Windows XP Event Logs
Is it possible to analyse windows xp event logs using linux based / FOSS tools?
Yes. I have written Perl code for analyzing .evt files, that are based on parsing the files on a binary level without using the MS API at all.
Also, check out PyFlag.
Absolutely. Both Delve and grokevt may be used to read EVT files.