Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add Support for EVTX Files #18

Open
modhash opened this issue Feb 12, 2024 · 2 comments
Open

Add Support for EVTX Files #18

modhash opened this issue Feb 12, 2024 · 2 comments

Comments

@modhash
Copy link

modhash commented Feb 12, 2024

Add Support for EVTX Files

Feature Request: Implement EVTX file support in toolong for importing, and reading Windows Event Viewer logs.

Why This Matters:

  • Relevance: EVTX is a crucial format for Windows event logs, widely used in IT security and troubleshooting.
  • Benefit: Facilitates direct log analysis within toolong, enhancing its utility for Windows system users.

Thank you for considering this enhancement.

@willmcgugan
Copy link
Contributor

If you could link me to something that describes the format, or an example file, that would be very helpful.

@modhash
Copy link
Author

modhash commented Feb 18, 2024

Sure, these 2 links might be helpful.

Info on the file format
A cross-platform parser for the Windows XML EventLog format

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants