Truxton event tag
Jump to navigation
Jump to search
This will tag the event.
It will cause a record to be created in the [Tagged] table.
Contents
Syntax
int truxton_event_tag( uint64_t event_handle, char const * tag_name, char const * why, uint64_t origin );
Parameters
event_handle
The handle created by the truxton_event_create call.
tag_name
The small bit of text that will serve as the tag.
This will show up in the user interface.
This parameter must match one of the values in the [Name] column of the [Tag] table.
You can create tags using the truxton_create_tag API.
why
The reason why this item was tagged.
origin
What produced this tag. If an algorithm produced this tag, it should be set to 1. If you are calling this method because a human told you to, the value should be 2.
Return value
A non-zero value on success, zero on failure.
Sample
void initialize_investigation( uint64_t truxton, char const * media_id, char const * file_id )
{
uint64_t event_handle = truxton_event_create( truxton );
truxton_event_set_name( event_handle, "Phase 1" );
truxton_event_set_description( event_handle, "As described by SA Barnett" );
truxton_event_set_start( event_handle, get_ticks( "2016-07-31T12:00:00-05:00" ) );
truxton_event_set_end( event_handle, get_ticks( "2017-01-04T12:00:00-05:00" ) );
truxton_event_set_type( event_handle, EVENT_TYPE_ADDED_BY_ANALYST );
truxton_event_set_media_id( event_handle, media_id );
truxton_event_set_file_id( event_handle, file_id );
truxton_event_save( event_handle );
char id[ 65 ];
truxton_event_get_id( event_handle, id, sizeof( id ) );
printf( "Event ID is %s\n", id );
truxton_event_tag( event_handle, "FBI", "Lead Mushroom for investigation", TAG_ORIGIN_HUMAN );
truxton_event_destroy( event_handle );
}