Article Number
000003183
Applies To
NetWitness Product Set: NetWitness Platform
NetWitness Product/Service Type: Malware Analysis
NetWitness Version/Condition: 11.x, 12.x
Platform: CentOS
O/S Version: 7
Issue
The NetWitness Malware Analysis is not processing any events on continuous scan mode.
Looking at the /var/lib/netwitness/malware-analytics-server/spectrum/logs/spectrum.log, it is showing that no events are being submitted to be processed.
Cause
Issue is caused by the two required App Rules spectrum.consume and spectrum.consume1.1 are not deployed on the Packet Decoders. These App Rules determine which sessions/events are to be submitted to the Malware Analysis for processing.
Resolution
1. In NetWitness UI, go to Configure > Live Content > Click on
MALWARE ANALYSIS > Click
Search2. Then subscribe and deploy all resources found to the packet decoders.
Below is a screenshot of Live search with Malware Analysis selected:
Image description