Skip to content

Bash Script to generate plaso file from E01 using log2timeline specifically for use with Timesketch

Notifications You must be signed in to change notification settings

domlobo/generate-plaso

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

4 Commits
 
 
 
 

Repository files navigation

generate-plaso

Bash Script to generate plaso file from E01 using log2timeline

When generating Plaso files for ingesting data into Timesketch, the version of log2timeline needs to match the version used by timesketch to prevent import errors. The easiest way to ensure the versions match is to use the log2timeline script that is in the timesketch image you are running. This script automates the process of doing this.

Example usage:

sh ./generate-plaso.sh /path/to/evidence.E01

About

Bash Script to generate plaso file from E01 using log2timeline specifically for use with Timesketch

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published

Languages