Add ingest history

This commit is contained in:
Karl Mortensen
2016-06-29 12:48:04 -04:00
parent 2e4f93cb22
commit fb63a121ef
8 changed files with 30 additions and 1 deletions
+14
View File
@@ -30,4 +30,18 @@ To open a case, either:
Navigate to the case directory and select the ".aut" file.
\section case_properties Viewing Case Properties
You can view the case properties by going to the "Case" menu and clicking "Case Properties". This will open a screen similar to one of the two following screenshots:
<br><br>
\image html single-user-case-properties.PNG
<br><br>
\image html multi-user-case-properties.PNG
<br><br>
You can use the "Ingest History" tab to view which data sources had which modules run upon them, and when, as shown in the screenshot below.
<br><br>
\image html case-properties-history-tab.PNG
<br><br>
*/
Binary file not shown.

After

Width:  |  Height:  |  Size: 32 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 27 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 27 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 20 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 40 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 22 KiB

+16 -1
View File
@@ -39,10 +39,25 @@ There may also be an "Advanced" button that is enabled in the lower corner. Pre
As an example, the hash lookup module will allow you to enable or disable hash databases in the "run time" options panel, but requires you to go to the "Advanced" dialog to add or remove hash databases from the Autopsy configuration.
<br><br>
\section ingest_already_run Notification of Ingest Already Run
If an ingest module has already been run for a particular data source, you will see a triangular yellow icon with an exclaimation point next to the module in the "Run Ingest Modules" dialog, as shown in the screenshot below.
<br><br>
\image html ingest-already-run.PNG
<br><br>
If an older version of an ingest module has been run for a particular data source, you will see a round blue icon with an "i" next to the module in the "Run Ingest Modules" dialog, as shown in the screenshot below.
<br><br>
\image html previous-version-already-run.PNG
<br><br>
Clicking "View Ingest History" will show you the ingest history in tabular form, allowing you to see which modules were run on which data sources and when, as shown in the screenshot below.
<br><br>
\image html ingest-history.PNG
<br><br>
\section ingest_results Viewing Ingest Module Results
Ingest modules run in the background. An ingest module can provide you results in a variety of ways, but we recommend specific methods:
Ingest modules run in the background. An ingest module can provide you results in a variety of ways, but we recommend specific methods:
-# If they post results to the Blackboard, then you will find them in the "Results" area of the tree in the main interface.
-# They can send a message to the Ingest Inbox so that you get a message each time something really important is found.