This website uses cookies. By clicking Accept, you consent to the use of cookies. Click Here to learn more about how we use cookies.
Accept
Reject

NetWitness Community

  • Home
  • Products
    • NetWitness Platform
      • Advisories
      • Documentation
        • Platform Documentation
        • Known Issues
        • Security Fixes
        • Hardware Documentation
        • Threat Content
        • Unified Data Model
        • Videos
      • Downloads
      • Integrations
      • Knowledge Base
    • NetWitness Cloud SIEM
      • Advisories
      • Documentation
      • Knowledge Base
    • NetWitness Detect AI
      • Advisories
      • Documentation
      • Knowledge Base
    • NetWitness Investigator
    • NetWitness Orchestrator
      • Advisories
      • Documentation
      • Knowledge Base
      • Legacy NetWitness Orchestrator
        • Advisories
        • Documentation
  • Community
    • Blog
    • Discussions
    • Events
    • Idea Exchange
  • Support
    • Case Portal
      • Create New Case
      • View My Cases
      • View My Team's Cases
    • Community Support
      • Getting Started
      • News & Announcements
      • Community Support Forum
      • Community Support Articles
    • Product Life Cycle
    • Support Information
    • General Security Advisories
  • Training
    • Blog
    • Certification Program
    • Course Catalog
      • Netwitness XDR
      • EC-Council Training
    • New Product Readiness
    • On-Demand Subscriptions
    • Student Resources
    • Upcoming Events
    • Role-Based Training
  • Technology Partners
  • Trust Center
Sign InRegister Now
cancel
Turn on suggestions
Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.
Showing results for 
Search instead for 
Did you mean: 
NetWitness Discussions
  • NetWitness Community
  • Discussions
  • Reporting Alert alertInterval
  • Options
    • Subscribe to RSS Feed
    • Mark Topic as New
    • Mark Topic as Read
    • Float this Topic for Current User
    • Bookmark
    • Subscribe
    • Mute
    • Printer Friendly Page

Reporting Alert alertInterval

JohnTyson1
JohnTyson1 Beginner
Beginner
Options
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Report Inappropriate Content

‎2017-04-07 02:57 PM

Designed a SMTP reporting alert to send an email whenever a specific log message was ingested.

 

The rule basically said msg.id =  '%C4K_CHASSIS-3-MUXBUFFERREADSUPERVISORSELECTIONFAILED'.  Which indicates that a 48 port card was down.  The network team would get an email and get to work on it.  

 

When setting up the alert, there were 2 options "execute once" or "execute each event".  Execute once was selected in the alert, but this is a little misleading.  The alerts were being logged about every second, and it didn't send that many emails; however we were receiving an email every minute.  

 

Fortunately this was a simple fix, by editing the "AlertInterval" located under the 'reporting engine>explore>  com.rsa.soc.re>alertConfiguration'; from 1 to 10 we now receive emails only every 10 minutes.  

 

Happy Hunting, hope this saves you some digging.

  • alert rules
  • alert_email
  • alertinterval
  • Community Thread
  • Discussion
  • Forum Thread
  • NetWitness
  • NW
  • NWP
  • report engine
  • RSA NetWitness
  • RSA NetWitness Platform
0 Likes
Share
Reply
  • All forum topics
  • Previous Topic
  • Next Topic
3 REPLIES 3

JohnKisner
Trusted Contributor JohnKisner Trusted Contributor
Trusted Contributor
Options
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Report Inappropriate Content

‎2017-04-13 06:29 PM

Please realize that by changing the AlertInterval you are causing the Alert scheduler to only run once per interval for all scheduled alerts, in this case once every 10 minutes, instead of the default once every 1 minute. As mentioned above there are two types of alert notification execution: Each Event and Once. Here is what each actually means.

 

Each Event

When the alert scheduler runs the rule for the alert it runs the alert rule query against the infrastructure. On query completion results are returned or none are returned. If some were returned, lets say 3 results came back that matched the rule, you would receive three notifications of that type for this interval. So if it was SMTP you would receive three separate emails from the alert and each would represent one of the three results returned. You can imagine how bad this can get if you return thousands of results. Though sometimes this is wanted when using Syslog or SNMP.

 

Once

If the Execute drop down is set to Once then only one alert notification will be sent per alert schedule interval no matter how many results were returned. Of course if no results were returned from the alert, no notification will be sent. This is designed to let you know something happened but not be flooded with alerts as you can use the templating system to tell you in the alert notification how many actual alert results came back in a single notification.

 

In summary, only change this AlertInterval if you are fully prepared for the consequences. Otherwise you may want to look closer at what you are alerting on and how you are getting notifications. As of now there is no alert suppression in the reporting engine for these normal alerts. There is alert suppression for alerts coming from the ESA however. If you have an ESA you can covert your normal Reporting Engine alerts into ESA alerts to provide the suppression you may be looking for.

 

I hope this provides more clarity around the AlertInterval and the two options for notification execution.

3 Likes
Share
Reply

JohnTyson1
JohnTyson1 Beginner
Beginner
In response to JohnKisner
Options
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Report Inappropriate Content

‎2017-05-01 10:17 AM

John,

Thanks for the reply and additional information, much appreciated.  We do have an ESA, but was thinking that since there was no correlation involved that I didn't want to use those resources.

 

Do you happen to know the steps to allows me to create reports on the IMDB in 10.6.2?

0 Likes
Share
Reply

JohnKisner
Trusted Contributor JohnKisner Trusted Contributor
Trusted Contributor
Options
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Report Inappropriate Content

‎2017-05-02 01:22 PM

John,

 

It should be about the same as writing reports for the NWDB but selecting the IMDB as the source when creating the rule. Here is the documentation about the IMDB rule syntax. https://community.rsa.com/docs/DOC-74656 

0 Likes
Share
Reply
Powered by Khoros
  • Blog
  • Events
  • Discussions
  • Idea Exchange
  • Knowledge Base
  • Case Portal
  • Community Support
  • Product Life Cycle
  • Support Information
  • About the Community
  • Terms & Conditions
  • Privacy Statement
  • Acceptable Use Policy
  • Employee Login
© 2022 RSA Security LLC or its affiliates. All rights reserved.