EVTX Flat Storage Optimization
When we try to play with several machines, Sysmon and WECs (Windows Event Collectors)
we quickly see the amount of logs growing. Knowing quite good the EVTX file format
we realized that no compression is builtin. In order to optimize the storage of
the events collected, we decided to run basic compression tests that we are
going to describe here.
more ...