etl-parser is a pure python 3 parser library for ETL Windows log files. ETL is the default format for [ETW](https://docs.microsoft.com/en-us/windows/win32/etw/event-tracing-portal). But It’s also the default format for the Kernel logger.
etl-parser has no system dependencies, and will work well on both Windows and Linux.
Since this format is not documented, we merged information from the blog of [Geoff Chappel](https://www.geoffchappell.com/) and reverse engineering activities conducted by Airbus CERT team.
What is ETL and why is it a pain to work with? Consider ETL as a container, like AVI is for video files. Reading ETL is similarly frustrating as reading an AVI file without the right codec.
etl-parser tries to solve this problem by including parsers for the following well known log formats: * ETW manifest base provider * TraceLogging * MOF for kernel log
Metadata
Release files for etl-parser 1.0.1
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| etl-parser-1.0.1.tar.gz | 856.8 kB | Details |
Release files / etl-parser-1.0.1.tar.gz
| Download URL | etl-parser-1.0.1.tar.gz |
|---|---|
| Size | 856.8 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
61a6b56cdaeddce976a54f15215a7d389ba5a663a56ae3ae00dc4fb8764854d7
|
|
BLAKE2b-256 checksum How to use checksums |
a5018b0e59f99423dabf4f9b9099979f4766dd5030211db3dd96d0e5b8977256
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/3.2.0 pkginfo/1.5.0.1 requests/2.24.0 setuptools/40.8.0 requests-toolbelt/0.9.1 tqdm/4.48.0 CPython/3.7.4
|