ntfs-logfile

Retrieves the file name, creation/modification/access time, and redo/undo operation type in the NTFS transaction log file. You can see the history of file creation, deletion, and renaming using the retrieved data.

Syntax

ntfs-logfile [zippath=ZIPFILE_PATH] FILE_PATH
Required Parameters
FILE_PATH
Path to NTFS log file. If you provided the zippath option, input the file path in the ZIP file.
zippath=ZIPFILE_PATH
The path to the ZIP file.

Description

Output Fields

After running the ntfs-logfile command, the output fields are as follows:

FieldTypeDescription
access_atDateLast access time
client_data_lengthIntegerRecord volume
created_atDateTime of creation
file_nameStringFile name
flagsIntegerFlag
lsnIntegerLog file sequence number
mft_headStringMFT header
mft_link_countIntegerNumber of entries referencing the corresponding file
mft_lsnIntegerMFT log file sequence number
modified_atDateLast modification time
pageIntegerPage number
prev_lsnIntegerPrevious log file sequence number
record_typeIntegerRecord type (2: checkpoint record, 1: other records)
redo_lenIntegerSize of redo data
redo_offsetIntegerOffset of redo data
redo_opStringRedo operation code
undo_lenIntegerSize of undo data
undo_offsetIntegerOffset of undo data
undo_opStringUndo operation code
Redo_op, Undo_op Operation Codes

The Operation Codes output to the redo_op and undo_op field are as follows:

redo_op/undo_opHex value
noop0x00
compensation_log_record0x1
initialize_file_record_segment0x2
deallocate_file_record_segment0x3
write_end_of_file_record_segment0x4
create_attribute0x5
delete_attribute0x6
update_resident_value0x7
update_non_resident_value0x8
update_mapping_pairs0x9
delete_dirty_clusters0xa
set_new_attribute_size0xb
add_index_entry_root0xc
delete_index_entry_root0xd
add_index_entry_allocation0xe
delete_index_entry_allocation0xf
set_index_entry_ven_allocation0x12
update_file_name_root0x13
update_file_name_allocation0x14
set_bits_in_non_resident_bitmap0x15
clear_bits_in_non_resident_bitmap0x16
prepare_transaction0x19
commit_transaction0x1a
forget_transaction0x1b
open_non_resident_attribute0x1c
open_attribute_table_dump0x1d
dirty_page_table_dump0x1f
transaction_table_dump0x20
update_record_data_root0x21

Usage

  1. Retrieve by providing the file path.

    ntfs-logfile /opt/logpresso/testdata/ntfs/test_LogFile
    
  2. Retrieve when the zippath option is provided.

    ntfs-logfile zippath=/opt/logpresso/testdata/NTFS.zip NTFS/test_LogFile
    
  3. Retrieve logs where the redo_op is related to the initialize_file_record_segment operation or any delete operation.

    ntfs-logfile /opt/logpresso/testdata/ntfs/test_LogFile
    | sort lsn
    | search redo_op == "initialize_file_record_segment"
          or redo_op == "*delete*"