This website uses cookies. By clicking Accept, you consent to the use of cookies. Click Here to learn more about how we use cookies.
Accept
Reject

NetWitness Community

  • Home
  • Products
    • NetWitness Platform
      • Advisories
      • Documentation
        • Platform Documentation
        • Known Issues
        • Security Fixes
        • Hardware Documentation
        • Threat Content
        • Unified Data Model
        • Videos
      • Downloads
      • Integrations
      • Knowledge Base
    • NetWitness Cloud SIEM
      • Advisories
      • Documentation
      • Knowledge Base
    • NetWitness Detect AI
      • Advisories
      • Documentation
      • Knowledge Base
    • NetWitness Investigator
    • NetWitness Orchestrator
      • Advisories
      • Documentation
      • Knowledge Base
      • Legacy NetWitness Orchestrator
        • Advisories
        • Documentation
  • Community
    • Blog
    • Discussions
    • Events
    • Idea Exchange
  • Support
    • Case Portal
      • Create New Case
      • View My Cases
      • View My Team's Cases
    • Community Support
      • Getting Started
      • News & Announcements
      • Community Support Forum
      • Community Support Articles
    • Product Life Cycle
    • Support Information
    • General Security Advisories
  • Training
    • Blog
    • Certification Program
    • Course Catalog
      • Netwitness XDR
      • EC-Council Training
    • New Product Readiness
    • On-Demand Subscriptions
    • Student Resources
    • Upcoming Events
    • Role-Based Training
  • Technology Partners
  • Trust Center
Sign InRegister Now
cancel
Turn on suggestions
Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.
Showing results for 
Search instead for 
Did you mean: 
NetWitness Discussions
  • NetWitness Community
  • Discussions
  • Re: reporting engine from IMDB and event data access?
  • Options
    • Subscribe to RSS Feed
    • Mark Topic as New
    • Mark Topic as Read
    • Float this Topic for Current User
    • Bookmark
    • Subscribe
    • Mute
    • Printer Friendly Page

reporting engine from IMDB and event data access?

VladimirPrevin
VladimirPrevin Beginner
Beginner
Options
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Report Inappropriate Content

‎2018-07-11 03:10 AM

hello,

 

wondering if for SA RE IMDB queries - is there any way to access event data in IMDB queries via RE? [when querying the alert collection]

e.g. alert.name,alert.events[0].threat_desc

or is it only the IM enriched groupby_
properties e.g.

alert.groupby_destination_country

 

 

{
"success": true,
"data": {
"destination_country": ["Australia"],
"groupby_type": "Log",
"user_summary": [""],
"groupby_domain": "blablalbalblabla",
"source": "Event Stream Analysis",
"type": ["Log"],
"groupby_source_country": "Romania",
"groupby_destination_country": "Australia",
"groupby_threat_source": "",
"signature_id": "xxxxx",
"groupby_filename": "",
"groupby_data_hash": "",
"groupby_event_desc": "",
"groupby_destination_ip": "alalalalala",
"groupby_threat_desc": "we have a custom group by group ignore this",
"groupby_source_ip": "snip",
"groupby_source_username": "",
"groupby_detector_ip": "xx.xx.xx.xx",
"events": [{

....."threat_desc":.......

  • Community Thread
  • Discussion
  • event data access for im alert queries
  • Forum Thread
  • imdb
  • NetWitness
  • NW
  • NWP
  • Reporting Engine
  • RSA NetWitness
  • RSA NetWitness Platform
0 Likes
Reply
  • All forum topics
  • Previous Topic
  • Next Topic
2 REPLIES 2

VladimirPrevin
VladimirPrevin Beginner
Beginner
Options
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Report Inappropriate Content

‎2018-07-11 03:12 AM

then again, maybe it's a bad idea and the normalization scripts are the place to take out any meta to access ...hmmm 

0 Likes
Reply

EricPartington
Employee EricPartington
Employee
Options
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Report Inappropriate Content

‎2018-07-11 08:29 AM

No, I am not aware of any way to access that event data from RE in IM database

0 Likes
Reply
Powered by Khoros
  • Blog
  • Events
  • Discussions
  • Idea Exchange
  • Knowledge Base
  • Case Portal
  • Community Support
  • Product Life Cycle
  • Support Information
  • About the Community
  • Terms & Conditions
  • Privacy Statement
  • Acceptable Use Policy
  • Employee Login
© 2022 RSA Security LLC or its affiliates. All rights reserved.