ceramicskate0 / SWELF

Simple Windows Event Log Forwarder (SWELF). Its easy to use/simply works Log Forwarder and EVTX Parser. Almost in full release here at https://github.com/ceramicskate0/SWELF/releases/latest.
https://ceramicskate0.github.io/SWELF/
GNU Affero General Public License v3.0
24 stars 7 forks source link

SWELF may have searching issues in Search.cs (v0.6.1.0) #136

Open ceramicskate0 opened 4 years ago

ceramicskate0 commented 4 years ago

recent review of splunk data show either improper parse of search string from searchs.txt or improper loggins of search_rule in log.