Chainsaw: EVTX overview
chainsaw_analyse_evtxAnalyse EVTX files to summarise channel, provider, and event-ID coverage, showing missing metadata and parsing gaps for Windows event log triage.
Instructions
Summarise EVTX channel, provider and event-ID coverage, including missing metadata.
Runs native analysis and a streamed dump pass. The inline per_file list is a bounded preview; page handle for full files, coverage_handle for identity counts, and diagnostics.handle for all runner messages. Missing Channel in ETW is not evidence of corruption, and successful exit does not establish complete parsing.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| paths | Yes | EVTX files or directories under an allowed root. | |
| skip_errors | No | Continue past unreadable files. |