You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Describe the bug
When json-timeline is used with --timeline-start, it shows no detections so no file is written.
Also, --timeline-end does not work correctly with json-timeline.
Step to Reproduce ./hayabusa-2.7.0-dev json-timeline -d ../hayabusa-sample-evtx -C -o test.json --timeline-start "2018-01-01 00:00:00 +00:00"
This gives 0 detections and 0 file size.
However, when I run the the same command with csv-timeline, it works: ./hayabusa-2.7.0-dev csv-timeline -d ../hayabusa-sample-evtx -C -o test.csv --timeline-start "2018-01-01 00:00:00 +00:00"
Total | Unique detections: 14,001 | 521 and 20 MB file get outputted.
Also, when using --timeline-end with json-timeline, a file gets outputted but it does not filter out events after the date.
For example the following command: ./hayabusa-2.7.0-dev csv-timeline -d ../hayabusa-sample-evtx -C -o test.csv --timeline-end "2018-01-01 00:00:00 +00:00"
gives this result: Total | Unique detections: 18,238 | 189
but ./hayabusa-2.7.0-dev json-timeline -d ../hayabusa-sample-evtx -C -o test.json --timeline-end "2018-01-01 00:00:00 +00:00"
gives this result: Total | Unique detections: 32,239 | 567 (same is when --timeline-end is not used)
Environment (please complete the following information):
OS: mac
hayabusa version: 2.7.0-dev but the bug seems to be in older versions as well. (Same behavior in 2.5.0 and 2.6.0)
The text was updated successfully, but these errors were encountered:
@hitenkoku Can you take a look at this?
Describe the bug
When
json-timeline
is used with--timeline-start
, it shows no detections so no file is written.Also,
--timeline-end
does not work correctly withjson-timeline
.Step to Reproduce
./hayabusa-2.7.0-dev json-timeline -d ../hayabusa-sample-evtx -C -o test.json --timeline-start "2018-01-01 00:00:00 +00:00"
This gives 0 detections and 0 file size.
However, when I run the the same command with
csv-timeline
, it works:./hayabusa-2.7.0-dev csv-timeline -d ../hayabusa-sample-evtx -C -o test.csv --timeline-start "2018-01-01 00:00:00 +00:00"
Total | Unique detections: 14,001 | 521
and 20 MB file get outputted.Also, when using
--timeline-end
withjson-timeline
, a file gets outputted but it does not filter out events after the date.For example the following command:
./hayabusa-2.7.0-dev csv-timeline -d ../hayabusa-sample-evtx -C -o test.csv --timeline-end "2018-01-01 00:00:00 +00:00"
gives this result:
Total | Unique detections: 18,238 | 189
but
./hayabusa-2.7.0-dev json-timeline -d ../hayabusa-sample-evtx -C -o test.json --timeline-end "2018-01-01 00:00:00 +00:00"
gives this result:
Total | Unique detections: 32,239 | 567
(same is when--timeline-end
is not used)Environment (please complete the following information):
The text was updated successfully, but these errors were encountered: