Skip to main content

wazuhevtx

A Python tool and library that parses EVTX files and converts them into JSON formatted logs mimicking Wazuh agent behavior in version 4.x. wazuhevtx is designed as a helper for wazuh-logtest tool.

Now, you can test your detection capabilities by replaying known attack samples such as Windows EVTX Samples.

Note: It runs on Windows-only! See Caveats below.

Installation

Alternative 1: Clone this repository

  • Simply git clone https://github.com/zbalkan/wazuhevtx.git and start playing wih it.
  • initiate your favorite virtual environment.
  • Install dependencies using pip install -r requirements.txt
  • Run the script by providing the path to evtx file.

Alternative 2: Use pip/pipx

If you plan to use the library and CLI:

  • initiate your favorite virtual environment.
  • Install the module using pip install wazuhevtx
  • Run the script by providing the path to evtx file. Or you ca just use import wazuhevtx

If you want to use only CLI tool:

  • Install the module using pipx install wazuhevtx
  • Run the script by providing the path to evtx file.

Usage

As a CLI tool

usage: wazuhevtx [-h] [-o OUTPUT] evtx

A Python tool and library that parses EVTX files and converts them into JSON formatted logs mimicking Wazuh agent behavior in version 4.x. wazuhevtx is designed as a helper for wazuh-logtest tool.

positional arguments:
  evtx                  Path to the Windows EVTX event log file

options:
  -h, --help            show this help message and exit
  -o OUTPUT, --output OUTPUT
                        Path of output JSON file. If not defined, output will be printed to console.

Check the animation for a speed run:

Alt Text

As a library

You can use the package as a library to integrate into your scripts.

from wazuhevtx.evtx2json import EvtxToJson

converter = EvtxToJson()

for log in converter.to_json(evtx_file):
    print(log)

Caveats

Windows-only

Due to Windows API dependencies of win32evtlog, the script works on Windows systems only. If you try on a Linux or Mac environment, you will get "This script is intended to be run on Windows." message, and the script will exit with error code 1.

Workaround for testing

In order to be able to test with wazuh-logtest utility, you need a workaround as we are sending JSON logs, not event_channel format.

  • Navigate to /var/ossec/ruleset/rules/0575-win-base_rules.xml file.
  • Update the rule 60000 this way:
<rule id="60000" level="2">
    <!-- category>ossec</category -->
    <!-- decoded_as>windows_eventchannel</decoded_as -->
    <decoded_as>json</decoded_as>
    <field name="win.system.providerName">\.+</field>
    <options>no_full_log</options>
    <description>Group of windows rules.</description>
</rule>

Corrupted EVTX files

If you encounter this error below, you will see that you cannot parse event logs. That is because I utilize Windows APIs, and by default the API does not provide a way to read or recover corrupted sections. If the file is corrupted, you cannot read it as a whole. I suggest using third party tools lie CQEVTXRecovery to recover files before using with wazuhevtx.

Error: The event log file is corrupted. (1500)

Log Provider missing

It is possible that the log provider is missing on your computer. For instance, you may not have Sysmon installed on the analyst workstation, therefore the formatted message may be missing. Then, you will face the error message in the event's message field Failed to get metadata for provider Microsoft-Windows-Sysmon. This is by design. You cannot get metadata from a provider that does not exist. If you plan to use message field in detections, beware of the error message.

Thanks

Thanks to Birol Capa for his article pointing to the simplest way to parse EVTX files. Before that I tried many different solutions that were limited after some point.

License

GNU General Public License version 2 only. See LICENSE.

Release files for wazuhevtx 1.1.1

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for wazuhevtx 1.1.1
File Size Uploaded
wazuhevtx-1.1.1.tar.gz 16.7 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for wazuhevtx 1.1.1
File Interpreter ABI Platform
wazuhevtx-1.1.1-py3-none-any.whl Python 3 none any Details

Total release size: 32.6 kB

Release files / wazuhevtx-1.1.1.tar.gz

Download URL wazuhevtx-1.1.1.tar.gz
Size 16.7 kB
Tags Source
SHA-256 checksum
How to use checksums
6d943361ea98d88e50fbbcc6991e8af1a019fe899a2a5c4b2c7ef72b2c740b28
BLAKE2b-256 checksum
How to use checksums
9cbf79439d5d5a2471e8a9a8643818147ed7dcadc738b42748712f94c616fdd5
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 28, 2026.

Transparency log

Release files / wazuhevtx-1.1.1-py3-none-any.whl

Download URL wazuhevtx-1.1.1-py3-none-any.whl
Size 15.9 kB
Tags Python 3
SHA-256 checksum
How to use checksums
28396e540e7edd2002f68e8547a0397b261d9a0e629d1519416bab46aa1a2da3
BLAKE2b-256 checksum
How to use checksums
24cd019de810a87b7b5f7f06f570949471d83c54660193f90e6835cf75c9e584
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 28, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

1.1.1 This release

2 release files

1.1.0

2 release files

1.0.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page