For a client i need to parse a few gigabytes of ms eventlogs in .evtx format.
This to build a timeline of events. Is there an ongoing effort to make this possible with rocknsm ? to me it is a feature missing everywhere. I’ve looked at logontracer and timesketch which both are promising.
Br,
Joris