Parse the EVTX file and output it in JSON format.
go get -u github.com/0xrawsec/golang-evtx/evtx
go build evtx2jsons.go
$ evtx2jsons.exe -i Security.evtx
-d string
This option is a short version of "--directory" option.
-directory string
Specifies the destination directory for the converted files.
(default "output")
-i string
This option is a short version of "--input" option.
-ids string
Specifies the event ID you want to output JOSN files.
Use "," to separate multiple IDs.
(default All Event IDs)
-input string
This option is required.
Specifies the EVTX file you want to convert to JSON file.
-
Basic Usage
$ evtx2jsons.exe -i Security.evtx
-
Specify the event IDs you want to output.
$ evtx2jsons.exe -i Security.evtx -ids 4624,4625,1102
-
Specify the destination directory.
$ evtx2jsons.exe -i Security.evtx -d output/jsons