This website uses cookies. By clicking Accept, you consent to the use of cookies. Click Here to learn more about how we use cookies.
Accept
Reject

NetWitness Community

  • Home
  • Products
    • NetWitness Platform
      • Advisories
      • Documentation
        • Platform Documentation
        • Known Issues
        • Security Fixes
        • Hardware Documentation
        • Threat Content
        • Unified Data Model
        • Videos
      • Downloads
      • Integrations
      • Knowledge Base
    • NetWitness Cloud SIEM
      • Advisories
      • Documentation
      • Knowledge Base
    • NetWitness Detect AI
      • Advisories
      • Documentation
      • Knowledge Base
    • NetWitness Investigator
    • NetWitness Orchestrator
      • Advisories
      • Documentation
      • Knowledge Base
      • Legacy NetWitness Orchestrator
        • Advisories
        • Documentation
  • Community
    • Blog
    • Discussions
    • Events
    • Idea Exchange
  • Support
    • Case Portal
      • Create New Case
      • View My Cases
      • View My Team's Cases
    • Community Support
      • Getting Started
      • News & Announcements
      • Community Support Forum
      • Community Support Articles
    • Product Life Cycle
    • Support Information
    • General Security Advisories
  • Training
    • Blog
    • Certification Program
    • Course Catalog
      • Netwitness XDR
      • EC-Council Training
    • New Product Readiness
    • On-Demand Subscriptions
    • Student Resources
    • Upcoming Events
    • Role-Based Training
  • Technology Partners
  • Trust Center
Sign InRegister Now
cancel
Turn on suggestions
Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.
Showing results for 
Search instead for 
Did you mean: 
NetWitness Discussions
  • NetWitness Community
  • Discussions
  • Re: NXLOG Windows Collection Support
  • Options
    • Subscribe to RSS Feed
    • Mark Topic as New
    • Mark Topic as Read
    • Float this Topic for Current User
    • Bookmark
    • Subscribe
    • Mute
    • Printer Friendly Page

NXLOG Windows Collection Support

huanzhou1
huanzhou1 Beginner
Beginner
Options
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Report Inappropriate Content

‎2017-04-26 08:42 AM

Any support or planned support for NXLOG for windows collection? Lots of customer doesn't want to use Snare. 

  • Community Thread
  • Discussion
  • Forum Thread
  • NetWitness
  • NW
  • NWP
  • RSA NetWitness
  • RSA NetWitness Platform
0 Likes
Share
Reply
  • All forum topics
  • Previous Topic
  • Next Topic
6 REPLIES 6

DavidWaugh1
Employee DavidWaugh1
Employee
Options
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Report Inappropriate Content

‎2017-04-26 08:45 AM

Is using winrm as a collection method an alternative?

I would have thought it was easier to set up as it can be controlled via domain policy and also scripted to be deployed in large environments.

0 Likes
Share
Reply

EricPartington
Employee EricPartington
Employee
Options
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Report Inappropriate Content

‎2017-04-26 09:22 AM

Or what about the built in windows collection method (using WinRM) Windows Event Collection (WEC/WEF) which works as push or pull and then collect from one central windows server witn WinRM to RSA NW ?

 

https://community.rsa.com/community/products/netwitness/blog/2017/01/30/logs-collecting-windows-events-with-wec

0 Likes
Share
Reply

JoeGumke
JoeGumke Beginner
Beginner
In response to EricPartington
Options
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Report Inappropriate Content

‎2017-04-27 07:42 AM

hey eric,

Have you found anything out about RSA leveraging reverse DNS lookups for WEF?  If users leveraged a subscription server, how are the endpoints/relay identified?

0 Likes
Share
Reply

EricPartington
Employee EricPartington
Employee
In response to JoeGumke
Options
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Report Inappropriate Content

‎2017-04-27 08:35 AM

event.computer contains the true client

device.ip contains the subscription server ip address

 

no word on the reverse lookups function

0 Likes
Share
Reply

huanzhou1
huanzhou1 Beginner
Beginner
In response to DavidWaugh1
Options
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Report Inappropriate Content

‎2017-05-04 02:52 AM

For winrm, how to failover to another VLC automatically? Customer wanted to use nxlog(same as snare) to send as syslog format, so can use load balancer to failover. 

0 Likes
Share
Reply

OmarGarciaGilio
OmarGarciaGilio Beginner
Beginner
Options
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Report Inappropriate Content

‎2018-02-08 06:09 PM

For my experience, I prefer syslog to Winrm, u other send methods.

Well you can try whit this nxlog.conf

 

<Extension _syslog>
Module xm_syslog
</Extension>

<Input in>
Module im_msvistalog
</Input>

<Output out>
Module om_tcp
Host #IP_SIEM#
Port 514
Exec to_syslog_snare(); $raw_event = replace($raw_event, "\t", ',');
</Output>

<Route 1>
Path in => out
</Route>

 

Also update your win snare parse from Live.

Your language system on windows must be English (EEUU), not work for other language. If you know about win snare parser for spanish version please let me know.

0 Likes
Share
Reply
Powered by Khoros
  • Blog
  • Events
  • Discussions
  • Idea Exchange
  • Knowledge Base
  • Case Portal
  • Community Support
  • Product Life Cycle
  • Support Information
  • About the Community
  • Terms & Conditions
  • Privacy Statement
  • Acceptable Use Policy
  • Employee Login
© 2022 RSA Security LLC or its affiliates. All rights reserved.