Skip to main content

Retrieving files from endpoints

The Retrieve file action allows you to remotely retrieve files from managed endpoints directly from the Network page. The retrieved files are stored as a password-protected archive in the task artifacts for 7 days, with controlled access.

You can retrieve files from multiple managed endpoints from multiple companies at the same time.

Create the task

To retrieve a file from one or more managed endpoints, follow these steps:

  1. Log in to GravityZone Control Center.

  2. Go to the Network page.

  3. Browse your network and select one or more managed endpoints.

  4. Click the Actions menu, then select Retrieve file.

    network_retrieve_file_action_cp_1568670_en.png
  5. In the Retrieve file configuration window, configure the following settings:

    • Task name - By default, the task name is Retrieve file followed by date.

      You can change it to make the task easier to identify on the Network > Tasks page.

      The task name supports up to 512 characters.

    • Archive name - Specify the name of the password-protected archive that will contain the retrieved file.

    • Password – Enter the password used to protect the archive.

      The password must contain at least 6 characters.

      The password supports the following special characters: !@#$%^&*()_+-={}[]|\:;<>;,.?/

    • Confirm password – Re-enter the password to confirm it.

    • File path – Specify the full path to the file you want to retrieve. If the same path is common to the selected endpoints, then the file will be retrieved from all of them.

      Examples:

      Windows

      D:\Temp\document.pdf

      Linux

      /home/username/documents/report.txt

      macOS

      /Users/username/Documents/file.txt

      The file path supports Windows, Linux, and macOS formats and can contain up to 1024 characters.

      Note

      The path does not support wildcards.

  6. Click Retrieve.

    The task is created.

    network_retrieve_file_configuration_cp_1568670_en.png

You can monitor the task progress on the Network > Tasks page, under Retrieve file type.

network_retrieve_file_tasks_cp_1568670_en.png

Download retrieved files

Within the task, GravityZone creates a subtask for each selected endpoint. When a subtask is finished, you can download the retrieved file.

To download a retrieved file, follow these steps:

  1. Go to the Network > Tasks page.

  2. Click the status indicator in the Status column to access the subtasks of the Retrieve file task.

    network_retrieve_file_task_status_cp_1568670_en.png
  3. Go to a subtask and click Download.

    network_retrieve_file_subtask_cp_1568670_en.png

The file is downloaded locally as a password-protected archive. Use the password you specified when creating the task to extract it.

Note

Only the user who created the task can download the retrieved file.

Retrieved files are retained for 7 days. After 7 days or after manual deletion, the file is no longer available for download.

You can also download the file from the Investigation tab in the details page of each endpoint.

network_retrieve_file_investigation_cp_1568670_en.png

Delete retrieved files

To delete a retrieved file, follow these steps:

  1. Go to the Network > Tasks page.

  2. Click the status indicator in the Status column to access the subtasks of the Retrieve file task.

  3. Go to a subtask and click Delete file.

The file is permanently deleted. To obtain it again, you must run the Retrieve file action.

Note

Only the user who created the task can delete the retrieved file.

Note

If the main task is deleted, the retrieved files are not automatically deleted. In this case, you can use the Delete all button from the Investigation tab in the details page of each endpoint.

Rules and limitations

Retrieving files from managed endpoint has the following rules and limitations:

  • Maximum file size: 25 MB per archive.

  • Maximum retrieved files per company: 30 files simultaneously. All action statuses except Failed count toward this limit.

    If a Retrieve file action is initiated while 30 files are already retrieved, the task will fail with a corresponding error message.

    For pending action statuses, you can delete the task from the Tasks page to free up capacity and initiate a new one.

Monitor user activity

You can review the tasks on the Accounts > User activity page.

  1. Select the company where the actions took place.

  2. Select the Area and the Action.

  3. Click Search.

The following actions are logged:

Action

Area

Description

Retrieved file

Network

Logged when the Retrieve file action is initiated from the Network page. The target shows the endpoint name, or the number of endpoints if multiple were selected.

Downloaded file

Tasks

Logged when a user downloads the retrieved file from a subtask. The target shows the archive name.

Deleted file

Tasks

Logged when a user deletes the retrieved file from a subtask. The target shows the archive name.

network_retrieve_file_user_activity_cp_1568670_en.png