Truxton event tag

From truxwiki.com
Jump to navigation Jump to search

This will tag the event. It will cause a record to be created in the [Tagged] table.

Syntax

int truxton_event_tag( uint64_t event_handle, char const * tag_name, char const * why, uint64_t origin );

Parameters

event_handle

The handle created by the truxton_event_create call.

tag_name

The small bit of text that will serve as the tag. This will show up in the user interface. This parameter must match one of the values in the [Name] column of the [Tag] table. You can create tags using the truxton_create_tag API.

why

The reason why this item was tagged.

origin

What produced this tag. If an algorithm produced this tag, it should be set to 1. If you are calling this method because a human told you to, the value should be 2.

Return value

A non-zero value on success, zero on failure.

Sample

void initialize_investigation( uint64_t truxton, char const * media_id, char const * file_id )
{
   uint64_t event_handle = truxton_event_create( truxton );

   truxton_event_set_name( event_handle, "Phase 1" );
   truxton_event_set_description( event_handle, "As described by SA Barnett" );
   truxton_event_set_start( event_handle, get_ticks( "2016-07-31T12:00:00-05:00" ) );
   truxton_event_set_end( event_handle, get_ticks( "2017-01-04T12:00:00-05:00" ) );
   truxton_event_set_type( event_handle, EVENT_TYPE_ADDED_BY_ANALYST );
   truxton_event_set_media_id( event_handle, media_id );
   truxton_event_set_file_id( event_handle, file_id );

   truxton_event_save( event_handle );

   char id[ 65 ];

   truxton_event_get_id( event_handle, id, sizeof( id ) );

   printf( "Event ID is %s\n", id );

   truxton_event_tag( event_handle, "FBI", "Lead Mushroom for investigation", TAG_ORIGIN_HUMAN );

   truxton_event_destroy( event_handle );
}