{"repo":"sumeshi/evtx2es","free":true,"listed":false,"github":"https://github.com/sumeshi/evtx2es","clone":"git clone https://github.com/sumeshi/evtx2es.git","description":"A command-line tool for parsing Windows Event Logs and importing the results into Elasticsearch.","language":"Python","stars":88,"topics":["elasticsearch","python","eventlog","evtx","windows","parser","dfir","forensics","forensics-tools"],"license":"MIT","category":"cli-tools","readme_excerpt":"evtx2es A command-line tool and Python library for parsing Windows Event Logs and importing the results into Elasticsearch. Life is too short to process huge Windows Event Logs using pure Python . evtx2es leverages the Rust-based parser pyevtx-rs, making it significantly faster than traditional tools. It can also recover as many records as possible from corrupted, partially overwritten, or carved .evtx files. Usage evtx2es can be used as a standalone command-line tool or integrated directly into your Python scripts. Arguments evtx2es can process multiple files at once: evtx2es can recursively process all .evtx files under a specified directory: Options Examples When using from the command line: When using from a Python script: With credentials for Elastic Security: [!WARNING] TLS certificate verification is enabled by default for Elasticsearch connections. Use --no-verify-certs only when connecting to a trusted cluster with self-signed or otherwise unverifiable certificates. Appendix evtx2json evtx2es also includes evtx2json , a command-line tool for converting Windows Event Logs into JSON files. :sushi: :sushi: :sushi: You can also convert .evtx files directly into a Python List[dict] object: Output Format Example The following example uses a sample .evtx file from JPCERT/CC:LogonTracer. Performance Evaluation (v1.8.0) Performance was evaluated using a sample .evtx file from JPCERT/CC:LogonTracer (approx. 30MB of binary data). Running Environment The tests were conducted wit","default_branch":null,"files":null,"tree":[],"storefront":"/r/sumeshi","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/sumeshi/evtx2es/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}