Chainsaw: dump records
chainsaw_dumpConvert evidence files or directories into a JSON record stream, returning a paged result handle to inspect complete records after narrowing a hunt.
Instructions
Convert every record in the evidence to JSON under a result handle.
Wraps chainsaw dump. Use it when a hunt or search has narrowed the scope to one
or two files and you need the complete record stream; page through the handle.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| paths | Yes | Evidence files or directories under an allowed root. | |
| fields | No | Dotted paths or shorthand names to project in the inline preview; see chainsaw_result_fields. Omit for the standard shorthand columns. | |
| preview | No | Records to include inline. | |
| extension | No | Only dump this extension. | |
| skip_errors | No | Continue past unreadable files. | |
| load_unknown | No | Try to parse unidentified files. |