JPCERTCC / LogonTracer

Investigate malicious Windows logon by visualizing and analyzing Windows event log
Other
2.7k stars 441 forks source link

Cant upload EVTX from elastic or locally #122

Closed Khughes777 closed 2 years ago

Khughes777 commented 2 years ago

Hi,

When I try upload data from logontracer either via elastic or manually, it immediately fails with the following error

"- 172.20.0.1 - - [18/May/2022 20:36:58] "GET /static/js/dark-mode-switch.min.js HTTP/1.1" 200 - 172.20.0.1 - - [18/May/2022 20:37:35] "GET /static/images/elastic-logo.png HTTP/1.1" 200 - 172.20.0.1 - - [18/May/2022 20:37:35] "GET /static/images/logo_top.svg HTTP/1.1" 200 - 172.20.0.1 - - [18/May/2022 20:37:57] "GET /static/images/elastic-logo.png HTTP/1.1" 200 - 172.20.0.1 - - [18/May/2022 20:37:57] "GET / HTTP/1.1" 200 - 172.20.0.1 - - [18/May/2022 20:37:57] "GET /static/images/logo_top.svg HTTP/1.1" 200 - 172.20.0.1 - - [18/May/2022 20:37:57] "GET /static/css/style.css HTTP/1.1" 304 - 172.20.0.1 - - [18/May/2022 20:37:57] "GET /static/css/dark-mode.css HTTP/1.1" 304 - 172.20.0.1 - - [18/May/2022 20:37:57] "GET /static/js/script.js HTTP/1.1" 304 - 172.20.0.1 - - [18/May/2022 20:37:57] "GET /static/js/dark-mode-switch.min.js HTTP/1.1" 304 -
172.20.0.1 - - [18/May/2022 20:38:01] "GET /static/images/elastic-logo.png HTTP/1.1" 200 - 172.20.0.1 - - [18/May/2022 20:38:01] "GET /static/images/logo_top.svg HTTP/1.1" 200 - 172.20.0.1 - - [18/May/2022 20:38:01] "GET / HTTP/1.1" 200 - 172.20.0.1 - - [18/May/2022 20:38:02] "GET /static/js/script.js HTTP/1.1" 304 - 172.20.0.1 - - [18/May/2022 20:38:02] "GET /static/js/dark-mode-switch.min.js HTTP/1.1" 304 -
172.20.0.1 - - [18/May/2022 20:38:02] "GET /static/css/style.css HTTP/1.1" 200 - 172.20.0.1 - - [18/May/2022 20:38:02] "GET /static/css/dark-mode.css HTTP/1.1" 200 - 172.20.0.1 - - [18/May/2022 20:38:02] "GET /static/images/logo_top.svg HTTP/1.1" 200 - 172.20.0.1 - - [18/May/2022 20:38:02] "GET /static/images/elastic-logo.png HTTP/1.1" 200 - 172.20.0.1 - - [18/May/2022 20:38:02] "GET /static/images/logo_top.svg HTTP/1.1" 304 -
172.20.0.1 - - [18/May/2022 20:38:25] "POST /upload HTTP/1.1" 200 - 172.20.0.1 - - [18/May/2022 20:38:31] "POST /upload HTTP/1.1" 200 - [2022-05-18 20:38:32,878] ERROR in app: Exception on /log [GET] Traceback (most recent call last): File "/usr/local/lib/python3.7/site-packages/flask/app.py", line 2077, in wsgi_app response = self.full_dispatch_request() File "/usr/local/lib/python3.7/site-packages/flask/app.py", line 1525, in full_dispatch_request rv = self.handle_user_exception(e) File "/usr/local/lib/python3.7/site-packages/flask/app.py", line 1523, in full_dispatch_request rv = self.dispatch_request() File "/usr/local/lib/python3.7/site-packages/flask/app.py", line 1509, in dispatch_request return self.ensure_sync(self.view_functions[rule.endpoint])(**req.view_args) File "logontracer.py", line 356, in logs with open(FPATH + "/static/logontracer.log", "r") as lf: FileNotFoundError: [Errno 2] No such file or directory: '/usr/local/src/LogonTracer/static/logontracer.log' 172.20.0.1 - - [18/May/2022 20:38:32] "GET /log HTTP/1.1" 500 - 172.20.0.1 - - [18/May/2022 20:48:53] "POST /upload HTTP/1.1" 200"

I am running it in Docker, any ideas what the issue might be?

Thank you in advance :)