When adding a Target to a session, a configurable setting may or may not be obviously available for use with the Target. In and of itself, this can be mildly frustrating if the wrong settings are tried with the wrong Target. More frustrating is that some settings are required. While the required setting may be logically deduced, it does not always work out that way.
Reading Session Data from Memory
In this article, I introduce the topic of reading session data from memory along with some of the pitfalls and some words of caution.
Better Practices for Reading Event_file Targets
In this article, I am going to address some better practices for Reading Event_file targets attached to an XEvent Session.
Dynamically Read event_file Data
There needs to be a more efficient means of grabbing the file without having to know the location. Knowing the session name should be adequate enough to parse the payload data from the target. This is exactly what I am going to show in this article – retrieving the file and path based strictly on the name of the session.
Auditing Needs Reporting
No matter the mechanism used to capture the data to fulfill the “investigation” phase of the audit, if the data is not analyzed and reports generated, then the audit did not happen. With that in mind, I settled on a quick intro in how to get the audit data in order to generate reports.