Configuring Timestamp Settings for Triage Acquisition
Configure and verify the timestamp settings before the installation procedure.
Avant de commencer
Role required: NowPlatform Security incident administrator (sn_si.admin)
Before installing the FireEye application, there are some pre-requisites that need to be performed on FireEye.
Triage Acquisition can be requested with an input of 'Around Timestamp' field or 'Standard' field. Around timestamp requests information collected during a specified amount of time before the timestamp until a specified amount of time after the timestamp. The timestamp is the time the event that generated the alert occurred. If you select Standard, the Endpoint Security appliance requests information from the host for all data around an event.
When an Endpoint Security user requests a triage collection based on a specific date and time the agent returns information for a specified window of time before and after the alert. The timestamp settings control the length of the window for the triage collection. Timestamp settings apply only to agent URL events (URL Monitor Events) and registry key events (Reg Key Events).
You can use the Timestamp Settings tab to specify the length of time before and after the timestamp during which information is collected. Timestamp Settings can range from 0- 86400 seconds. The default for both settings is 600 seconds.
You can use the Timestamp Settings tab on the Automatic Triage Settings page to specify the length of time before and after the timestamp during which information is collected. The timestamp is the time when the event that triggered the alert occurred.