logo

Wrangling Windows Event Logs with Hayabusa & SOF-ELK (Part 1)

ID: 74bf43e1-db81-53e7-93f6-bebf72258fc6

STIX ID: report--74bf43e1-db81-53e7-93f6-bebf72258fc6

Feed Name: Black Hills Infosec Blog

Date Published: 2025-09-17

Date Updated: 2026-04-27

Author: BHIS

...
...

This blog post provides a step-by-step tutorial for processing Windows Event Log (EVTX) files using Hayabusa to produce JSONL timeline output and ingesting that output into SOF-ELK for analysis. It walks through downloading and updating Hayabusa, running the json-timeline command, copying results to a SOF-ELK VM, verifying index ingestion, and using the Kibana web UI to filter and prioritize high-severity detections for efficient endpoint investigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.