From 7c9d4e15966d7e83e596ef2cc7744000b3de7ef9 Mon Sep 17 00:00:00 2001 From: William Schaefer Date: Tue, 8 Jan 2019 13:41:03 -0500 Subject: [PATCH] 4590 change data source profile artifact/attribute relationship to 1 to 1 --- .../recentactivity/DataSourceProfiler.java | 18 +++++++++--------- 1 file changed, 9 insertions(+), 9 deletions(-) diff --git a/RecentActivity/src/org/sleuthkit/autopsy/recentactivity/DataSourceProfiler.java b/RecentActivity/src/org/sleuthkit/autopsy/recentactivity/DataSourceProfiler.java index 408aa30256..82adb3929c 100644 --- a/RecentActivity/src/org/sleuthkit/autopsy/recentactivity/DataSourceProfiler.java +++ b/RecentActivity/src/org/sleuthkit/autopsy/recentactivity/DataSourceProfiler.java @@ -40,35 +40,35 @@ public class DataSourceProfiler extends Extract { @Override void process(Content dataSource, IngestJobContext context) { - Collection bbattributes = new ArrayList<>(); + this.dataSource = dataSource; try { - checkForWindowsVolume(bbattributes); + checkForWindowsVolume(); } catch (TskCoreException ex) { logger.log(Level.WARNING, "Failed to check if datasource contained Windows volume.", ex); } - //create an artifact if any attributes were added - if (!bbattributes.isEmpty()) { - addArtifact(BlackboardArtifact.ARTIFACT_TYPE.TSK_DATA_SOURCE_PROFILE, dataSource, bbattributes); - } + } /** * Check if the data source contains files which would indicate a windows * volume is present in it. * - * @param bbattributes the list of blackboard attributes to add to if a windows volume is present + * @param bbattributes the list of blackboard attributes to add to if a + * windows volume is present * * @throws TskCoreException */ - private void checkForWindowsVolume(Collection bbattributes) throws TskCoreException { + private void checkForWindowsVolume() throws TskCoreException { + Collection bbattributes = new ArrayList<>(); FileManager fileManager = currentCase.getServices().getFileManager(); List files = fileManager.findFilesByParentPath(dataSource.getId(), "/windows/system32"); - //create an attribute if any files with the windows/system32 path were found + //create an artifact if any files with the windows/system32 path were found if (!files.isEmpty()) { bbattributes.add(new BlackboardAttribute(BlackboardAttribute.ATTRIBUTE_TYPE.TSK_DATA_SOURCE_DESCRIPTOR, Bundle.DataSourceProfiler_parentModuleName(), "Windows volume")); //NON-NLS + addArtifact(BlackboardArtifact.ARTIFACT_TYPE.TSK_DATA_SOURCE_PROFILE, dataSource, bbattributes); } }