run_log2timeline
Creates a forensic timeline from a Windows partition by running log2timeline, outputting a .plaso file for analysis.
Instructions
Start log2timeline timeline creation (long-running). Poll with get_timeline_status.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| output_file | No | Path for .plaso output file | |
| partition | No | Block device of Windows partition |