Eve_archived.json file

I cannot interact with the eve_archived.json file. It is in the directory:

But when I run the command ‘less eve_archived.json’ I get nothing but a blank screen:

image.png.4e373c01c4b69dcb021c7687e9bf8615

I can access the eve.json file:

image.png.3edb19b083b9d466859174312ec0dbb8

Any ideas?

Edit:

I’m unable to run the subsequent commands as well:

cat eve_archived.json | jq -c 'select(.event_type == "alert")'

cat eve_archived.json | jq -c 'select(.event_type == "tls")'

I am using a Windows 10 machine and Putty. Do I need to install EveBox and jq for this to work?

Original post by bjadamsjr


Please always mention the exact lab when posting.

You need to install nothing.

A new file with a similar name has been created by the system.

The filename is now eve_archived.json.1

Original reply by Dimitrios