This website uses cookies. By clicking Accept, you consent to the use of cookies. Click Here to learn more about how we use cookies.
Accept
Reject

NetWitness Community

  • Home
  • Products
    • NetWitness Platform
      • Advisories
      • Documentation
        • Platform Documentation
        • Known Issues
        • Security Fixes
        • Hardware Documentation
        • Threat Content
        • Unified Data Model
        • Videos
      • Downloads
      • Integrations
      • Knowledge Base
    • NetWitness Cloud SIEM
      • Advisories
      • Documentation
      • Knowledge Base
    • NetWitness Detect AI
      • Advisories
      • Documentation
      • Knowledge Base
    • NetWitness Investigator
    • NetWitness Orchestrator
      • Advisories
      • Documentation
      • Knowledge Base
      • Legacy NetWitness Orchestrator
        • Advisories
        • Documentation
  • Community
    • Blog
    • Discussions
    • Events
    • Idea Exchange
  • Support
    • Case Portal
      • Create New Case
      • View My Cases
      • View My Team's Cases
    • Community Support
      • Getting Started
      • News & Announcements
      • Community Support Forum
      • Community Support Articles
    • Product Life Cycle
    • Support Information
    • General Security Advisories
  • Training
    • Blog
    • Certification Program
    • Course Catalog
      • Netwitness XDR
      • EC-Council Training
    • New Product Readiness
    • On-Demand Subscriptions
    • Student Resources
    • Upcoming Events
    • Role-Based Training
  • Technology Partners
  • Trust Center
Sign InRegister Now
cancel
Turn on suggestions
Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.
Showing results for 
Search instead for 
Did you mean: 
NetWitness Education Courses
  • NetWitness Community
  • NetWitness Education
  • Courses
  • RSA NetWitness Network and Splunk® Integration
  • Options
    • Subscribe to RSS Feed
    • Bookmark
    • Subscribe
    • Printer Friendly Page
    • Report Inappropriate Content
No ratings

RSA NetWitness Network and Splunk® Integration

ElenaKomarova
Employee ElenaKomarova
Employee
Options
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Report Inappropriate Content

on ‎2017-01-31 11:48 AM

Access Training

In order to register for a class, you need to first create an EMC account

If you need further assistance, contact us

 

Summary

This on-demand learning describes how to integrate RSA NetWitness Network with Splunk to allow sharing of relevant data between the two products for reporting, alerting and investigation purposes.

 

Overview

This on-demand learning provides students with the knowledge and skills to configure Splunk® Enterprise and RSA NetWitness Network to view security logs in Splunk, view Splunk metatdata in RSA NetWitness Network, link to Splunk data through a context menu, send logs to Splunk via an ESA alert, and send Reporting Engine logs to Splunk.

 

Note: Splunk Enterprise is a registered trademark of Splunk Inc.

Audience

Anyone interested in configuring Splunk

Delivery Type

On-Demand Learning (self-paced eLearning)

Duration

1.5 hours

Prerequisite Knowledge/Skills

Students should have familiarity with RSA NetWitness Network Splunk Enterprise

Learning Objectives

Upon successful completion of this course, participants should be able to:

• Describe the benefits of integration with Splunk

• Describe the integration options

• Create Context Actions to pivot from NetWitness investigations to Splunk

• Forward Security/Audit Logs to Splunk

• Configure Splunk to point to RSA NetWitness

• Forward ESA Alert Syslog Notifications to Splunk

• Forward Security/RE Logs to Splunk

Course Outline

  • Module 1 Integration Overview
    • Benefits of Splunk integration
    • Integration methods
  • Module 2 Creating Context Menus
    • Context action menus in RSA NetWitness Network
    • How to create a context menu action
    • Using a context menu in an investigation
    • Creating a Context Menu Action demonstration
  • Module 3 Configuring Syslog Notification
    • Configuration Splunk as a notification server
    • Viewing security/audit logs in Splunk
    • Configuring Syslog Notification demonstration
  • Module 4 Configuring ESA Alert Notification
    • Set up a TCP collector for Splunk data
    • Configure syslog notification for the Splunk server
    • Configure an ESA alert to send logs to Splunk
    • Configuring ESA Alert Notification demonstration
  • Module 5 Configuring Reporting Engine Logs
    • Set up a TCP collector for Splunk data
    • Create a Reporting Engine output action
    • Create a Reporting rule
    • Configuring Reporting Engine Logs demonstration

Access Training

In order to register for a class, you need to first create an EMC account

If you need further assistance, contact us

  • 10.6
  • Admin
  • advanced
  • Configuration
  • Ed Services
  • education
  • Education Services
  • english
  • expanding
  • Integration
  • learning
  • navigator
  • NetWitness
  • netwitness navigator
  • netwitness network and splunk
  • netwitness training
  • Network
  • network and splunk
  • network and splunk integration
  • network and splunk® integration
  • NW
  • NWP
  • on demand learning
  • on-demand
  • on-demand learning
  • Product Training
  • rsa
  • RSA NetWitness
  • rsa netwitness network and splunk
  • rsa netwitness network and splunk integration
  • rsa netwitness network and splunk® integration
  • rsa netwitness packets and splunk integration
  • RSA NetWitness Platform
  • RSA NetWitness Training
  • RSA University
  • RSAU
  • splunk
  • splunk®
  • splunk® integration
  • training
  • Training Course
  • university
Was this article helpful? Yes No
0 Likes
Version history
Last update:
‎2017-01-31 11:48 AM
Updated by:
Employee ElenaKomarova
Contributors
  • ElenaKomarova
    ElenaKomarova
Powered by Khoros
  • Blog
  • Events
  • Discussions
  • Idea Exchange
  • Knowledge Base
  • Case Portal
  • Community Support
  • Product Life Cycle
  • Support Information
  • About the Community
  • Terms & Conditions
  • Privacy Statement
  • Acceptable Use Policy
  • Employee Login
© 2022 RSA Security LLC or its affiliates. All rights reserved.