This website uses cookies. By clicking Accept, you consent to the use of cookies. Click Here to learn more about how we use cookies.
Accept
Reject

NetWitness Community

  • Home
  • Products
    • NetWitness Platform
      • Advisories
      • Documentation
        • Platform Documentation
        • Known Issues
        • Security Fixes
        • Hardware Documentation
        • Threat Content
        • Unified Data Model
        • Videos
      • Downloads
      • Integrations
      • Knowledge Base
    • NetWitness Cloud SIEM
      • Advisories
      • Documentation
      • Knowledge Base
    • NetWitness Detect AI
      • Advisories
      • Documentation
      • Knowledge Base
    • NetWitness Investigator
    • NetWitness Orchestrator
      • Advisories
      • Documentation
      • Knowledge Base
      • Legacy NetWitness Orchestrator
        • Advisories
        • Documentation
  • Community
    • Blog
    • Discussions
    • Events
    • Idea Exchange
  • Support
    • Case Portal
      • Create New Case
      • View My Cases
      • View My Team's Cases
    • Community Support
      • Getting Started
      • News & Announcements
      • Community Support Forum
      • Community Support Articles
    • Product Life Cycle
    • Support Information
    • General Security Advisories
  • Training
    • Blog
    • Certification Program
    • Course Catalog
      • Netwitness XDR
      • EC-Council Training
    • New Product Readiness
    • On-Demand Subscriptions
    • Student Resources
    • Upcoming Events
    • Role-Based Training
  • Technology Partners
  • Trust Center
Sign InRegister Now
cancel
Turn on suggestions
Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.
Showing results for 
Search instead for 
Did you mean: 
NetWitness Discussions
  • NetWitness Community
  • Discussions
  • Re: ESA alerts Report
  • Options
    • Subscribe to RSS Feed
    • Mark Topic as New
    • Mark Topic as Read
    • Float this Topic for Current User
    • Bookmark
    • Subscribe
    • Mute
    • Printer Friendly Page

ESA alerts Report

RenatoAbreu
RenatoAbreu Beginner
Beginner
Options
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Report Inappropriate Content

‎2016-09-22 04:01 PM

Hi all,

 

I am trying to create a report containing the alerts generated by the ESA rules for some range of time (e.g last 5 days).

The idea is to generate a report with the alert informations shown on the picture below (Severity, Alert Name, Count, etc).Alert Summary.PNG

 

Could anybody help me with this?

 

Thanks in advance.

  • alert summary
  • Community Thread
  • Discussion
  • ESA
  • Forum Thread
  • NetWitness
  • NW
  • NWP
  • Report
  • RSA NetWitness
  • RSA NetWitness Platform
1 Like
Reply
  • All forum topics
  • Previous Topic
  • Next Topic
15 REPLIES 15

JohnTyson1
JohnTyson1 Beginner
Beginner
In response to EricPartington
Options
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Report Inappropriate Content

‎2017-04-05 06:33 PM

Thanks Eric, very cool and helpful!  So the use case I am doing, is levering an ESA rule that is pretty much building a list anytime powershell.exe is run (not sure if this covers it while run in memory with say powerpick or something).  I simply wanted to create a report of the user/service account/machines that are evoking powershell for validation purposes.

There may be a better way, but this is allowing me to get some practical exp. on these app. interconnections.

0 Likes
Reply

MaximilianoCitt
MaximilianoCitt Frequent Contributor
Frequent Contributor
In response to EricPartington
Options
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Report Inappropriate Content

‎2017-04-06 12:14 PM

I have used the IMDB as data source on the Reporting Engine, but that only retrieve the "columns" of the alert or incident... there is any way to retrieve the related events of the alert?

0 Likes
Reply

UtsavSejpal
UtsavSejpal Beginner
Beginner
In response to EricPartington
Options
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Report Inappropriate Content

‎2017-12-07 09:53 PM

Dear All,

 

I am trying to use the suggested method to use IMDB as a data source to export report for the alerts. However, it doesn't allow me to choose the option "from". I see that meta section keeps loading. Am I missing out something?

 

pastedImage_1.png

 

Thanks,

Utsav Sejpal

0 Likes
Reply

sachinsahu
sachinsahu Beginner
Beginner
In response to EricPartington
Options
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Report Inappropriate Content

‎2018-01-31 11:00 PM

Hi Eric,

 

As per your instruction I was trying to create the same report via "NetWitness" Rules type, when I am creating the report then no any "from: alert" field is coming , I have left this and taken all remaining field. when I am testing this report getting message as below.

 

 

Error occurred while fetching data from source 'SA - Broker[127.0.0.1]'. Error details : Error occurred while fetching data from devices connected to 'SA - Broker[127.0.0.1]' . Please check logs for more details.

 

 

 

Kindly Help me for same.

 

Thanks

0 Likes
Reply

JoshRandall
Valued Contributor JoshRandall Valued Contributor
Valued Contributor
In response to UtsavSejpal
Options
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Report Inappropriate Content

‎2018-02-01 12:36 PM

Nothing appears in the "From:" dropdown menu?

 

respond_rule.png

 

Have you added Incident Management as a Data Source in your Reporting Engine configuration?

 

My meta section loads once I select either alert or incident in the dropdown.


Mr. Mongo
0 Likes
Reply

JoshRandall
Valued Contributor JoshRandall Valued Contributor
Valued Contributor
In response to sachinsahu
Options
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Report Inappropriate Content

‎2018-02-01 12:38 PM

Your rule type needs to be IMDB (Incident Management Database), not NWDB (NetWitness Database).


Mr. Mongo
0 Likes
Reply
  • « Previous
    • 1
    • 2
  • Next »
Powered by Khoros
  • Blog
  • Events
  • Discussions
  • Idea Exchange
  • Knowledge Base
  • Case Portal
  • Community Support
  • Product Life Cycle
  • Support Information
  • About the Community
  • Terms & Conditions
  • Privacy Statement
  • Acceptable Use Policy
  • Employee Login
© 2022 RSA Security LLC or its affiliates. All rights reserved.