evtx_search
Search Windows Event Logs (EVTX files) to filter events by time, Event ID, keywords, or provider for forensic analysis.
Instructions
Search events from EVTX file. Filter by time, Event ID, keywords, provider.
Input Schema
TableJSON Schema
| Name | Required | Description | Default |
|---|---|---|---|
| evtx_path | Yes | ||
| event_ids | No | ||
| start_time | No | ISO format datetime | |
| end_time | No | ||
| contains | No | ||
| not_contains | No | ||
| provider | No | ||
| limit | No |