markmckinnon/Autopsy-Plugins

Process_EVTX plugin: filter by "contains" operator

beyefendi opened this issue · 0 comments

It would be better to have a "contains" operator for filtering Evet Detail.
For example, one needs to find event logs related to a specific process name.