2020-11-11 01:09 AM
What is the difference between requirePri=false and snaplen=1514 in capture.device.params in Decoder config (DECODER->EXPLORE->decoder->config). When I add requirePri=false in that field, I can see that more logs are started received in decoder which are unable to proceed by concentrator & ESA.
2020-11-11 11:00 AM
The only required field on the Log Decoder is the requirePri=false
Is the event source supported by NetWitness? Is the format being used supported?
I need a little more info to assist
Dave