I want to write a small program to work with the EvtSubscribe function. However, I encountered a problem. Every time the callback function is called, I print a message to the screen and then call Sleep(5000). In this case, I noticed that not all the required events are coming.
Could this cause a problem in the future? For example, could the time spent analyzing the event after it arrives result in some events being missed?
int c = 0;
DWORD WINAPI SubscriptionCallback(EVT_SUBSCRIBE_NOTIFY_ACTION action, PVOID pContext, EVT_HANDLE hEvent)
{
UNREFERENCED_PARAMETER(pContext);
UNREFERENCED_PARAMETER(hEvent);
UNREFERENCED_PARAMETER(action);
printf("%d: Event triggered\n");
Sleep(5000);
return 0;
}
int main(void)
{
EVT_HANDLE hEvt = NULL;
LPCWSTR Channel = L"Security";
LPCWSTR Query = L"Event/System[EventID=1102]";
hEvt = EvtSubscribe(NULL, NULL, Channel, Query, NULL, NULL, (EVT_SUBSCRIBE_CALLBACK)SubscriptionCallback, 1);
if (hEvt == NULL)
{
printf("eRROR %d", GetLastError());
return - 1;
}
while (TRUE)
{
Sleep(1000);
}
I am also running the following Python code to test this.
for i in range(1, 150):
os.system("wevtutil cl Security")
Result:
0: Event triggered
1: Event triggered
Out of 149 events, only 2 arrived. But without the Sleep function, all events arrived. How can I solve this problem in another way? Maybe I should read all the events every minute within the loop?