How To Install python-evtx on Ubuntu 18.04

In this tutorial we learn how to install python-evtx on Ubuntu 18.04. python-evtx is parser for recent Windows Event Log files – Python 2 version

Introduction

In this tutorial we learn how to install python-evtx on Ubuntu 18.04.

What is python-evtx

python-evtx is:

This module provides programmatic access to the File and Chunk headers, record templates, and event entries from Microsoft Windows Vista and later.

This package contains modules for Python 2.

There are three methods to install python-evtx on Ubuntu 18.04. We can use apt-get, apt and aptitude. In the following sections we will describe each method. You can choose one of them.

Install python-evtx Using apt-get

Update apt database with apt-get using the following command.

sudo apt-get update

After updating apt database, We can install python-evtx using apt-get by running the following command:

sudo apt-get -y install python-evtx

Install python-evtx Using apt

Update apt database with apt using the following command.

sudo apt update

After updating apt database, We can install python-evtx using apt by running the following command:

sudo apt -y install python-evtx

Install python-evtx Using aptitude

If you want to follow this method, you might need to install aptitude first since aptitude is usually not installed by default on Ubuntu. Update apt database with aptitude using the following command.

sudo aptitude update

After updating apt database, We can install python-evtx using aptitude by running the following command:

sudo aptitude -y install python-evtx

How To Uninstall python-evtx on Ubuntu 18.04

To uninstall only the python-evtx package we can use the following command:

sudo apt-get remove python-evtx

Uninstall python-evtx And Its Dependencies

To uninstall python-evtx and its dependencies that are no longer needed by Ubuntu 18.04, we can use the command below:

sudo apt-get -y autoremove python-evtx

Remove python-evtx Configurations and Data

To remove python-evtx configuration and data from Ubuntu 18.04 we can use the following command:

sudo apt-get -y purge python-evtx

Remove python-evtx configuration, data, and all of its dependencies

We can use the following command to remove python-evtx configurations, data and all of its dependencies, we can use the following command:

sudo apt-get -y autoremove --purge python-evtx

References

Summary

In this tutorial we learn how to install python-evtx package on Ubuntu 18.04 using different package management tools: apt, apt-get and aptitude.