Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Export Event evtx Logs as CSV #113

Open
jlgandy2 opened this issue Nov 27, 2018 · 5 comments
Open

Export Event evtx Logs as CSV #113

jlgandy2 opened this issue Nov 27, 2018 · 5 comments

Comments

@jlgandy2
Copy link

Would be nice to have the .evtx logs as CSV to put them in Excel to be able to use filtering like we can with the MSDT outputs.

@dl2n
Copy link
Collaborator

dl2n commented Nov 28, 2018 via email

@jlgandy2
Copy link
Author

Yeah I see your point. Output size would be more, but still would love to see these event logs in CSV like the old tools SDP and MSDT. The evtx files take way too long to open one by one and require DLL's the client systems do not have to decode the Message data. Opening multiple evtx files to correlate them is near impossible with Message Analyzer it so slow. I have tried post processing with PowerShell get-WinEvent, but this is event worse from how long it takes to convert them. Logparser is by far the fastest to convert evtx to csv but it does not support the new roles like S2D and SDN. I even reached out to the original developer of Logparser to see if he could update it but he said "probably it's a new EventSource registration mechanism not supported by LogParser". Is there another solution? Could we add a switch if you wanted the evtx files converted to CSV you could add it and it would not be the default functionality?

@dl2n
Copy link
Collaborator

dl2n commented Nov 28, 2018 via email

@jlgandy2
Copy link
Author

jlgandy2 commented Dec 13, 2018

Found the original script used by the MSDT and SDP tools to export evtx to CSV. The script name is GetEvents.VBS and was Author: Andre Teixeira - [email protected]. It uses wevtutil which is a native tool for exporting event logs to CSV or other formats. Does this help?

@dl2n
Copy link
Collaborator

dl2n commented Dec 14, 2018 via email

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants