Thanks for the insight I was unaware of the winiis parser. I was under the impression that by not specifying a parser it would try everything or parse everything. The "basic-usage" paragraph on the linked page gave me that understanding [https://plaso.readthedocs.io/en/latest/sources/user/Using-log2timeline.html](url). This method is also covered in the SANS 508 class as an "all-inclusive" approach. <br>
When I tried using the "winiis" parser I got an error. I edited the /usr/share/plaso/presets.yaml file modifying the list of parsers included with the win7_slow to have the winiis in the list like the others.
I invoke the command using the following syntax log2timeline.py --workers 45 --parsers "win7_slow" --storage-fime ./Servername_parsers.plaso ./ServernameOSdisk.vhd . That command gives me an error "Unknown Parser or Plugin names in element(s): "winiis". After which processing is aborted. Is this an add-on module?
When I tried using the "winiis" parser I got an error. I edited the /usr/share/plaso/presets.yaml file modifying the list of parsers included with the win7_slow to have the winiis in the list like the others.
![image](https://github.com/log2timeline/plaso/assets/44442120/4a9f25e1-2a67-4fe2-a983-67204ce8ef23)
I invoke the command using the following syntax log2timeline.py --workers 45 --parsers "win7_slow" --storage-fime ./Servername_parsers.plaso ./ServernameOSdisk.vhd . That command gives me an error "Unknown Parser or Plugin names in element(s): "winiis". After which processing is aborted. Is this an add-on module?
Originally posted by @b1draper in https://github.com/log2timeline/plaso/issues/4813#issuecomment-1973721701