Chainsaw: search events
chainsaw_searchSearch Windows event logs and evidence for keywords, regular expressions, or tau field expressions to find matching events summarized by host, channel, event ID, and hour.
Instructions
Search evidence for keywords, regular expressions, or tau field expressions.
Runs chainsaw search; each matching document is stored under a result handle and
summarised by host, channel, event ID and hour. Use tau expressions to pivot on a
specific field (for example a LogonId, process GUID, or user) after a hunt.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| tau | No | Tau field expressions such as 'Event.System.EventID: =4104' or 'Event.EventData.Image: i*mimikatz*'. Combined with AND unless match_any. | |
| paths | Yes | Evidence files or directories under an allowed root. | |
| fields | No | Dotted paths or shorthand names to project in the inline preview; see chainsaw_result_fields. Omit for the standard shorthand columns. | |
| preview | No | Events to include inline. | |
| to_time | No | Drop documents newer than YYYY-MM-DDTHH:MM:SS. | |
| patterns | No | String or regular-expression patterns matched against the whole document. All must match unless match_any is true. | |
| timezone | No | IANA timezone for output. | |
| extension | No | Only load this extension. | |
| from_time | No | Drop documents older than YYYY-MM-DDTHH:MM:SS. | |
| match_any | No | Match a document when any one of the patterns matches (and, separately, any one of the tau expressions) instead of requiring all of them. Patterns and tau expressions are always combined with AND. | |
| ignore_case | No | Case-insensitive pattern matching. | |
| skip_errors | No | Continue past unreadable files. | |
| load_unknown | No | Try to parse unidentified files. | |
| timestamp_field | No | Field holding the timestamp when from_time/to_time are set. Default for EVTX: Event.System.TimeCreated_attributes.SystemTime. |