Skip to content

[bug] --JSON-input option does not work #1530

@nskley

Description

@nskley

Describe the bug
There is no way to scan json or jsonl files event when passing --JSON-input option.

Step to Reproduce
./hayabusa-2.18.0-lin-x64-gnu json-timeline -f ../in-jsonl/events.jsonl --JSON-input
or
./hayabusa-2.18.0-lin-x64-gnu json-timeline -d ../in-jsonl --JSON-input
...

Expected behavior
Start time: 2024/12/16 14:58

[ERROR] -f (--filepath) only accepts .evtx files. Hidden files are ignored. If you want to input event logs in JSON format, please specify -J (--JSON-input).

Elapsed time: 00:00:00.001

Please report any issues with Hayabusa rules to: https://github.com/Yamato-Security/hayabusa-rules/issues
Please report any false positives with Sigma rules to: https://github.com/SigmaHQ/sigma/issues
Please submit new Sigma rules with pull requests to: https://github.com/SigmaHQ/sigma/pulls
----------------------------OR---------------------------------------
Start time: 2024/12/16 14:59

[ERROR] No .evtx files were found.

Elapsed time: 00:00:00.001

Please report any issues with Hayabusa rules to: https://github.com/Yamato-Security/hayabusa-rules/issues
Please report any false positives with Sigma rules to: https://github.com/SigmaHQ/sigma/issues
Please submit new Sigma rules with pull requests to: https://github.com/SigmaHQ/sigma/pulls

Metadata

Metadata

Assignees

Labels

bugSomething isn't working

Type

No type

Projects

No projects

Relationships

None yet

Development

No branches or pull requests

Issue actions