Last login: Wed Jan 2 01:16:34 on ttys006
mojavas-iMac:~ mojava$ log2timeline.py --volumes
usage: log2timeline.py [-h] [-V] [--artifact_definitions PATH]
[--custom_artifact_definitions PATH] [--data PATH]
[--artifact_filters ARTIFACT_FILTERS]
[--artifact_filters_file PATH] [--preferred_year YEAR]
[--process_archives] [--skip_compressed_streams]
[-f FILE_FILTER] [--hasher_file_size_limit SIZE]
[--hashers HASHER_LIST] [--parsers PARSER_LIST]
[--yara_rules PATH] [--partitions PARTITIONS]
[--volumes VOLUMES] [-z TIMEZONE] [--no_vss]
[--vss_only] [--vss_stores VSS_STORES]
[--credential TYPE:DATA] [-d] [-q] [--info]
[--use_markdown] [--no_dependencies_check]
[--logfile FILENAME] [--status_view TYPE] [-t TEXT]
[--buffer_size BUFFER_SIZE] [--queue_size QUEUE_SIZE]
[--single_process] [--process_memory_limit SIZE]
[--temporary_directory DIRECTORY]
[--worker_memory_limit SIZE] [--workers WORKERS]
[--disable_zeromq] [--sigsegv_handler]
[--profilers PROFILERS_LIST]
[--profiling_directory DIRECTORY]
[--profiling_sample_rate SAMPLE_RATE]
[--storage_format FORMAT]
[STORAGE_FILE] [SOURCE]
log2timeline.py: error: argument --volumes/--volume: expected one argument
mojavas-iMac:~ mojava$
and
Last login: Wed Jan 2 00:47:36 on ttys002
mojavas-iMac:~ mojava$ log2timeline.py OUTPUT INPUT
2019-01-02 00:51:26,151 [INFO] (MainProcess) PID:4028 <data_location> Determined data location: /Library/Python/2.7/site-packages
2019-01-02 00:51:26,151 [INFO] (MainProcess) PID:4028 <artifact_definitions> Determined artifact definitions path: /usr/local/share/artifacts
Checking availability and versions of dependencies.
[OPTIONAL] missing: hachoir_core.
[OPTIONAL] missing: hachoir_metadata.
[OPTIONAL] missing: hachoir_parser.
[OPTIONAL] missing: lzma.
[OK]
2019-01-02 00:51:27,872 [WARNING] (MainProcess) PID:4028 <log2timeline> No such device, file or directory: /Users/mojava/INPUT.
mojavas-iMac:~ mojava$ log2timeline.py /Users/mojava/
2019-01-02 00:53:16,124 [INFO] (MainProcess) PID:4037 <data_location> Determined data location: /Library/Python/2.7/site-packages
2019-01-02 00:53:16,124 [INFO] (MainProcess) PID:4037 <artifact_definitions> Determined artifact definitions path: /usr/local/share/artifacts
ERROR: Missing source path.
Can I get some samples of commands written out the correct way to be able to learn to use this app?
My mail is djtherenovator>>gmail
Thank You.
David