You are here: Funzioni dell'Analista > Analisi delle evidence > Cose da sapere sulle evidence

What you should know about evidence

Analysis process

The analysis process is described below:

Phase Description
1

As the system collects evidence from the agent, it displays and updates the total counter.

2

The Analyst views all evidence and tags it for easy table consultation and subsequent export.

3

The Analyst analyzes incoming evidence details.

4

At the end of the investigation or upon request, the Analyst exports evidence to a file that can be viewed in a browser.

Evidence accumulated in the device.

Evidence is sent by the agent to the Collector in order of creation. If a device rarely synchronizes or has a limited bandwidth, evidence probably accumulates on the device and it will take a long time before the most recent data is received.

The same may happen if large-sized evidence is in queue: the most recent evidence can only be sent after having sent this evidence.

For this reason, we suggest you delete older evidence and/or evidence that exceeds a certain size. Evidence is deleted at the next synchronization.

See "Agent page".

Filtering evidence

Column heading filters can be used to limit the amount of evidence viewed.

See "Shared interface elements and actions"

IMPORTANT: if no evidence is displayed, check the counter at the bottom right. If a value like "0/1270" is displayed, this means that there is a filter set that prevents evidence from being displayed.

The selected filters can be saved with a short description to be used later.

IMPORTANT: if private filters are set, they cannot be used by other users.

Translating evidence

The RCS Translate module is available upon special license to translate evidence. In fact, it communicates with a third party translation software that returns text translated into the interface language.

RCS Translate translates the following types of evidence:

The translation is displayed in the page with the evidence list and the single piece of evidence detail page.

Delete evidence

This function deletes one or more pieces of evidence no longer deemed useful. This function depends on the type of license installed.

Filters can be used to select the evidence to be deleted (similar to selecting evidence to be exported).

IMPORTANT: the filter only appears when the Delete and Alt keys are pressed simultaneously.

.tgz file description with exported evidence

The exported .tgz file is a compressed file that can be opened with most compression programs (i.e.: WinZip, WinRar). Once unzipped, it looks like a folder with an HTML file.

To view the file:

Step Action
1

Open index.html with a browser: the homepage displays the list of days with collected evidence statistics per hour.

2

Click on a day: the list of evidence appears, similar to the one displayed in the Evidence function.

3

The following actions can be performed from this list:

  • on images: click to view the full image
  • on audio: click to run the mini player
  • on downloadable files: click to download the file

Tip: there are style sheets in the Style folder for customizations (i.e.: logos, etc.). These style sheets can be copied to the server to be used on all reports generated by the RCS Console.

RCS9.4 | User's Guide | © COPYRIGHT 2014