Chainsaw: log gap analysis
chainsaw_analyse_gapsDetect chronological or EventRecordID discontinuities in Windows EVTX logs to flag timeline gaps for investigation and correlation with acquisition history.
Instructions
Detect chronological or EventRecordID discontinuities for investigation.
Curated or filtered samples naturally contain gaps; these are not proof of deletion. Correlate with acquisition history and Security 1102 / System 104.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| limit | No | Maximum gaps to return. | |
| paths | Yes | EVTX files or directories under an allowed root. | |
| to_time | No | Analyse up to YYYY-MM-DDTHH:MM:SS. | |
| timezone | No | IANA timezone for output. | |
| from_time | No | Analyse from YYYY-MM-DDTHH:MM:SS. | |
| time_gaps | No | Detect chronological gaps. | |
| skip_errors | No | Continue past unreadable files. | |
| record_id_gaps | No | Detect EventRecordID gaps. | |
| min_time_gap_minutes | No | Flag time gaps at least this long. |