There are 4 repositories under windows-eventlog topic.
Agent for collecting, processing, aggregating, and writing metrics, logs, and other arbitrary data.
APT-Hunter is Threat Hunting tool for windows event logs which made by purple team mindset to provide detect APT movements hidden in the sea of windows event logs to decrease the time to uncover suspicious activity
Tail utility for monitoring text log files and Windows EventLog
Query and report user logons relations from MS Windows Security Events
Build a fast, free, and effective Threat Hunting/Incident Response Console with Windows Event Forwarding and PowerBI
An Incident Response tool that visualizes historic process execution evidence (based on Event ID 4688 - Process Creation Event) in a tree view.
Simple Powershell scripts to collect all Windows Event Logs from a host and parse them into one CSV timeline.
A PS forensics tool for Scraping, Filtering and Exporting Windows Event Logs
Automatically export Windows event logs to CSV
PowerShell Module for using Microsoft Windows Event Viewer Custom Views for Event Log Filtering in PowerShell
Capture all events across all logs produced during the running of a particular exploit/script. Search and filter events
A Python script that parses CPER-formatted raw data contained in error event log provided by WHEA-Logger
Search Windows event log and output results to a text file
SAP Lumira Data Access Extension sample code: Windows Event Log.
Python 3-based multithreaded Windows Event monitoring program
Setup-Guide for the central Logserver Graylog (dockerized)
Elasticsearch-based log search and wiki application
Blocks failed RDP login IPs using the routing table instead of Windows Firewall. Ideal for systems with firewall disabled for performance reasons.
Windows EventLog Parse
Flume source support windows event log
Windows Event Log logger for the node.js Winston module.
Deal with the Windows event log
Event Tracing for Windows
Runtime-configurable and scriptable log processor and forwarder
Logging to Windows Eventlog
A useful tool to check for time modifications
Capturing the 'print' event (Printer) in windows and then process the event
Event Lens provides a structured, searchable, and visually clean reference for critical Windows Security Event IDs
A Node.js event log utility for Windows 10 & Server '12/16 that actually works