aarislarsen
aarislarsen
This still appears to be broken, and the suggested workaround does not appear to work. Using ami-0c444654c3cb65700, resulting in `Permission denied (publickey)` when attempting to SSH with the `sansforensics` user.
[sample logs.zip](https://github.com/user-attachments/files/16491276/sample.logs.zip) [20240805055604_EvtxECmd_Output (2).zip](https://github.com/user-attachments/files/16491315/20240805055604_EvtxECmd_Output.2.zip) Attached here are the raw logs as well as the converted ones. The ones that aren't being parsed are 4624 and 4625, so I don't think...
@mpilking thank you for this, this works like a charm. It's slower by a factor of three, but if it's parsing more event types then I guess that makes sense,...