我已设置log4net
为我的应用程序使用单独的事件日志。
事件日志存在且可见(记录到该日志甚至用于工作!)
名称为"sbsysrst"
isUat
为true
。
预期LogName为 SB3-UAT 但是它仍然坚持登录 Applicaiton 日志,尽管下面有log4net
调试消息。
返回ILog
对象的方法。
public static ILog GetLogger(string name, bool isUat = false)
{
var eventLogAppender = new EventLogAppender
{
ApplicationName = name,
Layout = new PatternLayout
{
ConversionPattern = "%message%newline%exception"
},
LogName = "SB3" + (isUat ? "-" + UatSuffix : string.Empty),
Threshold = Level.Info
};
BasicConfigurator.Configure(eventLogAppender, FileAppenders[isUat]);
eventLogAppender.ActivateOptions();
return LogManager.GetLogger(name);
}
调试输出表单log4net
log4net: Searched for existing files in [C:\Windows\...]
log4net: curSizeRollBackups starts at [0]
log4net: Opening file for writing [C:\Windows\...\SB3.log] append [True]
log4net: Searched for existing files in [C:\Windows\...]
log4net: curSizeRollBackups starts at [0]
log4net: Opening file for writing [C:\Windows\...\SB3.log] append [True]
log4net: Searched for existing files in [C:\Windows\...UAT]
log4net: curSizeRollBackups starts at [0]
log4net: Opening file for writing [C:\Windows\...UAT\SB3.log] append [True]
log4net: Searched for existing files in [C:\Windows\...UAT]
log4net: curSizeRollBackups starts at [0]
log4net: Opening file for writing [C:\Windows\...UAT\SB3.log] append [True]
log4net: Converter [message] Option [] Format [min=-1,max=2147483647,leftAlign=False]
log4net: Converter [newline] Option [] Format [min=-1,max=2147483647,leftAlign=False]
log4net: Converter [message] Option [] Format [min=-1,max=2147483647,leftAlign=False]
log4net: Converter [newline] Option [] Format [min=-1,max=2147483647,leftAlign=False]
log4net: log4net assembly [log4net, Version=1.2.11.0, Culture=neutral, PublicKeyToken=669e0ddf0bb1aa2a]. Loaded from [...]. (.NET Runtime [2.0.50727.5448] on Microsoft Windows NT 6.1.7601 Service Pack 1)
log4net: defaultRepositoryType [log4net.Repository.Hierarchy.Hierarchy]
log4net: Creating repository for assembly [..., Version=1.0.0.0, Culture=neutral, PublicKeyToken=null]
log4net: Assembly [..., Version=1.0.0.0, Culture=neutral, PublicKeyToken=null] Loaded From [...]
log4net: Assembly [..., Version=1.0.0.0, Culture=neutral, PublicKeyToken=null] does not have a RepositoryAttribute specified.
log4net: Assembly [..., Version=1.0.0.0, Culture=neutral, PublicKeyToken=null] using repository [log4net-default-repository] and repository type [log4net.Repository.Hierarchy.Hierarchy]
log4net: log4net assembly [log4net, Version=1.2.11.0, Culture=neutral, PublicKeyToken=669e0ddf0bb1aa2a]. Loaded from [...]. (.NET Runtime [2.0.50727.5448] on Microsoft Windows NT 6.1.7601 Service Pack 1)
log4net: defaultRepositoryType [log4net.Repository.Hierarchy.Hierarchy]
log4net: Creating repository for assembly [..., Version=1.0.0.0, Culture=neutral, PublicKeyToken=null]
log4net: Assembly [..., Version=1.0.0.0, Culture=neutral, PublicKeyToken=null] Loaded From [...]
log4net: Assembly [..., Version=1.0.0.0, Culture=neutral, PublicKeyToken=null] does not have a RepositoryAttribute specified.
log4net: Assembly [..., Version=1.0.0.0, Culture=neutral, PublicKeyToken=null] using repository [log4net-default-repository] and repository type [log4net.Repository.Hierarchy.Hierarchy]
log4nlog4net: Creating repository [log4net-default-repository] using type [log4net.Repository.Hierarchy.Hierarchy]
et: Creating repository [log4net-default-repository] using type [log4net.Repository.Hierarchy.Hierarchy]
log4net: Changing event source [sbsysrst] from log [SB3] to log [SB3-UAT]
log4net: Source [sbsysrst] is registered to log [SB3-UAT]
log4net: Changing event source [sbsysrst] from log [SB3] to log [SB3-UAT]
log4net: Source [sbsysrst] is registered to log [SB3-UAT]
更新1
查看log4net源代码,代码主要归结为followimg,
// Inside ActivateOptions()
using (SecurityContext.Impersonate(this))
{
sourceAlreadyExists = EventLog.SourceExists(m_applicationName);
if (sourceAlreadyExists)
{
currentLogName = EventLog.LogNameFromSourceName(m_applicationName, m_machineName);
}
}
using (SecurityContext.Impersonate(this))
{
if (sourceAlreadyExists && currentLogName != m_logName)
{
//
// Re-register this to the current application if the user has changed
// the application / logfile association
//
EventLog.DeleteEventSource(m_applicationName, m_machineName);
CreateEventSource(m_applicationName, m_logName, m_machineName);
registeredLogName = EventLog.LogNameFromSourceName(m_applicationName, m_machineName);
}
else if (!sourceAlreadyExists)
{
CreateEventSource(m_applicationName, m_logName, m_machineName);
registeredLogName = EventLog.LogNameFromSourceName(m_applicationName, m_machineName);
}
}
// Inside Append(LoggingEvent loggingEvent)
using(SecurityContext.Impersonate(this))
{
EventLog.WriteEntry(m_applicationName, eventTxt, entryType, eventID, category);
}
关键部分EventLog.LogNameFromSourceName(m_applicationName, m_machineName);
会按预期返回 SB3-UAT 。
更新2
我编写了自己的EventLogAppender
,它通过使用设置为日志和源名称的实例Eventlog
对象来覆盖log4net功能。
令我非常惊讶的是,这也没有用,所以我越来越倾向于机器问题,或者与SecurityContext.Impersonate()
中的log4net
代码有关。
更新3
所以这不是log4net问题,甚至也不是dotnet问题。 下面是直接使用Windows API的代码,但仍然失败。 源名称曾在应用程序日志中注册的事实正在绊倒。
我正在查看相应的WinAPI,看看我是否能解决这个困惑。 当然要查看注册表项, 不 应该是一个问题。
const string SourceName = "sbsysrst";
const string TextMessage = "Test";
const string MachineName = ".";
// This code is essentially the watered down version behind `EventLog`
// in dotnet. There are two main WinAPI calls and just boiler code around
// passing parameters to them as expected.
var message = new[] { TextMessage };
SafeHandle eventLogHandle = null;
var numArray = new IntPtr[message.Length];
var gcHandleArray = new GCHandle[mesage.Length];
GCHandle gcHandle = GCHandle.Alloc(numArray, GCHandleType.Pinned);
try
{
eventLogHandle = SafeEventLogWriteHandle
.RegisterEventSource(MachineName, SourceName);
for (int index = 0; index < message.Length; index++)
{
gcHandleArray[index] = GCHandle
.Alloc(message[index], GCHandleType.Pinned);
numArray[index] = gcHandleArray[index]
.AddrOfPinnedObject();
}
if (!ReportEvent(
eventLogHandle,
0x0004, // Information type
0, // Category
0, // EventID
null, // user id
message.Length, // size of text array
0, // size of raw data array
new HandleRef(this, gcHandle.AddrOfPinnedObject()),
new byte[0])) // raw data (none)
{
throw new Win32Exception(Marshal.GetLastWin32Error());
}
}
finally
{
for (int index = 0; index < message.Length; ++index)
{
if (gcHandleArray[index].IsAllocated)
{
gcHandleArray[index].Free();
}
}
gcHandle.Free();
if (eventLogHandle != null)
{
eventLogHandle.Dispose();
}
}
// RegisterEventSource cannot return an abstract object.
internal sealed class SafeEventLogWriteHandle :
SafeHandleZeroOrMinusOneIsInvalid
{
internal SafeEventLogWriteHandle() : base(true)
{
}
[DllImport("advapi32.dll", CharSet = CharSet.Unicode, SetLastError = true)]
internal static extern SafeEventLogWriteHandle RegisterEventSource(
string uncServerName, string sourceName);
[ReliabilityContract(Consistency.WillNotCorruptState, Cer.Success)]
[DllImport("advapi32.dll", SetLastError = true)]
private static extern bool DeregisterEventSource(IntPtr hEventLog);
protected override bool ReleaseHandle()
{
return DeregisterEventSource(this.handle);
}
}
答案 0 :(得分:2)
问题在于,源名称过去在不同的EventLog下注册。虽然源注册已更改(在注册表中),但似乎EventLog服务缓存了注册。在重新启动计算机并尝试再次登录(无法重新启动Eventlog服务)时,事件条目将进入正确的事件日志。