Configure acquisition settings

Prev Next

Acquisition settings control how your agents collect and report triage, data, and file acquisition information from the endpoint host. Triage, data, and file acquisitions request forensic data from the agent about suspicious files and activity on the host endpoint at the time of an alert. Triage acquisition information is collected in a .mans file; file acquisition information is collected in a .zip file.

Triage information is provided on the Endpoint Security (HX) Web UI. If a triage is requested and the Endpoint Security (HX) appliance determines that the data is significant, a high-level summary of the triage data can be viewed on the Triage Summary page. At any time, the full triage .mans file can be downloaded and reviewed using Redline.

For information on Triage Summary, see Acquiring forensic data.

The default acquisition settings provide optimal information for most enterprises. Administrators can change the following settings: