idZddlZddlZddlZddlZejZejejejZ d dZ d dZ dej dddfdZ d dZd dZ d d ZdS)z0Event Log Utilities - helper for win32evtlog.pydN Applicationc| tj}tjtjd|d|}tj|ddtj||&tjtj ztj z}tj|ddtj ||dkrR| tj}tj|ddtj|tj|ddtj |tj |dS) a&Add a source of messages to the event log. Allows Python program to register a custom source of messages in the registry. You must also provide the DLL name that has the message table, so the full message text appears in the event log. Note that the win32evtlog.pyd file has a number of string entries with just "%1" built in, so many Python programs can simply use this DLL. Disadvantages are that you do not get language translation, and the full text is stored in the event log, blowing the size of the log up. N+SYSTEM\CurrentControlSet\Services\EventLog\\EventMessageFilerTypesSupportedCategoryMessageFile CategoryCount) win32evtlog__file__win32api RegCreateKeywin32conHKEY_LOCAL_MACHINE RegSetValueEx REG_EXPAND_SZEVENTLOG_ERROR_TYPEEVENTLOG_WARNING_TYPEEVENTLOG_INFORMATION_TYPE REG_DWORD RegCloseKey)appNamemsgDLL eventLogType eventLogFlags categoryDLL categoryCounthkeys GC:\PYTHON\_runtimes\venv\Lib\site-packages\win32/lib/win32evtlogutil.pyAddSourceToRegistryr s;6~%  #S,SS'SS  D       +/ 03 4      q  %.K  !  "                c tjtjd|d|dS#tj$r!}|jt jkrYd}~dSd}~wwxYw)z0Removes a source of messages from the event log.rrN)r RegDeleteKeyrrerrorwinerrorERROR_FILE_NOT_FOUND)rrexcs rRemoveSourceFromRegistryr(]s  ' Wl W Wg W W      > <88 8 8  9 8 8 8 8 8s%)AAAc tjd|}tj|||||||tj|dS)z4Report an event for a previously added event source.N)r RegisterEventSource ReportEventDeregisterEventSource)reventID eventCategory eventTypestringsdatasidhAppLogs rr+r+ks[-dG<      V$$$$V$$$$ :2sG4D514D&1C,D,DDD5DD5DD55E c|d} t||S#tj$rK|jd}nd|j}dt j|j|j|fzcYSwxYw)zcAs for FormatMessage, except returns an error message if the message can not be processed. Nrr6z, z|) rLr r$rCjoinr% HRESULT_CODErAr8)rErFdescs rSafeFormatMessagerQs ^W555 >     ' /DD99^9::D K%n&<==)     sAA0/A0c |tjtjz}tj||} tj||d}|snt |fd|- tj|dS#tj|wxYw)Nrc||fSN)itemfeeders rz%FeedEventLogRecords..sFFTG,<r!)r EVENTLOG_BACKWARDS_READEVENTLOG_SEQUENTIAL_READ OpenEventLog ReadEventLogmap CloseEventLog)rX machineNamelogName readFlagshobjectss rFeedEventLogRecordsres  /+2V V   g66A% G!.q)Q??G  F<<rjs66  X2H4L M M  NNNNb    "-   ////62222j    0@D%%%%%%r!