This website uses cookies. By clicking Accept, you consent to the use of cookies. Click Here to learn more about how we use cookies.
Accept
Reject

NetWitness Community

  • Home
  • Products
    • NetWitness Platform
      • Advisories
      • Documentation
        • Platform Documentation
        • Known Issues
        • Security Fixes
        • Hardware Documentation
        • Threat Content
        • Unified Data Model
        • Videos
      • Downloads
      • Integrations
      • Knowledge Base
    • NetWitness Cloud SIEM
      • Advisories
      • Documentation
      • Knowledge Base
    • NetWitness Detect AI
      • Advisories
      • Documentation
      • Knowledge Base
    • NetWitness Investigator
    • NetWitness Orchestrator
      • Advisories
      • Documentation
      • Knowledge Base
      • Legacy NetWitness Orchestrator
        • Advisories
        • Documentation
  • Community
    • Blog
    • Discussions
    • Events
    • Idea Exchange
  • Support
    • Case Portal
      • Create New Case
      • View My Cases
      • View My Team's Cases
    • Community Support
      • Getting Started
      • News & Announcements
      • Community Support Forum
      • Community Support Articles
    • Product Life Cycle
    • Support Information
    • General Security Advisories
  • Training
    • Blog
    • Certification Program
    • Course Catalog
      • Netwitness XDR
      • EC-Council Training
    • New Product Readiness
    • On-Demand Subscriptions
    • Student Resources
    • Upcoming Events
    • Role-Based Training
  • Technology Partners
  • Trust Center
Sign InRegister Now
cancel
Turn on suggestions
Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.
Showing results for 
Search instead for 
Did you mean: 
NetWitness Discussions
  • NetWitness Community
  • Discussions
  • Re: Collecte Box events
  • Options
    • Subscribe to RSS Feed
    • Mark Topic as New
    • Mark Topic as Read
    • Float this Topic for Current User
    • Bookmark
    • Subscribe
    • Mute
    • Printer Friendly Page

Collecte Box events

Go to solution
BaptOnfroy
BaptOnfroy Contributor
Contributor
Options
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Report Inappropriate Content

‎2022-05-16 05:03 AM

Hello team,

 

I would like to collect the logs of the Box. Has someone already done it here?

 

Thank you !

 

 

Labels:
  • Labels:
  • RSA NetWitness Platform
  • box
  • Collecte
  • events
0 Likes
Reply
  • All forum topics
  • Previous Topic
  • Next Topic
1 ACCEPTED SOLUTION

Accepted Solutions

Go to solution
VincentWareham
Frequent Contributor VincentWareham Frequent Contributor
Frequent Contributor
Options
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Report Inappropriate Content

‎2022-06-18 07:17 PM

Hello BaptOnfroy

 

When looking for the Box device on supported NetWitness Integration guides webpage, I am not finding it.

 

Reference: Integrations - https://community.netwitness.com/t5/netwitness-platform-integrations/tkb-p/netwitness-integrations

 

As NetWitness collecting logs from the Box device is not supported and no one else is currently responding to say they have done this, then the options you have are the following.

 

1. Create your own Custom parser.

 

a. See the "Build Your Own Integration" topic on the NetWitness Community website. RSA Customer Support cannot help with writing a custom parser.

 

Reference: Build Your Own Integration - https://community.netwitness.com/t5/netwitness-platform-integrations/build-your-own-integration/ta-p/569322

 

b. Write Custom Log Parser Rules in the NetWitness UI, Configure > Log Parser Rules

 

Reference: Log Parser Customization Guide for 11.7 - https://community.netwitness.com/t5/netwitness-platform-online/log-parser-customization-guide-for-11-7/ta-p/654853

 

Other Log Parser Rules topics can be found on the NetWitness Community website with a URL like below.

 

https://community.netwitness.com/t5/forums/searchpage/tab/message?q=%22Log%20Parser%20rules%22&noSynonym=false&collapse_discussion=true

 

2. Let RSA Engineering know of your interest in having a future qualified parser for this device type by going to the NetWitness Community Ideas website to "Submit an Idea" to get NetWitness Product Management attention.

 

Click on "Submit an Idea" and describe the suggestion on the webpage, NetWitness Ideas - https://community.netwitness.com/t5/netwitness-ideas/idb-p/netwitness-ideas

 

This is the location where enhancement requests can be created, and also see what other Customers are suggesting. RSA Product Management monitors these suggestions and will consider the ideas that are most voted for by Customers.

View solution in original post

0 Likes
Reply
2 REPLIES 2

Go to solution
VincentWareham
Frequent Contributor VincentWareham Frequent Contributor
Frequent Contributor
Options
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Report Inappropriate Content

‎2022-06-18 07:17 PM

Hello BaptOnfroy

 

When looking for the Box device on supported NetWitness Integration guides webpage, I am not finding it.

 

Reference: Integrations - https://community.netwitness.com/t5/netwitness-platform-integrations/tkb-p/netwitness-integrations

 

As NetWitness collecting logs from the Box device is not supported and no one else is currently responding to say they have done this, then the options you have are the following.

 

1. Create your own Custom parser.

 

a. See the "Build Your Own Integration" topic on the NetWitness Community website. RSA Customer Support cannot help with writing a custom parser.

 

Reference: Build Your Own Integration - https://community.netwitness.com/t5/netwitness-platform-integrations/build-your-own-integration/ta-p/569322

 

b. Write Custom Log Parser Rules in the NetWitness UI, Configure > Log Parser Rules

 

Reference: Log Parser Customization Guide for 11.7 - https://community.netwitness.com/t5/netwitness-platform-online/log-parser-customization-guide-for-11-7/ta-p/654853

 

Other Log Parser Rules topics can be found on the NetWitness Community website with a URL like below.

 

https://community.netwitness.com/t5/forums/searchpage/tab/message?q=%22Log%20Parser%20rules%22&noSynonym=false&collapse_discussion=true

 

2. Let RSA Engineering know of your interest in having a future qualified parser for this device type by going to the NetWitness Community Ideas website to "Submit an Idea" to get NetWitness Product Management attention.

 

Click on "Submit an Idea" and describe the suggestion on the webpage, NetWitness Ideas - https://community.netwitness.com/t5/netwitness-ideas/idb-p/netwitness-ideas

 

This is the location where enhancement requests can be created, and also see what other Customers are suggesting. RSA Product Management monitors these suggestions and will consider the ideas that are most voted for by Customers.

0 Likes
Reply

Go to solution
BaptOnfroy
BaptOnfroy Contributor
Contributor
In response to VincentWareham
Options
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Report Inappropriate Content

‎2022-07-29 03:42 AM

Thank you for your answer, the process does not seem easy but your answer is very complete.

0 Likes
Reply
Powered by Khoros
  • Blog
  • Events
  • Discussions
  • Idea Exchange
  • Knowledge Base
  • Case Portal
  • Community Support
  • Product Life Cycle
  • Support Information
  • About the Community
  • Terms & Conditions
  • Privacy Statement
  • Acceptable Use Policy
  • Employee Login
© 2022 RSA Security LLC or its affiliates. All rights reserved.