-
Notifications
You must be signed in to change notification settings - Fork 32
Open
Description
Hi there! Great tool, I got it to ingest Security.evtx and Application.evtx, but when I try to ingest System.evtx I always get a parsing error. I have a very basic understanding of programming logic, not nearly that about Python - I got most of it to work with your step-by-step on Dragos' blog and some Google-fu. How can I help diagnose, maybe even help correct, this parsing error?
oh! Found one on Elasticsearch's logs:
Caused by: java.lang.IllegalArgumentException: object field starting or ending with a [.] makes object resolution ambiguous: [.NETServiceMethod]
And rolling up the log, it seems every parsing error is caused because of this error.
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
No labels