Closed Joe860 closed 2 years ago
I guess Workaround would be Mark Hallman's Filters
by using "message contains" method? which is clever.
by using "message contains" method? which is clever.
Actually this is unlikely to work with the latest plaso, since message is a virtual member of event which we no longer support in the event filter. See the bottom of https://plaso.readthedocs.io/en/latest/sources/user/Event-filters.html#how-do-event-filters-work
The best way to to filter on event log messages in event filters is use:
IOError: pywrc_resource_get_language_identifiers: unable to retrieve number of languages. libwrc_resource_read_value: unsupported resource type: 0x00000000. libwrc_resource_get_number_of_languages: unable to read resource value.
This looks the wrc library encounters an unsupported format issue. Could you indicate to me which version of libwrc/pywrc you are using. I'll see if I can reproduce this on Win10 when time permits.
by using "message contains" method? which is clever.
Actually this is unlikely to work with the latest plaso, since message is a virtual member of event which we no longer support in the event filter. See the bottom of https://plaso.readthedocs.io/en/latest/sources/user/Event-filters.html#how-do-event-filters-work
I can confirm this, it didn't work.
The best way to to filter on event log messages in event filters is use:
- message provider
- event ID + qualifiers
- and specific event string/data values
IOError: pywrc_resource_get_language_identifiers: unable to retrieve number of languages. libwrc_resource_read_value: unsupported resource type: 0x00000000. libwrc_resource_get_number_of_languages: unable to read resource value.
This looks the wrc library encounters an unsupported format issue. Could you indicate to me which version of libwrc/pywrc you are using. I'll see if I can reproduce this on Win10 when time permits.
./runtests.py gives me:
[OK] pywrc version: 20181203
pywrc_resource_get_language_identifiers has been deprecated and scripts have been updated to use new pywrc API. Give it a try and reopen if issue persists.
I'm trying to build new winevt-kb.db so that i could use plaso tagging analyser with sysmon logs. My assumption is that you can't add sysmon events to tag_windows.txt without rebuilding winevt-kb.db , is that correct? psort.py reports immediatly "killed" while using custom sysmon tags.
I have mounted filesystem under win10sysmon/image -path. I noticed that i'll have to use dfvfs version 20180831 or extract.py does not run at all, and if i used newer version of dfvfs, for some reason i'll get apfs related -errors which are not relevant at all(?)