diff --git a/evtx2sql-convert2sql.php b/evtx2sql-convert2sql.php index d635a7c..414f645 100755 --- a/evtx2sql-convert2sql.php +++ b/evtx2sql-convert2sql.php @@ -153,8 +153,8 @@ function xmldefaulthandler($parser, $data) { $emeta->eventid = $data; } else if (strstr($xmlelement, "EVENT\tSYSTEM\tEVENTRECORDID") <> false) { $emeta->eventrecordid = $data; - } else if (strstr($xmlelement, "EVENT\tSYSTEM\tKEYWORD") <> false) { - $emeta->keyword = $data; + } else if (strstr($xmlelement, "EVENT\tSYSTEM\tKEYWORDS") <> false) { + $emeta->keywords = $data; } else if (strstr($xmlelement, "EVENT\tSYSTEM\tLEVEL") <> false) { $emeta->level = $data; } else if (strstr($xmlelement, "EVENT\tSYSTEM\tCOMPUTER") <> false) {