Configure file acquisition settings

Prev Next

When an Endpoint Security (HX) user makes a file acquisition request, the Endpoint Security (HX) appliance instructs an agent to obtain a file from its host endpoint. File acquisitions are used for static or dynamic analysis, as well as for evidence retention during insider threat investigations. File acquisition information is collected in a .zip file.

Each acquisition request can only obtain one file at a time from an individual host endpoint. You can request the same file from multiple host endpoints using host sets. You can request other files from the same host endpoint by making additional requests. The only limits on the total number of acquisition requests you can make for any host endpoint are related to acquisition aging settings.

You can control the following file acquisition functions using file acquisition settings:

Function

Description

Enable or disable file acquisitions

Enables file acquisitions. File acquisitions are enabled by default.

See Enable or disable file acquisitions using the Web UI and Enabling File Acquisitions Using the CLI .

Disable file acquisitions

Disables file acquisitions.

See Disabling file acquisitions using the Web UI and Disabling file acquisitions using the CLI .Disable file acquisitions using the Web UI

Specify the file acquisition passphrase

Identifies the passphrase used to encrypt file acquisition.

See Changing the file acquisition passphrase using the CLI .

Prerequisites
  • Admin access