diff --git a/docs/doxygen-user/auto_ingest.dox b/docs/doxygen-user/auto_ingest.dox
new file mode 100644
index 0000000000..246d1efe22
--- /dev/null
+++ b/docs/doxygen-user/auto_ingest.dox
@@ -0,0 +1,92 @@
+/*! \page auto_ingest_page Automated Ingest
+
+\section auto_ingest_overview Overview
+
+Auto ingest allows one or many computers to process \ref ds_page "data sources" automatically with minimal support from a user. The resulting \ref multiuser_page "multi-user cases" can be opened and reviewed by analysts, using any of the normal functions in Autopsy.
+
+There are three types of computers in an Automated Processing Deployment:
+
+- Automated Ingest Node:
+These computers are responsible for monitoring the Shared Images Folder and detecting when new images have been copied in. Each writes its results to the Shared Cases Folder.
+
- Examiner Node: These computers can open a case during processing or after it has been analyzed by the Automated Ingest Node. They allow the examiner to review the results, tag files, and perform additional analysis as needed.
+
- Services/Storage Node: These computers run the services needed for \ref multiuser_page "multi-user cases", hold the images to be processed and store the analyzed Autopsy cases.
+
+
+The general workflow is as follows:
+
+- Disk images or other types of data sources are added to the shared images folder. This folder will contain all the disk and phone images that are copied into the system. They must be copied into here before they can be analyzed. As more than one machine may need to access this folder across the network, use UNC paths (if possible) to refer to this folder.
+
- A \ref auto_ingest_manifest_creation "manifest file" is added for each data source that is to be processed.
+
- An auto ingest node finds that manifest file and begins processing the data source. It will make a case in the shared cases folder if there is not one there already. This folder will contain all of the analysis results after automated analysis has been performed on the images. This folder will not contain the images, those will stay in the Shared Images Folder. As more than one machine may need to access this folder across the network, use UNC paths (if possible) to refer to this folder.
+
- An analyst on an examiner node opens the case and starts their analysis. This can happen while an auto ingest node is processing data or afterwards.
+
+
+An Automated Processing Deployment could have an architecture, such as this:
+
+\image html AutoIngest\overview_pic1.png
+
+Another illustration, including the network infrastructure, is shown below:
+
+\image html AutoIngest\overview_pic2.png
+
+\section auto_ingest_setup_section Configuration
+
+Configuring a group of computers for auto ingest is described on the \ref auto_ingest_setup_page page.
+
+\section auto_ingest_ex_usage Examiner Node Usage
+
+An examiner node in an auto ingest environment is generally the same as any normal Autopsy client set up for \ref multiuser_page "multi-user cases." Any number of examiner nodes can open cases that have been created by the auto ingest nodes. The cases do not need to be complete.
+
+The examiner can open the auto ingest dashboard through the Tools menu. This allows the user to see what cases and data sources are scheduled, in progress, or done.
+
+\image html AutoIngest\examiner_dashboard.png
+
+\section auto_ingest_ain_usage Auto Ingest Node Usage
+
+\subsection auto_ingest_manifest_creation Preparing Data for Auto Ingest
+
+Users will manually copy images to the source images folder (using subfolders if desired) and schedule them to be ingested by creating one file in the folder alongside the image to be ingested. This file is a manifest file describing the image. This file's name must end in "_Manifest.xml."
+
+\image html AutoIngest\manifest_file_in_file_explorer.png
+
+The following is an example of an Autopsy manifest file. Line breaks/spaces are not required, but are shown here for better human readability.
+\verbatim
+
+ XperiaCase
+ 50549
+ mtd3_userdata.bin
+\endverbatim
+
+The following is a description of each required field:
+- CaseName: Case name. Multiple data sources can belong to the same case.
+
- DeviceId: (Optional) A globally unique ID representing device this data source came from. This can be an integer or a UUID.
+
- DataSource: File name of the data source. Does not include the path.
+
+Any amount of additional data may be included in the XML file as long as the fields above are present.
+
+Manifest files can be automatically generated by using the \ref manifest_tool_page.
+
+\subsection auto_ingest_running Running an Auto Ingest Node
+
+When auto ingest mode is enabled, Autopsy will open with a different UI than normal, allowing the user to see what cases are being processed, which are done, and which are next in the queue. You can also change the priority of cases and reprocess cases that may have had an error.
+
+\image html AutoIngest\auto_ingest_in_progress.png
+
+The user must press the "Start" button to being the auto ingest process. Note that if the computer running Autopsy in auto ingest mode is restarted, someone must log into it to restart Autopsy. It does not start by itself. When "Start" is pressed, the node will scan through the Shared Images folder looking for manifest files. This scan happens periodically when ingest is running. It can also be started manually using the "Refresh" button.
+
+The UI for the auto ingest node will display what images are scheduled for analysis, what is currently running, and what has been completed. If a newly added image should be the highest priority, then you can select it and choose "Prioritize Case". This will prioritize all images within the same case to be top priority. You may also prioritize only a single data source (job) using the "Prioritize Job" button in the same manner. If you have prioritized something by mistake, the "Deprioritize" buttons will undo it.
+
+In the middle area, you can see the currently running jobs. You have the option of cancelling an entire image that is being analyzed or to cancel only the current module that is running. The latter is used when one of the modules has been running for too long and you think that the module is having trouble with the image and will never complete. If the auto ingest node loses connection to either the database or Solr services it will automatically cancel the currently running job and will pause processing. Once the connectivity issue has been resolved you must manually resume processing.
+
+If an error occurs while processing a job, or if a job was set up incorrectly, the "Reprocess Job" button can be used to move a completed job back into the Pending Jobs table, where it can be prioritized if desired. No case data is deleted which may result in some duplication in the results.
+
+"Delete Case" will remove a case from the list and remove all of its data. This will not remove the original image, manifest file, or anything else from the input directory. A case can not be deleted if it is currently open in any Examiner Node or if an auto ingest node is currently working on a job related to the case. Care should be used with the delete case button. Note that once a case is deleted the path to its data sources must be changed before they can be reprocessed (i.e., rename the base folder).
+
+The "Auto Ingest Metrics" button displays processing data for all of the auto ingest nodes in the system from a user-entered starting date.
+
+\image html AutoIngest\metrics.png
+
+\section auto_ingest_administration_section Auto Ingest Node Administration
+
+See the \ref auto_ingest_admin_page for information on how to enable administrator features.
+
+*/
\ No newline at end of file
diff --git a/docs/doxygen-user/auto_ingest_administration.dox b/docs/doxygen-user/auto_ingest_administration.dox
new file mode 100644
index 0000000000..972ef510bd
--- /dev/null
+++ b/docs/doxygen-user/auto_ingest_administration.dox
@@ -0,0 +1,91 @@
+/*! \page auto_ingest_admin_page Auto Ingest Administration
+
+\section auto_ingest_admin_overview Overview
+
+Examiner nodes in an \ref auto_ingest_page environment can be given a type of administrator access. This allows an admin to:
+
+- Access admin-only options on the Auto Ingest Jobs Panel, including:
+
+- Prioritizing jobs and cases
+
- Cancelling jobs
+
- Deleting and reprocessing jobs
+
+ - Access the Auto Ingest Nodes Panel, which allows the user to:
+
- View the currently active auto ingest nodes
+
- Pause/resume/shutdown the active auto ingest nodes
+
- View/enabled the health monitor
+
- View auto ingest metrics
+
+
+\section auto_ingest_admin_setup Setup
+
+The admin panel is enabled by creating the file "admin" in the user config directory. Note that the name must be exactly that with no extension. It also works to make a folder named "admin" instead of a file which can be easier on machines where the file extension is hidden. No restart is needed; simply reopen the Auto Ingest Dashboard after creating the file.
+
+For an installed copy of Autopsy, the file will go under \c "C:\Users\\AppData\Roaming\Autopsy\config".
+
+\image html AutoIngest\admin_file.png
+
+\section auto_ingest_admin_jobs_panel Auto Ingest Jobs Panel
+
+With the admin file in place, the user can right-click on jobs in each of the tables of the jobs panel to perform different actions. In the Pending Jobs table, the context menu allows cases and individual jobs to be prioritized.
+
+\image html AutoIngest\admin_jobs_panel.png
+
+In the Running Jobs tables, the ingest progress can be viewed and the current job can be cancelled. Note that cancellation can take some time.
+
+\image html AutoIngest\admin_jobs_cancel.png
+
+In the Completed Jobs table, the user can reprocess a job (generally useful when a job had errors), delete a case (if no other machines are using it) and view the case log.
+
+\image html AutoIngest\admin_jobs_completed.png
+
+\section auto_ingest_admin_nodes_panel Auto Ingest Nodes Panel
+
+The Nodes panel displays the status of every online auto ingest node. Additionally, an admin can pause or resume a node, or shut down a node entirely (i.e., exit the Autopsy app).
+
+\image html AutoIngest\admin_nodes_panel.png
+
+\section auto_ingest_admin_cases_panel Cases Panel
+
+The Cases panel shows information about each auto ingest case - the name, creation and last accessed times, the case directory, and flags for which parts of the case have been deleted.
+
+\image html AutoIngest\cases_panel.png
+
+If you right-click on a case, you can open it, see the log, delete the case, or view properties of the case.
+
+\image html AutoIngest\cases_context_menu.png
+
+Note that you can select multiple cases at once to delete. If you choose to delete a case (or cases), you'll see the following confirmation dialog:
+
+\image html case_delete_confirm.png
+
+\section auto_ingest_admin_health_monitor Health Monitor
+
+The health monitor shows timing stats and the general state of the system. The Health Monitor is accessed from the Auto Ingest Nodes panel. To enable health monitoring, click on the Health Monitor button to get the following screen and then press the "Enable monitor" button.
+
+\image html AutoIngest\health_monitor_disabled.png
+
+This will enable the health monitor metrics on every node (both auto ingest nodes and examiner nodes) that is using this PostgreSQL server. Once enabled, the monitor will display the collected metrics.
+
+\image html AutoIngest\health_monitor.png
+
+By default, the graphs will show all metrics collected in the last day.
+
+The Timing Metrics area shows how long various tasks took to perform. There are several options in the Timing Metrics section:
+- Max days to display: Choose to show the last day, week, two week, or month
+
- Filter by host: Show only metrics that came from the selected host
+
- Show trend line: Show or hide the red trend line
+
- Do not plot outliers: Redraws the graph allowing very high metrics to go off the screen. Can be helpful with data where a couple of entries took an exceptionally long time.
+
+
+The User Metrics section shows open cases and logged on nodes. For the open cases section, the count is the number of distinct cases open. If ten nodes have the same case open, the count will be one. The logged in users section shows the total number of active nodes, with auto ingest nodes on the bottom in green and examiner nodes on top in blue. The User Metrics section only has one option:
+- Max days to display: Choose to show the last day, week, two week, or month
+
+
+\section auto_ingest_admin_metrics Auto Ingest Metrics
+
+The Auto Ingest Metrics can be accessed the Auto Ingest Nodes panel and shows data about the jobs completed in a selected time frame.
+
+\image html AutoIngest\metrics.png
+
+*/
\ No newline at end of file
diff --git a/docs/doxygen-user/auto_ingest_setup.dox b/docs/doxygen-user/auto_ingest_setup.dox
new file mode 100644
index 0000000000..48d33d67fe
--- /dev/null
+++ b/docs/doxygen-user/auto_ingest_setup.dox
@@ -0,0 +1,104 @@
+/*! \page auto_ingest_setup_page Auto Ingest Configuration
+
+\section auto_ingest_setup_overview Overview
+
+A multi-user installation requires several network-based services, such as a central database and a messaging system, and automated ingest requires one or more auto ingest nodes. While you may run all of the external services on a single node, this is not likely to be ideal - spreading the services out across several machines can improve throughput. Keeping in mind that all the following machines need to be able to communicate with each other with network visibility to the shared drive, here is a description of a possible configuration:
+
+
+| Number of Machines | Services |
+| One | - Solr - Install Solr on the highest-powered machine; the more CPUs the better.
+- The case output folders can also be put on this machine.
|
+| One | - ActiveMQ - This service has minimal memory and disk requirements.
+- PostgreSQL - This service has minimal memory and disk requirements.
|
+| One | - Shared image folder - This machine needs a large amount of disk space but doesn't need the fastest hardware.
|
+| One or more | - Automated Ingest Node(s) - These machines don't need much disk space but benefit from additional memory and processing power.
|
+| One or more | - Examiner Node(s) - See \ref installation_page for recommended system requirements.
|
+
+
+Solr is going to be a sizeable resource hog. A big performance increase will be seen if you put solid state drives (SSD) in the machine running Solr, and have that machine also host the large network drive on the SSDs as a place to store case output. The source images to can be on SAS drives (slower than SSD) with very little impact on performance. This idea here is to have the most resource-intensive operations on the fastest hardware. Using this strategy, there are actually two large network stores, one for input images and one for output cases.
+
+\section auto_ingest_setup_services Installing Services and Configuring Autopsy
+Follow the instructions on the \ref install_multiuser_page page to set up the necessary services and configure your Autopsy clients to use them. After this is complete, you should be able to \ref multiuser_page "create and use multi-user cases".
+
+\section auto_ingest_setup_ain_config Auto Ingest Node Configuration
+
+While Examiner nodes only require multi-user cases to be set up, the auto ingest nodes need additional configuration. To start, go to the "Auto Ingest" tab on the Options menu and select the "Auto Ingest mode" radio button. If you haven't saved your multi-user settings there will be a warning message displayed here - if you see it, go back to the "Multi-User" tab and make sure you've entered all the required fields and then hit the "Apply" button.
+
+\image html AutoIngest\auto_ingest_mode_setup.png
+
+\subsection auto_ingest_config_folders Folder Configuration
+
+The first thing to do is to set two folder locations. The shared images folder is the base folder for all data that will be ingested through the auto ingest node. The shared cases folder is the base folder for the cases that will be created by the auto ingest node.
+
+\subsection auto_ingest_config_ingest_settings Ingest Module Settings
+The "Ingest Module Settings" button is used to configure the \ref ingest_page you want to run during auto-ingest. One note is that on auto-ingest nodes, we recommend that you configure the Keyword Search module to not perform periodic keyword searches. When a user is in front of the computer, this feature exists to provide frequent updates, but it is not needed on this node. To configure this, choose the Keyword Search item in the Options window. Select the "General" tab and choose the option for no periodic search.
+
+\image html AutoIngest\no_periodic_searches.png
+
+\subsection auto_ingest_advanced_settings Advanced Settings
+
+The "Advanced Settings" button will bring up the automated ingest job settings. As expressed in the warning statement, care must be used when making changes on this panel.
+
+\image html AutoIngest\advanced_settings.png
+
+The Automated Ingest Job Settings section contains the following options:
+
+- System synchronization wait time
+- A wait time used by auto ingest nodes to ensure proper synchronization of node operations in circumstances where delays may occur, e.g., a wait to compensate for network file system latency effects on the visibility of newly created shared directories and files.
+- External processes time out
+- Autopsy components that spawn potentially long-running processes have the option to use this setting, if it is enabled, to terminate those processes if the specified time out period has elapsed. Each component that uses this feature is responsible for implementing its own policy for the handling of incomplete processing when an external process time out occurs. Core components that use external process time outs include the \ref recent_activity_page and \ref photorec_carver_page ingest modules.
+- Interval between input scans
+- The interval between scans of the auto ingest input directories for manifest files. Note that the actual timing of input scans by each node depends on both this setting and node startup time.
+- Maximum job retries allowed
+- The maximum number of times a crashed auto ingest job will be automatically retried. No distinction is made between jobs that crash due to system error conditions such as power outages and jobs that crash due to input data source corruption. In general, input data source corruption should be handled gracefully by Autopsy, but this setting provides insurance against unforeseen issues with input data viability.
+- Target concurrent jobs per case
+- A soft limit on the number of concurrent jobs per case when multiple cases are processed simultaneously by a group of auto ingest nodes. This setting specifies a target rather than a hard limit because nodes are never idled if there are ingest jobs to do and nodes work cooperatively rather than rely on a centralized, load-balancing job scheduling service.
+- Number of threads to use for file ingest
+- The number of threads an auto ingest node dedicates to analyzing files from input data sources in parallel. Note that analysis of input data source files themselves is always single-threaded.
+
+
+\subsection auto_ingest_file_export File Export
+
+The "File Export" button will bring up the \ref file_export_page settings. This allows certain types of files to be automatically exported during auto ingest. Setting up this feature requires knowledge of internal Autopsy data structures and can be ignored for users.
+
+\subsection auto_ingest_shared_config Shared Configuration
+
+When using multiple auto ingest nodes, configuration can be centralized and shared with any auto ingest node that desires to use it. This is called Shared Configuration. The general idea is that you will set up one node (the "master") and upload that configuration to a central location. Then the other auto ingest nodes (the "secondary" nodes) will download that configuration whenever they start a new job. This saves time because you only need to configure one node, and ensures consistency across the auto ingest nodes.
+
+\subsubsection auto_ingest_shared_config_master Master Node
+
+On the computer that is going to be the configuration master automated ingest node, follow the configuration steps described in above to configure the node.
+If you would like every automated ingest node to share the configuration settings, check the first checkbox in the Shared Configuration section of the Auto Ingest settings panel. Next select a folder to store the shared configuration in. This folder must be a path to a network share that the other machines in the system will have access to. Use a UNC path if possible. Next, check the "Use this node as a master node that can upload settings" checkbox which should enable the "Save & Upload Config" button. If this does not happen, look for a red error message explaining what settings are missing.
+
+\image html AutoIngest\master_node.png
+
+After saving and uploading the configuration, hit the "Save" button to exit the Options panel.
+
+\subsubsection auto_ingest_shared_config_secondary Secondary Node
+
+Once one node has uploaded shared configuration data, the remaining nodes can be set up to download it, skipping over some of the configuration steps above.
+
+To set up a secondary node, start by going through the \ref install_multiuser_page "multi-user configuration." Apply those changes, then switch to the Auto Ingest tab on the Options panel. Check the box to enable auto ingest, and then the box to enable shared configuration and enter the same folder used on the master node. The "Download Config" button should now be enabled and can be used to get the rest of the configuration automatically. Afterwards a dialog will likely appear telling you to restart Autopsy.
+
+\subsubsection auto_ingest_shared_config_notes Notes
+
+Some notes on shared configuration:
+- The \ref auto_ingest_error_suppression "error suppression registry edit" below will need to be done on each node
+
- After the initial setup, the current shared configuration data will be updated before each job (no need to manually download it again)
+
- A few options require a restart to take effect (for example, most of the multi-user settings). If these are downloaded automatically while automated ingest is running, they will not be used until the automated ingest node is restarted.
+
- There is currently a limitation on where hash databases can be saved. Each database will be downloaded to the same folder it was in on the master node, which will cause errors if that drive letter is not present or the folder is not writeable on every node.
+
- Shared copies of the hash databases are also not currently supported. Each node will download its own copy of each database.
+
+
+
+\subsection auto_ingest_error_suppression Error Suppression
+
+On an auto ingest node, we also strongly recommend that you configure the system to suppress error dialogs that Windows may display if an application crashes. Some of the modules that Autopsy runs have crashed on some test data in the past and if an error dialog is displayed all processing stops.
+
+Disabling the error messages is done by setting the following registry key to "1", as shown in the screenshot below.
+\verbatim HKCU\Software\Microsoft\Windows\Windows Error Reporting\DontShowUI\endverbatim
+
+\image html AutoIngest\error_suppression.png
+
+
+*/
\ No newline at end of file
diff --git a/docs/doxygen-user/experimental.dox b/docs/doxygen-user/experimental.dox
index 4593a16df8..c5fcc742a8 100644
--- a/docs/doxygen-user/experimental.dox
+++ b/docs/doxygen-user/experimental.dox
@@ -6,13 +6,13 @@ The Experimental module, as the name implies, contains code that is not yet part
\section exp_setup Enabling the Experimental Module
-To start, go to Tools->Plugins and select the "Installed" tab, then check the box next to "Experimental" and click "Activate" and go throught the next couple of screens. A reset should not be required.
+To start, go to Tools->Plugins and select the "Installed" tab, then check the box next to "Experimental" and click "Activate" and go through the next couple of screens. A restart should not be required.
\image html experimental_plugins_menu.png
\section exp_features Current Experimental Features
-- Auto Ingest
+- \ref auto_ingest_page
- \ref object_detection_page
- \ref volatility_dsp_page
diff --git a/docs/doxygen-user/file_export.dox b/docs/doxygen-user/file_export.dox
new file mode 100644
index 0000000000..84502c00cc
--- /dev/null
+++ b/docs/doxygen-user/file_export.dox
@@ -0,0 +1,69 @@
+/*! \page file_export_page File Export
+
+\section file_export_overview Overview
+
+If enabled, the File Exporter will run after each \ref auto_ingest_page job and export any files from that data source that match the supplied rules. Most users will not need to use this feature - analysts can open the auto ingest cases in an examiner node and look through the data there.
+
+\section file_export_setup Configuration
+
+After enabling the file exporter, the first thing to do is set two output folders. The "Files Folder" is the base directory for all exported files, and the "Reports Folder" is the base directory for reports (lists of every file exported for each data source). If possible, it is best to use UNC paths.
+
+\image html AutoIngest\file_exporter_main.png
+
+Next you'll make rules for the files you want to export. Each rule must have a name and at least one condition set. If more than one condition is set, then all conditions must be true to export the file. When you're done setting up your rule, press the "Save" button to save it. You'll see the new rule in the list on the left side.
+
+All of the saved rules will be run against each data source. There's no way to set a rule as inactive, so if you make a rule and don't want it to run you'll have to use the "Delete Rule" button to remove it.
+
+You'll need to run at the \ref hash_db_page and \ref file_type_identification_page to use the file exporter. You may need to run additional modules based on any attributes in your rules.
+
+\subsection file_exporter_mime MIME Type
+
+The first condition is based on MIME type. To enable it, check the box before "MIME Type", then select a MIME type from the list and choose whether you want to match it or not match it. Multiple MIME types can not be selected at this time. The following shows a rule that will match all PNG images.
+
+\image html AutoIngest\file_export_png.png
+
+\subsection file_exporter_size File Size
+
+The second condition is based on file size. You can choose a file size (using the list on the right to change the units) and then select whether files should be larger, smaller, equal to, or not equal to that size. The following shows a rule that will match plain text files that are over 1kB.
+
+\image html AutoIngest\file_export_size.png
+
+\subsection file_exporter_attributes Attributes
+
+The third condition is based on blackboard artifacts and attributes, which is how Autopsy stores most of its analysis results. A file will be exported if it is linked to a matching attribute. Using this type of condition will require some familiarity with exactly how these attributes are being created and what data we expect to see in them. There's some information to get started in the Sleuthkit documentation. You will most likely also have to open an Autopsy database file to verify the exact attribute types being used to hold the data you're interested in.
+
+To make an attribute condition, select the artifact type and then the attribute type that you are interested in. On the next line you can enter a value and set what relation you want the attribute to have to it (equals, not equals, greater/less than). Not all options will make sense with all data types. Then use the "Add Attribute" button to add it to the attribute list. If you make a mistake, use the "Delete Attribute" button to erase it. The following shows a rule that will export any files that had a keyword hit for the word "bomb" in them.
+
+\image html AutoIngest\file_export_keyword.png
+
+It's possible to do more general matching on the artifacts. Suppose you wanted to export all files that the \ref encryption_page flagged as "Encryption Suspected". These files will have a TSK_ENCRYPTION_SUSPECTED artifact with a single "TSK_COMMENT" attribute that contains the entropy calculated for the file. In this case we can use the "not equals" operator on a string that we wouldn't expect to see in the TSK_COMMENT field to effectively change the condition to "has an associated TSK_ENCRYPTION_SUSPECTED artifact."
+
+\image html AutoIngest\file_export_encrypton.png
+
+\section file_export_output Output
+
+The exported files are found under the files folder that was specified in the \ref file_export_setup step and then organized at the top layer by the device ID of the data source.
+
+\image html AutoIngest\file_export_dir_structure.png
+
+Exported files are named with their hash and stored in subfolders based on parts of that hash, to prevent any single folder from becoming very large.
+
+\image html AutoIngest\file_export_file_loc.png
+
+The report files are also found in subfolders under the device ID and then the rule name.
+
+\image html AutoIngest\file_export_json_loc.png
+
+This json file will contain information about the file, and any associated artifact that was part of the rule's conditions.
+\verbatim
+{"7C89F280C337AB3E997D20527B8EC6F8":{"Filename":"\\\\WIN-4913\\AutopsyData\\FileExportFiles\\37567\\text-plain\\7C\\89\\F2\\80\\7C89F280C337AB3E997D20527B8EC6F8",
+"Type":"text/plain","MD5":"7C89F280C337AB3E997D20527B8EC6F8","File data":{"Modified":["0000-00-00 00:00:00"],"Changed":["0000-00-0000:00:00"],
+"Accessed":["0000-00-00 00:00:00"],"Created":["0000-00-00 00:00:00"],"Extension":["txt"],"Filename":["File about explosions.txt"],"Size":["54"],
+"Source Path":["/kwTest_2019_03_14_12_53_33//File about explosions.txt"],"Flags (Dir)":["Allocated"],"Flags (Meta)":["Allocated"],
+"Mode":["r---------"],"User ID":["0"],"Group ID":["0"],"Meta Addr":["0"],"Attr Addr":["1-0"],"Dir Type":["r"],"MetaType":["r"],
+"Known":["unknown"]},"TSK_KEYWORD_HIT":{"TSK_KEYWORD":["bomb"]},
+"TSK_KEYWORD_HIT":{"TSK_KEYWORD_PREVIEW":["keyword search for the word bomb in this file.\n\n\n------"]},
+"TSK_KEYWORD_HIT":{"TSK_SET_NAME":["bomb"]},"TSK_KEYWORD_HIT":{"TSK_KEYWORD_SEARCH_TYPE":["0"]}}}
+\endverbatim
+
+*/
\ No newline at end of file
diff --git a/docs/doxygen-user/images/AutoIngest/admin_file.png b/docs/doxygen-user/images/AutoIngest/admin_file.png
new file mode 100644
index 0000000000..0112d84ef3
Binary files /dev/null and b/docs/doxygen-user/images/AutoIngest/admin_file.png differ
diff --git a/docs/doxygen-user/images/AutoIngest/admin_jobs_cancel.png b/docs/doxygen-user/images/AutoIngest/admin_jobs_cancel.png
new file mode 100644
index 0000000000..ba3fb81691
Binary files /dev/null and b/docs/doxygen-user/images/AutoIngest/admin_jobs_cancel.png differ
diff --git a/docs/doxygen-user/images/AutoIngest/admin_jobs_completed.png b/docs/doxygen-user/images/AutoIngest/admin_jobs_completed.png
new file mode 100644
index 0000000000..f1046371de
Binary files /dev/null and b/docs/doxygen-user/images/AutoIngest/admin_jobs_completed.png differ
diff --git a/docs/doxygen-user/images/AutoIngest/admin_jobs_panel.png b/docs/doxygen-user/images/AutoIngest/admin_jobs_panel.png
new file mode 100644
index 0000000000..32dfa89cdd
Binary files /dev/null and b/docs/doxygen-user/images/AutoIngest/admin_jobs_panel.png differ
diff --git a/docs/doxygen-user/images/AutoIngest/admin_nodes_panel.png b/docs/doxygen-user/images/AutoIngest/admin_nodes_panel.png
new file mode 100644
index 0000000000..08488323dd
Binary files /dev/null and b/docs/doxygen-user/images/AutoIngest/admin_nodes_panel.png differ
diff --git a/docs/doxygen-user/images/AutoIngest/advanced_settings.png b/docs/doxygen-user/images/AutoIngest/advanced_settings.png
new file mode 100644
index 0000000000..8dd88696d3
Binary files /dev/null and b/docs/doxygen-user/images/AutoIngest/advanced_settings.png differ
diff --git a/docs/doxygen-user/images/AutoIngest/auto_ingest_in_progress.png b/docs/doxygen-user/images/AutoIngest/auto_ingest_in_progress.png
new file mode 100644
index 0000000000..cf894b13c3
Binary files /dev/null and b/docs/doxygen-user/images/AutoIngest/auto_ingest_in_progress.png differ
diff --git a/docs/doxygen-user/images/AutoIngest/auto_ingest_mode_setup.png b/docs/doxygen-user/images/AutoIngest/auto_ingest_mode_setup.png
new file mode 100644
index 0000000000..e11db06246
Binary files /dev/null and b/docs/doxygen-user/images/AutoIngest/auto_ingest_mode_setup.png differ
diff --git a/docs/doxygen-user/images/AutoIngest/case_delete_confirm.png b/docs/doxygen-user/images/AutoIngest/case_delete_confirm.png
new file mode 100644
index 0000000000..6d3acec6ae
Binary files /dev/null and b/docs/doxygen-user/images/AutoIngest/case_delete_confirm.png differ
diff --git a/docs/doxygen-user/images/AutoIngest/cases_context_menu.png b/docs/doxygen-user/images/AutoIngest/cases_context_menu.png
new file mode 100644
index 0000000000..e83c083f49
Binary files /dev/null and b/docs/doxygen-user/images/AutoIngest/cases_context_menu.png differ
diff --git a/docs/doxygen-user/images/AutoIngest/cases_panel.png b/docs/doxygen-user/images/AutoIngest/cases_panel.png
new file mode 100644
index 0000000000..c932b57bf1
Binary files /dev/null and b/docs/doxygen-user/images/AutoIngest/cases_panel.png differ
diff --git a/docs/doxygen-user/images/AutoIngest/error_suppression.png b/docs/doxygen-user/images/AutoIngest/error_suppression.png
new file mode 100644
index 0000000000..91d2805029
Binary files /dev/null and b/docs/doxygen-user/images/AutoIngest/error_suppression.png differ
diff --git a/docs/doxygen-user/images/AutoIngest/examiner_dashboard.png b/docs/doxygen-user/images/AutoIngest/examiner_dashboard.png
new file mode 100644
index 0000000000..7e0da4d353
Binary files /dev/null and b/docs/doxygen-user/images/AutoIngest/examiner_dashboard.png differ
diff --git a/docs/doxygen-user/images/AutoIngest/file_export_dir_structure.png b/docs/doxygen-user/images/AutoIngest/file_export_dir_structure.png
new file mode 100644
index 0000000000..2e9003831c
Binary files /dev/null and b/docs/doxygen-user/images/AutoIngest/file_export_dir_structure.png differ
diff --git a/docs/doxygen-user/images/AutoIngest/file_export_encrypton.png b/docs/doxygen-user/images/AutoIngest/file_export_encrypton.png
new file mode 100644
index 0000000000..829ee730f0
Binary files /dev/null and b/docs/doxygen-user/images/AutoIngest/file_export_encrypton.png differ
diff --git a/docs/doxygen-user/images/AutoIngest/file_export_file_loc.png b/docs/doxygen-user/images/AutoIngest/file_export_file_loc.png
new file mode 100644
index 0000000000..8311283585
Binary files /dev/null and b/docs/doxygen-user/images/AutoIngest/file_export_file_loc.png differ
diff --git a/docs/doxygen-user/images/AutoIngest/file_export_json_loc.png b/docs/doxygen-user/images/AutoIngest/file_export_json_loc.png
new file mode 100644
index 0000000000..2652c387cc
Binary files /dev/null and b/docs/doxygen-user/images/AutoIngest/file_export_json_loc.png differ
diff --git a/docs/doxygen-user/images/AutoIngest/file_export_keyword.png b/docs/doxygen-user/images/AutoIngest/file_export_keyword.png
new file mode 100644
index 0000000000..c2b6a26b78
Binary files /dev/null and b/docs/doxygen-user/images/AutoIngest/file_export_keyword.png differ
diff --git a/docs/doxygen-user/images/AutoIngest/file_export_png.png b/docs/doxygen-user/images/AutoIngest/file_export_png.png
new file mode 100644
index 0000000000..2d872401d0
Binary files /dev/null and b/docs/doxygen-user/images/AutoIngest/file_export_png.png differ
diff --git a/docs/doxygen-user/images/AutoIngest/file_export_size.png b/docs/doxygen-user/images/AutoIngest/file_export_size.png
new file mode 100644
index 0000000000..c4e2eb7917
Binary files /dev/null and b/docs/doxygen-user/images/AutoIngest/file_export_size.png differ
diff --git a/docs/doxygen-user/images/AutoIngest/file_exporter_main.png b/docs/doxygen-user/images/AutoIngest/file_exporter_main.png
new file mode 100644
index 0000000000..2aa3e99778
Binary files /dev/null and b/docs/doxygen-user/images/AutoIngest/file_exporter_main.png differ
diff --git a/docs/doxygen-user/images/AutoIngest/health_monitor.png b/docs/doxygen-user/images/AutoIngest/health_monitor.png
new file mode 100644
index 0000000000..2550900ee8
Binary files /dev/null and b/docs/doxygen-user/images/AutoIngest/health_monitor.png differ
diff --git a/docs/doxygen-user/images/AutoIngest/health_monitor_disabled.png b/docs/doxygen-user/images/AutoIngest/health_monitor_disabled.png
new file mode 100644
index 0000000000..ae8bcf64e9
Binary files /dev/null and b/docs/doxygen-user/images/AutoIngest/health_monitor_disabled.png differ
diff --git a/docs/doxygen-user/images/AutoIngest/manifest_file_in_file_explorer.png b/docs/doxygen-user/images/AutoIngest/manifest_file_in_file_explorer.png
new file mode 100644
index 0000000000..2df4d7a777
Binary files /dev/null and b/docs/doxygen-user/images/AutoIngest/manifest_file_in_file_explorer.png differ
diff --git a/docs/doxygen-user/images/AutoIngest/manifest_tool_ui.png b/docs/doxygen-user/images/AutoIngest/manifest_tool_ui.png
index 5c5c9458d1..70766fc8a4 100644
Binary files a/docs/doxygen-user/images/AutoIngest/manifest_tool_ui.png and b/docs/doxygen-user/images/AutoIngest/manifest_tool_ui.png differ
diff --git a/docs/doxygen-user/images/AutoIngest/master_node.png b/docs/doxygen-user/images/AutoIngest/master_node.png
new file mode 100644
index 0000000000..3f0813047f
Binary files /dev/null and b/docs/doxygen-user/images/AutoIngest/master_node.png differ
diff --git a/docs/doxygen-user/images/AutoIngest/metrics.png b/docs/doxygen-user/images/AutoIngest/metrics.png
new file mode 100644
index 0000000000..bff656a259
Binary files /dev/null and b/docs/doxygen-user/images/AutoIngest/metrics.png differ
diff --git a/docs/doxygen-user/images/AutoIngest/no_periodic_searches.png b/docs/doxygen-user/images/AutoIngest/no_periodic_searches.png
new file mode 100644
index 0000000000..40326527d2
Binary files /dev/null and b/docs/doxygen-user/images/AutoIngest/no_periodic_searches.png differ
diff --git a/docs/doxygen-user/images/AutoIngest/overview_pic1.png b/docs/doxygen-user/images/AutoIngest/overview_pic1.png
new file mode 100644
index 0000000000..29852cb6e3
Binary files /dev/null and b/docs/doxygen-user/images/AutoIngest/overview_pic1.png differ
diff --git a/docs/doxygen-user/images/AutoIngest/overview_pic2.png b/docs/doxygen-user/images/AutoIngest/overview_pic2.png
new file mode 100644
index 0000000000..99dcc07266
Binary files /dev/null and b/docs/doxygen-user/images/AutoIngest/overview_pic2.png differ
diff --git a/docs/doxygen-user/multiuser.dox b/docs/doxygen-user/multiuser.dox
index f57527a507..99141d0a22 100644
--- a/docs/doxygen-user/multiuser.dox
+++ b/docs/doxygen-user/multiuser.dox
@@ -2,40 +2,28 @@
\section creating_multi_user_cases Creating Multi-user cases
-Multi-user cases allow multiple instances of Autopsy to have the same case open at the same time. When creating a case, users are now presented with a choice of Single-user or Multi-user as shown in the screenshot below.
+Multi-user cases allow multiple instances of Autopsy to have the same case open at the same time. When creating a case, users are presented with a choice of Single-user or Multi-user as shown in the screenshot below.
-
\image html case-newcase.PNG
-
-
-Single-user functions the same as always, with a back end SQLite database and a machine-local version of Solr.
To create a multi-user case, the following must occur:
- The network services must be installed, configured, and running. See \ref multiuser_install_services.
- The Case folder needs to be in a shared folder that all other clients can also access at the same path (UNC or drive letter).
- The data sources that are added with the Add Data Source wizard must be in a shared folder that all clients can access at the same path.
-
-
\section multi_user_other Other Multi-user Information
- When using a multi-user case, other nodes could be running data ingest on the same case. While this is happening, you will see a progress bar labelled with the hostname of the machine performing the ingest on the bottom right of Autopsy. The progress bar will continue to move back and forth until ingest has been completed or cancelled. You can still run ingest on your local machine while this is ongoing. This is shown in the screenshot below.
-
\image html othernodeingesting.PNG
-
- When issues occur, there is an information "bubble" on the bottom right of the screen. It has an "i" inside a circle, with the color of the circle changed based upon the message. It uses red for bad and blue for good. See the screenshot below.
-
\image html messagebubbles.PNG
-
- Clicking on the information "bubble" brings up the list of prior notifications that have not been dismissed by clicking on the "x". As you can see in the screenshot below, the network cable was unplugged from the machine and it lost all connection to the three services. When the cable was reconnected, it found the services again.
-
\image html messagebubblesbigger.PNG
-
- When creating multi-user cases, we recommend using UNC paths to specify drive names. Drive mapping will work, but it is sometimes difficult to get all the machines participating in a case to map to the same drive letters for the same resources. It is much simpler to use fully-specified UNC paths in the form of \\\\hostname\\sharename\\folder.