2021-07-13 12:31 PM - edited 2021-07-13 02:13 PM
Hi, I was troubleshooting a custom packet parser in my environment when I realized my test traffic is plaintext only AFTER Netwitness already deencoded it for viewing. That's awesome from an analyst standpoint. But my parser was not grabbing any meta values for alerting because it is scanning the encoded/gzip/etc data.
Would there happen to be any api I can use in a packet parser like "nw.un-gzip/un-brotli/etc(some specific payload)"?