The analysis process is described below:
Phase | Description |
---|---|
1 |
As the system collects evidence from the agent, it displays and updates the total counter. |
2 |
The Analyst views all evidence and tags it for easy table consultation and subsequent export. |
3 |
The Analyst analyzes incoming evidence details. |
4 |
At the end of the investigation or upon request, the Analyst exports evidence to a file that can be viewed in a browser. |
Evidence is sent by the agent to the Collector in order of creation. If a device rarely synchronizes or has a limited bandwidth, evidence probably accumulates on the device and it will take a long time before the most recent data is received.
The same may happen if large-sized evidence is in queue: the most recent evidence can only be sent after having sent this evidence.
For this reason, we suggest you delete older evidence and/or evidence that exceeds a certain size. Evidence is deleted at the next synchronization.
Column heading filters can be used to limit the amount of evidence viewed.
See "Shared interface elements and actions"
IMPORTANT: if no evidence is displayed, check the counter at the bottom right. If a value like "0/1270" is displayed, this means that there is a filter set that prevents evidence from being displayed.
The selected filters can be saved with a short description to be used later.
IMPORTANT: if private filters are set, they cannot be used by other users.
The RCS Translate module is available upon special license to translate evidence. In fact, it communicates with a third party translation software that returns text translated into the interface language.
RCS Translate translates the following types of evidence:
The translation is displayed in the page with the evidence list and the single piece of evidence detail page.
This function deletes one or more pieces of evidence no longer deemed useful. This function depends on the type of license installed.
Filters can be used to select the evidence to be deleted (similar to selecting evidence to be exported).
IMPORTANT: the filter only appears when the Delete and Alt keys are pressed simultaneously.
The exported .tgz file is a compressed file that can be opened with most compression programs (i.e.: WinZip, WinRar). Once unzipped, it looks like a folder with an HTML file.
To view the file:
Step | Action |
---|---|
1 |
Open index.html with a browser: the homepage displays the list of days with collected evidence statistics per hour. |
2 |
Click on a day: the list of evidence appears, similar to the one displayed in the Evidence function. |
3 |
The following actions can be performed from this list:
|
Tip: there are style sheets in the Style folder for customizations (i.e.: logos, etc.). These style sheets can be copied to the server to be used on all reports generated by the RCS Console.
RCS9.3 | User's and Installation Guide | © COPYRIGHT 2013