<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>War Room</title>
	<atom:link href="https://warroom.rsmus.com/category/forensics/elk/feed/" rel="self" type="application/rss+xml" />
	<link>https://warroom.rsmus.com</link>
	<description>Shells From Above</description>
	<lastBuildDate>Mon, 19 May 2025 14:02:01 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.9.4</generator>

<image>
	<url>https://warroom.rsmus.com/wp-content/uploads/2018/09/cropped-favicon-32x32.png</url>
	<title>War Room</title>
	<link>https://warroom.rsmus.com</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Manually upload EVTX log files to ELK with Winlogbeat and PowerShell</title>
		<link>https://warroom.rsmus.com/manually-upload-evtx-log-files-to-elk-with-winlogbeat-and-powershell/</link>
		
		<dc:creator><![CDATA[Zach Burnham]]></dc:creator>
		<pubDate>Fri, 07 Feb 2020 21:42:54 +0000</pubDate>
				<category><![CDATA[ELK]]></category>
		<category><![CDATA[Forensics]]></category>
		<category><![CDATA[EVTX]]></category>
		<category><![CDATA[Kibana]]></category>
		<category><![CDATA[Walkthrough]]></category>
		<category><![CDATA[Winlogbeat]]></category>
		<guid isPermaLink="false">https://warroom.rsmus.com/?p=4982</guid>

					<description><![CDATA[While the Elastic Stack (ELK) is typically used for live log monitoring, Winlogbeat can be modified to manually send cold logs, or old, inactive Windows Event Logs (EVTX) to ELK for analysis. This functionality allows an analyst to take EVTX files from images or data collected from potentially relevant systems and utilize the functionality of [&#8230;]]]></description>
		
		
		
			</item>
	</channel>
</rss>
