From ddfc5a1dbd4f0d0f9ac033fc7da9fd3032f47acc Mon Sep 17 00:00:00 2001 From: Mark McKinnon Date: Thu, 17 Sep 2020 15:24:41 -0400 Subject: [PATCH 1/6] Update ILeappFileProcessor.java Remove stack trace and add attribute name and file name where the date parse error is occuring. --- .../modules/ileappanalyzer/ILeappFileProcessor.java | 8 +++++--- 1 file changed, 5 insertions(+), 3 deletions(-) diff --git a/Core/src/org/sleuthkit/autopsy/modules/ileappanalyzer/ILeappFileProcessor.java b/Core/src/org/sleuthkit/autopsy/modules/ileappanalyzer/ILeappFileProcessor.java index 1bc80c9019..8c9c8c340b 100644 --- a/Core/src/org/sleuthkit/autopsy/modules/ileappanalyzer/ILeappFileProcessor.java +++ b/Core/src/org/sleuthkit/autopsy/modules/ileappanalyzer/ILeappFileProcessor.java @@ -202,6 +202,7 @@ public final class ILeappFileProcessor { * * @param line a tsv line to process that was read * @param columnNumberToProcess Which columns to process in the tsv line + * @param fileName name of file begin processed * * @return */ @@ -220,7 +221,7 @@ public final class ILeappFileProcessor { break; } String attrType = attributeType.getValueType().getLabel().toUpperCase(); - checkAttributeType(bbattributes, attrType, columnValues, columnNumber, attributeType); + checkAttributeType(bbattributes, attrType, columnValues, columnNumber, attributeType, fileName); } catch (TskCoreException ex) { throw new IngestModuleException(String.format("Error getting Attribute type for Attribute Name %s", attributeName), ex); //NON-NLS } @@ -234,7 +235,8 @@ public final class ILeappFileProcessor { } - private void checkAttributeType(Collection bbattributes, String attrType, String[] columnValues, Integer columnNumber, BlackboardAttribute.Type attributeType) { + private void checkAttributeType(Collection bbattributes, String attrType, String[] columnValues, Integer columnNumber, BlackboardAttribute.Type attributeType, + String fileName) { if (attrType.matches("STRING")) { bbattributes.add(new BlackboardAttribute(attributeType, MODULE_NAME, columnValues[columnNumber])); } else if (attrType.matches("INTEGER")) { @@ -256,7 +258,7 @@ public final class ILeappFileProcessor { } catch (ParseException ex) { // catching error and displaying date that could not be parsed // we set the timestamp to 0 and continue on processing - logger.log(Level.WARNING, String.format("Failed to parse date/time %s for attribute.", columnValues[columnNumber]), ex); //NON-NLS + logger.log(Level.WARNING, String.format("Failed to parse date/time %s for attribute type %s in file %s.", columnValues[columnNumber], attributeType.getDisplayName(), fileName)); //NON-NLS } } else if (attrType.matches("JSON")) { From 4f87563a27904bc54a048d33b92eeda8235e3156 Mon Sep 17 00:00:00 2001 From: Kelly Kelly Date: Fri, 18 Sep 2020 15:21:26 -0400 Subject: [PATCH 2/6] The changed the ingestProfile argument --- .../CommandLineOptionProcessor.java | 25 ++++++------------- 1 file changed, 7 insertions(+), 18 deletions(-) diff --git a/Core/src/org/sleuthkit/autopsy/commandlineingest/CommandLineOptionProcessor.java b/Core/src/org/sleuthkit/autopsy/commandlineingest/CommandLineOptionProcessor.java index 350e99c598..ad84bdcd0f 100755 --- a/Core/src/org/sleuthkit/autopsy/commandlineingest/CommandLineOptionProcessor.java +++ b/Core/src/org/sleuthkit/autopsy/commandlineingest/CommandLineOptionProcessor.java @@ -49,8 +49,7 @@ public class CommandLineOptionProcessor extends OptionProcessor { private final Option dataSourceObjectIdOption = Option.requiredArgument('i', "dataSourceObjectId"); private final Option addDataSourceCommandOption = Option.withoutArgument('a', "addDataSource"); private final Option caseDirOption = Option.requiredArgument('d', "caseDir"); - private final Option runIngestCommandOption = Option.withoutArgument('r', "runIngest"); - private final Option ingestProfileOption = Option.requiredArgument('p', "ingestProfile"); + private final Option runIngestCommandOption = Option.optionalArgument('r', "runIngest"); private final Option listAllDataSourcesCommandOption = Option.withoutArgument('l', "listAllDataSources"); private final Option generateReportsOption = Option.optionalArgument('g', "generateReports"); private final Option defaultArgument = Option.defaultArguments(); @@ -76,7 +75,6 @@ public class CommandLineOptionProcessor extends OptionProcessor { set.add(dataSourceObjectIdOption); set.add(caseDirOption); set.add(runIngestCommandOption); - set.add(ingestProfileOption); set.add(listAllDataSourcesCommandOption); set.add(generateReportsOption); set.add(defaultArgument); @@ -205,21 +203,6 @@ public class CommandLineOptionProcessor extends OptionProcessor { } } - String ingestProfile = ""; - if (values.containsKey(ingestProfileOption)) { - - argDirs = values.get(ingestProfileOption); - if (argDirs.length < 1) { - handleError("Argument missing from 'ingestProfile' option"); - } - ingestProfile = argDirs[0]; - - // verify inputs - if (ingestProfile == null || ingestProfile.isEmpty()) { - handleError("Missing argument 'ingestProfile'"); - } - } - // Create commands in order in which they should be executed: // First create the "CREATE_CASE" command, if present if (values.containsKey(createCaseCommandOption)) { @@ -263,9 +246,15 @@ public class CommandLineOptionProcessor extends OptionProcessor { runFromCommandLine = true; } + String ingestProfile = ""; // Add RUN_INGEST command, if present if (values.containsKey(runIngestCommandOption)) { + argDirs = values.get(runIngestCommandOption); + if(argDirs != null && argDirs.length > 0) { + ingestProfile = argDirs[0]; + } + // 'caseDir' must only be specified if the case is not being created during the current run if (!values.containsKey(createCaseCommandOption) && caseDir.isEmpty()) { // new case is not being created during this run, so 'caseDir' should have been specified From 427c5f00e17140108c90422696fe3d2f0c0a8430 Mon Sep 17 00:00:00 2001 From: William Schaefer Date: Mon, 21 Sep 2020 10:02:44 -0400 Subject: [PATCH 3/6] 6876 add description for domain specific filters --- .../discovery/search/Bundle.properties-MERGED | 9 +++++ .../discovery/search/SearchFiltering.java | 35 +++++++++++++++++-- 2 files changed, 42 insertions(+), 2 deletions(-) diff --git a/Core/src/org/sleuthkit/autopsy/discovery/search/Bundle.properties-MERGED b/Core/src/org/sleuthkit/autopsy/discovery/search/Bundle.properties-MERGED index e1cbc654a1..037868e838 100644 --- a/Core/src/org/sleuthkit/autopsy/discovery/search/Bundle.properties-MERGED +++ b/Core/src/org/sleuthkit/autopsy/discovery/search/Bundle.properties-MERGED @@ -87,12 +87,21 @@ SearchData.Frequency.verycommon.displayName=Very Common (100+) SearchData.Score.interesting.displayName=Interesting SearchData.Score.notable.displayName=Notable SearchData.Score.unknown.displayName=Unknown +# {0} - artifactTypes +SearchFiltering.artifactTypeFilter.desc=Result type(s): {0} +SearchFiltering.artifactTypeFilter.or=, # {0} - Data source name # {1} - Data source ID SearchFiltering.DataSourceFilter.datasource={0}({1}) # {0} - filters SearchFiltering.DataSourceFilter.desc=Data source(s): {0} SearchFiltering.DataSourceFilter.or=, +# {0} - startDate +SearchFiltering.dateRangeFilter.after=after: {0} +SearchFiltering.dateRangeFilter.and=\ and +# {0} - endDate +SearchFiltering.dateRangeFilter.before=before: {0} +SearchFiltering.dateRangeFilter.lable=Activity date # {0} - filters SearchFiltering.FileTypeFilter.desc=Type: {0} SearchFiltering.FileTypeFilter.or=, diff --git a/Core/src/org/sleuthkit/autopsy/discovery/search/SearchFiltering.java b/Core/src/org/sleuthkit/autopsy/discovery/search/SearchFiltering.java index dd2609a56a..47731c6be0 100644 --- a/Core/src/org/sleuthkit/autopsy/discovery/search/SearchFiltering.java +++ b/Core/src/org/sleuthkit/autopsy/discovery/search/SearchFiltering.java @@ -18,6 +18,7 @@ */ package org.sleuthkit.autopsy.discovery.search; +import java.text.SimpleDateFormat; import org.sleuthkit.autopsy.centralrepository.datamodel.CorrelationAttributeInstance; import org.sleuthkit.autopsy.centralrepository.datamodel.CorrelationAttributeNormalizationException; import org.sleuthkit.autopsy.centralrepository.datamodel.CentralRepoException; @@ -32,8 +33,11 @@ import org.sleuthkit.datamodel.TagName; import org.sleuthkit.datamodel.TskCoreException; import java.util.ArrayList; import java.util.Arrays; +import java.util.Date; import java.util.List; +import java.util.Locale; import java.util.StringJoiner; +import java.util.concurrent.TimeUnit; import java.util.stream.Collectors; import org.openide.util.NbBundle; import org.sleuthkit.datamodel.BlackboardArtifact; @@ -171,9 +175,25 @@ public class SearchFiltering { + " AND (value_int64 BETWEEN " + startDate + " AND " + endDate + ")"; } + @NbBundle.Messages({"SearchFiltering.dateRangeFilter.lable=Activity date ", + "# {0} - startDate", + "SearchFiltering.dateRangeFilter.after=after: {0}", + "# {0} - endDate", + "SearchFiltering.dateRangeFilter.before=before: {0}", + "SearchFiltering.dateRangeFilter.and= and "}) @Override public String getDesc() { - return "ArtifactDateRangeFilter Stub"; + String desc = ""; // NON-NLS + if (!(startDate <= 0 )) { + desc += Bundle.SearchFiltering_dateRangeFilter_after(new SimpleDateFormat("yyyy/MM/dd", Locale.getDefault()).format(new Date(TimeUnit.SECONDS.toMillis(startDate)))); + } + if (!(endDate > 10000000000L)) { //arbitrary time sometime in the 23rd century to check that they specified a date and the max date isn't being used + if (!desc.isEmpty()) { + desc += Bundle.SearchFiltering_dateRangeFilter_and(); + } + desc += Bundle.SearchFiltering_dateRangeFilter_before(new SimpleDateFormat("yyyy/MM/dd", Locale.getDefault()).format(new Date(TimeUnit.SECONDS.toMillis(endDate)))); + } + return desc; } } @@ -204,9 +224,20 @@ public class SearchFiltering { return "artifact_type_id IN (" + joiner + ")"; } + @NbBundle.Messages({"# {0} - artifactTypes", + "SearchFiltering.artifactTypeFilter.desc=Result type(s): {0}", + "SearchFiltering.artifactTypeFilter.or=, "}) @Override public String getDesc() { - return "ArtifactTypeFilter Stub"; + String desc = ""; // NON-NLS + for (ARTIFACT_TYPE type : types) { + if (!desc.isEmpty()) { + desc += Bundle.SearchFiltering_artifactTypeFilter_or(); + } + desc += type.getDisplayName(); + } + desc = Bundle.SearchFiltering_artifactTypeFilter_desc(desc); + return desc; } } From c74cff253580e7f2cf295c14ecfb714883e5aa52 Mon Sep 17 00:00:00 2001 From: William Schaefer Date: Mon, 21 Sep 2020 10:07:01 -0400 Subject: [PATCH 4/6] 6870 simplify comparisons --- .../sleuthkit/autopsy/discovery/search/SearchFiltering.java | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/Core/src/org/sleuthkit/autopsy/discovery/search/SearchFiltering.java b/Core/src/org/sleuthkit/autopsy/discovery/search/SearchFiltering.java index 47731c6be0..975ffa6edd 100644 --- a/Core/src/org/sleuthkit/autopsy/discovery/search/SearchFiltering.java +++ b/Core/src/org/sleuthkit/autopsy/discovery/search/SearchFiltering.java @@ -184,10 +184,10 @@ public class SearchFiltering { @Override public String getDesc() { String desc = ""; // NON-NLS - if (!(startDate <= 0 )) { + if (startDate > 0 ) { desc += Bundle.SearchFiltering_dateRangeFilter_after(new SimpleDateFormat("yyyy/MM/dd", Locale.getDefault()).format(new Date(TimeUnit.SECONDS.toMillis(startDate)))); } - if (!(endDate > 10000000000L)) { //arbitrary time sometime in the 23rd century to check that they specified a date and the max date isn't being used + if (endDate < 10000000000L) { //arbitrary time sometime in the 23rd century to check that they specified a date and the max date isn't being used if (!desc.isEmpty()) { desc += Bundle.SearchFiltering_dateRangeFilter_and(); } From f129409c0f97b7a481c3025360d2e96e1476e76e Mon Sep 17 00:00:00 2001 From: William Schaefer Date: Mon, 21 Sep 2020 10:21:12 -0400 Subject: [PATCH 5/6] 6870 add initial label --- .../sleuthkit/autopsy/discovery/search/SearchFiltering.java | 3 +++ 1 file changed, 3 insertions(+) diff --git a/Core/src/org/sleuthkit/autopsy/discovery/search/SearchFiltering.java b/Core/src/org/sleuthkit/autopsy/discovery/search/SearchFiltering.java index 975ffa6edd..c88726c998 100644 --- a/Core/src/org/sleuthkit/autopsy/discovery/search/SearchFiltering.java +++ b/Core/src/org/sleuthkit/autopsy/discovery/search/SearchFiltering.java @@ -193,6 +193,9 @@ public class SearchFiltering { } desc += Bundle.SearchFiltering_dateRangeFilter_before(new SimpleDateFormat("yyyy/MM/dd", Locale.getDefault()).format(new Date(TimeUnit.SECONDS.toMillis(endDate)))); } + if (!desc.isEmpty()){ + desc = Bundle.SearchFiltering_dateRangeFilter_lable()+desc; + } return desc; } } From 85e13e742c178b0bd29b61c8177838326812d2d8 Mon Sep 17 00:00:00 2001 From: William Schaefer Date: Mon, 21 Sep 2020 11:51:51 -0400 Subject: [PATCH 6/6] 6870 fix empty filter Domain search description --- .../discovery/ui/Bundle.properties-MERGED | 2 ++ .../discovery/ui/DiscoveryTopComponent.java | 20 ++++++++++++++++--- 2 files changed, 19 insertions(+), 3 deletions(-) diff --git a/Core/src/org/sleuthkit/autopsy/discovery/ui/Bundle.properties-MERGED b/Core/src/org/sleuthkit/autopsy/discovery/ui/Bundle.properties-MERGED index 814d78da16..ae35449d15 100644 --- a/Core/src/org/sleuthkit/autopsy/discovery/ui/Bundle.properties-MERGED +++ b/Core/src/org/sleuthkit/autopsy/discovery/ui/Bundle.properties-MERGED @@ -12,7 +12,9 @@ DateFilterPanel.dateRange.text=Date Range ({0}): DateFilterPanel.invalidRange.text=Range or Only Last must be selected DateFilterPanel.startOrEndNeeded.text=A start or end date must be specified to use the range filter DiscoveryDialog.name.text=Discovery +DiscoveryTopComponent.additionalFilters.text=; DiscoveryTopComponent.cancelButton.text=Cancel Search +DiscoveryTopComponent.domainSearch.text=Type: Domain DiscoveryTopComponent.name=\ Discovery DiscoveryTopComponent.newSearch.text=New Search DiscoveryTopComponent.searchCancelled.text=Search has been cancelled. diff --git a/Core/src/org/sleuthkit/autopsy/discovery/ui/DiscoveryTopComponent.java b/Core/src/org/sleuthkit/autopsy/discovery/ui/DiscoveryTopComponent.java index ff3e0cb7cd..07465afcfd 100644 --- a/Core/src/org/sleuthkit/autopsy/discovery/ui/DiscoveryTopComponent.java +++ b/Core/src/org/sleuthkit/autopsy/discovery/ui/DiscoveryTopComponent.java @@ -38,6 +38,7 @@ import org.openide.windows.TopComponent; import org.openide.windows.WindowManager; import org.sleuthkit.autopsy.coreutils.ThreadConfined; import org.sleuthkit.autopsy.discovery.search.DiscoveryEventUtils; +import org.sleuthkit.autopsy.discovery.search.SearchData.Type; import static org.sleuthkit.autopsy.discovery.search.SearchData.Type.DOMAIN; /** @@ -56,6 +57,7 @@ public final class DiscoveryTopComponent extends TopComponent { private final GroupListPanel groupListPanel; private final DetailsPanel detailsPanel; private final ResultsPanel resultsPanel; + private Type searchType; private int dividerLocation = -1; private SwingAnimator animator = null; @@ -288,7 +290,8 @@ public final class DiscoveryTopComponent extends TopComponent { void handleSearchStartedEvent(DiscoveryEventUtils.SearchStartedEvent searchStartedEvent) { newSearchButton.setText(Bundle.DiscoveryTopComponent_cancelButton_text()); progressMessageTextArea.setForeground(Color.red); - progressMessageTextArea.setText(Bundle.DiscoveryTopComponent_searchInProgress_text(searchStartedEvent.getType().name())); + searchType = searchStartedEvent.getType(); + progressMessageTextArea.setText(Bundle.DiscoveryTopComponent_searchInProgress_text(searchType.name())); rightSplitPane.getComponent(1).setVisible(searchStartedEvent.getType() != DOMAIN); rightSplitPane.getComponent(2).setVisible(searchStartedEvent.getType() != DOMAIN); } @@ -302,11 +305,22 @@ public final class DiscoveryTopComponent extends TopComponent { @Subscribe @Messages({"DiscoveryTopComponent.newSearch.text=New Search", "# {0} - search", - "DiscoveryTopComponent.searchComplete.text=Results with {0}"}) + "DiscoveryTopComponent.searchComplete.text=Results with {0}", + "DiscoveryTopComponent.domainSearch.text=Type: Domain", + "DiscoveryTopComponent.additionalFilters.text=; "}) void handleSearchCompleteEvent(DiscoveryEventUtils.SearchCompleteEvent searchCompleteEvent) { newSearchButton.setText(Bundle.DiscoveryTopComponent_newSearch_text()); progressMessageTextArea.setForeground(Color.black); - progressMessageTextArea.setText(Bundle.DiscoveryTopComponent_searchComplete_text(searchCompleteEvent.getFilters().stream().map(AbstractFilter::getDesc).collect(Collectors.joining("; ")))); + String descriptionText = ""; + if (searchType == DOMAIN) { + //domain does not have a file type filter to add the type information so it is manually added + descriptionText = Bundle.DiscoveryTopComponent_domainSearch_text(); + if (!searchCompleteEvent.getFilters().isEmpty()) { + descriptionText += Bundle.DiscoveryTopComponent_additionalFilters_text(); + } + } + descriptionText += searchCompleteEvent.getFilters().stream().map(AbstractFilter::getDesc).collect(Collectors.joining("; ")); + progressMessageTextArea.setText(Bundle.DiscoveryTopComponent_searchComplete_text(descriptionText)); progressMessageTextArea.setCaretPosition(0); }