Triage data acquisitions may fail if they take longer than the amount of time you have configured. To solve this problem, increase the timeout, delete the cached files for the acquisitions that failed due to timeout, and process the acquisitions again. Data acquisitions can also pose a challenge because of the amount of disk space needed for storage or back up.
Deleting your cached files frees up space on your local drive. The Delete cache action removes any triage viewer artifacts and clears the uncompressed .sqlite triage files for the selected acquisitions from the triage .zip directory, including the following file types:
Triages (manual only)
Quick File Listing
Full disk
Full memory
Driver memory
Process memory
Comprehensive Investigative details
Standard Investigative details
Power shell
Command shell history
The following procedures explain how to reprocess acquisitions that have failed due to timeout, how to reduce the data footprint of successfully processed acquisitions by deleting the cache and reprocessing the acquisitions, and how to reprocess acquisitions as required after an Endpoint Security (HX) upgrade.
Managing acquisitions that fail due to timeout
If your acquisitions fail because they time out, then a message stating "Acquisition not viewable. Server timeout while processing data. Delete cache and re-process after increasing server timeout" is displayed in the details pane of the Acquisitions page. You can perform the following steps to make sure your triage acquisitions successfully process:
Increase the time limit for acquisition extractions.
hostname (config) #
hx server acquisition extraction timeout <seconds>Delete the triage data for the failed acquisition from your cache.
On the Acquisitions page, select the acquisitions that failed due to timeout. You can select more than one acquisition.
In the Actions menu, select Delete cache.
Click Go.
In the confirmation dialog box, click Delete.
A banner is displayed at the top of the page stating that the cache for the selected number of acquisitions was marked for deletion and a Deleting cache processing icon that includes a View Data Acquisition button is displayed in the Acquisition details pane.
Reprocess your acquisitions. Select the acquisitions and click Process Data Acquisitions in the details pane of the Acquisitions page.
The acquisition's status changes from Waiting to Process to Acquired when reprocessing is finished.
Managing acquisitions that process successfully
After your triage data acquisitions successful process (Acquired status), you can delete the uncompressed files from your cache to minimize the amount of disk space needed to store or back up the acquisitions.
Use the following steps to delete the cached triage data:
On the Acquisitions page, select the acquisitions. You can select more than one acquisition.
In the Actions menu, select Delete cache.
Click Go.
In the confirmation dialog box, click Delete.
A banner is displayed at the top of the page stating that the cache for the selected number of acquisitions was marked for deletion and you see a Deleting cache processing icon that includes a View Data Acquisition button in the Acquisition details pane.
The Process Data Acquisitions button is displayed in the details pane of the Acquisitions page after the delete process is finished.
Reprocess your acquisitions. Select the acquisitions you want to reprocess and click Process Data Acquisitions.
Reprocessing automatic triages after an upgrade
When a new release of Endpoint Security (HX) contains changes or enhancements to the Audit Viewer or to the automatic triage process, you may be required to reprocess your existing automatic triages after you upgrade your Endpoint Security (HX) instance.
Use the following steps to reprocesses automatic triages:
On the Acquisitions page, select the acquisitions you want to reprocess. You can select more than one acquisition.
In the Actions menu, select Reprocess acquisition.
Click Go.
When reprocessing is complete, the status for the selected acquisitions changes to Acquired and View Data Acquisition button is displayed in the Acquisition details pane.