In NetWitness Investigate, when the data for a drill point is displayed in the Navigate view, you can:
- Extract files from a session and choose the type of files to extract: archives, audio BitTorrent, documents, executable, images, other, video, and web.
- Export the drill point as a packet capture (PCAP) file, a log file, or a metadata file.
- Print the drill point.
The details being exported are affected by both the time range and drill point at the time of exporting.
To export a drill point from the Navigate view:
- Conduct an investigation until you reach the desired drill point.
- For Version 11.0, In the toolbar, select Actions > Export and select one of the export options: PCAP, Logs, or Meta.
The drill point is extracted, and a message advises that the job is scheduled. You can check the jobs page for the status.
- For Version 11.1, in the toolbar, select Save Events > and select one of the export options: PCAP, Logs, Files, or Meta.
A dialog gives you an opportunity to edit the default filename for the file. The default filename is in the form investigation-Feb-21-15-44-33. When you are exporting a PCAP, the file is exported with no choice of formats. If you are using one of the other export options, a dialog is displayed.
- In the dialog, select:
- The export log format: Text, XML, CSV, or JSON.
- The file types to export: Archives, Audio, BitTorrent, Documents, Executables, Images, Other, Video, and Web.
- The Meta format: Text, CSV, TSV, JSON.
- When the scheduled file extraction is complete, it is displayed in the Job Notifications tray.
- Click the View link in the Jobs tray and download the specific extraction file requested.
To print the current drill point:
In the Navigate view, you can display the contents of the current drill point in printer friendly format in the browser window.
To display the current drill point in a print view: