Create a forensic investigation search to investigate captured events for file names, keywords, or end-user names.
Note
* indicates a required field. It is possible to create a forensic investigation search without specifying additional criteria, but it will analyze every item in the dataset.
Category | Option | Definition |
|---|---|---|
Search options | Name * | Enter a unique name for the scan. This field is required. |
Description | Optional field for adding additional information about the search. | |
Dataset * | Click The number of appliances and an approximate number of captured events that might be searched as part of this dataset is shown. The number of captured events is taken from the appliance in the dataset that has the most events to search. Click Refresh to re-evaluate the number of events that might be searched. You can edit the dataset if the number is too large, and re-evaluate it until the number is acceptable. | |
Max Results to Report | Select the maximum number of results to display in the Search Results list for each appliance. Default: 100 | |
stop search when max results reached | Select this box to stop the search when the number set in Max Results to Report is reached for each appliance. When this option is deselected, the search continues and saves all results in the detailed results report. | |
Results: Store original files as evidence | Creates evidence files from any positive results. Deselect this option to avoid storage and performance implications. | |
Condition | End-User | Click |
File Name | Enter the file name in the text box. | |
Search Term | Select a language from the drop-down list, then enter the search term in the text box. Click Select exact match to match the term, or deselect to search for related terms. | |
Save & Run | Select this option to run the search immediately. The search is added to the list of searches. | |
Save | Select this option to save the search definition and run later. The search is added to the list of searches. | |
Cancel | Cancels the search definition without saving. | |
.png)
