Skip to content

Fix rename#7

Merged
maximelb merged 7 commits intomasterfrom
fix-rename
Aug 21, 2025
Merged

Fix rename#7
maximelb merged 7 commits intomasterfrom
fix-rename

Conversation

@maximelb
Copy link
Copy Markdown

Description of the change

Update deps and fix renamed API upstream.

Type of change

  • Bug fix (non-breaking change that fixes an issue)
  • New feature (non-breaking change that adds functionality)
  • Breaking change (fix or feature that would cause existing functionality to not work as expected)

scudette and others added 7 commits July 31, 2024 03:45
…elocidex#30)

The struct layout is a bit different when parsed within a template or
not. Typically events forwarded from a different system do not have a
template interpolated so they will trigger this bug.

Dependency identifier is optional:
https://github.com/libyal/libevtx/blob/main/documentation/Windows%20XML%20Event%20Log%20(EVTX).asciidoc#414-element-start
Some event ID have multiple messages stored in the message lists - these
are generally designed for events which have different number of
properties. So for example the message file might contain two messages
for the same event id, one with 1 expansion and one with 2 expansions.
Then the application might emit an event to the log file with 2
properties or only 1 property of the same event id.

This pr stores both the messages and the number of expasions in the
message set and is able to select the most appropriate one for each
message - we aim to maximize the number of expasions available in the
message string.
@maximelb maximelb merged commit 06f8e57 into master Aug 21, 2025
1 check passed
@maximelb maximelb deleted the fix-rename branch August 21, 2025 22:56
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants