2019-08-04 11:09 AM
Hi,
While investigating a certain type of log (trendmicrodsa) i have noticed that even though i do have an existing meta key that contains a value, i cant use this meta key when (for example) trying to 'work' with that meta key under meta groups...
does that has anything to do with the fact that the meta key is not grayed?
how can i fix this?
attaching an example of field "action"... (not grayed)
2019-08-06 12:27 PM
Hi Adi,
That reconstruction view is showing you indexed metas (grayed) vs. not indexed. You can refer to this documentation to help you determine which indexing levels are appropriate for your environment, use cases, and other needs, as well as learn how to change them: https://community.rsa.com/docs/DOC-81117
Keep in mind that it is best to be deliberate and intentional when making changes to your index. Simply indexing everything to the highest level will most likely result in performance issues down the line, so identifying the specific metas that you need indexed for your specific needs will both help you get the most value out of netwitness, as well as keep it performing optimally.