Data acquisitions (sometimes referred to as Live Response requests) allow you to acquire data you need from a single running endpoint. Using the Data Acquisition Scripts page, you can create, edit, copy, and delete the data acquisition scripts used for data acquisition requests. Trellix supplies several data acquisition scripts (sometimes referred to as audits). You cannot delete these scripts, although you can copy and edit some of them to use as a basis for your own scripts. See Using the supplied scripts .
When a data acquisition request is made, the Endpoint Security (HX) xAgent on the selected host endpoint collects the forensic data requested by the associated data acquisition script.
Data returned from a data acquisition can be reviewed using the following methods.
You can process and view the data in the Audit Viewer. See Reviewing forensic data in Audit Viewer .
You can download the returned data in a
.mansfile to review all the data in Redline. See Reviewing forensic data in Redline .
For the Full Memory and Full Disk acquisitions, you can download the returned data in a .zip file.
Caution
Full Memory or Full Disk data acquisitions can return more information than expected and cause performance and storage problems. Trellix recommends that you limit the scope of these scripts.