command
module
Version:
v0.5.3
Opens a new window with list of versions in this module.
Published: Aug 19, 2025
License: MIT
Opens a new window with license information.
Imports: 4
Opens a new window with list of imports.
Imported by: 0
Opens a new window with list of known importers.
README
¶
flog

Log forensic artifacts as JSON in ECS format.
go install github.com/cuhsat/flog@latest
Usage
$ flog [-pqhv] [-D DIRECTORY] [FILE ...]
Available options:
-D Log directory
-p Pretty JSON
-q Quiet mode
-h Show usage
-v Show version
Required system commands:
Use scripts/eztools.sh to install Eric Zimmerman's Tools.
Artifacts
Supported artifacts for Windows 7+ systems:
License
Released under the MIT License.
Documentation
¶
Log forensic artifacts as JSON in ECS format.
Usage:
flog [-pqhv] [-D DIR] [FILE ...]
The flags are:
-D directory
The log directory.
-p
Pretty JSON.
-q
Quiet mode.
-h
Show usage.
-v
Show version.
The arguments are:
file
The event log file(s) to process.
Defaults to STDIN if not given.
Source Files
¶
Directories
¶
internal
|
|
|
|
|
ecs
https://www.elastic.co/docs/reference/ecs/ecs-field-reference
|
https://www.elastic.co/docs/reference/ecs/ecs-field-reference |
|
|
|
|
|
|
|
|
|
Click to show internal directories.
Click to hide internal directories.