Configure acquisition settings

Prev Next

Acquisition settings manage how the EDRF Client collects and reports forensic data from the endpoint. These settings request triage, data, and file information regarding suspicious files or activity during an alert. The EDRF Client collects triage acquisition data in a .mans file. It collects file acquisition information in a .zip file.

Triage information is provided on the Endpoint Security (HX) Web UI. If a triage is requested and the Endpoint Security (HX) appliance determines that the data is significant, a high-level summary of the triage data can be viewed on the Triage Summary page. At any time, the full triage .mans file can be downloaded and reviewed using Redline.

The default acquisition settings provide optimal information for most enterprises. Administrators can change the following settings: