using im_msvistalog to read fron .evtx files directly

View thread