Skip to main content

Pure Python parser for recent Windows event log files (.evtx).

Project description

python-evtx is a pure Python parser for recent Windows Event Log files (those with the file extension “.evtx”). The module provides programmatic access to the File and Chunk headers, record templates, and event entries. For example, you can use python-evtx to review the event logs of Windows 7 systems from a Mac or Linux workstation. The structure definitions and parsing strategies were heavily inspired by the work of Andreas Schuster and his Perl implementation “Parse-Evtx”.

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distributions

python-evtx-0.1.zip (19.0 kB view details)

Uploaded Source

python-evtx-0.1.tar.gz (15.7 kB view details)

Uploaded Source

File details

Details for the file python-evtx-0.1.zip.

File metadata

  • Download URL: python-evtx-0.1.zip
  • Upload date:
  • Size: 19.0 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No

File hashes

Hashes for python-evtx-0.1.zip
Algorithm Hash digest
SHA256 6e8348ab515f063910f8ca9a53cab0edc8e969cb43ccd4111cf6f5c19a9b4937
MD5 ca746d38b7126f701cf05b2b54abfcc8
BLAKE2b-256 594859ce37a5fa97fe3839ebee3b1e59eda70a0be3d40c35b49a6de0e744bf23

See more details on using hashes here.

File details

Details for the file python-evtx-0.1.tar.gz.

File metadata

  • Download URL: python-evtx-0.1.tar.gz
  • Upload date:
  • Size: 15.7 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No

File hashes

Hashes for python-evtx-0.1.tar.gz
Algorithm Hash digest
SHA256 145e768a6879357daf4b8776272720ea9a1615dc14e284dec52c62561ece877d
MD5 03b1931dc19257eff3cc070195c6ccd5
BLAKE2b-256 adc8c887e728c92c47a910256434bbef1071cb3dc32b9faf20b008dbcc31a605

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page