Follow

Export and upload a case from Griffeye Analyze DI to Intelligence Server

Griffeye Analyze Digital Investigator (DI) and Intelligence Server can interoperate using VICS format data files. In order to export a case from Analyze DI and upload it to Intelligence Server, you have to turn on the VICS add-in in DI, then choose the appropriate options to export the case. From there, Intelligence Agent is configured and the file is uploaded.

Turn on the VICS add-in in Analyze DI

  1. In Analyze DI, click NetClean Forensic Market in the "Apps" section of the ribbon toolbar.
  2. Select VICS (OData), then choose Activate Free.
  3. Close the Forensic Market window.

Export the case in VICS format

  1. In your open case, choose Report/Export.
  2. In the VICS (Odata) Case Export section, choose Data, then choose the desired set of files (for example All Files).
  3. Select the export folder and categories and click Next
  4. Choose the desired options for the next two pages (the default settings should work).
  5. Click Start.

Configure Intelligence Server to process uploaded files

  1. In the Services MMC snap-in (Choose Start->Run and type services.msc), right click on Hubstream Intelligence Server Service and choose Properties.
  2. On the Log On tab, enter the credentials for a user that has write database owner access to the Intelligence Server database.
  3. Open Notepad.exe using Run As Administrator.
  4. Edit the file C:\Program Files\Hubstream\Intelligence Server\Processing Service\ProcessingService.exe.config
  5. Find the section HubstreamMediaEndPoint and change the URL to match your instance in the following pattern:
    http://{server}/{Instance}ServiceInterfaces/Media.svc
    {Server} is the hostname or domain name of your server
    {Instance} is the name of the Intelligence Server instance as specified in the System Configuration tool.
  6. Start the Hubstream Intelligence Server Service using the Services MMC Snap-In.

Configure Intelligence Agent to connect to Intelligence Server

  1. Open Intelligence Agent.
  2. Click the Settings button.
  3. On the Fabric tab, deselect Fabric.
  4. On the Server tab, select Server.
  5. Enter the Server URL in the following pattern:
    http://{server}/{Instance}ServiceInterfaces/Media.svc
    {Server} is the hostname or domain name of your server
    {Instance} is the name of the Intelligence Server instance as specified in the System Configuration tool.
  6. Choose to either use the current Windows user (if domain-joined to the same domain as the server, or if connecting from the server itself), or enter a username and password that matches a user with appropriate permissions in the Intelligence Server database.
  7. Click OK.

Upload the Exported JSON file

  1. In Intelligence Agent, choose Actions, then Upload.
  2. Navigate to the location of the created JSON file, select the file and click Open.
  3. The file should upload automatically.

Verify the Uploaded File

  1. Navigate to the web site corresponding to the configured instance. For instance, http://{server}/{instance} using the parameters shown above.
  2. Log in using the same user that uploaded the JSON file.
  3. Click on the Lists label in the top navigation bar.
  4. This shows the Investigations list by default. See that a new investigation as added that corresponds to your uploaded file. Click on the new investigation to see the investigation details, which should match the case information and file references created with Analyze DI.
Was this article helpful?
0 out of 0 found this helpful
Have more questions? Submit a request

Comments