Filter data in Hash view
Hash view enables you to search and investigate files based on their hash value.
Open Hash view
You can open Hash view the following ways:
- Search for the file hash directly
- Pivot to Hash view when viewing a process- or file-based event in Asset view
Search for the file hash directly
To open Hash view directly:
Enter the hash value in the Chronicle search field. Click SEARCH.
Search for hash from the landing page
Select the hash value from the HASHES drop-down menu.
Chronicle search autodetect menu
Hash view is displayed.
Hash view
Navigate to Hash view from Asset view
You can also navigate to Hash view while investigating an asset in Asset view.
Search for an asset and view it in Asset view.
Search for asset from the landing page
Asset view is displayed.
Asset view
From the TIMELINE tab to the left, scroll down to any event tied to a process or file modification, such as PROCESS_LAUNCH.
Increase the time range to find events
Expand the file to view details and investigate.
Find a process or file-related event
You can open Hash view for the file by clicking the hash value in Asset view.
Hash value link in Asset view
Hash view is displayed.
Hash view
Filter options in Hash view
The following Procedural Filtering options are available in Hash view:
- ASSETS
- EVENT TYPE
- LOG SOURCE
- PID
- PROCESS NAME
Hash view filtering options