This website uses cookies. By clicking Accept, you consent to the use of cookies. Click Here to learn more about how we use cookies.
Accept
Reject

NetWitness Community

  • Home
  • Products
    • NetWitness Platform
      • Advisories
      • Documentation
        • Platform Documentation
        • Known Issues
        • Security Fixes
        • Hardware Documentation
        • Threat Content
        • Unified Data Model
        • Videos
      • Downloads
      • Integrations
      • Knowledge Base
    • NetWitness Cloud SIEM
      • Advisories
      • Documentation
      • Knowledge Base
    • NetWitness Detect AI
      • Advisories
      • Documentation
      • Knowledge Base
    • NetWitness Investigator
    • NetWitness Orchestrator
      • Advisories
      • Documentation
      • Knowledge Base
      • Legacy NetWitness Orchestrator
        • Advisories
        • Documentation
  • Community
    • Blog
    • Discussions
    • Events
    • Idea Exchange
  • Support
    • Case Portal
      • Create New Case
      • View My Cases
      • View My Team's Cases
    • Community Support
      • Getting Started
      • News & Announcements
      • Community Support Forum
      • Community Support Articles
    • Product Life Cycle
    • Support Information
    • General Security Advisories
  • Training
    • Blog
    • Certification Program
    • Course Catalog
      • Netwitness XDR
      • EC-Council Training
    • New Product Readiness
    • On-Demand Subscriptions
    • Student Resources
    • Upcoming Events
    • Role-Based Training
  • Technology Partners
  • Trust Center
Sign InRegister Now
Enter a search word
    Turn off suggestions
    Enter a search word
      Turn off suggestions
      Enter a user name or rank
        Turn off suggestions
        Enter a search word
          Turn off suggestions
          Enter a search word
            Turn off suggestions
            cancel
            Turn on suggestions
            Showing results for 
            Search instead for 
            Did you mean: 
            NetWitness Discussions
            • NetWitness Community
            • Discussions
            • Re: RSA Netwitness Logs&packets log-hybrid
            • Options
              • Subscribe to RSS Feed
              • Mark Topic as New
              • Mark Topic as Read
              • Float this Topic for Current User
              • Bookmark
              • Subscribe
              • Mute
              • Printer Friendly Page

            RSA Netwitness Logs&packets log-hybrid

            AbdulrhmanM
            AbdulrhmanM Beginner
            Beginner
            Options
            • Mark as New
            • Bookmark
            • Subscribe
            • Mute
            • Subscribe to RSS Feed
            • Permalink
            • Print
            • Report Inappropriate Content

            ‎2018-10-10 02:42 AM

            Hi, I have a question regarding how log hybrid collects logs. Is there any kind of agent on each server? and those agents send logs to the log hybrid? or all servers are connected to an aggregation switch, which is connected to the log hybrid? or maybe neither of these? 

             

            Thanks

            • Community Thread
            • Discussion
            • Forum Thread
            • NetWitness
            • NW
            • NWP
            • RSA NetWitness
            • RSA NetWitness Platform
            0 Likes
            Reply
            • All forum topics
            • Previous Topic
            • Next Topic
            7 REPLIES 7

            MohammedMustafa
            Frequent Contributor MohammedMustafa Frequent Contributor
            Frequent Contributor
            Options
            • Mark as New
            • Bookmark
            • Subscribe
            • Mute
            • Subscribe to RSS Feed
            • Permalink
            • Print
            • Report Inappropriate Content

            ‎2018-10-10 09:22 AM

            Hi Abdul,

             

            Log Hybrid (Physical or Virtual) is a device that has log decoder, log collector & Concentrator service running on a single host.

            So the log collection on log-hybrid is similar to the log collection that happens on a Log decoder hosted on a separate device.

            Hope it helps.

            Thanks
            Mohammed Mustafa
            1 Like
            Reply

            Anonymous
            Not applicable
            Options
            • Mark as New
            • Bookmark
            • Subscribe
            • Mute
            • Subscribe to RSS Feed
            • Permalink
            • Print
            • Report Inappropriate Content

            ‎2018-10-10 03:09 PM

            Hi Abdulrhman,

             

            There are many ways to collect logs in NetWitness.  We accept logs via syslog, odbc, files, plugins, and many others.  Some require agents to push to us such as SFTPing files or our Endpoint Agent to send us Windows logs.  Others we pull from the sources such as WinRM, and ODBC.  Still others, such as syslog, are send directly from a source to NetWitness.

             

            You can see how to collect logs from our supported event source types in the guides on this page.

             

            https://community.rsa.com/community/products/netwitness/parser-network/event-sources 

            1 Like
            Reply

            AbdulrhmanM
            AbdulrhmanM Beginner
            Beginner
            Options
            • Mark as New
            • Bookmark
            • Subscribe
            • Mute
            • Subscribe to RSS Feed
            • Permalink
            • Print
            • Report Inappropriate Content

            ‎2018-10-11 03:45 AM

            Thank you guys, that was helpful.

             

            About log collector, what does it do? if we have a decoder that ingests raw data and applies parsers, and concentrator indexes data, what is the purpose of log collector? I don't see it mentioned in RSA Netwitness documentations.

            Another thing about the system, is SA a host by its self? or a part of another host? what does it exactly do? does it differ from ESA?  

            Thank you again, I'm new to all of this, so you might want to excuse me

            0 Likes
            Reply

            MihaMesojedec
            Employee MihaMesojedec
            Employee
            Options
            • Mark as New
            • Bookmark
            • Subscribe
            • Mute
            • Subscribe to RSS Feed
            • Permalink
            • Print
            • Report Inappropriate Content

            ‎2018-10-11 03:59 AM

            Please review this link: Log Collection Configuration Guide for Version 11.x - Table of Contents 

            and

            https://community.rsa.com/docs/DOC-79963 

            0 Likes
            Reply

            RichardAraujo1
            RichardAraujo1 Beginner
            Beginner
            Options
            • Mark as New
            • Bookmark
            • Subscribe
            • Mute
            • Subscribe to RSS Feed
            • Permalink
            • Print
            • Report Inappropriate Content

            ‎2019-03-27 10:00 AM

            Olá a todos Preciso de ajuda sobre netwitness: Log usando estrutura híbrida, é possível usar dois servidores híbridos em ambiente diferente?

            0 Likes
            Reply

            RichardAraujo1
            RichardAraujo1 Beginner
            Beginner
            In response to RichardAraujo1
            Options
            • Mark as New
            • Bookmark
            • Subscribe
            • Mute
            • Subscribe to RSS Feed
            • Permalink
            • Print
            • Report Inappropriate Content

            ‎2019-03-27 10:05 AM

            I need help about netwitness :Log's using hybrid structure, its possible to use two hybrid servers in different enviroment?

            0 Likes
            Reply

            RichardAraujo1
            RichardAraujo1 Beginner
            Beginner
            Options
            • Mark as New
            • Bookmark
            • Subscribe
            • Mute
            • Subscribe to RSS Feed
            • Permalink
            • Print
            • Report Inappropriate Content

            ‎2019-03-27 10:06 AM

            I need help about netwitness :Log's using hybrid structure, its possible to use two hybrid servers in different enviroment?

            0 Likes
            Reply
            li.common.scroll-to.top
            Powered by Khoros
            • Blog
            • Events
            • Discussions
            • Idea Exchange
            • Knowledge Base
            • Case Portal
            • Community Support
            • Product Life Cycle
            • Support Information
            • About the Community
            • Terms & Conditions
            • Privacy Statement
            • Acceptable Use Policy
            • Employee Login
            © 2022 RSA Security LLC or its affiliates. All rights reserved.
            Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.