Logs
Reads the raw logs that were loaded. Use it for logs no artifact was extracted from, or when you need to read around an extracted result.
Log types
The tree on the left is the log type.
| Type | What it is |
|---|---|
| Text logs | Logs in various text formats |
| NTFS events | USN journal ($J) records |
| Windows events | The Windows event log, with per-channel entries beneath it |
| Web logs | IIS, Apache, Nginx and other web server logs |
| Firewall and detection logs | Security appliance logs |
| PCAP | Packet captures |
The entries under Windows events are not separate tables - they are channel conditions: System, Application, Security, PowerShell, Windows Defender, Remote Desktop (connection manager and session manager), and Task Scheduler. Select the parent to see all of them.
The registry and the MFT have screens of their own, so they do not appear in this tree.
How you investigate here
Results are handled the same way the Artifacts screen handles them. Right-click a cell to filter
on its value, watch the conditions stack up in the chip bar as the query they stand for
(Ctrl+Q clears them), star a record to tag it and leave a note, and click a row for the detail
panel with every field and tag on it. There is more in
Artifacts.
The filter bar is shared with the other browsing screens, so settling on a host and a time range once lets you carry that scope from screen to screen.
routinely carry timestamps from years back, and a narrow range can exclude all of them.
Next: detection rules and evidence definitions, in Administration.