RsWindowsThingies: see Windows Event Logs in real time
RsWindowsThingies
listen_mft
Watch an entries’ values change.
listen_events
The event listen tool allows you to see Windows Event Logs in real-time.
Note: It takes a minute for the event logs to catch up. I need to implement more of the Windows API to fix this. When the “Waiting for new events…” message appears, you know it is actively listening.
print_channels
The print channels tool allows you to dump the channels and their configs. This helps to identify what is available on your system and the configuration settings. It is mainly an interface for some of the library components that are used in helping establish what channels to monitor for in the event monitoring tool.
print_publishers
The print publishers tool allows to you dump the publishers and their configs. This helps to identify what is available on your system and the configuration settings. It is mainly an interface for some of the library components that are used in helping establish what providers exist for monitoring purposes.
Download
Copyright (C) 2020 forensicmatt