Timestamp missing in .evtx
When importing .evtx files from windows event viewer. The Timestamp field stays empty. The timestamp information is crucial in some log audits.
@LeTak0 I cannot reproduce the symptom you mentioned with my .evtx files, could you help to provide some .evtx files which show empty timestamp for further analysis? Thanks.
@LeTak0 I cannot reproduce the symptom you mentioned with my .evtx files, could you help to provide some .evtx files which show empty timestamp for further analysis? Thanks.
@LeTak0 I cannot reproduce the symptom you mentioned with my .evtx files, could you help to provide some .evtx files which show empty timestamp for further analysis? Thanks.
@LeTak0 The Timestamp column show as expected after opening the .evtx file you provided:
Could you help to provide screenshot, operating system and the version of ULogViewer you use? Thanks.
4.0.8.303 ULogViewer Linux Kernel 6.6.22.1 Arch Linux Wayland , Hyprland
@LeTak0 I cannot reproduce the symptom you mentioned with my .evtx files, could you help to provide some .evtx files which show empty timestamp for further analysis? Thanks.
@LeTak0 The
Timestampcolumn show as expected after opening the .evtx file you provided:
Could you help to provide screenshot, operating system and the version of ULogViewer you use? Thanks.
