2012-11-20 02:31 PM
Can the free version of Investigator also work with log data as supported by NetWitness for logs?
I'm have syslog files that I want to import into Investigator to see how the data would be parsed.
Or does Investigator only work with packet captures?
Thanks
2012-11-30 01:42 PM
You can only import packet data into a local collection. There are no plans to enhance Investigator because it has been replaced with Security Analytics and no longer ships with v10.x. However 9.8 Investigator/Administrator is compatible with v10.x appliances.
Scott
2012-11-30 01:42 PM
You can only import packet data into a local collection. There are no plans to enhance Investigator because it has been replaced with Security Analytics and no longer ships with v10.x. However 9.8 Investigator/Administrator is compatible with v10.x appliances.
Scott
2012-11-30 03:11 PM
Thanks for the response. I guess a moving target as the Technology is maturing and we are right in the middle of it.
John