|
Type |
Item |
|---|---|
|
Host |
Endpoint name: Specify an endpoint name FQDN: Specify a Fully Qualified Domain Name accessed by an endpoint. Examples:
IP address: Specify an IPv4 address accessed by an endpoint. Example:
|
|
User account |
Specify the name of the Active Directory account or local user. Examples:
Note:
Use the local user account name only (<user name>). Do not include the domain name. |
|
File name |
Specify the full file name and file extension. Example:
|
|
File path |
Specify the full path. Example:
Note:
Do not include the file name. |
|
Hash value |
Specify the hash value of a file. Example:
Note:
Endpoint Sensor records SHA-1 values only by default. To use SHA-256 or MD5 hash values, update the agent policy to include additional hash types. |
|
Registry key |
Specify the full or partial registry key, name or data. Note:
|
|
Registry name |
|
|
Registry data |
|
|
Command line |
Specify the command line parameters, and press ENTER to add an entry. Note:
Using command line as investigation criteria has the following limitations:
|
Views:
