Configure automatic triage settings

Prev Next

The automatic triage acquisition feature allows the EDRF Client to automatically collect information surrounding the time of an alert using parameters that optimize performance and analysis value. See Triage collections. In Endpoint Security (HX) version 4.9 and later, you can specify automatic triage by alert type.

Note

The request type for automatic triage is "Around timestamp". The timestamp is the time the event that generated the alert occurred. Around timestamp requests information collected during a specified amount of time before the timestamp until a specified amount of time after the timestamp.

Administrators can disable this feature using the Endpoint Security (HX) Web UI. The default for this setting is On.

When automatic triage is turned off, you can still manually request triage collections.

Note

Malware alerts do not trigger an automatic triage, as other alerts do. Triage data cannot be collected for Linux endpoints.

Prerequisites
  • Admin access

  • The Process Tracker module must be installed and enabled before you can configure automatic triage for Process Tracker (PRO) alerts