WithSecureLabs / chainsaw

Rapidly Search and Hunt through Windows Forensic Artefacts

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

Request for time filters(start and end dates) in local time

termcap opened this issue · comments

It would be great to have the start and end date filters support the local machine time as apart from servers most desktops in an organization would have local time set.

Currently the events returned with date filters set are also in UTC time which means one needs to reconvert back the output to local time.

I'll look into this.

Working on this now, just to clarify, are you wanting chainsaw to mutate the timestamp column to the local time on output?

This is addressed in v2.0.0-alpha.0