plaso
plaso copied to clipboard
Clean up usage of processing configuration, knowledge base and session
Clean up usage of processing configuration, knowledge base and session
- session to contain basic information about invocation of tools
- processing / session configuration to contain tool provided options
- knowledge base to contain values derived from the source data
Use the mediator to interface between processing / session configuration and knowledge base. For now have processing / session configuration override those derived from the source data
To consider:
- support more than 1 host name per system configuration
- ~~move GetSessions out of store https://github.com/log2timeline/plaso/pull/3941~~
- SystemConfiguration
- ~~remove GetSystemConfigurationIdentifier - https://github.com/log2timeline/plaso/pull/3942~~
- have other artifact attribute containers reference system configuration / source volume they belong to ?