Start / end date options to select events to process
einarssonm opened this issue · comments
Markus Einarsson commented
Request to include start / end date options, to select events to process. This would optimize processing of large event log files, such as ForwardedEvents.evtx with 10-20 GB max size. Ideally the date filters would be applied as early as possible, to avoid unnecessary processing of irrelevant events. Suggested options:
OPTIONS:
-sd, --start-date <datetime>
Start date for including events (UTC). Anything older than this is dropped. Format: yyyy-MM-dd HH:mm:ss
-ed, --end-date <datetime>
End date for including events (UTC). Anything newer than this is dropped. Format: yyyy-MM-dd HH:mm:ss
fscc-jamesd commented
Good idea, I'll work on adding this.
Olaf Hartong commented
Good idea, I'll work on adding this.
I'd love to see that too ! Great tool by the way!
fscc-jamesd commented
This has been added in #29 and is now live in the latest build. Let me know if you find any issues.