GrokEVT is a collection of scripts for reading Windows event log files on Unix. The scripts work together on one or more mounted Windows partitions to extract all information needed (registry entries, message templates, and log files) to convert the logs to a human-readable format.
729ebacf9abc79130c80a6e599bb78dc
Comments
No comments yet, be the first!