For a forensic timeline tool, the strongest matches are yamato-security/hayabusa (Hayabusa is a Windows event log analyzer that generates), withsecurelabs/chainsaw (Chainsaw is a Windows forensic analysis tool that ingests) and log2timeline/plaso (Plaso ingests system logs from multiple sources, automatically parses). wazuh/wazuh and opensearch-project/opensearch round out the shortlist. Each is ranked by relevance to your query, popularity and recent activity.
Analyze and reconstruct historical event sequences by parsing and correlating data from various system logs.
Hayabusa is a Windows event log analyzer, threat hunting tool, and forensic timeline generator. It functions as a detection engine that applies threat patterns to logs to identify suspicious behavior and security threats. The project distinguishes itself through the ability to synchronize detection rules from remote repositories and tune risk levels to prioritize critical alerts. It also provides specialized forensic capabilities, such as extracting event log data into chronological records for incident response investigations. The tool's broader capabilities include security log enrichment
Hayabusa is a Windows event log analyzer that generates chronological forensic timelines from EVTX files, directly aligning with the request for log ingestion and timeline reconstruction, though its focus is Windows-specific threat hunting rather than multi-source ingestion or visual timeline exports.
Chainsaw is a Windows forensic analysis tool used for parsing system databases and extracting security artefacts. It functions as a forensic artefact extractor and a scanner for identifying security threats and log tampering within Windows event logs. The project distinguishes itself by implementing a Sigma rule forensic scanner that applies standardized detection logic and custom rule sets to event logs and forensic artefacts. It enables threat hunting workflows by matching event data against patterns to identify malicious activity, lateral movement, and brute force attacks. The tool's capa
Chainsaw is a Windows forensic analysis tool that ingests Windows event logs and reconstructs execution timelines, with event correlation and Sigma-rule–based search and filtering, fitting your search for a timeline reconstruction tool—though it is limited to Windows event logs and does not include built-in timeline visualization or broad log format support.
Super timeline all the things
Plaso ingests system logs from multiple sources, automatically parses and correlates events into a chronological timeline for incident reconstruction, and supports search, filtering, and export to CSV and other formats—exactly the kind of tool this search targets.
Wazuh is an integrated security platform that combines endpoint detection and response, security information and event management, and cloud workload protection. It functions as a centralized system for collecting telemetry, aggregating logs, and correlating events across distributed infrastructure to maintain security and integrity. The platform distinguishes itself through its active response orchestration, which allows for the automated execution of scripts on remote endpoints to neutralize threats in real time. It provides deep visibility into system activity through file integrity monito
Wazuh is a security monitoring and SIEM platform that ingests logs from distributed agents, correlates events, and provides a timeline view for incident reconstruction, which aligns with the requested log analysis and timeline reconstruction capability even though its primary focus is security rather than general-purpose forensic timelines.
OpenSearch is a distributed search and analytics engine designed for indexing, searching, and analyzing massive volumes of structured and unstructured data in real time. It functions as a comprehensive platform that integrates enterprise-grade search capabilities, a vector database for high-dimensional similarity lookups, and a unified observability suite for monitoring logs, metrics, and traces across complex distributed environments. The platform distinguishes itself through its support for agentic workflow automation, allowing users to orchestrate multi-agent tasks and integrate foundation
OpenSearch is a distributed search and analytics platform with an integrated observability suite that ingests logs from multiple sources and visualizes them as chronological timelines via dashboards, fitting the log analysis and timeline reconstruction use case, though it is a broader engine rather than a specialized timeline tool.
OpenObserve is a unified observability data platform designed to ingest, store, and analyze logs, metrics, and traces. It functions as a cloud-native monitoring tool that centralizes telemetry from diverse sources, including standard collectors and cloud service providers, into a single, scalable system. By utilizing a columnar storage engine backed by object storage, the platform enables efficient long-term data retention and high-performance analytical querying. The platform distinguishes itself through deep integration with artificial intelligence, allowing users to query data using natura
OpenObserve is a unified observability platform that ingests logs from multiple sources and provides search and analytics, fitting the need for timeline-based incident reconstruction, though its broader scope and lack of explicit timeline visualization features make it a narrower fit than a dedicated timeline tool.
SigNoz is a full-stack observability platform designed to collect, store, and visualize metrics, logs, and distributed traces in a unified environment. It leverages OpenTelemetry-based data collection to ingest telemetry from diverse sources using vendor-neutral protocols, ensuring interoperability across complex microservices architectures. The platform utilizes a high-performance columnar storage engine to enable rapid aggregation and filtering, providing a centralized backend for monitoring application health and performance. What distinguishes the platform is its focus on automated instru
SigNoz is an observability platform that ingests logs and traces, so it can provide chronological timelines of events, but its primary focus is on distributed tracing and APM rather than dedicated system log analysis and event reconstruction for incident timeline purposes.
This project is a containerized orchestration layer for the Elastic Stack, providing a pre-configured set of Docker Compose files to deploy Elasticsearch, Logstash, and Kibana as a unified data analysis stack. It functions as a centralized log management system for ingesting, indexing, and searching log data using a cluster of interconnected services. The deployment pattern includes an Elasticsearch cluster manager that enables scaling data nodes through replica scaling and internal discovery. It provides a web-based administration interface for monitoring cluster health and status. The syst
This repository is a Docker Compose setup for deploying the Elastic Stack (Elasticsearch, Logstash, Kibana) as a centralized log management infrastructure, rather than a direct log analysis and timeline reconstruction tool; while the ELK stack offers many required features, the repo itself is an orchestration layer for deploying it, not the tool you interact with to visualize timelines or correlate events.
GRR is a distributed incident response platform and asynchronous forensic task orchestrator. It functions as a remote forensics framework designed to collect and analyze volatile data, system memory, and digital artifacts from remote hosts during security incident response. The system operates as a remote endpoint triage system, utilizing a coordinated architecture to manage a fleet of agents. It enables the execution of investigative tasks across multiple systems, allowing for the search of files and registries across a large fleet of machines to identify compromised hosts. The platform pro
GRR is a remote forensics and incident response platform for collecting artifacts from endpoints, which supports forensic timeline reconstruction as a feature, but it is not a dedicated log analysis and timeline visualization tool that ingests logs from multiple sources and provides an event timeline view like the visitor is looking for.
Logan is a cross-platform mobile logging framework that collects, stores, and uploads client-side logs from iOS, Android, Web, and Flutter environments for centralized debugging and analysis. It provides a complete pipeline from client-side log buffering and file-based local storage through to server-side ingestion and a visual browser for inspecting parsed logs. The system uses a structured binary protocol to encode log entries with content, type, timestamp, and thread metadata, enabling consistent parsing across platforms. A log receiving server handles uploaded files, while a web-based int
Logan is a cross-platform mobile logging framework focused on client-side debugging, not a system-log timeline reconstruction tool — it lacks system-log ingestion and event correlation for incident analysis.
LogonTracer is a security auditing tool designed for logon analysis and forensic log auditing. It functions as a dockerized security auditor that utilizes a security event graph database to map account names and network addresses, allowing for the visualization of complex system compromise patterns and authentication paths. The system features a Sigma detection engine that scans imported event logs against standardized rule sets to identify known malicious activity. It also includes an anomalous behavior detector that applies statistical analysis, graph algorithms, and hidden Markov models to
LogonTracer ingests Windows event logs and visualizes authentication relationships as a graph, but it is optimized for attack-path mapping rather than producing a chronological timeline of general system events, so it only partially meets the timeline reconstruction focus you described.
HyperDX is an OpenTelemetry observability platform that provides centralized log management, distributed tracing, and a self-hosted monitoring stack. It functions as a unified system for collecting, indexing, and visualizing logs, metrics, and traces from cloud and container environments. The platform distinguishes itself with specialized tooling for large language model monitoring and session replay, allowing user interactions in the browser to be linked to backend telemetry. It employs schema-less JSON parsing to index structured logs dynamically and uses source maps to resolve minified sta
HyperDX is a broad OpenTelemetry observability platform that ingests logs and traces, which supports timeline-like exploration, but it is designed for application monitoring and debugging rather than dedicated chronological incident reconstruction and event correlation.
| Repository | Stars | Language | License | Last push |
|---|---|---|---|---|
| yamato-security/hayabusa | 3K | Rust | agpl-3.0 | |
| withsecurelabs/chainsaw | 3.4K | Rust | gpl-3.0 | |
| log2timeline/plaso | 2.1K | Python | Apache-2.0 | |
| wazuh/wazuh | 14.8K | C | other | |
| opensearch-project/opensearch | 13.2K | Java | Apache-2.0 | |
| openobserve/openobserve | 17.9K | TypeScript | agpl-3.0 | |
| signoz/signoz | 27.4K | TypeScript | NOASSERTION | |
| deviantony/docker-elk | 18.4K | Shell | MIT | |
| google/grr | 5.1K | Python | Apache-2.0 | |
| meituan-dianping/logan | 6K | C | MIT |