When an Endpoint Security (HX) user requests a triage collection based on a specific date and time, or when an automatic triage acquisition collects host endpoint information related to the time of an alert, the agent returns information for a specified window of time before and after the alert. The timestamp settings control the length of the window for the triage collection.
Timestamp settings apply only to agent URL events (URL Monitor Events) and registry key events (Reg Key Events).
You can use the Timestamp Settings tab to specify the length of time before and after the timestamp during which information is collected. Timestamp Settings can range from 0-86400 seconds. The default for both settings is 600 seconds.
Admin access