-
Notifications
You must be signed in to change notification settings - Fork 200
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Bug: metrics, logon-summary and csv-timline show different total event records #1105
Comments
The cause of the problem has been identified. The difference between metrics and csv-timeline is that the record count in metrics was counting the number of records after channel name and EID filtering. Filtered record is following, filtered by Event>System>Channel is not found.
|
…t option is set in logon-summary command #1105
@YamatoSecurity There are two ways to fix it: 1. for 2. it affects the % of metrics and logon-summary display; and 2. for 3. it affects the % of logon-summary display. If you want to avoid affecting the % notation, need to separate the display variables from the aggregate variables. (In #1106, This adjusted)
|
…ted records in metrics and logon-summary #1105
When running the
metrics
,logon-summary
andcsv-timeline
commands, the total event records count will be different.Test:
./hayabusa-2.6.0-mac-intel metrics -d ../hayabusa-sample-evtx -o test.csv -C
./hayabusa-2.6.0-mac-intel logon-summary -d ../hayabusa-sample-evtx -o test.csv -C
./hayabusa-2.6.0-mac-intel csv-timeline -d ../hayabusa-sample-evtx -o test.csv -C
Results:
logon-summary
: 94950metrics
: 47475csv-timeline
: 47,476Also, there are no commas displayed with
logon-summary
andmetrics
so it is difficult to read the number when the event record count is in the millions. (ie.234723049
) So I would like to add commas like incsv-timeline
(->234,723,049
)@hitenkoku Could you look at this whenever you have time? (I think you are the most knowledgable about this)
The text was updated successfully, but these errors were encountered: