Forensic investigation

Prev Next

Create a forensic investigation search to investigate captured events for file names, keywords, or end-user names.

Note

* indicates a required field. It is possible to create a forensic investigation search without specifying additional criteria, but it will analyze every item in the dataset.

Option definitions

Category

Option

Definition

Search options

Name *

Enter a unique name for the scan. This field is required.

Description

Optional field for adding additional information about the search.

Dataset *

Click GUID-6F526415-DCB6-4F53-8296-245AECEC7DE5-low.png to select a dataset from an existing list or create a new one.

The number of appliances and an approximate number of captured events that might be searched as part of this dataset is shown.

The number of captured events is taken from the appliance in the dataset that has the most events to search.

Click Refresh to re-evaluate the number of events that might be searched.

You can edit the dataset if the number is too large, and re-evaluate it until the number is acceptable.

Max Results to Report

Select the maximum number of results to display in the Search Results list for each appliance. Default: 100

stop search when max results reached

Select this box to stop the search when the number set in Max Results to Report is reached for each appliance.

When this option is deselected, the search continues and saves all results in the detailed results report.

Results: Store original files as evidence

Creates evidence files from any positive results.

Deselect this option to avoid storage and performance implications.

Condition

End-User

Click GUID-6F526415-DCB6-4F53-8296-245AECEC7DE5-low.png to select users from an LDAP server.

File Name

Enter the file name in the text box.

Search Term

Select a language from the drop-down list, then enter the search term in the text box. Click GUID-551C7C8D-638A-4BDE-B7ED-092A760A3336-low.png to add more search terms.

Select exact match to match the term, or deselect to search for related terms.

Save & Run

Select this option to run the search immediately. The search is added to the list of searches.

Save

Select this option to save the search definition and run later. The search is added to the list of searches.

Cancel

Cancels the search definition without saving.