This website uses cookies. By clicking Accept, you consent to the use of cookies. Click Here to learn more about how we use cookies.
Accept
Reject

NetWitness Community

  • Home
  • Products
    • NetWitness Platform
      • Advisories
      • Documentation
        • Platform Documentation
        • Known Issues
        • Security Fixes
        • Hardware Documentation
        • Threat Content
        • Unified Data Model
        • Videos
      • Downloads
      • Integrations
      • Knowledge Base
    • NetWitness Cloud SIEM
      • Advisories
      • Documentation
      • Knowledge Base
    • NetWitness Detect AI
      • Advisories
      • Documentation
      • Knowledge Base
    • NetWitness Investigator
    • NetWitness Orchestrator
      • Advisories
      • Documentation
      • Knowledge Base
      • Legacy NetWitness Orchestrator
        • Advisories
        • Documentation
  • Community
    • Blog
    • Discussions
    • Events
    • Idea Exchange
  • Support
    • Case Portal
      • Create New Case
      • View My Cases
      • View My Team's Cases
    • Community Support
      • Getting Started
      • News & Announcements
      • Community Support Forum
      • Community Support Articles
    • Product Life Cycle
    • Support Information
    • General Security Advisories
  • Training
    • Blog
    • Certification Program
    • Course Catalog
      • Netwitness XDR
      • EC-Council Training
    • New Product Readiness
    • On-Demand Subscriptions
    • Student Resources
    • Upcoming Events
    • Role-Based Training
  • Technology Partners
  • Trust Center
Sign InRegister Now
cancel
Turn on suggestions
Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.
Showing results for 
Search instead for 
Did you mean: 
NetWitness Discussions
  • NetWitness Community
  • Discussions
  • Re: Funny problem: too many events
  • Options
    • Subscribe to RSS Feed
    • Mark Topic as New
    • Mark Topic as Read
    • Float this Topic for Current User
    • Bookmark
    • Subscribe
    • Mute
    • Printer Friendly Page

Funny problem: too many events

RomanZeltser
RomanZeltser Beginner
Beginner
Options
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Report Inappropriate Content

‎2017-05-18 02:05 PM

Most of us are trying to add more event sources to get better picture of what is going on on the wire. I have the opposite problem: I have too many events coming from Windows and Cisco parsers. This problem is causing the Alarm (see attachment 1). In fact, based on some research and browsing through the system, the volume of data is about 6-8 times bigger than allowed volume!

 

Just to show you the source of the problem (Cisco parser) that delivers plenty of meaningless data, see the attachment 2.

Similar stream of meaningless data comes from Windows devices.

The question is how to decrease the volume of useless data on the Netwitness side without editing the parsers (as it may be very intrusive)? What do you do if you need to filter some of the data down to analyze the only meaningful ones?

  • Community Thread
  • Discussion
  • event.desc alarm
  • Forum Thread
  • NetWitness
  • NW
  • NWP
  • RSA NetWitness
  • RSA NetWitness Platform
Preview file
32 KB
Preview file
7 KB
0 Likes
Share
Reply
  • All forum topics
  • Previous Topic
  • Next Topic
4 REPLIES 4

AndreasFunk
Employee AndreasFunk
Employee
Options
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Report Inappropriate Content

‎2017-05-19 04:14 AM

Hi Roman,

you can filter these events easily with an app rule on the log decoder. Please find an example below. You can define rules like this for all the data that is meaningless to you.

 

Filter.png

2 Likes
Share
Reply

RomanZeltser
RomanZeltser Beginner
Beginner
In response to AndreasFunk
Options
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Report Inappropriate Content

‎2017-05-19 08:26 AM

Andeas, thank you.

 

What kind of editor do you use? When I use my Rule Editor I see the following:

 

 

 

===============

Roman Zeltser

Sr. IM Security Analyst

CDR Associates

 

307 International Circle

Suite 300

Hunt Valley, MD 21030

P: 410-560-2269 x.1261

rzeltser@cdrassociates.com<mailto:rzeltser@cdrassociates.com>

Preview file
2 KB
Preview file
17 KB
0 Likes
Share
Reply

DavidWaugh1
Employee DavidWaugh1
Employee
In response to RomanZeltser
Options
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Report Inappropriate Content

‎2017-05-19 08:30 AM

Hi Roman,

 

You need to go to the log or packet decoder and then select config. App Rules can then be configured on the App Rules tab.

0 Likes
Share
Reply

RomanZeltser
RomanZeltser Beginner
Beginner
In response to DavidWaugh1
Options
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Report Inappropriate Content

‎2017-05-19 08:36 AM

Aha! That’s it! Thank you guys!

 

===============

Roman Zeltser

Sr. IM Security Analyst

CDR Associates

 

307 International Circle

Suite 300

Hunt Valley, MD 21030

P: 410-560-2269 x.1261

rzeltser@cdrassociates.com<mailto:rzeltser@cdrassociates.com>

Preview file
2 KB
0 Likes
Share
Reply
Powered by Khoros
  • Blog
  • Events
  • Discussions
  • Idea Exchange
  • Knowledge Base
  • Case Portal
  • Community Support
  • Product Life Cycle
  • Support Information
  • About the Community
  • Terms & Conditions
  • Privacy Statement
  • Acceptable Use Policy
  • Employee Login
© 2022 RSA Security LLC or its affiliates. All rights reserved.