Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

feat: added wild card and exact search in filter option #1240 #1249

Merged

Conversation

hitenkoku
Copy link
Collaborator

What Changed

  • added exact search to filter option
  • adjusted wildcard char (? , *) in filter option

@hitenkoku hitenkoku added the enhancement New feature or request label Jan 11, 2024
@hitenkoku hitenkoku self-assigned this Jan 11, 2024
@hitenkoku hitenkoku linked an issue Jan 11, 2024 that may be closed by this pull request
@hitenkoku
Copy link
Collaborator Author

Evidence

  • > .\1240.exe search -d ../hayabusa-sample-evtx -r ".*" -F EventID:*1 -o 1240.csv -C
cat 1240.csv

"Timestamp","Hostname","Channel","Event ID","Record ID","EventTitle","AllFieldInfo","EvtxFile"
"2013-10-24 01:16:15.703 +09:00","37L4247D28-05","Sec",4731,10,"Security-enabled local group created","PrivilegeList: - ¦ SamAccountName: Network Configuration Operators ¦ SidHistory: - ¦ SubjectDomainName: WORKGROUP ¦ SubjectLogonId: 0x3e7 ¦ SubjectUserName: 37L4247D28-05$ ¦ SubjectUserSid: S-1-5-18 ¦ TargetDomainName: Builtin ¦ TargetSid: S-1-5-32-556 ¦ TargetUserName: Network Configuration Operators","../hayabusa-sample-evtx\DeepBlueCLI\many-events-security.evtx"
"2013-10-24 01:16:15.703 +09:00","37L4247D28-05","Sec",4731,8,"Security-enabled local group created","PrivilegeList: - ¦ SamAccountName: Remote Desktop Users ¦ SidHistory: - ¦ SubjectDomainName: WORKGROUP ¦ SubjectLogonId: 0x3e7 ¦ SubjectUserName: 37L4247D28-05$ ¦ SubjectUserSid: S-1-5-18 ¦ TargetDomainName: Builtin ¦ TargetSid: S-1-5-32-555 ¦ TargetUserName: Remote Desktop Users","../hayabusa-sample-evtx\DeepBlueCLI\many-events-security.evtx"
"2013-10-24 01:16:15.703 +09:00","37L4247D28-05","Sec",4731,12,"Security-enabled local group created","PrivilegeList: - ¦ SamAccountName: Power Users ¦ SidHistory: - ¦ SubjectDomainName: WORKGROUP ¦ SubjectLogonId: 0x3e7 ¦ SubjectUserName: 37L4247D28-05$ ¦ SubjectUserSid: S-1-5-18 ¦ TargetDomainName: Builtin ¦ TargetSid: S-1-5-32-547 ¦ TargetUserName: Power Users","../hayabusa-sample-evtx\DeepBlueCLI\many-events-security.evtx"
"2013-10-24 01:16:15.703 +09:00","37L4247D28-05","Sec",4731,4,"Security-enabled local group created","PrivilegeList: - ¦ SamAccountName: Backup Operators ¦ SidHistory: - ¦ SubjectDomainName: WORKGROUP ¦ SubjectLogonId: 0x3e7 ¦ SubjectUserName: 37L4247D28-05$ ¦ SubjectUserSid: S-1-5-18 ¦ TargetDomainName: Builtin ¦ TargetSid: S-1-5-32-551 ¦ TargetUserName: Backup Operators","../hayabusa-sample-evtx\DeepBlueCLI\many-events-security.evtx"
"2013-10-24 01:16:15.703 +09:00","37L4247D28-05","Sec",4731,6,"Security-enabled local group created","PrivilegeList: - ¦ SamAccountName: Replicator ¦ SidHistory: - ¦ SubjectDomainName: WORKGROUP ¦ SubjectLogonId: 0x3e7 ¦ SubjectUserName: 37L4247D28-05$ ¦ SubjectUserSid: S-1-5-18 ¦ TargetDomainName: Builtin ¦ TargetSid: S-1-5-32-552 ¦ TargetUserName: Replicator","../hayabusa-sample-evtx\DeepBlueCLI\many-events-security.evtx"
"2013-10-24 01:16:16.015 +09:00","37L4247D28-05","Sec",4731,14,"Security-enabled local group created","PrivilegeList: - ¦ SamAccountName: Cryptographic Operators ¦ SidHistory: - ¦ SubjectDomainName: WORKGROUP ¦ SubjectLogonId: 0x3e7 ¦ SubjectUserName: 37L4247D28-05$ ¦ SubjectUserSid: S-1-5-18 ¦ TargetDomainName: Builtin ¦ TargetSid: S-1-5-32-569 ¦ TargetUserName: Cryptographic Operators","../hayabusa-sample-evtx\DeepBlueCLI\many-events-security.evtx"
"2013-10-24 01:16:27.000 +09:00","37L4247D28-05","Sys",6011,2,"-","Data: 37L4247D28-05 ¦ Data: WIN-QALA5Q3KJ43","../hayabusa-sample-evtx\DeepBlueCLI\many-events-system.evtx"
"2013-10-24 01:16:29.484 +09:00","37L4247D28-05","App",1531,2,"-","-","../hayabusa-sample-evtx\DeepBlueCLI\many-events-application.evtx"
"2013-10-24 01:16:46.562 +09:00","37L4247D28-05","Sys",20001,114,"-","DeviceInstanceID: ROOT\MSSMBIOS\0000 ¦ DriverDescription: Microsoft System Management BIOS Driver ¦ DriverName: FileRepository\machine.inf_x86_neutral_65848c2d7375a720\machine.inf ¦ DriverProvider: Microsoft ¦ DriverVersion: 6.1.7600.16385 ¦ InstallStatus: 0x0 ¦ IsDriverOEM: false ¦ RebootOption: false ¦ SetupClass: 4D36E97D-E325-11CE-BFC1-08002BE10318 ¦ UpgradeDevice: false ¦ xmlns:auto-ns2: http://schemas.microsoft.com/win/2004/08/events","../hayabusa-sample-evtx\DeepBlueCLI\many-events-system.evtx"
"2013-10-24 01:16:56.406 +09:00","37L4247D28-05","Sys",20001,117,"-","DeviceInstanceID: ROOT\MS_NDISWANBH\0000 ¦ DriverDescription: WAN Miniport (Network Monitor) ¦ DriverName: ¦ DriverProvider: Microsoft ¦ DriverVersion: 6.1.7600.16385 ¦ InstallStatus: 0x0 ¦ IsDriverOEM: false ¦ RebootOption: false ¦ SetupClass: 4D36E972-E325-11CE-BFC1-08002BE10318 ¦ UpgradeDevice: true ¦ xmlns:auto-ns2: http://schemas.microsoft.com/win/2004/08/events","../hayabusa-sample-evtx\DeepBlueCLI\many-events-system.evtx"
"2013-10-24 01:16:57.171 +09:00","37L4247D28-05","Sys",20001,119,"-","DeviceInstanceID: ROOT\MS_AGILEVPNMINIPORT\0000 ¦ DriverDescription: WAN Miniport (IKEv2) ¦ DriverName: ¦ DriverProvider: Microsoft ¦ DriverVersion: 6.1.7600.16385 ¦ InstallStatus: 0x0 ¦ IsDriverOEM: false ¦ RebootOption: false ¦ SetupClass: 4D36E972-E325-11CE-BFC1-08002BE10318 ¦ UpgradeDevice: true ¦ xmlns:auto-ns2: http://schemas.microsoft.com/win/2004/08/events","../hayabusa-sample-evtx\DeepBlueCLI\many-events-system.evtx"
"2013-10-24 01:16:58.843 +09:00","37L4247D28-05","Sys",20001,122,"-","DeviceInstanceID: ROOT\MS_NDISWANIP\0000 ¦ DriverDescription: WAN Miniport (IP) ¦ DriverName: ¦ DriverProvider: Microsoft ¦ DriverVersion: 6.1.7600.16385 ¦ InstallStatus: 0x0 ¦ IsDriverOEM: false ¦ RebootOption: false ¦ SetupClass: 4D36E972-E325-11CE-BFC1-08002BE10318 ¦ UpgradeDevice: true ¦ xmlns:auto-ns2: http://schemas.microsoft.com/win/2004/08/events","../hayabusa-sample-evtx\DeepBlueCLI\many-events-system.evtx"
"2013-10-24 01:16:59.968 +09:00","37L4247D28-05","Sys",20001,124,"-","DeviceInstanceID: ROOT\MS_L2TPMINIPORT\0000 ¦ DriverDescription: WAN Miniport (L2TP) ¦ DriverName: ¦ DriverProvider: Microsoft ¦ DriverVersion: 6.1.7600.16385 ¦ InstallStatus: 0x0 ¦ IsDriverOEM: false ¦ RebootOption: false ¦ SetupClass: 4D36E972-E325-11CE-BFC1-08002BE10318 ¦ UpgradeDevice: true ¦ xmlns:auto-ns2: http://schemas.microsoft.com/win/2004/08/events","../hayabusa-sample-evtx\DeepBlueCLI\many-events-system.evtx"
"2013-10-24 01:17:01.140 +09:00","37L4247D28-05","Sys",20001,127,"-","DeviceInstanceID: ROOT\MS_NDISWANIPV6\0000 ¦ DriverDescription: WAN Miniport (IPv6) ¦ DriverName: ¦ DriverProvider: Microsoft ¦ DriverVersion: 6.1.7600.16385 ¦ InstallStatus: 0x0 ¦ IsDriverOEM: false ¦ RebootOption: false ¦ SetupClass: 4D36E972-E325-11CE-BFC1-08002BE10318 ¦ UpgradeDevice: true ¦ xmlns:auto-ns2: http://schemas.microsoft.com/win/2004/08/events","../hayabusa-sample-evtx\DeepBlueCLI\many-events-system.evtx"
"2013-10-24 01:17:02.656 +09:00","37L4247D28-05","Sys",20001,129,"-","DeviceInstanceID: ROOT\MS_PPPOEMINIPORT\0000 ¦ DriverDescription: WAN Miniport (PPPOE) ¦ DriverName: ¦ DriverProvider: Microsoft ¦ DriverVersion: 6.1.7600.16385 ¦ InstallStatus: 0x0 ¦ IsDriverOEM: false ¦ RebootOption: false ¦ SetupClass: 4D36E972-E325-11CE-BFC1-08002BE10318 ¦ UpgradeDevice: true ¦ xmlns:auto-ns2: http://schemas.microsoft.com/win/2004/08/events","../hayabusa-sample-evtx\DeepBlueCLI\many-events-system.evtx"
"2013-10-24 01:17:02.906 +09:00","37L4247D28-05","Sys",20001,130,"-","DeviceInstanceID: ROOT\ACPI_HAL\0000 ¦ DriverDescription: ACPI x86-based PC ¦ DriverName: FileRepository\hal.inf_x86_neutral_bf3422256b0b201d\hal.inf ¦ DriverProvider: Microsoft ¦ DriverVersion: 6.1.7600.16385 ¦ InstallStatus: 0x0 ¦ IsDriverOEM: false ¦ RebootOption: true ¦ SetupClass: 4D36E966-E325-11CE-BFC1-08002BE10318 ¦ UpgradeDevice: true ¦ xmlns:auto-ns2: http://schemas.microsoft.com/win/2004/08/events","../hayabusa-sample-evtx\DeepBlueCLI\many-events-system.evtx"
"2013-10-24 01:17:04.031 +09:00","37L4247D28-05","Sys",20001,132,"-","DeviceInstanceID: ROOT\BLBDRIVE\0000 ¦ DriverDescription: File as Volume Driver ¦ DriverName: FileRepository\blbdrive.inf_x86_neutral_1aa816fe7dc98c3f\blbdrive.inf ¦ DriverProvider: Microsoft ¦ DriverVersion: 6.1.7600.16385 ¦ InstallStatus: 0x0 ¦ IsDriverOEM: false ¦ RebootOption: true ¦ SetupClass: 4D36E97D-E325-11CE-BFC1-08002BE10318 ¦ UpgradeDevice: true ¦ xmlns:auto-ns2: http://schemas.microsoft.com/win/2004/08/events","../hayabusa-sample-evtx\DeepBlueCLI\many-events-system.evtx"
"2013-10-24 01:17:05.328 +09:00","37L4247D28-05","Sys",20001,134,"-","DeviceInstanceID: ROOT\MS_PPTPMINIPORT\0000 ¦ DriverDescription: WAN Miniport (PPTP) ¦ DriverName: ¦ DriverProvider: Microsoft ¦ DriverVersion: 6.1.7600.16385 ¦ InstallStatus: 0x0 ¦ IsDriverOEM: false ¦ RebootOption: false ¦ SetupClass: 4D36E972-E325-11CE-BFC1-08002BE10318 ¦ UpgradeDevice: true ¦ xmlns:auto-ns2: http://schemas.microsoft.com/win/2004/08/events","../hayabusa-sample-evtx\DeepBlueCLI\many-events-system.evtx"
"2013-10-24 01:17:06.093 +09:00","37L4247D28-05","Sys",20001,136,"-","DeviceInstanceID: ROOT\MS_SSTPMINIPORT\0000 ¦ DriverDescription: WAN Miniport (SSTP) ¦ DriverName: ¦ DriverProvider: Microsoft ¦ DriverVersion: 6.1.7600.16385 ¦ InstallStatus: 0x0 ¦ IsDriverOEM: false ¦ RebootOption: false ¦ SetupClass: 4D36E972-E325-11CE-BFC1-08002BE10318 ¦ UpgradeDevice: true ¦ xmlns:auto-ns2: http://schemas.microsoft.com/win/2004/08/events","../hayabusa-sample-evtx\DeepBlueCLI\many-events-system.evtx"
"2013-10-24 01:17:06.734 +09:00","37L4247D28-05","Sys",20001,138,"-","DeviceInstanceID: ROOT\COMPOSITEBUS\0000 ¦ DriverDescription: Composite Bus Enumerator ¦ DriverName: FileRepository\compositebus.inf_x86_neutral_21bd9e8289e1734d\compositebus.inf ¦ DriverProvider: Microsoft ¦ DriverVersion: 6.1.7600.16385 ¦ InstallStatus: 0x0 ¦ IsDriverOEM: false ¦ RebootOption: false ¦ SetupClass: 4D36E97D-E325-11CE-BFC1-08002BE10318 ¦ UpgradeDevice: true ¦ xmlns:auto-ns2: http://schemas.microsoft.com/win/2004/08/events","../hayabusa-sample-evtx\DeepBlueCLI\many-events-system.evtx"
"2013-10-24 01:17:07.765 +09:00","37L4247D28-05","Sys",20001,141,"-","DeviceInstanceID: ROOT\RDP_KBD\0000 ¦ DriverDescription: Terminal Server Keyboard Driver ¦ DriverName: FileRepository\machine.inf_x86_neutral_65848c2d7375a720\machine.inf ¦ DriverProvider: Microsoft ¦ DriverVersion: 6.1.7600.16385 ¦ InstallStatus: 0x0 ¦ IsDriverOEM: false ¦ RebootOption: true ¦ SetupClass: 4D36E97D-E325-11CE-BFC1-08002BE10318 ¦ UpgradeDevice: true ¦ xmlns:auto-ns2: http://schemas.microsoft.com/win/2004/08/events","../hayabusa-sample-evtx\DeepBlueCLI\many-events-system.evtx"
"2013-10-24 01:17:08.812 +09:00","37L4247D28-05","Sys",20001,144,"-","DeviceInstanceID: ROOT\RDP_MOU\0000 ¦ DriverDescription: Terminal Server Mouse Driver ¦ DriverName: FileRepository\machine.inf_x86_neutral_65848c2d7375a720\machine.inf ¦ DriverProvider: Microsoft ¦ DriverVersion: 6.1.7600.16385 ¦ InstallStatus: 0x0 ¦ IsDriverOEM: false ¦ RebootOption: true ¦ SetupClass: 4D36E97D-E325-11CE-BFC1-08002BE10318 ¦ UpgradeDevice: true ¦ xmlns:auto-ns2: http://schemas.microsoft.com/win/2004/08/events","../hayabusa-sample-evtx\DeepBlueCLI\many-events-system.evtx"
"2013-10-24 01:17:10.093 +09:00","37L4247D28-05","Sys",20001,146,"-","DeviceInstanceID: ROOT\SYSTEM\0000 ¦ DriverDescription: Plug and Play Software Device Enumerator ¦ DriverName: FileRepository\machine.inf_x86_neutral_65848c2d7375a720\machine.inf ¦ DriverProvider: Microsoft ¦ DriverVersion: 6.1.7600.16385 ¦ InstallStatus: 0x0 ¦ IsDriverOEM: false ¦ RebootOption: false ¦ SetupClass: 4D36E97D-E325-11CE-BFC1-08002BE10318 ¦ UpgradeDevice: true ¦ xmlns:auto-ns2: http://schemas.microsoft.com/win/2004/08/events","../hayabusa-sample-evtx\DeepBlueCLI\many-events-system.evtx"
"2013-10-24 01:17:10.906 +09:00","37L4247D28-05","Sys",20001,148,"-","DeviceInstanceID: ROOT\UMBUS\0000 ¦ DriverDescription: UMBus Root Bus Enumerator ¦ DriverName: FileRepository\umbus.inf_x86_neutral_b5261e2f9508e396\umbus.inf ¦ DriverProvider: Microsoft ¦ DriverVersion: 6.1.7600.16385 ¦ InstallStatus: 0x0 ¦ IsDriverOEM: false ¦ RebootOption: false ¦ SetupClass: 4D36E97D-E325-11CE-BFC1-08002BE10318 ¦ UpgradeDevice: true ¦ xmlns:auto-ns2: http://schemas.microsoft.com/win/2004/08/events","../hayabusa-sample-evtx\DeepBlueCLI\many-events-system.evtx"
"2013-10-24 01:17:11.453 +09:00","37L4247D28-05","Sys",20001,150,"-","DeviceInstanceID: ROOT\VDRVROOT\0000 ¦ DriverDescription: Microsoft Virtual Drive Enumerator Driver ¦ DriverName: FileRepository\machine.inf_x86_neutral_65848c2d7375a720\machine.inf ¦ DriverProvider: Microsoft ¦ DriverVersion: 6.1.7600.16385 ¦ InstallStatus: 0x0 ¦ IsDriverOEM: false ¦ RebootOption: false ¦ SetupClass: 4D36E97D-E325-11CE-BFC1-08002BE10318 ¦ UpgradeDevice: false ¦ xmlns:auto-ns2: http://schemas.microsoft.com/win/2004/08/events","../hayabusa-sample-evtx\DeepBlueCLI\many-events-system.evtx"
"2013-10-24 01:17:11.734 +09:00","37L4247D28-05","Sys",20001,152,"-","DeviceInstanceID: ROOT\VOLMGR\0000 ¦ DriverDescription: Volume Manager ¦ DriverName: FileRepository\machine.inf_x86_neutral_65848c2d7375a720\machine.inf ¦ DriverProvider: Microsoft ¦ DriverVersion: 6.1.7600.16385 ¦ InstallStatus: 0x0 ¦ IsDriverOEM: false ¦ RebootOption: true ¦ SetupClass: 4D36E97D-E325-11CE-BFC1-08002BE10318 ¦ UpgradeDevice: true ¦ xmlns:auto-ns2: http://schemas.microsoft.com/win/2004/08/events","../hayabusa-sample-evtx\DeepBlueCLI\many-events-system.evtx"
"2013-10-24 01:17:12.515 +09:00","37L4247D28-05","Sys",20001,154,"-","DeviceInstanceID: ACPI_HAL\PNP0C08\0 ¦ DriverDescription: Microsoft ACPI-Compliant System ¦ DriverName: FileRepository\acpi.inf_x86_neutral_ddd3c514822f1b21\acpi.inf ¦ DriverProvider: Microsoft ¦ DriverVersion: 6.1.7600.16385 ¦ InstallStatus: 0x0 ¦ IsDriverOEM: false ¦ RebootOption: true ¦ SetupClass: 4D36E97D-E325-11CE-BFC1-08002BE10318 ¦ UpgradeDevice: false ¦ xmlns:auto-ns2: http://schemas.microsoft.com/win/2004/08/events","../hayabusa-sample-evtx\DeepBlueCLI\many-events-system.evtx"
"2013-10-24 01:17:13.375 +09:00","37L4247D28-05","Sys",20001,156,"-","DeviceInstanceID: STORAGE\VOLUME\{59FF5BEA-3BFE-11E3-8B4A-806E6F6E6963}#0000000000100000 ¦ DriverDescription: Generic volume ¦ DriverName: FileRepository\volume.inf_x86_neutral_29364d30156a24ca\volume.inf ¦ DriverProvider: Microsoft ¦ DriverVersion: 6.1.7600.16385 ¦ InstallStatus: 0x0 ¦ IsDriverOEM: false ¦ RebootOption: false ¦ SetupClass: 71A27CDD-812A-11D0-BEC7-08002BE2092F ¦ UpgradeDevice: false ¦ xmlns:auto-ns2: http://schemas.microsoft.com/win/2004/08/events","../hayabusa-sample-evtx\DeepBlueCLI\many-events-system.evtx"
"2013-10-24 01:17:13.937 +09:00","37L4247D28-05","Sys",20001,158,"-","DeviceInstanceID: STORAGE\VOLUME\{59FF5BEA-3BFE-11E3-8B4A-806E6F6E6963}#0000000006500000 ¦ DriverDescription: Generic volume ¦ DriverName: FileRepository\volume.inf_x86_neutral_29364d30156a24ca\volume.inf ¦ DriverProvider: Microsoft ¦ DriverVersion: 6.1.7600.16385 ¦ InstallStatus: 0x0 ¦ IsDriverOEM: false ¦ RebootOption: false ¦ SetupClass: 71A27CDD-812A-11D0-BEC7-08002BE2092F ¦ UpgradeDevice: false ¦ xmlns:auto-ns2: http://schemas.microsoft.com/win/2004/08/events","../hayabusa-sample-evtx\DeepBlueCLI\many-events-system.evtx"
"2013-10-24 01:17:14.140 +09:00","37L4247D28-05","Sys",20001,159,"-","DeviceInstanceID: ACPI\FIXEDBUTTON\2&DABA3FF&1 ¦ DriverDescription: ACPI Fixed Feature Button ¦ DriverName: FileRepository\machine.inf_x86_neutral_65848c2d7375a720\machine.inf ¦ DriverProvider: Microsoft ¦ DriverVersion: 6.1.7600.16385 ¦ InstallStatus: 0x0 ¦ IsDriverOEM: false ¦ RebootOption: true ¦ SetupClass: 4D36E97D-E325-11CE-BFC1-08002BE10318 ¦ UpgradeDevice: false ¦ xmlns:auto-ns2: http://schemas.microsoft.com/win/2004/08/events","../hayabusa-sample-evtx\DeepBlueCLI\many-events-system.evtx"
"2013-10-24 01:17:14.671 +09:00","37L4247D28-05","Sys",20001,161,"-","DeviceInstanceID: ACPI\GENUINEINTEL_-_X86_FAMILY_6_MODEL_30_-_INTEL(R)_XEON(R)_CPU___________X3440__@_2.53GHZ\_1 ¦ DriverDescription: Intel Processor ¦ DriverName: FileRepository\cpu.inf_x86_neutral_729b871528391032\cpu.inf ¦ DriverProvider: Microsoft ¦ DriverVersion: 6.1.7600.16385 ¦ InstallStatus: 0x0 ¦ IsDriverOEM: false ¦ RebootOption: true ¦ SetupClass: 50127DC3-0F36-415E-A6CC-4CB3BE910B65 ¦ UpgradeDevice: false ¦ xmlns:auto-ns2: http://schemas.microsoft.com/win/2004/08/events","../hayabusa-sample-evtx\DeepBlueCLI\many-events-system.evtx"
"2013-10-24 01:17:15.046 +09:00","37L4247D28-05","Sys",20001,163,"-","DeviceInstanceID: ACPI\PNP0A03\0 ¦ DriverDescription: PCI bus ¦ DriverName: FileRepository\machine.inf_x86_neutral_65848c2d7375a720\machine.inf ¦ DriverProvider: Microsoft ¦ DriverVersion: 6.1.7600.16385 ¦ InstallStatus: 0x0 ¦ IsDriverOEM: false ¦ RebootOption: true ¦ SetupClass: 4D36E97D-E325-11CE-BFC1-08002BE10318 ¦ UpgradeDevice: false ¦ xmlns:auto-ns2: http://schemas.microsoft.com/win/2004/08/events","../hayabusa-sample-evtx\DeepBlueCLI\many-events-system.evtx"
...
  • > .\1240.exe search -d ../hayabusa-sample-evtx -r ".*" -F EventID:1 -o 1240.csv -C
cat 1240.csv
"Timestamp","Hostname","Channel","Event ID","Record ID","EventTitle","AllFieldInfo","EvtxFile"
"2013-10-24 01:17:44.109 +09:00","37L4247D28-05","Sys",1,236,"-","Binary: 0000000002002C000000000001000040000000000000000000000000000000000000000000000000 ¦ Data: ¦ Data: Microsoft Virtual Machine Bus Network Adapter","../hayabusa-sample-evtx\DeepBlueCLI\many-events-system.evtx"
"2013-10-24 01:18:33.828 +09:00","IE8Win7","Sys",1,295,"-","Binary: 0000000002002C000000000001000040000000000000000000000000000000000000000000000000 ¦ Data: ¦ Data: Microsoft Virtual Machine Bus Network Adapter","../hayabusa-sample-evtx\DeepBlueCLI\many-events-system.evtx"
"2013-10-24 01:21:33.630 +09:00","IE8Win7","Sys",1,346,"-","NewTime: 2013-10-23T16:21:33.630000Z ¦ OldTime: 2013-10-23T16:21:33.375000Z","../hayabusa-sample-evtx\DeepBlueCLI\many-events-system.evtx"
"2013-10-24 01:22:39.911 +09:00","IE8Win7","Sys",1,361,"-","NewTime: 2013-10-23T16:22:39.911000Z ¦ OldTime: 2013-10-23T16:22:40.005000Z","../hayabusa-sample-evtx\DeepBlueCLI\many-events-system.evtx"
"2013-10-24 01:22:40.005 +09:00","IE8Win7","Sys",1,360,"-","NewTime: 2013-10-23T16:22:40.005000Z ¦ OldTime: 2013-10-23T16:22:40.005000Z","../hayabusa-sample-evtx\DeepBlueCLI\many-events-system.evtx"
"2013-10-24 01:23:39.000 +09:00","IE8Win7","App",1,101,"-","-","../hayabusa-sample-evtx\DeepBlueCLI\many-events-application.evtx"
"2013-10-24 01:24:00.130 +09:00","IE8Win7","Sys",1,378,"-","NewTime: 2013-10-23T16:24:00.130000Z ¦ OldTime: 2013-10-23T16:23:58.979359Z","../hayabusa-sample-evtx\DeepBlueCLI\many-events-system.evtx"
"2013-10-24 01:27:48.911 +09:00","IE8Win7","Sys",1,409,"-","NewTime: 2013-10-23T16:27:48.911000Z ¦ OldTime: 2013-10-23T16:27:48.911250Z","../hayabusa-sample-evtx\DeepBlueCLI\many-events-system.evtx"
"2013-10-24 02:30:47.140 +09:00","IE8Win7","Sys",1,873,"-","Binary: 0000000002002C000000000001000040000000000000000000000000000000000000000000000000 ¦ Data: ¦ Data: Microsoft Virtual Machine Bus Network Adapter","../hayabusa-sample-evtx\DeepBlueCLI\many-events-system.evtx"
"2013-10-24 02:31:10.741 +09:00","IE8Win7","Sys",1,914,"-","NewTime: 2013-10-23T17:31:10.741000Z ¦ OldTime: 2013-10-23T17:31:10.281250Z","../hayabusa-sample-evtx\DeepBlueCLI\many-events-system.evtx"
"2013-10-24 02:32:53.796 +09:00","IE8Win7","Sys",1,962,"-","Binary: 0000000002002C000000000001000040000000000000000000000000000000000000000000000000 ¦ Data: ¦ Data: Microsoft Virtual Machine Bus Network Adapter","../hayabusa-sample-evtx\DeepBlueCLI\many-events-system.evtx"
"2013-10-24 02:33:31.593 +09:00","IE8Win7","Sys",1,1002,"-","NewTime: 2013-10-23T17:33:31.593000Z ¦ OldTime: 2013-10-23T17:33:31.125000Z","../hayabusa-sample-evtx\DeepBlueCLI\many-events-system.evtx"
"2013-10-24 02:35:55.000 +09:00","IE8Win7","App",1,195,"-","-","../hayabusa-sample-evtx\DeepBlueCLI\many-events-application.evtx"
"2013-10-24 02:45:29.131 +09:00","IE8Win7","Sys",1,1044,"-","NewTime: 2013-10-23T17:45:29.116000Z ¦ OldTime: 2013-10-23T17:39:44.249250Z","../hayabusa-sample-evtx\DeepBlueCLI\many-events-system.evtx"
"2013-10-24 02:49:38.890 +09:00","IE8Win7","Sys",1,1231,"-","Binary: 0000000002002C000000000001000040000000000000000000000000000000000000000000000000 ¦ Data: ¦ Data: Microsoft Virtual Machine Bus Network Adapter","../hayabusa-sample-evtx\DeepBlueCLI\many-events-system.evtx"
"2013-10-24 02:50:33.551 +09:00","IE8Win7","Sys",1,1272,"-","NewTime: 2013-10-23T17:50:33.551000Z ¦ OldTime: 2013-10-23T17:50:33.281250Z","../hayabusa-sample-evtx\DeepBlueCLI\many-events-system.evtx"
"2013-10-24 02:53:48.000 +09:00","IE8Win7","App",1,236,"-","-","../hayabusa-sample-evtx\DeepBlueCLI\many-events-application.evtx"
"2013-10-24 03:48:37.144 +09:00","IE8Win7","Sys",1,1383,"-","SP: 1","../hayabusa-sample-evtx\DeepBlueCLI\many-events-system.evtx"
"2013-10-24 04:04:09.406 +09:00","IE8Win7","Sys",1,1442,"-","Binary: 0000000002002C000000000001000040000000000000000000000000000000000000000000000000 ¦ Data: ¦ Data: Microsoft Virtual Machine Bus Network Adapter","../hayabusa-sample-evtx\DeepBlueCLI\many-events-system.evtx"
"2013-10-24 04:05:04.098 +09:00","IE8Win7","Sys",1,1483,"-","NewTime: 2013-10-23T19:05:04.098000Z ¦ OldTime: 2013-10-23T19:05:03.093750Z","../hayabusa-sample-evtx\DeepBlueCLI\many-events-system.evtx"
"2013-10-24 04:05:59.484 +09:00","IE8Win7","Sys",1,1537,"-","Binary: 0000000002002C000000000001000040000000000000000000000000000000000000000000000000 ¦ Data: ¦ Data: Microsoft Virtual Machine Bus Network Adapter","../hayabusa-sample-evtx\DeepBlueCLI\many-events-system.evtx"
"2013-10-24 04:07:16.729 +09:00","IE8Win7","Sys",1,1578,"-","NewTime: 2013-10-23T19:07:16.729000Z ¦ OldTime: 2013-10-23T19:07:15.984375Z","../hayabusa-sample-evtx\DeepBlueCLI\many-events-system.evtx"
"2013-10-24 04:10:27.000 +09:00","IE8Win7","App",1,439,"-","-","../hayabusa-sample-evtx\DeepBlueCLI\many-events-application.evtx"
"2013-10-24 04:19:23.812 +09:00","IE8Win7","Sys",1,1648,"-","Binary: 0000000002002C000000000001000040000000000000000000000000000000000000000000000000 ¦ Data: ¦ Data: Microsoft Virtual Machine Bus Network Adapter","../hayabusa-sample-evtx\DeepBlueCLI\many-events-system.evtx"
"2013-10-24 04:20:01.879 +09:00","IE8Win7","Sys",1,1689,"-","NewTime: 2013-10-23T19:20:01.879000Z ¦ OldTime: 2013-10-23T19:20:01.796875Z","../hayabusa-sample-evtx\DeepBlueCLI\many-events-system.evtx"
"2013-10-24 04:22:39.125 +09:00","IE8Win7","Sys",1,1759,"-","Binary: 0000000002002C000000000001000040000000000000000000000000000000000000000000000000 ¦ Data: ¦ Data: Microsoft Virtual Machine Bus Network Adapter","../hayabusa-sample-evtx\DeepBlueCLI\many-events-system.evtx"
...

Copy link

codecov bot commented Jan 11, 2024

Codecov Report

Attention: 8 lines in your changes are missing coverage. Please review.

Comparison is base (1894d33) 82.45% compared to head (304f475) 82.45%.

Files Patch % Lines
src/timeline/search.rs 0.00% 8 Missing ⚠️
Additional details and impacted files
@@           Coverage Diff           @@
##             main    #1249   +/-   ##
=======================================
  Coverage   82.45%   82.45%           
=======================================
  Files          27       27           
  Lines       24689    24688    -1     
=======================================
  Hits        20357    20357           
+ Misses       4332     4331    -1     

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

Copy link
Collaborator

@fukusuket fukusuket left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I found another issue #1251 (I’m sorry for I couldn't detect it when testing...><)
but the filter is working so it's LGTM!!🚀

Copy link
Collaborator

@YamatoSecurity YamatoSecurity left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@hitenkoku Sorry for the late review. LGTM! Thanks so much!

@YamatoSecurity YamatoSecurity added this to the v2.13.0 milestone Jan 22, 2024
@hitenkoku hitenkoku merged commit fd81b32 into main Jan 23, 2024
7 checks passed
@hitenkoku hitenkoku deleted the 1240-make-search-commands-filter-option-an-exact-match branch January 23, 2024 08:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request
Projects
None yet
Development

Successfully merging this pull request may close these issues.

Make search command's Filter option an exact match
3 participants