Know Before You GO – Target Settings

When adding a Target to a session, a configurable setting may or may not be obviously available for use with the Target. In and of itself, this can be mildly frustrating if the wrong settings are tried with the wrong Target. More frustrating is that some settings are required. While the required setting may be logically deduced, it does not always work out that way.

Reading Session Data from Memory

In this article, I introduce the topic of reading session data from memory along with some of the pitfalls and some words of caution.

Better Practices for Reading Event_file Targets

In this article, I am going to address some better practices for Reading Event_file targets attached to an XEvent Session.

Dynamically Read event_file Data

There needs to be a more efficient means of grabbing the file without having to know the location. Knowing the session name should be adequate enough to parse the payload data from the target. This is exactly what I am going to show in this article – retrieving the file and path based strictly on the name of the session.

Auditing Needs Reporting

No matter the mechanism used to capture the data to fulfill the “investigation” phase of the audit, if the data is not analyzed and reports generated, then the audit did not happen. With that in mind, I settled on a quick intro in how to get the audit data in order to generate reports.