Plaso storage issue #2859
Replies: 2 comments · 4 replies
-
Hey, something is not really making sense, the error message states the file is created in version And can you go into the docker container and do: And run Thx |
Beta Was this translation helpful? Give feedback.
All reactions
-
Here all info: ************************** Plaso Storage Information ***************************
|
Beta Was this translation helpful? Give feedback.
All reactions
-
Yes so you have |
Beta Was this translation helpful? Give feedback.
All reactions
-
Well, I should check the entire configuration. This docker comes from this repo https://github.com/blueteam0ps/AllthingsTimesketch. (https://github.com/blueteam0ps/AllthingsTimesketch/blob/master/tsplaso_docker_install.sh). |
Beta Was this translation helpful? Give feedback.
All reactions
-
So, I tried to update manually Plaso but the old version is automatically provided with Timesketck image downloaded from the original repo (us-docker.pkg.dev/osdfir-registry/timesketch/timesketch). So I suppose that the image should be updated including last version of Plaso. At the moment I solved converting everything in csv format using psort. I tried to update Plaso within the container but I got the same issue, even if the command log2timeline.py -V returned
|
Beta Was this translation helpful? Give feedback.
All reactions
-
The Log2Timeline.py utility is already included in the Timesketch Docker image. To ensure compatibility, you should use this preinstalled version to process your disk images or other files into .plaso format. Perform this conversion from within the Timesketch container itself, as this ensures version compatibility with Timesketch. I hope this clarifies things. |
Beta Was this translation helpful? Give feedback.
-
Hey there,
yesterday after creating a plaso file, I tried to upload it on Timesketch and I got this message:
The file has been generated with plaso - log2timeline version 20230717, while Timeskecth version is 20230721 (runnning on Docker).
How can I fix this issue?
Beta Was this translation helpful? Give feedback.
All reactions