2018-03-07 06:49 AM
Hi,
I'm using NetWitness 11.0.
Is there any API to perform queries that will return if the query subject is linked to an event or alert or task?
For example if ip.src = 1.1.1.1 is linked to some event or alert?
Thanks!
2018-03-08 09:49 AM
As of right now there is no way that I know of to perform the action you are looking for.
2018-03-07 02:44 PM
Evyatar,
To the best of my knowledge the REST interface is currently for the core services only. This means you can run queries via REST only against the brokers, concentrators, decoders and archivers. You can't run it against Response, Reporting Engine or Event Stream Analysis.
2018-03-08 02:16 AM
Is there any other way (WebSockets for example) to get such data?
Thanks
2018-03-08 09:49 AM
As of right now there is no way that I know of to perform the action you are looking for.
2018-03-12 10:48 AM
Is there any way to get Eventsources Alarms via rest api?
2018-03-12 11:01 AM
Not at this time. The only way to get these alarms is to set them up to be sent out via SNMP, syslog or SMTP.
2018-06-13 09:28 AM
Evyatar & Nikolay,
Some new information was given to me about the new API in 11.1. You can find it here: NetWitness Suite API User Guide for Version 11.1. It looks to be for accessing the Response service. So any alerts/incidents can be accessible via this API in 11.1. You may be able to use this API to find what you are looking for.