This website uses cookies. By clicking Accept, you consent to the use of cookies. Click Here to learn more about how we use cookies.
Accept
Reject

NetWitness Community

  • Home
  • Products
    • NetWitness Platform
      • Advisories
      • Documentation
        • Platform Documentation
        • Known Issues
        • Security Fixes
        • Hardware Documentation
        • Threat Content
        • Unified Data Model
        • Videos
      • Downloads
      • Integrations
      • Knowledge Base
    • NetWitness Cloud SIEM
      • Advisories
      • Documentation
      • Knowledge Base
    • NetWitness Detect AI
      • Advisories
      • Documentation
      • Knowledge Base
    • NetWitness Investigator
    • NetWitness Orchestrator
      • Advisories
      • Documentation
      • Knowledge Base
      • Legacy NetWitness Orchestrator
        • Advisories
        • Documentation
  • Community
    • Blog
    • Discussions
    • Events
    • Idea Exchange
  • Support
    • Case Portal
      • Create New Case
      • View My Cases
      • View My Team's Cases
    • Community Support
      • Getting Started
      • News & Announcements
      • Community Support Forum
      • Community Support Articles
    • Product Life Cycle
    • Support Information
    • General Security Advisories
  • Training
    • Blog
    • Certification Program
    • Course Catalog
    • New Product Readiness
    • On-Demand Subscriptions
    • Student Resources
    • Upcoming Events
  • Technology Partners
  • Trust Center
Sign InRegister Now
cancel
Turn on suggestions
Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.
Showing results for 
Search instead for 
Did you mean: 
NetWitness Discussions
Announcement Banner

Scheduled Maintenance for the Case Portal during May 20-22

View Details
  • NetWitness Community
  • Discussions
  • Re: Custom logs parsing on ESI, but not on SA
  • Options
    • Subscribe to RSS Feed
    • Mark Topic as New
    • Mark Topic as Read
    • Float this Topic for Current User
    • Bookmark
    • Subscribe
    • Mute
    • Printer Friendly Page

Custom logs parsing on ESI, but not on SA

VishamSinghRawa
VishamSinghRawa Beginner
Beginner
Options
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Email to a Friend
  • Report Inappropriate Content

‎2016-05-15 08:51 AM

I've been able to successfully create a parser on the ESI toolkit and get the logs parsed for a custom device, but for some reason the logs go undetected on SA.

Under what circumstances can this happen? I've made sure that each column has been parsed successfully and under the appropriate tag, yet this problem comes up.

Any help would be appreciated.

  • Community Thread
  • custom log parser
  • Discussion
  • esi
  • Forum Thread
  • NetWitness
  • NW
  • NWP
  • Parser
  • RSA NetWitness
  • RSA NetWitness Platform
  • rsa sa
  • security_analytics
0 Likes
Share
Reply
  • All forum topics
  • Previous Topic
  • Next Topic
3 REPLIES 3

OmarGarciaGilio
OmarGarciaGilio Beginner
Beginner
Options
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Email to a Friend
  • Report Inappropriate Content

‎2016-05-16 11:18 AM

Hello,

I have the same problem, my parser works fine on ESI but not work on SA (after i deployed it).

maybe this tips help you:

     1. Check that all envision's fields that you use have a meta on SA (tablemaps).

     2. Check the DeviceID, it must be unique. you can see it on ini file.

Hope that helps you.

0 Likes
Share
Reply

VishamSinghRawa
VishamSinghRawa Beginner
Beginner
In response to OmarGarciaGilio
Options
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Email to a Friend
  • Report Inappropriate Content

‎2016-05-17 03:44 AM

Hi Omar,

 

I've created my new custom metakeys within the table-map-custom.xml file. I've mapped those values to my ESI table-map.xml file. The meta is available in the ESI toolkit.

 

I've managed to successfully parse the logs of 4 out of 6 custom log files (devices).

For the two devices I haven't managed to parse, just a little bit of info, don't know if it's relevant, these are exports of tables from a SQL database, converted to text and then log format.

The four that were successfully parsed are the usual .text or .log formats. 

 

Also, for each of these devices, I've found four fields within the .ini file. For some reason, DeviceType=7104 is common to all, something to do with a common parsing platform?

DatabaseName=customapp

DisplayName=customapp

DeviceGroup=Application Servers

DeviceType=7104

0 Likes
Share
Reply

VishamSinghRawa
VishamSinghRawa Beginner
Beginner
In response to VishamSinghRawa
Options
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Email to a Friend
  • Report Inappropriate Content

‎2016-05-17 04:52 AM

No worries, it's done. Thanks for the response.

0 Likes
Share
Reply
Powered by Khoros
  • Blog
  • Events
  • Discussions
  • Idea Exchange
  • Knowledge Base
  • Case Portal
  • Community Support
  • Product Life Cycle
  • Support Information
  • About the Community
  • Terms & Conditions
  • Privacy Statement
  • Acceptable Use Policy
  • Employee Login
© 2022 RSA Security LLC or its affiliates. All rights reserved.