-
Notifications
You must be signed in to change notification settings - Fork 259
Description
Describe the bug
There is no way to scan json or jsonl files event when passing --JSON-input option.
Step to Reproduce
./hayabusa-2.18.0-lin-x64-gnu json-timeline -f ../in-jsonl/events.jsonl --JSON-input
or
./hayabusa-2.18.0-lin-x64-gnu json-timeline -d ../in-jsonl --JSON-input
...
Expected behavior
Start time: 2024/12/16 14:58
[ERROR] -f (--filepath) only accepts .evtx files. Hidden files are ignored. If you want to input event logs in JSON format, please specify -J (--JSON-input).
Elapsed time: 00:00:00.001
Please report any issues with Hayabusa rules to: https://github.com/Yamato-Security/hayabusa-rules/issues
Please report any false positives with Sigma rules to: https://github.com/SigmaHQ/sigma/issues
Please submit new Sigma rules with pull requests to: https://github.com/SigmaHQ/sigma/pulls
----------------------------OR---------------------------------------
Start time: 2024/12/16 14:59
[ERROR] No .evtx files were found.
Elapsed time: 00:00:00.001
Please report any issues with Hayabusa rules to: https://github.com/Yamato-Security/hayabusa-rules/issues
Please report any false positives with Sigma rules to: https://github.com/SigmaHQ/sigma/issues
Please submit new Sigma rules with pull requests to: https://github.com/SigmaHQ/sigma/pulls