Skip to main content

Plaso (Plaso Langar Að Safna Öllu) - super timeline all the things

Plaso (Plaso Langar Að Safna Öllu), or super timeline all the things, is a Python-based engine used by several tools for automatic creation of timelines. Plaso default behavior is to create super timelines but it also supports creating more targeted timelines.

These timelines support digital forensic investigators/analysts, to correlate the large amount of information found in logs and other files found on an average computer.

A longer version

The initial purpose of Plaso was to collect all timestamped events of interest on a computer system and have them aggregated in a single place for computer forensic analysis (aka Super Timeline).

However Plaso has become a framework that supports:

  • adding new parsers or parsing plug-ins;
  • adding new analysis plug-ins;
  • writing one-off scripts to automate repetitive tasks in computer forensic analysis or equivalent.

And is moving to support:

  • adding new general purpose parses/plugins that may not have timestamps associated to them;
  • adding more analysis context;
  • tagging events;
  • allowing more targeted approach to the collection/parsing.

Also see

Metadata

Release files for plaso 20260720

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for plaso 20260720
File Size Uploaded
plaso-20260720.tar.gz 2.9 MB Details

Built distribution (wheel)

Table of built distributions (wheels) for plaso 20260720
File Interpreter ABI Platform
plaso-20260720-py3-none-any.whl Python 3 none any Details

Total release size: 5.9 MB

Release files / plaso-20260720.tar.gz

Download URL plaso-20260720.tar.gz
Size 2.9 MB
Tags Source
SHA-256 checksum
How to use checksums
c868892d9f203a3d002a907ef1942344ab06706412f32aefef856940a371927e
BLAKE2b-256 checksum
How to use checksums
c37c738f884fdf42a23744f868e2d3184cb273978ac5bcb4bb77e40f1e66b74c
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Jul 21, 2026.

Transparency log

Release files / plaso-20260720-py3-none-any.whl

Download URL plaso-20260720-py3-none-any.whl
Size 3.0 MB
Tags Python 3
SHA-256 checksum
How to use checksums
d9ade1e336a7900bd0e173a21c26b4c69eba6f6fbeef8ef23d6d332e40405782
BLAKE2b-256 checksum
How to use checksums
3e151dc165e541f64f069b36b3292aa0e31a1e586a8079cb3530241d771fe6b1
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Jul 21, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

20260720 This release

2 release files

1.4.1-20160802

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page