diff --git a/docs/doxygen-user/case_management.dox b/docs/doxygen-user/case_management.dox index d458238b67..141e909dfd 100755 --- a/docs/doxygen-user/case_management.dox +++ b/docs/doxygen-user/case_management.dox @@ -30,4 +30,18 @@ To open a case, either: Navigate to the case directory and select the ".aut" file. +\section case_properties Viewing Case Properties +You can view the case properties by going to the "Case" menu and clicking "Case Properties". This will open a screen similar to one of the two following screenshots: +

+\image html single-user-case-properties.PNG +

+\image html multi-user-case-properties.PNG +

+ +You can use the "Ingest History" tab to view which data sources had which modules run upon them, and when, as shown in the screenshot below. +

+\image html case-properties-history-tab.PNG +

+ + */ diff --git a/docs/doxygen-user/images/case-properties-history-tab.PNG b/docs/doxygen-user/images/case-properties-history-tab.PNG new file mode 100755 index 0000000000..9add4e8fb5 Binary files /dev/null and b/docs/doxygen-user/images/case-properties-history-tab.PNG differ diff --git a/docs/doxygen-user/images/ingest-already-run.PNG b/docs/doxygen-user/images/ingest-already-run.PNG new file mode 100755 index 0000000000..e3243711fe Binary files /dev/null and b/docs/doxygen-user/images/ingest-already-run.PNG differ diff --git a/docs/doxygen-user/images/ingest-history.PNG b/docs/doxygen-user/images/ingest-history.PNG new file mode 100755 index 0000000000..085475a6d4 Binary files /dev/null and b/docs/doxygen-user/images/ingest-history.PNG differ diff --git a/docs/doxygen-user/images/multi-user-case-properties.PNG b/docs/doxygen-user/images/multi-user-case-properties.PNG new file mode 100755 index 0000000000..1bd87ba21f Binary files /dev/null and b/docs/doxygen-user/images/multi-user-case-properties.PNG differ diff --git a/docs/doxygen-user/images/previous-version-already-run.PNG b/docs/doxygen-user/images/previous-version-already-run.PNG new file mode 100755 index 0000000000..d2223795cd Binary files /dev/null and b/docs/doxygen-user/images/previous-version-already-run.PNG differ diff --git a/docs/doxygen-user/images/single-user-case-properties.PNG b/docs/doxygen-user/images/single-user-case-properties.PNG new file mode 100755 index 0000000000..181cf65b87 Binary files /dev/null and b/docs/doxygen-user/images/single-user-case-properties.PNG differ diff --git a/docs/doxygen-user/ingest.dox b/docs/doxygen-user/ingest.dox index b2c9d02bf0..7ab8212f85 100644 --- a/docs/doxygen-user/ingest.dox +++ b/docs/doxygen-user/ingest.dox @@ -39,10 +39,25 @@ There may also be an "Advanced" button that is enabled in the lower corner. Pre As an example, the hash lookup module will allow you to enable or disable hash databases in the "run time" options panel, but requires you to go to the "Advanced" dialog to add or remove hash databases from the Autopsy configuration. +

+\section ingest_already_run Notification of Ingest Already Run +If an ingest module has already been run for a particular data source, you will see a triangular yellow icon with an exclaimation point next to the module in the "Run Ingest Modules" dialog, as shown in the screenshot below. +

+\image html ingest-already-run.PNG +

+If an older version of an ingest module has been run for a particular data source, you will see a round blue icon with an "i" next to the module in the "Run Ingest Modules" dialog, as shown in the screenshot below. +

+\image html previous-version-already-run.PNG +

+ +Clicking "View Ingest History" will show you the ingest history in tabular form, allowing you to see which modules were run on which data sources and when, as shown in the screenshot below. +

+\image html ingest-history.PNG +

\section ingest_results Viewing Ingest Module Results -Ingest modules run in the background. An ingest module can provide you results in a variety of ways, but we recommend specific methods: +Ingest modules run in the background. An ingest module can provide you results in a variety of ways, but we recommend specific methods: -# If they post results to the Blackboard, then you will find them in the "Results" area of the tree in the main interface. -# They can send a message to the Ingest Inbox so that you get a message each time something really important is found.