Query the event with the ``ids`` or perform a query with the raw query ``filter`` Both parameters are mutually exclusive. .. note:: Here are some query examples List all events with a event data attribute named 'RuleName': ``Event/EventData/Data[@Name='
(self, filter=None, ids=None, timeout=None)
| 439 | self.classic_event_metadata_by_id = {} # For classic only |
| 440 | |
| 441 | def query(self, filter=None, ids=None, timeout=None): |
| 442 | """Query the event with the ``ids`` or perform a query with the raw query ``filter`` |
| 443 | |
| 444 | Both parameters are mutually exclusive. |
| 445 | |
| 446 | .. note:: Here are some query examples |
| 447 | |
| 448 | List all events with a event data attribute named 'RuleName': |
| 449 | ``Event/EventData/Data[@Name='RuleName']`` |
| 450 | |
| 451 | List all events with a event data value of 'C:\\\\WINDOWS\\\\System32\\\\svchost.exe': |
| 452 | ``Event/EventData[Data='C:\\WINDOWS\\System32\\svchost.exe']`` |
| 453 | |
| 454 | List all events with an EventID of 2006: |
| 455 | ``Event/System[EventID=2006]`` |
| 456 | |
| 457 | List all event with a given EventID while searching for a specific field value (Sysmon for the test here) |
| 458 | ``Event/System[EventID=3] and Event/EventData/Data[@Name='DestinationIp'] and Event/EventData[Data='10.0.0.2']`` |
| 459 | |
| 460 | :rtype: :class:`EvtQuery` |
| 461 | """ |
| 462 | if ids and filter: |
| 463 | raise ValueError("<ids> and <filter> are mutually exclusive") |
| 464 | if ids is not None: |
| 465 | if isinstance(ids, int_types): |
| 466 | ids = (ids,) |
| 467 | ids_filter = " or ".join("EventID={0}".format(id) for id in ids) |
| 468 | filter = "Event/System[{0}]".format(ids_filter) |
| 469 | query_handle = winproxy.EvtQuery(None, self.name, filter, self.DEFAULT_QUERY_FLAGS) |
| 470 | return EvtQuery(query_handle, self, timeout=timeout) |
| 471 | |
| 472 | @property |
| 473 | def events(self): |