Sometimes, the results zip downloaded from the Extended Forensics module will be empty without a manifest or supporting files. This occurs for few reasons:
The Extended Forensics module installation was not successful or failed to install
Even though Extended Forensics was enabled for the host set, the endpoint module was not installed by the HX policy manager prior to the command attempting to execute on the endpoint. Typically waiting and then starting a new job for the host set shall result in a successful job.
There must have been a failure to install the endpoint module on the endpoint.
In both cases see Verifying the installation
The results are not ready in the server
The endpoint agents may have successfully completed the commands within the job however, the Extended Forensics server module has not yet collected the results for the hosts to make them available for download using the UI.
To ensure the results are available for the job, the Downloaded column available in the grid view needs to be checked.
Typically waiting for few minutes after the job indicates complete shall solve the issue and the results zip file can be downloaded.
This is known issue and can be mitigated in future release of the module.