diff --git a/Core/src/org/sleuthkit/autopsy/timeline/ui/detailview/datamodel/DetailsViewModel.java b/Core/src/org/sleuthkit/autopsy/timeline/ui/detailview/datamodel/DetailsViewModel.java index b1d1ebb92a..91e2b66520 100644 --- a/Core/src/org/sleuthkit/autopsy/timeline/ui/detailview/datamodel/DetailsViewModel.java +++ b/Core/src/org/sleuthkit/autopsy/timeline/ui/detailview/datamodel/DetailsViewModel.java @@ -161,9 +161,9 @@ final public class DetailsViewModel { final boolean needsHashSets = filterState.hasActiveHashFilters(); TimelineDBUtils dbUtils = new TimelineDBUtils(sleuthkitCase); String querySql = "SELECT " + formatTimeFunctionHelper(rangeInfo.getPeriodSize().toChronoUnit(), timeZone) + " AS interval, " // NON-NLS - + dbUtils.csvAggFunction("events.event_id") + " as event_ids, " //NON-NLS - + dbUtils.csvAggFunction("CASE WHEN hash_hit = 1 THEN events.event_id ELSE NULL END") + " as hash_hits, " //NON-NLS - + dbUtils.csvAggFunction("CASE WHEN tagged = 1 THEN events.event_id ELSE NULL END") + " as taggeds, " //NON-NLS + + dbUtils.csvAggFunction("tsk_events.event_id") + " as event_ids, " //NON-NLS + + dbUtils.csvAggFunction("CASE WHEN hash_hit = 1 THEN tsk_events.event_id ELSE NULL END") + " as hash_hits, " //NON-NLS + + dbUtils.csvAggFunction("CASE WHEN tagged = 1 THEN tsk_events.event_id ELSE NULL END") + " as taggeds, " //NON-NLS + " min(time) AS minTime, max(time) AS maxTime, " + typeColumn + ", " + descriptionColumn // NON-NLS + " FROM " + TimelineManager.getAugmentedEventsTablesSQL(needsTags, needsHashSets) // NON-NLS + " WHERE time >= " + start + " AND time < " + end + " AND " + eventManager.getSQLWhere(filterState.getActiveFilter()) // NON-NLS diff --git a/Core/src/org/sleuthkit/autopsy/timeline/ui/listvew/datamodel/ListViewModel.java b/Core/src/org/sleuthkit/autopsy/timeline/ui/listvew/datamodel/ListViewModel.java index 388da66664..203db0994c 100644 --- a/Core/src/org/sleuthkit/autopsy/timeline/ui/listvew/datamodel/ListViewModel.java +++ b/Core/src/org/sleuthkit/autopsy/timeline/ui/listvew/datamodel/ListViewModel.java @@ -88,12 +88,12 @@ public class ListViewModel { final boolean needsTags = filterState.hasActiveTagsFilters(); final boolean needsHashSets = filterState.hasActiveHashFilters(); TimelineDBUtils dbUtils = new TimelineDBUtils(sleuthkitCase); - final String querySql = "SELECT full_description, time, file_id, " - + dbUtils.csvAggFunction("CAST(events.event_id AS VARCHAR)") + " AS eventIDs, " + final String querySql = "SELECT full_description, time, file_obj_id, " + + dbUtils.csvAggFunction("CAST(tsk_events.event_id AS VARCHAR)") + " AS eventIDs, " + dbUtils.csvAggFunction("CAST(sub_type AS VARCHAR)") + " AS eventTypes" + " FROM " + TimelineManager.getAugmentedEventsTablesSQL(needsTags, needsHashSets) + " WHERE time >= " + startTime + " AND time <" + endTime + " AND " + eventManager.getSQLWhere(filterState.getActiveFilter()) - + " GROUP BY time, full_description, file_id ORDER BY time ASC, full_description"; + + " GROUP BY time, full_description, file_obj_id ORDER BY time ASC, full_description"; try (SleuthkitCase.CaseDbQuery dbQuery = sleuthkitCase.executeQuery(querySql); ResultSet resultSet = dbQuery.getResultSet();) { @@ -108,7 +108,7 @@ public class ListViewModel { for (int i = 0; i < eventIDs.size(); i++) { eventMap.put(eventTypes.get(i), eventIDs.get(i)); } - combinedEvents.add(new CombinedEvent(resultSet.getLong("time") * 1000, resultSet.getString("full_description"), resultSet.getLong("file_id"), eventMap)); + combinedEvents.add(new CombinedEvent(resultSet.getLong("time") * 1000, resultSet.getString("full_description"), resultSet.getLong("file_obj_id"), eventMap)); } } catch (SQLException sqlEx) {