snovvcrash / usbrip

Tracking history of USB events on GNU/Linux
https://habr.com/ru/post/352254/
GNU General Public License v3.0
1.15k stars 112 forks source link

Wrong Timestamp error #14

Closed br-at-d closed 5 years ago

br-at-d commented 5 years ago

I always get "CRITICAL] Wrong timestamp format found in "/var/log/syslog"" when running this tool on an existing syslog file

snovvcrash commented 5 years ago

Please, provide an example of how your /var/log/syslog looks like (some random line).

br-at-d commented 5 years ago

I discovered this when doing your HTB challenge

Nov 9 09:56:57 kali kernel: [ 2556.806748] usb 2-1: Product: 180038A2EF71F12960D35319D3EF153 Nov 9 09:56:57 kali kernel: [ 2556.806749] usb 2-1: Manufacturer: 1336BA657773B419D3EE799258FF7 Nov 9 09:56:57 kali kernel: [ 2556.806750] usb 2-1: SerialNumber: 139DADB1430077E5C67ED03 Nov 9 09:56:57 kali kernel: [ 2556.806751] usb-storage 2-1:1.0: USB Mass Storage device detected Nov 9 09:56:57 kali kernel: [ 2556.806752] scsi host3: usb-storage 2-1:1.0 Nov 9 09:57:23 kali kernel: [ 2556.806753] usb 2-1: USB disconnect, device number 5

snovvcrash commented 5 years ago

Take a look at #7 and the new requirement for the syslog structure. Maybe you should use an older version? 😉