Adjusting script acquisition data types

Prev Next

You can edit the acquisition data types selected for the script.

To change the acquisition types selected for a data acquisition script:
  1. Select Data Acquisition Scripts from the Configure section of the main menu of the Endpoint Security (HX) Web UI.

  2. Select the script you want to modify in the list of scripts on the left side of the Data Acquisition Scripts page.

    Details about the script appear on the right side of the page, including separate sections for each operating system supported by the script. Be sure to edit the correct operating system section.

  3. At least two Actions menus appear for user-defined scripts. One menu appears in the heading area and one appears for each operating system that the script supports. (The supplied Standard Investigative Details, Comprehensive Investigative Details, and Process Details scripts do not have an Actions menu in the heading area.)

    Select Edit in the Actions menu that appears in the operating system section of the script that you want to change.

    The Data Acquisition page adjusts so only the script section associated with the selected operating system appears. You can identify the operating system by the icon displayed to the left of the script name: Windows (IconWinHost.png), macOS (IconOSXHost.png), or Linux (linux.png).

  4. Select an acquisition data type in the script or add a new one by selecting one in the Add an acquisition type drop-down box and clicking Add. See Acquisition data type reference .

    Options for the acquisition data type you requested appear to the right of the script list.

  5. Supply values for the acquisition data type options or use the default values that are already selected.

    Note

    The Web UI does not warn you or remove tabs, spaces, or unwanted characters (such as \n) in your specifications. (HXEP-10562)

  6. Repeat the previous 2 steps to request additional data for the data acquisition script.

    Some acquisition data types are available only once for a script, while others can be specified more than once. After adding an acquisition type to a script, the list of acquisition types available in the Add an acquisition type drop-down box adjusts appropriately.

  7. To remove an acquisition data type from the script, click the x icon (HX_Remove_icon.png) on the acquisition tab on the left side of the page.

  8. When all acquisition data types and options are specified, click Save.

    The script is updated.