Hello Apriestman.
I come back to you after a new test, with the same result : Autopsy 4.14.0 64 bits blocked at 86%.
I have a file CopyLogs.zip which contains all the logs at each step. But I can’t add to the post (the forum only accept .jpg files ; I try renaming the .zip in .jpg, but it was not accepted). Can you give me a possibility to send you the Copylogs.zip ? This file is necessary.
I uninstalled Autopsy and reinstalled Autopsy 4.14.0 for Windows 64 bits.
The version of Java is…
All the test was done on 15th (february)
I run Autopsy a first time without creating case.
The logs are in the directory 1-Logs_FirstExecStoppedWithoutCreatingCase
Please, see the CopyLogs.zip file.
I run it again (Exec 2) and I copied the logs in 2-Logs_Exec2BeforeCreatingCase
Before creating the Case ; I stopped my antivirus (Avast) and my firewall (Comodo).
I created the case (at 14:57).
I selected lhe following ingest modules : Recent activity, File type identification, Extension mismatch detection, Exif parser, Keyword search, Email Parser, Encryption detection, Interesting files identifier, Correlation Engine, Virtual Machine Extractor, Data source integrity.
Not selected : Hash lookup, Photorec carver, Plaso, Android analyser.
Run ingest on : Allfiles, directories, and unallocated space.
The source image is a dd image of a MacBook disk (only 60 Gb).
The “Analysing files from image…” began at 14:57. At this beginning, I copied the logs, in 3-Logs_Exec2AfterCreationCaseAtBeginning,
logs of [myself]\AppData\Roaming\autopsy\var\log in the directory FromVar-log
The logs of the case, in the directory FromTheCase.
When the progression was blocked at 86%, I copied the logs in 4-Logs_Exec2WhenBlocquedAt86percent, in the subdirectories FromVar-log and FromTheCase.
After, I quitted Autopsy, by the menu Case > Exit.
The “Solr Keyword Search Service” (Closing Case Ressorces ; Preparing) ran a long time and after Autopsy failed.
I copied the logs in 5-Logs_Exec2WhenExit (FromVar-log and FromTheCase)
About 1-Logs_FirstExecStoppedWithoutCreatingCase
in autopsy.log.o, no error, no warning.
In messages.log, line 22 “J2KImageReader not loaded. JPEG2000 files will not be processed.”
and 15 warnings in lines 25 to 27, 117 and 118, 154 to 158, 160 to 162, 169, 184 (the end of this line is in French ; translation : the marking of the document following the root element must have a correct format.
About 2-Logs_Exec2BeforeCreatingCase
in autopsy.log.o, no error, no warning.
In messages.log, 12 warning in lines 25 to 27, 117 and 118, 154 to 158, 160 and 161.
About 3-Logs_Exec2AfterCreationCaseAtBeginning
in the directory FromTheCase, in autopsy.log.0, there are 21 warning (with error) which seem mainly problems with character sets.
In the directory FromVar-log, in autopsy.log.0, no warning no error ; in Messages.log, the same 12 warnings as in 2-Logs_Exec2BeforeCreatingCase.
About 4-Logs_Exec2WhenBlocquedAt86percent
in the directory FromTheCase, in the autopys.log.0, there are the 40 errors reported in the screen when clicking on the forbidden sense symbol at the right end of the line "Analyzing files from image … ". See, in the same directory, the fle “The40errors.txt” and the ScreenCopy.jpg. These errors occured at the beginning, 28 minutes after beginnng, and all occured in 5 seconds. Other errors in the same autopys.log.0 after the last 40th error (line 3442), see OtherErrorsAfter.txt.
In the directory FromVar-log, no warning no error in the autopsy.log.0. In messages.log, the same 12 warnings as in 3-Logs_Exec2AfterCreationCaseAtBeginning and 2 new Warnings in lines 1699 and 1700. In Tika.log.0, 803 Warnings (Avertissement, in French) including 786 “Caused by: java…”. In solr.log.stderr 1 line, 1 warning. In solr.log.stdout22 lines, 21 WARN.
About 5-Logs_Exec2WhenExit
in the directory FromCase, the new records begin in line 5385, about actions to close Autopsy. It crashed at 18:22 14".
In the Directoria FromVar-log, in autopsy.log.0, the last record is at 18:23 33".In messages.log, there are 7 new records (beginning at line 1701).In monitor.log.0, the new records begin at line 569.The tika.log.0 is the same as this of 4- above.
I am sorry for so many work to you and I thank you very much.
Kindly.