{"id":517,"date":"2022-04-17T12:56:56","date_gmt":"2022-04-17T12:56:56","guid":{"rendered":"https:\/\/eventlogxp.com\/blog\/?p=517"},"modified":"2022-04-17T12:56:56","modified_gmt":"2022-04-17T12:56:56","slug":"event-log-explorer-forensic-edition","status":"publish","type":"post","link":"https:\/\/eventlogxp.com\/blog\/event-log-explorer-forensic-edition\/","title":{"rendered":"Event Log Explorer Forensic Edition"},"content":{"rendered":"<p>Recently we released a new edition of Event Log Explorer \u2013 Forensic Edition. Currently it has a beta version status \u2013 the final release will appear after we complete the documentation and add extra forensic features.<\/p>\n<p>Here I will describe the difference between the standard and forensic editions.<\/p>\n<p>The program keeps all features of the Standard Edition, and you commonly don\u2019t need to use the Standard Edition if you have the Forensic one. Anyway, if you have a license key to Forensic Edition, you can use it with Standard Edition. However, if you have a license key to Standard Edition, it will work only with the current beta version of Forensic Edition but won\u2019t work with the final release. You will be able to upgrade from Standard to Forensic by paying the price difference.<\/p>\n<p>New program doesn\u2019t require elevation when you run it. So, if you don\u2019t have the admin rights, you can still run this program. The standard edition requires elevation to access the Security log and to manage event logs (e.g., clear them). Forensic users commonly work with log files, so it is not necessary to start it elevated. However, if you need to access the Security log, you may run it as Admin manually.<\/p>\n<p>When you start the program, you can find the major difference between the editions in the user interface. There are two new menu items in the main menu: Forensics and Script.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"http:\/\/eventlogxp.com\/blog\/wp-content\/uploads\/2022\/04\/ElexFE-menu.png\" data-rel=\"lightbox-gallery-4eq6Dgwp\" data-rl_title=\"\" data-rl_caption=\"\" title=\"\"><img loading=\"lazy\" class=\"alignnone size-full wp-image-520\" src=\"http:\/\/eventlogxp.com\/blog\/wp-content\/uploads\/2022\/04\/ElexFE-menu.png\" alt=\"\" width=\"858\" height=\"109\" srcset=\"https:\/\/eventlogxp.com\/blog\/wp-content\/uploads\/2022\/04\/ElexFE-menu.png 858w, https:\/\/eventlogxp.com\/blog\/wp-content\/uploads\/2022\/04\/ElexFE-menu-300x38.png 300w, https:\/\/eventlogxp.com\/blog\/wp-content\/uploads\/2022\/04\/ElexFE-menu-768x98.png 768w, https:\/\/eventlogxp.com\/blog\/wp-content\/uploads\/2022\/04\/ElexFE-menu-660x84.png 660w\" sizes=\"(max-width: 858px) 100vw, 858px\" \/><\/a><\/p>\n<p>Script lets you create and run your own scripts (written in Pascal script) which helps you to automate some operations or create complex filters. We will add scripting to the Enterprise Edition of Event Log Explorer as well.<\/p>\n<p>Forensics menu opens access to the forensic features of the program.<\/p>\n<p><strong>Add imaged computer<\/strong> lets you create a virtual computer in the Objects tree and access its log files as \u201clive\u201d logs.<\/p>\n<p><strong>Forensic open file<\/strong> lets you open event log files using a \u201cforensic\u201d method. This includes opening files without Windows API and allows you to open damaged files.<\/p>\n<p><strong>Deep scan<\/strong> lets you scan an event log file, a disk image or even a whole disk for events. This lets you extract events from highly damaged log files or unmounted or damaged disk images.<\/p>\n<p><strong>Take and Load snapshot<\/strong> let you save your current event log view into a file for future analysis.<\/p>\n<p>I will write several articles about each new forensic feature soon, but now you can download and try the new forensic edition yourself:<\/p>\n<p><a href=\"https:\/\/eventlogxp.com\/download.php\" target=\"_blank\" rel=\"noreferrer noopener\">Download Event Log Explorer Forensic Edition<\/a> right now to get access to new forensic features of the program.<\/p>\n<a class=\"synved-social-button synved-social-button-share synved-social-size-24 synved-social-resolution-single synved-social-provider-facebook nolightbox\" data-provider=\"facebook\" target=\"_blank\" rel=\"nofollow\" title=\"Share on Facebook\" href=\"https:\/\/www.facebook.com\/sharer.php?u=https%3A%2F%2Feventlogxp.com%2Fblog%2Fwp-json%2Fwp%2Fv2%2Fposts%2F517&#038;t=Event%20Log%20Explorer%20Forensic%20Edition&#038;s=100&#038;p&#091;url&#093;=https%3A%2F%2Feventlogxp.com%2Fblog%2Fwp-json%2Fwp%2Fv2%2Fposts%2F517&#038;p&#091;images&#093;&#091;0&#093;=https%3A%2F%2Feventlogxp.com%2Fblog%2Fwp-content%2Fuploads%2F2022%2F04%2FElex_FE_logo.png&#038;p&#091;title&#093;=Event%20Log%20Explorer%20Forensic%20Edition\" style=\"font-size: 0px;width:24px;height:24px;margin:0;margin-bottom:5px;margin-right:5px\"><img alt=\"Facebook\" title=\"Share on Facebook\" class=\"synved-share-image synved-social-image synved-social-image-share\" width=\"24\" height=\"24\" style=\"display: inline;width:24px;height:24px;margin: 0;padding: 0;border: none\" src=\"https:\/\/eventlogxp.com\/blog\/wp-content\/plugins\/social-media-feather\/synved-social\/image\/social\/regular\/48x48\/facebook.png\" \/><\/a><a class=\"synved-social-button synved-social-button-share synved-social-size-24 synved-social-resolution-single synved-social-provider-twitter nolightbox\" data-provider=\"twitter\" target=\"_blank\" rel=\"nofollow\" title=\"Share on Twitter\" href=\"https:\/\/twitter.com\/intent\/tweet?url=https%3A%2F%2Feventlogxp.com%2Fblog%2Fwp-json%2Fwp%2Fv2%2Fposts%2F517&#038;text=Check%20this%20Event%20Log%20Explorer%20blog%20post\" style=\"font-size: 0px;width:24px;height:24px;margin:0;margin-bottom:5px;margin-right:5px\"><img alt=\"twitter\" title=\"Share on Twitter\" class=\"synved-share-image synved-social-image synved-social-image-share\" width=\"24\" height=\"24\" style=\"display: inline;width:24px;height:24px;margin: 0;padding: 0;border: none\" src=\"https:\/\/eventlogxp.com\/blog\/wp-content\/plugins\/social-media-feather\/synved-social\/image\/social\/regular\/48x48\/twitter.png\" \/><\/a><a class=\"synved-social-button synved-social-button-share synved-social-size-24 synved-social-resolution-single synved-social-provider-reddit nolightbox\" data-provider=\"reddit\" target=\"_blank\" rel=\"nofollow\" title=\"Share on Reddit\" href=\"https:\/\/www.reddit.com\/submit?url=https%3A%2F%2Feventlogxp.com%2Fblog%2Fwp-json%2Fwp%2Fv2%2Fposts%2F517&#038;title=Event%20Log%20Explorer%20Forensic%20Edition\" style=\"font-size: 0px;width:24px;height:24px;margin:0;margin-bottom:5px;margin-right:5px\"><img alt=\"reddit\" title=\"Share on Reddit\" class=\"synved-share-image synved-social-image synved-social-image-share\" width=\"24\" height=\"24\" style=\"display: inline;width:24px;height:24px;margin: 0;padding: 0;border: none\" src=\"https:\/\/eventlogxp.com\/blog\/wp-content\/plugins\/social-media-feather\/synved-social\/image\/social\/regular\/48x48\/reddit.png\" \/><\/a><a class=\"synved-social-button synved-social-button-share synved-social-size-24 synved-social-resolution-single synved-social-provider-pinterest nolightbox\" data-provider=\"pinterest\" target=\"_blank\" rel=\"nofollow\" title=\"Pin it with Pinterest\" href=\"https:\/\/pinterest.com\/pin\/create\/button\/?url=https%3A%2F%2Feventlogxp.com%2Fblog%2Fwp-json%2Fwp%2Fv2%2Fposts%2F517&#038;media=https%3A%2F%2Feventlogxp.com%2Fblog%2Fwp-content%2Fuploads%2F2022%2F04%2FElex_FE_logo.png&#038;description=Event%20Log%20Explorer%20Forensic%20Edition\" style=\"font-size: 0px;width:24px;height:24px;margin:0;margin-bottom:5px;margin-right:5px\"><img alt=\"pinterest\" title=\"Pin it with Pinterest\" class=\"synved-share-image synved-social-image synved-social-image-share\" width=\"24\" height=\"24\" style=\"display: inline;width:24px;height:24px;margin: 0;padding: 0;border: none\" src=\"https:\/\/eventlogxp.com\/blog\/wp-content\/plugins\/social-media-feather\/synved-social\/image\/social\/regular\/48x48\/pinterest.png\" \/><\/a><a class=\"synved-social-button synved-social-button-share synved-social-size-24 synved-social-resolution-single synved-social-provider-linkedin nolightbox\" data-provider=\"linkedin\" target=\"_blank\" rel=\"nofollow\" title=\"Share on Linkedin\" href=\"https:\/\/www.linkedin.com\/shareArticle?mini=true&#038;url=https%3A%2F%2Feventlogxp.com%2Fblog%2Fwp-json%2Fwp%2Fv2%2Fposts%2F517&#038;title=Event%20Log%20Explorer%20Forensic%20Edition\" style=\"font-size: 0px;width:24px;height:24px;margin:0;margin-bottom:5px;margin-right:5px\"><img alt=\"linkedin\" title=\"Share on Linkedin\" class=\"synved-share-image synved-social-image synved-social-image-share\" width=\"24\" height=\"24\" style=\"display: inline;width:24px;height:24px;margin: 0;padding: 0;border: none\" src=\"https:\/\/eventlogxp.com\/blog\/wp-content\/plugins\/social-media-feather\/synved-social\/image\/social\/regular\/48x48\/linkedin.png\" \/><\/a><a class=\"synved-social-button synved-social-button-share synved-social-size-24 synved-social-resolution-single synved-social-provider-mail nolightbox\" data-provider=\"mail\" rel=\"nofollow\" title=\"Share by email\" href=\"mailto:?subject=Event%20Log%20Explorer%20Forensic%20Edition&#038;body=Check%20this%20Event%20Log%20Explorer%20blog%20post:%20https%3A%2F%2Feventlogxp.com%2Fblog%2Fwp-json%2Fwp%2Fv2%2Fposts%2F517\" style=\"font-size: 0px;width:24px;height:24px;margin:0;margin-bottom:5px\"><img alt=\"mail\" title=\"Share by email\" class=\"synved-share-image synved-social-image synved-social-image-share\" width=\"24\" height=\"24\" style=\"display: inline;width:24px;height:24px;margin: 0;padding: 0;border: none\" src=\"https:\/\/eventlogxp.com\/blog\/wp-content\/plugins\/social-media-feather\/synved-social\/image\/social\/regular\/48x48\/mail.png\" \/><\/a>","protected":false},"excerpt":{"rendered":"<p>Recently we released a new edition of Event Log Explorer \u2013 Forensic Edition. Currently it has a beta version status \u2013 the final release will appear after we complete the documentation and add extra forensic features. Here I will describe the difference between the standard and forensic editions. The program keeps all features of the Standard Edition, and you commonly don\u2019t need to use the\u2026 <span class=\"read-more\"><a href=\"https:\/\/eventlogxp.com\/blog\/event-log-explorer-forensic-edition\/\">Read More &raquo;<\/a><\/span><\/p>\n","protected":false},"author":2,"featured_media":518,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[40],"tags":[51,49],"amp_enabled":true,"_links":{"self":[{"href":"https:\/\/eventlogxp.com\/blog\/wp-json\/wp\/v2\/posts\/517"}],"collection":[{"href":"https:\/\/eventlogxp.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/eventlogxp.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/eventlogxp.com\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/eventlogxp.com\/blog\/wp-json\/wp\/v2\/comments?post=517"}],"version-history":[{"count":3,"href":"https:\/\/eventlogxp.com\/blog\/wp-json\/wp\/v2\/posts\/517\/revisions"}],"predecessor-version":[{"id":522,"href":"https:\/\/eventlogxp.com\/blog\/wp-json\/wp\/v2\/posts\/517\/revisions\/522"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/eventlogxp.com\/blog\/wp-json\/wp\/v2\/media\/518"}],"wp:attachment":[{"href":"https:\/\/eventlogxp.com\/blog\/wp-json\/wp\/v2\/media?parent=517"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/eventlogxp.com\/blog\/wp-json\/wp\/v2\/categories?post=517"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/eventlogxp.com\/blog\/wp-json\/wp\/v2\/tags?post=517"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}