Viewing comments inline / showing comments column, and exporting this, possible in new UI? (High level timeline) #3273
Unanswered
J-A-Sec
asked this question in
Q&A, quick solutions, support
Replies: 0 comments
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
Hi,
Is it possible to view comments inline with events in the new UI, similar to how the old UI worked?
Our workflow is something like this:
Star events of interest > review starred events > distil the full timeline to a "high level" timeline of key events in simple, human readable events - the most notable touchpoints in a given investigation.
Unfortunately, this last step happens manually in Excel. It would be fantastic if we could do all this within Timesketch, so for example we could comment on events, then show comments in a column and save this view as the high level timeline. This could later feed into a "graphical timeline view" of the investigation, similar to the graphs that The DFIR Report/DFIR-IRIS produce (another feature idea :) )
I've tried to show both the comment and comments columns, but they only show the comments icon. Switching to the old UI allows me to see the raw comments inline/as a column, but when trying to export, only "__tag_comment" is exported, not the comment itself. I've had to revert to using Tags as comments, since these show inline of the event and can be exported - but of course you end up with hundreds of tags!
I appreciate that Stories cover some of this functionality, but taking the time to save an appropriate search and describe events on a separate page can take an analyst out of the "flow".
If there's a way to export a sketch which includes comments as a column, that would be great also.
Thanks!
Beta Was this translation helpful? Give feedback.
All reactions