Groups
Groups
Sign in
Groups
Groups
log2timeline-discuss
Conversations
About
Send feedback
Help
log2timeline-discuss
Contact owners and managers
1–30 of 170
Welcome to log2timeline-discuss, a discussion mailing list for all things log2timeline/plaso/
Log2Timeline
Mark all as read
Report group
0 selected
Rob Ayers
, …
Joachim Metz
7
11/6/23
Latest version - plaso - log2timeline version 20230717 in Docker
log2timeline.py and psteal.py have different arguments have a close look at their --help information
unread,
Latest version - plaso - log2timeline version 20230717 in Docker
log2timeline.py and psteal.py have different arguments have a close look at their --help information
11/6/23
Craig Sharp
,
Joachim Metz
2
8/4/23
log2timeline bitlocker recovery key issue
Plaso uses libbde have a look if that has a similar issue, you could be encountering an unsupported
unread,
log2timeline bitlocker recovery key issue
Plaso uses libbde have a look if that has a similar issue, you could be encountering an unsupported
8/4/23
Markus Bauer
,
Joachim Metz
2
10/30/21
Linux Auth.log
Markus, there are many formats that Plaso log2timeline does not support https://github.com/
unread,
Linux Auth.log
Markus, there are many formats that Plaso log2timeline does not support https://github.com/
10/30/21
Markus Bauer
,
Joachim Metz
2
10/30/21
Two more suggestions
Markus, feel free to submit a pull request On Sat, Oct 30, 2021 at 1:06 AM Markus Bauer <m.
unread,
Two more suggestions
Markus, feel free to submit a pull request On Sat, Oct 30, 2021 at 1:06 AM Markus Bauer <m.
10/30/21
Justin Grover
,
Joachim Metz
3
7/22/21
log2timeline - no user prompts?
Nice!!!! Thanks Joachim! On Thu, Jul 22, 2021, 11:51 PM Joachim Metz <joachi...@gmail.com>
unread,
log2timeline - no user prompts?
Nice!!!! Thanks Joachim! On Thu, Jul 22, 2021, 11:51 PM Joachim Metz <joachi...@gmail.com>
7/22/21
Aristeu Jr
5/7/21
no_vss not switching off vss check
I'm using ubuntu 20.04 and a plaso docker (today latest) and some errors occur when using l2t. I
unread,
no_vss not switching off vss check
I'm using ubuntu 20.04 and a plaso docker (today latest) and some errors occur when using l2t. I
5/7/21
Joachim Metz
5/6/21
Re: [log2timeline-discuss] libbde ([FAILURE] unable to determine version information for: pybde)
Sebastien, first of all we do not recommend using pip as an installation method unless you are
unread,
Re: [log2timeline-discuss] libbde ([FAILURE] unable to determine version information for: pybde)
Sebastien, first of all we do not recommend using pip as an installation method unless you are
5/6/21
Giochidimagia Editore
, …
Daniel White
5
2/10/21
log2timeline.exe
You might also find this recent video about using Plaso in WSL2 useful: https://www.youtube.com/watch
unread,
log2timeline.exe
You might also find this recent video about using Plaso in WSL2 useful: https://www.youtube.com/watch
2/10/21
Alspeedo
,
Joachim Metz
8
9/1/20
New to Plaso and log2timeline setup - Errors
you have to make sure that your system is configured correctly to talk to a PPA on launchpad On Tue,
unread,
New to Plaso and log2timeline setup - Errors
you have to make sure that your system is configured correctly to talk to a PPA on launchpad On Tue,
9/1/20
Arieh Tal
,
Joachim Metz
2
8/10/20
libbde [pybde]
Have a look at: * https://plaso.readthedocs.io/en/latest/sources/user/Troubleshooting.html * https://
unread,
libbde [pybde]
Have a look at: * https://plaso.readthedocs.io/en/latest/sources/user/Troubleshooting.html * https://
8/10/20
Farhan Adeen
,
Infosec Analyzer
2
3/22/20
Speed up Supertimeline
Not an expert here, but yes: 1. run as little as possible, in other words, run limited parsers, 2.
unread,
Speed up Supertimeline
Not an expert here, but yes: 1. run as little as possible, in other words, run limited parsers, 2.
3/22/20
Infosec Analyzer
3/22/20
How to authenticate to elasticsearch from psort?
Hi, quick question, I would like to push psort output directly into elasticsearch. There is basic
unread,
How to authenticate to elasticsearch from psort?
Hi, quick question, I would like to push psort output directly into elasticsearch. There is basic
3/22/20
Steven Duong
,
Joachim Metz
2
12/30/19
Parsing WebCacheV01.dat File From Windows 10
Steven, which version of Windows 10? You are likely running into this issue https://github.com/
unread,
Parsing WebCacheV01.dat File From Windows 10
Steven, which version of Windows 10? You are likely running into this issue https://github.com/
12/30/19
David Johnson
,
Joachim Metz
2
1/2/19
Help please..
David the information you ask for can be found in the documentation, eg https://plaso.readthedocs.io/
unread,
Help please..
David the information you ask for can be found in the documentation, eg https://plaso.readthedocs.io/
1/2/19
rp....@gmail.com
,
Daniel White
2
11/2/18
ZMQError: Too many open files (windows 10 image, plaso running on macbook)
How many files are in the EWF archive? This looks like a variant of https://github.com/log2timeline/
unread,
ZMQError: Too many open files (windows 10 image, plaso running on macbook)
How many files are in the EWF archive? This looks like a variant of https://github.com/log2timeline/
11/2/18
Dave
,
Joachim Metz
10
10/25/18
ntfs_make_run: Run length is larger than file system
Correcting my post about fls working. The following shows 3 different fls commands. The first two did
unread,
ntfs_make_run: Run length is larger than file system
Correcting my post about fls working. The following shows 3 different fls commands. The first two did
10/25/18
goorg...@protonmail.com
, …
Joachim Metz
5
10/25/18
Missing file system events using the MFT parser
Hello Dave, Hello Joachim, Dave's solution was indeed the correct one. $MFT was now parsed. I
unread,
Missing file system events using the MFT parser
Hello Dave, Hello Joachim, Dave's solution was indeed the correct one. $MFT was now parsed. I
10/25/18
sim...@gmail.com
,
Joachim Metz
5
10/13/18
What can be done using Plaso framework tools ?
Thank you again for the feedback, I will stick with "How-to use the Plaso toolset for Timeline
unread,
What can be done using Plaso framework tools ?
Thank you again for the feedback, I will stick with "How-to use the Plaso toolset for Timeline
10/13/18
Daniel White
10/11/18
Open source forensic tools slack
Hey everyone, Just a quick heads up that we've set up a slack to discuss open source forensics
unread,
Open source forensic tools slack
Hey everyone, Just a quick heads up that we've set up a slack to discuss open source forensics
10/11/18
Lee Armet
, …
sim...@gmail.com
3
10/10/18
Date Histogram
try combine it with gnuplot Le mercredi 21 mars 2018 15:51:39 UTC, Lee Armet a écrit : Any way to
unread,
Date Histogram
try combine it with gnuplot Le mercredi 21 mars 2018 15:51:39 UTC, Lee Armet a écrit : Any way to
10/10/18
pm
, …
Daniel White
4
9/25/18
Log2timeline parameters to run on a HFS 500GB drive
log2timeline.py is usually CPU bound, so increasing the worker count and disabling the memory limit
unread,
Log2timeline parameters to run on a HFS 500GB drive
log2timeline.py is usually CPU bound, so increasing the worker count and disabling the memory limit
9/25/18
Sue Tree
8/16/18
LOOKING FOR SOMEONE TO INTERVIEW FOR UPCOMING STORY ON 4N6TIME'S BENEFITS FOR LAW ENFORCERS
Hi there - I'm doing an article on this software to celebrate its creator, at KPMG, and am
unread,
LOOKING FOR SOMEONE TO INTERVIEW FOR UPCOMING STORY ON 4N6TIME'S BENEFITS FOR LAW ENFORCERS
Hi there - I'm doing an article on this software to celebrate its creator, at KPMG, and am
8/16/18
pm
,
Joachim Metz
5
7/27/18
Issue with log2timeline with MacOS artifact-filters
Ok, thanks. On Thu, Jul 19, 2018 at 4:48 AM Joachim Metz <joachi...@gmail.com> wrote: The
unread,
Issue with log2timeline with MacOS artifact-filters
Ok, thanks. On Thu, Jul 19, 2018 at 4:48 AM Joachim Metz <joachi...@gmail.com> wrote: The
7/27/18
Abel Morales
,
Joachim Metz
2
7/13/18
log2timeline evtx plugin
> Is it possible to run multiple evtx files into one plaso file? yes, put them in a directory and
unread,
log2timeline evtx plugin
> Is it possible to run multiple evtx files into one plaso file? yes, put them in a directory and
7/13/18
Colin
,
Joachim Metz
8
3/27/18
Error when trying to tag events within a plaso file
Thanks for the info. I have setup a virtual environment and deployed inside it and all seems fine so
unread,
Error when trying to tag events within a plaso file
Thanks for the info. I have setup a virtual environment and deployed inside it and all seems fine so
3/27/18
christy porter
2/5/18
The amount of time it takes from start to completion
I have been running numerous tests, to attempt to troubleshoot the amount of time a image is taking
unread,
The amount of time it takes from start to completion
I have been running numerous tests, to attempt to troubleshoot the amount of time a image is taking
2/5/18
Joshua Lewis
,
Joachim Metz
2
1/17/18
dfdatetime
Joshua, if the date and time is formatted as "2017-07-13 08:43:46" dfdatetime.TimeElements
unread,
dfdatetime
Joshua, if the date and time is formatted as "2017-07-13 08:43:46" dfdatetime.TimeElements
1/17/18
greyson
, …
Joachim Metz
8
11/27/17
Please fix the error in log2timeline!
Mike this is working as expected: log2timeline.py --artifact_definitions /usr/local/lib/python2.7/
unread,
Please fix the error in log2timeline!
Mike this is working as expected: log2timeline.py --artifact_definitions /usr/local/lib/python2.7/
11/27/17
greyfolded
,
Joachim Metz
4
10/24/17
Trouble with Plaso install
Actually it's still not working. I can run psteal but when I actually try to run log2timeline I
unread,
Trouble with Plaso install
Actually it's still not working. I can run psteal but when I actually try to run log2timeline I
10/24/17
Jonas Plum
,
Daniel White
6
10/20/17
AnalysisPlugin
OK, that sounds reasonable, and I can see why tags aren't a good fit. I'll think a little
unread,
AnalysisPlugin
OK, that sounds reasonable, and I can see why tags aren't a good fit. I'll think a little
10/20/17