Skip to content

Event Log EVT Files

Evidence: Event Log EVT Files
Description: Dump evt event log files
Category: EventLogs
Platform: windows
Short Name: evt
Is Parsed: Yes
Sent to Investigation Hub: Yes
Collect File(s): No

Windows event log files (EVTX/EVT) store channel data on disk. This data is essential for offline analysis and evidence preservation.

This collector gathers structured data about event log evt files.

This collector enumerates standard event log directories (EVTX in winevt\Logs, legacy EVT in System32\config), copies files, and records metadata and hashes.

This evidence is crucial for forensic investigations to preserve original log files and verify integrity with hashes.