Metadata tags

Common entities are tagged to allow investigators to quickly retrieve exact result sets from relevant documents.

Many metadata fields might be used in the Incident Forensic index, depending on the type of session, document, or protocol.

When you specify a metadata tag name, it must be exact and exist in the forensic repository.

The following table lists types of metadata tag searches.

Table 1. Metadata tag searches
Type of metadata tag search Format Example
Standard MetadataTag:<value> ApplicationProtocol:http
Wildcard MetadataTag:* CreditCardNumber:*
Range MetadataTag:[<start value> TO <end value> Duration:[30 TO 56]