-
Notifications
You must be signed in to change notification settings - Fork 353
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
winevtx parser failing to extract creation time in not well-formed XML string #3595
Labels
Milestone
Comments
joachimmetz
added
enhancement
New or improved functionality
parsers
Issues related to parsers and parser plug-ins
labels
May 15, 2021
Related issue #442 |
joachimmetz
added a commit
to joachimmetz/plaso
that referenced
this issue
May 15, 2021
The culprit |
joachimmetz
added
the
close after review
Issue as outstanding pull request(s) and can be closed once these have been reviewed and merged
label
May 15, 2021
joachimmetz
added a commit
to joachimmetz/plaso
that referenced
this issue
May 15, 2021
4 tasks
joachimmetz
changed the title
Change winevtx parser to handle not well-formed XML string
winevtx parser failing to extract creation time in not well-formed XML string
May 15, 2021
joachimmetz
added a commit
that referenced
this issue
May 15, 2021
joachimmetz
removed
the
close after review
Issue as outstanding pull request(s) and can be closed once these have been reviewed and merged
label
May 15, 2021
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Labels
As flagged in #442 Windows Event Log XML is not necessary proper (well-formed) XML. This is causing the winevtx to error on certain evtx files. Change the parser to use an alternative approach to extract the TimeCreated value.
The text was updated successfully, but these errors were encountered: