Event Log Forensics with Log Parser

Event Log Forensics with Log Parser

13Cubed

6 лет назад

34,212 Просмотров

Ссылки и html тэги не поддерживаются


Комментарии:

D. C.
D. C. - 10.04.2022 00:30

This is the heart of Kansa :( I am not sure why it is used over standard PowerShell. Does anyone else know?

Ответить
shashank sharma
shashank sharma - 25.12.2021 18:46

Great job man its to good u saved a day for me ...

Ответить
Auditor Zaman Now
Auditor Zaman Now - 03.08.2021 20:34

Very enlightening, thanks for your share

Ответить
Steven Miller
Steven Miller - 02.07.2021 17:58

thank you so much for this amazing video.

Ответить
W G
W G - 19.06.2021 10:16

Amazing video series! You covered some great foundational concepts. I know that in the examples provided, many of the parsed fields are set as aliases. When examining logs, how do you set conditions on aliases? For example, if I wanted to find all usernames within 4624's where Type 3 Logons were less than 10 count, how would I go about creating this query? Is Log Parser the right tool for this? Thanks for any help you can provide!

Ответить
Code Cad
Code Cad - 04.06.2021 12:56

What happen that you changed this nice and smooth intro like here into idiotic, laud and annoying BBBBBBIIIIIIBBBIIIBIBIBIIIBIBI in 2019?

Ответить
Faizan Khurshid
Faizan Khurshid - 21.04.2021 00:15

C:\Users\Hp\Desktop\logs\10>"C:\Program Files (x86)\Log Parser 2.2\LogParser.exe" -stats:OFF -i:EVT "SELECT * FROM 'Security.evtx' WHERE EventID = '4624'"
Error: Error retrieving files: Error opening file "C:\Users\Hp\Desktop\logs\10\Security.evtx": The system cannot find the file specified.
I am getting this error while running the query

Ответить
Ayana Hines
Ayana Hines - 02.12.2020 07:36

Log parser is totally legal in Mozilla never Windows because it doesn’t create files. It’s a duplicate of prompt. Used to bring data to now not to explain data

Ответить
Ayana Hines
Ayana Hines - 02.12.2020 07:34

Isn’t it illegal to example log parser due to the directory being cancelled in 2005 by Internet Explorer and transferee tranced to Mozilla Firefox?

Ответить
Joseph Ford
Joseph Ford - 28.09.2020 20:24

Thanks for this awesome content. Do you have a solution while opening an event logs, it is giving me "the data is invalid" error, but I know the data is not corrupted. It has something to do with mismatched floating footer. Was referring some docs online, but couldn't follow.

Ответить
O
O - 08.07.2020 16:13

Nice video TY

Ответить
Rodrigo Fritzen
Rodrigo Fritzen - 29.04.2020 23:29

Very enlightening, congratulations for the work

Ответить
Hemant S
Hemant S - 21.01.2020 00:02

Loved it, thanks for sharing...

Ответить
Demo1
Demo1 - 16.11.2019 06:04

Great intro to the log parser tool. Sad Microsoft does not provide/teach as part of "Getting Started". Thanks.

Ответить
Eskimoz
Eskimoz - 07.10.2019 11:52

On aime :)

Ответить
Vero 0
Vero 0 - 24.07.2019 04:48

Just wanted to say again how much I appreciate this series. Good luck at the 4cast awards 👍

Ответить
Rohith K
Rohith K - 15.07.2019 21:22

I am a huge fan of your work. You explain everything simple and easy.
I would like to know which is an easier tool in (splunk, log parser ) which one do you prefer and why ?

Ответить
Eskimoz
Eskimoz - 04.07.2019 22:13

On supporte :)

Ответить
Lakshmi
Lakshmi - 31.01.2019 12:21

sir.... how to extract the software execution data .

Ответить
Benjamin Newman
Benjamin Newman - 14.05.2018 08:22

Hi love the videos, could you maybe zoom in slightly? the text is always very small, notepad section was a lovely size

Ответить