ceramicskate0 / SWELF

Simple Windows Event Log Forwarder (SWELF). Its easy to use/simply works Log Forwarder and EVTX Parser. Almost in full release here at https://github.com/ceramicskate0/SWELF/releases/latest.
https://ceramicskate0.github.io/SWELF/
GNU Affero General Public License v3.0
24 stars 7 forks source link

Redo the "not_in_log" search logic #93

Closed ceramicskate0 closed 5 years ago

ceramicskate0 commented 5 years ago

The "not_in_log" search needs to be revised. I should look for evemt logs with data in them and then remove the ones that contain the NOT data in them. Im thinking using the search_multiple like logic with a whitelist option