Metadata tags
Common entities are tagged to allow investigators to quickly retrieve exact result sets from relevant documents.
Many metadata fields might be used in the Incident Forensic index, depending on the type of session, document, or protocol.
When you specify a metadata tag name, it must be exact and exist in the forensic repository.
The following table lists types of metadata tag searches.
| Type of metadata tag search | Format | Example |
|---|---|---|
| Standard | MetadataTag:<value> | ApplicationProtocol:http |
| Wildcard | MetadataTag:* | CreditCardNumber:* |
| Range | MetadataTag:[<start value> TO <end value> | Duration:[30 TO 56] |