Adding and editing data acquisition comments

Prev Next

All acquisition requests now provide a Comment field. Use this field to add comments to the selected data acquisition, including the reason for the acquisition request and any specific details about the acquisition request that you want to record for incident tracking. You can review and edit saved comments in the Acquisition Details panel on the Acquisitions page.

HX_Acquisition_Comment_scap.png
To add a comment to a data acquisition request:
  1. Select Hosts in the Endpoint Security (HX) Web UI.

  2. Select one or more hosts.

    Note

    The following supplied data acquisitions are not available for multiple hosts: Driver Memory, Raw Disk, Full Memory, and Process Memory. These acquisition requests are available for a single host only.

  3. In the Actions menu, select the data acquisition script you want to process.

    Caution

    Full Memory or Raw Disk data acquisitions can return more information than expected and cause performance and storage problems. Trellix recommends that you limit the scope of these scripts.

  4. Click Go to access the Acquire dialog box.

  5. If the data acquisition dialog box has multiple fields, enter the required information in each field.

  6. In the Comment field, enter the reason for the acquisition request and any specific details about the request that you want to record.

    HX_SSType_SIDComment_scap.png
  7. Click Acquire to start the file acquisition process.

To edit a data acquisition comment.

  1. Select Acquisitions in the Endpoint Security (HX) Web UI.

  2. Select a host.

  3. In the Acquisition Details panel, click the Comment drop-down to access any saved comments for the selected acquisition.

  4. Click the Edit icon to modify or update the comment.

    HX_Acquisition_CommentEdit_scap.png
  5. Click Save.