Create a new investigation
Create a forensic investigation, assign access, and start a data collection.
Create a forensic investigation to group data collections, alerts, and evidence for a single case.
Go to Investigation & Response → Forensics.
Select New Investigation.
Enter an investigation name and optional description.
In Permissions, select users who can access the investigation data.
Select Save to create the investigation.
Select Save & Start a Collection to add data immediately.
Configure the time zone and timestamp format from UTC Timezone, if needed. See Configure server settings.
Last updated
Was this helpful?
