Skip to content

Creating Analyzers #1855

Discussion options

You must be logged in to vote

Hi @lucky-luk3,

Sorry for the late answer here.

  1. Correct, interface.BaseAnalyzer is the object to use
  2. I'll have a look at the broken page. In the mean time I would recommend simply getting the Event Logs from a Windows machine, running log2timeline and then importing them to Timesketch
  3. In order for your analyzer, or changes to it, to show up you have to restart Celery

Replies: 2 comments

Comment options

You must be logged in to vote
0 replies
Answer selected by jaegeral
Comment options

You must be logged in to vote
0 replies
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
3 participants