This website uses cookies. By clicking Accept, you consent to the use of cookies. Click Here to learn more about how we use cookies.
Accept
Reject

NetWitness Community

  • Home
  • Products
    • NetWitness Platform
      • Advisories
      • Documentation
        • Platform Documentation
        • Known Issues
        • Security Fixes
        • Hardware Documentation
        • Threat Content
        • Unified Data Model
        • Videos
      • Downloads
      • Integrations
      • Knowledge Base
    • NetWitness Cloud SIEM
      • Advisories
      • Documentation
      • Knowledge Base
    • NetWitness Detect AI
      • Advisories
      • Documentation
      • Knowledge Base
    • NetWitness Investigator
    • NetWitness Orchestrator
      • Advisories
      • Documentation
      • Knowledge Base
      • Legacy NetWitness Orchestrator
        • Advisories
        • Documentation
  • Community
    • Blog
    • Discussions
    • Events
    • Idea Exchange
  • Support
    • Case Portal
      • Create New Case
      • View My Cases
      • View My Team's Cases
    • Community Support
      • Getting Started
      • News & Announcements
      • Community Support Forum
      • Community Support Articles
    • Product Life Cycle
    • Support Information
    • General Security Advisories
  • Training
    • Blog
    • Certification Program
    • Course Catalog
      • Netwitness XDR
      • EC-Council Training
    • New Product Readiness
    • On-Demand Subscriptions
    • Student Resources
    • Upcoming Events
    • Role-Based Training
  • Technology Partners
  • Trust Center
Sign InRegister Now
cancel
Turn on suggestions
Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.
Showing results for 
Search instead for 
Did you mean: 
NetWitness Education Courses
  • NetWitness Community
  • NetWitness Education
  • Courses
  • RSA NetWitness Logs & Network Integration with RSA NetWitness Endpoint
  • Options
    • Subscribe to RSS Feed
    • Bookmark
    • Subscribe
    • Printer Friendly Page
    • Report Inappropriate Content
No ratings

RSA NetWitness Logs & Network Integration with RSA NetWitness Endpoint

CraigHansen1
CraigHansen1 Beginner
Beginner
Options
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Report Inappropriate Content

on ‎2016-07-14 10:02 AM

Access Training

In order to register for a class, you need to first create an EMC account

If you need further assistance, contact us

 

Summary

This on-demand learning covers how to configure integration between RSA NetWitness Logs & Network and RSA NetWitness Endpoint.

 

Overview

This on-demand learning describes how to integrate RSA NetWitness Logs & Network and RSA NetWitness Endpoint to perform investigations using both tools. It covers various forms of integration including syslog, Live feeds, recurring feed and Incident Management (message bus).

 

Audience

NetWitness Endpoint Administrators

NetWitness Logs & Network Administrators

 

Delivery Type

On-Demand Learning

 

Duration

1 hour

 

Prerequisite Knowledge/Skills

RSA NetWitness Endpoint Foundations (I day ILT)  or RSA NetWitness Endpoint Fundamentals (On-Demand Learning) or equivalent experience

 

Learning Objectives

Upon successful completion of this course, participants should be able to:

  • Identify integration requirements
  • Describe the types of integration
  • Configure NetWitness Endpoint for syslog to the Log Decoder
  • Configure NetWitness Endpoint alerts via the message bus
  • Configure contextual data from NetWitness Endpoint via recurring feed
  • Configure NetWitness Endpoint to receive Live feeds
  • Analyze data using NetWitness Logs & Network and NetWitness Endpoint

 

Course Outline

  • Integration Overview
    • Integration methods
    • Integration requirements
  • Syslog Integration
    • Configuration prerequisites
    • Configuration steps
    • Configuration results
    • Syslog integration demonstration
  • Incident Management Integration
    • Configuration prerequisites
    • Configuration steps
    • Configuration results
  • Feed Integration
    • Configuration prerequisites
    • Configuration steps
    • Configuration results
    • Feed integration demonstration
  • Live Feed Integration
    • Configuration prerequisites
    • Configuration steps
    • Configuration results
    • Live Feed integration demonstration
  • Analyzing data
    • Drilling into NetWitness Logs & Network from Endpoint
    • Drilling into Endpoint from NetWitness Logs & Network
    • Context Hub
    • Endpoint IOC Lookup
    • Endpoint ESA integration
    • Endpoint reporting integration

 

 

 

 

 

Access Training

In order to register for a class, you need to first create an EMC account

If you need further assistance, contact us

  • &
  • 10.6
  • 4.3
  • Admin
  • advanced
  • Configuration
  • ECAT
  • Ed Services
  • education
  • Education Services
  • Endpoint
  • english
  • expanding
  • Integration
  • logs & network
  • logs and packets
  • navigator
  • NetWitness
  • netwitness logs & network
  • netwitness navigator
  • netwitness training
  • Network
  • NW
  • NWP
  • on demand learning
  • Product Training
  • rsa
  • RSA NetWitness
  • RSA NetWitness Platform
  • RSA NetWitness Training
  • RSA Security Analytics
  • RSA University
  • RSAU
  • threat hunter
  • training
  • Training Course
  • university
Was this article helpful? Yes No
1 Like
Version history
Last update:
‎2016-07-14 10:02 AM
Updated by:
CraigHansen1 Beginner
Contributors
  • CraigHansen1
    CraigHansen1
Powered by Khoros
  • Blog
  • Events
  • Discussions
  • Idea Exchange
  • Knowledge Base
  • Case Portal
  • Community Support
  • Product Life Cycle
  • Support Information
  • About the Community
  • Terms & Conditions
  • Privacy Statement
  • Acceptable Use Policy
  • Employee Login
© 2022 RSA Security LLC or its affiliates. All rights reserved.