In the Investigate dialog, analysts can select a service or a collection to investigate. The dialog is automatically displayed when you first go to the Navigate view or Legacy Events view and have not selected a default service to investigate. To access the dialog from a current investigation, select the current service name in the toolbar.
This workflow has references to several views that were renamed in Version 11.4: the Event Analysis view became Events view, the Events view became Legacy Events view.
What do you want to do?
|User Role||I want to ...||Show me how|
|Incident Responder|| |
review critical incidents or alerts
NetWitness Respond User Guide
|Threat Hunter||query a service, metadata, and time range*|
|Threat Hunter|| |
|Threat Hunter|| |
view raw event data
reconstruct the event
|Threat Hunter||examine files|
|Threat Hunter||perform lookups|
|Threat Hunter||create an incident or add to an incident|
add a meta value to a Context Hub list
*You can perform this task in the current view.
The Investigate dialog has two tabs: Services and Collections.
The Services tab includes a list of services available for investigation, and three buttons. All features are described in the following table.
|Default Service||Clicking this button sets or clears the default service to investigate. When a service has been set as the default service, the word (Default) is appended to the service name.|
|Name||The name of the service.|
|Address||The IP address of the service.|
|Type||The type of service.|
|Cancel||Closes the dialog.|
|Navigate||Opens the selected service in the Navigate or Legacy Events view.|
The Collections tab has two buttons and two panels: Workbench and Collections.
The Workbench panel lists available Workbench services by name. After a Workbench service is selected, you can select a collection from the Collections panel.
The Collections panel lists available collections to investigate. After a collection is selected, you can click Navigate to view the collection.
The following table describes the features of the Collections panel.
|Name||The name of the collection.|
|Type||The type of collection.|
|Size||The size of the collection.|
|Data Type||The type of data within the collection.|
|Date Created||The date the collection was created.|