error parse evtx as the map is empty
naderhabbbab opened this issue · 3 comments
naderhabbbab commented
im getting the following error when parse win evt as some logs are empty
Correct the errors and try again. Exiting
C:\Forensic Program Files\Zimmerman\EvtxExplorer\Maps\WindowsDefender_5007.map had validation errors:
'Provider' must not be empty.
Correct the errors and try again. Exiting
The following maps had errors. Scroll up to review errors, correct them, and try again.
C:\Forensic Program Files\Zimmerman\EvtxExplorer\Maps\System-Audit-CVE_2.map had validation errors:
'Provider' must not be empty.
AndrewRathbun commented
You have outdated and/or duplicate maps. Delete entire Maps folder and resync with EVTXECmd.exe --sync. Try again after that. Report back please.
AndrewRathbun commented
@naderhabbbab were you able to figure this out?
naderhabbbab commented
Yes it’s fixed thank you
On Tue, 12 Jan 2021 at 6:34 AM Andrew Rathbun ***@***.***> wrote:
@naderhabbbab <https://github.com/naderhabbbab> were you able to figure
this out?
—
You are receiving this because you were mentioned.
Reply to this email directly, view it on GitHub
<#90 (comment)>,
or unsubscribe
<https://github.com/notifications/unsubscribe-auth/AAJ5AN2J45D2EOWICQIGIRDSZO7NNANCNFSM4V5BKHJQ>
.
--
Mobile