Skip to content
This repository was archived by the owner on Aug 17, 2022. It is now read-only.
This repository was archived by the owner on Aug 17, 2022. It is now read-only.

0 records read #2

@dlimanov

Description

@dlimanov

Is there anything special I need to do to get it to understand the EVTX files from Win7 machine? Installed dependencies, all looks well but when I run it, I get this:

/event2timeline-master$ python event2timeline.py -e -f evt.evtx
[*] Reading EVTX file evt.evtx
0 records read
[*] Unique users: 5
[*] Mapped 38 sessions from 2012-11-07 21:36:06 to 2015-03-13 16:18:07

It creates evtdata.js in /timeline folder but nothing else. Am I missing something obvious?
Thanks!

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions