ceramicskate0/SWELF
Simple Windows Event Log Forwarder (SWELF). Its easy to use/simply works Log Forwarder and EVTX Parser. Almost in full release here at https://github.com/ceramicskate0/SWELF/releases/latest.
C#AGPL-3.0
Pinned issues
Issues
- 0
SPLUNK .Net SDKs now out
#142 opened by ceramic-skate0 - 0
- 0
Add new sysmon event ID's from 2018 to today
#141 opened by ceramicskate0 - 0
.cpl
#140 opened by ceramic-skate0 - 1
Add to searchs.txt for cmdline
#138 opened by ceramic-skate0 - 1
Add to search,txt
#137 opened by ceramic-skate0 - 0
- 1
Update SWELF_SPLUNK_DASHBOARD.xml
#135 opened by ceramicskate0 - 0
SWELF will log the full URL to the error log of application when it is unable to access it
#117 opened by ceramicskate0 - 1
SWELF CPU usage to High in 0.5.0.3
#99 opened by ceramicskate0 - 0
Not all Errors being recorded
#134 opened by ceramicskate0 - 1
- 0
SWELF 0.6.1.0 Crash under certain conditions for SEND_Errors_To_Central_Location()
#133 opened by ceramicskate0 - 0
Send Logs in JSON Format
#132 opened by ceramicskate0 - 0
Add feature for tcp TLS connection
#106 opened by ceramicskate0 - 0
When SWELF reads in EventLogs it stores compmressed but also in cleartext
#101 opened by ceramicskate0 - 0
Error log default output has typo
#125 opened by ceramicskate0 - 0
Add App_Config option to parse out sysmon
#131 opened by ceramicskate0 - 1
INCORRECT ERROR everyrun Severity=critical MethodInCode=SEC_Check_Failed() Message=SEC_Check Fail the reg hostname != to the config hostname for log_collector1. Possible SWELF config integrity issue.
#105 opened by ceramicskate0 - 0
ips.txt and hash.txt file name is backwards
#110 opened by ceramicskate0 - 0
- 0
- 1
- 3
Add sysmon integ check feature addition
#114 opened by ceramicskate0 - 0
- 0
- 3
Send Logs over tcp SSL/TLS
#129 opened by ceramicskate0 - 5
Lock down install dir for SWELF
#109 opened by ceramicskate0 - 0
After Code refactor UPDATE DOCS
#127 opened by ceramicskate0 - 1
- 1
Add msbuild IOC to searchs.txt
#122 opened by ceramicskate0 - 1
ADD to template
#108 opened by ceramicskate0 - 1
add Software\Classes\AppX82a6gwre4fdg3bt635tn5ctqjf8msdd2\Shell\open\command
#115 opened by ceramicskate0 - 1
add eventid 1042
#119 opened by ceramicskate0 - 1
Add DelegateExecute reg value for UAC bypasses
#121 opened by ceramicskate0 - 1
Add forfiles.exe
#123 opened by ceramicskate0 - 1
add C:\Windows\System32\wsreset.exe
#116 opened by ceramicskate0 - 0
- 0
Add MSSQL log event ID's
#120 opened by ceramicskate0 - 0
Default files created during install appear to have _ in them and some dont.
#102 opened by ceramicskate0 - 2
SWELF 1st run takes 5 runs to setup
#100 opened by ceramicskate0 - 3
Current version in test has issue with wrong search term in eventlog on system
#104 opened by ceramicskate0 - 0
- 0
- 0
Redo the "not_in_log" search logic
#93 opened by ceramicskate0 - 1
Fresh install not working
#95 opened by ceramicskate0 - 1
Add reg key for wdigest
#96 opened by ceramicskate0 - 1
- 1
Search_Command that will search only network connections for hits on IP or part of/whole match of Domain/TLD
#90 opened by ceramicskate0 - 0