Difference between revisions of "TruxtonEvent"
Jump to navigation
Jump to search
(Created page with "This class lets you add to the Event table in Truxton. =Attributes and Methods= ==<code>id</code>== This is the [https://en.wikipedia.org/wiki/Universally_unique_identifier GU...") |
|||
| Line 8: | Line 8: | ||
The longer description of the event. | The longer description of the event. | ||
| − | |||
| − | |||
==<code>end</code>== | ==<code>end</code>== | ||
When the event ended. | When the event ended. | ||
| − | |||
| − | |||
| − | |||
| − | |||
==<code>file()</code>== | ==<code>file()</code>== | ||
| Line 22: | Line 16: | ||
==<code>fileid</code>== | ==<code>fileid</code>== | ||
| − | This is the [https://en.wikipedia.org/wiki/Universally_unique_identifier GUID] of the file. | + | This is the [https://en.wikipedia.org/wiki/Universally_unique_identifier GUID] of the file this event came from. |
This identifier corresponds to the <code>ID</code> of the <code>File</code> table. | This identifier corresponds to the <code>ID</code> of the <code>File</code> table. | ||
| − | |||
| − | |||
| − | |||
| − | |||
| − | |||
| − | |||
| − | |||
| − | |||
==<code>mediaid</code>== | ==<code>mediaid</code>== | ||
| − | This is the [https://en.wikipedia.org/wiki/Universally_unique_identifier GUID] of the | + | This is the [https://en.wikipedia.org/wiki/Universally_unique_identifier GUID] of the event. |
This identifier corresponds to the <code>MediaID</code> of the <code>File</code> table. | This identifier corresponds to the <code>MediaID</code> of the <code>File</code> table. | ||
| − | ==<code> | + | ==<code>start</code>== |
| − | |||
| − | |||
| − | |||
| − | |||
| − | |||
| − | |||
| − | |||
| − | |||
| − | |||
| − | |||
| − | ==<code> | + | ==<code>title</code>== |
| − | |||
| − | |||
| − | ==<code> | + | ==<code>type</code>== |
| − | |||
| − | |||
=Sample= | =Sample= | ||
Revision as of 16:58, 27 May 2020
This class lets you add to the Event table in Truxton.
Contents
Attributes and Methods
id
This is the GUID of the event.
It becomes non-zero after save() has been called.
description
The longer description of the event.
end
When the event ended.
file()
This method will return a read-only file that you can use to read the contents of the file.
fileid
This is the GUID of the file this event came from.
This identifier corresponds to the ID of the File table.
mediaid
This is the GUID of the event.
This identifier corresponds to the MediaID of the File table.
start
title
type
Sample
1 import truxton
2
3 def main():
4 etl = truxton.etl()
5 etl.name = "My New ETL"
6 etl.description = "This ETL processes files in the Truxton system"
7 etl.queue = "anewetl"
8 etl.stage = 40
9 etl.expanderid = 0x05fc0bf6a57726a0
10 etl.version = 0
11 etl.depot = "thumbnail"
12 etl.depotype = truxton.DEPOT_TYPE_THUMBNAILS
13 etl.poly = 0
14
15 etl.addarg("--verbose")
16 etl.addarg("Yes")
17
18 etl.sendmefileid("5ecbebc4-9937-2b88-f691-91a800000024")
19 etl.sendmehash("baa51f0cc8361660df911e06e7637485")
20 etl.sendmefiles(truxton.Type_JPEGWithExif, 100)
21 etl.sendmefiles(truxton.Type_TIFFWithExif, 500)
22 etl.sendmelocalfile( "C:/Test Files/Video/Fragmented/Recovered Video.mp4", truxton.Type_MPEG4Video, 0 )
23
24 message = etl.getmessage()
25
26 while message is not None:
27 file_in_truxton = message.file()
28
29 # YOUR FORENSIC CODE GOES HERE
30
31 line_of_text = file_in_truxton.readline()
32
33 if "[SetupAPI" in line_of_text:
34 child = file_in_truxton.newchild()
35 child.name = "Child file from New ETL"
36 child.write("This is the file you were looking for.")
37 child.save()
38
39 if __name__ == "__main__":
40 main()