Use the Data Acquisition Scripts page to create and manage data acquisition scripts used in data acquisition requests from your host endpoints. Data acquisition requests allow you to acquire any data you need from a single running endpoint.
Several scripts are provided by Trellix. You cannot delete these scripts, although you can edit them or copy them and use them as a basis for your own script. If you have edited them, you can also reset them to their factory-distributed form.
For complete information, see Maintaining data acquisition scripts and Requesting a data acquisition.
.png)
To access the Data Acquisition Scripts page, select Data Acquisition Scripts from the Configure section in the main menu.
Admin, Analyst, Senior Analyst, or Investigator access
Some features, such as Comprehensive Investigative Details require the Endpoint Security (HX) Power license.
Create Script button
Click the Create Script button to start the process of creating a new script.
Import Script button
Click the Import Script button to start the process of importing a new script.
Script list
The script list on the left side of the page lists known scripts. When you select a script, its definition appears in the script detail area and an Actions drop-down menu appears above the script details. You can:
Delete the script
Changing the script's title and description
Adding data acquisition requests for a different operating system
Import a data acquisition script for a different operating system.
Be sure to click Save to save your settings if you make any to the script.
Script Detail area
The script detail area shows the definition of a selected script. The script for each platform includes an Actions drop-down menu. The actions you can select for the script for an individual operating system include:
Deleting the script for that operating system
Editing the script for that operating system
Exporting the script for that operating system.