Time Offset for .evtx files

Posted on May 15, 2021 at 8:26 PM
Hi Toby,

I just wanted to apply a time offset to an windows event log file (.evtx). However the menu item is disabled for this file.
Is this by intention or a bug?

Regards
Andreas
Posted on May 16, 2021 at 6:50 AM
Hi Andreas,

This is by design, but it is probably something that we need to revisit.  The issue here is that binary log files are processed differently from other log file types and support for post-processors (like the Time Offset) was never added.  Currently, the EVTX reader is the only binary parser that ships with LogViewPlus.

We currently have a version of LogViewPlus in BETA, the release after this one is going to be focused on improved parsing.  I think it is a good time to review the post processor support.

Thanks for bringing this issue to our attention.

Toby
Posted on Jun 7, 2021 at 8:31 AM
Hi Andreas,

I just wanted to let you know that we have now released LogViewPlus v2.5.19 as a beta release. This release adds time offset support to log readers and data sources (including EVTX files).

Hope that helps.  Thanks for bringing this issue to our attention!

Toby
Posted on Jun 8, 2021 at 6:04 PM
Hi Toby,

I used the new feature today in an analysis and it worked!

Thanks!

Andreas
Posted on Jun 8, 2021 at 6:29 PM
Glad that helped Andreas - thanks for letting me know!

Toby

This topic is closed and cannot receive new replies.