Closed rj-chap closed 2 years ago
I figured I'd include what's at the log endpoint
[+] Script start. 2021/10/06 16:10:05 [+] Neo4j Kernel version: 4.2.6 [+] Delete all nodes and relationships from this Neo4j database. [+] make cache folder /usr/local/src/LogonTracer/cache. [+] Last record number is 2369. [+] Start parsing the EVTX file. [+] Parse the EVTX file /usr/local/src/LogonTracer/upload/0.evtx. [+] Now loading 100 records. [+] Now loading 200 records. [+] Now loading 300 records. [+] Now loading 400 records. [+] Now loading 500 records. ... [+] Now loading 185000 records. [+] Now loading 185100 records. [+] Now loading 185200 records. [+] Now loading 185300 records. [+] Now loading 185400 records. [+] Now loading 185500 records. [+] Now loading 185600 records. [+] Now loading 185700 records.
...Still procesing...
I found a bug with a parsing status above 100% and will fix it.
I found a bug with a parsing status above 100% and will fix it.
Awesome! Thanks much!
I fixed the status bar issue. If the EVTX file doesn't finish loading, it may be a machine performance issue. It's note that Docker on mscOS has low performance, so if the EVTX file size is too large, it may not finish loading.
Awesome! I'll be able to test this later this week. Not sure if you want to go ahead and close now or close after verification with the new version. Either way for me, thanks!
Hey team. I uploaded 7 EVTX files that are processing now. The upload dialogue is showing some wonky parsing percentages though (e.g.
7134%
:I didn't see this listed as an issue previously, so I figured I'd bring it up. I'm running your primary docker container under macOS:
docker image
docker details
I can provide a
docker inspect
or whatever else you'd like, but I cannot provide the actual EVTX files for obvious reasons.