Closed jsaspo closed 3 years ago
I now see that Issue #69 was recently closed with this same log, event ID, and error. Was there a fix?
the reporter closed the issue without any further information. im not aware of any fix.
interesting that its the same log/id/error. i'm not able to provide too much support for this parser these days, but perhaps i can take a peek and attempt a fix if its obvious.
taking a hint from this post, i've found that Python on Windows handles dates differently than on Linux (i guess thats probably not a surprise to anyone). specifically, a "zero date" (like the 1601-01... one you show above) cannot be represented correctly:
I'll update the date parsing code to better handle this case on Windows
although... i think this should be fixed in master thanks to 28095cc24fdd972531b67edc8aa80bdf83c403ef and a5eac06a44c232cca509d8a5308e61c3989faf99
do you have a moment to try out the code in master? if it works for you, i'll cut a new release and upload to pypi
Thank you for the quick response. The code in master worked great! No issue, buzzed through the entire System.evtx.
I should have looked into this further. I used pip install initially and didn't realize the versions are different. I'm a little green on Git/PyPi.
Awesome, thanks again.
@williballenthin
Closing as it appears this is resolved in master.
Using evtx_dump.py to dump several .evtx logs successfully. However, I have one System.evtx that produces the following error mid-dump (the XML at the top is the last successful record "1190" before the dump errors out:
I'm assuming this is an issue with the following record "1191". Here is the Event Viewer display for that record:
Here is the evtx_record_strcture.py dump of that record: