run_psort
Query a Plaso timeline to retrieve forensic events sorted by time, with optional date range filters and a limit on number of events returned.
Instructions
Query the plaso timeline. Returns events sorted by time.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| filter_query | No | e.g. 'date > 2016-10-01 AND date < 2016-11-05' | |
| top_n | No | Max events to return (default 100) |