ingest_parsed_csv
Import pre-parsed CSV from Eric Zimmerman forensic tools for querying. Auto-detects CSV type by column headers to enable filtering and analysis.
Instructions
Import pre-parsed CSV from Eric Zimmerman tools (MFTECmd, PECmd, AmcacheParser, SrumECmd) for querying. Auto-detects CSV type by column headers. Useful when you already have parsed output from EZ tools.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| csv_path | Yes | Path to the CSV file | |
| csv_type | No | Type of CSV (auto-detected if not specified) | auto |
| filter_field | No | Field name to filter on (e.g., 'filename', 'sha1', 'executable') | |
| filter_value | No | Value to filter for (case-insensitive substring match) | |
| time_range_start | No | ISO format datetime - filter entries after this time | |
| time_range_end | No | ISO format datetime - filter entries before this time | |
| limit | No | Maximum number of entries to return |