+| Operation | Command(s) | Parameter(s) | Example |
+| Create New Case | --createCase | --caseName
+--caseBaseDir | --createCase --caseName="test5" --caseBaseDir="C:\work\cases" |
+
+| Open Existing Case | | --caseDir | --caseDir="C:\work\Cases\test5_2019_09_20_11_01_29" |
+
+| Add a Data Source | --addDataSource
+--runIngest (optional) | --dataSourcePath | --addDataSource --dataSourcePath="R:\work\images\small2.img" --runIngest |
+
+| Run Ingest on Existing Data Source | --runIngest | --dataSourceObjectId | --runIngest --dataSourceObjectId=1 |
+
+| Generate Reports | --generateReports | | --generateReports |
+
+| Create List of Data Sources | --listAllDataSources | | | --listAllDataSources
+
+
+
+More details on each operation along with additional examples are given below.
+
+\subsection command_line_cases Creating and Opening Cases
+
+You will always need to either create a case or give the path to an existing case. When creating a case, the current timestamp will be added to the case name. For example, running this command:
\verbatim
-autopsy64.exe --inputPath=(data source path) --caseName=(case name) --runFromCommandLine=true
+autopsy64.exe --createCase --caseName="test5" --caseBaseDir="C:\work\cases"
\endverbatim
-In the example below, we're going to process a disk image with path "R:\work\images\xp-sp3-v4.E01" and name the case "xpCase".
+could create a case folder "test5_2019_09_20_11_01_29". Note that even though a timestamp is added to the name, the --caseName field must be unique for each run.
+
+\image html command_line_ingest_case_folder.png
+
+Once a case is created you will need to use the full path to the case instead of the case name and base folder. For example, if we created the empty case "test5" as above, we could use the following command to add a data source to it:
+
+\verbatim
+autopsy64.exe --caseDir="C:\work\Cases\test5_2019_09_20_11_01_29" --addDataSource
+ --dataSourcePath="R:\work\images\small2.img"
+\endverbatim
+
+\subsection command_line_ds Adding a New Data Source and Running Ingest
+
+You can add a data source to a new case or an existing case using the --addDataSource option and then giving the path to the data source. If you use the --runIngest option, the ingest modules you selected in the \ref command_line_ingest_config "configuration step" will be run on the data source. Both \ref ds_img "disk images" and \ref ds_log "logical files" are supported. You can only add one data source at a time.
+
+In this example, we'll create a new case named "test6" and add the data source "blue_images.img".
+
+\verbatim
+autopsy64.exe --createCase --caseName="test6" --caseBaseDir="C:\work\cases" --addDataSource
+ --dataSourcePath="R:\work\images\blue_images.img"
+\endverbatim
+
+And here we'll add another data source ("green_images.img") to the case we just made and run ingest on it. Note that ingest will only run on the new data source ("green_images.img"), not the one already in the case ("blue_images.img").
+
+\verbatim
+autopsy64.exe --caseDir="C:\work\cases\test6_2019_09_20_13_00_51" --addDataSource --runIngest
+ --dataSourcePath="R:\work\images\green_images.img"
+\endverbatim
+
+Finally we'll add a folder ("Test files") as a logical file set to a new case ("test9").
+
+\verbatim
+autopsy64.exe --createCase --caseName="test9" --caseBaseDir="C:\work\Cases" --addDataSource
+ --dataSourcePath="R:\work\images\Test files" --runIngest
+\endverbatim
+
+\subsection command_line_existing_ds Running Ingest on an Existing Data Source
+
+You can run ingest on a data source already in the case if you know its object ID. To find this, go to the case folder and open the "Command Output" folder.
+
+\image html command_line_ingest_output_folder.png
+
+If you've run with the --listAllDataSources option, there will be at least one file starting "listAllDataSources". Open the most recent one - the format will be similar to this:
+
+\verbatim
+{
+ "@dataSourceName" : "blue_images.img",
+ "@dataSourceObjectId" : "1"
+} {
+ "@dataSourceName" : "green_images.img",
+ "@dataSourceObjectId" : "84"
+}
+\endverbatim
+
+You can also look through the addDataSource files to find the one corresponding to the file you want to ingest. The format will be the same. Once you know the data source object ID, you can use the --dataSourceObjectId option to specify it. For example, this will run ingest on "blue_images.img":
+
+\verbatim
+autopsy64.exe --caseDir="C:\work\cases\test6_2019_09_20_13_00_51" --runIngest --dataSourceObjectId=1
+\endverbatim
+
+\subsection command_line_report Generating Reports
+
+You can generate a report on the case using the --generateReports option. You can select which report type to export through the Autopsy options panel (see the \ref command_line_ingest_config "configuration section"). This option can be run alone or at the same time as you're processing a data source. In this example we're adding a new data source ("small2.img") and generating a report.
+
+\verbatim
+autopsy64.exe --caseDir="C:\work\cases\test6_2019_09_20_13_00_51" --addDataSource
+ --dataSourcePath="R:\work\images\small2.img" --runIngest --generateReports
+\endverbatim
+
+\subsection command_line_listds Listing All Data Sources
+
+You can add the --listAllDataSources at any time to output a list of all data sources currently in the case along with their object IDs, to be used when \ref command_line_existing_ds "running on an existing data source". This command can even be run alone with just the path to the case.
+
+\verbatim
+autopsy64.exe --caseDir="C:\work\cases\test6_2019_09_20_13_00_51" --listAllDataSources
+\endverbatim
+
+
+\section command_line_ingest_run Running Autopsy
+
+Once you determine which parameters you need, it's time to run Autopsy. In the example below we're creating a new case ("xpCase"), adding a data source to it ("xp-sp3-v4.001"), running ingest and generating a report. The report type was \ref command_line_ingest_config "configured" earlier to be an HTML report.
\image html command_line_ingest_command_entry.png
-You'll start seeing output in the command prompt and the Autopsy UI will open. In the middle of the UI you'll see the following dialog:
+If you've entered everything correctly, Autopsy will load and you'll see this dialog in the middle of the screen:
\image html command_line_ingest_dialog.png
-Once Autopsy finishes processing you'll be back at the command window. Press enter to return to the command prompt.
+If you instead see the normal case open dialog, it most likely means that your command line is malformed. Verify that there are no typos and that you have the appropriate parameters for the operation(s) you're attempting.
+
+If everything works correctly, you'll see a log of the processing being done and Autopsy will close when finished.
\image html command_line_ingest_console_output.png
+
\section command_line_ingest_results Viewing Results
You can open the case created on the command line like any other Autopsy case. Simply go to "Open Case" and then browse to the output folder you set up in the \ref command_line_ingest_config section and look for the folder starting with your case name. It will have a timestamp appended to the name you specified.
\image html command_line_ingest_open_case.png
-If you are only interested in the \ref report_case_uco report then you don't need to open Autopsy. The report can be found in the case folder under "Reports\CASE-UCO" and then an automatically generated data source name containing the ID and timestamp.
+If you are only interested in the reports then you don't need to open Autopsy. You can just browse to the "Reports" folder in the case and access the reports directly.
\image html command_line_ingest_report.png
diff --git a/docs/doxygen-user/communications.dox b/docs/doxygen-user/communications.dox
index 94b46e9d30..9efd0f02f1 100644
--- a/docs/doxygen-user/communications.dox
+++ b/docs/doxygen-user/communications.dox
@@ -14,7 +14,7 @@ The Communications Visualization Tool is loaded through the Tools->Communication
\image html cvt_main.png
-From the left hand column, you can choose which devices to display, which types of data to display, and optionally select a time range. You can also choose to limit the display to only the most recent communications. After any changes to the filters, use the Apply button to update the tables.
+From the left hand column, you can choose which devices to display, which types of data to display, and optionally select a time range. You can also choose to limit the display to only the most recent communications. After any changes to the filters, use the Apply button to update the tables. You can hide this column by clicking the left arrow at the top of the column.
The middle column displays each account, its device and type, and the number of associated messages (emails, call logs, etc.). By default it will be sorted in descending order of frequency. The middle column and the right hand column both have a \ref ui_quick_search feature which can be used to quickly find a visible item in their section's table.
@@ -25,7 +25,7 @@ Selecting an account in the middle column will bring up the data for that accoun
\image html cvt_summary_tab.png
-