GrokEVT is a collection of scripts for reading Windows event log files on Unix. The scripts work together on one or more mounted Windows partitions to extract all information needed (registry entries, message templates, and log files) to convert the logs to a human-readable format.
0c260a44bf4caee2dfb43987199b2a2f
Comments
No comments yet, be the first!