What is Timesketch?
Timesketch is an open source tool for collaborative forensic timeline analysis. Using sketches you and your collaborators can easily organize your timelines and analyze them all at the same time. Add meaning to your raw data with rich annotations, comments, tags and stars.
How to Use
Run the Timesketch container and link it to databases using the following command (replace password and address properties with values relevant to our setup):
docker run -d -e POSTGRES_USER=timesketch -e POSTGRES_PASSWORD=password -e TIMESKETCH_USER=admin -e TIMESKETCH_PASSWORD=password -e POSTGRES_ADDRESS=postgres -e POSTGRES_PORT=5432 -e ELASTIC_ADDRESS=elastic -e ELASTIC_PORT=9200 jessemillar/timesketch
For a more production-quality setup, utilize the optional
--restart=always flag. This will automatically restart the container in the event of a crash.
View license information for the software contained in this image.
Supported Docker Versions
This image is officially supported on Docker version 1.12.3.
Please see the Docker installation documentation for details on how to upgrade your Docker daemon.
If you have any problems with or questions about this image, please contact us through a GitHub issue.
Documentation for the software contained in this image can be found in the GitHub wiki.