Skip to content
Discussion options

You must be logged in to vote

I've tested again and can confirm that 2.3.110-20220407 in IMPORT mode does include so-import-evtx for me:

[doug@securityonion ~]$ cat /etc/soversion
2.3.110
[doug@securityonion ~]$ ls -alh /usr/sbin/so-import-*
-rwxr-xr-x. 1 root root 5.1K Apr 20 11:34 /usr/sbin/so-import-evtx
-rwxr-xr-x. 1 root root 7.4K Apr 20 11:34 /usr/sbin/so-import-pcap

Is it possible you accidentally installed an older ISO image?

What is the output of the following?

cat /etc/soversion

Have you tried a second installation of 2.3.110-20220407 in IMPORT mode?

Any word on a mass import? ( I have 60 syslog text files & 20 evtx's to import)

Once you get so-import-evtx working, you should be able to use wildcards to …

Replies: 3 comments 1 reply

Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
1 reply
@wilmerism
Comment options

Answer selected by dougburks
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
2 participants