grokevt-addlog(1) | grokevt-addlog(1) |
grokevt-addlog - A tool for adding a raw event log to an existing GrokEVT database.
grokevt-addlog database-dir evt-file new-type base-type
grokevt-addlog takes a raw event log (.evt file) and adds it to a pre-built database generated by grokevt-builddb(1). This new log file will be set up to use the message templates of another log, as determined by the user.
This tool is primarily useful for processing deleted logs and log fragments found on a system. While it is possible to use the database generated from one system with the logs of another, this is not recommended for investigations unless no alternatives exist.
grokevt-addlog uses the following arguments:
Probably several. This particular script has not been extensively tested.
Written by Timothy D. Morgan.
Please see the file "LICENSE" included with this software distribution.
This program is distributed in the hope that it will be useful, but WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License version 3 for more details.
grokevt(7) grokevt-builddb(1) grokevt-dumpmsgs(1) grokevt-findlogs(1) grokevt-parselog(1) grokevt-ripdll(1)
20 June 2011 | File Conversion Utilities |