GrokEVT

  802 downloads
0.5.0 GPL (GNU General Public License)    
2.3/5 16
A collection of scripts for reading Windows event log files

description

download

specifications

changelog

GrokEVT is a collection of scripts built for reading Windows NT event log files. GrokEVT is released under the GNU GPL, and is implemented in Python. GrokEVT is loosely based on the PHP script and documentation provided by Jamie French.

Currently the scripts work together on one or more mounted Windows partitions to extract all information needed (registry entries, message templates, and log files) to convert the logs to a human-readable format.
read more   
Last updated on June 21st, 2011
1  
GrokEVT

0 User reviews so far.

SUBMIT