Open Jissynacktiv opened 3 years ago
What version of Autopsy are you using? Yes, newer versions of Plaso without the 4n6time_sqlite output will not work. The plugin will have parts of it rewritten to support a different output method from psort.
I'm using Autopsy 4.18 (release version)
I will take a look at this as time permits.
Thanks! And regarding the self.local_settings.getSetting
problem, I think it impacts all of your other plugins functioning like this one.
Hi there,
having to use autopsy on Linux, I tried to use you Plaso modules. It seems they are both outdated.
My first attempt was to try the Plaso Module:
Looking at #33 I think pretty much all your plugins relying on
self.local_settings.getSetting
are impacted (thus not working anymore).I've never coded a plugin for autopsy so I don't know the inner mechanisms but debugging a bit pointed out that
PlasoSettingsWithUISettingsPanel(self.settings)
populates correctly thelocal_settings
class variable within:https://github.com/markmckinnon/Autopsy-Plugins/blob/103f59a36774bbe8b276fbdbf226ba385d24c619/Plaso/Plaso.py#L112-L116
But in the subsequent call,
local_settings
isNone
:https://github.com/markmckinnon/Autopsy-Plugins/blob/103f59a36774bbe8b276fbdbf226ba385d24c619/Plaso/Plaso.py#L143-L148
Because I don't really have the time to take a deep dive in autopsy code, my second attempt was to try to use the Plaso Import Module:
I first executed
log2timeline.py
on command line, then hardcoded paths inPlaso_Import.py
(as it faces the same problem as aformentioned) but encountered another problem:A look at
psort.py
shows that it does not support4n6time_sqlite
format anymore:psort.py
version being:I don't know how much autopsy core changed since this modules were coded but I guess some other similar problems may be encountered.