.png)
The Storytime Viewer is an interactive grid containing details about all the chapters. Specific columns such as Alert ID, Triage ID, and Hostname are links to more information related to the chapter. When you click the Chapter View link, the Storytime Visualization opens in a separate tab.
The Storytime Visualization is a graphical representation of the triage data on an alert. The visualization focuses on the most relevant data from the auto-triage on the alert and shows the critical path to the event node that triggered the detection. To quickly identify the compromised node, the visualization uses a red line for the critical path. The default view shows only the hit node, its sibling, and minimal information around it. Use the expand icon on a node or the Expand All button to view parallel events.
.png)
For a detailed explanation about the nodes and icons used in the visualization, use the Show Legend button. If you click a node, additional information is available in either a side panel or a table view. From the table view you can download a CSV file. Use the export icon if you want to view the JSON chapter file.
To access the Storytime System Module:
Log in to the Endpoint Security (HX) Web UI with your admin credentials.
From the Modules menu, select Endpoint Module Administration.
On the Modules page, click the System Modules tab.
In the Name column, click the Storytime link to open Storytime Viewer.