JPCERTCC / LogonTracer

Investigate malicious Windows logon by visualizing and analyzing Windows event log
Other
2.7k stars 441 forks source link

This event log did not include logs to be visualized. Please check the details of the event log. #106

Closed esdk123 closed 3 years ago

esdk123 commented 3 years ago

Now loading 20300 records. [+] Now loading 20400 records. [+] Now loading 20500 records. [+] Now loading 20600 records. [+] Now loading 20700 records. [+] Now loading 20800 records. [+] Now loading 20900 records. [+] Now loading 21000 records. [+] Now loading 21100 records. [+] Now loading 21200 records. [+] Now loading 21300 records. [+] Now loading 21400 records. [+] Now loading 21500 records. [+] Now loading 21600 records. [+] Now loading 21700 records. [+] Now loading 21800 records. [+] Now loading 21900 records. [+] Now loading 22000 records. [+] Now loading 22100 records. [+] Now loading 22200 records. [+] Load finished. [+] Total Event log is 22220. [!] This event log did not include logs to be visualized. Please check the details of the event log.

[!] This event log did not include logs to be visualized. Please check the details of the event log.

Why does this happen? My logs are exported from the server.

t-tani commented 3 years ago

Did you upload the security log of your domain controller? If so, please check if your logs contain EventID 4624/4625. You could check it with the EventViewer, which is installed on Windows default. Or if you had set your audit policy NOT to record the Account Logon Events, LogonTracer could not find logs required to visualize the graph.