Article Number
000001450
Applies To
RSA Product Set: NetWitness Logs and Packets
RSA Product/Service Type: Security Analytics Server
RSA Version/Condition: 10.6.x.x & 11.0.x.x
Issue
This article is helpful in case you want to:
- Have "Live Connect" as data-source to your RSA Context-Hub service.
- Properly configure RSA Automated Threat Detection "ATD".
Cause
- ESA Appliance MUST have connectivity to RSA's Live URL "cms.netwitness.com"
- A connection from the ESA host to the Whois service (same location as RSA Live cms:netwitness.com:443) must be opened on port 443
Resolution
- Notice that you have a valid RSA Live account and have both "Threat-Insights" and "Analyst Behaviour" enabled.
- However only Analyst Behavior is enabled as depicted below:
?