Skip to content
master
Switch branches/tags
Code

Latest commit

 

Git stats

Files

Permalink
Failed to load latest commit information.
Type
Name
Latest commit message
Commit time
 
 
 
 
 
 
 
 

Event2Timeline

Event2Timeline is a free tool based on D3js to graph Microsoft Windows sessions events. It parses both EVTX event logs from post Vista systems (Vista, Windows 7, Windows 8), and CSV exports of the legacy EVT log files.

How to install

  • Clone the git repository

  • Create a virtual environment with virtualenv and activate it (optional)

  • Install requirements with pip install -r requirements.txt

Alternatively:

How to run

For old EVT files:

  • Convert your eventlogs to CSV format. You can use the free Microsoft Log Parser 2.2.

  • Run event2timeline.py -c -f csv_filename.csv

  • Open timeline/timeline-sessions.html in your favorite browser

The timeline is divided into two parts: a large timeline, and a smaller one. You can select what events to display on the large timeline by dragging your mouse on the smaller timeline. Events encompassed in the selected timespan will be displayed on the bigger timeline.

Post-Vista EVTX files are supported. Just run event2timeline.py -e -f Security.evtx

Example

Rendering example

License

This work is licensed under the GPL License http://www.gnu.org/licenses/gpl.txt

About

Simple Microsoft Windows sessions event logs visualization

Resources

License

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published