Evtxtoelk
A lightweight tool to load Windows Event Log evtx files into Elasticsearch.
Install / Use
/learn @dgunter/EvtxtoelkREADME
EvtxtoElk
A lightweight tool to load Windows Event Log evtx files into Elasticsearch.
Examples
We wrote a blog on basic usage here https://dragos.com/blog/20180717EvtxToElk.html
More details will be posted here shortly.
