The Audit Viewer detail pane provides details about a line of audit data you have selected. The information displayed on the detail pane depends on the acquisition data you have selected and upon the operating system of the host endpoint from which the data was acquired. You can also add tags and comments to the selected audit data using the detail pane. See Tagging Rows of Data and Adding Comments to Rows of Data .
Review an acquisition in the Audit Viewer. See Viewing the Acquisition Data .
Make sure the data for which you want detail information is displayed in the grid. See Selecting Data to Review .
Select a row for which you want to view detailed information in the Audit Viewer grid.
Click the open detail pane button in the upper right corner of the Audit Viewer page. The detail information for the select grid line appears on the Details tab.
.png)
The Additional Data tab only appears if data in the selected row correlates to other data acquisition types in the acquisition data or in nested data from the same acquisition time that might not appear in the grid. The correlation is based on a common field, such as a process ID.
The timestamps on the detail pane are taken from the master file table entry for a file and include: the date the file was created, the date the file was modified, the date the file was accessed, and the date the file was changed. The date the file name was created, the date the file name was modified, the date the file name was accessed, and the date the file name was changed are also included.
If an audit produces items with multiple timestamps, multiple lines appear in Timeline view (once for each timestamp). This allows you to trace the full timeline of events that happened on the endpoint. You can determine which timestamp is represented by a selected row in the timeline by looking at the corresponding Field column. For example, in a file audit, the same file appears multiple times in Timeline view, once for each timestamp associated with the file.
Click the close detail pane button in the upper right corner of the Audit Viewer page.