Visualising Event Logs
Shusey Tomonaga describes how the “LogonTracer” tool works and how to run it. JPCERT / CC developed and released the LogonTracer tool, which supports this analysis of the event log.
The analysis of event logs is an indispensable task in the investigation of security incidents. However, since the event logs are huge depending on the environment, it is necessary to understand how to begin the analysis.
Analysis of event logs is a time-consuming process. This tool allows you to easily analyze the event log, visualizing the relationship between accounts and hosts.