You can use the Timestamp Settings tab on the Automatic Triage Settings page to specify the length of time before and after the timestamp during which information is collected. The timestamp is the time when the event that triggered the alert occurred.
Log in to the Endpoint Security (HX) Web UI.
From the Configure section of the main menu, select Triage Settings.
On the Automatic Triage Settings page, click the Timestamp Settings tab.
On the Timestamp Settings page, specify the length of time before and after the timestamp during which information is collected.
In the upper box of the Timestamp Settings page, enter the number of seconds before the specified timestamp during which information should be collected.
In the lower box of the Timestamp Settings page, enter the number of seconds after the timestamp during which information should be collected.
Click Save to save your settings.
Note
You can change all values on the page back to the default settings by clicking Reset to Defaults, and clicking Save.