Manage evidence

Overview

During your investigation, you can save relevant fragments from logs and IP addresses as evidence for later use in the Evidence collection section.

Example of how to use evidence: You can create filters for your query. For details, see Filter by evidence.

evidence collection section

Add evidence

There are two ways to add evidence: manually, from the Evidence collection section, or from the query results table.

In the evidence collection

  1. In the Evidence collection section, select next to the evidence list where you want to add your evidence.
  2. Select Add.

add evidence from the evidence collection section

Different evidence items are distinguished by a line break: every piece of evidence is on a separate line.

In the query results

  1. In the query results table, right-click on a field.
  2. In the Add to evidence list section, select where you want to add the evidence.

add evidence from the query results table

You can also add multiple items at once to the evidence list or create a new list from the selection.

Strings (partial or full value of fields) can go in the IoC preset string list or in custom string lists created by you.

IPs can go in preset IP lists (Suspicious, Safe) or in custom IP lists created by you.

There is no limitation on the number of lists you can create or of items (strings or IPs) you can add to a list in your evidence collection.

Besides IPv4 addresses, you can also add as evidence IPv6 addresses or subnet masks. Filtering by evidence containing a subnet mask displays all IPs within that subnet, which simplifies your queries.

Create custom lists

You can create custom evidence lists from the query results table.

  1. Right-click on a field.
  2. In the Add to evidence list section, select New list.

add new evidence list

Delete evidence

You can delete items in your evidence list individually or in bulk.

  1. In the Evidence collection section, select next to the evidence list where you want to delete evidence.

  2. Select Manage.

  3. Select the items you want to delete.

  4. Select Delete.

delete IPs

Rename and delete lists

In Evidence collection you can

  • Rename preset and custom evidence lists

    1. Select next to the evidence list that you want to rename.
    2. Select Rename.
  • Delete custom lists

    1. Select next to the evidence list that you want to delete.
    2. Select Delete.