Title
#windows
thor

thor

11/14/2019, 4:34 AM
@puffycid I'd love that. I really wanted this some time ago but got a bit held up on the XML -> JSON parsing. If you're up to the challenge here's the branch where I started this (https://github.com/osquery/osquery/compare/master...muffins:windows-event-log-vtable)
puffycid

puffycid

11/14/2019, 12:55 PM
Cool I've been messing around with event log parsing on my own branch But I will take a look at your implementation
thor

thor

11/14/2019, 5:57 PM
Lemme know if I can help at all! Happy to do reviews or take on small bits of the implementation