log2timeline / l2tscaffolder

Scaffolders for bootstrapping development of open source forensics tools.
http://l2tscaffolder.readthedocs.io/
Apache License 2.0
6 stars 9 forks source link

add support for plaso dsv parser generation #73

Open joachimmetz opened 5 years ago

joachimmetz commented 5 years ago

For plaso support generating a DSV-based (delimiter separated) parser

kiddinn commented 5 years ago

The DSV parser: https://github.com/log2timeline/plaso/blob/master/plaso/parsers/dsv_parser.py

And a sample parser that uses the DSV parser: https://github.com/log2timeline/plaso/blob/master/plaso/parsers/mactime.py

Mactime can probably be used as the basis for the template.