JPCERTCC / LogonTracer

Investigate malicious Windows logon by visualizing and analyzing Windows event log
Other
2.74k stars 443 forks source link

Docker - Doesn't Remove Example Data #98

Closed joshlemon closed 3 years ago

joshlemon commented 3 years ago

When using the latest Docker image, if you upload new data it does not remove the example data already loaded in the Docker image. This means you have both your uploaded data and the example data mixed together in the graph.

joshlemon commented 3 years ago

Found the issue.

For the first log file you upload, you need to uncheck "Add additional EVTX or XML files", this will delete all previous logs uploaded into LogonTracer, which would include the example data.

image