Skip to content

Event Log EVT Records

Evidence: Event Log EVT Records
Description: Collect most recent event log records
Category: EventLogs
Platform: windows
Short Name: evtr
Is Parsed: Yes
Sent to Investigation Hub: Yes
Collect File(s): Yes

Windows event logs (EVTX/EVT) capture system, security, and application events. This data is essential for detection and incident response.

This collector gathers structured data about event log evt records.

This collector loads an event configuration, locates channel EVTX files, and parses recent events with filters, storing summaries and event data rows.

This evidence is crucial for forensic investigations to reconstruct timelines, detect attacks, and analyze security-relevant events. Default Windows event collection profiles include critical Kerberos Key Distribution Center (KDC) events (Event ID 42), expanding detection visibility for authentication downgrade or anomaly scenarios often relevant in enterprise breaches.