Requesting a data acquisition

Prev Next

You can acquire data from a host using the Endpoint Security (HX) Web UI. Multiple data acquisitions can be requested simultaneously from a host. In addition, you can select multiple hosts and request data acquisitions from them.

Prerequisites
  • Analyst, Senior Analyst, Investigator, or Administrator access

  • The data you want to acquire is defined in a data acquisition script. See Managing data acquisition scripts.

  • An active license is installed.

    If your license expires after you have created your own data acquisition scripts or have edited supplied scripts, you will be able to see these scripts on the Data Acquisition Scripts page, but you will not be able to edit them or use them to acquire data. You will be able to export them.

Requesting a data acquisition from the Hosts page

To request a data acquisition from the Hosts page:
  1. Select Hosts in the Endpoint Security (HX) Web UI.

  2. Select one or more hosts.

    Note

    If you select multiple hosts, the following supplied data acquisitions are not available: Driver Memory, Full Disk, Full Memory, and Process Memory. These are available only when a single host is selected.

  1. In the Actions menu, select the data acquisition script to be used.

    Caution

    Full Memory or Full Disk data acquisitions can return more information than expected and cause performance and storage problems. Trellix recommends that you limit the scope of these scripts.

  2. If the data acquisition script you select requires more information, an Acquire dialog box appears. Enter the information and click Acquire. For more information about each dialog box, see Using the supplied scripts.

    If the script requires no more information, the data acquisition request is automatically submitted.

You can also request data acquisitions from the host alert detailshost alert details and host detailshost details sections of the Hosts pageHosts page.

Requesting a data acquisition from a Host Details page

To request a data acquisition from a host endpoint using the host alert details or host details sections:
  1. Select Hosts in the Endpoint Security (HX) Web UI.

  2. Request host details by clicking on the Expand icon (ExpandIcon.png) associated with a host.

  3. In the Acquire menu, select the data acquisition script to be used.

    Caution

    Full Memory or Full Disk data acquisitions can return more information than expected and cause performance and storage problems. Trellix recommends that you limit the scope of these scripts.

  4. If the data acquisition script you select requires more information, an Acquire dialog box appears. Enter the information and click Acquire. For more information about each dialog box, see Using the supplied scripts.

    If the script requires no more information, the data acquisition request is automatically submitted.

You can monitor the status of an acquisition request in the Status column of the Acquisitions page. The status changes from Requested, to Acquiring, and then to Acquired when the acquisition is ready.

For more information about acquired forensic data, read Downloading forensic data and Reviewing forensic data in Redline.