You do not have permission to delete messages in this group
Copy link
Report message
Show original message
Either email addresses are anonymous for this group or you need the view member email addresses permission to view the original message
to log2timeline-discuss
I'm new to log2timeline and plaso. I have a set of raw evtx files that I would like to run through log2timeline and then through plaso to export into CSV.
Is it possible to run multiple evtx files into one plaso file? Let me share what I have tried:
I get an export that is difficult to read. What am I missing for it to parse out the username, host, event ID, and description field?
Joachim Metz
unread,
Jul 13, 2018, 12:31:22 AM7/13/18
Reply to author
Sign in to reply to author
Forward
Sign in to forward
Delete
You do not have permission to delete messages in this group
Copy link
Report message
Show original message
Either email addresses are anonymous for this group or you need the view member email addresses permission to view the original message
to abelam...@gmail.com, log2timeline-discuss
> Is it possible to run multiple evtx files into one plaso file?
yes, put them in a directory and point log2timeline.exe to the
directory or multiple times run log2timeline.exe with the same plaso
file with different evtx files
> I get an export that is difficult to read.
psort supports multiple output formats, I opt to look for an output
format that closer matches your needs