In NetWitness Investigate, when you have the data for a drill point displayed in the Navigate view, you can:
- Extract files from a session and choose the type of files to extract: archives, audio BitTorrent, documents, executable, images, other, video, and web.
- Export the drillpoint as a packet capture (PCAP) file, a log file or a meta data file.
- Print the drillpoint.
The details being exported are affected by both the time range and drill point at the time of exporting.
To export a drill point from the Navigate view:
- Conduct an investigation until you reach the desired drillpoint.
- For Version 11.0, In the toolbar, select Actions > Export and select one of the export options: PCAP, Logs, or Meta.
The drill point is extracted, and a message advises that the job is scheduled. You can check the jobs page for the status.
- For Version 11.1, in the toolbar, select Save Events > and selecto one of the export options: PCAP, Logs, Files, Meta.
A dialog gives you an opportunity to edit the default filename for the file. The default is in the form investigation-Feb-21-15-44-33
- A dialog allows you to select the export log format: Text, XML, CSV, JSON. A dialog selects file types. A dilaog selecte Meta format: Text, CSV, TSV, JSON.
- When the scheduled file extraction is complete, it is displayed in the Job Notifications tray.
- Click the View link in the Jobs tray sand download the specific extraction file requested.
To print the current drill point:
In the Navigate view, you can display the contents of the current drill point in printer friendly format in the browser window.
To display the current drill point in a print view: