr
, szEventText
);
1417 EnableWindow(GetDlgItem(hDlg
, IDC_BYTESRADIO
), bEventData
);
1418 EnableWindow(GetDlgItem(hDlg
, IDC_WORDRADIO
), bEventData
);
1420 SetDlgItemTextW(hDlg
, IDC_EVENTDATESTATIC
, szDate
);
1421 SetDlgItemTextW(hDlg
, IDC_EVENTTIMESTATIC
, szTime
);
1423 SetDlgItemTextW(hDlg
, IDC_EVENTUSERSTATIC
, szUser
);
1424 SetDlgItemTextW(hDlg
, IDC_EVENTSOURCESTATIC
, szSource
);
1425 SetDlgItemTextW(hDlg
, IDC_EVENTCOMPUTERSTATIC
, szComputer
);
1426 SetDlgItemTextW(hDlg
, IDC_EVENTCATEGORYSTATIC
, szCategory
);
1427 SetDlgItemTextW(hDlg
, IDC_EVENTIDSTATIC
, szEventID
);
1428 SetDlgItemTextW(hDlg
, IDC_EVENTTYPESTATIC
, szEventType
);
1429 SetDlgItemTextW(hDlg
, IDC_EVENTTEXTEDIT
, szEventText
);
1430 SetDlgItemTextW(hDlg
, IDC_EVENTDATAEDIT
, szEventData
);
1435 L
"No Items in ListView",
1437 MB_OK
| MB_ICONINFORMATION
);
1444 StatusMessageWindowProc(IN HWND hwndDlg
,
1449 UNREFERENCED_PARAMETER(wParam
);
1462 // Message handler for event details box.
1464 EventDetails(HWND hDlg
, UINT message
, WPARAM wParam
, LPARAM lParam
)
1466 UNREFERENCED_PARAMETER(lParam
);
1471 // Show event info on dialog box
1473 return (INT_PTR
)TRUE
;
1476 switch (LOWORD(wParam
))
1480 EndDialog(hDlg
, LOWORD(wParam
));
1481 return (INT_PTR
)TRUE
;
1484 SendMessage(hwndListView
, WM_KEYDOWN
, VK_UP
, 0);
1486 // Show event info on dialog box
1488 return (INT_PTR
)TRUE
;
1491 SendMessage(hwndListView
, WM_KEYDOWN
, VK_DOWN
, 0);
1493 // Show event info on dialog box
1495 return (INT_PTR
)TRUE
;
1497 case IDC_BYTESRADIO
:
1498 return (INT_PTR
)TRUE
;
1501 return (INT_PTR
)TRUE
;
1505 L
"Help not implemented yet!",
1507 MB_OK
| MB_ICONINFORMATION
);
1508 return (INT_PTR
)TRUE
;
1516 return (INT_PTR
)FALSE
;