EricZimmerman/evtx

error parse evtx as the map is empty

naderhabbbab opened this issue · 3 comments

im getting the following error when parse win evt as some logs are empty

Correct the errors and try again. Exiting

C:\Forensic Program Files\Zimmerman\EvtxExplorer\Maps\WindowsDefender_5007.map had validation errors:
'Provider' must not be empty.

Correct the errors and try again. Exiting

The following maps had errors. Scroll up to review errors, correct them, and try again.

C:\Forensic Program Files\Zimmerman\EvtxExplorer\Maps\System-Audit-CVE_2.map had validation errors:
'Provider' must not be empty.

You have outdated and/or duplicate maps. Delete entire Maps folder and resync with EVTXECmd.exe --sync. Try again after that. Report back please.

@naderhabbbab were you able to figure this out?