This website uses cookies. By clicking Accept, you consent to the use of cookies. Click Here to learn more about how we use cookies.
Accept
Reject

NetWitness Community

  • Home
  • Products
    • NetWitness Platform
      • Advisories
      • Documentation
        • Platform Documentation
        • Known Issues
        • Security Fixes
        • Hardware Documentation
        • Threat Content
        • Unified Data Model
        • Videos
      • Downloads
      • Integrations
      • Knowledge Base
    • NetWitness Cloud SIEM
      • Advisories
      • Documentation
      • Knowledge Base
    • NetWitness Detect AI
      • Advisories
      • Documentation
      • Knowledge Base
    • NetWitness Investigator
    • NetWitness Orchestrator
      • Advisories
      • Documentation
      • Knowledge Base
      • Legacy NetWitness Orchestrator
        • Advisories
        • Documentation
  • Community
    • Blog
    • Discussions
    • Events
    • Idea Exchange
  • Support
    • Case Portal
      • Create New Case
      • View My Cases
      • View My Team's Cases
    • Community Support
      • Getting Started
      • News & Announcements
      • Community Support Forum
      • Community Support Articles
    • Product Life Cycle
    • Support Information
    • General Security Advisories
  • Training
    • Blog
    • Certification Program
    • Course Catalog
      • Netwitness XDR
      • EC-Council Training
    • New Product Readiness
    • On-Demand Subscriptions
    • Student Resources
    • Upcoming Events
    • Role-Based Training
  • Technology Partners
  • Trust Center
Sign InRegister Now
cancel
Turn on suggestions
Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.
Showing results for 
Search instead for 
Did you mean: 
NetWitness Discussions
  • NetWitness Community
  • Discussions
  • Is it possible to force the Concentrator to process the LogDecoder data?
  • Options
    • Subscribe to RSS Feed
    • Mark Topic as New
    • Mark Topic as Read
    • Float this Topic for Current User
    • Bookmark
    • Subscribe
    • Mute
    • Printer Friendly Page

Is it possible to force the Concentrator to process the LogDecoder data?

PedroQueiros
PedroQueiros Beginner
Beginner
Options
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Report Inappropriate Content

‎2018-04-24 05:34 AM

Hello,

I've recently had a problem of free space in my Concentrator, and as such, I've lost old meta (meta.oldest.file.time is only two weeks ago).

 

Since this data still exists in the LogDecoder, and I've reconfigured the available space in the Concentrator, is it possible somehow to force the Concentrator to reprocess that data, so I can go back one month, instead of only two weeks?

 

Thank you for your help!

 

Kind Regards,

Pedro Queirós

  • Community Thread
  • Discussion
  • Forum Thread
  • NetWitness
  • NW
  • NWP
  • RSA NetWitness
  • RSA NetWitness Platform
0 Likes
Reply
  • All forum topics
  • Previous Topic
  • Next Topic
5 REPLIES 5

JohnKisner
Trusted Contributor JohnKisner Trusted Contributor
Trusted Contributor
Options
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Report Inappropriate Content

‎2018-04-24 10:42 AM

Pedro,

 

You can reconsume all the available meta and session data on the log decoder by doing a data reset on the concentrator. This will cause the concentrator to reconsume everything that it can from the connected log decoder. It is important that you look at the log decoder's meta and session data to make sure they both are about the same amount of time back. This way when the concentrator reconsumes from the log decoder you have a good picture of how much log decoder data will be available on the concentrator.

 

A side effect of reconsuming like this is that you may receive old alerts firing from the reporting engine or the Event Stream Analysis appliance. Since the concentrator would be consuming from scratch, these devices won't realize they have alerted on the data coming back into the concentrator. These old alerts will continue to fire until the concentrator is fully caught up. Also trying to perform any Investigations against this concentrator before it is fully caught up can cause inconsistent results.

 

I hope this helps.

2 Likes
Reply

PedroQueiros
PedroQueiros Beginner
Beginner
In response to JohnKisner
Options
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Report Inappropriate Content

‎2018-04-24 12:41 PM

Hello John,

 

Thank you for your reply. And how can I do a "data reset" on the concentrator?

 

Kind Regards,

Pedro Queirós

0 Likes
Reply

JohnKisner
Trusted Contributor JohnKisner Trusted Contributor
Trusted Contributor
In response to PedroQueiros
Options
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Report Inappropriate Content

‎2018-04-24 02:11 PM

Pedro,

 

Within the Netwitness UI, go to the Services page.

1. Click the Actions -> View -> Explore for the concentrator you want to data reset.

2. Once in the Explore view right click on the concentrator node and click Properties.

3. In the Properties area click the drop down and select reset.

4. Then put data=1 in the Parameters area and click Send. Once you click Send in the Response Output section it will tell you that you have to add the something to the Parameter area to verify that you want to do the data reset.

5. In the output there were will a verify=######. You will need to add this verify=###### to the end of the Parameter field. So it should look something like this: data=1 verify=213298.

6. Click Send again and the concentrator will restart and delete all the data files from all index, sessiondb, and metadb locations.

 

Once the restart of the service is complete it will begin reconsuming everything that it can from the connected log decoder. 

 

IMPORTANT: This is a one way operation. If you tell the concentrator to do a data reset, you cannot undo the reset. So make sure you want to delete all the data from the concentrator. 

 

I hope this helps.

0 Likes
Reply

RenatoGoncalves
RenatoGoncalves Beginner
Beginner
In response to JohnKisner
Options
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Report Inappropriate Content

‎2018-10-09 04:43 AM

Hello John,

 

How can i do that in 11.2? After right clicking in the concentrator the drop down in properties has no data.....

0 Likes
Reply

JohnKisner
Trusted Contributor JohnKisner Trusted Contributor
Trusted Contributor
In response to RenatoGoncalves
Options
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Report Inappropriate Content

‎2018-10-22 10:13 AM

Renato,

 

Sorry for the long delay. The process is the same in 11.2. I you are seeing nothing in the drop down it sounds like you may not have full permissions to the service. Make sure you are using the default admin account if possible. If you cannot use the admin account itself you will need to make sure that the account you are using has full permissions on the concentrator service. This is generally setup using the Roles under the service's Security area.

0 Likes
Reply
Powered by Khoros
  • Blog
  • Events
  • Discussions
  • Idea Exchange
  • Knowledge Base
  • Case Portal
  • Community Support
  • Product Life Cycle
  • Support Information
  • About the Community
  • Terms & Conditions
  • Privacy Statement
  • Acceptable Use Policy
  • Employee Login
© 2022 RSA Security LLC or its affiliates. All rights reserved.