Introduction
The Files page allows authorized users to review, track, search, and export files collected from monitored endpoints during security investigations. From this page, you can monitor file collection requests, view file details, track request status, and download completed file retrievals when available.
If your organization requires access to collected files or additional file retrieval capabilities, contact Field Effect Support.
This article covers the following topics:
- Access & Navigate the Files Page
- Download Files
- Customize Columns
- Search for Files
- Sort and Filter Results
- Export Results
Access & Navigate the Files Page
The Files page, located in the sidebar's Endpoints section, displays file collection requests in a table format. You can customize the table by showing or hiding columns, rearranging their order, resizing columns, and sorting results.
List View
The main table contains information about file collection requests and their current status. Available columns include:
- File Name
- File Path
- File Size
- Host Name
- Status
- Requested (UTC)
- Completed (UTC)
- Analysis Results
- Analysis Score
- MD5
- SHA1
- Notes
Additional columns may be available depending on your permissions and configuration.

Details View
Select a row to display additional information about the file in the details pane below the table.

You can expand the details pane into a larger modal view by selecting Expand. Selecting the Host Name link opens the corresponding endpoint's details page.

Download Files
When a collected file becomes available, you can download it by selecting the Download icon in the file's row. File retrieval requests are processed asynchronously. After a request is approved, the endpoint agent must retrieve the file before it becomes available for download.
Use the Status column to track progress:
- Clock icon: The request is still processing.
- Checkmark icon: The file is available for download.
Downloaded files are compressed and encrypted for security purposes.

Customize Columns
You can customize the Files page to display only the information most relevant to your investigation.
To modify visible columns:
- Select Edit Columns.
- Select the columns you want displayed.
- Clear the columns you want hidden.
- Select Apply.

You can also:
- Resize columns by dragging the column boundary.
- Rearrange columns by dragging them into a new position.
- Sort columns by selecting the column header.
Search for Files
Use the search bar to quickly locate files or create advanced filters.
You can:
- Search by keyword.
- Use predefined searches such as completed downloads.
- Build custom queries using column-based filters.
For example, you can:
- Find files with a specific filename.
- Search for files located in a particular path.
- Display files associated with a specific endpoint.
- Show only completed or pending file requests.
When you select a column, the search builder presents available operators and suggested values to help you create a query.
You are not limited to suggested values and can enter custom search criteria when needed.

Sort and Filter Results
To sort results:
- Select a column header to switch between ascending and descending order.
- Use the Order By option in the search builder.
To filter results, use operators such as:
- Contains
- Is Not
- Is Null
Suggestions are displayed as you build your query, making it easier to refine results.

Export Results
To export data from the Files page:
- Apply any desired filters.
- Select Export CSV.
You can export either:
- The entire file list.
- A filtered subset of results.
The CSV file is downloaded to your browser's default download location.

Was this article helpful?
That’s Great!
Thank you for your feedback
Sorry! We couldn't be helpful
Thank you for your feedback
Feedback sent
We appreciate your effort and will try to fix the article