Extracting Event Logs
When event logs are analyzed, the most common approach is to export logs and then review them on the forensics workstation. There are a few reasons for such an approach. Often, we need to analyze a few event logs (for example, System, Security, and Application) from several workstations and Domain Controller. So, it is very convenient to have all event log files in one place. Also, many forensics tools not enough good work with event logs.
There are two main approaches to export event logs:
- Live systems
- Offline systems
Both of them have their own set of features; let's see what they are.
Live systems
While working with live systems, remember that event log files are always used, which creates some additional challenges. One way of exporting data from a live system is using Event Viewer. If you right-click on the event log file, the
Save All Events As...
option will appear. Logs can be saved in various formats, including
.evtx
, .csv
, .xml
, or .txt
...