7.8 Interpreting Summary Information
If a log file contains invalid data or lacks a recognizable (CEH or SEH) header, the results produced by the summary command will be affected.
- If the final event in a log file contains invalid data, SEA cannot determine the date information for the Last Entry Time field. In this case, the current date and time are shown in the Last Entry Time field.
- If an event does not include a recognized header, the event type is reported as 0. In this case the summary command indicates that the event is Unrecognized/Unsupported. This applies to events that only contain a Windows header even if they are translated correctly.
The new command to simulate automatic analysis using a saved error log file is:
wsea ana input eventlog notify