Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Unknown parser or plugin names in element(s): "bash" #54

Closed
nannib opened this issue Oct 29, 2019 · 3 comments
Closed

Unknown parser or plugin names in element(s): "bash" #54

nannib opened this issue Oct 29, 2019 · 3 comments

Comments

@nannib
Copy link

nannib commented Oct 29, 2019

Hi,
I have log2timeline plaso - log2timeline version 20190916 and CDQR 5.1.0 in Ubuntu 18.04
I got this error:
2019-10-29 10:27:14,880 [ERROR] (MainProcess) PID:2845 Unknown parser or plugin names in element(s): "bash" of parser filter expression: bash,bencode,binary_cookies,chrome_cache,chrome_preferences,czip,esedb,esedb/msie_webcache,filestat,firefox_cache,java_idx,lnk,mcafee_protection,msiecf,olecf,opera_global,opera_typed_history,pe,plist/safari_history,prefetch,recycle_bin,recycle_bin_info2,sccm,sophos_av,sqlite,sqlite/chrome_27_history,sqlite/chrome_8_history,sqlite/chrome_autofill,sqlite/chrome_cookies,sqlite/chrome_extension_activity,sqlite/firefox_cookies,sqlite/firefox_downloads,sqlite/firefox_history,symantec_scanlog,winevt,winevtx,winfirewall,winjob,winreg,zsh_extended_history

when I launch:
./cdqr.py disk.dd

@orlikoski
Copy link
Owner

orlikoski commented Oct 29, 2019

CDQR 5.1.0 hasn't been tested with Plaso 20190916 and that error is due to a parser name that isn't supported inside of Plaso. Something probably changed with Plaso between the versions that is causing it to error in that way. Try using the Plaso v20190708 as that is the version 5.1.0 supports

@nannib
Copy link
Author

nannib commented Oct 29, 2019

If you are thinking to release a compatible version of CDQR, I could wait ;-)

@orlikoski
Copy link
Owner

I do not have any plans to write a new version myself. Please see more details in my Open Letter to the users of Skadi, CyLR, and CDQR

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants