{"id":164,"date":"2016-04-11T03:00:26","date_gmt":"2016-04-11T03:00:26","guid":{"rendered":"http:\/\/eventlogxp.com\/blog\/?p=164"},"modified":"2016-04-11T09:58:52","modified_gmt":"2016-04-11T09:58:52","slug":"event-log-explorer-forensic-edition-preview","status":"publish","type":"post","link":"https:\/\/eventlogxp.com\/blog\/event-log-explorer-forensic-edition-preview\/","title":{"rendered":"Event Log Explorer Forensic Edition Preview"},"content":{"rendered":"<p>Several days ago, we published a preview of the new edition of Event Log Explorer software \u2013 Forensic Edition! Here I will show what benefits you can get from this edition. First, I should say that currently it is fully compatible with the standard edition of Event Log Explorer \u2013 it uses the same workspace, the same settings and currently the same registration key. By default, it installs itself into another folder, so you can use both editions concurrently.\u00a0By the way, the forensic edition preview is available at<br \/>\n<a href=\"http:\/\/eventlogxp.com\/download\/elex_fe_setup.exe\">http:\/\/eventlogxp.com\/download\/elex_fe_setup.exe<\/a><\/p>\n<h3>What should you pay attention to?<\/h3>\n<p>You can find a new button on the tool bar <img loading=\"lazy\" class=\"alignnone wp-image-165 size-full\" style=\"margin: 0;\" src=\"http:\/\/eventlogxp.com\/blog\/wp-content\/uploads\/2016\/04\/add-imaged-pc.png\" alt=\"add imaged pc button\" width=\"20\" height=\"20\" \/>\u00a0&#8211; Add imaged computer.<\/p>\n<p>How it works. When you have a forensic image, you can mount it as a disk on your computer. And this command lets you add this imaged computer to the tree, and then view event logs from it.<\/p>\n<p><em>Example: <\/em><br \/>\nI currently don&#8217;t have forensic images, but I have an old hard drive and connected it to my computer for tests. It is drive E:. I click &#8220;Add imaged computer&#8221; button and get this dialog:<br \/>\n<a href=\"http:\/\/eventlogxp.com\/blog\/wp-content\/uploads\/2016\/04\/forensic-edition-add-imaged-dialog.png\" rel=\"attachment wp-att-166\" data-rel=\"lightbox-gallery-ey7N5PAX\" data-rl_title=\"\" data-rl_caption=\"\" title=\"\"><img loading=\"lazy\" class=\"alignnone size-medium wp-image-166\" src=\"http:\/\/eventlogxp.com\/blog\/wp-content\/uploads\/2016\/04\/forensic-edition-add-imaged-dialog-300x160.png\" alt=\"Addimaged computer dialog\" width=\"300\" height=\"160\" srcset=\"https:\/\/eventlogxp.com\/blog\/wp-content\/uploads\/2016\/04\/forensic-edition-add-imaged-dialog-300x160.png 300w, https:\/\/eventlogxp.com\/blog\/wp-content\/uploads\/2016\/04\/forensic-edition-add-imaged-dialog.png 461w\" sizes=\"(max-width: 300px) 100vw, 300px\" \/><br \/>\n<\/a>Event Log Explore tries to detect a mounted system drive automatically \u2013 it found it in my case, but if it wouldn&#8217;t find, just type correct path to the Windows folder on the mounted disk.<\/p>\n<p>Type any name in &#8220;Friendly name&#8221; field, and press OK.<\/p>\n<p>Now you can see that this &#8220;computer&#8221; has been added to the tree and you can open it and view event logs.<a href=\"http:\/\/eventlogxp.com\/blog\/wp-content\/uploads\/2016\/04\/tree-with-imaged-logs.png\" rel=\"attachment wp-att-167\" data-rel=\"lightbox-gallery-ey7N5PAX\" data-rl_title=\"\" data-rl_caption=\"\" title=\"\"><img loading=\"lazy\" class=\"alignnone size-medium wp-image-167\" src=\"http:\/\/eventlogxp.com\/blog\/wp-content\/uploads\/2016\/04\/tree-with-imaged-logs-275x300.png\" alt=\"forensic edition - new entity in the tree\" width=\"275\" height=\"300\" srcset=\"https:\/\/eventlogxp.com\/blog\/wp-content\/uploads\/2016\/04\/tree-with-imaged-logs-275x300.png 275w, https:\/\/eventlogxp.com\/blog\/wp-content\/uploads\/2016\/04\/tree-with-imaged-logs.png 310w\" sizes=\"(max-width: 275px) 100vw, 275px\" \/><br \/>\n<\/a>Let&#8217;s try to open any log from this imaged computer, e.g. Application. Double click on Application and the event log will appear as a log file.<br \/>\n<a href=\"http:\/\/eventlogxp.com\/blog\/wp-content\/uploads\/2016\/04\/open-imaged-log.png\" rel=\"attachment wp-att-168\" data-rel=\"lightbox-gallery-ey7N5PAX\" data-rl_title=\"\" data-rl_caption=\"\" title=\"\"><img loading=\"lazy\" class=\"alignnone size-medium wp-image-168\" src=\"http:\/\/eventlogxp.com\/blog\/wp-content\/uploads\/2016\/04\/open-imaged-log-300x104.png\" alt=\"forensic edition - imaged log\" width=\"300\" height=\"104\" srcset=\"https:\/\/eventlogxp.com\/blog\/wp-content\/uploads\/2016\/04\/open-imaged-log-300x104.png 300w, https:\/\/eventlogxp.com\/blog\/wp-content\/uploads\/2016\/04\/open-imaged-log-768x267.png 768w, https:\/\/eventlogxp.com\/blog\/wp-content\/uploads\/2016\/04\/open-imaged-log-1024x356.png 1024w, https:\/\/eventlogxp.com\/blog\/wp-content\/uploads\/2016\/04\/open-imaged-log-660x230.png 660w, https:\/\/eventlogxp.com\/blog\/wp-content\/uploads\/2016\/04\/open-imaged-log.png 1052w\" sizes=\"(max-width: 300px) 100vw, 300px\" \/><br \/>\n<\/a>Pay attention to the icon that appears on the log icons area. Commonly it appears when you set a description server. But now it notifies you that Event Log Explorer will try to get descriptions from the mounted disk, when if it failed to find them locally. Whenever Event Log Explorer tries to get event description, it will try to get it locally first (as always), but if the description is not available, it will open registry on the mounted disk, find a resource file that contains event description and try to extract the description from this file. Note that if you research this disk not only with help of Event Log Explorer, but with e.g. Registry Editor and opened registry files (loaded them as hives), you should unload the hives, or Event Log Explorer won&#8217;t be able to open them. If you want disable \u00a0getting descriptions from the imaged computer, just double click on that icon and uncheck &#8220;If no description available, get it from imaged disk&#8221; option.<\/p>\n<h3>What else<\/h3>\n<p>We disabled functionality that lets you modify event logs, such us clear log command, modifying event log properties.<\/p>\n<h3>What&#8217;s next?<\/h3>\n<p>We are planning to add the following features to forensic edition:<\/p>\n<ul>\n<li>Timeline creation<\/li>\n<li>Opening heavily damaged evtx files<\/li>\n<li>Opening evt and evtx fragments<\/li>\n<li>Features you will requested to add!<\/li>\n<\/ul>\n<a class=\"synved-social-button synved-social-button-share synved-social-size-24 synved-social-resolution-single synved-social-provider-facebook nolightbox\" data-provider=\"facebook\" target=\"_blank\" rel=\"nofollow\" title=\"Share on Facebook\" href=\"https:\/\/www.facebook.com\/sharer.php?u=https%3A%2F%2Feventlogxp.com%2Fblog%2Fwp-json%2Fwp%2Fv2%2Fposts%2F164&#038;t=Event%20Log%20Explorer%20Forensic%20Edition%20Preview&#038;s=100&#038;p&#091;url&#093;=https%3A%2F%2Feventlogxp.com%2Fblog%2Fwp-json%2Fwp%2Fv2%2Fposts%2F164&#038;p&#091;images&#093;&#091;0&#093;=https%3A%2F%2Feventlogxp.com%2Fblog%2Fwp-content%2Fuploads%2F2016%2F04%2Felex-fingerprint.png&#038;p&#091;title&#093;=Event%20Log%20Explorer%20Forensic%20Edition%20Preview\" style=\"font-size: 0px;width:24px;height:24px;margin:0;margin-bottom:5px;margin-right:5px\"><img alt=\"Facebook\" title=\"Share on Facebook\" class=\"synved-share-image synved-social-image synved-social-image-share\" width=\"24\" height=\"24\" style=\"display: inline;width:24px;height:24px;margin: 0;padding: 0;border: none\" src=\"https:\/\/eventlogxp.com\/blog\/wp-content\/plugins\/social-media-feather\/synved-social\/image\/social\/regular\/48x48\/facebook.png\" \/><\/a><a class=\"synved-social-button synved-social-button-share synved-social-size-24 synved-social-resolution-single synved-social-provider-twitter nolightbox\" data-provider=\"twitter\" target=\"_blank\" rel=\"nofollow\" title=\"Share on Twitter\" href=\"https:\/\/twitter.com\/intent\/tweet?url=https%3A%2F%2Feventlogxp.com%2Fblog%2Fwp-json%2Fwp%2Fv2%2Fposts%2F164&#038;text=Check%20this%20Event%20Log%20Explorer%20blog%20post\" style=\"font-size: 0px;width:24px;height:24px;margin:0;margin-bottom:5px;margin-right:5px\"><img alt=\"twitter\" title=\"Share on Twitter\" class=\"synved-share-image synved-social-image synved-social-image-share\" width=\"24\" height=\"24\" style=\"display: inline;width:24px;height:24px;margin: 0;padding: 0;border: none\" src=\"https:\/\/eventlogxp.com\/blog\/wp-content\/plugins\/social-media-feather\/synved-social\/image\/social\/regular\/48x48\/twitter.png\" \/><\/a><a class=\"synved-social-button synved-social-button-share synved-social-size-24 synved-social-resolution-single synved-social-provider-reddit nolightbox\" data-provider=\"reddit\" target=\"_blank\" rel=\"nofollow\" title=\"Share on Reddit\" href=\"https:\/\/www.reddit.com\/submit?url=https%3A%2F%2Feventlogxp.com%2Fblog%2Fwp-json%2Fwp%2Fv2%2Fposts%2F164&#038;title=Event%20Log%20Explorer%20Forensic%20Edition%20Preview\" style=\"font-size: 0px;width:24px;height:24px;margin:0;margin-bottom:5px;margin-right:5px\"><img alt=\"reddit\" title=\"Share on Reddit\" class=\"synved-share-image synved-social-image synved-social-image-share\" width=\"24\" height=\"24\" style=\"display: inline;width:24px;height:24px;margin: 0;padding: 0;border: none\" src=\"https:\/\/eventlogxp.com\/blog\/wp-content\/plugins\/social-media-feather\/synved-social\/image\/social\/regular\/48x48\/reddit.png\" \/><\/a><a class=\"synved-social-button synved-social-button-share synved-social-size-24 synved-social-resolution-single synved-social-provider-pinterest nolightbox\" data-provider=\"pinterest\" target=\"_blank\" rel=\"nofollow\" title=\"Pin it with Pinterest\" href=\"https:\/\/pinterest.com\/pin\/create\/button\/?url=https%3A%2F%2Feventlogxp.com%2Fblog%2Fwp-json%2Fwp%2Fv2%2Fposts%2F164&#038;media=https%3A%2F%2Feventlogxp.com%2Fblog%2Fwp-content%2Fuploads%2F2016%2F04%2Felex-fingerprint.png&#038;description=Event%20Log%20Explorer%20Forensic%20Edition%20Preview\" style=\"font-size: 0px;width:24px;height:24px;margin:0;margin-bottom:5px;margin-right:5px\"><img alt=\"pinterest\" title=\"Pin it with Pinterest\" class=\"synved-share-image synved-social-image synved-social-image-share\" width=\"24\" height=\"24\" style=\"display: inline;width:24px;height:24px;margin: 0;padding: 0;border: none\" src=\"https:\/\/eventlogxp.com\/blog\/wp-content\/plugins\/social-media-feather\/synved-social\/image\/social\/regular\/48x48\/pinterest.png\" \/><\/a><a class=\"synved-social-button synved-social-button-share synved-social-size-24 synved-social-resolution-single synved-social-provider-linkedin nolightbox\" data-provider=\"linkedin\" target=\"_blank\" rel=\"nofollow\" title=\"Share on Linkedin\" href=\"https:\/\/www.linkedin.com\/shareArticle?mini=true&#038;url=https%3A%2F%2Feventlogxp.com%2Fblog%2Fwp-json%2Fwp%2Fv2%2Fposts%2F164&#038;title=Event%20Log%20Explorer%20Forensic%20Edition%20Preview\" style=\"font-size: 0px;width:24px;height:24px;margin:0;margin-bottom:5px;margin-right:5px\"><img alt=\"linkedin\" title=\"Share on Linkedin\" class=\"synved-share-image synved-social-image synved-social-image-share\" width=\"24\" height=\"24\" style=\"display: inline;width:24px;height:24px;margin: 0;padding: 0;border: none\" src=\"https:\/\/eventlogxp.com\/blog\/wp-content\/plugins\/social-media-feather\/synved-social\/image\/social\/regular\/48x48\/linkedin.png\" \/><\/a><a class=\"synved-social-button synved-social-button-share synved-social-size-24 synved-social-resolution-single synved-social-provider-mail nolightbox\" data-provider=\"mail\" rel=\"nofollow\" title=\"Share by email\" href=\"mailto:?subject=Event%20Log%20Explorer%20Forensic%20Edition%20Preview&#038;body=Check%20this%20Event%20Log%20Explorer%20blog%20post:%20https%3A%2F%2Feventlogxp.com%2Fblog%2Fwp-json%2Fwp%2Fv2%2Fposts%2F164\" style=\"font-size: 0px;width:24px;height:24px;margin:0;margin-bottom:5px\"><img alt=\"mail\" title=\"Share by email\" class=\"synved-share-image synved-social-image synved-social-image-share\" width=\"24\" height=\"24\" style=\"display: inline;width:24px;height:24px;margin: 0;padding: 0;border: none\" src=\"https:\/\/eventlogxp.com\/blog\/wp-content\/plugins\/social-media-feather\/synved-social\/image\/social\/regular\/48x48\/mail.png\" \/><\/a>","protected":false},"excerpt":{"rendered":"<p>Several days ago, we published a preview of the new edition of Event Log Explorer software \u2013 Forensic Edition! Here I will show what benefits you can get from this edition. First, I should say that currently it is fully compatible with the standard edition of Event Log Explorer \u2013 it uses the same workspace, the same settings and currently the same registration key. By\u2026 <span class=\"read-more\"><a href=\"https:\/\/eventlogxp.com\/blog\/event-log-explorer-forensic-edition-preview\/\">Read More &raquo;<\/a><\/span><\/p>\n","protected":false},"author":2,"featured_media":172,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[40],"tags":[51,49],"amp_enabled":true,"_links":{"self":[{"href":"https:\/\/eventlogxp.com\/blog\/wp-json\/wp\/v2\/posts\/164"}],"collection":[{"href":"https:\/\/eventlogxp.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/eventlogxp.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/eventlogxp.com\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/eventlogxp.com\/blog\/wp-json\/wp\/v2\/comments?post=164"}],"version-history":[{"count":4,"href":"https:\/\/eventlogxp.com\/blog\/wp-json\/wp\/v2\/posts\/164\/revisions"}],"predecessor-version":[{"id":272,"href":"https:\/\/eventlogxp.com\/blog\/wp-json\/wp\/v2\/posts\/164\/revisions\/272"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/eventlogxp.com\/blog\/wp-json\/wp\/v2\/media\/172"}],"wp:attachment":[{"href":"https:\/\/eventlogxp.com\/blog\/wp-json\/wp\/v2\/media?parent=164"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/eventlogxp.com\/blog\/wp-json\/wp\/v2\/categories?post=164"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/eventlogxp.com\/blog\/wp-json\/wp\/v2\/tags?post=164"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}