Changing script operating systems

Prev Next

You can add or remove operating systems in a data acquisition script using the Endpoint Security (HX) Web UI.

Adding an operating system

To add an operating system to a data acquisition script:
  1. Select Data Acquisition Scripts from the Configure section of the main menu in the Endpoint Security (HX) Web UI.

  2. Select the script you want to modify in the list of scripts on the left side of the Data Acquisition Scripts page.

    Details about the script appear on the right side of the page, including separate sections for each operating system supported by the script.

  3. At least two Actions menus appear for user-defined scripts. One menu appears in the heading area and one appears for each operating system that the script supports. (The supplied Standard Investigative Details, Comprehensive Investigative Details, and Process Details scripts do not have an Actions menu in the heading area.)

    As appropriate, select Add Windows version, Add OS X version, or Add Linux version, in the Actions menu in the heading area.

    The Data Acquisition page adjusts so only the script section associated with the selected operating system appears. You can identify the operating system by the icon displayed to the left of the script name: Windows (IconWinHost.png), Mac OS X (IconOSXHost.png), or Linux (linux.png).

  4. Select an acquisition type in the Add an acquisition type drop-down box and click Add. See Acquisition type reference .

    Options for the acquisition type you requested appear to the right of the script list.

  5. Supply values for the acquisition type options or use the default values that are already selected.

    Note

    The Web UI does not warn you or remove tabs, spaces, or unwanted characters (such as \n) in your specifications. (HXEP-10562)

  6. Repeat the previous 2 steps to request additional data for the data acquisition script.

    Some acquisition types are available only once for a script, while others can be specified more than once. After adding an acquisition type to a script, the list of acquisition types available in the Add an acquisition type drop-down box adjusts appropriately.

  7. To remove an acquisition type from the script, click the x icon (HX_Remove_icon.png) on the acquisition tab on the left side of the page.

  8. When all acquisition types and options are specified, click Save.

    The script is updated for the new operating system.

Removing an operating system version

To remove an operating system version from a data acquisition script:
  1. Select Data Acquisition Scripts from the Configure section of the main menu in the Endpoint Security (HX) Web UI.

  2. Select the script you want to modify in the list of scripts on the left side of the Data Acquisition Scripts page.

    Details about the script appear on the right side of the page, including separate sections for each operating system supported by the script.

  3. At least two Actions menus appear for a script. One menu appears in the heading area and one appears for each operating system that the script supports.

    Select Delete in the Actions menu that appears in the operating system section you want to remove.

    A dialog appears prompting you to confirm the deletion.

  4. Click Delete on the dialog.

    The data acquisition script is adjusted and saved on the Data Acquisition Scripts page.