Truxton group set created

From truxwiki.com
Revision as of 07:09, 13 April 2024 by Sam (talk | contribs) (Created page with "This sets the time the group was created. This corresponds to the <code>[Created]</code> column of the <code>[Group]</code> table. =Syntax= <source lang="C"> void truxton_gro...")
(diff) ← Older revision | Latest revision (diff) | Newer revision → (diff)
Jump to navigation Jump to search

This sets the time the group was created. This corresponds to the [Created] column of the [Group] table.

Syntax

void truxton_group_set_created( uint64_t group_handle, uint64_t ticks );

Parameters

group_handle

The handle created by truxton_group_create() or truxton_investigation_create_group().

ticks

The date in FILETIME ticks.

Sample

void create_my_things(uint64_t investigation_handle)
{
    if (investigation_handle == 0)
    {
        return;
    }

    uint64_t truxton_handle = truxton_investigation_get_truxton( investigation_handle );
    uint64_t group_handle = truxton_group_create( truxton_handle );
 
    truxton_group_set_id( group_handle, "47726F75-7020-5361-6D70-6C65636F6465" );
    truxton_group_set_name( group_handle, "My Things" );
    truxton_group_set_description( group_handle, "These are my things" );
    truxton_group_set_is_default( group_handle, 1 );
    truxton_group_set_type( group_handle, GROUP_TYPE_USER );

    if ( truxton_group_save( group_handle ) != 0 )
    {
        char guid[MINIMUM_GUID_STRING_BUFFER_SIZE + 5];

        truxton_group_get_id( group_handle, guid, sizeof(guid) );
        truxton_investigation_set_active_group_id( investigation_handle, guid );
    }

    FILETIME now;

    GetSystemTimePreciseAsFileTime( &now );

    ULARGE_INTEGER ticks;

    ticks.LowPart = now.dwLowDateTime;
    ticks.HighPart = now.dwHighDateTime;

    truxton_group_set_created( group_handle, ticks.QuadPart );

    truxton_group_destroy( group_handle );
}