Logpresso Forensic

Download 0
Last updated Oct 11, 2026

Logs

Reads the raw logs that were loaded. Use it for logs no artifact was extracted from, or when you need to read around an extracted result.

Log types

The tree on the left is the log type.

TypeWhat it is
Text logsLogs in various text formats
NTFS eventsUSN journal ($J) records
Windows eventsThe Windows event log, with per-channel entries beneath it
Web logsIIS, Apache, Nginx and other web server logs
Firewall and detection logsSecurity appliance logs
PCAPPacket captures

The entries under Windows events are not separate tables - they are channel conditions: System, Application, Security, PowerShell, Windows Defender, Remote Desktop (connection manager and session manager), and Task Scheduler. Select the parent to see all of them.

The registry and the MFT have screens of their own, so they do not appear in this tree.

How you investigate here

Results are handled the same way the Artifacts screen handles them. Right-click a cell to filter on its value, watch the conditions stack up in the chip bar as the query they stand for (Ctrl+Q clears them), star a record to tag it and leave a note, and click a row for the detail panel with every field and tag on it. There is more in Artifacts.

The filter bar is shared with the other browsing screens, so settling on a host and a time range once lets you carry that scope from screen to screen.

Note
If a search comes back empty, check the time range in the filter bar first. Forensic records
routinely carry timestamps from years back, and a narrow range can exclude all of them.

Next: detection rules and evidence definitions, in Administration.