diff --git a/evtx2sql-convert2sql.php b/evtx2sql-convert2sql.php index 8bf68d8..ebf1f38 100755 --- a/evtx2sql-convert2sql.php +++ b/evtx2sql-convert2sql.php @@ -95,23 +95,23 @@ function sql_addmeta ($data, $darray) { if (isset ($darray['ServiceName'])) $data->servicename = $darray['ServiceName']; if (isset ($darray['Status'])) $data->status = $darray['Status']; if (isset ($darray['ProcessName'])) $data->data = $darray['ProcessName']; + + printf ("INSERT INTO tbl_EventMeta (eventrecordid, time, eventid, task, level, keywords, computer, server, username, domainname, servicename, data, status) VALUES('%s','%s','%s','%s','%s','%s','%s','%s','%s','%s','%s','%s','%s');\n", + $data->eventrecordid, + $data->time, + $data->eventid, + $data->task, + $data->level, + substr($data->keywords, 0, 32), + substr($data->computer, 0, 64), + substr($data->server, 0, 64), + substr($data->username, 0, 64), + substr($data->domainname, 0, 64), + substr($data->servicename, 0, 64), + substr($data->data, 0, 64), + substr($data->status, 0, 16) + ); } - - printf ("INSERT INTO tbl_EventMeta (eventrecordid, time, eventid, task, level, keywords, computer, server, username, domainname, servicename, data, status) VALUES('%s','%s','%s','%s','%s','%s','%s','%s','%s','%s','%s','%s','%s');\n", - $data->eventrecordid, - $data->time, - $data->eventid, - $data->task, - $data->level, - substr($data->keywords, 0, 32), - substr($data->computer, 0, 64), - substr($data->server, 0, 64), - substr($data->username, 0, 64), - substr($data->domainname, 0, 64), - substr($data->servicename, 0, 64), - substr($data->data, 0, 64), - substr($data->status, 0, 16) - ); $data->Clear(); };