Create a Computer Investigation

Applies To: WatchGuard Advanced EPDR

You can create a computer investigation for a computer on a specific day and then review the details of the monitored and collected events that occurred.

To create a computer investigation, in the Endpoint Security management UI:

  1. To open computer details, select Computers, then select a computer.
    The computer investigation for the selected computer opens.
  2. To create a computer investigation for another computer, on the Investigation page, click .
  3. Screenshot of Computer Investigation menu option

  4. Select Computer Investigation.
    The Investigate Computer page opens.
  5. Screenshot of Investigate Computer page

  6. Select the MUID or Computer Name check box and enter the unique identifier or Windows computer name in the text box.
  7. In the From text boxes, select the start date and time for the investigation.
  8. In the To text boxes, select the end date and time for the investigation.
  9. The date range cannot be greater than two days. You can select a date up to seven days prior.

  10. From the Time Zone drop-down list, select the time zone.
  11. Click OK.
    A computer investigation is created.

In a computer investigation, you can:

Related Topics

About the Advanced SQL Query Tool

Configure Verbose Mode