Following diagram shows how NetWitness MetaExport works:
There are of three plugins available that helps with MetaExport.
-
Input plugin: The Input plugin collects the events from the event sources. The NetWitness Export Connector uses NetWitness API that collects the meta data from the decoder. The data is then forwarded to the Filter plugin.
-
Filter plugin (optional): The Filter plugin adds, removes, or modifies the received data and forwards it to the Output plugin. You can use the standard Logstash filter plugins to add, remove, or modify the data.
-
Output plugin: The syslog Output plugin sends the processed event data to the third-party application where the Syslog receiver is configured.