Triage status

You can drill down to the Actions table from the status link of the triage to view the search the status of all the artifacts for the triage.

FieldDescription
Endpoint nameAgent hostname.
Endpoint IDAgent unique ID.
Action IDUnique identifier for this agent action.
Type

Type of collection.

Example: Amcache, File Collection, Event Logs

PathPath for files, registry path for registry artifacts.
Status

Displays one of the following statuses of the search:

  • Pending: agent action sent
  • In progress: SAM not sent
  • Results received: received SAM results
  • Timeout: SAM timed out
  • Ingesting: Ingestion started
  • Uploaded: data received, but not parsed
  • Ingested: ingestion completed
  • Partially ingested: ingested with errors
  • Failed: ingestion failed
Details

Shows the detailed output from the ingestion script.

Example: Ingested X of Y records

CollectedTime the data was collected.
Download expirationTime when bucket data (raw files) is to be deleted.
PresetName of the triage configuration.
Collection TypeCollection type.
Triage IDUnique ID associated with this triage data.