Acquisitions page

Prev Next

To rapidly review and respond to potential compromises, you can directly acquire files and triage collections from hosts. The Acquisition page allows you to view the details of each acquisition. To access the Acquisitions page, select Acquisitions from the main menu.

For information on using this page, see Analyzing forensic data.

HX_Acquisitions.png

The Acquisitions page is divided into an Acquisitions grid and an Acquisition Detail pane. At the top of the page, you can search for a specific acquisition by hostname or IP address.

Prerequisites
  • Administrator, Analyst, Senior Analyst, or Investigator privileges (full access)

Filter drop-down boxes

You can filter the data in the grid using the filter drop-down boxes.

AcqFilters.png

Using these boxes, you can filter the data in the grid by acquisition type, status, who requested the acquisition, and the operating system on which the acquisition was requested.

Acquisition space area

The Acquisitions page shows how much disk space is remaining for acquisitions.

AcqSpace.png

See Setting disk utilization limits for acquisitions to specify the total disk space that can be used for acquisitions.

Paging area

The paging area indicates the range of acquisitions shown on this page of the grid and the total number of acquisitions stored.

Paging.png

The buttons in the paging area allow you to scroll through the list of acquisitions in the grid.

Button

Description

PagingFirst.png

Show the first page of acquisitions in the grid.

PagingPrev.png

Scroll to the previous page of acquisitions in the grid.

PagingNext.png

Scroll to the next page of acquisitions in the grid.

PagingLast.png

Show the last page of acquisitions in the grid.

Actions area

The Actions area allows you to take action on any acquisition in the list.

AcqActions.png

The selection box (SelectionBox.png) to the left of the Actions drop-down box allows you to select every acquisition in the grid. The number of acquisitions selected for an action is listed to the right of the Go button in the Actions area.

The Actions drop-down menu lists actions you can take on acquisitions you have selected in the grid. If no acquisitions are selected, no actions can be selected in the Actions drop-down menu.

After selecting an action in the Actions drop-down, click Go to start the selected action.

Acquisitions grid

The Acquisitions grid lists the acquired files and triage collections.

Click on a column name in the Acquisitions grid once to sort the grid data in ascending alphanumeric sequence based on the column data. Click on the column name again to sort the grid data in descending alphanumeric sequence based on the column data. An arrow to the right of the column name indicates how the grid data is sorted.

Field

Description

SelectionBox.png

Select an acquisition for which you want to take action.

(Containment Status)

Icons identify the containment status of the host endpoint associated with the acquisition: requested (containment-requested.png), approved (containment-approved.png), contained (Contained.png), cancellation in progress (containment-uncontain.png), failed (containment-failed.png), and ineligible for containment (containment-ineligible.png). See Containment overview.

(Host Type)

The type of host machine associated with the acquisition: Windows (IconWinHost.png), Mac OS X (IconOSXHost.png), Linux (linux.png), or server (IconSrvHost.png).

Hostname

The hostname of the host from which the file was acquired.

IP Address

The IP address of the host from which the file was acquired.

Requested

The amount of time since the acquisition request was made.

Acquisition

The type of acquisition: File or Triage.

Download Size

The size of the acquisition.

Status

The acquisition status:

Acquired—The acquisition was successful.

Acquiring—The acquisition is in progress.

Failed—The acquisition was not successful.

Processing—An acquisition action is in progress.

Requested—An acquisition was requested.

Update Required— The acquisition requires updating.

Waiting for processing—The acquisition action is waiting to be processed.

Acquisition Details pane

The Acquisition Details pane shows detailed information for the selected acquisition request.

Select Download Full Triage to download a .mans file containing the acquisition data. You can review this data in Redline.

Select PROCESS DATA ACQUISITION to process the data acquisition and display the data in the Audit Viewer.

Note

Timestamps in the Web UI are presented in UTC time.