PowerShell Kieran Jacobsen PowerShell Kieran Jacobsen

[Updated Module] Posh-SYSLOG v4.1.5 has been released

A new version of the [Posh-SYSLOG](https://github.com/poshsecurity/AzurePublicIPAddresses/) module has been released. The purpose of this update is to provide better support when running on PowerShell Core.

A new version of the Posh-SYSLOG module has been released.

The purpose of this update is to provide better support when running on PowerShell Core. This module removes the dependencies on Get-CIMInstance that isn't available on PS Core (at least on MacOS and Linux).

This code will not work correctly on PSCore 6 on WSL at this stage due to an issue in the underlying .Net Core version.

I have also switched to YAML builds and added additional test cases. I need to write a few more test cases for the new functionality.

Getting the Module

If you have never used the module before, the easiest way to get Posh-SYSLOG is through the PowerShell Gallery:

PS> Install-Module -Name Posh-SYSLOG

If you already have the module installed, you can update the module from the PowerShell Gallery with:

PS> Update-Module -Name Posh-SYSLOG

You can also download the release from the module’s GitHub Releases page.

Found an issue? Then raise any bugs or feature requests via GitHub Issues.

Read More
PowerShell Kieran Jacobsen PowerShell Kieran Jacobsen

Posh-SYSLOG version 4 is now available

The Posh-SYSLOG PowerShell module continues to surprise me. I originally developed the module in early 2012, making it available on GitHub in 2013. Since then I've continued to maintain the module, even though I don’t directly use the module.

The Posh-SYSLOG PowerShell module continues to surprise me. I originally developed the module in early 2012, making it available on GitHub in 2013. Since then I've continued to maintain the module, even though I don’t directly use the module.

Early this year, usage of the module skyrocketed. Growing from a few hundred downloads a year to an average of 10 thousand downloads each month. I don’t know what’s driven this growth, but it's been incredible.

Today is another milestone for Posh-SYSLOG. I'm happy to announce that version 4.0 has been released. This release adds support for sending SYSLOG messages over TLS. Sending messages over TLS

Switching to TLS is super easy!

With previous versions, the Transport parameter allowed you to specify UDP and TCP transport options, in version 4.0, we now have the TCPwithTLS option. To send a message with TLS:

PS> Send-SyslogMessage -Server ‘myserver.local’ -Message ‘My Message’ -Severity Alert -Facility kern -Transport TCPwithTLS

Default behaviours

There are some default behaviours that you should be aware of:

  1. TLS 1.2 is used by default when connecting to the server. If your server doesn’t support this, you can use the SslProtocols parameter to change the behaviour. This parameter uses the type System.Security.Authentication.SSLProtocols, and supports specifying TLS 1.0, TLS 1.1, SSL 2 and SSL 3.
  2. By default, the value specified for the Server parameter is validated against the server’s certificate. This means that the certificate will need to contain this value for validation to be successful. Currently, you can't change this logic, but I'll look at including this in version 4.1.
  3. Sometimes we can’t validate the server’s certificate, we can ignore any validation errors by including the DoNotValidateTLSCertificate parameter. If this parameter is used, a warning will be displayed to the user.

Any potential breaking issues?

I don’t believe there are any breaking changes, but there's a minor change to one of the parameter types.

Before the Transport parameter was a string, this has been changed to an enum, Syslog_Protocol. PowerShell should be able to cast between the strings TCP and UDP to the enum without any issues. If this assumption turns out to cause any significant issues, I'll revert this change.

What else is fixed?

This release also fixes more issues caused on older PowerShell versions due to the use of OutputType([null])]. These have now been fully removed. I want to thank athelu for reporting the issue.

Getting the Module

If you have never used the module before, the easiest way to get Posh-SYSLOG is through the PowerShell Gallery:

PS> Install-Module -Name Posh-SYSLOG

If you already have the module installed, you can update the module from the PowerShell Gallery with:

PS> Update-Module -Name Posh-SYSLOG

You can also download the release from the module’s GitHub Releases page.

Found an issue? Then raise any bugs or feature requests via GitHub Issues.

Read More
PowerShell Kieran Jacobsen PowerShell Kieran Jacobsen

Posh-SYSLOG 3.3 has been released

Several days ago, Jared raised a Pull Request for Posh-SYSLOG to correct an issue with the module’s manifest. It seems that in version 3.0 of Posh-SYSLOG, I used the PowerShellHostVersion attribute of the module manifest and not PowerShellVersion to specify the minimum Powershell version. This wouldn't have created issues within a normal PowerShell session, but would have prevented the module from loading in VS Code (as Jared reported) or the ISE.

Several days ago, Jared (powershellshock) raised a Pull Request for Posh-SYSLOG to correct an issue with the module’s manifest. It seems that in version 3.0 of Posh-SYSLOG, I used the PowerShellHostVersion attribute of the module manifest and not PowerShellVersion to specify the minimum Powershell version. This wouldn't have created issues within a normal PowerShell session, but would have prevented the module from loading in VS Code (as Jared reported) or the ISE.

To understand the difference of these attributes, I suggest reading: PowerShellHostVersion – WTF?, by Jeffrey Snover.

This is by far my most popular module and it's become even more popular this year. Since January there's been almost 20 000 downloads of the module, compared to 1600 for the previous 2 years combined! I'm amazed that this simple little module has gained such popularity!

Getting the Module

If you have never used the module before, the easiest way to get Posh-SYSLOG is through the PowerShell Gallery:

PS> Install-Module -Name Posh-SYSLOG

If you already have the module installed, you can update the module from the PowerShell Gallery with:

PS> Update-Module -Name Posh-SYSLOG

You can also find the module on GitHub.

Found an issue? Then raise any bugs or feature requests via GitHub Issues.

Read More
PowerShell Kieran Jacobsen PowerShell Kieran Jacobsen

Posh-SYSLOG 3.2.1 has been released

In early January, Ben Claussen reported that there was a date formatting issue in Posh-SYSLOG, I've released Posh-SYSLOG 3.2.1 to address these issues.

When I initially developed Posh-SYSLOG, I didn’t correctly follow RFC 3164. The timestamps sent had a leading zero for dates less than 10, but the RFC states this should be a leading space. I don’t know how much this impacted some users, and apologise for any issues.

In early January, Ben Claussen reported that there was a date formatting issue in Posh-SYSLOG, I've released Posh-SYSLOG 3.2.1 to address these issues.

When I initially developed Posh-SYSLOG, I didn’t correctly follow RFC 3164. The timestamps sent had a leading zero for dates less than 10, but the RFC states this should be a leading space. I don’t know how much this impacted some users, and apologise for any issues.

I want to thank Ben for putting together such a great issue, he included some recommended fixes and tested an updated version before its release.

As it stands, there are no outstanding issues, and only one feature request for Posh-SYSLOG. If you find any issues or want to make a feature request, please do so via a GitHub Issue.

You can get the new version from GitHub or from the PowerShell Gallery.

Kieran Jacobsen

Read More
PowerShell Kieran Jacobsen PowerShell Kieran Jacobsen

Posh-SYSLOG 3.2 has been released

Over the Christmas break, I had a few hours to spare and tackled a few issues in some of my PowerShell modules. I’ve released Posh-SYSLOG 3.2 as a resolve of this.

This version removes the need to call Get-NetAdapter that's contained in the NetTCPIP module. The reason why I wanted to remove this dependency is to allow Posh-SYSLOG to run on PowerShell 6 (at least on Windows to start with).

Over the Christmas break, I had a few hours to spare and tackled a few issues in some of my PowerShell modules. I’ve released Posh-SYSLOG 3.2 as a resolve of this.

This version removes the need to call Get-NetAdapter that's contained in the NetTCPIP module. The reason why I wanted to remove this dependency is to allow Posh-SYSLOG to run on PowerShell 6 (at least on Windows to start with).

An issue has been reported on GitHub, Ben Claussen has identified an issue with the timestamp for RFC3164 messages. The fix appears to be simple, but I'll want to do some more through testing. I'm hoping to have this fix out in the next week as version 3.2.1.

You can get the updated version from GitHub, or better yet, the PowerShell Gallery.

Kieran Jacobsen

Read More