Recently RSA NetWitness (NW) added the ability to report on the IMDB component of the platform. Based on some recent questions it seemed useful to create a few template rules and reports that could be used to create a starter pack for reporting on IMDB data.
RSA IMDB reporting syntax
https://community.rsa.com/docs/DOC-64586
Included at the bottom is the rule and report pack that cover a few scenarios that should get you started reporting on data that you might want to see.
Some things that I have found out during this development.
S you can create rules that provide data like this for alerts:
Like this for incidents
or pretty close to this
The rules in the included pack
IMDB>
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.