-
Notifications
You must be signed in to change notification settings - Fork 166
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Update Dump Json and jq Implementation #91
base: master
Are you sure you want to change the base?
Conversation
…sing data within System xml
looks like all checks passed too! |
Checking to see if you can merge! Let me know if there are any other issues |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
program logic looks reasonable. see inline comment about formatting.
would you be up for adding a test case? if not, i can add it after the merge.
thanks!
I can definitely try to add a test case, I will admit it is my first time adding one |
Oh, cool! I'm happy to help out, either explaining ideas or answering questions. Thanks for everything you've done so far! |
I want to create a test that runs the evtx_dump_json with the evtx data located within the data folder. However, I am having trouble calling the main function. I tried to import scripts but it was never able to import the module even after I added a init.py to the scripts directory. Any thoughts? |
I wasn't able to figure it out, apologies! |
fixed issues with EventData missing key and added a UserData loop to cover newly discovered evtx data fields |
(sorry I wasn't able to get this merged before I left for a little PTO. i have an explicit TODO item to merge this when i return. i hope that's ok. ) |
No worries! Was just working on some other tasks and found something I needed to address here. Didn't mean to come across as pressuring! |
New commits address missing data within Event XML so that all necessary information is pulled from log data. Prior commits only pulled EventRecordID from within System section. New upgrades pull things like EventID, TimeCreated, Channel, etc. Also, proper usage with jq added so that output can be piped to jq for ease of analysis. New dataset added to tests folder as well!