* Observe typed native WEC subscription runtime status * Link typed WEC runtime changelog to PR 424 * Pass a native null source for subscription runtime queries * Ignore unused count storage for native null WEC variants * Keep unavailable WEC source inventories unknown and diagnose native XML reads * Read native WEC subscription XML with bounded explicit Unicode pipes * Use bounded Unicode subscription reads in runtime observations and cleanup * Decode native WEC XML BOMs without unsupported Unicode switch * Describe strict native WEC XML byte decoding * Reference System.Xml explicitly when compiling under Windows PowerShell * Regenerate website changelog snapshots with their proper headers
WELA (Windows Event Log Analyzer) ゑ羅
A tool for auditing Windows event log settings.
Created by Yamato Security — make sure you are
actually recording the events that matter for DFIR.
📖 Read the Documentation →
Available in 15 languages — English · 日本語 · 繁體中文 · 한국어 · Deutsch · Türkçe · Français · Español · Português (Brasil) · Українська · हिन्दी · Bahasa Indonesia · မြန်မာဘာသာ · ไทย · العربية🦅 About
WELA (Windows Event Log Analyzer, ゑ羅) is a tool for auditing Windows event log settings. Windows event logs are a vital source of information for Digital Forensics and Incident Response (DFIR) — WELA checks your audit policy and log file sizes against best-practice guidelines and real-world Sigma-rule detectability, and can apply the recommended settings for you.
Advanced audit policy can also use versioned WELA, Microsoft, CIS and ASD profiles for shared audit, plan and configure behavior. Profiles cover advanced audit policy only.
📖 Documentation
All documentation now lives on a dedicated, searchable, multi-language site:
👉 yamato-security.github.io/WELA
| Section | |
|---|---|
| 🚀 Getting Started | Prerequisites, downloads and running WELA |
| ⌨️ Command Reference | audit-settings, audit-filesize, configure, configure-sacl, update-rules |
| ✨ Features | What WELA can do |
| 📦 Resources | Companion projects, changelog, contributing |
⬇️ Download
Grab the latest release from the Releases page.
🗂️ Looking for the old README?
The previous single-page README is preserved unchanged:
- 📄 OLD-README.md — English
- 📄 OLD-README-Japanese.md — 日本語
🤝 Contributing & License
Contributions and bug reports are welcome — see Contributing & Support. WELA is released under the MIT license.
