Comments (4)
So I'm guessing I cannot open the file because it is too large...
Do you know of a easy way to reduce the supertimeline it creates and only have a csv that contains a certain date range? The 2GB csv timeline it creates is unable to open and when I went to import the data into the SANS Color Timeline, I was only able to copy in a portion of the data because it is so huge.
Also, random question about the date ranges in the timeline output...Why am I seeing years prior to 1970, such as 1906, 1601, 1831, and 1830?
from cdqr.
The purpose of the Reports folder was to help break the file up into
smaller chunks. Have you checked the reports found in the Reports folder?
I would recommend using grep to isolate date ranges out of the
SuperTimeLine.
There are many reasons that those dates could show up and the are too
varied and situation specific to be able to give an accurate answer. That
said, start by identifying what parser provided that data and research what
the date and time fields mean for that entry.
On Fri, Apr 22, 2016, 1:44 PM Zach [email protected] wrote:
So I'm guessing I cannot open the file because it is too large...
Do you know of a easy way to reduce the supertimeline it creates and only
have a csv that contains a certain date range? The 2GB csv timeline it
creates is unable to open and when I went to import the data into the SANS
Color Timeline
https://digital-forensics.sans.org/blog/2012/01/25/digital-forensic-sifting-colorized-super-timeline-template-for-log2timeline-output-files,
I was only able to copy in a portion of the data because it is so huge.Also, random question about the date ranges in the timeline output...Why
am I seeing years prior to 1970, such as 1906, 1601, 1831, and 1830?—
You are receiving this because you are subscribed to this thread.
Reply to this email directly or view it on GitHub
#3 (comment)
from cdqr.
The reports folder is good if you know exactly what you are looking for, but seeing the context around the particular times is much easier done when all the information is in one file.
from cdqr.
One way to make it easier to find the things you're looking for is to sort on column P, "format" in either the SuperTimeLine or the Reports. This gives you the ability to sort by parser name and should greatly speed up your ability find what you're looking for.
from cdqr.
Related Issues (20)
- Add Splunk support HOT 2
- Database Filename Issues on Windows HOT 6
- Process not completing HOT 3
- Add support to accept defaults HOT 2
- CDQR Parsing when Timesketch Elastic Search Not running HOT 4
- Manage Timeout HOT 1
- add skip compressed file parameter HOT 6
- Error when Results folder already exists HOT 2
- What's the right way to run dead box collection? HOT 4
- cdqr breaks on unicode characters HOT 5
- Bypass pause at the end of CDQR processing HOT 1
- Add the ability to use plaso filters HOT 1
- Make MFT and USNJRNL Optional HOT 1
- Error when Unknown parser or plugin names HOT 3
- Can't parse zip if hostname contains '-' HOT 13
- Unknown parser or plugin names in element(s): "bash" HOT 3
- ZIP Not Found HOT 1
- CDQR does not parse Windows Event correctly to Kibana HOT 2
- Execution of cdqr.exe requires log2timeline.exe HOT 9
- log2timeline.py: error: unrecognized arguments: Results/artifacts/host1 HOT 1
Recommend Projects
-
React
A declarative, efficient, and flexible JavaScript library for building user interfaces.
-
Vue.js
🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.
-
Typescript
TypeScript is a superset of JavaScript that compiles to clean JavaScript output.
-
TensorFlow
An Open Source Machine Learning Framework for Everyone
-
Django
The Web framework for perfectionists with deadlines.
-
Laravel
A PHP framework for web artisans
-
D3
Bring data to life with SVG, Canvas and HTML. 📊📈🎉
-
Recommend Topics
-
javascript
JavaScript (JS) is a lightweight interpreted programming language with first-class functions.
-
web
Some thing interesting about web. New door for the world.
-
server
A server is a program made to process requests and deliver data to clients.
-
Machine learning
Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.
-
Visualization
Some thing interesting about visualization, use data art
-
Game
Some thing interesting about game, make everyone happy.
Recommend Org
-
Facebook
We are working to build community through open source technology. NB: members must have two-factor auth.
-
Microsoft
Open source projects and samples from Microsoft.
-
Google
Google ❤️ Open Source for everyone.
-
Alibaba
Alibaba Open Source for everyone
-
D3
Data-Driven Documents codes.
-
Tencent
China tencent open source team.
from cdqr.