EVTX Long Tail Analysis

I have loaded the module for EVTX analysis and I get two results:

image

Windows Event Logs
Windows Event Logs Long Tail Analysis

How are the items in the long tail analysis determined? Is it just a count of EventIDs? I want to make sure I understand it.

This is a great module - Thanks!!

Bob

The long tail analysis is a count of distinct Event id’s per event log.

2 Likes