Difference between revisions of "Truxton event set file id"
Jump to navigation
Jump to search
(→Sample) |
|||
| (One intermediate revision by the same user not shown) | |||
| Line 19: | Line 19: | ||
=Sample= | =Sample= | ||
<source lang="C" highlight="11"> | <source lang="C" highlight="11"> | ||
| − | void initialize_investigation(uint64_t truxton, char const * media_id, char const * file_id) | + | void initialize_investigation( uint64_t truxton, char const * media_id, char const * file_id ) |
{ | { | ||
| − | uint64_t event_handle = truxton_event_create(truxton); | + | uint64_t event_handle = truxton_event_create( truxton ); |
truxton_event_set_title( event_handle, "Phase 1" ); | truxton_event_set_title( event_handle, "Phase 1" ); | ||
| Line 39: | Line 39: | ||
printf( "Event ID is %s\n", id ); | printf( "Event ID is %s\n", id ); | ||
| − | truxton_event_destroy( | + | truxton_event_destroy( event_handle ); |
} | } | ||
</source> | </source> | ||
Latest revision as of 09:08, 10 February 2021
This sets the source file of the event.
Syntax
void truxton_event_set_file_id( uint64_t event_handle, char const * id );
Parameters
event_handle
The handle to an event created by the truxton_event_create call.
id
The string representation of a GUID.
It corresponds to the [FileID] column of the [Event] table.
Remarks
This identifier should be a value from the [ID] column of the[File] table in the database.
Sample
void initialize_investigation( uint64_t truxton, char const * media_id, char const * file_id )
{
uint64_t event_handle = truxton_event_create( truxton );
truxton_event_set_title( event_handle, "Phase 1" );
truxton_event_set_description( event_handle, "As described by SA Barnett" );
truxton_event_set_start( event_handle, get_ticks( "2016-07-31T12:00:00-05:00" ) );
truxton_event_set_end( event_handle, get_ticks( "2017-01-04T12:00:00-05:00" ) );
truxton_event_set_type( event_handle, EVENT_TYPE_ADDED_BY_ANALYST );
truxton_event_set_media_id( event_handle, media_id );
truxton_event_set_file_id( event_handle, file_id );
truxton_event_save( event_handle );
char id[ 65 ];
truxton_event_get_id( event_handle, id, sizeof( id ) );
printf( "Event ID is %s\n", id );
truxton_event_destroy( event_handle );
}