EvtxECmd - this tool will help us to convert event logs into csv format. Later we can use timeline analysis tool to analysis the csv data more efficiently.
This tool also help us to convert logs into json format.
Download the tool first.
https://ericzimmerman.github.io/#!index.md
Command:
evtxecmd --sync
evtxecmd -f E:\C\Windows\System32\winevt\logs\Security.evtx --csv g:\Labs\event-logs --csvf security.csv
evtxecmd -f "e:\C\Windows\System32\winevt\logs\Microsoft-Windows-TaskScheduler%40Operational.evtx" --csv G:\Labs\event-logs --csvf taskscheduler.csv
You can use mark hallman Process-EventLogs tool that will parse important event id's from bulk event logs leveraging evtxecmd tool.
https://github.com/mark-hallman/Process-EventLogs
.\Automate_EvtxECmd.ps1 -source E:\c\Windows\system32\winevt\logs\ -dest G:\Labs\event-logs\evtx-all
The above command will create csv file. Check this book Workbook and Labs Section 1-2.pdf 181 page for more info. The name has been changed of the script now. Current name is Process-EventLogs.ps1
The reason for using this tool is evtxecmd can process only one file at a time.
Avi
Comments
Post a Comment