@@ -221,10 +221,10 @@ func (wp *WindowsProbe) parseCreateNewFileArgs(e *etw.DDEventRecord) (*createNew
221221func (ca * createHandleArgs ) string (t string ) string {
222222 var output strings.Builder
223223
224- output .WriteString (t + " PID: " + strconv .Itoa (int (ca .ProcessID )) + "\n " )
225- output .WriteString (" Name: " + ca .fileName + "\n " )
226- output .WriteString (" Opts: " + strconv .FormatUint (uint64 (ca .createOptions ), 16 ) + " Share: " + strconv .FormatUint (uint64 (ca .shareAccess ), 16 ) + "\n " )
227- output .WriteString (" OBJ: " + strconv .FormatUint (uint64 (ca .fileObject ), 16 ) + " \n " )
224+ output .WriteString (t + " PID: " + strconv .Itoa (int (ca .ProcessID )) + ", " )
225+ output .WriteString ("Name: " + ca .fileName + ", " )
226+ output .WriteString ("Opts: " + strconv .FormatUint (uint64 (ca .createOptions ), 16 ) + " Share: " + strconv .FormatUint (uint64 (ca .shareAccess ), 16 ) + ", " )
227+ output .WriteString ("Obj: " + strconv .FormatUint (uint64 (ca .fileObject ), 16 ))
228228
229229 return output .String ()
230230}
@@ -316,11 +316,11 @@ func (wp *WindowsProbe) parseInformationArgs(e *etw.DDEventRecord) (*setInformat
316316func (sia * setInformationArgs ) string (t string ) string {
317317 var output strings.Builder
318318
319- output .WriteString (t + " TID: " + strconv .Itoa (int (sia .threadID )) + "\n " )
320- output .WriteString (" Name: " + sia .fileName + "\n " )
321- output .WriteString (" InfoClass: " + strconv .FormatUint (uint64 (sia .infoClass ), 16 ) + "\n " )
322- output .WriteString (" OBJ: " + strconv .FormatUint (uint64 (sia .fileObject ), 16 ) + "\n " )
323- output .WriteString (" KEY: " + strconv .FormatUint (uint64 (sia .fileKey ), 16 ) + " \n " )
319+ output .WriteString (t + " TID: " + strconv .Itoa (int (sia .threadID )) + ", " )
320+ output .WriteString ("Name: " + sia .fileName + ", " )
321+ output .WriteString ("InfoClass: " + strconv .FormatUint (uint64 (sia .infoClass ), 16 ) + ", " )
322+ output .WriteString ("Obj: " + strconv .FormatUint (uint64 (sia .fileObject ), 16 ) + ", " )
323+ output .WriteString ("Key: " + strconv .FormatUint (uint64 (sia .fileKey ), 16 ))
324324
325325 return output .String ()
326326
@@ -473,10 +473,10 @@ func (wp *WindowsProbe) parseFlushArgs(e *etw.DDEventRecord) (*flushArgs, error)
473473func (ca * cleanupArgs ) string (t string ) string {
474474 var output strings.Builder
475475
476- output .WriteString (t + ": TID: " + strconv .Itoa (int (ca .threadID )) + "\n " )
477- output .WriteString (" Name: " + ca .fileName + "\n " )
478- output .WriteString (" OBJ: " + strconv .FormatUint (uint64 (ca .fileObject ), 16 ) + "\n " )
479- output .WriteString (" KEY: " + strconv .FormatUint (uint64 (ca .fileKey ), 16 ) + " \n " )
476+ output .WriteString (t + ": TID: " + strconv .Itoa (int (ca .threadID )) + ", " )
477+ output .WriteString ("Name: " + ca .fileName + ", " )
478+ output .WriteString ("Obj: " + strconv .FormatUint (uint64 (ca .fileObject ), 16 ) + ", " )
479+ output .WriteString ("Key: " + strconv .FormatUint (uint64 (ca .fileKey ), 16 ))
480480 return output .String ()
481481
482482}
@@ -511,7 +511,7 @@ type readArgs struct {
511511}
512512type writeArgs readArgs
513513
514- func (wp * WindowsProbe ) parseReadArgs (e * etw.DDEventRecord ) (* readArgs , error ) {
514+ func (wp * WindowsProbe ) parseReadWriteArgs (e * etw.DDEventRecord ) (* readArgs , error ) {
515515 ra := & readArgs {
516516 DDEventHeader : e .EventHeader ,
517517 }
@@ -554,11 +554,11 @@ func (wp *WindowsProbe) parseReadArgs(e *etw.DDEventRecord) (*readArgs, error) {
554554func (ra * readArgs ) string (t string ) string {
555555 var output strings.Builder
556556
557- output .WriteString (t + ": PID: " + strconv .Itoa (int (ra .DDEventHeader .ProcessID )) + "\n " )
558- output .WriteString (" fo : " + strconv .FormatUint (uint64 (ra .fileObject ), 16 ) + "\n " )
559- output .WriteString (" fk : " + strconv .FormatUint (uint64 (ra .fileKey ), 16 ) + "\n " )
560- output .WriteString (" Name: " + ra .fileName + "\n " )
561- output .WriteString (" Size: " + strconv .FormatUint (uint64 (ra .IOSize ), 16 ) + " \n " )
557+ output .WriteString (t + ": PID: " + strconv .Itoa (int (ra .DDEventHeader .ProcessID )) + ", " )
558+ output .WriteString ("Obj : " + strconv .FormatUint (uint64 (ra .fileObject ), 16 ) + ", " )
559+ output .WriteString ("Key : " + strconv .FormatUint (uint64 (ra .fileKey ), 16 ) + ", " )
560+ output .WriteString ("Name: " + ra .fileName + ", " )
561+ output .WriteString ("Size: " + strconv .FormatUint (uint64 (ra .IOSize ), 16 ))
562562 return output .String ()
563563
564564}
@@ -569,7 +569,7 @@ func (ra *readArgs) String() string {
569569}
570570
571571func (wp * WindowsProbe ) parseWriteArgs (e * etw.DDEventRecord ) (* writeArgs , error ) {
572- wa , err := wp .parseReadArgs (e )
572+ wa , err := wp .parseReadWriteArgs (e )
573573 if err != nil {
574574 return nil , err
575575 }
@@ -660,10 +660,10 @@ func (wp *WindowsProbe) parseDeletePathArgs(e *etw.DDEventRecord) (*deletePathAr
660660func (dpa * deletePathArgs ) string (t string ) string {
661661 var output strings.Builder
662662
663- output .WriteString (t + ": PID: " + strconv .Itoa (int (dpa .ProcessID )) + "\n " )
664- output .WriteString (" Name: " + dpa .filePath + "\n " )
665- output .WriteString (" OBJ : " + strconv .FormatUint (uint64 (dpa .fileObject ), 16 ) + "\n " )
666- output .WriteString (" KEY : " + strconv .FormatUint (uint64 (dpa .fileKey ), 16 ) + " \n " )
663+ output .WriteString (t + ": PID: " + strconv .Itoa (int (dpa .ProcessID )) + ", " )
664+ output .WriteString ("Name: " + dpa .filePath + ", " )
665+ output .WriteString ("Obj : " + strconv .FormatUint (uint64 (dpa .fileObject ), 16 ) + ", " )
666+ output .WriteString ("Key : " + strconv .FormatUint (uint64 (dpa .fileKey ), 16 ))
667667 return output .String ()
668668
669669}
@@ -733,8 +733,8 @@ func (wp *WindowsProbe) parseNameCreateArgs(e *etw.DDEventRecord) (*nameCreateAr
733733func (ca * nameCreateArgs ) string (t string ) string {
734734 var output strings.Builder
735735
736- output .WriteString (t + ": KEY : " + strconv .FormatUint (uint64 (ca .fileKey ), 16 ) + "\n " )
737- output .WriteString (" Name: " + ca .fileName + " \n " )
736+ output .WriteString (t + ": Key : " + strconv .FormatUint (uint64 (ca .fileKey ), 16 ) + ", " )
737+ output .WriteString ("Name: " + ca .fileName )
738738 return output .String ()
739739
740740}
0 commit comments