Details
-
Sub-task
-
Status: Resolved
-
Major
-
Resolution: Fixed
-
None
-
None
-
None
Description
Windows event logs are stored in .evtx format as-of Windows Vista. If we port the pure python implementation of an evtx parser at https://github.com/williballenthin/python-evtx to Java, we should be able to ingest those files in NiFi on any operating system
These files are located in C:\Windows\System32\winevt\Logs unless exported elsewhere.
Attachments
Issue Links
- links to